314 MB
/srv/reproducible-results/rbuild-debian/r-b-build.5edwg386/b1/scap-security-guide_0.1.76-1_armhf.changes vs.
/srv/reproducible-results/rbuild-debian/r-b-build.5edwg386/b2/scap-security-guide_0.1.76-1_armhf.changes
824 B
Files
    
Offset 1, 6 lines modifiedOffset 1, 6 lines modified
  
1 ·7eed571c9f8330192b1f0ef913f50a2f·153788·admin·optional·ssg-applications_0.1.76-1_all.deb1 ·a77783cec0f5c03ae282de17b05b5937·153784·admin·optional·ssg-applications_0.1.76-1_all.deb
2 ·ea0c1f19113a8a6c0a6e8b10e8e208a9·32632·admin·optional·ssg-base_0.1.76-1_all.deb2 ·ea0c1f19113a8a6c0a6e8b10e8e208a9·32632·admin·optional·ssg-base_0.1.76-1_all.deb
3 ·7eaa0a636948b3f5739bc9d9bf4f742a·3725584·admin·optional·ssg-debderived_0.1.76-1_all.deb 
4 ·f97e43471e5f34b96470b0fa0e9feacb·1232544·admin·optional·ssg-debian_0.1.76-1_all.deb 
5 ·9093fafb28937b9d3a8f2c06e1a572d1·37096220·admin·optional·ssg-nondebian_0.1.76-1_all.deb3 ·8999b98ff1f2096aa2fac1e933988b84·3725468·admin·optional·ssg-debderived_0.1.76-1_all.deb
 4 ·671e27b810515e8b79e1ea365e2d2755·1232336·admin·optional·ssg-debian_0.1.76-1_all.deb
 5 ·b709422cc81011da93ce0f7da703c301·37099308·admin·optional·ssg-nondebian_0.1.76-1_all.deb
411 KB
ssg-applications_0.1.76-1_all.deb
367 B
file list
    
Offset 1, 3 lines modifiedOffset 1, 3 lines modified
1 -rw-r--r--···0········0········0········4·2025-03-01·08:08:00.000000·debian-binary1 -rw-r--r--···0········0········0········4·2025-03-01·08:08:00.000000·debian-binary
2 -rw-r--r--···0········0········0·····1728·2025-03-01·08:08:00.000000·control.tar.xz2 -rw-r--r--···0········0········0·····1728·2025-03-01·08:08:00.000000·control.tar.xz
3 -rw-r--r--···0········0········0···151868·2025-03-01·08:08:00.000000·data.tar.xz3 -rw-r--r--···0········0········0···151864·2025-03-01·08:08:00.000000·data.tar.xz
98.0 B
control.tar.xz
70.0 B
control.tar
48.0 B
./md5sums
30.0 B
./md5sums
Files differ
410 KB
data.tar.xz
410 KB
data.tar
78.0 KB
./usr/share/xml/scap/ssg/content/ssg-chromium-ds.xml
77.9 KB
./usr/share/xml/scap/ssg/content/ssg-chromium-ds.xml
    
Offset 19, 23 lines modifiedOffset 19, 23 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-chromium-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-chromium-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-chromium-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-chromium-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-chromium-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-chromium-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-chromium-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-chromium-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-chromium-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-chromium-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-chromium-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-chromium-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-chromium-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-chromium-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/a:google:chromium-browser">28 ······<cpe-dict:cpe-item·name="cpe:/a:google:chromium-browser">
29 ········<cpe-dict:title·xml:lang="en-us">Google·Chromium·Browser</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Google·Chromium·Browser</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-chromium-cpe-oval.xml">oval:ssg-installed_app_is_chromium:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-chromium-cpe-oval.xml">oval:ssg-installed_app_is_chromium:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ····</cpe-dict:cpe-list>32 ····</cpe-dict:cpe-list>
33 ··</ds:component>33 ··</ds:component>
34 ··<ds:component·id="scap_org.open-scap_comp_ssg-chromium-xccdf.xml"·timestamp="2025-02-28T20:08:00">34 ··<ds:component·id="scap_org.open-scap_comp_ssg-chromium-xccdf.xml"·timestamp="2025-03-01T22:08:00">
35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_CHROMIUM"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_CHROMIUM"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Chromium</xccdf-1.2:title>37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Chromium</xccdf-1.2:title>
38 ······<xccdf-1.2:description>38 ······<xccdf-1.2:description>
39 ········This·guide·presents·a·catalog·of·security-relevant39 ········This·guide·presents·a·catalog·of·security-relevant
40 configuration·settings·for·Chromium.·It·is·a·rendering·of40 configuration·settings·for·Chromium.·It·is·a·rendering·of
41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 1675, 15 lines modifiedOffset 1675, 15 lines modified
1675 ··········<xccdf-1.2:check·system="http://scap.nist.gov/schema/ocil/2">1675 ··········<xccdf-1.2:check·system="http://scap.nist.gov/schema/ocil/2">
1676 ············<xccdf-1.2:check-content-ref·href="ssg-chromium-ocil.xml"·name="ocil:ssg-chromium_whitelist_plugin_urls_ocil:questionnaire:1"/>1676 ············<xccdf-1.2:check-content-ref·href="ssg-chromium-ocil.xml"·name="ocil:ssg-chromium_whitelist_plugin_urls_ocil:questionnaire:1"/>
1677 ··········</xccdf-1.2:check>1677 ··········</xccdf-1.2:check>
1678 ········</xccdf-1.2:Rule>1678 ········</xccdf-1.2:Rule>
1679 ······</xccdf-1.2:Group>1679 ······</xccdf-1.2:Group>
1680 ····</xccdf-1.2:Benchmark>1680 ····</xccdf-1.2:Benchmark>
1681 ··</ds:component>1681 ··</ds:component>
1682 ··<ds:component·id="scap_org.open-scap_comp_ssg-chromium-oval.xml"·timestamp="2025-02-28T20:08:00">1682 ··<ds:component·id="scap_org.open-scap_comp_ssg-chromium-oval.xml"·timestamp="2025-03-01T22:08:00">
1683 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">1683 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
1684 ······<oval-def:generator>1684 ······<oval-def:generator>
1685 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>1685 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
1686 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.2</oval:product_version>1686 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.2</oval:product_version>
1687 ········<oval:schema_version>5.11</oval:schema_version>1687 ········<oval:schema_version>5.11</oval:schema_version>
1688 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>1688 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
1689 ······</oval-def:generator>1689 ······</oval-def:generator>
Offset 2539, 813 lines modifiedOffset 2539, 813 lines modified
2539 ········<oval-def:external_variable·id="oval:ssg-var_enable_encrypted_searching:var:1"·version="1"·datatype="string"·comment="Expected·search·provider·name"/>2539 ········<oval-def:external_variable·id="oval:ssg-var_enable_encrypted_searching:var:1"·version="1"·datatype="string"·comment="Expected·search·provider·name"/>
2540 ········<oval-def:external_variable·id="oval:ssg-var_extension_whitelist:var:1"·version="1"·datatype="string"·comment="Expected·approved·extensions"/>2540 ········<oval-def:external_variable·id="oval:ssg-var_extension_whitelist:var:1"·version="1"·datatype="string"·comment="Expected·approved·extensions"/>
2541 ········<oval-def:external_variable·id="oval:ssg-var_auth_schema:var:1"·version="1"·datatype="string"·comment="Expected·HTTP·authentication·type"/>2541 ········<oval-def:external_variable·id="oval:ssg-var_auth_schema:var:1"·version="1"·datatype="string"·comment="Expected·HTTP·authentication·type"/>
2542 ········<oval-def:external_variable·id="oval:ssg-var_trusted_home_page:var:1"·version="1"·datatype="string"·comment="Expected·home·page"/>2542 ········<oval-def:external_variable·id="oval:ssg-var_trusted_home_page:var:1"·version="1"·datatype="string"·comment="Expected·home·page"/>
2543 ······</oval-def:variables>2543 ······</oval-def:variables>
2544 ····</oval-def:oval_definitions>2544 ····</oval-def:oval_definitions>
2545 ··</ds:component>2545 ··</ds:component>
2546 ··<ds:component·id="scap_org.open-scap_comp_ssg-chromium-ocil.xml"·timestamp="2025-02-28T20:08:00">2546 ··<ds:component·id="scap_org.open-scap_comp_ssg-chromium-ocil.xml"·timestamp="2025-03-01T22:08:00">
2547 ····<ocil:ocil>2547 ····<ocil:ocil>
2548 ······<ocil:generator>2548 ······<ocil:generator>
2549 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>2549 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
2550 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>2550 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
2551 ········<ocil:schema_version>2.0</ocil:schema_version>2551 ········<ocil:schema_version>2.0</ocil:schema_version>
2552 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>2552 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
2553 ······</ocil:generator>2553 ······</ocil:generator>
2554 ······<ocil:questionnaires>2554 ······<ocil:questionnaires>
2555 ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_google_sync_ocil:questionnaire:1">2555 ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_password_manager_ocil:questionnaire:1">
2556 ··········<ocil:title>Disable·Data·Synchronization·to·Google</ocil:title>2556 ··········<ocil:title>Disable·Chromium·Password·Manager</ocil:title>
2557 ··········<ocil:actions>2557 ··········<ocil:actions>
 2558 ············<ocil:test_action_ref>ocil:ssg-chromium_disable_password_manager_action:testaction:1</ocil:test_action_ref>
 2559 ··········</ocil:actions>
 2560 ········</ocil:questionnaire>
 2561 ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_session_cookies_ocil:questionnaire:1">
 2562 ··········<ocil:title>Disable·Session·Cookies</ocil:title>
 2563 ··········<ocil:actions>
2558 ············<ocil:test_action_ref>ocil:ssg-chromium_disable_google_sync_action:testaction:1</ocil:test_action_ref>2564 ············<ocil:test_action_ref>ocil:ssg-chromium_disable_session_cookies_action:testaction:1</ocil:test_action_ref>
 2565 ··········</ocil:actions>
 2566 ········</ocil:questionnaire>
 2567 ········<ocil:questionnaire·id="ocil:ssg-chromium_blacklist_extension_installation_ocil:questionnaire:1">
 2568 ··········<ocil:title>Disable·All·Extensions·by·Default</ocil:title>
 2569 ··········<ocil:actions>
 2570 ············<ocil:test_action_ref>ocil:ssg-chromium_blacklist_extension_installation_action:testaction:1</ocil:test_action_ref>
 2571 ··········</ocil:actions>
 2572 ········</ocil:questionnaire>
 2573 ········<ocil:questionnaire·id="ocil:ssg-chromium_enable_encrypted_searching_ocil:questionnaire:1">
 2574 ··········<ocil:title>Enable·Encrypted·Searching</ocil:title>
 2575 ··········<ocil:actions>
 2576 ············<ocil:test_action_ref>ocil:ssg-chromium_enable_encrypted_searching_action:testaction:1</ocil:test_action_ref>
 2577 ··········</ocil:actions>
 2578 ········</ocil:questionnaire>
 2579 ········<ocil:questionnaire·id="ocil:ssg-chromium_disallow_location_tracking_ocil:questionnaire:1">
 2580 ··········<ocil:title>Disable·Location·Tracking</ocil:title>
 2581 ··········<ocil:actions>
 2582 ············<ocil:test_action_ref>ocil:ssg-chromium_disallow_location_tracking_action:testaction:1</ocil:test_action_ref>
2559 ··········</ocil:actions>2583 ··········</ocil:actions>
2560 ········</ocil:questionnaire>2584 ········</ocil:questionnaire>
2561 ········<ocil:questionnaire·id="ocil:ssg-chromium_whitelist_plugin_urls_ocil:questionnaire:1">2585 ········<ocil:questionnaire·id="ocil:ssg-chromium_whitelist_plugin_urls_ocil:questionnaire:1">
2562 ··········<ocil:title>Enable·Plugins·for·Only·Approved·URLs</ocil:title>2586 ··········<ocil:title>Enable·Plugins·for·Only·Approved·URLs</ocil:title>
2563 ··········<ocil:actions>2587 ··········<ocil:actions>
2564 ············<ocil:test_action_ref>ocil:ssg-chromium_whitelist_plugin_urls_action:testaction:1</ocil:test_action_ref>2588 ············<ocil:test_action_ref>ocil:ssg-chromium_whitelist_plugin_urls_action:testaction:1</ocil:test_action_ref>
2565 ··········</ocil:actions>2589 ··········</ocil:actions>
2566 ········</ocil:questionnaire>2590 ········</ocil:questionnaire>
2567 ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_cleartext_passwords_ocil:questionnaire:1">2591 ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_cloud_print_sharing_ocil:questionnaire:1">
2568 ··········<ocil:title>Disable·Use·of·Cleartext·Passwords</ocil:title>2592 ··········<ocil:title>Disable·Cloud·Print·Sharing</ocil:title>
2569 ··········<ocil:actions>2593 ··········<ocil:actions>
2570 ············<ocil:test_action_ref>ocil:ssg-chromium_disable_cleartext_passwords_action:testaction:1</ocil:test_action_ref>2594 ············<ocil:test_action_ref>ocil:ssg-chromium_disable_cloud_print_sharing_action:testaction:1</ocil:test_action_ref>
2571 ··········</ocil:actions>2595 ··········</ocil:actions>
2572 ········</ocil:questionnaire>2596 ········</ocil:questionnaire>
2573 ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_saved_passwords_ocil:questionnaire:1">2597 ········<ocil:questionnaire·id="ocil:ssg-chromium_default_search_provider_ocil:questionnaire:1">
2574 ··········<ocil:title>Disable·Saved·Passwords</ocil:title>2598 ··········<ocil:title>Enable·the·Default·Search·Provider</ocil:title>
2575 ··········<ocil:actions>2599 ··········<ocil:actions>
2576 ············<ocil:test_action_ref>ocil:ssg-chromium_disable_saved_passwords_action:testaction:1</ocil:test_action_ref>2600 ············<ocil:test_action_ref>ocil:ssg-chromium_default_search_provider_action:testaction:1</ocil:test_action_ref>
2577 ··········</ocil:actions>2601 ··········</ocil:actions>
2578 ········</ocil:questionnaire>2602 ········</ocil:questionnaire>
2579 ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_firewall_traversal_ocil:questionnaire:1">2603 ········<ocil:questionnaire·id="ocil:ssg-chromium_extension_whitelist_ocil:questionnaire:1">
2580 ··········<ocil:title>Disable·Chromium's·Ability·to·Traverse·Firewalls</ocil:title>2604 ··········<ocil:title>Enable·Only·Approved·Extensions</ocil:title>
2581 ··········<ocil:actions>2605 ··········<ocil:actions>
2582 ············<ocil:test_action_ref>ocil:ssg-chromium_disable_firewall_traversal_action:testaction:1</ocil:test_action_ref>2606 ············<ocil:test_action_ref>ocil:ssg-chromium_extension_whitelist_action:testaction:1</ocil:test_action_ref>
2583 ··········</ocil:actions>2607 ··········</ocil:actions>
2584 ········</ocil:questionnaire>2608 ········</ocil:questionnaire>
2585 ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_thirdparty_cookies_ocil:questionnaire:1">2609 ········<ocil:questionnaire·id="ocil:ssg-chromium_policy_file_ocil:questionnaire:1">
2586 ··········<ocil:title>Disable·3rd·Party·Cookies</ocil:title>2610 ··········<ocil:title>Ensure·the·Chromium·Policy·Configuration·File·Exists</ocil:title>
2587 ··········<ocil:actions>2611 ··········<ocil:actions>
2588 ············<ocil:test_action_ref>ocil:ssg-chromium_disable_thirdparty_cookies_action:testaction:1</ocil:test_action_ref>2612 ············<ocil:test_action_ref>ocil:ssg-chromium_policy_file_action:testaction:1</ocil:test_action_ref>
2589 ··········</ocil:actions>2613 ··········</ocil:actions>
2590 ········</ocil:questionnaire>2614 ········</ocil:questionnaire>
2591 ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_password_manager_ocil:questionnaire:1">2615 ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_popups_ocil:questionnaire:1">
2592 ··········<ocil:title>Disable·Chromium·Password·Manager</ocil:title>2616 ··········<ocil:title>Disable·Popups</ocil:title>
2593 ··········<ocil:actions>2617 ··········<ocil:actions>
2594 ············<ocil:test_action_ref>ocil:ssg-chromium_disable_password_manager_action:testaction:1</ocil:test_action_ref>2618 ············<ocil:test_action_ref>ocil:ssg-chromium_disable_popups_action:testaction:1</ocil:test_action_ref>
2595 ··········</ocil:actions>2619 ··········</ocil:actions>
2596 ········</ocil:questionnaire>2620 ········</ocil:questionnaire>
2597 ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_autocomplete_ocil:questionnaire:1">2621 ········<ocil:questionnaire·id="ocil:ssg-chromium_enable_approved_plugins_ocil:questionnaire:1">
2598 ··········<ocil:title>Disable·the·AutoFill·Feature</ocil:title>2622 ··········<ocil:title>Enable·Only·Approved·Plugins</ocil:title>
2599 ··········<ocil:actions>2623 ··········<ocil:actions>
2600 ············<ocil:test_action_ref>ocil:ssg-chromium_disable_autocomplete_action:testaction:1</ocil:test_action_ref>2624 ············<ocil:test_action_ref>ocil:ssg-chromium_enable_approved_plugins_action:testaction:1</ocil:test_action_ref>
2601 ··········</ocil:actions>2625 ··········</ocil:actions>
Max diff block lines reached; 68468/79655 bytes (85.96%) of diff not shown.
69.4 KB
./usr/share/xml/scap/ssg/content/ssg-chromium-ocil.xml
69.3 KB
./usr/share/xml/scap/ssg/content/ssg-chromium-ocil.xml
Ordering differences only
    
Offset 3, 795 lines modifiedOffset 3, 795 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_google_sync_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_password_manager_ocil:questionnaire:1">
11 ······<ocil:title>Disable·Data·Synchronization·to·Google</ocil:title>11 ······<ocil:title>Disable·Chromium·Password·Manager</ocil:title>
12 ······<ocil:actions>12 ······<ocil:actions>
 13 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_password_manager_action:testaction:1</ocil:test_action_ref>
 14 ······</ocil:actions>
 15 ····</ocil:questionnaire>
 16 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_session_cookies_ocil:questionnaire:1">
 17 ······<ocil:title>Disable·Session·Cookies</ocil:title>
 18 ······<ocil:actions>
13 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_google_sync_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_session_cookies_action:testaction:1</ocil:test_action_ref>
 20 ······</ocil:actions>
 21 ····</ocil:questionnaire>
 22 ····<ocil:questionnaire·id="ocil:ssg-chromium_blacklist_extension_installation_ocil:questionnaire:1">
 23 ······<ocil:title>Disable·All·Extensions·by·Default</ocil:title>
 24 ······<ocil:actions>
 25 ········<ocil:test_action_ref>ocil:ssg-chromium_blacklist_extension_installation_action:testaction:1</ocil:test_action_ref>
 26 ······</ocil:actions>
 27 ····</ocil:questionnaire>
 28 ····<ocil:questionnaire·id="ocil:ssg-chromium_enable_encrypted_searching_ocil:questionnaire:1">
 29 ······<ocil:title>Enable·Encrypted·Searching</ocil:title>
 30 ······<ocil:actions>
 31 ········<ocil:test_action_ref>ocil:ssg-chromium_enable_encrypted_searching_action:testaction:1</ocil:test_action_ref>
 32 ······</ocil:actions>
 33 ····</ocil:questionnaire>
 34 ····<ocil:questionnaire·id="ocil:ssg-chromium_disallow_location_tracking_ocil:questionnaire:1">
 35 ······<ocil:title>Disable·Location·Tracking</ocil:title>
 36 ······<ocil:actions>
 37 ········<ocil:test_action_ref>ocil:ssg-chromium_disallow_location_tracking_action:testaction:1</ocil:test_action_ref>
14 ······</ocil:actions>38 ······</ocil:actions>
15 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
16 ····<ocil:questionnaire·id="ocil:ssg-chromium_whitelist_plugin_urls_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-chromium_whitelist_plugin_urls_ocil:questionnaire:1">
17 ······<ocil:title>Enable·Plugins·for·Only·Approved·URLs</ocil:title>41 ······<ocil:title>Enable·Plugins·for·Only·Approved·URLs</ocil:title>
18 ······<ocil:actions>42 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-chromium_whitelist_plugin_urls_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-chromium_whitelist_plugin_urls_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>44 ······</ocil:actions>
21 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_cleartext_passwords_ocil:questionnaire:1">46 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_cloud_print_sharing_ocil:questionnaire:1">
23 ······<ocil:title>Disable·Use·of·Cleartext·Passwords</ocil:title>47 ······<ocil:title>Disable·Cloud·Print·Sharing</ocil:title>
24 ······<ocil:actions>48 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_cleartext_passwords_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_cloud_print_sharing_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>50 ······</ocil:actions>
27 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_saved_passwords_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-chromium_default_search_provider_ocil:questionnaire:1">
29 ······<ocil:title>Disable·Saved·Passwords</ocil:title>53 ······<ocil:title>Enable·the·Default·Search·Provider</ocil:title>
30 ······<ocil:actions>54 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_saved_passwords_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-chromium_default_search_provider_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>56 ······</ocil:actions>
33 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_firewall_traversal_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-chromium_extension_whitelist_ocil:questionnaire:1">
35 ······<ocil:title>Disable·Chromium's·Ability·to·Traverse·Firewalls</ocil:title>59 ······<ocil:title>Enable·Only·Approved·Extensions</ocil:title>
36 ······<ocil:actions>60 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_firewall_traversal_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-chromium_extension_whitelist_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>62 ······</ocil:actions>
39 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_thirdparty_cookies_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-chromium_policy_file_ocil:questionnaire:1">
41 ······<ocil:title>Disable·3rd·Party·Cookies</ocil:title>65 ······<ocil:title>Ensure·the·Chromium·Policy·Configuration·File·Exists</ocil:title>
42 ······<ocil:actions>66 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_thirdparty_cookies_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-chromium_policy_file_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>68 ······</ocil:actions>
45 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_password_manager_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_popups_ocil:questionnaire:1">
47 ······<ocil:title>Disable·Chromium·Password·Manager</ocil:title>71 ······<ocil:title>Disable·Popups</ocil:title>
48 ······<ocil:actions>72 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_password_manager_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_popups_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>74 ······</ocil:actions>
51 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_autocomplete_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-chromium_enable_approved_plugins_ocil:questionnaire:1">
53 ······<ocil:title>Disable·the·AutoFill·Feature</ocil:title>77 ······<ocil:title>Enable·Only·Approved·Plugins</ocil:title>
54 ······<ocil:actions>78 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_autocomplete_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-chromium_enable_approved_plugins_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>80 ······</ocil:actions>
57 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_session_cookies_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_google_sync_ocil:questionnaire:1">
59 ······<ocil:title>Disable·Session·Cookies</ocil:title>83 ······<ocil:title>Disable·Data·Synchronization·to·Google</ocil:title>
60 ······<ocil:actions>84 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_session_cookies_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_google_sync_action:testaction:1</ocil:test_action_ref>
 86 ······</ocil:actions>
 87 ····</ocil:questionnaire>
 88 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_network_prediction_ocil:questionnaire:1">
 89 ······<ocil:title>Disable·Network·Prediction</ocil:title>
 90 ······<ocil:actions>
 91 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_network_prediction_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>92 ······</ocil:actions>
63 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_metrics_reporting_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_metrics_reporting_ocil:questionnaire:1">
65 ······<ocil:title>Disable·Metrics·Reporting</ocil:title>95 ······<ocil:title>Disable·Metrics·Reporting</ocil:title>
66 ······<ocil:actions>96 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_metrics_reporting_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_metrics_reporting_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>98 ······</ocil:actions>
69 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-chromium_block_desktop_notifications_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_saved_passwords_ocil:questionnaire:1">
71 ······<ocil:title>Prevent·Desktop·Notifications</ocil:title>101 ······<ocil:title>Disable·Saved·Passwords</ocil:title>
72 ······<ocil:actions>102 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-chromium_block_desktop_notifications_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_saved_passwords_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>104 ······</ocil:actions>
75 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-chromium_default_search_provider_name_ocil:questionnaire:1">106 ····<ocil:questionnaire·id="ocil:ssg-chromium_default_search_provider_name_ocil:questionnaire:1">
77 ······<ocil:title>Set·the·Default·Search·Provider's·URL</ocil:title>107 ······<ocil:title>Set·the·Default·Search·Provider's·URL</ocil:title>
78 ······<ocil:actions>108 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-chromium_default_search_provider_name_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-chromium_default_search_provider_name_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>110 ······</ocil:actions>
81 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-chromium_enable_encrypted_searching_ocil:questionnaire:1">112 ····<ocil:questionnaire·id="ocil:ssg-chromium_plugins_require_authorization_ocil:questionnaire:1">
83 ······<ocil:title>Enable·Encrypted·Searching</ocil:title>113 ······<ocil:title>Require·Outdated·Plugins·to·be·Authorized</ocil:title>
84 ······<ocil:actions>114 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-chromium_enable_encrypted_searching_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-chromium_plugins_require_authorization_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>116 ······</ocil:actions>
87 ····</ocil:questionnaire>117 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-chromium_blacklist_extension_installation_ocil:questionnaire:1">118 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_cleartext_passwords_ocil:questionnaire:1">
89 ······<ocil:title>Disable·All·Extensions·by·Default</ocil:title>119 ······<ocil:title>Disable·Use·of·Cleartext·Passwords</ocil:title>
90 ······<ocil:actions>120 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-chromium_blacklist_extension_installation_action:testaction:1</ocil:test_action_ref>121 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_cleartext_passwords_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>122 ······</ocil:actions>
93 ····</ocil:questionnaire>123 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-chromium_check_cert_revocation_ocil:questionnaire:1">124 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_search_suggestions_ocil:questionnaire:1">
95 ······<ocil:title>Enable·Online·OCSP/CRL·Certificate·Checks</ocil:title>125 ······<ocil:title>Disable·Search·Suggestion</ocil:title>
96 ······<ocil:actions>126 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-chromium_check_cert_revocation_action:testaction:1</ocil:test_action_ref>127 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_search_suggestions_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>128 ······</ocil:actions>
99 ····</ocil:questionnaire>129 ····</ocil:questionnaire>
Max diff block lines reached; 60131/70834 bytes (84.89%) of diff not shown.
86.2 KB
./usr/share/xml/scap/ssg/content/ssg-eks-ds.xml
86.1 KB
./usr/share/xml/scap/ssg/content/ssg-eks-ds.xml
    
Offset 19, 15 lines modifiedOffset 19, 15 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-eks-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-eks-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-eks-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-eks-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-eks-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-eks-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-eks-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-eks-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-eks-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-eks-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-eks-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-eks-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-eks-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-eks-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/a:amazon:elastic_kubernetes_service:1">28 ······<cpe-dict:cpe-item·name="cpe:/a:amazon:elastic_kubernetes_service:1">
29 ········<cpe-dict:title·xml:lang="en-us">Amazon·Elastic·Kubernetes·Service</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Amazon·Elastic·Kubernetes·Service</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-eks-cpe-oval.xml">oval:ssg-installed_app_is_eks:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-eks-cpe-oval.xml">oval:ssg-installed_app_is_eks:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ······<cpe-dict:cpe-item·name="cpe:/a:amazon:elastic_kubernetes_service_node:1.21">32 ······<cpe-dict:cpe-item·name="cpe:/a:amazon:elastic_kubernetes_service_node:1.21">
33 ········<cpe-dict:title·xml:lang="en-us">Amazon·Elastic·Kubernetes·Service·1.21</cpe-dict:title>33 ········<cpe-dict:title·xml:lang="en-us">Amazon·Elastic·Kubernetes·Service·1.21</cpe-dict:title>
Offset 35, 15 lines modifiedOffset 35, 15 lines modified
35 ······</cpe-dict:cpe-item>35 ······</cpe-dict:cpe-item>
36 ······<cpe-dict:cpe-item·name="cpe:/o:amazon:elastic_kubernetes_service_node:1">36 ······<cpe-dict:cpe-item·name="cpe:/o:amazon:elastic_kubernetes_service_node:1">
37 ········<cpe-dict:title·xml:lang="en-us">Amazon·Elastic·Kubernetes·Service·Node</cpe-dict:title>37 ········<cpe-dict:title·xml:lang="en-us">Amazon·Elastic·Kubernetes·Service·Node</cpe-dict:title>
38 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-eks-cpe-oval.xml">oval:ssg-installed_app_is_eks_node:def:1</cpe-dict:check>38 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-eks-cpe-oval.xml">oval:ssg-installed_app_is_eks_node:def:1</cpe-dict:check>
39 ······</cpe-dict:cpe-item>39 ······</cpe-dict:cpe-item>
40 ····</cpe-dict:cpe-list>40 ····</cpe-dict:cpe-list>
41 ··</ds:component>41 ··</ds:component>
42 ··<ds:component·id="scap_org.open-scap_comp_ssg-eks-xccdf.xml"·timestamp="2025-02-28T20:08:00">42 ··<ds:component·id="scap_org.open-scap_comp_ssg-eks-xccdf.xml"·timestamp="2025-03-01T22:08:00">
43 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_EKS"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">43 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_EKS"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
44 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>44 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
45 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Amazon·Elastic·Kubernetes·Service</xccdf-1.2:title>45 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Amazon·Elastic·Kubernetes·Service</xccdf-1.2:title>
46 ······<xccdf-1.2:description>46 ······<xccdf-1.2:description>
47 ········This·guide·presents·a·catalog·of·security-relevant47 ········This·guide·presents·a·catalog·of·security-relevant
48 configuration·settings·for·Amazon·Elastic·Kubernetes·Service.·It·is·a·rendering·of48 configuration·settings·for·Amazon·Elastic·Kubernetes·Service.·It·is·a·rendering·of
49 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)49 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 1545, 15 lines modifiedOffset 1545, 15 lines modified
1545 ··············<xccdf-1.2:check-content-ref·href="ssg-eks-ocil.xml"·name="ocil:ssg-file_permissions_worker_kubeconfig_ocil:questionnaire:1"/>1545 ··············<xccdf-1.2:check-content-ref·href="ssg-eks-ocil.xml"·name="ocil:ssg-file_permissions_worker_kubeconfig_ocil:questionnaire:1"/>
1546 ············</xccdf-1.2:check>1546 ············</xccdf-1.2:check>
1547 ··········</xccdf-1.2:Rule>1547 ··········</xccdf-1.2:Rule>
1548 ········</xccdf-1.2:Group>1548 ········</xccdf-1.2:Group>
1549 ······</xccdf-1.2:Group>1549 ······</xccdf-1.2:Group>
1550 ····</xccdf-1.2:Benchmark>1550 ····</xccdf-1.2:Benchmark>
1551 ··</ds:component>1551 ··</ds:component>
1552 ··<ds:component·id="scap_org.open-scap_comp_ssg-eks-oval.xml"·timestamp="2025-02-28T20:08:00">1552 ··<ds:component·id="scap_org.open-scap_comp_ssg-eks-oval.xml"·timestamp="2025-03-01T22:08:00">
1553 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">1553 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
1554 ······<oval-def:generator>1554 ······<oval-def:generator>
1555 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>1555 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
1556 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.2</oval:product_version>1556 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.2</oval:product_version>
1557 ········<oval:schema_version>5.11</oval:schema_version>1557 ········<oval:schema_version>5.11</oval:schema_version>
1558 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>1558 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
1559 ······</oval-def:generator>1559 ······</oval-def:generator>
Offset 2166, 442 lines modifiedOffset 2166, 442 lines modified
2166 ········<oval-def:external_variable·id="oval:ssg-var_streaming_connection_timeouts:var:1"·version="1"·datatype="string"·comment="variable"/>2166 ········<oval-def:external_variable·id="oval:ssg-var_streaming_connection_timeouts:var:1"·version="1"·datatype="string"·comment="variable"/>
2167 ········<oval-def:local_variable·id="oval:ssg-kubelet_read_only_port_secured_file_location:var:1"·version="1"·datatype="string"·comment="The·actual·path·of·the·file·to·scan.">2167 ········<oval-def:local_variable·id="oval:ssg-kubelet_read_only_port_secured_file_location:var:1"·version="1"·datatype="string"·comment="The·actual·path·of·the·file·to·scan.">
2168 ··········<oval-def:literal_component>/etc/kubernetes/compliance-operator/kubeletconfig/openscap-kubeletconfig</oval-def:literal_component>2168 ··········<oval-def:literal_component>/etc/kubernetes/compliance-operator/kubeletconfig/openscap-kubeletconfig</oval-def:literal_component>
2169 ········</oval-def:local_variable>2169 ········</oval-def:local_variable>
2170 ······</oval-def:variables>2170 ······</oval-def:variables>
2171 ····</oval-def:oval_definitions>2171 ····</oval-def:oval_definitions>
2172 ··</ds:component>2172 ··</ds:component>
2173 ··<ds:component·id="scap_org.open-scap_comp_ssg-eks-ocil.xml"·timestamp="2025-02-28T20:08:00">2173 ··<ds:component·id="scap_org.open-scap_comp_ssg-eks-ocil.xml"·timestamp="2025-03-01T22:08:00">
2174 ····<ocil:ocil>2174 ····<ocil:ocil>
2175 ······<ocil:generator>2175 ······<ocil:generator>
2176 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>2176 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
2177 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>2177 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
2178 ········<ocil:schema_version>2.0</ocil:schema_version>2178 ········<ocil:schema_version>2.0</ocil:schema_version>
2179 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>2179 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
2180 ······</ocil:generator>2180 ······</ocil:generator>
2181 ······<ocil:questionnaires>2181 ······<ocil:questionnaires>
2182 ········<ocil:questionnaire·id="ocil:ssg-kubelet_enable_streaming_connections_deprecated_ocil:questionnaire:1"> 
2183 ··········<ocil:title>kubelet·-·Do·Not·Disable·Streaming·Timeouts</ocil:title> 
2184 ··········<ocil:actions> 
2185 ············<ocil:test_action_ref>ocil:ssg-kubelet_enable_streaming_connections_deprecated_action:testaction:1</ocil:test_action_ref> 
2186 ··········</ocil:actions> 
2187 ········</ocil:questionnaire> 
2188 ········<ocil:questionnaire·id="ocil:ssg-kubelet_read_only_port_secured_ocil:questionnaire:1"> 
2189 ··········<ocil:title>kubelet·-·Ensure·that·the·--read-only-port·is·secured</ocil:title> 
2190 ··········<ocil:actions> 
2191 ············<ocil:test_action_ref>ocil:ssg-kubelet_read_only_port_secured_action:testaction:1</ocil:test_action_ref> 
2192 ··········</ocil:actions> 
2193 ········</ocil:questionnaire> 
2194 ········<ocil:questionnaire·id="ocil:ssg-kubelet_enable_iptables_util_chains_ocil:questionnaire:1">2182 ········<ocil:questionnaire·id="ocil:ssg-private_nodes_ocil:questionnaire:1">
2195 ··········<ocil:title>kubelet·-·Allow·Automatic·Firewall·Configuration</ocil:title>2183 ··········<ocil:title>Ensure·Cluster·Private·Nodes</ocil:title>
2196 ··········<ocil:actions>2184 ··········<ocil:actions>
2197 ············<ocil:test_action_ref>ocil:ssg-kubelet_enable_iptables_util_chains_action:testaction:1</ocil:test_action_ref>2185 ············<ocil:test_action_ref>ocil:ssg-private_nodes_action:testaction:1</ocil:test_action_ref>
2198 ··········</ocil:actions>2186 ··········</ocil:actions>
2199 ········</ocil:questionnaire>2187 ········</ocil:questionnaire>
2200 ········<ocil:questionnaire·id="ocil:ssg-iam_integration_ocil:questionnaire:1">2188 ········<ocil:questionnaire·id="ocil:ssg-iam_integration_ocil:questionnaire:1">
2201 ··········<ocil:title>Manage·Users·with·AWS·IAM</ocil:title>2189 ··········<ocil:title>Manage·Users·with·AWS·IAM</ocil:title>
2202 ··········<ocil:actions>2190 ··········<ocil:actions>
2203 ············<ocil:test_action_ref>ocil:ssg-iam_integration_action:testaction:1</ocil:test_action_ref>2191 ············<ocil:test_action_ref>ocil:ssg-iam_integration_action:testaction:1</ocil:test_action_ref>
2204 ··········</ocil:actions>2192 ··········</ocil:actions>
2205 ········</ocil:questionnaire>2193 ········</ocil:questionnaire>
2206 ········<ocil:questionnaire·id="ocil:ssg-kubelet_configure_client_ca_ocil:questionnaire:1"> 
2207 ··········<ocil:title>kubelet·-·Configure·the·Client·CA·Certificate</ocil:title> 
2208 ··········<ocil:actions> 
2209 ············<ocil:test_action_ref>ocil:ssg-kubelet_configure_client_ca_action:testaction:1</ocil:test_action_ref> 
2210 ··········</ocil:actions> 
2211 ········</ocil:questionnaire> 
2212 ········<ocil:questionnaire·id="ocil:ssg-secret_encryption_ocil:questionnaire:1">2194 ········<ocil:questionnaire·id="ocil:ssg-fargate_ocil:questionnaire:1">
2213 ··········<ocil:title>Ensure·Kubernetes·Secrets·are·Encrypted</ocil:title>2195 ··········<ocil:title>Consider·Fargate·for·Untrusted·Workloads</ocil:title>
2214 ··········<ocil:actions>2196 ··········<ocil:actions>
2215 ············<ocil:test_action_ref>ocil:ssg-secret_encryption_action:testaction:1</ocil:test_action_ref>2197 ············<ocil:test_action_ref>ocil:ssg-fargate_action:testaction:1</ocil:test_action_ref>
2216 ··········</ocil:actions>2198 ··········</ocil:actions>
2217 ········</ocil:questionnaire>2199 ········</ocil:questionnaire>
2218 ········<ocil:questionnaire·id="ocil:ssg-registry_access_ocil:questionnaire:1">2200 ········<ocil:questionnaire·id="ocil:ssg-kubelet_authorization_mode_ocil:questionnaire:1">
2219 ··········<ocil:title>Minimize·user·access·to·Amazon·ECR</ocil:title>2201 ··········<ocil:title>Ensure·authorization·is·set·to·Webhook</ocil:title>
2220 ··········<ocil:actions>2202 ··········<ocil:actions>
2221 ············<ocil:test_action_ref>ocil:ssg-registry_access_action:testaction:1</ocil:test_action_ref>2203 ············<ocil:test_action_ref>ocil:ssg-kubelet_authorization_mode_action:testaction:1</ocil:test_action_ref>
2222 ··········</ocil:actions>2204 ··········</ocil:actions>
2223 ········</ocil:questionnaire>2205 ········</ocil:questionnaire>
2224 ········<ocil:questionnaire·id="ocil:ssg-kubelet_enable_cert_rotation_ocil:questionnaire:1">2206 ········<ocil:questionnaire·id="ocil:ssg-configure_tls_ocil:questionnaire:1">
2225 ··········<ocil:title>kubelet·-·Enable·Certificate·Rotation</ocil:title>2207 ··········<ocil:title>Encrypt·Traffic·to·Load·Balancers·and·Workloads</ocil:title>
2226 ··········<ocil:actions>2208 ··········<ocil:actions>
2227 ············<ocil:test_action_ref>ocil:ssg-kubelet_enable_cert_rotation_action:testaction:1</ocil:test_action_ref>2209 ············<ocil:test_action_ref>ocil:ssg-configure_tls_action:testaction:1</ocil:test_action_ref>
2228 ··········</ocil:actions>2210 ··········</ocil:actions>
2229 ········</ocil:questionnaire>2211 ········</ocil:questionnaire>
2230 ········<ocil:questionnaire·id="ocil:ssg-file_owner_kubelet_conf_ocil:questionnaire:1">2212 ········<ocil:questionnaire·id="ocil:ssg-registry_access_ocil:questionnaire:1">
2231 ··········<ocil:title>Verify·User·Who·Owns·The·Kubelet·Configuration·File</ocil:title>2213 ··········<ocil:title>Minimize·user·access·to·Amazon·ECR</ocil:title>
2232 ··········<ocil:actions>2214 ··········<ocil:actions>
2233 ············<ocil:test_action_ref>ocil:ssg-file_owner_kubelet_conf_action:testaction:1</ocil:test_action_ref>2215 ············<ocil:test_action_ref>ocil:ssg-registry_access_action:testaction:1</ocil:test_action_ref>
2234 ··········</ocil:actions>2216 ··········</ocil:actions>
2235 ········</ocil:questionnaire>2217 ········</ocil:questionnaire>
2236 ········<ocil:questionnaire·id="ocil:ssg-endpoint_configuration_ocil:questionnaire:1">2218 ········<ocil:questionnaire·id="ocil:ssg-kubelet_enable_protect_kernel_defaults_ocil:questionnaire:1">
2237 ··········<ocil:title>Ensure·Private·Endpoint·Access</ocil:title>2219 ··········<ocil:title>kubelet·-·Enable·Protect·Kernel·Defaults</ocil:title>
2238 ··········<ocil:actions>2220 ··········<ocil:actions>
2239 ············<ocil:test_action_ref>ocil:ssg-endpoint_configuration_action:testaction:1</ocil:test_action_ref>2221 ············<ocil:test_action_ref>ocil:ssg-kubelet_enable_protect_kernel_defaults_action:testaction:1</ocil:test_action_ref>
2240 ··········</ocil:actions>2222 ··········</ocil:actions>
2241 ········</ocil:questionnaire>2223 ········</ocil:questionnaire>
2242 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_worker_kubeconfig_ocil:questionnaire:1"> 
2243 ··········<ocil:title>Verify·Permissions·on·the·Worker·Kubeconfig·File</ocil:title>2224 ········<ocil:questionnaire·id="ocil:ssg-configure_network_policies_namespaces_ocil:questionnaire:1">
 2225 ··········<ocil:title>Ensure·that·application·Namespaces·have·Network·Policies·defined.</ocil:title>
Max diff block lines reached; 77222/88108 bytes (87.64%) of diff not shown.
77.7 KB
./usr/share/xml/scap/ssg/content/ssg-eks-ocil.xml
77.6 KB
./usr/share/xml/scap/ssg/content/ssg-eks-ocil.xml
Ordering differences only
    
Offset 3, 433 lines modifiedOffset 3, 433 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-kubelet_enable_streaming_connections_deprecated_ocil:questionnaire:1"> 
11 ······<ocil:title>kubelet·-·Do·Not·Disable·Streaming·Timeouts</ocil:title> 
12 ······<ocil:actions> 
13 ········<ocil:test_action_ref>ocil:ssg-kubelet_enable_streaming_connections_deprecated_action:testaction:1</ocil:test_action_ref> 
14 ······</ocil:actions> 
15 ····</ocil:questionnaire> 
16 ····<ocil:questionnaire·id="ocil:ssg-kubelet_read_only_port_secured_ocil:questionnaire:1"> 
17 ······<ocil:title>kubelet·-·Ensure·that·the·--read-only-port·is·secured</ocil:title> 
18 ······<ocil:actions> 
19 ········<ocil:test_action_ref>ocil:ssg-kubelet_read_only_port_secured_action:testaction:1</ocil:test_action_ref> 
20 ······</ocil:actions> 
21 ····</ocil:questionnaire> 
22 ····<ocil:questionnaire·id="ocil:ssg-kubelet_enable_iptables_util_chains_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-private_nodes_ocil:questionnaire:1">
23 ······<ocil:title>kubelet·-·Allow·Automatic·Firewall·Configuration</ocil:title>11 ······<ocil:title>Ensure·Cluster·Private·Nodes</ocil:title>
24 ······<ocil:actions>12 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-kubelet_enable_iptables_util_chains_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-private_nodes_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>14 ······</ocil:actions>
27 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-iam_integration_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-iam_integration_ocil:questionnaire:1">
29 ······<ocil:title>Manage·Users·with·AWS·IAM</ocil:title>17 ······<ocil:title>Manage·Users·with·AWS·IAM</ocil:title>
30 ······<ocil:actions>18 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-iam_integration_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-iam_integration_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>20 ······</ocil:actions>
33 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-kubelet_configure_client_ca_ocil:questionnaire:1"> 
35 ······<ocil:title>kubelet·-·Configure·the·Client·CA·Certificate</ocil:title> 
36 ······<ocil:actions> 
37 ········<ocil:test_action_ref>ocil:ssg-kubelet_configure_client_ca_action:testaction:1</ocil:test_action_ref> 
38 ······</ocil:actions> 
39 ····</ocil:questionnaire> 
40 ····<ocil:questionnaire·id="ocil:ssg-secret_encryption_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-fargate_ocil:questionnaire:1">
41 ······<ocil:title>Ensure·Kubernetes·Secrets·are·Encrypted</ocil:title>23 ······<ocil:title>Consider·Fargate·for·Untrusted·Workloads</ocil:title>
42 ······<ocil:actions>24 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-secret_encryption_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-fargate_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>26 ······</ocil:actions>
45 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-registry_access_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-kubelet_authorization_mode_ocil:questionnaire:1">
47 ······<ocil:title>Minimize·user·access·to·Amazon·ECR</ocil:title>29 ······<ocil:title>Ensure·authorization·is·set·to·Webhook</ocil:title>
48 ······<ocil:actions>30 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-registry_access_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-kubelet_authorization_mode_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>32 ······</ocil:actions>
51 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-kubelet_enable_cert_rotation_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-configure_tls_ocil:questionnaire:1">
53 ······<ocil:title>kubelet·-·Enable·Certificate·Rotation</ocil:title>35 ······<ocil:title>Encrypt·Traffic·to·Load·Balancers·and·Workloads</ocil:title>
54 ······<ocil:actions>36 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-kubelet_enable_cert_rotation_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-configure_tls_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>38 ······</ocil:actions>
57 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-file_owner_kubelet_conf_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-registry_access_ocil:questionnaire:1">
59 ······<ocil:title>Verify·User·Who·Owns·The·Kubelet·Configuration·File</ocil:title>41 ······<ocil:title>Minimize·user·access·to·Amazon·ECR</ocil:title>
60 ······<ocil:actions>42 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-file_owner_kubelet_conf_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-registry_access_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>44 ······</ocil:actions>
63 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-endpoint_configuration_ocil:questionnaire:1">46 ····<ocil:questionnaire·id="ocil:ssg-kubelet_enable_protect_kernel_defaults_ocil:questionnaire:1">
65 ······<ocil:title>Ensure·Private·Endpoint·Access</ocil:title>47 ······<ocil:title>kubelet·-·Enable·Protect·Kernel·Defaults</ocil:title>
66 ······<ocil:actions>48 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-endpoint_configuration_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-kubelet_enable_protect_kernel_defaults_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>50 ······</ocil:actions>
69 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_worker_kubeconfig_ocil:questionnaire:1"> 
71 ······<ocil:title>Verify·Permissions·on·the·Worker·Kubeconfig·File</ocil:title>52 ····<ocil:questionnaire·id="ocil:ssg-configure_network_policies_namespaces_ocil:questionnaire:1">
 53 ······<ocil:title>Ensure·that·application·Namespaces·have·Network·Policies·defined.</ocil:title>
72 ······<ocil:actions>54 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-file_permissions_worker_kubeconfig_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-configure_network_policies_namespaces_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>56 ······</ocil:actions>
75 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-dedicated_service_accounts_ocil:questionnaire:1"> 
77 ······<ocil:title>Use·Dedicated·Service·Accounts</ocil:title>58 ····<ocil:questionnaire·id="ocil:ssg-kubelet_configure_client_ca_ocil:questionnaire:1">
 59 ······<ocil:title>kubelet·-·Configure·the·Client·CA·Certificate</ocil:title>
78 ······<ocil:actions>60 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-dedicated_service_accounts_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-kubelet_configure_client_ca_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>62 ······</ocil:actions>
81 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-fargate_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-file_owner_worker_kubeconfig_ocil:questionnaire:1">
83 ······<ocil:title>Consider·Fargate·for·Untrusted·Workloads</ocil:title>65 ······<ocil:title>Verify·User·Who·Owns·The·Worker·Kubeconfig·File</ocil:title>
84 ······<ocil:actions>66 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-fargate_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-file_owner_worker_kubeconfig_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>68 ······</ocil:actions>
87 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_kubelet_conf_ocil:questionnaire:1"> 
89 ······<ocil:title>Verify·Permissions·on·The·Kubelet·Configuration·File</ocil:title>70 ····<ocil:questionnaire·id="ocil:ssg-kubelet_enable_streaming_connections_deprecated_ocil:questionnaire:1">
 71 ······<ocil:title>kubelet·-·Do·Not·Disable·Streaming·Timeouts</ocil:title>
90 ······<ocil:actions>72 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-file_permissions_kubelet_conf_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-kubelet_enable_streaming_connections_deprecated_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>74 ······</ocil:actions>
93 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-approved_registries_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-kubelet_enable_iptables_util_chains_ocil:questionnaire:1">
95 ······<ocil:title>Only·use·approved·container·registries</ocil:title>77 ······<ocil:title>kubelet·-·Allow·Automatic·Firewall·Configuration</ocil:title>
96 ······<ocil:actions>78 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-approved_registries_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-kubelet_enable_iptables_util_chains_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>80 ······</ocil:actions>
99 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-audit_logging_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-configure_network_policy_ocil:questionnaire:1">
101 ······<ocil:title>Ensure·Audit·Logging·is·Enabled</ocil:title>83 ······<ocil:title>Ensure·Network·Policy·is·Enabled</ocil:title>
102 ······<ocil:actions>84 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-audit_logging_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-configure_network_policy_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>86 ······</ocil:actions>
105 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-file_owner_worker_kubeconfig_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_worker_kubeconfig_ocil:questionnaire:1">
107 ······<ocil:title>Verify·User·Who·Owns·The·Worker·Kubeconfig·File</ocil:title>89 ······<ocil:title>Verify·Group·Who·Owns·The·Worker·Kubeconfig·File</ocil:title>
108 ······<ocil:actions>90 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-file_owner_worker_kubeconfig_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_worker_kubeconfig_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>92 ······</ocil:actions>
111 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-private_nodes_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_kubelet_conf_ocil:questionnaire:1">
113 ······<ocil:title>Ensure·Cluster·Private·Nodes</ocil:title>95 ······<ocil:title>Verify·Group·Who·Owns·The·Kubelet·Configuration·File</ocil:title>
114 ······<ocil:actions>96 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-private_nodes_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_kubelet_conf_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>98 ······</ocil:actions>
117 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-kubelet_enable_protect_kernel_defaults_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-secret_encryption_ocil:questionnaire:1">
119 ······<ocil:title>kubelet·-·Enable·Protect·Kernel·Defaults</ocil:title>101 ······<ocil:title>Ensure·Kubernetes·Secrets·are·Encrypted</ocil:title>
120 ······<ocil:actions>102 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-kubelet_enable_protect_kernel_defaults_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-secret_encryption_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>104 ······</ocil:actions>
123 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
124 ····<ocil:questionnaire·id="ocil:ssg-configure_network_policy_ocil:questionnaire:1">106 ····<ocil:questionnaire·id="ocil:ssg-file_owner_kubelet_conf_ocil:questionnaire:1">
125 ······<ocil:title>Ensure·Network·Policy·is·Enabled</ocil:title>107 ······<ocil:title>Verify·User·Who·Owns·The·Kubelet·Configuration·File</ocil:title>
126 ······<ocil:actions>108 ······<ocil:actions>
Max diff block lines reached; 67819/79312 bytes (85.51%) of diff not shown.
53.2 KB
./usr/share/xml/scap/ssg/content/ssg-firefox-ds.xml
53.1 KB
./usr/share/xml/scap/ssg/content/ssg-firefox-ds.xml
    
Offset 19, 23 lines modifiedOffset 19, 23 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-firefox-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-firefox-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-firefox-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-firefox-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-firefox-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-firefox-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-firefox-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-firefox-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-firefox-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-firefox-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-firefox-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-firefox-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-firefox-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-firefox-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/a:mozilla:firefox">28 ······<cpe-dict:cpe-item·name="cpe:/a:mozilla:firefox">
29 ········<cpe-dict:title·xml:lang="en-us">Mozilla·Firefox</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Mozilla·Firefox</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-firefox-cpe-oval.xml">oval:ssg-installed_app_is_firefox:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-firefox-cpe-oval.xml">oval:ssg-installed_app_is_firefox:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ····</cpe-dict:cpe-list>32 ····</cpe-dict:cpe-list>
33 ··</ds:component>33 ··</ds:component>
34 ··<ds:component·id="scap_org.open-scap_comp_ssg-firefox-xccdf.xml"·timestamp="2025-02-28T20:08:00">34 ··<ds:component·id="scap_org.open-scap_comp_ssg-firefox-xccdf.xml"·timestamp="2025-03-01T22:08:00">
35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_FIREFOX"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_FIREFOX"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Firefox</xccdf-1.2:title>37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Firefox</xccdf-1.2:title>
38 ······<xccdf-1.2:description>38 ······<xccdf-1.2:description>
39 ········This·guide·presents·a·catalog·of·security-relevant39 ········This·guide·presents·a·catalog·of·security-relevant
40 configuration·settings·for·Firefox.·It·is·a·rendering·of40 configuration·settings·for·Firefox.·It·is·a·rendering·of
41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 3488, 15 lines modifiedOffset 3488, 15 lines modified
3488 ··············<xccdf-1.2:check-content-ref·href="ssg-firefox-ocil.xml"·name="ocil:ssg-firefox_preferences-enable_ca_trust_ocil:questionnaire:1"/>3488 ··············<xccdf-1.2:check-content-ref·href="ssg-firefox-ocil.xml"·name="ocil:ssg-firefox_preferences-enable_ca_trust_ocil:questionnaire:1"/>
3489 ············</xccdf-1.2:check>3489 ············</xccdf-1.2:check>
3490 ··········</xccdf-1.2:Rule>3490 ··········</xccdf-1.2:Rule>
3491 ········</xccdf-1.2:Group>3491 ········</xccdf-1.2:Group>
3492 ······</xccdf-1.2:Group>3492 ······</xccdf-1.2:Group>
3493 ····</xccdf-1.2:Benchmark>3493 ····</xccdf-1.2:Benchmark>
3494 ··</ds:component>3494 ··</ds:component>
3495 ··<ds:component·id="scap_org.open-scap_comp_ssg-firefox-oval.xml"·timestamp="2025-02-28T20:08:00">3495 ··<ds:component·id="scap_org.open-scap_comp_ssg-firefox-oval.xml"·timestamp="2025-03-01T22:08:00">
3496 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">3496 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
3497 ······<oval-def:generator>3497 ······<oval-def:generator>
3498 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>3498 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
3499 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.2</oval:product_version>3499 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.2</oval:product_version>
3500 ········<oval:schema_version>5.11</oval:schema_version>3500 ········<oval:schema_version>5.11</oval:schema_version>
3501 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>3501 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
3502 ······</oval-def:generator>3502 ······</oval-def:generator>
Offset 5198, 240 lines modifiedOffset 5198, 240 lines modified
5198 ··············<oval-def:literal_component>/distribution</oval-def:literal_component>5198 ··············<oval-def:literal_component>/distribution</oval-def:literal_component>
5199 ············</oval-def:concat>5199 ············</oval-def:concat>
5200 ··········</oval-def:unique>5200 ··········</oval-def:unique>
5201 ········</oval-def:local_variable>5201 ········</oval-def:local_variable>
5202 ······</oval-def:variables>5202 ······</oval-def:variables>
5203 ····</oval-def:oval_definitions>5203 ····</oval-def:oval_definitions>
5204 ··</ds:component>5204 ··</ds:component>
5205 ··<ds:component·id="scap_org.open-scap_comp_ssg-firefox-ocil.xml"·timestamp="2025-02-28T20:08:00">5205 ··<ds:component·id="scap_org.open-scap_comp_ssg-firefox-ocil.xml"·timestamp="2025-03-01T22:08:00">
5206 ····<ocil:ocil>5206 ····<ocil:ocil>
5207 ······<ocil:generator>5207 ······<ocil:generator>
5208 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>5208 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5209 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>5209 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
5210 ········<ocil:schema_version>2.0</ocil:schema_version>5210 ········<ocil:schema_version>2.0</ocil:schema_version>
5211 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>5211 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
5212 ······</ocil:generator>5212 ······</ocil:generator>
5213 ······<ocil:questionnaires>5213 ······<ocil:questionnaires>
5214 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-extension_update_ocil:questionnaire:1">5214 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-extension_update_ocil:questionnaire:1">
5215 ··········<ocil:title>Firefox·must·be·configured·to·not·automatically·update·installed·add-ons·and·plugins.</ocil:title>5215 ··········<ocil:title>Firefox·must·be·configured·to·not·automatically·update·installed·add-ons·and·plugins.</ocil:title>
5216 ··········<ocil:actions>5216 ··········<ocil:actions>
5217 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-extension_update_action:testaction:1</ocil:test_action_ref>5217 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-extension_update_action:testaction:1</ocil:test_action_ref>
5218 ··········</ocil:actions>5218 ··········</ocil:actions>
5219 ········</ocil:questionnaire>5219 ········</ocil:questionnaire>
5220 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-forget_button_ocil:questionnaire:1">5220 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-pop-up_windows_ocil:questionnaire:1">
5221 ··········<ocil:title>Firefox·must·prevent·the·user·from·quickly·deleting·data.</ocil:title>5221 ··········<ocil:title>Enable·Firefox·Pop-up·Blocker</ocil:title>
5222 ··········<ocil:actions>5222 ··········<ocil:actions>
5223 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-forget_button_action:testaction:1</ocil:test_action_ref>5223 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-pop-up_windows_action:testaction:1</ocil:test_action_ref>
5224 ··········</ocil:actions>5224 ··········</ocil:actions>
5225 ········</ocil:questionnaire>5225 ········</ocil:questionnaire>
5226 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-autoplay_video_ocil:questionnaire:1">5226 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-fingerprinting_protection_ocil:questionnaire:1">
5227 ··········<ocil:title>Firefox·autoplay·must·be·disabled.</ocil:title>5227 ··········<ocil:title>Enabled·Firefox·Fingerprinting·Protection</ocil:title>
5228 ··········<ocil:actions>5228 ··········<ocil:actions>
5229 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-autoplay_video_action:testaction:1</ocil:test_action_ref>5229 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-fingerprinting_protection_action:testaction:1</ocil:test_action_ref>
5230 ··········</ocil:actions>5230 ··········</ocil:actions>
5231 ········</ocil:questionnaire>5231 ········</ocil:questionnaire>
5232 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-search_suggestion_ocil:questionnaire:1">5232 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-telemetry_ocil:questionnaire:1">
5233 ··········<ocil:title>Firefox·search·suggestions·must·be·disabled.</ocil:title>5233 ··········<ocil:title>Disable·Firefox·Telemetry</ocil:title>
5234 ··········<ocil:actions>5234 ··········<ocil:actions>
5235 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-search_suggestion_action:testaction:1</ocil:test_action_ref>5235 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-telemetry_action:testaction:1</ocil:test_action_ref>
5236 ··········</ocil:actions>5236 ··········</ocil:actions>
5237 ········</ocil:questionnaire>5237 ········</ocil:questionnaire>
5238 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-javascript_window_resizing_ocil:questionnaire:1">5238 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-network_prediction_ocil:questionnaire:1">
5239 ··········<ocil:title>Disable·JavaScript's·Moving·Or·Resizing·Windows·Capability</ocil:title>5239 ··········<ocil:title>Disable·Firefox·network·prediction</ocil:title>
5240 ··········<ocil:actions>5240 ··········<ocil:actions>
5241 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-javascript_window_resizing_action:testaction:1</ocil:test_action_ref>5241 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-network_prediction_action:testaction:1</ocil:test_action_ref>
5242 ··········</ocil:actions>5242 ··········</ocil:actions>
5243 ········</ocil:questionnaire>5243 ········</ocil:questionnaire>
5244 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-javascript_window_changes_ocil:questionnaire:1">5244 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-javascript_window_resizing_ocil:questionnaire:1">
5245 ··········<ocil:title>Disable·JavaScript's·Raise·Or·Lower·Windows·Capability</ocil:title>5245 ··········<ocil:title>Disable·JavaScript's·Moving·Or·Resizing·Windows·Capability</ocil:title>
5246 ··········<ocil:actions>5246 ··········<ocil:actions>
5247 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-javascript_window_changes_action:testaction:1</ocil:test_action_ref>5247 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-javascript_window_resizing_action:testaction:1</ocil:test_action_ref>
5248 ··········</ocil:actions>5248 ··········</ocil:actions>
5249 ········</ocil:questionnaire>5249 ········</ocil:questionnaire>
5250 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-telemetry_ocil:questionnaire:1">5250 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-autoplay_video_ocil:questionnaire:1">
5251 ··········<ocil:title>Disable·Firefox·Telemetry</ocil:title>5251 ··········<ocil:title>Firefox·autoplay·must·be·disabled.</ocil:title>
5252 ··········<ocil:actions>5252 ··········<ocil:actions>
5253 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-telemetry_action:testaction:1</ocil:test_action_ref>5253 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-autoplay_video_action:testaction:1</ocil:test_action_ref>
5254 ··········</ocil:actions>5254 ··········</ocil:actions>
5255 ········</ocil:questionnaire>5255 ········</ocil:questionnaire>
5256 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-cryptomining_ocil:questionnaire:1">5256 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-forget_button_ocil:questionnaire:1">
5257 ··········<ocil:title>Enabled·Firefox·Cryptomining·protection</ocil:title>5257 ··········<ocil:title>Firefox·must·prevent·the·user·from·quickly·deleting·data.</ocil:title>
5258 ··········<ocil:actions>5258 ··········<ocil:actions>
5259 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-cryptomining_action:testaction:1</ocil:test_action_ref>5259 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-forget_button_action:testaction:1</ocil:test_action_ref>
5260 ··········</ocil:actions>5260 ··········</ocil:actions>
5261 ········</ocil:questionnaire>5261 ········</ocil:questionnaire>
5262 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-fingerprinting_protection_ocil:questionnaire:1">5262 ········<ocil:questionnaire·id="ocil:ssg-installed_firefox_version_supported_ocil:questionnaire:1">
5263 ··········<ocil:title>Enabled·Firefox·Fingerprinting·Protection</ocil:title>5263 ··········<ocil:title>Supported·Version·of·Firefox·Installed</ocil:title>
5264 ··········<ocil:actions>5264 ··········<ocil:actions>
5265 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-fingerprinting_protection_action:testaction:1</ocil:test_action_ref>5265 ············<ocil:test_action_ref>ocil:ssg-installed_firefox_version_supported_action:testaction:1</ocil:test_action_ref>
5266 ··········</ocil:actions>5266 ··········</ocil:actions>
5267 ········</ocil:questionnaire>5267 ········</ocil:questionnaire>
5268 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-disable_pocket_ocil:questionnaire:1">5268 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-disable_pocket_ocil:questionnaire:1">
5269 ··········<ocil:title>Disable·Firefox·Pocket</ocil:title>5269 ··········<ocil:title>Disable·Firefox·Pocket</ocil:title>
5270 ··········<ocil:actions>5270 ··········<ocil:actions>
5271 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-disable_pocket_action:testaction:1</ocil:test_action_ref>5271 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-disable_pocket_action:testaction:1</ocil:test_action_ref>
5272 ··········</ocil:actions>5272 ··········</ocil:actions>
5273 ········</ocil:questionnaire>5273 ········</ocil:questionnaire>
5274 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-content_blocker_ocil:questionnaire:1">5274 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-private_browsing_ocil:questionnaire:1">
5275 ··········<ocil:title>Ensure·the·Content·Blocker·uBlock·Origin·is·Installed</ocil:title>5275 ··········<ocil:title>Firefox·private·browsing·must·be·disabled.</ocil:title>
5276 ··········<ocil:actions>5276 ··········<ocil:actions>
5277 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-content_blocker_action:testaction:1</ocil:test_action_ref>5277 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-private_browsing_action:testaction:1</ocil:test_action_ref>
5278 ··········</ocil:actions>5278 ··········</ocil:actions>
5279 ········</ocil:questionnaire>5279 ········</ocil:questionnaire>
5280 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-disable_studies_ocil:questionnaire:1">5280 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-disable_studies_ocil:questionnaire:1">
5281 ··········<ocil:title>Disable·Firefox·Studies</ocil:title>5281 ··········<ocil:title>Disable·Firefox·Studies</ocil:title>
5282 ··········<ocil:actions>5282 ··········<ocil:actions>
5283 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-disable_studies_action:testaction:1</ocil:test_action_ref>5283 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-disable_studies_action:testaction:1</ocil:test_action_ref>
5284 ··········</ocil:actions>5284 ··········</ocil:actions>
Max diff block lines reached; 42713/54228 bytes (78.77%) of diff not shown.
45.9 KB
./usr/share/xml/scap/ssg/content/ssg-firefox-ocil.xml
45.8 KB
./usr/share/xml/scap/ssg/content/ssg-firefox-ocil.xml
Ordering differences only
    
Offset 9, 225 lines modifiedOffset 9, 225 lines modified
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-extension_update_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-extension_update_ocil:questionnaire:1">
11 ······<ocil:title>Firefox·must·be·configured·to·not·automatically·update·installed·add-ons·and·plugins.</ocil:title>11 ······<ocil:title>Firefox·must·be·configured·to·not·automatically·update·installed·add-ons·and·plugins.</ocil:title>
12 ······<ocil:actions>12 ······<ocil:actions>
13 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-extension_update_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-extension_update_action:testaction:1</ocil:test_action_ref>
14 ······</ocil:actions>14 ······</ocil:actions>
15 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
16 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-forget_button_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-pop-up_windows_ocil:questionnaire:1">
17 ······<ocil:title>Firefox·must·prevent·the·user·from·quickly·deleting·data.</ocil:title>17 ······<ocil:title>Enable·Firefox·Pop-up·Blocker</ocil:title>
18 ······<ocil:actions>18 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-forget_button_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-pop-up_windows_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>20 ······</ocil:actions>
21 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-autoplay_video_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-fingerprinting_protection_ocil:questionnaire:1">
23 ······<ocil:title>Firefox·autoplay·must·be·disabled.</ocil:title>23 ······<ocil:title>Enabled·Firefox·Fingerprinting·Protection</ocil:title>
24 ······<ocil:actions>24 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-autoplay_video_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-fingerprinting_protection_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>26 ······</ocil:actions>
27 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-search_suggestion_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-telemetry_ocil:questionnaire:1">
29 ······<ocil:title>Firefox·search·suggestions·must·be·disabled.</ocil:title>29 ······<ocil:title>Disable·Firefox·Telemetry</ocil:title>
30 ······<ocil:actions>30 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-search_suggestion_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-telemetry_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>32 ······</ocil:actions>
33 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-javascript_window_resizing_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-network_prediction_ocil:questionnaire:1">
35 ······<ocil:title>Disable·JavaScript's·Moving·Or·Resizing·Windows·Capability</ocil:title>35 ······<ocil:title>Disable·Firefox·network·prediction</ocil:title>
36 ······<ocil:actions>36 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-javascript_window_resizing_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-network_prediction_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>38 ······</ocil:actions>
39 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-javascript_window_changes_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-javascript_window_resizing_ocil:questionnaire:1">
41 ······<ocil:title>Disable·JavaScript's·Raise·Or·Lower·Windows·Capability</ocil:title>41 ······<ocil:title>Disable·JavaScript's·Moving·Or·Resizing·Windows·Capability</ocil:title>
42 ······<ocil:actions>42 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-javascript_window_changes_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-javascript_window_resizing_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>44 ······</ocil:actions>
45 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-telemetry_ocil:questionnaire:1">46 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-autoplay_video_ocil:questionnaire:1">
47 ······<ocil:title>Disable·Firefox·Telemetry</ocil:title>47 ······<ocil:title>Firefox·autoplay·must·be·disabled.</ocil:title>
48 ······<ocil:actions>48 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-telemetry_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-autoplay_video_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>50 ······</ocil:actions>
51 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-cryptomining_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-forget_button_ocil:questionnaire:1">
53 ······<ocil:title>Enabled·Firefox·Cryptomining·protection</ocil:title>53 ······<ocil:title>Firefox·must·prevent·the·user·from·quickly·deleting·data.</ocil:title>
54 ······<ocil:actions>54 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-cryptomining_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-forget_button_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>56 ······</ocil:actions>
57 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-fingerprinting_protection_ocil:questionnaire:1"> 
59 ······<ocil:title>Enabled·Firefox·Fingerprinting·Protection</ocil:title>58 ····<ocil:questionnaire·id="ocil:ssg-installed_firefox_version_supported_ocil:questionnaire:1">
 59 ······<ocil:title>Supported·Version·of·Firefox·Installed</ocil:title>
60 ······<ocil:actions>60 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-fingerprinting_protection_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-installed_firefox_version_supported_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>62 ······</ocil:actions>
63 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-disable_pocket_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-disable_pocket_ocil:questionnaire:1">
65 ······<ocil:title>Disable·Firefox·Pocket</ocil:title>65 ······<ocil:title>Disable·Firefox·Pocket</ocil:title>
66 ······<ocil:actions>66 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-disable_pocket_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-disable_pocket_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>68 ······</ocil:actions>
69 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-content_blocker_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-private_browsing_ocil:questionnaire:1">
71 ······<ocil:title>Ensure·the·Content·Blocker·uBlock·Origin·is·Installed</ocil:title>71 ······<ocil:title>Firefox·private·browsing·must·be·disabled.</ocil:title>
72 ······<ocil:actions>72 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-content_blocker_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-private_browsing_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>74 ······</ocil:actions>
75 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-disable_studies_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-disable_studies_ocil:questionnaire:1">
77 ······<ocil:title>Disable·Firefox·Studies</ocil:title>77 ······<ocil:title>Disable·Firefox·Studies</ocil:title>
78 ······<ocil:actions>78 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-disable_studies_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-disable_studies_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>80 ······</ocil:actions>
81 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-enhanced_tracking_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-cryptomining_ocil:questionnaire:1">
83 ······<ocil:title>Enabled·Firefox·Enhanced·Tracking·Protection</ocil:title>83 ······<ocil:title>Enabled·Firefox·Cryptomining·protection</ocil:title>
84 ······<ocil:actions>84 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-enhanced_tracking_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-cryptomining_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>86 ······</ocil:actions>
87 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-private_browsing_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-javascript_window_changes_ocil:questionnaire:1">
89 ······<ocil:title>Firefox·private·browsing·must·be·disabled.</ocil:title>89 ······<ocil:title>Disable·JavaScript's·Raise·Or·Lower·Windows·Capability</ocil:title>
90 ······<ocil:actions>90 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-private_browsing_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-javascript_window_changes_action:testaction:1</ocil:test_action_ref>
 92 ······</ocil:actions>
 93 ····</ocil:questionnaire>
 94 ····<ocil:questionnaire·id="ocil:ssg-firefox_preferences-auto-download_actions_ocil:questionnaire:1">
 95 ······<ocil:title>Disable·auto-download·for·proscribed·MIME·types.</ocil:title>
 96 ······<ocil:actions>
 97 ········<ocil:test_action_ref>ocil:ssg-firefox_preferences-auto-download_actions_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>98 ······</ocil:actions>
93 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-extension_recommendation_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-extension_recommendation_ocil:questionnaire:1">
95 ······<ocil:title>Disabled·Firefox·Extension·Recommendations</ocil:title>101 ······<ocil:title>Disabled·Firefox·Extension·Recommendations</ocil:title>
96 ······<ocil:actions>102 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-extension_recommendation_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-extension_recommendation_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>104 ······</ocil:actions>
99 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-installed_firefox_version_supported_ocil:questionnaire:1">106 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-search_suggestion_ocil:questionnaire:1">
101 ······<ocil:title>Supported·Version·of·Firefox·Installed</ocil:title>107 ······<ocil:title>Firefox·search·suggestions·must·be·disabled.</ocil:title>
102 ······<ocil:actions>108 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-installed_firefox_version_supported_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-search_suggestion_action:testaction:1</ocil:test_action_ref>
 110 ······</ocil:actions>
 111 ····</ocil:questionnaire>
 112 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-content_blocker_ocil:questionnaire:1">
 113 ······<ocil:title>Ensure·the·Content·Blocker·uBlock·Origin·is·Installed</ocil:title>
 114 ······<ocil:actions>
 115 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-content_blocker_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>116 ······</ocil:actions>
105 ····</ocil:questionnaire>117 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-firefox_preferences-enable_ca_trust_ocil:questionnaire:1">118 ····<ocil:questionnaire·id="ocil:ssg-firefox_preferences-enable_ca_trust_ocil:questionnaire:1">
107 ······<ocil:title>Enable·Shared·System·Certificates</ocil:title>119 ······<ocil:title>Enable·Shared·System·Certificates</ocil:title>
108 ······<ocil:actions>120 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-firefox_preferences-enable_ca_trust_action:testaction:1</ocil:test_action_ref>121 ········<ocil:test_action_ref>ocil:ssg-firefox_preferences-enable_ca_trust_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>122 ······</ocil:actions>
111 ····</ocil:questionnaire>123 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-network_prediction_ocil:questionnaire:1">124 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-disable_deprecated_ciphers_ocil:questionnaire:1">
113 ······<ocil:title>Disable·Firefox·network·prediction</ocil:title>125 ······<ocil:title>Disable·Firefox·deprecated·ciphers</ocil:title>
114 ······<ocil:actions>126 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-network_prediction_action:testaction:1</ocil:test_action_ref>127 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-disable_deprecated_ciphers_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>128 ······</ocil:actions>
117 ····</ocil:questionnaire>129 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-pop-up_windows_ocil:questionnaire:1">130 ····<ocil:questionnaire·id="ocil:ssg-firefox_preferences-dod_root_certificate_installed_ocil:questionnaire:1">
119 ······<ocil:title>Enable·Firefox·Pop-up·Blocker</ocil:title>131 ······<ocil:title>The·DoD·Root·Certificate·Exists</ocil:title>
120 ······<ocil:actions>132 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-pop-up_windows_action:testaction:1</ocil:test_action_ref>133 ········<ocil:test_action_ref>ocil:ssg-firefox_preferences-dod_root_certificate_installed_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>134 ······</ocil:actions>
Max diff block lines reached; 35146/46758 bytes (75.17%) of diff not shown.
12.0 MB
ssg-debderived_0.1.76-1_all.deb
452 B
file list
    
Offset 1, 3 lines modifiedOffset 1, 3 lines modified
1 -rw-r--r--···0········0········0········4·2025-03-01·08:08:00.000000·debian-binary1 -rw-r--r--···0········0········0········4·2025-03-01·08:08:00.000000·debian-binary
2 -rw-r--r--···0········0········0·····3036·2025-03-01·08:08:00.000000·control.tar.xz2 -rw-r--r--···0········0········0·····3040·2025-03-01·08:08:00.000000·control.tar.xz
3 -rw-r--r--···0········0········0··3722356·2025-03-01·08:08:00.000000·data.tar.xz3 -rw-r--r--···0········0········0··3722236·2025-03-01·08:08:00.000000·data.tar.xz
98.0 B
control.tar.xz
70.0 B
control.tar
48.0 B
./md5sums
30.0 B
./md5sums
Files differ
12.0 MB
data.tar.xz
12.0 MB
data.tar
54.7 KB
./usr/share/doc/ssg-debderived/ssg-ubuntu2004-guide-cis_level1_server.html
    
Offset 68198, 94 lines modifiedOffset 68198, 94 lines modified
0010a650:·2d74·6172·6765·743d·2223·6964·6d31·3539··-target="#idm1590010a650:·2d74·6172·6765·743d·2223·6964·6d31·3539··-target="#idm159
0010a660:·3832·2220·7461·6269·6e64·6578·3d22·3022··82"·tabindex="0"0010a660:·3832·2220·7461·6269·6e64·6578·3d22·3022··82"·tabindex="0"
0010a670:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a0010a670:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
0010a680:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa0010a680:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
0010a690:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti0010a690:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
0010a6a0:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·0010a6a0:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
0010a6b0:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi0010a6b0:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
0010a6c0:·6174·696f·6e20·4b75·6265·726e·6574·6573··ation·Kubernetes 
0010a6d0:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a> 
0010a6e0:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class=" 
0010a6f0:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c 
0010a700:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm 
0010a710:·3135·3938·3222·3e3c·7461·626c·6520·636c··15982"><table·cl 
0010a720:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table 
0010a730:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b 
0010a740:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co 
0010a750:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th 
0010a760:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th 
0010a770:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t 
0010a780:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup 
0010a790:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6d65··tion:</th><td>me 
0010a7a0:·6469·756d·3c2f·7464·3e3c·2f74·723e·3c74··dium</td></tr><t 
0010a7b0:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t 
0010a7c0:·683e·3c74·643e·7472·7565·3c2f·7464·3e3c··h><td>true</td>< 
0010a7d0:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra 
0010a7e0:·7465·6779·3a3c·2f74·683e·3c74·643e·6469··tegy:</th><td>di 
0010a7f0:·7361·626c·653c·2f74·643e·3c2f·7472·3e3c··sable</td></tr>< 
0010a800:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod 
0010a810:·653e·6170·6956·6572·7369·6f6e·3a20·6d61··e>apiVersion:·ma 
0010a820:·6368·696e·6563·6f6e·6669·6775·7261·7469··chineconfigurati 
0010a830:·6f6e·2e6f·7065·6e73·6869·6674·2e69·6f2f··on.openshift.io/ 
0010a840:·7631·0a6b·696e·643a·204d·6163·6869·6e65··v1.kind:·Machine 
0010a850:·436f·6e66·6967·0a73·7065·633a·0a20·2063··Config.spec:.··c 
0010a860:·6f6e·6669·673a·0a20·2020·2069·676e·6974··onfig:.····ignit 
0010a870:·696f·6e3a·0a20·2020·2020·2076·6572·7369··ion:.······versi 
0010a880:·6f6e·3a20·332e·312e·300a·2020·2020·7379··on:·3.1.0.····sy 
0010a890:·7374·656d·643a·0a20·2020·2020·2075·6e69··stemd:.······uni 
0010a8a0:·7473·3a0a·2020·2020·2020·2d20·6e61·6d65··ts:.······-·name 
0010a8b0:·3a20·6e66·7461·626c·6573·2e73·6572·7669··:·nftables.servi 
0010a8c0:·6365·0a20·2020·2020·2020·2065·6e61·626c··ce.········enabl 
0010a8d0:·6564·3a20·6661·6c73·650a·2020·2020·2020··ed:·false.······ 
0010a8e0:·2020·6d61·736b·3a20·7472·7565·0a20·2020····mask:·true.··· 
0010a8f0:·2020·202d·206e·616d·653a·206e·6674·6162·····-·name:·nftab 
0010a900:·6c65·732e·736f·636b·6574·0a20·2020·2020··les.socket.····· 
0010a910:·2020·2065·6e61·626c·6564·3a20·6661·6c73·····enabled:·fals 
0010a920:·650a·2020·2020·2020·2020·6d61·736b·3a20··e.········mask:· 
0010a930:·7472·7565·0a3c·2f63·6f64·653e·3c2f·7072··true.</code></pr 
0010a940:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class 
0010a950:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes 
0010a960:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle=" 
0010a970:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t 
0010a980:·6172·6765·743d·2223·6964·6d31·3539·3833··arget="#idm15983 
0010a990:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r 
0010a9a0:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari 
0010a9b0:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals 
0010a9c0:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa 
0010a9d0:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr 
0010a9e0:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat 
0010a9f0:·696f·6e20·5075·7070·6574·2073·6e69·7070··ion·Puppet·snipp0010a6c0:·6174·696f·6e20·5075·7070·6574·2073·6e69··ation·Puppet·sni
0010aa00:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d0010a6d0:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>
0010aa10:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-0010a6e0:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
0010aa20:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps0010a6f0:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
0010aa30:·6522·2069·643d·2269·646d·3135·3938·3322··e"·id="idm15983"0010a700:·7073·6522·2069·643d·2269·646d·3135·3938··pse"·id="idm1598
0010aa40:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t0010a710:·3222·3e3c·7461·626c·6520·636c·6173·733d··2"><table·class=
0010aa50:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip0010a720:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str
0010aa60:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere0010a730:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde
0010aa70:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense0010a740:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden
0010aa80:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl0010a750:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com
0010aa90:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l0010a760:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td
0010aaa0:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>0010a770:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
0010aab0:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:<0010a780:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption
0010aac0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>0010a790:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
0010aad0:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb0010a7a0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e52··d></tr><tr><th>R
0010aae0:·6f6f·743a·3c2f·7468·3e3c·7464·3e66·616c··oot:</th><td>fal0010a7b0:·6562·6f6f·743a·3c2f·7468·3e3c·7464·3e66··eboot:</th><td>f
 0010a7c0:·616c·7365·3c2f·7464·3e3c·2f74·723e·3c74··alse</td></tr><t
 0010a7d0:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<
 0010a7e0:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</
 0010a7f0:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table>
 0010a800:·3c70·7265·3e3c·636f·6465·3e69·6e63·6c75··<pre><code>inclu
 0010a810:·6465·2064·6973·6162·6c65·5f6e·6674·6162··de·disable_nftab
 0010a820:·6c65·730a·0a63·6c61·7373·2064·6973·6162··les..class·disab
 0010a830:·6c65·5f6e·6674·6162·6c65·7320·7b0a·2020··le_nftables·{.··
 0010a840:·7365·7276·6963·6520·7b27·6e66·7461·626c··service·{'nftabl
 0010a850:·6573·273a·0a20·2020·2065·6e61·626c·6520··es':.····enable·
 0010a860:·3d26·6774·3b20·6661·6c73·652c·0a20·2020··=&gt;·false,.···
 0010a870:·2065·6e73·7572·6520·3d26·6774·3b20·2773···ensure·=&gt;·'s
 0010a880:·746f·7070·6564·272c·0a20·207d·0a7d·0a3c··topped',.··}.}.<
 0010a890:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di
 0010a8a0:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn·
 0010a8b0:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat
 0010a8c0:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap
 0010a8d0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
 0010a8e0:·2223·6964·6d31·3539·3833·2220·7461·6269··"#idm15983"·tabi
 0010a8f0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
 0010a900:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
 0010a910:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
 0010a920:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
 0010a930:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
 0010a940:·223e·5265·6d65·6469·6174·696f·6e20·4b75··">Remediation·Ku
 0010a950:·6265·726e·6574·6573·2073·6e69·7070·6574··bernetes·snippet
 0010a960:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
 0010a970:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
 0010a980:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
 0010a990:·2069·643d·2269·646d·3135·3938·3322·3e3c···id="idm15983"><
 0010a9a0:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab
 0010a9b0:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped
 0010a9c0:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·
 0010a9d0:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"
 0010a9e0:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex
 0010a9f0:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low
 0010aa00:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
 0010aa10:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t
 0010aa20:·683e·3c74·643e·6d65·6469·756d·3c2f·7464··h><td>medium</td
 0010aa30:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re
 0010aa40:·626f·6f74·3a3c·2f74·683e·3c74·643e·7472··boot:</th><td>tr
0010aaf0:·7365·3c2f·7464·3e3c·2f74·723e·3c74·723e··se</td></tr><tr>0010aa50:·7565·3c2f·7464·3e3c·2f74·723e·3c74·723e··ue</td></tr><tr>
0010ab00:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t0010aa60:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t
0010ab10:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td0010aa70:·683e·3c74·643e·6469·7361·626c·653c·2f74··h><td>disable</t
0010ab20:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p 
0010ab30:·7265·3e3c·636f·6465·3e69·6e63·6c75·6465··re><code>include 
0010ab40:·2064·6973·6162·6c65·5f6e·6674·6162·6c65···disable_nftable 
0010ab50:·730a·0a63·6c61·7373·2064·6973·6162·6c65··s..class·disable 
0010ab60:·5f6e·6674·6162·6c65·7320·7b0a·2020·7365··_nftables·{.··se 
0010ab70:·7276·6963·6520·7b27·6e66·7461·626c·6573··rvice·{'nftables 
0010ab80:·273a·0a20·2020·2065·6e61·626c·6520·3d26··':.····enable·=&0010aa80:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><
 0010aa90:·7072·653e·3c63·6f64·653e·6170·6956·6572··pre><code>apiVer
 0010aaa0:·7369·6f6e·3a20·6d61·6368·696e·6563·6f6e··sion:·machinecon
Max diff block lines reached; 36650/48268 bytes (75.93%) of diff not shown.
7.39 KB
html2text {}
    
Offset 13167, 14 lines modifiedOffset 13167, 27 lines modified
13167 ··-·medium_severity13167 ··-·medium_severity
13168 ··-·no_reboot_needed13168 ··-·no_reboot_needed
13169 ··-·service_nftables_disabled13169 ··-·service_nftables_disabled
13170 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x813170 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
13171 [customizations.services]13171 [customizations.services]
13172 masked·=·["nftables"]13172 masked·=·["nftables"]
 13173 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 13174 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 13175 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 13176 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 13177 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 13178 include·disable_nftables
  
 13179 class·disable_nftables·{
 13180 ··service·{'nftables':
 13181 ····enable·=>·false,
 13182 ····ensure·=>·'stopped',
 13183 ··}
 13184 }
13173 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x813185 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
13174 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low13186 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
13175 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium13187 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
13176 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true13188 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
13177 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable13189 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
13178 apiVersion:·machineconfiguration.openshift.io/v113190 apiVersion:·machineconfiguration.openshift.io/v1
13179 kind:·MachineConfig13191 kind:·MachineConfig
Offset 13186, 27 lines modifiedOffset 13199, 14 lines modified
13186 ······units:13199 ······units:
13187 ······-·name:·nftables.service13200 ······-·name:·nftables.service
13188 ········enabled:·false13201 ········enabled:·false
13189 ········mask:·true13202 ········mask:·true
13190 ······-·name:·nftables.socket13203 ······-·name:·nftables.socket
13191 ········enabled:·false13204 ········enabled:·false
13192 ········mask:·true13205 ········mask:·true
13193 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
13194 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
13195 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
13196 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
13197 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
13198 include·disable_nftables 
  
13199 class·disable_nftables·{ 
13200 ··service·{'nftables': 
13201 ····enable·=>·false, 
13202 ····ensure·=>·'stopped', 
13203 ··} 
13204 } 
13205 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x813206 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
13206 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low13207 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
13207 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low13208 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
13208 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false13209 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
13209 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable13210 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
13210 #·Remediation·is·applicable·only·in·certain·platforms13211 #·Remediation·is·applicable·only·in·certain·platforms
13211 if·(·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'firewalld'·2>/dev/null·|·grep·-13212 if·(·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'firewalld'·2>/dev/null·|·grep·-
Offset 16162, 14 lines modifiedOffset 16162, 27 lines modified
16162 ··-·medium_severity16162 ··-·medium_severity
16163 ··-·no_reboot_needed16163 ··-·no_reboot_needed
16164 ··-·service_autofs_disabled16164 ··-·service_autofs_disabled
16165 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x816165 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
16166 [customizations.services]16166 [customizations.services]
16167 masked·=·["autofs"]16167 masked·=·["autofs"]
 16168 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 16169 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 16170 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 16171 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 16172 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 16173 include·disable_autofs
  
 16174 class·disable_autofs·{
 16175 ··service·{'autofs':
 16176 ····enable·=>·false,
 16177 ····ensure·=>·'stopped',
 16178 ··}
 16179 }
16168 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x816180 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
16169 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low16181 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
16170 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium16182 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
16171 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true16183 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
16172 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable16184 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
16173 apiVersion:·machineconfiguration.openshift.io/v116185 apiVersion:·machineconfiguration.openshift.io/v1
16174 kind:·MachineConfig16186 kind:·MachineConfig
Offset 16181, 27 lines modifiedOffset 16194, 14 lines modified
16181 ······units:16194 ······units:
16182 ······-·name:·autofs.service16195 ······-·name:·autofs.service
16183 ········enabled:·false16196 ········enabled:·false
16184 ········mask:·true16197 ········mask:·true
16185 ······-·name:·autofs.socket16198 ······-·name:·autofs.socket
16186 ········enabled:·false16199 ········enabled:·false
16187 ········mask:·true16200 ········mask:·true
16188 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
16189 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
16190 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
16191 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
16192 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
16193 include·disable_autofs 
  
16194 class·disable_autofs·{ 
16195 ··service·{'autofs': 
16196 ····enable·=>·false, 
16197 ····ensure·=>·'stopped', 
16198 ··} 
16199 } 
16200 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x816201 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
16201 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low16202 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
16202 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low16203 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
16203 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false16204 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
16204 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable16205 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
16205 #·Remediation·is·applicable·only·in·certain·platforms16206 #·Remediation·is·applicable·only·in·certain·platforms
16206 if·(·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'autofs'·2>/dev/null·|·grep·-16207 if·(·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'autofs'·2>/dev/null·|·grep·-
Offset 19674, 14 lines modifiedOffset 19674, 27 lines modified
19674 ··-·medium_severity19674 ··-·medium_severity
19675 ··-·no_reboot_needed19675 ··-·no_reboot_needed
19676 ··-·service_avahi-daemon_disabled19676 ··-·service_avahi-daemon_disabled
19677 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x819677 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
19678 [customizations.services]19678 [customizations.services]
19679 masked·=·["avahi-daemon"]19679 masked·=·["avahi-daemon"]
 19680 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 19681 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 19682 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 19683 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 19684 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 19685 include·disable_avahi-daemon
  
 19686 class·disable_avahi-daemon·{
Max diff block lines reached; 3008/7543 bytes (39.88%) of diff not shown.
27.6 KB
./usr/share/doc/ssg-debderived/ssg-ubuntu2004-guide-cis_level1_workstation.html
    
Offset 70047, 94 lines modifiedOffset 70047, 94 lines modified
001119e0:·6765·743d·2223·6964·6d31·3539·3832·2220··get="#idm15982"·001119e0:·6765·743d·2223·6964·6d31·3539·3832·2220··get="#idm15982"·
001119f0:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol001119f0:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol
00111a00:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-00111a00:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-
00111a10:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"00111a10:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"
00111a20:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate00111a20:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate
00111a30:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href00111a30:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href
00111a40:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio00111a40:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio
00111a50:·6e20·4b75·6265·726e·6574·6573·2073·6e69··n·Kubernetes·sni00111a50:·6e20·5075·7070·6574·2073·6e69·7070·6574··n·Puppet·snippet
00111a60:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>00111a60:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
00111a70:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane00111a70:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
00111a80:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla00111a80:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
00111a90:·7073·6522·2069·643d·2269·646d·3135·3938··pse"·id="idm159800111a90:·2069·643d·2269·646d·3135·3938·3222·3e3c···id="idm15982"><
00111aa0:·3222·3e3c·7461·626c·6520·636c·6173·733d··2"><table·class=00111aa0:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab
00111ab0:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str00111ab0:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped
00111ac0:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde00111ac0:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·
00111ad0:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden00111ad0:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"
00111ae0:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com00111ae0:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex
00111af0:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td00111af0:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low
00111b00:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t 
00111b10:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption 
00111b20:·3a3c·2f74·683e·3c74·643e·6d65·6469·756d··:</th><td>medium 
00111b30:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t00111b00:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
 00111b10:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t
 00111b20:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
 00111b30:·7472·3e3c·7472·3e3c·7468·3e52·6562·6f6f··tr><tr><th>Reboo
 00111b40:·743a·3c2f·7468·3e3c·7464·3e66·616c·7365··t:</th><td>false
 00111b50:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
 00111b60:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th>
 00111b70:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td><
 00111b80:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre
 00111b90:·3e3c·636f·6465·3e69·6e63·6c75·6465·2064··><code>include·d
 00111ba0:·6973·6162·6c65·5f6e·6674·6162·6c65·730a··isable_nftables.
 00111bb0:·0a63·6c61·7373·2064·6973·6162·6c65·5f6e··.class·disable_n
 00111bc0:·6674·6162·6c65·7320·7b0a·2020·7365·7276··ftables·{.··serv
 00111bd0:·6963·6520·7b27·6e66·7461·626c·6573·273a··ice·{'nftables':
 00111be0:·0a20·2020·2065·6e61·626c·6520·3d26·6774··.····enable·=&gt
 00111bf0:·3b20·6661·6c73·652c·0a20·2020·2065·6e73··;·false,.····ens
 00111c00:·7572·6520·3d26·6774·3b20·2773·746f·7070··ure·=&gt;·'stopp
 00111c10:·6564·272c·0a20·207d·0a7d·0a3c·2f63·6f64··ed',.··}.}.</cod
 00111c20:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a
 00111c30:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn-
 00111c40:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to
 00111c50:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"·
 00111c60:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
 00111c70:·6d31·3539·3833·2220·7461·6269·6e64·6578··m15983"·tabindex
 00111c80:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto
 00111c90:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded
 00111ca0:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="
 00111cb0:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve
 00111cc0:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re
 00111cd0:·6d65·6469·6174·696f·6e20·4b75·6265·726e··mediation·Kubern
00111b40:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t 
00111b50:·643e·7472·7565·3c2f·7464·3e3c·2f74·723e··d>true</td></tr> 
00111b60:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy 
00111b70:·3a3c·2f74·683e·3c74·643e·6469·7361·626c··:</th><td>disabl 
00111b80:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab 
00111b90:·6c65·3e3c·7072·653e·3c63·6f64·653e·6170··le><pre><code>ap 
00111ba0:·6956·6572·7369·6f6e·3a20·6d61·6368·696e··iVersion:·machin 
00111bb0:·6563·6f6e·6669·6775·7261·7469·6f6e·2e6f··econfiguration.o 
00111bc0:·7065·6e73·6869·6674·2e69·6f2f·7631·0a6b··penshift.io/v1.k 
00111bd0:·696e·643a·204d·6163·6869·6e65·436f·6e66··ind:·MachineConf 
00111be0:·6967·0a73·7065·633a·0a20·2063·6f6e·6669··ig.spec:.··confi 
00111bf0:·673a·0a20·2020·2069·676e·6974·696f·6e3a··g:.····ignition: 
00111c00:·0a20·2020·2020·2076·6572·7369·6f6e·3a20··.······version:· 
00111c10:·332e·312e·300a·2020·2020·7379·7374·656d··3.1.0.····system 
00111c20:·643a·0a20·2020·2020·2075·6e69·7473·3a0a··d:.······units:. 
00111c30:·2020·2020·2020·2d20·6e61·6d65·3a20·6e66········-·name:·nf 
00111c40:·7461·626c·6573·2e73·6572·7669·6365·0a20··tables.service.· 
00111c50:·2020·2020·2020·2065·6e61·626c·6564·3a20·········enabled:· 
00111c60:·6661·6c73·650a·2020·2020·2020·2020·6d61··false.········ma 
00111c70:·736b·3a20·7472·7565·0a20·2020·2020·202d··sk:·true.······- 
00111c80:·206e·616d·653a·206e·6674·6162·6c65·732e···name:·nftables. 
00111c90:·736f·636b·6574·0a20·2020·2020·2020·2065··socket.········e 
00111ca0:·6e61·626c·6564·3a20·6661·6c73·650a·2020··nabled:·false.·· 
00111cb0:·2020·2020·2020·6d61·736b·3a20·7472·7565········mask:·true 
00111cc0:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></ 
00111cd0:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt 
00111ce0:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d 
00111cf0:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll 
00111d00:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe 
00111d10:·743d·2223·6964·6d31·3539·3833·2220·7461··t="#idm15983"·ta 
00111d20:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role= 
00111d30:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex 
00111d40:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t 
00111d50:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t 
00111d60:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href=" 
00111d70:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation· 
00111d80:·5075·7070·6574·2073·6e69·7070·6574·20e2··Puppet·snippet·.00111ce0:·6574·6573·2073·6e69·7070·6574·20e2·87b2··etes·snippet·...
00111d90:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c00111cf0:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
00111da0:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll00111d00:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
00111db0:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i00111d10:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
00111dc0:·643d·2269·646d·3135·3938·3322·3e3c·7461··d="idm15983"><ta00111d20:·2269·646d·3135·3938·3322·3e3c·7461·626c··"idm15983"><tabl
00111dd0:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table00111d30:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t
00111de0:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t00111d40:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab
00111df0:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta00111d50:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl
00111e00:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><00111d60:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr
00111e10:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit00111d70:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:
00111e20:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</00111d80:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
 00111d90:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di
 00111da0:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t
 00111db0:·643e·6d65·6469·756d·3c2f·7464·3e3c·2f74··d>medium</td></t
 00111dc0:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot
 00111dd0:·3a3c·2f74·683e·3c74·643e·7472·7565·3c2f··:</th><td>true</
00111e30:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>00111de0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
00111e40:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th> 
00111e50:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
00111e60:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot: 
00111e70:·3c2f·7468·3e3c·7464·3e66·616c·7365·3c2f··</th><td>false</ 
00111e80:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
00111e90:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t00111df0:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t
00111ea0:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t 
00111eb0:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre>< 
00111ec0:·636f·6465·3e69·6e63·6c75·6465·2064·6973··code>include·dis 
00111ed0:·6162·6c65·5f6e·6674·6162·6c65·730a·0a63··able_nftables..c 
00111ee0:·6c61·7373·2064·6973·6162·6c65·5f6e·6674··lass·disable_nft 
00111ef0:·6162·6c65·7320·7b0a·2020·7365·7276·6963··ables·{.··servic 
00111f00:·6520·7b27·6e66·7461·626c·6573·273a·0a20··e·{'nftables':.· 
00111f10:·2020·2065·6e61·626c·6520·3d26·6774·3b20·····enable·=&gt;· 
00111f20:·6661·6c73·652c·0a20·2020·2065·6e73·7572··false,.····ensur 
00111f30:·6520·3d26·6774·3b20·2773·746f·7070·6564··e·=&gt;·'stopped 
00111f40:·272c·0a20·207d·0a7d·0a3c·2f63·6f64·653e··',.··}.}.</code>00111e00:·643e·6469·7361·626c·653c·2f74·643e·3c2f··d>disable</td></
 00111e10:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>
 00111e20:·3c63·6f64·653e·6170·6956·6572·7369·6f6e··<code>apiVersion
 00111e30:·3a20·6d61·6368·696e·6563·6f6e·6669·6775··:·machineconfigu
 00111e40:·7261·7469·6f6e·2e6f·7065·6e73·6869·6674··ration.openshift
 00111e50:·2e69·6f2f·7631·0a6b·696e·643a·204d·6163··.io/v1.kind:·Mac
 00111e60:·6869·6e65·436f·6e66·6967·0a73·7065·633a··hineConfig.spec:
Max diff block lines reached; 12584/24202 bytes (52.00%) of diff not shown.
3.78 KB
html2text {}
    
Offset 13613, 14 lines modifiedOffset 13613, 27 lines modified
13613 ··-·medium_severity13613 ··-·medium_severity
13614 ··-·no_reboot_needed13614 ··-·no_reboot_needed
13615 ··-·service_nftables_disabled13615 ··-·service_nftables_disabled
13616 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x813616 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
13617 [customizations.services]13617 [customizations.services]
13618 masked·=·["nftables"]13618 masked·=·["nftables"]
 13619 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 13620 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 13621 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 13622 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 13623 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 13624 include·disable_nftables
  
 13625 class·disable_nftables·{
 13626 ··service·{'nftables':
 13627 ····enable·=>·false,
 13628 ····ensure·=>·'stopped',
 13629 ··}
 13630 }
13619 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x813631 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
13620 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low13632 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
13621 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium13633 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
13622 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true13634 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
13623 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable13635 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
13624 apiVersion:·machineconfiguration.openshift.io/v113636 apiVersion:·machineconfiguration.openshift.io/v1
13625 kind:·MachineConfig13637 kind:·MachineConfig
Offset 13632, 27 lines modifiedOffset 13645, 14 lines modified
13632 ······units:13645 ······units:
13633 ······-·name:·nftables.service13646 ······-·name:·nftables.service
13634 ········enabled:·false13647 ········enabled:·false
13635 ········mask:·true13648 ········mask:·true
13636 ······-·name:·nftables.socket13649 ······-·name:·nftables.socket
13637 ········enabled:·false13650 ········enabled:·false
13638 ········mask:·true13651 ········mask:·true
13639 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
13640 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
13641 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
13642 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
13643 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
13644 include·disable_nftables 
  
13645 class·disable_nftables·{ 
13646 ··service·{'nftables': 
13647 ····enable·=>·false, 
13648 ····ensure·=>·'stopped', 
13649 ··} 
13650 } 
13651 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x813652 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
13652 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low13653 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
13653 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low13654 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
13654 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false13655 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
13655 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable13656 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
13656 #·Remediation·is·applicable·only·in·certain·platforms13657 #·Remediation·is·applicable·only·in·certain·platforms
13657 if·(·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'firewalld'·2>/dev/null·|·grep·-13658 if·(·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'firewalld'·2>/dev/null·|·grep·-
Offset 19620, 14 lines modifiedOffset 19620, 27 lines modified
19620 ··-·medium_severity19620 ··-·medium_severity
19621 ··-·no_reboot_needed19621 ··-·no_reboot_needed
19622 ··-·service_avahi-daemon_disabled19622 ··-·service_avahi-daemon_disabled
19623 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x819623 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
19624 [customizations.services]19624 [customizations.services]
19625 masked·=·["avahi-daemon"]19625 masked·=·["avahi-daemon"]
 19626 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 19627 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 19628 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 19629 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 19630 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 19631 include·disable_avahi-daemon
  
 19632 class·disable_avahi-daemon·{
 19633 ··service·{'avahi-daemon':
 19634 ····enable·=>·false,
 19635 ····ensure·=>·'stopped',
 19636 ··}
 19637 }
19626 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x819638 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
19627 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low19639 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
19628 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium19640 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
19629 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true19641 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
19630 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable19642 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
19631 apiVersion:·machineconfiguration.openshift.io/v119643 apiVersion:·machineconfiguration.openshift.io/v1
19632 kind:·MachineConfig19644 kind:·MachineConfig
Offset 19639, 27 lines modifiedOffset 19652, 14 lines modified
19639 ······units:19652 ······units:
19640 ······-·name:·avahi-daemon.service19653 ······-·name:·avahi-daemon.service
19641 ········enabled:·false19654 ········enabled:·false
19642 ········mask:·true19655 ········mask:·true
19643 ······-·name:·avahi-daemon.socket19656 ······-·name:·avahi-daemon.socket
19644 ········enabled:·false19657 ········enabled:·false
19645 ········mask:·true19658 ········mask:·true
19646 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
19647 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
19648 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
19649 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
19650 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
19651 include·disable_avahi-daemon 
  
19652 class·disable_avahi-daemon·{ 
19653 ··service·{'avahi-daemon': 
19654 ····enable·=>·false, 
19655 ····ensure·=>·'stopped', 
19656 ··} 
19657 } 
19658 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x819659 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
19659 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low19660 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
19660 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low19661 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
19661 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false19662 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
19662 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable19663 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
19663 #·Remediation·is·applicable·only·in·certain·platforms19664 #·Remediation·is·applicable·only·in·certain·platforms
19664 if·(·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'avahi-daemon'·2>/dev/null·|·grep·-19665 if·(·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'avahi-daemon'·2>/dev/null·|·grep·-
54.7 KB
./usr/share/doc/ssg-debderived/ssg-ubuntu2004-guide-cis_level2_server.html
    
Offset 69549, 94 lines modifiedOffset 69549, 94 lines modified
0010fac0:·2d74·6172·6765·743d·2223·6964·6d31·3539··-target="#idm1590010fac0:·2d74·6172·6765·743d·2223·6964·6d31·3539··-target="#idm159
0010fad0:·3832·2220·7461·6269·6e64·6578·3d22·3022··82"·tabindex="0"0010fad0:·3832·2220·7461·6269·6e64·6578·3d22·3022··82"·tabindex="0"
0010fae0:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a0010fae0:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
0010faf0:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa0010faf0:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
0010fb00:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti0010fb00:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
0010fb10:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·0010fb10:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
0010fb20:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi0010fb20:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
0010fb30:·6174·696f·6e20·4b75·6265·726e·6574·6573··ation·Kubernetes0010fb30:·6174·696f·6e20·5075·7070·6574·2073·6e69··ation·Puppet·sni
0010fb40:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>0010fb40:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>
0010fb50:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="0010fb50:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
0010fb60:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c0010fb60:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
0010fb70:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm0010fb70:·7073·6522·2069·643d·2269·646d·3135·3938··pse"·id="idm1598
0010fb80:·3135·3938·3222·3e3c·7461·626c·6520·636c··15982"><table·cl0010fb80:·3222·3e3c·7461·626c·6520·636c·6173·733d··2"><table·class=
0010fb90:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table0010fb90:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str
0010fba0:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b0010fba0:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde
0010fbb0:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co0010fbb0:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden
0010fbc0:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th0010fbc0:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com
0010fbd0:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th0010fbd0:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td
0010fbe0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t0010fbe0:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
0010fbf0:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup0010fbf0:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption
0010fc00:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6d65··tion:</th><td>me0010fc00:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
 0010fc10:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e52··d></tr><tr><th>R
 0010fc20:·6562·6f6f·743a·3c2f·7468·3e3c·7464·3e66··eboot:</th><td>f
0010fc10:·6469·756d·3c2f·7464·3e3c·2f74·723e·3c74··dium</td></tr><t0010fc30:·616c·7365·3c2f·7464·3e3c·2f74·723e·3c74··alse</td></tr><t
0010fc20:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t0010fc40:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<
 0010fc50:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</
 0010fc60:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table>
 0010fc70:·3c70·7265·3e3c·636f·6465·3e69·6e63·6c75··<pre><code>inclu
 0010fc80:·6465·2064·6973·6162·6c65·5f6e·6674·6162··de·disable_nftab
 0010fc90:·6c65·730a·0a63·6c61·7373·2064·6973·6162··les..class·disab
 0010fca0:·6c65·5f6e·6674·6162·6c65·7320·7b0a·2020··le_nftables·{.··
 0010fcb0:·7365·7276·6963·6520·7b27·6e66·7461·626c··service·{'nftabl
 0010fcc0:·6573·273a·0a20·2020·2065·6e61·626c·6520··es':.····enable·
 0010fcd0:·3d26·6774·3b20·6661·6c73·652c·0a20·2020··=&gt;·false,.···
 0010fce0:·2065·6e73·7572·6520·3d26·6774·3b20·2773···ensure·=&gt;·'s
 0010fcf0:·746f·7070·6564·272c·0a20·207d·0a7d·0a3c··topped',.··}.}.<
 0010fd00:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di
 0010fd10:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn·
 0010fd20:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat
 0010fd30:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap
 0010fd40:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
 0010fd50:·2223·6964·6d31·3539·3833·2220·7461·6269··"#idm15983"·tabi
 0010fd60:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
 0010fd70:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
 0010fd80:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
 0010fd90:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
 0010fda0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
 0010fdb0:·223e·5265·6d65·6469·6174·696f·6e20·4b75··">Remediation·Ku
 0010fdc0:·6265·726e·6574·6573·2073·6e69·7070·6574··bernetes·snippet
 0010fdd0:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
 0010fde0:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
 0010fdf0:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
 0010fe00:·2069·643d·2269·646d·3135·3938·3322·3e3c···id="idm15983"><
 0010fe10:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab
 0010fe20:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped
 0010fe30:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·
 0010fe40:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"
 0010fe50:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex
 0010fe60:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low
 0010fe70:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
 0010fe80:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t
0010fc30:·683e·3c74·643e·7472·7565·3c2f·7464·3e3c··h><td>true</td><0010fe90:·683e·3c74·643e·6d65·6469·756d·3c2f·7464··h><td>medium</td
0010fc40:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra0010fea0:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re
 0010feb0:·626f·6f74·3a3c·2f74·683e·3c74·643e·7472··boot:</th><td>tr
 0010fec0:·7565·3c2f·7464·3e3c·2f74·723e·3c74·723e··ue</td></tr><tr>
 0010fed0:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t
 0010fee0:·683e·3c74·643e·6469·7361·626c·653c·2f74··h><td>disable</t
 0010fef0:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><
 0010ff00:·7072·653e·3c63·6f64·653e·6170·6956·6572··pre><code>apiVer
 0010ff10:·7369·6f6e·3a20·6d61·6368·696e·6563·6f6e··sion:·machinecon
 0010ff20:·6669·6775·7261·7469·6f6e·2e6f·7065·6e73··figuration.opens
 0010ff30:·6869·6674·2e69·6f2f·7631·0a6b·696e·643a··hift.io/v1.kind:
 0010ff40:·204d·6163·6869·6e65·436f·6e66·6967·0a73···MachineConfig.s
 0010ff50:·7065·633a·0a20·2063·6f6e·6669·673a·0a20··pec:.··config:.·
 0010ff60:·2020·2069·676e·6974·696f·6e3a·0a20·2020·····ignition:.···
 0010ff70:·2020·2076·6572·7369·6f6e·3a20·332e·312e·····version:·3.1.
 0010ff80:·300a·2020·2020·7379·7374·656d·643a·0a20··0.····systemd:.·
 0010ff90:·2020·2020·2075·6e69·7473·3a0a·2020·2020·······units:.····
 0010ffa0:·2020·2d20·6e61·6d65·3a20·6e66·7461·626c····-·name:·nftabl
 0010ffb0:·6573·2e73·6572·7669·6365·0a20·2020·2020··es.service.·····
0010fc50:·7465·6779·3a3c·2f74·683e·3c74·643e·6469··tegy:</th><td>di 
0010fc60:·7361·626c·653c·2f74·643e·3c2f·7472·3e3c··sable</td></tr>< 
0010fc70:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod 
0010fc80:·653e·6170·6956·6572·7369·6f6e·3a20·6d61··e>apiVersion:·ma 
0010fc90:·6368·696e·6563·6f6e·6669·6775·7261·7469··chineconfigurati 
0010fca0:·6f6e·2e6f·7065·6e73·6869·6674·2e69·6f2f··on.openshift.io/ 
0010fcb0:·7631·0a6b·696e·643a·204d·6163·6869·6e65··v1.kind:·Machine 
0010fcc0:·436f·6e66·6967·0a73·7065·633a·0a20·2063··Config.spec:.··c 
0010fcd0:·6f6e·6669·673a·0a20·2020·2069·676e·6974··onfig:.····ignit 
0010fce0:·696f·6e3a·0a20·2020·2020·2076·6572·7369··ion:.······versi 
0010fcf0:·6f6e·3a20·332e·312e·300a·2020·2020·7379··on:·3.1.0.····sy 
0010fd00:·7374·656d·643a·0a20·2020·2020·2075·6e69··stemd:.······uni 
0010fd10:·7473·3a0a·2020·2020·2020·2d20·6e61·6d65··ts:.······-·name 
0010fd20:·3a20·6e66·7461·626c·6573·2e73·6572·7669··:·nftables.servi 
0010fd30:·6365·0a20·2020·2020·2020·2065·6e61·626c··ce.········enabl 
0010fd40:·6564·3a20·6661·6c73·650a·2020·2020·2020··ed:·false.······ 
0010fd50:·2020·6d61·736b·3a20·7472·7565·0a20·2020····mask:·true.··· 
0010fd60:·2020·202d·206e·616d·653a·206e·6674·6162·····-·name:·nftab 
0010fd70:·6c65·732e·736f·636b·6574·0a20·2020·2020··les.socket.····· 
0010fd80:·2020·2065·6e61·626c·6564·3a20·6661·6c73·····enabled:·fals0010ffc0:·2020·2065·6e61·626c·6564·3a20·6661·6c73·····enabled:·fals
0010fd90:·650a·2020·2020·2020·2020·6d61·736b·3a20··e.········mask:·0010ffd0:·650a·2020·2020·2020·2020·6d61·736b·3a20··e.········mask:·
 0010ffe0:·7472·7565·0a20·2020·2020·202d·206e·616d··true.······-·nam
 0010fff0:·653a·206e·6674·6162·6c65·732e·736f·636b··e:·nftables.sock
 00110000:·6574·0a20·2020·2020·2020·2065·6e61·626c··et.········enabl
0010fda0:·7472·7565·0a3c·2f63·6f64·653e·3c2f·7072··true.</code></pr 
0010fdb0:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class 
0010fdc0:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes 
0010fdd0:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle=" 
0010fde0:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t 
0010fdf0:·6172·6765·743d·2223·6964·6d31·3539·3833··arget="#idm15983 
0010fe00:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r 
0010fe10:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari 
0010fe20:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals 
0010fe30:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa 
0010fe40:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr 
0010fe50:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat 
0010fe60:·696f·6e20·5075·7070·6574·2073·6e69·7070··ion·Puppet·snipp 
0010fe70:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d 
0010fe80:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel- 
0010fe90:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps 
0010fea0:·6522·2069·643d·2269·646d·3135·3938·3322··e"·id="idm15983" 
0010feb0:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t 
0010fec0:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip 
0010fed0:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere 
0010fee0:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense 
0010fef0:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl 
0010ff00:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l 
Max diff block lines reached; 36650/48268 bytes (75.93%) of diff not shown.
7.39 KB
html2text {}
    
Offset 13324, 14 lines modifiedOffset 13324, 27 lines modified
13324 ··-·medium_severity13324 ··-·medium_severity
13325 ··-·no_reboot_needed13325 ··-·no_reboot_needed
13326 ··-·service_nftables_disabled13326 ··-·service_nftables_disabled
13327 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x813327 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
13328 [customizations.services]13328 [customizations.services]
13329 masked·=·["nftables"]13329 masked·=·["nftables"]
 13330 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 13331 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 13332 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 13333 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 13334 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 13335 include·disable_nftables
  
 13336 class·disable_nftables·{
 13337 ··service·{'nftables':
 13338 ····enable·=>·false,
 13339 ····ensure·=>·'stopped',
 13340 ··}
 13341 }
13330 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x813342 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
13331 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low13343 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
13332 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium13344 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
13333 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true13345 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
13334 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable13346 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
13335 apiVersion:·machineconfiguration.openshift.io/v113347 apiVersion:·machineconfiguration.openshift.io/v1
13336 kind:·MachineConfig13348 kind:·MachineConfig
Offset 13343, 27 lines modifiedOffset 13356, 14 lines modified
13343 ······units:13356 ······units:
13344 ······-·name:·nftables.service13357 ······-·name:·nftables.service
13345 ········enabled:·false13358 ········enabled:·false
13346 ········mask:·true13359 ········mask:·true
13347 ······-·name:·nftables.socket13360 ······-·name:·nftables.socket
13348 ········enabled:·false13361 ········enabled:·false
13349 ········mask:·true13362 ········mask:·true
13350 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
13351 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
13352 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
13353 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
13354 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
13355 include·disable_nftables 
  
13356 class·disable_nftables·{ 
13357 ··service·{'nftables': 
13358 ····enable·=>·false, 
13359 ····ensure·=>·'stopped', 
13360 ··} 
13361 } 
13362 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x813363 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
13363 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low13364 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
13364 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low13365 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
13365 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false13366 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
13366 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable13367 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
13367 #·Remediation·is·applicable·only·in·certain·platforms13368 #·Remediation·is·applicable·only·in·certain·platforms
13368 if·(·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'firewalld'·2>/dev/null·|·grep·-13369 if·(·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'firewalld'·2>/dev/null·|·grep·-
Offset 16777, 14 lines modifiedOffset 16777, 27 lines modified
16777 ··-·medium_severity16777 ··-·medium_severity
16778 ··-·no_reboot_needed16778 ··-·no_reboot_needed
16779 ··-·service_autofs_disabled16779 ··-·service_autofs_disabled
16780 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x816780 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
16781 [customizations.services]16781 [customizations.services]
16782 masked·=·["autofs"]16782 masked·=·["autofs"]
 16783 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 16784 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 16785 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 16786 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 16787 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 16788 include·disable_autofs
  
 16789 class·disable_autofs·{
 16790 ··service·{'autofs':
 16791 ····enable·=>·false,
 16792 ····ensure·=>·'stopped',
 16793 ··}
 16794 }
16783 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x816795 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
16784 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low16796 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
16785 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium16797 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
16786 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true16798 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
16787 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable16799 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
16788 apiVersion:·machineconfiguration.openshift.io/v116800 apiVersion:·machineconfiguration.openshift.io/v1
16789 kind:·MachineConfig16801 kind:·MachineConfig
Offset 16796, 27 lines modifiedOffset 16809, 14 lines modified
16796 ······units:16809 ······units:
16797 ······-·name:·autofs.service16810 ······-·name:·autofs.service
16798 ········enabled:·false16811 ········enabled:·false
16799 ········mask:·true16812 ········mask:·true
16800 ······-·name:·autofs.socket16813 ······-·name:·autofs.socket
16801 ········enabled:·false16814 ········enabled:·false
16802 ········mask:·true16815 ········mask:·true
16803 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
16804 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
16805 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
16806 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
16807 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
16808 include·disable_autofs 
  
16809 class·disable_autofs·{ 
16810 ··service·{'autofs': 
16811 ····enable·=>·false, 
16812 ····ensure·=>·'stopped', 
16813 ··} 
16814 } 
16815 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x816816 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
16816 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low16817 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
16817 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low16818 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
16818 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false16819 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
16819 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable16820 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
16820 #·Remediation·is·applicable·only·in·certain·platforms16821 #·Remediation·is·applicable·only·in·certain·platforms
16821 if·(·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'autofs'·2>/dev/null·|·grep·-16822 if·(·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'autofs'·2>/dev/null·|·grep·-
Offset 20289, 14 lines modifiedOffset 20289, 27 lines modified
20289 ··-·medium_severity20289 ··-·medium_severity
20290 ··-·no_reboot_needed20290 ··-·no_reboot_needed
20291 ··-·service_avahi-daemon_disabled20291 ··-·service_avahi-daemon_disabled
20292 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x820292 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
20293 [customizations.services]20293 [customizations.services]
20294 masked·=·["avahi-daemon"]20294 masked·=·["avahi-daemon"]
 20295 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 20296 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 20297 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 20298 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 20299 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 20300 include·disable_avahi-daemon
  
 20301 class·disable_avahi-daemon·{
Max diff block lines reached; 3008/7543 bytes (39.88%) of diff not shown.
54.5 KB
./usr/share/doc/ssg-debderived/ssg-ubuntu2004-guide-cis_level2_workstation.html
    
Offset 71398, 94 lines modifiedOffset 71398, 94 lines modified
00116e50:·6574·3d22·2369·646d·3135·3938·3222·2074··et="#idm15982"·t00116e50:·6574·3d22·2369·646d·3135·3938·3222·2074··et="#idm15982"·t
00116e60:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role00116e60:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
00116e70:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e00116e70:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
00116e80:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·00116e80:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
00116e90:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·00116e90:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
00116ea0:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=00116ea0:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
00116eb0:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation00116eb0:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
00116ec0:·204b·7562·6572·6e65·7465·7320·736e·6970···Kubernetes·snip00116ec0:·2050·7570·7065·7420·736e·6970·7065·7420···Puppet·snippet·
00116ed0:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br><00116ed0:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·
00116ee0:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel00116ee0:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col
00116ef0:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap00116ef0:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·
00116f00:·7365·2220·6964·3d22·6964·6d31·3539·3832··se"·id="idm1598200116f00:·6964·3d22·6964·6d31·3539·3832·223e·3c74··id="idm15982"><t
00116f10:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="00116f10:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl
00116f20:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri00116f20:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·
00116f30:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border00116f30:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t
00116f40:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens00116f40:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">
00116f50:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp00116f50:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi
00116f60:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>00116f60:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<
00116f70:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr 
00116f80:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption: 
00116f90:·3c2f·7468·3e3c·7464·3e6d·6564·6975·6d3c··</th><td>medium< 
00116fa0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th00116f70:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 00116f80:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th
 00116f90:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
 00116fa0:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot
 00116fb0:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false<
 00116fc0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 00116fd0:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><
 00116fe0:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></
 00116ff0:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>
 00117000:·3c63·6f64·653e·696e·636c·7564·6520·6469··<code>include·di
 00117010:·7361·626c·655f·6e66·7461·626c·6573·0a0a··sable_nftables..
 00117020:·636c·6173·7320·6469·7361·626c·655f·6e66··class·disable_nf
 00117030:·7461·626c·6573·207b·0a20·2073·6572·7669··tables·{.··servi
 00117040:·6365·207b·276e·6674·6162·6c65·7327·3a0a··ce·{'nftables':.
 00117050:·2020·2020·656e·6162·6c65·203d·2667·743b······enable·=&gt;
 00117060:·2066·616c·7365·2c0a·2020·2020·656e·7375···false,.····ensu
 00117070:·7265·203d·2667·743b·2027·7374·6f70·7065··re·=&gt;·'stoppe
 00117080:·6427·2c0a·2020·7d0a·7d0a·3c2f·636f·6465··d',.··}.}.</code
 00117090:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a·
 001170a0:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s
 001170b0:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog
 001170c0:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d
 001170d0:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
 001170e0:·3135·3938·3322·2074·6162·696e·6465·783d··15983"·tabindex=
 001170f0:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button
 00117100:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=
 00117110:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A
 00117120:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea
 00117130:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem
 00117140:·6564·6961·7469·6f6e·204b·7562·6572·6e65··ediation·Kuberne
00116fb0:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td 
00116fc0:·3e74·7275·653c·2f74·643e·3c2f·7472·3e3c··>true</td></tr>< 
00116fd0:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy: 
00116fe0:·3c2f·7468·3e3c·7464·3e64·6973·6162·6c65··</th><td>disable 
00116ff0:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl 
00117000:·653e·3c70·7265·3e3c·636f·6465·3e61·7069··e><pre><code>api 
00117010:·5665·7273·696f·6e3a·206d·6163·6869·6e65··Version:·machine 
00117020:·636f·6e66·6967·7572·6174·696f·6e2e·6f70··configuration.op 
00117030:·656e·7368·6966·742e·696f·2f76·310a·6b69··enshift.io/v1.ki 
00117040:·6e64·3a20·4d61·6368·696e·6543·6f6e·6669··nd:·MachineConfi 
00117050:·670a·7370·6563·3a0a·2020·636f·6e66·6967··g.spec:.··config 
00117060:·3a0a·2020·2020·6967·6e69·7469·6f6e·3a0a··:.····ignition:. 
00117070:·2020·2020·2020·7665·7273·696f·6e3a·2033········version:·3 
00117080:·2e31·2e30·0a20·2020·2073·7973·7465·6d64··.1.0.····systemd 
00117090:·3a0a·2020·2020·2020·756e·6974·733a·0a20··:.······units:.· 
001170a0:·2020·2020·202d·206e·616d·653a·206e·6674·······-·name:·nft 
001170b0:·6162·6c65·732e·7365·7276·6963·650a·2020··ables.service.·· 
001170c0:·2020·2020·2020·656e·6162·6c65·643a·2066········enabled:·f 
001170d0:·616c·7365·0a20·2020·2020·2020·206d·6173··alse.········mas 
001170e0:·6b3a·2074·7275·650a·2020·2020·2020·2d20··k:·true.······-· 
001170f0:·6e61·6d65·3a20·6e66·7461·626c·6573·2e73··name:·nftables.s 
00117100:·6f63·6b65·740a·2020·2020·2020·2020·656e··ocket.········en 
00117110:·6162·6c65·643a·2066·616c·7365·0a20·2020··abled:·false.··· 
00117120:·2020·2020·206d·6173·6b3a·2074·7275·650a·······mask:·true. 
00117130:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d 
00117140:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn 
00117150:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da 
00117160:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla 
00117170:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target 
00117180:·3d22·2369·646d·3135·3938·3322·2074·6162··="#idm15983"·tab 
00117190:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role=" 
001171a0:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp 
001171b0:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti 
001171c0:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to 
001171d0:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="# 
001171e0:·2122·3e52·656d·6564·6961·7469·6f6e·2050··!">Remediation·P 
001171f0:·7570·7065·7420·736e·6970·7065·7420·e287··uppet·snippet·..00117150:·7465·7320·736e·6970·7065·7420·e287·b23c··tes·snippet·...<
00117200:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl00117160:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas
00117210:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla00117170:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps
00117220:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id00117180:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="
00117230:·3d22·6964·6d31·3539·3833·223e·3c74·6162··="idm15983"><tab00117190:·6964·6d31·3539·3833·223e·3c74·6162·6c65··idm15983"><table
00117240:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·001171a0:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta
00117250:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta001171b0:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl
00117260:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab001171c0:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table
00117270:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t001171d0:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>
00117280:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity001171e0:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<
00117290:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t001171f0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
001172a0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D00117200:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis
001172b0:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><00117210:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td
001172c0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
001172d0:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:< 
001172e0:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t00117220:·3e6d·6564·6975·6d3c·2f74·643e·3c2f·7472··>medium</td></tr
 00117230:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot:
 00117240:·3c2f·7468·3e3c·7464·3e74·7275·653c·2f74··</th><td>true</t
001172f0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S00117250:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S
00117300:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td00117260:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td
00117310:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr 
00117320:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c 
00117330:·6f64·653e·696e·636c·7564·6520·6469·7361··ode>include·disa 
00117340:·626c·655f·6e66·7461·626c·6573·0a0a·636c··ble_nftables..cl 
00117350:·6173·7320·6469·7361·626c·655f·6e66·7461··ass·disable_nfta 
00117360:·626c·6573·207b·0a20·2073·6572·7669·6365··bles·{.··service 
00117370:·207b·276e·6674·6162·6c65·7327·3a0a·2020···{'nftables':.·· 
00117380:·2020·656e·6162·6c65·203d·2667·743b·2066····enable·=&gt;·f 
00117390:·616c·7365·2c0a·2020·2020·656e·7375·7265··alse,.····ensure 
001173a0:·203d·2667·743b·2027·7374·6f70·7065·6427···=&gt;·'stopped'00117270:·3e64·6973·6162·6c65·3c2f·7464·3e3c·2f74··>disable</td></t
 00117280:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><
 00117290:·636f·6465·3e61·7069·5665·7273·696f·6e3a··code>apiVersion:
 001172a0:·206d·6163·6869·6e65·636f·6e66·6967·7572···machineconfigur
 001172b0:·6174·696f·6e2e·6f70·656e·7368·6966·742e··ation.openshift.
 001172c0:·696f·2f76·310a·6b69·6e64·3a20·4d61·6368··io/v1.kind:·Mach
 001172d0:·696e·6543·6f6e·6669·670a·7370·6563·3a0a··ineConfig.spec:.
 001172e0:·2020·636f·6e66·6967·3a0a·2020·2020·6967····config:.····ig
 001172f0:·6e69·7469·6f6e·3a0a·2020·2020·2020·7665··nition:.······ve
 00117300:·7273·696f·6e3a·2033·2e31·2e30·0a20·2020··rsion:·3.1.0.···
 00117310:·2073·7973·7465·6d64·3a0a·2020·2020·2020···systemd:.······
Max diff block lines reached; 36514/48132 bytes (75.86%) of diff not shown.
7.39 KB
html2text {}
    
Offset 13770, 14 lines modifiedOffset 13770, 27 lines modified
13770 ··-·medium_severity13770 ··-·medium_severity
13771 ··-·no_reboot_needed13771 ··-·no_reboot_needed
13772 ··-·service_nftables_disabled13772 ··-·service_nftables_disabled
13773 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x813773 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
13774 [customizations.services]13774 [customizations.services]
13775 masked·=·["nftables"]13775 masked·=·["nftables"]
 13776 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 13777 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 13778 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 13779 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 13780 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 13781 include·disable_nftables
  
 13782 class·disable_nftables·{
 13783 ··service·{'nftables':
 13784 ····enable·=>·false,
 13785 ····ensure·=>·'stopped',
 13786 ··}
 13787 }
13776 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x813788 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
13777 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low13789 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
13778 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium13790 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
13779 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true13791 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
13780 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable13792 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
13781 apiVersion:·machineconfiguration.openshift.io/v113793 apiVersion:·machineconfiguration.openshift.io/v1
13782 kind:·MachineConfig13794 kind:·MachineConfig
Offset 13789, 27 lines modifiedOffset 13802, 14 lines modified
13789 ······units:13802 ······units:
13790 ······-·name:·nftables.service13803 ······-·name:·nftables.service
13791 ········enabled:·false13804 ········enabled:·false
13792 ········mask:·true13805 ········mask:·true
13793 ······-·name:·nftables.socket13806 ······-·name:·nftables.socket
13794 ········enabled:·false13807 ········enabled:·false
13795 ········mask:·true13808 ········mask:·true
13796 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
13797 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
13798 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
13799 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
13800 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
13801 include·disable_nftables 
  
13802 class·disable_nftables·{ 
13803 ··service·{'nftables': 
13804 ····enable·=>·false, 
13805 ····ensure·=>·'stopped', 
13806 ··} 
13807 } 
13808 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x813809 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
13809 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low13810 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
13810 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low13811 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
13811 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false13812 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
13812 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable13813 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
13813 #·Remediation·is·applicable·only·in·certain·platforms13814 #·Remediation·is·applicable·only·in·certain·platforms
13814 if·(·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'firewalld'·2>/dev/null·|·grep·-13815 if·(·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'firewalld'·2>/dev/null·|·grep·-
Offset 17223, 14 lines modifiedOffset 17223, 27 lines modified
17223 ··-·medium_severity17223 ··-·medium_severity
17224 ··-·no_reboot_needed17224 ··-·no_reboot_needed
17225 ··-·service_autofs_disabled17225 ··-·service_autofs_disabled
17226 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x817226 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
17227 [customizations.services]17227 [customizations.services]
17228 masked·=·["autofs"]17228 masked·=·["autofs"]
 17229 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 17230 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 17231 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 17232 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 17233 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 17234 include·disable_autofs
  
 17235 class·disable_autofs·{
 17236 ··service·{'autofs':
 17237 ····enable·=>·false,
 17238 ····ensure·=>·'stopped',
 17239 ··}
 17240 }
17229 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x817241 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
17230 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low17242 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
17231 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium17243 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
17232 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true17244 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
17233 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable17245 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
17234 apiVersion:·machineconfiguration.openshift.io/v117246 apiVersion:·machineconfiguration.openshift.io/v1
17235 kind:·MachineConfig17247 kind:·MachineConfig
Offset 17242, 27 lines modifiedOffset 17255, 14 lines modified
17242 ······units:17255 ······units:
17243 ······-·name:·autofs.service17256 ······-·name:·autofs.service
17244 ········enabled:·false17257 ········enabled:·false
17245 ········mask:·true17258 ········mask:·true
17246 ······-·name:·autofs.socket17259 ······-·name:·autofs.socket
17247 ········enabled:·false17260 ········enabled:·false
17248 ········mask:·true17261 ········mask:·true
17249 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
17250 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
17251 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
17252 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
17253 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
17254 include·disable_autofs 
  
17255 class·disable_autofs·{ 
17256 ··service·{'autofs': 
17257 ····enable·=>·false, 
17258 ····ensure·=>·'stopped', 
17259 ··} 
17260 } 
17261 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x817262 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
17262 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low17263 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
17263 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low17264 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
17264 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false17265 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
17265 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable17266 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
17266 #·Remediation·is·applicable·only·in·certain·platforms17267 #·Remediation·is·applicable·only·in·certain·platforms
17267 if·(·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'autofs'·2>/dev/null·|·grep·-17268 if·(·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'autofs'·2>/dev/null·|·grep·-
Offset 20735, 14 lines modifiedOffset 20735, 27 lines modified
20735 ··-·medium_severity20735 ··-·medium_severity
20736 ··-·no_reboot_needed20736 ··-·no_reboot_needed
20737 ··-·service_avahi-daemon_disabled20737 ··-·service_avahi-daemon_disabled
20738 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x820738 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
20739 [customizations.services]20739 [customizations.services]
20740 masked·=·["avahi-daemon"]20740 masked·=·["avahi-daemon"]
 20741 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 20742 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 20743 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 20744 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 20745 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 20746 include·disable_avahi-daemon
  
 20747 class·disable_avahi-daemon·{
Max diff block lines reached; 3008/7543 bytes (39.88%) of diff not shown.
13.7 KB
./usr/share/doc/ssg-debderived/ssg-ubuntu2004-guide-standard.html
    
Offset 28558, 94 lines modifiedOffset 28558, 94 lines modified
0006f8d0:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i0006f8d0:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i
0006f8e0:·646d·3230·3938·3322·2074·6162·696e·6465··dm20983"·tabinde0006f8e0:·646d·3230·3938·3322·2074·6162·696e·6465··dm20983"·tabinde
0006f8f0:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt0006f8f0:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt
0006f900:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande0006f900:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande
0006f910:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=0006f910:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=
0006f920:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev0006f920:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev
0006f930:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R0006f930:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R
0006f940:·656d·6564·6961·7469·6f6e·204b·7562·6572··emediation·Kuber0006f940:·656d·6564·6961·7469·6f6e·2050·7570·7065··emediation·Puppe
 0006f950:·7420·736e·6970·7065·7420·e287·b23c·2f61··t·snippet·...</a
 0006f960:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
 0006f970:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
 0006f980:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
 0006f990:·6d32·3039·3833·223e·3c74·6162·6c65·2063··m20983"><table·c
 0006f9a0:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl
 0006f9b0:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-
 0006f9c0:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c
 0006f9d0:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t
 0006f9e0:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t
 0006f9f0:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
 0006fa00:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru
 0006fa10:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l
 0006fa20:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
 0006fa30:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th>
 0006fa40:·3c74·643e·6661·6c73·653c·2f74·643e·3c2f··<td>false</td></
 0006fa50:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat
 0006fa60:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena
 0006fa70:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t
 0006fa80:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>
 0006fa90:·696e·636c·7564·6520·6469·7361·626c·655f··include·disable_
 0006faa0:·6170·706f·7274·0a0a·636c·6173·7320·6469··apport..class·di
 0006fab0:·7361·626c·655f·6170·706f·7274·207b·0a20··sable_apport·{.·
 0006fac0:·2073·6572·7669·6365·207b·2761·7070·6f72···service·{'appor
 0006fad0:·7427·3a0a·2020·2020·656e·6162·6c65·203d··t':.····enable·=
 0006fae0:·2667·743b·2066·616c·7365·2c0a·2020·2020··&gt;·false,.····
 0006faf0:·656e·7375·7265·203d·2667·743b·2027·7374··ensure·=&gt;·'st
 0006fb00:·6f70·7065·6427·2c0a·2020·7d0a·7d0a·3c2f··opped',.··}.}.</
 0006fb10:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div
 0006fb20:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b
 0006fb30:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data
 0006fb40:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps
 0006fb50:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
 0006fb60:·2369·646d·3230·3938·3422·2074·6162·696e··#idm20984"·tabin
 0006fb70:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
 0006fb80:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
 0006fb90:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
 0006fba0:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
 0006fbb0:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
 0006fbc0:·3e52·656d·6564·6961·7469·6f6e·204b·7562··>Remediation·Kub
0006f950:·6e65·7465·7320·736e·6970·7065·7420·e287··netes·snippet·..0006fbd0:·6572·6e65·7465·7320·736e·6970·7065·7420··ernetes·snippet·
0006f960:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl0006fbe0:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·
0006f970:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla0006fbf0:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col
0006f980:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id0006fc00:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·
0006f990:·3d22·6964·6d32·3039·3833·223e·3c74·6162··="idm20983"><tab0006fc10:·6964·3d22·6964·6d32·3039·3834·223e·3c74··id="idm20984"><t
0006f9a0:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·0006fc20:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl
0006f9b0:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta0006fc30:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·
0006f9c0:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab0006fc40:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t
0006f9d0:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t0006fc50:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">
0006f9e0:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity0006fc60:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi
0006f9f0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t0006fc70:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<
0006fa00:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D 
0006fa10:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th>< 
0006fa20:·7464·3e6d·6564·6975·6d3c·2f74·643e·3c2f··td>medium</td></ 
0006fa30:·7472·3e3c·7472·3e3c·7468·3e52·6562·6f6f··tr><tr><th>Reboo 
0006fa40:·743a·3c2f·7468·3e3c·7464·3e74·7275·653c··t:</th><td>true< 
0006fa50:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th0006fc80:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 0006fc90:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th
 0006fca0:·3e3c·7464·3e6d·6564·6975·6d3c·2f74·643e··><td>medium</td>
 0006fcb0:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb
 0006fcc0:·6f6f·743a·3c2f·7468·3e3c·7464·3e74·7275··oot:</th><td>tru
 0006fcd0:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr><
0006fa60:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><0006fce0:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th
0006fa70:·7464·3e64·6973·6162·6c65·3c2f·7464·3e3c··td>disable</td><0006fcf0:·3e3c·7464·3e64·6973·6162·6c65·3c2f·7464··><td>disable</td
0006fa80:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre0006fd00:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p
0006fa90:·3e3c·636f·6465·3e61·7069·5665·7273·696f··><code>apiVersio0006fd10:·7265·3e3c·636f·6465·3e61·7069·5665·7273··re><code>apiVers
0006faa0:·6e3a·206d·6163·6869·6e65·636f·6e66·6967··n:·machineconfig0006fd20:·696f·6e3a·206d·6163·6869·6e65·636f·6e66··ion:·machineconf
0006fab0:·7572·6174·696f·6e2e·6f70·656e·7368·6966··uration.openshif0006fd30:·6967·7572·6174·696f·6e2e·6f70·656e·7368··iguration.opensh
0006fac0:·742e·696f·2f76·310a·6b69·6e64·3a20·4d61··t.io/v1.kind:·Ma0006fd40:·6966·742e·696f·2f76·310a·6b69·6e64·3a20··ift.io/v1.kind:·
0006fad0:·6368·696e·6543·6f6e·6669·670a·7370·6563··chineConfig.spec0006fd50:·4d61·6368·696e·6543·6f6e·6669·670a·7370··MachineConfig.sp
0006fae0:·3a0a·2020·636f·6e66·6967·3a0a·2020·2020··:.··config:.····0006fd60:·6563·3a0a·2020·636f·6e66·6967·3a0a·2020··ec:.··config:.··
0006faf0:·6967·6e69·7469·6f6e·3a0a·2020·2020·2020··ignition:.······0006fd70:·2020·6967·6e69·7469·6f6e·3a0a·2020·2020····ignition:.····
0006fb00:·7665·7273·696f·6e3a·2033·2e31·2e30·0a20··version:·3.1.0.·0006fd80:·2020·7665·7273·696f·6e3a·2033·2e31·2e30····version:·3.1.0
0006fb10:·2020·2073·7973·7465·6d64·3a0a·2020·2020·····systemd:.····0006fd90:·0a20·2020·2073·7973·7465·6d64·3a0a·2020··.····systemd:.··
0006fb20:·2020·756e·6974·733a·0a20·2020·2020·202d····units:.······-0006fda0:·2020·2020·756e·6974·733a·0a20·2020·2020······units:.·····
0006fb30:·206e·616d·653a·2061·7070·6f72·742e·7365···name:·apport.se0006fdb0:·202d·206e·616d·653a·2061·7070·6f72·742e···-·name:·apport.
0006fb40:·7276·6963·650a·2020·2020·2020·2020·656e··rvice.········en0006fdc0:·7365·7276·6963·650a·2020·2020·2020·2020··service.········
0006fb50:·6162·6c65·643a·2066·616c·7365·0a20·2020··abled:·false.···0006fdd0:·656e·6162·6c65·643a·2066·616c·7365·0a20··enabled:·false.·
0006fb60:·2020·2020·206d·6173·6b3a·2074·7275·650a·······mask:·true.0006fde0:·2020·2020·2020·206d·6173·6b3a·2074·7275·········mask:·tru
0006fb70:·2020·2020·2020·2d20·6e61·6d65·3a20·6170········-·name:·ap0006fdf0:·650a·2020·2020·2020·2d20·6e61·6d65·3a20··e.······-·name:·
0006fb80:·706f·7274·2e73·6f63·6b65·740a·2020·2020··port.socket.····0006fe00:·6170·706f·7274·2e73·6f63·6b65·740a·2020··apport.socket.··
0006fb90:·2020·2020·656e·6162·6c65·643a·2066·616c······enabled:·fal0006fe10:·2020·2020·2020·656e·6162·6c65·643a·2066········enabled:·f
0006fba0:·7365·0a20·2020·2020·2020·206d·6173·6b3a··se.········mask:0006fe20:·616c·7365·0a20·2020·2020·2020·206d·6173··alse.········mas
0006fbb0:·2074·7275·650a·3c2f·636f·6465·3e3c·2f70···true.</code></p0006fe30:·6b3a·2074·7275·650a·3c2f·636f·6465·3e3c··k:·true.</code><
0006fbc0:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas 
0006fbd0:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe 
0006fbe0:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle= 
0006fbf0:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data- 
0006fc00:·7461·7267·6574·3d22·2369·646d·3230·3938··target="#idm2098 
0006fc10:·3422·2074·6162·696e·6465·783d·2230·2220··4"·tabindex="0"· 
0006fc20:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar 
0006fc30:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal 
0006fc40:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ 
0006fc50:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h 
0006fc60:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia 
0006fc70:·7469·6f6e·2050·7570·7065·7420·736e·6970··tion·Puppet·snip 
0006fc80:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br>< 
0006fc90:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel 
0006fca0:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap 
0006fcb0:·7365·2220·6964·3d22·6964·6d32·3039·3834··se"·id="idm20984 
0006fcc0:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class=" 
0006fcd0:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri 
0006fce0:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border 
0006fcf0:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens 
0006fd00:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp 
0006fd10:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td> 
0006fd20:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr 
0006fd30:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption: 
0006fd40:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td 
0006fd50:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re 
0006fd60:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa 
0006fd70:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr 
0006fd80:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</ 
0006fd90:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t 
0006fda0:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table>< 
0006fdb0:·7072·653e·3c63·6f64·653e·696e·636c·7564··pre><code>includ 
0006fdc0:·6520·6469·7361·626c·655f·6170·706f·7274··e·disable_apport 
0006fdd0:·0a0a·636c·6173·7320·6469·7361·626c·655f··..class·disable_ 
0006fde0:·6170·706f·7274·207b·0a20·2073·6572·7669··apport·{.··servi 
Max diff block lines reached; 414/12032 bytes (3.44%) of diff not shown.
1.84 KB
html2text {}
    
Offset 3686, 14 lines modifiedOffset 3686, 27 lines modified
3686 ··-·no_reboot_needed3686 ··-·no_reboot_needed
3687 ··-·service_apport_disabled3687 ··-·service_apport_disabled
3688 ··-·unknown_severity3688 ··-·unknown_severity
3689 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x83689 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
3690 [customizations.services]3690 [customizations.services]
3691 masked·=·["apport"]3691 masked·=·["apport"]
 3692 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 3693 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 3694 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 3695 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 3696 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 3697 include·disable_apport
  
 3698 class·disable_apport·{
 3699 ··service·{'apport':
 3700 ····enable·=>·false,
 3701 ····ensure·=>·'stopped',
 3702 ··}
 3703 }
3692 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x83704 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
3693 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low3705 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
3694 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium3706 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
3695 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true3707 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
3696 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable3708 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
3697 apiVersion:·machineconfiguration.openshift.io/v13709 apiVersion:·machineconfiguration.openshift.io/v1
3698 kind:·MachineConfig3710 kind:·MachineConfig
Offset 3705, 27 lines modifiedOffset 3718, 14 lines modified
3705 ······units:3718 ······units:
3706 ······-·name:·apport.service3719 ······-·name:·apport.service
3707 ········enabled:·false3720 ········enabled:·false
3708 ········mask:·true3721 ········mask:·true
3709 ······-·name:·apport.socket3722 ······-·name:·apport.socket
3710 ········enabled:·false3723 ········enabled:·false
3711 ········mask:·true3724 ········mask:·true
3712 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
3713 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
3714 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
3715 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
3716 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
3717 include·disable_apport 
  
3718 class·disable_apport·{ 
3719 ··service·{'apport': 
3720 ····enable·=>·false, 
3721 ····ensure·=>·'stopped', 
3722 ··} 
3723 } 
3724 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x83725 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
3725 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low3726 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
3726 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low3727 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
3727 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false3728 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
3728 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable3729 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
3729 #·Remediation·is·applicable·only·in·certain·platforms3730 #·Remediation·is·applicable·only·in·certain·platforms
3730 if·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'apport'·2>/dev/null·|3731 if·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'apport'·2>/dev/null·|
14.0 KB
./usr/share/doc/ssg-debderived/ssg-ubuntu2004-guide-stig.html
    
Offset 63383, 96 lines modifiedOffset 63383, 96 lines modified
000f7960:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="000f7960:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
000f7970:·2369·646d·3231·3337·3122·2074·6162·696e··#idm21371"·tabin000f7970:·2369·646d·3231·3337·3122·2074·6162·696e··#idm21371"·tabin
000f7980:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu000f7980:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
000f7990:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan000f7990:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
000f79a0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl000f79a0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
000f79b0:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r000f79b0:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
000f79c0:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"000f79c0:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
000f79d0:·3e52·656d·6564·6961·7469·6f6e·204b·7562··>Remediation·Kub000f79d0:·3e52·656d·6564·6961·7469·6f6e·2050·7570··>Remediation·Pup
000f79e0:·6572·6e65·7465·7320·736e·6970·7065·7420··ernetes·snippet·000f79e0:·7065·7420·736e·6970·7065·7420·e287·b23c··pet·snippet·...<
000f79f0:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·000f79f0:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas
000f7a00:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col000f7a00:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps
000f7a10:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·000f7a10:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="
000f7a20:·6964·3d22·6964·6d32·3133·3731·223e·3c74··id="idm21371"><t000f7a20:·6964·6d32·3133·3731·223e·3c74·6162·6c65··idm21371"><table
000f7a30:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl000f7a30:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta
000f7a40:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·000f7a40:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl
000f7a50:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t000f7a50:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table
000f7a60:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">000f7a60:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>
000f7a70:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi000f7a70:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<
000f7a80:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<000f7a80:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
000f7a90:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th000f7a90:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis
000f7aa0:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th000f7aa0:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td
000f7ab0:·3e3c·7464·3e6d·6564·6975·6d3c·2f74·643e··><td>medium</td>000f7ab0:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
 000f7ac0:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t
 000f7ad0:·683e·3c74·643e·6661·6c73·653c·2f74·643e··h><td>false</td>
000f7ac0:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb000f7ae0:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str
000f7ad0:·6f6f·743a·3c2f·7468·3e3c·7464·3e74·7275··oot:</th><td>tru000f7af0:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e
000f7ae0:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr><000f7b00:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr><
000f7af0:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th 
000f7b00:·3e3c·7464·3e64·6973·6162·6c65·3c2f·7464··><td>disable</td 
000f7b10:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p 
000f7b20:·7265·3e3c·636f·6465·3e61·7069·5665·7273··re><code>apiVers 
000f7b30:·696f·6e3a·206d·6163·6869·6e65·636f·6e66··ion:·machineconf 
000f7b40:·6967·7572·6174·696f·6e2e·6f70·656e·7368··iguration.opensh 
000f7b50:·6966·742e·696f·2f76·310a·6b69·6e64·3a20··ift.io/v1.kind:· 
000f7b60:·4d61·6368·696e·6543·6f6e·6669·670a·7370··MachineConfig.sp 
000f7b70:·6563·3a0a·2020·636f·6e66·6967·3a0a·2020··ec:.··config:.·· 
000f7b80:·2020·6967·6e69·7469·6f6e·3a0a·2020·2020····ignition:.····000f7b10:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod
 000f7b20:·653e·696e·636c·7564·6520·6469·7361·626c··e>include·disabl
 000f7b30:·655f·6b64·756d·702d·746f·6f6c·730a·0a63··e_kdump-tools..c
 000f7b40:·6c61·7373·2064·6973·6162·6c65·5f6b·6475··lass·disable_kdu
 000f7b50:·6d70·2d74·6f6f·6c73·207b·0a20·2073·6572··mp-tools·{.··ser
 000f7b60:·7669·6365·207b·276b·6475·6d70·2d74·6f6f··vice·{'kdump-too
 000f7b70:·6c73·273a·0a20·2020·2065·6e61·626c·6520··ls':.····enable·
 000f7b80:·3d26·6774·3b20·6661·6c73·652c·0a20·2020··=&gt;·false,.···
 000f7b90:·2065·6e73·7572·6520·3d26·6774·3b20·2773···ensure·=&gt;·'s
 000f7ba0:·746f·7070·6564·272c·0a20·207d·0a7d·0a3c··topped',.··}.}.<
 000f7bb0:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di
 000f7bc0:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn·
 000f7bd0:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat
 000f7be0:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap
 000f7bf0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
 000f7c00:·2223·6964·6d32·3133·3732·2220·7461·6269··"#idm21372"·tabi
 000f7c10:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
 000f7c20:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
 000f7c30:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
 000f7c40:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
 000f7c50:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
 000f7c60:·223e·5265·6d65·6469·6174·696f·6e20·4b75··">Remediation·Ku
 000f7c70:·6265·726e·6574·6573·2073·6e69·7070·6574··bernetes·snippet
 000f7c80:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
 000f7c90:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
 000f7ca0:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
 000f7cb0:·2069·643d·2269·646d·3231·3337·3222·3e3c···id="idm21372"><
 000f7cc0:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab
 000f7cd0:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped
 000f7ce0:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·
 000f7cf0:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"
 000f7d00:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex
 000f7d10:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low
 000f7d20:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
 000f7d30:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t
 000f7d40:·683e·3c74·643e·6d65·6469·756d·3c2f·7464··h><td>medium</td
 000f7d50:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re
 000f7d60:·626f·6f74·3a3c·2f74·683e·3c74·643e·7472··boot:</th><td>tr
 000f7d70:·7565·3c2f·7464·3e3c·2f74·723e·3c74·723e··ue</td></tr><tr>
 000f7d80:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t
 000f7d90:·683e·3c74·643e·6469·7361·626c·653c·2f74··h><td>disable</t
 000f7da0:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><
 000f7db0:·7072·653e·3c63·6f64·653e·6170·6956·6572··pre><code>apiVer
 000f7dc0:·7369·6f6e·3a20·6d61·6368·696e·6563·6f6e··sion:·machinecon
 000f7dd0:·6669·6775·7261·7469·6f6e·2e6f·7065·6e73··figuration.opens
 000f7de0:·6869·6674·2e69·6f2f·7631·0a6b·696e·643a··hift.io/v1.kind:
 000f7df0:·204d·6163·6869·6e65·436f·6e66·6967·0a73···MachineConfig.s
 000f7e00:·7065·633a·0a20·2063·6f6e·6669·673a·0a20··pec:.··config:.·
 000f7e10:·2020·2069·676e·6974·696f·6e3a·0a20·2020·····ignition:.···
000f7b90:·2020·7665·7273·696f·6e3a·2033·2e31·2e30····version:·3.1.0000f7e20:·2020·2076·6572·7369·6f6e·3a20·332e·312e·····version:·3.1.
000f7ba0:·0a20·2020·2073·7973·7465·6d64·3a0a·2020··.····systemd:.··000f7e30:·300a·2020·2020·7379·7374·656d·643a·0a20··0.····systemd:.·
000f7bb0:·2020·2020·756e·6974·733a·0a20·2020·2020······units:.·····000f7e40:·2020·2020·2075·6e69·7473·3a0a·2020·2020·······units:.····
000f7bc0:·202d·206e·616d·653a·206b·6475·6d70·2d74···-·name:·kdump-t 
000f7bd0:·6f6f·6c73·2e73·6572·7669·6365·0a20·2020··ools.service.··· 
000f7be0:·2020·2020·2065·6e61·626c·6564·3a20·6661·······enabled:·fa000f7e50:·2020·2d20·6e61·6d65·3a20·6b64·756d·702d····-·name:·kdump-
 000f7e60:·746f·6f6c·732e·7365·7276·6963·650a·2020··tools.service.··
 000f7e70:·2020·2020·2020·656e·6162·6c65·643a·2066········enabled:·f
000f7bf0:·6c73·650a·2020·2020·2020·2020·6d61·736b··lse.········mask000f7e80:·616c·7365·0a20·2020·2020·2020·206d·6173··alse.········mas
000f7c00:·3a20·7472·7565·0a20·2020·2020·202d·206e··:·true.······-·n000f7e90:·6b3a·2074·7275·650a·2020·2020·2020·2d20··k:·true.······-·
000f7c10:·616d·653a·206b·6475·6d70·2d74·6f6f·6c73··ame:·kdump-tools000f7ea0:·6e61·6d65·3a20·6b64·756d·702d·746f·6f6c··name:·kdump-tool
000f7c20:·2e73·6f63·6b65·740a·2020·2020·2020·2020··.socket.········000f7eb0:·732e·736f·636b·6574·0a20·2020·2020·2020··s.socket.·······
000f7c30:·656e·6162·6c65·643a·2066·616c·7365·0a20··enabled:·false.·000f7ec0:·2065·6e61·626c·6564·3a20·6661·6c73·650a···enabled:·false.
000f7c40:·2020·2020·2020·206d·6173·6b3a·2074·7275·········mask:·tru000f7ed0:·2020·2020·2020·2020·6d61·736b·3a20·7472··········mask:·tr
000f7c50:·650a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··e.</code></pre>< 
000f7c60:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b 
000f7c70:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"· 
000f7c80:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col 
000f7c90:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ 
000f7ca0:·6574·3d22·2369·646d·3231·3337·3222·2074··et="#idm21372"·t 
000f7cb0:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role 
000f7cc0:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e 
000f7cd0:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"· 
000f7ce0:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate· 
000f7cf0:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href= 
000f7d00:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation 
000f7d10:·2050·7570·7065·7420·736e·6970·7065·7420···Puppet·snippet· 
000f7d20:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div· 
000f7d30:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col 
000f7d40:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"· 
000f7d50:·6964·3d22·6964·6d32·3133·3732·223e·3c74··id="idm21372"><t 
000f7d60:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl 
000f7d70:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped· 
000f7d80:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t 
000f7d90:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed"> 
000f7da0:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi 
000f7db0:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low< 
000f7dc0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
000f7dd0:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th 
000f7de0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t 
000f7df0:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot 
000f7e00:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false< 
Max diff block lines reached; 414/12308 bytes (3.36%) of diff not shown.
1.87 KB
html2text {}
    
Offset 11424, 14 lines modifiedOffset 11424, 27 lines modified
11424 ··-·medium_severity11424 ··-·medium_severity
11425 ··-·no_reboot_needed11425 ··-·no_reboot_needed
11426 ··-·service_kdump_disabled11426 ··-·service_kdump_disabled
11427 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x811427 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
11428 [customizations.services]11428 [customizations.services]
11429 masked·=·["kdump-tools"]11429 masked·=·["kdump-tools"]
 11430 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 11431 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 11432 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 11433 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 11434 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 11435 include·disable_kdump-tools
  
 11436 class·disable_kdump-tools·{
 11437 ··service·{'kdump-tools':
 11438 ····enable·=>·false,
 11439 ····ensure·=>·'stopped',
 11440 ··}
 11441 }
11430 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x811442 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
11431 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low11443 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
11432 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium11444 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
11433 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true11445 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
11434 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable11446 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
11435 apiVersion:·machineconfiguration.openshift.io/v111447 apiVersion:·machineconfiguration.openshift.io/v1
11436 kind:·MachineConfig11448 kind:·MachineConfig
Offset 11443, 27 lines modifiedOffset 11456, 14 lines modified
11443 ······units:11456 ······units:
11444 ······-·name:·kdump-tools.service11457 ······-·name:·kdump-tools.service
11445 ········enabled:·false11458 ········enabled:·false
11446 ········mask:·true11459 ········mask:·true
11447 ······-·name:·kdump-tools.socket11460 ······-·name:·kdump-tools.socket
11448 ········enabled:·false11461 ········enabled:·false
11449 ········mask:·true11462 ········mask:·true
11450 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
11451 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
11452 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
11453 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
11454 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
11455 include·disable_kdump-tools 
  
11456 class·disable_kdump-tools·{ 
11457 ··service·{'kdump-tools': 
11458 ····enable·=>·false, 
11459 ····ensure·=>·'stopped', 
11460 ··} 
11461 } 
11462 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x811463 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
11463 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low11464 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
11464 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low11465 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
11465 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false11466 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
11466 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable11467 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
11467 #·Remediation·is·applicable·only·in·certain·platforms11468 #·Remediation·is·applicable·only·in·certain·platforms
11468 if·dpkg-query·--show·--showformat='${db:Status-Status}11469 if·dpkg-query·--show·--showformat='${db:Status-Status}
54.5 KB
./usr/share/doc/ssg-debderived/ssg-ubuntu2204-guide-cis_level1_server.html
    
Offset 90179, 94 lines modifiedOffset 90179, 94 lines modified
00160420:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=00160420:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
00160430:·2223·6964·6d31·3938·3837·2220·7461·6269··"#idm19887"·tabi00160430:·2223·6964·6d31·3938·3837·2220·7461·6269··"#idm19887"·tabi
00160440:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b00160440:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
00160450:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa00160450:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
00160460:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit00160460:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
00160470:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·00160470:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
00160480:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!00160480:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
00160490:·223e·5265·6d65·6469·6174·696f·6e20·4b75··">Remediation·Ku00160490:·223e·5265·6d65·6469·6174·696f·6e20·5075··">Remediation·Pu
001604a0:·6265·726e·6574·6573·2073·6e69·7070·6574··bernetes·snippet001604a0:·7070·6574·2073·6e69·7070·6574·20e2·87b2··ppet·snippet·...
001604b0:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div001604b0:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
001604c0:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co001604c0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
001604d0:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"001604d0:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
001604e0:·2069·643d·2269·646d·3139·3838·3722·3e3c···id="idm19887"><001604e0:·2269·646d·3139·3838·3722·3e3c·7461·626c··"idm19887"><tabl
001604f0:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab001604f0:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t
00160500:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped00160500:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab
00160510:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·00160510:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl
00160520:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"00160520:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr
00160530:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex00160530:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:
00160540:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low00160540:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
00160550:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
00160560:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t 
00160570:·683e·3c74·643e·6d65·6469·756d·3c2f·7464··h><td>medium</td 
00160580:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re00160550:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di
 00160560:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t
 00160570:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
 00160580:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</
 00160590:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td
 001605a0:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St
00160590:·626f·6f74·3a3c·2f74·683e·3c74·643e·7472··boot:</th><td>tr001605b0:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>
 001605c0:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr>
 001605d0:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co
 001605e0:·6465·3e69·6e63·6c75·6465·2064·6973·6162··de>include·disab
 001605f0:·6c65·5f61·7574·6f66·730a·0a63·6c61·7373··le_autofs..class
 00160600:·2064·6973·6162·6c65·5f61·7574·6f66·7320···disable_autofs·
 00160610:·7b0a·2020·7365·7276·6963·6520·7b27·6175··{.··service·{'au
 00160620:·746f·6673·273a·0a20·2020·2065·6e61·626c··tofs':.····enabl
 00160630:·6520·3d26·6774·3b20·6661·6c73·652c·0a20··e·=&gt;·false,.·
 00160640:·2020·2065·6e73·7572·6520·3d26·6774·3b20·····ensure·=&gt;·
 00160650:·2773·746f·7070·6564·272c·0a20·207d·0a7d··'stopped',.··}.}
 00160660:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></
 00160670:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt
 00160680:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d
 00160690:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll
 001606a0:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
 001606b0:·743d·2223·6964·6d31·3938·3838·2220·7461··t="#idm19888"·ta
 001606c0:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
 001606d0:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
 001606e0:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
 001606f0:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
 00160700:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
 00160710:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
 00160720:·4b75·6265·726e·6574·6573·2073·6e69·7070··Kubernetes·snipp
 00160730:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d
 00160740:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-
 00160750:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps
 00160760:·6522·2069·643d·2269·646d·3139·3838·3822··e"·id="idm19888"
 00160770:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t
 00160780:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip
 00160790:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere
 001607a0:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense
 001607b0:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl
 001607c0:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l
001605a0:·7565·3c2f·7464·3e3c·2f74·723e·3c74·723e··ue</td></tr><tr>001607d0:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
 001607e0:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:<
 001607f0:·2f74·683e·3c74·643e·6d65·6469·756d·3c2f··/th><td>medium</
 00160800:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 00160810:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td>
 00160820:·7472·7565·3c2f·7464·3e3c·2f74·723e·3c74··true</td></tr><t
001605b0:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t00160830:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<
001605c0:·683e·3c74·643e·6469·7361·626c·653c·2f74··h><td>disable</t00160840:·2f74·683e·3c74·643e·6469·7361·626c·653c··/th><td>disable<
001605d0:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><00160850:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table
001605e0:·7072·653e·3c63·6f64·653e·6170·6956·6572··pre><code>apiVer00160860:·3e3c·7072·653e·3c63·6f64·653e·6170·6956··><pre><code>apiV
001605f0:·7369·6f6e·3a20·6d61·6368·696e·6563·6f6e··sion:·machinecon00160870:·6572·7369·6f6e·3a20·6d61·6368·696e·6563··ersion:·machinec
00160600:·6669·6775·7261·7469·6f6e·2e6f·7065·6e73··figuration.opens00160880:·6f6e·6669·6775·7261·7469·6f6e·2e6f·7065··onfiguration.ope
00160610:·6869·6674·2e69·6f2f·7631·0a6b·696e·643a··hift.io/v1.kind:00160890:·6e73·6869·6674·2e69·6f2f·7631·0a6b·696e··nshift.io/v1.kin
00160620:·204d·6163·6869·6e65·436f·6e66·6967·0a73···MachineConfig.s001608a0:·643a·204d·6163·6869·6e65·436f·6e66·6967··d:·MachineConfig
00160630:·7065·633a·0a20·2063·6f6e·6669·673a·0a20··pec:.··config:.·001608b0:·0a73·7065·633a·0a20·2063·6f6e·6669·673a··.spec:.··config:
00160640:·2020·2069·676e·6974·696f·6e3a·0a20·2020·····ignition:.···001608c0:·0a20·2020·2069·676e·6974·696f·6e3a·0a20··.····ignition:.·
00160650:·2020·2076·6572·7369·6f6e·3a20·332e·312e·····version:·3.1.001608d0:·2020·2020·2076·6572·7369·6f6e·3a20·332e·······version:·3.
00160660:·300a·2020·2020·7379·7374·656d·643a·0a20··0.····systemd:.·001608e0:·312e·300a·2020·2020·7379·7374·656d·643a··1.0.····systemd:
00160670:·2020·2020·2075·6e69·7473·3a0a·2020·2020·······units:.····001608f0:·0a20·2020·2020·2075·6e69·7473·3a0a·2020··.······units:.··
00160680:·2020·2d20·6e61·6d65·3a20·6175·746f·6673····-·name:·autofs00160900:·2020·2020·2d20·6e61·6d65·3a20·6175·746f······-·name:·auto
00160690:·2e73·6572·7669·6365·0a20·2020·2020·2020··.service.·······00160910:·6673·2e73·6572·7669·6365·0a20·2020·2020··fs.service.·····
001606a0:·2065·6e61·626c·6564·3a20·6661·6c73·650a···enabled:·false.00160920:·2020·2065·6e61·626c·6564·3a20·6661·6c73·····enabled:·fals
001606b0:·2020·2020·2020·2020·6d61·736b·3a20·7472··········mask:·tr00160930:·650a·2020·2020·2020·2020·6d61·736b·3a20··e.········mask:·
001606c0:·7565·0a20·2020·2020·202d·206e·616d·653a··ue.······-·name:00160940:·7472·7565·0a20·2020·2020·202d·206e·616d··true.······-·nam
001606d0:·2061·7574·6f66·732e·736f·636b·6574·0a20···autofs.socket.·00160950:·653a·2061·7574·6f66·732e·736f·636b·6574··e:·autofs.socket
001606e0:·2020·2020·2020·2065·6e61·626c·6564·3a20·········enabled:·00160960:·0a20·2020·2020·2020·2065·6e61·626c·6564··.········enabled
001606f0:·6661·6c73·650a·2020·2020·2020·2020·6d61··false.········ma00160970:·3a20·6661·6c73·650a·2020·2020·2020·2020··:·false.········
00160700:·736b·3a20·7472·7565·0a3c·2f63·6f64·653e··sk:·true.</code>00160980:·6d61·736b·3a20·7472·7565·0a3c·2f63·6f64··mask:·true.</cod
00160710:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c 
00160720:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su 
00160730:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg 
00160740:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da 
00160750:·7461·2d74·6172·6765·743d·2223·6964·6d31··ta-target="#idm1 
00160760:·3938·3838·2220·7461·6269·6e64·6578·3d22··9888"·tabindex=" 
00160770:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button" 
00160780:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded=" 
00160790:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac 
001607a0:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal 
001607b0:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme 
001607c0:·6469·6174·696f·6e20·5075·7070·6574·2073··diation·Puppet·s 
001607d0:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b 
001607e0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa 
001607f0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col 
00160800:·6c61·7073·6522·2069·643d·2269·646d·3139··lapse"·id="idm19 
00160810:·3838·3822·3e3c·7461·626c·6520·636c·6173··888"><table·clas 
00160820:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s 
00160830:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor 
00160840:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond 
00160850:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C 
00160860:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th>< 
00160870:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
00160880:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti 
00160890:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low< 
001608a0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
001608b0:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td 
001608c0:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr> 
001608d0:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy 
001608e0:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable 
001608f0:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl 
00160900:·653e·3c70·7265·3e3c·636f·6465·3e69·6e63··e><pre><code>inc 
00160910:·6c75·6465·2064·6973·6162·6c65·5f61·7574··lude·disable_aut 
00160920:·6f66·730a·0a63·6c61·7373·2064·6973·6162··ofs..class·disab 
00160930:·6c65·5f61·7574·6f66·7320·7b0a·2020·7365··le_autofs·{.··se 
00160940:·7276·6963·6520·7b27·6175·746f·6673·273a··rvice·{'autofs': 
00160950:·0a20·2020·2065·6e61·626c·6520·3d26·6774··.····enable·=&gt 
Max diff block lines reached; 36516/48134 bytes (75.86%) of diff not shown.
7.37 KB
html2text {}
    
Offset 17677, 14 lines modifiedOffset 17677, 27 lines modified
17677 ··-·medium_severity17677 ··-·medium_severity
17678 ··-·no_reboot_needed17678 ··-·no_reboot_needed
17679 ··-·service_autofs_disabled17679 ··-·service_autofs_disabled
17680 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x817680 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
17681 [customizations.services]17681 [customizations.services]
17682 masked·=·["autofs"]17682 masked·=·["autofs"]
 17683 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 17684 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 17685 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 17686 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 17687 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 17688 include·disable_autofs
  
 17689 class·disable_autofs·{
 17690 ··service·{'autofs':
 17691 ····enable·=>·false,
 17692 ····ensure·=>·'stopped',
 17693 ··}
 17694 }
17683 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x817695 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
17684 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low17696 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
17685 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium17697 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
17686 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true17698 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
17687 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable17699 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
17688 apiVersion:·machineconfiguration.openshift.io/v117700 apiVersion:·machineconfiguration.openshift.io/v1
17689 kind:·MachineConfig17701 kind:·MachineConfig
Offset 17696, 27 lines modifiedOffset 17709, 14 lines modified
17696 ······units:17709 ······units:
17697 ······-·name:·autofs.service17710 ······-·name:·autofs.service
17698 ········enabled:·false17711 ········enabled:·false
17699 ········mask:·true17712 ········mask:·true
17700 ······-·name:·autofs.socket17713 ······-·name:·autofs.socket
17701 ········enabled:·false17714 ········enabled:·false
17702 ········mask:·true17715 ········mask:·true
17703 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
17704 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
17705 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
17706 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
17707 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
17708 include·disable_autofs 
  
17709 class·disable_autofs·{ 
17710 ··service·{'autofs': 
17711 ····enable·=>·false, 
17712 ····ensure·=>·'stopped', 
17713 ··} 
17714 } 
17715 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x817716 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
17716 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low17717 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
17717 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low17718 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
17718 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false17719 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
17719 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable17720 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
17720 #·Remediation·is·applicable·only·in·certain·platforms17721 #·Remediation·is·applicable·only·in·certain·platforms
17721 if·(·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'autofs'·2>/dev/null·|·grep·-17722 if·(·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'autofs'·2>/dev/null·|·grep·-
Offset 22443, 14 lines modifiedOffset 22443, 27 lines modified
22443 ··-·no_reboot_needed22443 ··-·no_reboot_needed
22444 ··-·service_apport_disabled22444 ··-·service_apport_disabled
22445 ··-·unknown_severity22445 ··-·unknown_severity
22446 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x822446 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
22447 [customizations.services]22447 [customizations.services]
22448 masked·=·["apport"]22448 masked·=·["apport"]
 22449 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 22450 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 22451 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 22452 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 22453 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 22454 include·disable_apport
  
 22455 class·disable_apport·{
 22456 ··service·{'apport':
 22457 ····enable·=>·false,
 22458 ····ensure·=>·'stopped',
 22459 ··}
 22460 }
22449 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x822461 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
22450 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low22462 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
22451 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium22463 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
22452 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true22464 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
22453 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable22465 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
22454 apiVersion:·machineconfiguration.openshift.io/v122466 apiVersion:·machineconfiguration.openshift.io/v1
22455 kind:·MachineConfig22467 kind:·MachineConfig
Offset 22462, 27 lines modifiedOffset 22475, 14 lines modified
22462 ······units:22475 ······units:
22463 ······-·name:·apport.service22476 ······-·name:·apport.service
22464 ········enabled:·false22477 ········enabled:·false
22465 ········mask:·true22478 ········mask:·true
22466 ······-·name:·apport.socket22479 ······-·name:·apport.socket
22467 ········enabled:·false22480 ········enabled:·false
22468 ········mask:·true22481 ········mask:·true
22469 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
22470 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
22471 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
22472 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
22473 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
22474 include·disable_apport 
  
22475 class·disable_apport·{ 
22476 ··service·{'apport': 
22477 ····enable·=>·false, 
22478 ····ensure·=>·'stopped', 
22479 ··} 
22480 } 
22481 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x822482 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
22482 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low22483 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
22483 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low22484 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
22484 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false22485 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
22485 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable22486 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
22486 #·Remediation·is·applicable·only·in·certain·platforms22487 #·Remediation·is·applicable·only·in·certain·platforms
22487 if·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'apport'·2>/dev/null·|·grep·-22488 if·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'apport'·2>/dev/null·|·grep·-
Offset 22714, 14 lines modifiedOffset 22714, 27 lines modified
22714 ··-·medium_severity22714 ··-·medium_severity
22715 ··-·no_reboot_needed22715 ··-·no_reboot_needed
22716 ··-·service_avahi-daemon_disabled22716 ··-·service_avahi-daemon_disabled
22717 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x822717 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
22718 [customizations.services]22718 [customizations.services]
22719 masked·=·["avahi-daemon"]22719 masked·=·["avahi-daemon"]
 22720 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 22721 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 22722 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 22723 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 22724 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 22725 include·disable_avahi-daemon
  
 22726 class·disable_avahi-daemon·{
Max diff block lines reached; 3008/7519 bytes (40.01%) of diff not shown.
27.5 KB
./usr/share/doc/ssg-debderived/ssg-ubuntu2204-guide-cis_level1_workstation.html
    
Offset 102926, 94 lines modifiedOffset 102926, 94 lines modified
001920d0:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id001920d0:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
001920e0:·6d32·3231·3732·2220·7461·6269·6e64·6578··m22172"·tabindex001920e0:·6d32·3231·3732·2220·7461·6269·6e64·6578··m22172"·tabindex
001920f0:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto001920f0:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto
00192100:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded00192100:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded
00192110:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="00192110:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="
00192120:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve00192120:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve
00192130:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re00192130:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re
 00192140:·6d65·6469·6174·696f·6e20·5075·7070·6574··mediation·Puppet
 00192150:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>
 00192160:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="
 00192170:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c
 00192180:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm
 00192190:·3232·3137·3222·3e3c·7461·626c·6520·636c··22172"><table·cl
 001921a0:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table
 001921b0:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b
 001921c0:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co
 001921d0:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th
 001921e0:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th
 001921f0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
 00192200:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup
 00192210:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo
 00192220:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
 00192230:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th><
 00192240:·7464·3e66·616c·7365·3c2f·7464·3e3c·2f74··td>false</td></t
 00192250:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate
 00192260:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab
 00192270:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta
 00192280:·626c·653e·3c70·7265·3e3c·636f·6465·3e69··ble><pre><code>i
 00192290:·6e63·6c75·6465·2064·6973·6162·6c65·5f61··nclude·disable_a
 001922a0:·7070·6f72·740a·0a63·6c61·7373·2064·6973··pport..class·dis
 001922b0:·6162·6c65·5f61·7070·6f72·7420·7b0a·2020··able_apport·{.··
 001922c0:·7365·7276·6963·6520·7b27·6170·706f·7274··service·{'apport
 001922d0:·273a·0a20·2020·2065·6e61·626c·6520·3d26··':.····enable·=&
 001922e0:·6774·3b20·6661·6c73·652c·0a20·2020·2065··gt;·false,.····e
 001922f0:·6e73·7572·6520·3d26·6774·3b20·2773·746f··nsure·=&gt;·'sto
 00192300:·7070·6564·272c·0a20·207d·0a7d·0a3c·2f63··pped',.··}.}.</c
 00192310:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div>
 00192320:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt
 00192330:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data-
 00192340:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse
 00192350:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
 00192360:·6964·6d32·3231·3733·2220·7461·6269·6e64··idm22173"·tabind
 00192370:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
 00192380:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
 00192390:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
 001923a0:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
 001923b0:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
00192140:·6d65·6469·6174·696f·6e20·4b75·6265·726e··mediation·Kubern001923c0:·5265·6d65·6469·6174·696f·6e20·4b75·6265··Remediation·Kube
00192150:·6574·6573·2073·6e69·7070·6574·20e2·87b2··etes·snippet·...001923d0:·726e·6574·6573·2073·6e69·7070·6574·20e2··rnetes·snippet·.
00192160:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla001923e0:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c
00192170:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap001923f0:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
00192180:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=00192400:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
00192190:·2269·646d·3232·3137·3222·3e3c·7461·626c··"idm22172"><tabl00192410:·643d·2269·646d·3232·3137·3322·3e3c·7461··d="idm22173"><ta
001921a0:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t00192420:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table
001921b0:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab00192430:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t
001921c0:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl00192440:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta
001921d0:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr00192450:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><
001921e0:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:00192460:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit
001921f0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td00192470:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</
00192200:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di 
00192210:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t 
00192220:·643e·6d65·6469·756d·3c2f·7464·3e3c·2f74··d>medium</td></t 
00192230:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot 
00192240:·3a3c·2f74·683e·3c74·643e·7472·7565·3c2f··:</th><td>true</ 
00192250:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>00192480:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 00192490:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th>
 001924a0:·3c74·643e·6d65·6469·756d·3c2f·7464·3e3c··<td>medium</td><
 001924b0:·2f74·723e·3c74·723e·3c74·683e·5265·626f··/tr><tr><th>Rebo
 001924c0:·6f74·3a3c·2f74·683e·3c74·643e·7472·7565··ot:</th><td>true
 001924d0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
00192260:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t001924e0:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th>
00192270:·643e·6469·7361·626c·653c·2f74·643e·3c2f··d>disable</td></001924f0:·3c74·643e·6469·7361·626c·653c·2f74·643e··<td>disable</td>
00192280:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>00192500:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr
00192290:·3c63·6f64·653e·6170·6956·6572·7369·6f6e··<code>apiVersion00192510:·653e·3c63·6f64·653e·6170·6956·6572·7369··e><code>apiVersi
001922a0:·3a20·6d61·6368·696e·6563·6f6e·6669·6775··:·machineconfigu00192520:·6f6e·3a20·6d61·6368·696e·6563·6f6e·6669··on:·machineconfi
001922b0:·7261·7469·6f6e·2e6f·7065·6e73·6869·6674··ration.openshift00192530:·6775·7261·7469·6f6e·2e6f·7065·6e73·6869··guration.openshi
001922c0:·2e69·6f2f·7631·0a6b·696e·643a·204d·6163··.io/v1.kind:·Mac00192540:·6674·2e69·6f2f·7631·0a6b·696e·643a·204d··ft.io/v1.kind:·M
001922d0:·6869·6e65·436f·6e66·6967·0a73·7065·633a··hineConfig.spec:00192550:·6163·6869·6e65·436f·6e66·6967·0a73·7065··achineConfig.spe
001922e0:·0a20·2063·6f6e·6669·673a·0a20·2020·2069··.··config:.····i00192560:·633a·0a20·2063·6f6e·6669·673a·0a20·2020··c:.··config:.···
001922f0:·676e·6974·696f·6e3a·0a20·2020·2020·2076··gnition:.······v00192570:·2069·676e·6974·696f·6e3a·0a20·2020·2020···ignition:.·····
00192300:·6572·7369·6f6e·3a20·332e·312e·300a·2020··ersion:·3.1.0.··00192580:·2076·6572·7369·6f6e·3a20·332e·312e·300a···version:·3.1.0.
00192310:·2020·7379·7374·656d·643a·0a20·2020·2020····systemd:.·····00192590:·2020·2020·7379·7374·656d·643a·0a20·2020······systemd:.···
00192320:·2075·6e69·7473·3a0a·2020·2020·2020·2d20···units:.······-·001925a0:·2020·2075·6e69·7473·3a0a·2020·2020·2020·····units:.······
00192330:·6e61·6d65·3a20·6170·706f·7274·2e73·6572··name:·apport.ser001925b0:·2d20·6e61·6d65·3a20·6170·706f·7274·2e73··-·name:·apport.s
00192340:·7669·6365·0a20·2020·2020·2020·2065·6e61··vice.········ena001925c0:·6572·7669·6365·0a20·2020·2020·2020·2065··ervice.········e
00192350:·626c·6564·3a20·6661·6c73·650a·2020·2020··bled:·false.····001925d0:·6e61·626c·6564·3a20·6661·6c73·650a·2020··nabled:·false.··
00192360:·2020·2020·6d61·736b·3a20·7472·7565·0a20······mask:·true.·001925e0:·2020·2020·2020·6d61·736b·3a20·7472·7565········mask:·true
00192370:·2020·2020·202d·206e·616d·653a·2061·7070·······-·name:·app001925f0:·0a20·2020·2020·202d·206e·616d·653a·2061··.······-·name:·a
00192380:·6f72·742e·736f·636b·6574·0a20·2020·2020··ort.socket.·····00192600:·7070·6f72·742e·736f·636b·6574·0a20·2020··pport.socket.···
00192390:·2020·2065·6e61·626c·6564·3a20·6661·6c73·····enabled:·fals00192610:·2020·2020·2065·6e61·626c·6564·3a20·6661·······enabled:·fa
001923a0:·650a·2020·2020·2020·2020·6d61·736b·3a20··e.········mask:·00192620:·6c73·650a·2020·2020·2020·2020·6d61·736b··lse.········mask
001923b0:·7472·7565·0a3c·2f63·6f64·653e·3c2f·7072··true.</code></pr00192630:·3a20·7472·7565·0a3c·2f63·6f64·653e·3c2f··:·true.</code></
001923c0:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class 
001923d0:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes 
001923e0:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle=" 
001923f0:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t 
00192400:·6172·6765·743d·2223·6964·6d32·3231·3733··arget="#idm22173 
00192410:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r 
00192420:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari 
00192430:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals 
00192440:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa 
00192450:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr 
00192460:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat 
00192470:·696f·6e20·5075·7070·6574·2073·6e69·7070··ion·Puppet·snipp 
00192480:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d 
00192490:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel- 
001924a0:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps 
001924b0:·6522·2069·643d·2269·646d·3232·3137·3322··e"·id="idm22173" 
001924c0:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t 
001924d0:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip 
001924e0:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere 
001924f0:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense 
00192500:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl 
00192510:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l 
00192520:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr> 
00192530:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:< 
00192540:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td> 
00192550:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb 
00192560:·6f6f·743a·3c2f·7468·3e3c·7464·3e66·616c··oot:</th><td>fal 
00192570:·7365·3c2f·7464·3e3c·2f74·723e·3c74·723e··se</td></tr><tr> 
00192580:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t 
00192590:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td 
001925a0:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p 
001925b0:·7265·3e3c·636f·6465·3e69·6e63·6c75·6465··re><code>include 
001925c0:·2064·6973·6162·6c65·5f61·7070·6f72·740a···disable_apport. 
001925d0:·0a63·6c61·7373·2064·6973·6162·6c65·5f61··.class·disable_a 
001925e0:·7070·6f72·7420·7b0a·2020·7365·7276·6963··pport·{.··servic 
Max diff block lines reached; 12586/24206 bytes (52.00%) of diff not shown.
3.75 KB
html2text {}
    
Offset 21676, 14 lines modifiedOffset 21676, 27 lines modified
21676 ··-·no_reboot_needed21676 ··-·no_reboot_needed
21677 ··-·service_apport_disabled21677 ··-·service_apport_disabled
21678 ··-·unknown_severity21678 ··-·unknown_severity
21679 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x821679 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
21680 [customizations.services]21680 [customizations.services]
21681 masked·=·["apport"]21681 masked·=·["apport"]
 21682 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 21683 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 21684 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 21685 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 21686 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 21687 include·disable_apport
  
 21688 class·disable_apport·{
 21689 ··service·{'apport':
 21690 ····enable·=>·false,
 21691 ····ensure·=>·'stopped',
 21692 ··}
 21693 }
21682 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x821694 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
21683 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low21695 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
21684 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium21696 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
21685 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true21697 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
21686 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable21698 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
21687 apiVersion:·machineconfiguration.openshift.io/v121699 apiVersion:·machineconfiguration.openshift.io/v1
21688 kind:·MachineConfig21700 kind:·MachineConfig
Offset 21695, 27 lines modifiedOffset 21708, 14 lines modified
21695 ······units:21708 ······units:
21696 ······-·name:·apport.service21709 ······-·name:·apport.service
21697 ········enabled:·false21710 ········enabled:·false
21698 ········mask:·true21711 ········mask:·true
21699 ······-·name:·apport.socket21712 ······-·name:·apport.socket
21700 ········enabled:·false21713 ········enabled:·false
21701 ········mask:·true21714 ········mask:·true
21702 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
21703 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
21704 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
21705 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
21706 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
21707 include·disable_apport 
  
21708 class·disable_apport·{ 
21709 ··service·{'apport': 
21710 ····enable·=>·false, 
21711 ····ensure·=>·'stopped', 
21712 ··} 
21713 } 
21714 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x821715 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
21715 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low21716 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
21716 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low21717 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
21717 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false21718 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
21718 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable21719 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
21719 #·Remediation·is·applicable·only·in·certain·platforms21720 #·Remediation·is·applicable·only·in·certain·platforms
21720 if·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'apport'·2>/dev/null·|·grep·-21721 if·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'apport'·2>/dev/null·|·grep·-
Offset 21947, 14 lines modifiedOffset 21947, 27 lines modified
21947 ··-·medium_severity21947 ··-·medium_severity
21948 ··-·no_reboot_needed21948 ··-·no_reboot_needed
21949 ··-·service_avahi-daemon_disabled21949 ··-·service_avahi-daemon_disabled
21950 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x821950 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
21951 [customizations.services]21951 [customizations.services]
21952 masked·=·["avahi-daemon"]21952 masked·=·["avahi-daemon"]
 21953 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 21954 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 21955 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 21956 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 21957 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 21958 include·disable_avahi-daemon
  
 21959 class·disable_avahi-daemon·{
 21960 ··service·{'avahi-daemon':
 21961 ····enable·=>·false,
 21962 ····ensure·=>·'stopped',
 21963 ··}
 21964 }
21953 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x821965 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
21954 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low21966 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
21955 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium21967 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
21956 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true21968 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
21957 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable21969 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
21958 apiVersion:·machineconfiguration.openshift.io/v121970 apiVersion:·machineconfiguration.openshift.io/v1
21959 kind:·MachineConfig21971 kind:·MachineConfig
Offset 21966, 27 lines modifiedOffset 21979, 14 lines modified
21966 ······units:21979 ······units:
21967 ······-·name:·avahi-daemon.service21980 ······-·name:·avahi-daemon.service
21968 ········enabled:·false21981 ········enabled:·false
21969 ········mask:·true21982 ········mask:·true
21970 ······-·name:·avahi-daemon.socket21983 ······-·name:·avahi-daemon.socket
21971 ········enabled:·false21984 ········enabled:·false
21972 ········mask:·true21985 ········mask:·true
21973 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
21974 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
21975 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
21976 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
21977 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
21978 include·disable_avahi-daemon 
  
21979 class·disable_avahi-daemon·{ 
21980 ··service·{'avahi-daemon': 
21981 ····enable·=>·false, 
21982 ····ensure·=>·'stopped', 
21983 ··} 
21984 } 
21985 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x821986 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
21986 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low21987 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
21987 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low21988 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
21988 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false21989 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
21989 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable21990 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
21990 #·Remediation·is·applicable·only·in·certain·platforms21991 #·Remediation·is·applicable·only·in·certain·platforms
21991 if·(·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'avahi-daemon'·2>/dev/null·|·grep·-21992 if·(·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'avahi-daemon'·2>/dev/null·|·grep·-
54.5 KB
./usr/share/doc/ssg-debderived/ssg-ubuntu2204-guide-cis_level2_server.html
    
Offset 94217, 93 lines modifiedOffset 94217, 93 lines modified
00170080:·6172·6765·743d·2223·6964·6d31·3938·3837··arget="#idm1988700170080:·6172·6765·743d·2223·6964·6d31·3938·3837··arget="#idm19887
00170090:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r00170090:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r
001700a0:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari001700a0:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari
001700b0:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals001700b0:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals
001700c0:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa001700c0:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa
001700d0:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr001700d0:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr
001700e0:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat001700e0:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat
001700f0:·696f·6e20·4b75·6265·726e·6574·6573·2073··ion·Kubernetes·s001700f0:·696f·6e20·5075·7070·6574·2073·6e69·7070··ion·Puppet·snipp
00170100:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b00170100:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d
00170110:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa00170110:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-
00170120:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col00170120:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps
00170130:·6c61·7073·6522·2069·643d·2269·646d·3139··lapse"·id="idm1900170130:·6522·2069·643d·2269·646d·3139·3838·3722··e"·id="idm19887"
00170140:·3838·3722·3e3c·7461·626c·6520·636c·6173··887"><table·clas00170140:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t
00170150:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s00170150:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip
00170160:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor00170160:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere
00170170:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond00170170:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense
00170180:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C00170180:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl
00170190:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><00170190:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l
001701a0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>001701a0:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
001701b0:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti001701b0:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:<
001701c0:·6f6e·3a3c·2f74·683e·3c74·643e·6d65·6469··on:</th><td>medi001701c0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
 001701d0:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb
 001701e0:·6f6f·743a·3c2f·7468·3e3c·7464·3e66·616c··oot:</th><td>fal
001701d0:·756d·3c2f·7464·3e3c·2f74·723e·3c74·723e··um</td></tr><tr>001701f0:·7365·3c2f·7464·3e3c·2f74·723e·3c74·723e··se</td></tr><tr>
 00170200:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t
 00170210:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td
 00170220:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p
 00170230:·7265·3e3c·636f·6465·3e69·6e63·6c75·6465··re><code>include
001701e0:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th> 
001701f0:·3c74·643e·7472·7565·3c2f·7464·3e3c·2f74··<td>true</td></t 
00170200:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate 
00170210:·6779·3a3c·2f74·683e·3c74·643e·6469·7361··gy:</th><td>disa 
00170220:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t 
00170230:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code> 
00170240:·6170·6956·6572·7369·6f6e·3a20·6d61·6368··apiVersion:·mach 
00170250:·696e·6563·6f6e·6669·6775·7261·7469·6f6e··ineconfiguration 
00170260:·2e6f·7065·6e73·6869·6674·2e69·6f2f·7631··.openshift.io/v1 
00170270:·0a6b·696e·643a·204d·6163·6869·6e65·436f··.kind:·MachineCo 
00170280:·6e66·6967·0a73·7065·633a·0a20·2063·6f6e··nfig.spec:.··con 
00170290:·6669·673a·0a20·2020·2069·676e·6974·696f··fig:.····ignitio 
001702a0:·6e3a·0a20·2020·2020·2076·6572·7369·6f6e··n:.······version 
001702b0:·3a20·332e·312e·300a·2020·2020·7379·7374··:·3.1.0.····syst 
001702c0:·656d·643a·0a20·2020·2020·2075·6e69·7473··emd:.······units 
001702d0:·3a0a·2020·2020·2020·2d20·6e61·6d65·3a20··:.······-·name:· 
001702e0:·6175·746f·6673·2e73·6572·7669·6365·0a20··autofs.service.· 
001702f0:·2020·2020·2020·2065·6e61·626c·6564·3a20·········enabled:· 
00170300:·6661·6c73·650a·2020·2020·2020·2020·6d61··false.········ma 
00170310:·736b·3a20·7472·7565·0a20·2020·2020·202d··sk:·true.······- 
00170320:·206e·616d·653a·2061·7574·6f66·732e·736f···name:·autofs.so 
00170330:·636b·6574·0a20·2020·2020·2020·2065·6e61··cket.········ena 
00170340:·626c·6564·3a20·6661·6c73·650a·2020·2020··bled:·false.···· 
00170350:·2020·2020·6d61·736b·3a20·7472·7565·0a3c······mask:·true.< 
00170360:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di 
00170370:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn· 
00170380:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat 
00170390:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap 
001703a0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target= 
001703b0:·2223·6964·6d31·3938·3838·2220·7461·6269··"#idm19888"·tabi 
001703c0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b 
001703d0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa 
001703e0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit 
001703f0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to· 
00170400:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#! 
00170410:·223e·5265·6d65·6469·6174·696f·6e20·5075··">Remediation·Pu 
00170420:·7070·6574·2073·6e69·7070·6574·20e2·87b2··ppet·snippet·... 
00170430:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla 
00170440:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap 
00170450:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id= 
00170460:·2269·646d·3139·3838·3822·3e3c·7461·626c··"idm19888"><tabl 
00170470:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t 
00170480:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab 
00170490:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl 
001704a0:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr 
001704b0:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity: 
001704c0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td 
001704d0:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di 
001704e0:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t 
001704f0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr>< 
00170500:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</ 
00170510:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td 
00170520:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St 
00170530:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td> 
00170540:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr> 
00170550:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co 
00170560:·6465·3e69·6e63·6c75·6465·2064·6973·6162··de>include·disab 
00170570:·6c65·5f61·7574·6f66·730a·0a63·6c61·7373··le_autofs..class 
00170580:·2064·6973·6162·6c65·5f61·7574·6f66·7320···disable_autofs·00170240:·2064·6973·6162·6c65·5f61·7574·6f66·730a···disable_autofs.
00170590:·7b0a·2020·7365·7276·6963·6520·7b27·6175··{.··service·{'au 
001705a0:·746f·6673·273a·0a20·2020·2065·6e61·626c··tofs':.····enabl 
001705b0:·6520·3d26·6774·3b20·6661·6c73·652c·0a20··e·=&gt;·false,.·00170250:·0a63·6c61·7373·2064·6973·6162·6c65·5f61··.class·disable_a
 00170260:·7574·6f66·7320·7b0a·2020·7365·7276·6963··utofs·{.··servic
 00170270:·6520·7b27·6175·746f·6673·273a·0a20·2020··e·{'autofs':.···
001705c0:·2020·2065·6e73·7572·6520·3d26·6774·3b20·····ensure·=&gt;·00170280:·2065·6e61·626c·6520·3d26·6774·3b20·6661···enable·=&gt;·fa
001705d0:·2773·746f·7070·6564·272c·0a20·207d·0a7d··'stopped',.··}.}00170290:·6c73·652c·0a20·2020·2065·6e73·7572·6520··lse,.····ensure·
 001702a0:·3d26·6774·3b20·2773·746f·7070·6564·272c··=&gt;·'stopped',
 001702b0:·0a20·207d·0a7d·0a3c·2f63·6f64·653e·3c2f··.··}.}.</code></
 001702c0:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla
 001702d0:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ
 001702e0:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle
 001702f0:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data
 00170300:·2d74·6172·6765·743d·2223·6964·6d31·3938··-target="#idm198
 00170310:·3838·2220·7461·6269·6e64·6578·3d22·3022··88"·tabindex="0"
 00170320:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
 00170330:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
 00170340:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
 00170350:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
 00170360:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
 00170370:·6174·696f·6e20·4b75·6265·726e·6574·6573··ation·Kubernetes
 00170380:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>
 00170390:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="
 001703a0:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c
 001703b0:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm
 001703c0:·3139·3838·3822·3e3c·7461·626c·6520·636c··19888"><table·cl
 001703d0:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table
 001703e0:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b
 001703f0:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co
 00170400:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th
 00170410:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th
 00170420:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
 00170430:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup
 00170440:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6d65··tion:</th><td>me
 00170450:·6469·756d·3c2f·7464·3e3c·2f74·723e·3c74··dium</td></tr><t
 00170460:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t
 00170470:·683e·3c74·643e·7472·7565·3c2f·7464·3e3c··h><td>true</td><
 00170480:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra
 00170490:·7465·6779·3a3c·2f74·683e·3c74·643e·6469··tegy:</th><td>di
 001704a0:·7361·626c·653c·2f74·643e·3c2f·7472·3e3c··sable</td></tr><
Max diff block lines reached; 36654/48134 bytes (76.15%) of diff not shown.
7.37 KB
html2text {}
    
Offset 18517, 14 lines modifiedOffset 18517, 27 lines modified
18517 ··-·medium_severity18517 ··-·medium_severity
18518 ··-·no_reboot_needed18518 ··-·no_reboot_needed
18519 ··-·service_autofs_disabled18519 ··-·service_autofs_disabled
18520 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x818520 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
18521 [customizations.services]18521 [customizations.services]
18522 masked·=·["autofs"]18522 masked·=·["autofs"]
 18523 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 18524 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 18525 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 18526 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 18527 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 18528 include·disable_autofs
  
 18529 class·disable_autofs·{
 18530 ··service·{'autofs':
 18531 ····enable·=>·false,
 18532 ····ensure·=>·'stopped',
 18533 ··}
 18534 }
18523 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x818535 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
18524 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low18536 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
18525 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium18537 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
18526 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true18538 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
18527 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable18539 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
18528 apiVersion:·machineconfiguration.openshift.io/v118540 apiVersion:·machineconfiguration.openshift.io/v1
18529 kind:·MachineConfig18541 kind:·MachineConfig
Offset 18536, 27 lines modifiedOffset 18549, 14 lines modified
18536 ······units:18549 ······units:
18537 ······-·name:·autofs.service18550 ······-·name:·autofs.service
18538 ········enabled:·false18551 ········enabled:·false
18539 ········mask:·true18552 ········mask:·true
18540 ······-·name:·autofs.socket18553 ······-·name:·autofs.socket
18541 ········enabled:·false18554 ········enabled:·false
18542 ········mask:·true18555 ········mask:·true
18543 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
18544 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
18545 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
18546 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
18547 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
18548 include·disable_autofs 
  
18549 class·disable_autofs·{ 
18550 ··service·{'autofs': 
18551 ····enable·=>·false, 
18552 ····ensure·=>·'stopped', 
18553 ··} 
18554 } 
18555 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x818556 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
18556 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low18557 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
18557 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low18558 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
18558 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false18559 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
18559 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable18560 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
18560 #·Remediation·is·applicable·only·in·certain·platforms18561 #·Remediation·is·applicable·only·in·certain·platforms
18561 if·(·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'autofs'·2>/dev/null·|·grep·-18562 if·(·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'autofs'·2>/dev/null·|·grep·-
Offset 23496, 14 lines modifiedOffset 23496, 27 lines modified
23496 ··-·no_reboot_needed23496 ··-·no_reboot_needed
23497 ··-·service_apport_disabled23497 ··-·service_apport_disabled
23498 ··-·unknown_severity23498 ··-·unknown_severity
23499 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x823499 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
23500 [customizations.services]23500 [customizations.services]
23501 masked·=·["apport"]23501 masked·=·["apport"]
 23502 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 23503 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 23504 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 23505 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 23506 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 23507 include·disable_apport
  
 23508 class·disable_apport·{
 23509 ··service·{'apport':
 23510 ····enable·=>·false,
 23511 ····ensure·=>·'stopped',
 23512 ··}
 23513 }
23502 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x823514 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
23503 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low23515 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
23504 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium23516 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
23505 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true23517 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
23506 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable23518 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
23507 apiVersion:·machineconfiguration.openshift.io/v123519 apiVersion:·machineconfiguration.openshift.io/v1
23508 kind:·MachineConfig23520 kind:·MachineConfig
Offset 23515, 27 lines modifiedOffset 23528, 14 lines modified
23515 ······units:23528 ······units:
23516 ······-·name:·apport.service23529 ······-·name:·apport.service
23517 ········enabled:·false23530 ········enabled:·false
23518 ········mask:·true23531 ········mask:·true
23519 ······-·name:·apport.socket23532 ······-·name:·apport.socket
23520 ········enabled:·false23533 ········enabled:·false
23521 ········mask:·true23534 ········mask:·true
23522 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
23523 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
23524 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
23525 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
23526 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
23527 include·disable_apport 
  
23528 class·disable_apport·{ 
23529 ··service·{'apport': 
23530 ····enable·=>·false, 
23531 ····ensure·=>·'stopped', 
23532 ··} 
23533 } 
23534 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x823535 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
23535 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low23536 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
23536 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low23537 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
23537 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false23538 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
23538 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable23539 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
23539 #·Remediation·is·applicable·only·in·certain·platforms23540 #·Remediation·is·applicable·only·in·certain·platforms
23540 if·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'apport'·2>/dev/null·|·grep·-23541 if·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'apport'·2>/dev/null·|·grep·-
Offset 23767, 14 lines modifiedOffset 23767, 27 lines modified
23767 ··-·medium_severity23767 ··-·medium_severity
23768 ··-·no_reboot_needed23768 ··-·no_reboot_needed
23769 ··-·service_avahi-daemon_disabled23769 ··-·service_avahi-daemon_disabled
23770 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x823770 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
23771 [customizations.services]23771 [customizations.services]
23772 masked·=·["avahi-daemon"]23772 masked·=·["avahi-daemon"]
 23773 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 23774 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 23775 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 23776 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 23777 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 23778 include·disable_avahi-daemon
  
 23779 class·disable_avahi-daemon·{
Max diff block lines reached; 3008/7519 bytes (40.01%) of diff not shown.
54.4 KB
./usr/share/doc/ssg-debderived/ssg-ubuntu2204-guide-cis_level2_workstation.html
    
Offset 93882, 93 lines modifiedOffset 93882, 93 lines modified
0016eb90:·743d·2223·6964·6d31·3938·3837·2220·7461··t="#idm19887"·ta0016eb90:·743d·2223·6964·6d31·3938·3837·2220·7461··t="#idm19887"·ta
0016eba0:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=0016eba0:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
0016ebb0:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex0016ebb0:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
0016ebc0:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t0016ebc0:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
0016ebd0:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t0016ebd0:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
0016ebe0:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="0016ebe0:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
0016ebf0:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·0016ebf0:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
0016ec00:·4b75·6265·726e·6574·6573·2073·6e69·7070··Kubernetes·snipp0016ec00:·5075·7070·6574·2073·6e69·7070·6574·20e2··Puppet·snippet·.
0016ec10:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d0016ec10:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c
0016ec20:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-0016ec20:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
0016ec30:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps0016ec30:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
0016ec40:·6522·2069·643d·2269·646d·3139·3838·3722··e"·id="idm19887"0016ec40:·643d·2269·646d·3139·3838·3722·3e3c·7461··d="idm19887"><ta
0016ec50:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t0016ec50:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table
0016ec60:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip0016ec60:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t
0016ec70:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere0016ec70:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta
0016ec80:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense0016ec80:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><
0016ec90:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl0016ec90:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit
0016eca0:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l0016eca0:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</
0016ecb0:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr> 
0016ecc0:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:< 
0016ecd0:·2f74·683e·3c74·643e·6d65·6469·756d·3c2f··/th><td>medium</ 
0016ece0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>0016ecb0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 0016ecc0:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th>
 0016ecd0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
 0016ece0:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot:
 0016ecf0:·3c2f·7468·3e3c·7464·3e66·616c·7365·3c2f··</th><td>false</
 0016ed00:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 0016ed10:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t
 0016ed20:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t
 0016ed30:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><
 0016ed40:·636f·6465·3e69·6e63·6c75·6465·2064·6973··code>include·dis
 0016ed50:·6162·6c65·5f61·7574·6f66·730a·0a63·6c61··able_autofs..cla
 0016ed60:·7373·2064·6973·6162·6c65·5f61·7574·6f66··ss·disable_autof
 0016ed70:·7320·7b0a·2020·7365·7276·6963·6520·7b27··s·{.··service·{'
 0016ed80:·6175·746f·6673·273a·0a20·2020·2065·6e61··autofs':.····ena
 0016ed90:·626c·6520·3d26·6774·3b20·6661·6c73·652c··ble·=&gt;·false,
 0016eda0:·0a20·2020·2065·6e73·7572·6520·3d26·6774··.····ensure·=&gt
 0016edb0:·3b20·2773·746f·7070·6564·272c·0a20·207d··;·'stopped',.··}
 0016edc0:·0a7d·0a3c·2f63·6f64·653e·3c2f·7072·653e··.}.</code></pre>
 0016edd0:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class="
 0016ede0:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success"
 0016edf0:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co
 0016ee00:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar
 0016ee10:·6765·743d·2223·6964·6d31·3938·3838·2220··get="#idm19888"·
 0016ee20:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol
 0016ee30:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-
 0016ee40:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"
 0016ee50:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate
 0016ee60:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href
 0016ee70:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio
 0016ee80:·6e20·4b75·6265·726e·6574·6573·2073·6e69··n·Kubernetes·sni
 0016ee90:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>
 0016eea0:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
 0016eeb0:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
 0016eec0:·7073·6522·2069·643d·2269·646d·3139·3838··pse"·id="idm1988
 0016eed0:·3822·3e3c·7461·626c·6520·636c·6173·733d··8"><table·class=
 0016eee0:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str
 0016eef0:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde
 0016ef00:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden
 0016ef10:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com
 0016ef20:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td
 0016ef30:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
 0016ef40:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption
 0016ef50:·3a3c·2f74·683e·3c74·643e·6d65·6469·756d··:</th><td>medium
 0016ef60:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
0016ecf0:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td>0016ef70:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t
0016ed00:·7472·7565·3c2f·7464·3e3c·2f74·723e·3c74··true</td></tr><t0016ef80:·643e·7472·7565·3c2f·7464·3e3c·2f74·723e··d>true</td></tr>
0016ed10:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<0016ef90:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy
0016ed20:·2f74·683e·3c74·643e·6469·7361·626c·653c··/th><td>disable<0016efa0:·3a3c·2f74·683e·3c74·643e·6469·7361·626c··:</th><td>disabl
0016ed30:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table0016efb0:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab
0016ed40:·3e3c·7072·653e·3c63·6f64·653e·6170·6956··><pre><code>apiV0016efc0:·6c65·3e3c·7072·653e·3c63·6f64·653e·6170··le><pre><code>ap
0016ed50:·6572·7369·6f6e·3a20·6d61·6368·696e·6563··ersion:·machinec0016efd0:·6956·6572·7369·6f6e·3a20·6d61·6368·696e··iVersion:·machin
0016ed60:·6f6e·6669·6775·7261·7469·6f6e·2e6f·7065··onfiguration.ope0016efe0:·6563·6f6e·6669·6775·7261·7469·6f6e·2e6f··econfiguration.o
0016ed70:·6e73·6869·6674·2e69·6f2f·7631·0a6b·696e··nshift.io/v1.kin0016eff0:·7065·6e73·6869·6674·2e69·6f2f·7631·0a6b··penshift.io/v1.k
0016ed80:·643a·204d·6163·6869·6e65·436f·6e66·6967··d:·MachineConfig0016f000:·696e·643a·204d·6163·6869·6e65·436f·6e66··ind:·MachineConf
0016ed90:·0a73·7065·633a·0a20·2063·6f6e·6669·673a··.spec:.··config:0016f010:·6967·0a73·7065·633a·0a20·2063·6f6e·6669··ig.spec:.··confi
0016eda0:·0a20·2020·2069·676e·6974·696f·6e3a·0a20··.····ignition:.·0016f020:·673a·0a20·2020·2069·676e·6974·696f·6e3a··g:.····ignition:
0016edb0:·2020·2020·2076·6572·7369·6f6e·3a20·332e·······version:·3.0016f030:·0a20·2020·2020·2076·6572·7369·6f6e·3a20··.······version:·
0016edc0:·312e·300a·2020·2020·7379·7374·656d·643a··1.0.····systemd:0016f040:·332e·312e·300a·2020·2020·7379·7374·656d··3.1.0.····system
0016edd0:·0a20·2020·2020·2075·6e69·7473·3a0a·2020··.······units:.··0016f050:·643a·0a20·2020·2020·2075·6e69·7473·3a0a··d:.······units:.
0016ede0:·2020·2020·2d20·6e61·6d65·3a20·6175·746f······-·name:·auto0016f060:·2020·2020·2020·2d20·6e61·6d65·3a20·6175········-·name:·au
0016edf0:·6673·2e73·6572·7669·6365·0a20·2020·2020··fs.service.·····0016f070:·746f·6673·2e73·6572·7669·6365·0a20·2020··tofs.service.···
0016ee00:·2020·2065·6e61·626c·6564·3a20·6661·6c73·····enabled:·fals0016f080:·2020·2020·2065·6e61·626c·6564·3a20·6661·······enabled:·fa
0016ee10:·650a·2020·2020·2020·2020·6d61·736b·3a20··e.········mask:·0016f090:·6c73·650a·2020·2020·2020·2020·6d61·736b··lse.········mask
0016ee20:·7472·7565·0a20·2020·2020·202d·206e·616d··true.······-·nam0016f0a0:·3a20·7472·7565·0a20·2020·2020·202d·206e··:·true.······-·n
0016ee30:·653a·2061·7574·6f66·732e·736f·636b·6574··e:·autofs.socket0016f0b0:·616d·653a·2061·7574·6f66·732e·736f·636b··ame:·autofs.sock
0016ee40:·0a20·2020·2020·2020·2065·6e61·626c·6564··.········enabled0016f0c0:·6574·0a20·2020·2020·2020·2065·6e61·626c··et.········enabl
0016ee50:·3a20·6661·6c73·650a·2020·2020·2020·2020··:·false.········0016f0d0:·6564·3a20·6661·6c73·650a·2020·2020·2020··ed:·false.······
0016ee60:·6d61·736b·3a20·7472·7565·0a3c·2f63·6f64··mask:·true.</cod0016f0e0:·2020·6d61·736b·3a20·7472·7565·0a3c·2f63····mask:·true.</c
0016ee70:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a 
0016ee80:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn- 
0016ee90:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to 
0016eea0:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"· 
0016eeb0:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id 
0016eec0:·6d31·3938·3838·2220·7461·6269·6e64·6578··m19888"·tabindex 
0016eed0:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto 
0016eee0:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded 
0016eef0:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title=" 
0016ef00:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve 
0016ef10:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re 
0016ef20:·6d65·6469·6174·696f·6e20·5075·7070·6574··mediation·Puppet 
0016ef30:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a> 
0016ef40:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class=" 
0016ef50:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c 
0016ef60:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm 
0016ef70:·3139·3838·3822·3e3c·7461·626c·6520·636c··19888"><table·cl 
0016ef80:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table 
0016ef90:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b 
0016efa0:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co 
0016efb0:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th 
0016efc0:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th 
0016efd0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t 
0016efe0:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup 
0016eff0:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo 
0016f000:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr>< 
0016f010:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th>< 
0016f020:·7464·3e66·616c·7365·3c2f·7464·3e3c·2f74··td>false</td></t 
0016f030:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate 
0016f040:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab 
0016f050:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta 
0016f060:·626c·653e·3c70·7265·3e3c·636f·6465·3e69··ble><pre><code>i 
0016f070:·6e63·6c75·6465·2064·6973·6162·6c65·5f61··nclude·disable_a 
0016f080:·7574·6f66·730a·0a63·6c61·7373·2064·6973··utofs..class·dis 
0016f090:·6162·6c65·5f61·7574·6f66·7320·7b0a·2020··able_autofs·{.·· 
0016f0a0:·7365·7276·6963·6520·7b27·6175·746f·6673··service·{'autofs 
0016f0b0:·273a·0a20·2020·2065·6e61·626c·6520·3d26··':.····enable·=& 
0016f0c0:·6774·3b20·6661·6c73·652c·0a20·2020·2065··gt;·false,.····e 
Max diff block lines reached; 36516/47996 bytes (76.08%) of diff not shown.
7.37 KB
html2text {}
    
Offset 18435, 14 lines modifiedOffset 18435, 27 lines modified
18435 ··-·medium_severity18435 ··-·medium_severity
18436 ··-·no_reboot_needed18436 ··-·no_reboot_needed
18437 ··-·service_autofs_disabled18437 ··-·service_autofs_disabled
18438 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x818438 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
18439 [customizations.services]18439 [customizations.services]
18440 masked·=·["autofs"]18440 masked·=·["autofs"]
 18441 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 18442 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 18443 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 18444 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 18445 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 18446 include·disable_autofs
  
 18447 class·disable_autofs·{
 18448 ··service·{'autofs':
 18449 ····enable·=>·false,
 18450 ····ensure·=>·'stopped',
 18451 ··}
 18452 }
18441 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x818453 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
18442 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low18454 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
18443 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium18455 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
18444 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true18456 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
18445 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable18457 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
18446 apiVersion:·machineconfiguration.openshift.io/v118458 apiVersion:·machineconfiguration.openshift.io/v1
18447 kind:·MachineConfig18459 kind:·MachineConfig
Offset 18454, 27 lines modifiedOffset 18467, 14 lines modified
18454 ······units:18467 ······units:
18455 ······-·name:·autofs.service18468 ······-·name:·autofs.service
18456 ········enabled:·false18469 ········enabled:·false
18457 ········mask:·true18470 ········mask:·true
18458 ······-·name:·autofs.socket18471 ······-·name:·autofs.socket
18459 ········enabled:·false18472 ········enabled:·false
18460 ········mask:·true18473 ········mask:·true
18461 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
18462 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
18463 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
18464 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
18465 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
18466 include·disable_autofs 
  
18467 class·disable_autofs·{ 
18468 ··service·{'autofs': 
18469 ····enable·=>·false, 
18470 ····ensure·=>·'stopped', 
18471 ··} 
18472 } 
18473 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x818474 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
18474 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low18475 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
18475 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low18476 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
18476 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false18477 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
18477 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable18478 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
18478 #·Remediation·is·applicable·only·in·certain·platforms18479 #·Remediation·is·applicable·only·in·certain·platforms
18479 if·(·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'autofs'·2>/dev/null·|·grep·-18480 if·(·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'autofs'·2>/dev/null·|·grep·-
Offset 23414, 14 lines modifiedOffset 23414, 27 lines modified
23414 ··-·no_reboot_needed23414 ··-·no_reboot_needed
23415 ··-·service_apport_disabled23415 ··-·service_apport_disabled
23416 ··-·unknown_severity23416 ··-·unknown_severity
23417 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x823417 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
23418 [customizations.services]23418 [customizations.services]
23419 masked·=·["apport"]23419 masked·=·["apport"]
 23420 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 23421 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 23422 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 23423 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 23424 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 23425 include·disable_apport
  
 23426 class·disable_apport·{
 23427 ··service·{'apport':
 23428 ····enable·=>·false,
 23429 ····ensure·=>·'stopped',
 23430 ··}
 23431 }
23420 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x823432 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
23421 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low23433 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
23422 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium23434 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
23423 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true23435 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
23424 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable23436 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
23425 apiVersion:·machineconfiguration.openshift.io/v123437 apiVersion:·machineconfiguration.openshift.io/v1
23426 kind:·MachineConfig23438 kind:·MachineConfig
Offset 23433, 27 lines modifiedOffset 23446, 14 lines modified
23433 ······units:23446 ······units:
23434 ······-·name:·apport.service23447 ······-·name:·apport.service
23435 ········enabled:·false23448 ········enabled:·false
23436 ········mask:·true23449 ········mask:·true
23437 ······-·name:·apport.socket23450 ······-·name:·apport.socket
23438 ········enabled:·false23451 ········enabled:·false
23439 ········mask:·true23452 ········mask:·true
23440 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
23441 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
23442 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
23443 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
23444 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
23445 include·disable_apport 
  
23446 class·disable_apport·{ 
23447 ··service·{'apport': 
23448 ····enable·=>·false, 
23449 ····ensure·=>·'stopped', 
23450 ··} 
23451 } 
23452 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x823453 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
23453 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low23454 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
23454 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low23455 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
23455 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false23456 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
23456 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable23457 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
23457 #·Remediation·is·applicable·only·in·certain·platforms23458 #·Remediation·is·applicable·only·in·certain·platforms
23458 if·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'apport'·2>/dev/null·|·grep·-23459 if·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'apport'·2>/dev/null·|·grep·-
Offset 23685, 14 lines modifiedOffset 23685, 27 lines modified
23685 ··-·medium_severity23685 ··-·medium_severity
23686 ··-·no_reboot_needed23686 ··-·no_reboot_needed
23687 ··-·service_avahi-daemon_disabled23687 ··-·service_avahi-daemon_disabled
23688 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x823688 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
23689 [customizations.services]23689 [customizations.services]
23690 masked·=·["avahi-daemon"]23690 masked·=·["avahi-daemon"]
 23691 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 23692 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 23693 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 23694 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 23695 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 23696 include·disable_avahi-daemon
  
 23697 class·disable_avahi-daemon·{
Max diff block lines reached; 3008/7519 bytes (40.01%) of diff not shown.
13.6 KB
./usr/share/doc/ssg-debderived/ssg-ubuntu2204-guide-standard.html
    
Offset 28559, 93 lines modifiedOffset 28559, 93 lines modified
0006f8e0:·6574·3d22·2369·646d·3232·3137·3222·2074··et="#idm22172"·t0006f8e0:·6574·3d22·2369·646d·3232·3137·3222·2074··et="#idm22172"·t
0006f8f0:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role0006f8f0:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
0006f900:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e0006f900:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
0006f910:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·0006f910:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
0006f920:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·0006f920:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
0006f930:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=0006f930:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
0006f940:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation0006f940:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
0006f950:·204b·7562·6572·6e65·7465·7320·736e·6970···Kubernetes·snip0006f950:·2050·7570·7065·7420·736e·6970·7065·7420···Puppet·snippet·
0006f960:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br><0006f960:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·
0006f970:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel0006f970:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col
0006f980:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap0006f980:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·
0006f990:·7365·2220·6964·3d22·6964·6d32·3231·3732··se"·id="idm221720006f990:·6964·3d22·6964·6d32·3231·3732·223e·3c74··id="idm22172"><t
0006f9a0:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="0006f9a0:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl
0006f9b0:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri0006f9b0:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·
0006f9c0:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border0006f9c0:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t
0006f9d0:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens0006f9d0:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">
0006f9e0:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp0006f9e0:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi
0006f9f0:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>0006f9f0:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<
0006fa00:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr 
0006fa10:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption: 
0006fa20:·3c2f·7468·3e3c·7464·3e6d·6564·6975·6d3c··</th><td>medium< 
0006fa30:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th0006fa00:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 0006fa10:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th
 0006fa20:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
 0006fa30:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot
 0006fa40:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false<
 0006fa50:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 0006fa60:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><
 0006fa70:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></
 0006fa80:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>
 0006fa90:·3c63·6f64·653e·696e·636c·7564·6520·6469··<code>include·di
 0006faa0:·7361·626c·655f·6170·706f·7274·0a0a·636c··sable_apport..cl
 0006fab0:·6173·7320·6469·7361·626c·655f·6170·706f··ass·disable_appo
 0006fac0:·7274·207b·0a20·2073·6572·7669·6365·207b··rt·{.··service·{
 0006fad0:·2761·7070·6f72·7427·3a0a·2020·2020·656e··'apport':.····en
 0006fae0:·6162·6c65·203d·2667·743b·2066·616c·7365··able·=&gt;·false
 0006faf0:·2c0a·2020·2020·656e·7375·7265·203d·2667··,.····ensure·=&g
 0006fb00:·743b·2027·7374·6f70·7065·6427·2c0a·2020··t;·'stopped',.··
 0006fb10:·7d0a·7d0a·3c2f·636f·6465·3e3c·2f70·7265··}.}.</code></pre
 0006fb20:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class=
 0006fb30:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success
 0006fb40:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c
 0006fb50:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta
 0006fb60:·7267·6574·3d22·2369·646d·3232·3137·3322··rget="#idm22173"
 0006fb70:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro
 0006fb80:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria
 0006fb90:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false
 0006fba0:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat
 0006fbb0:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre
 0006fbc0:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati
 0006fbd0:·6f6e·204b·7562·6572·6e65·7465·7320·736e··on·Kubernetes·sn
 0006fbe0:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br
 0006fbf0:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
 0006fc00:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
 0006fc10:·6170·7365·2220·6964·3d22·6964·6d32·3231··apse"·id="idm221
 0006fc20:·3733·223e·3c74·6162·6c65·2063·6c61·7373··73"><table·class
 0006fc30:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st
 0006fc40:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord
 0006fc50:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde
 0006fc60:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co
 0006fc70:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t
 0006fc80:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
 0006fc90:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio
 0006fca0:·6e3a·3c2f·7468·3e3c·7464·3e6d·6564·6975··n:</th><td>mediu
 0006fcb0:·6d3c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··m</td></tr><tr><
0006fa40:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td0006fcc0:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th><
0006fa50:·3e74·7275·653c·2f74·643e·3c2f·7472·3e3c··>true</td></tr><0006fcd0:·7464·3e74·7275·653c·2f74·643e·3c2f·7472··td>true</td></tr
0006fa60:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:0006fce0:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg
0006fa70:·3c2f·7468·3e3c·7464·3e64·6973·6162·6c65··</th><td>disable0006fcf0:·793a·3c2f·7468·3e3c·7464·3e64·6973·6162··y:</th><td>disab
0006fa80:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl0006fd00:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta
0006fa90:·653e·3c70·7265·3e3c·636f·6465·3e61·7069··e><pre><code>api0006fd10:·626c·653e·3c70·7265·3e3c·636f·6465·3e61··ble><pre><code>a
0006faa0:·5665·7273·696f·6e3a·206d·6163·6869·6e65··Version:·machine0006fd20:·7069·5665·7273·696f·6e3a·206d·6163·6869··piVersion:·machi
0006fab0:·636f·6e66·6967·7572·6174·696f·6e2e·6f70··configuration.op0006fd30:·6e65·636f·6e66·6967·7572·6174·696f·6e2e··neconfiguration.
0006fac0:·656e·7368·6966·742e·696f·2f76·310a·6b69··enshift.io/v1.ki0006fd40:·6f70·656e·7368·6966·742e·696f·2f76·310a··openshift.io/v1.
0006fad0:·6e64·3a20·4d61·6368·696e·6543·6f6e·6669··nd:·MachineConfi0006fd50:·6b69·6e64·3a20·4d61·6368·696e·6543·6f6e··kind:·MachineCon
0006fae0:·670a·7370·6563·3a0a·2020·636f·6e66·6967··g.spec:.··config0006fd60:·6669·670a·7370·6563·3a0a·2020·636f·6e66··fig.spec:.··conf
0006faf0:·3a0a·2020·2020·6967·6e69·7469·6f6e·3a0a··:.····ignition:.0006fd70:·6967·3a0a·2020·2020·6967·6e69·7469·6f6e··ig:.····ignition
0006fb00:·2020·2020·2020·7665·7273·696f·6e3a·2033········version:·30006fd80:·3a0a·2020·2020·2020·7665·7273·696f·6e3a··:.······version:
0006fb10:·2e31·2e30·0a20·2020·2073·7973·7465·6d64··.1.0.····systemd0006fd90:·2033·2e31·2e30·0a20·2020·2073·7973·7465···3.1.0.····syste
0006fb20:·3a0a·2020·2020·2020·756e·6974·733a·0a20··:.······units:.·0006fda0:·6d64·3a0a·2020·2020·2020·756e·6974·733a··md:.······units:
0006fb30:·2020·2020·202d·206e·616d·653a·2061·7070·······-·name:·app0006fdb0:·0a20·2020·2020·202d·206e·616d·653a·2061··.······-·name:·a
0006fb40:·6f72·742e·7365·7276·6963·650a·2020·2020··ort.service.····0006fdc0:·7070·6f72·742e·7365·7276·6963·650a·2020··pport.service.··
0006fb50:·2020·2020·656e·6162·6c65·643a·2066·616c······enabled:·fal0006fdd0:·2020·2020·2020·656e·6162·6c65·643a·2066········enabled:·f
0006fb60:·7365·0a20·2020·2020·2020·206d·6173·6b3a··se.········mask:0006fde0:·616c·7365·0a20·2020·2020·2020·206d·6173··alse.········mas
0006fb70:·2074·7275·650a·2020·2020·2020·2d20·6e61···true.······-·na0006fdf0:·6b3a·2074·7275·650a·2020·2020·2020·2d20··k:·true.······-·
0006fb80:·6d65·3a20·6170·706f·7274·2e73·6f63·6b65··me:·apport.socke0006fe00:·6e61·6d65·3a20·6170·706f·7274·2e73·6f63··name:·apport.soc
0006fb90:·740a·2020·2020·2020·2020·656e·6162·6c65··t.········enable0006fe10:·6b65·740a·2020·2020·2020·2020·656e·6162··ket.········enab
0006fba0:·643a·2066·616c·7365·0a20·2020·2020·2020··d:·false.·······0006fe20:·6c65·643a·2066·616c·7365·0a20·2020·2020··led:·false.·····
0006fbb0:·206d·6173·6b3a·2074·7275·650a·3c2f·636f···mask:·true.</co0006fe30:·2020·206d·6173·6b3a·2074·7275·650a·3c2f·····mask:·true.</
0006fbc0:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div>< 
0006fbd0:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn 
0006fbe0:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t 
0006fbf0:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse" 
0006fc00:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i 
0006fc10:·646d·3232·3137·3322·2074·6162·696e·6465··dm22173"·tabinde 
0006fc20:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt 
0006fc30:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande 
0006fc40:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title= 
0006fc50:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev 
0006fc60:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R 
0006fc70:·656d·6564·6961·7469·6f6e·2050·7570·7065··emediation·Puppe 
0006fc80:·7420·736e·6970·7065·7420·e287·b23c·2f61··t·snippet·...</a 
0006fc90:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class= 
0006fca0:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse· 
0006fcb0:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id 
0006fcc0:·6d32·3231·3733·223e·3c74·6162·6c65·2063··m22173"><table·c 
0006fcd0:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl 
0006fce0:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table- 
0006fcf0:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c 
0006fd00:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t 
0006fd10:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t 
0006fd20:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></ 
0006fd30:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru 
0006fd40:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l 
0006fd50:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr> 
0006fd60:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th> 
0006fd70:·3c74·643e·6661·6c73·653c·2f74·643e·3c2f··<td>false</td></ 
0006fd80:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat 
0006fd90:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena 
0006fda0:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t 
0006fdb0:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code> 
0006fdc0:·696e·636c·7564·6520·6469·7361·626c·655f··include·disable_ 
0006fdd0:·6170·706f·7274·0a0a·636c·6173·7320·6469··apport..class·di 
0006fde0:·7361·626c·655f·6170·706f·7274·207b·0a20··sable_apport·{.· 
0006fdf0:·2073·6572·7669·6365·207b·2761·7070·6f72···service·{'appor 
0006fe00:·7427·3a0a·2020·2020·656e·6162·6c65·203d··t':.····enable·= 
0006fe10:·2667·743b·2066·616c·7365·2c0a·2020·2020··&gt;·false,.···· 
Max diff block lines reached; 414/11894 bytes (3.48%) of diff not shown.
1.84 KB
html2text {}
    
Offset 3701, 14 lines modifiedOffset 3701, 27 lines modified
3701 ··-·no_reboot_needed3701 ··-·no_reboot_needed
3702 ··-·service_apport_disabled3702 ··-·service_apport_disabled
3703 ··-·unknown_severity3703 ··-·unknown_severity
3704 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x83704 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
3705 [customizations.services]3705 [customizations.services]
3706 masked·=·["apport"]3706 masked·=·["apport"]
 3707 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 3708 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 3709 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 3710 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 3711 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 3712 include·disable_apport
  
 3713 class·disable_apport·{
 3714 ··service·{'apport':
 3715 ····enable·=>·false,
 3716 ····ensure·=>·'stopped',
 3717 ··}
 3718 }
3707 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x83719 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
3708 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low3720 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
3709 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium3721 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
3710 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true3722 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
3711 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable3723 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
3712 apiVersion:·machineconfiguration.openshift.io/v13724 apiVersion:·machineconfiguration.openshift.io/v1
3713 kind:·MachineConfig3725 kind:·MachineConfig
Offset 3720, 27 lines modifiedOffset 3733, 14 lines modified
3720 ······units:3733 ······units:
3721 ······-·name:·apport.service3734 ······-·name:·apport.service
3722 ········enabled:·false3735 ········enabled:·false
3723 ········mask:·true3736 ········mask:·true
3724 ······-·name:·apport.socket3737 ······-·name:·apport.socket
3725 ········enabled:·false3738 ········enabled:·false
3726 ········mask:·true3739 ········mask:·true
3727 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
3728 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
3729 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
3730 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
3731 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
3732 include·disable_apport 
  
3733 class·disable_apport·{ 
3734 ··service·{'apport': 
3735 ····enable·=>·false, 
3736 ····ensure·=>·'stopped', 
3737 ··} 
3738 } 
3739 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x83740 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
3740 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low3741 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
3741 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low3742 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
3742 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false3743 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
3743 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable3744 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
3744 #·Remediation·is·applicable·only·in·certain·platforms3745 #·Remediation·is·applicable·only·in·certain·platforms
3745 if·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'apport'·2>/dev/null3746 if·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'apport'·2>/dev/null
14.0 KB
./usr/share/doc/ssg-debderived/ssg-ubuntu2204-guide-stig.html
    
Offset 67364, 96 lines modifiedOffset 67364, 96 lines modified
00107230:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="00107230:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
00107240:·2369·646d·3232·3536·3022·2074·6162·696e··#idm22560"·tabin00107240:·2369·646d·3232·3536·3022·2074·6162·696e··#idm22560"·tabin
00107250:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu00107250:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
00107260:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan00107260:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
00107270:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl00107270:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
00107280:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r00107280:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
00107290:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"00107290:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
001072a0:·3e52·656d·6564·6961·7469·6f6e·204b·7562··>Remediation·Kub001072a0:·3e52·656d·6564·6961·7469·6f6e·2050·7570··>Remediation·Pup
001072b0:·6572·6e65·7465·7320·736e·6970·7065·7420··ernetes·snippet·001072b0:·7065·7420·736e·6970·7065·7420·e287·b23c··pet·snippet·...<
001072c0:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·001072c0:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas
001072d0:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col001072d0:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps
001072e0:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·001072e0:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="
001072f0:·6964·3d22·6964·6d32·3235·3630·223e·3c74··id="idm22560"><t001072f0:·6964·6d32·3235·3630·223e·3c74·6162·6c65··idm22560"><table
00107300:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl00107300:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta
00107310:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·00107310:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl
00107320:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t00107320:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table
00107330:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">00107330:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>
00107340:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi00107340:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<
00107350:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<00107350:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
00107360:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th00107360:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis
00107370:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th00107370:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td
00107380:·3e3c·7464·3e6d·6564·6975·6d3c·2f74·643e··><td>medium</td>00107380:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
 00107390:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t
 001073a0:·683e·3c74·643e·6661·6c73·653c·2f74·643e··h><td>false</td>
00107390:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb001073b0:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str
001073a0:·6f6f·743a·3c2f·7468·3e3c·7464·3e74·7275··oot:</th><td>tru001073c0:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e
001073b0:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr><001073d0:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr><
001073c0:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th 
001073d0:·3e3c·7464·3e64·6973·6162·6c65·3c2f·7464··><td>disable</td 
001073e0:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p 
001073f0:·7265·3e3c·636f·6465·3e61·7069·5665·7273··re><code>apiVers 
00107400:·696f·6e3a·206d·6163·6869·6e65·636f·6e66··ion:·machineconf 
00107410:·6967·7572·6174·696f·6e2e·6f70·656e·7368··iguration.opensh 
00107420:·6966·742e·696f·2f76·310a·6b69·6e64·3a20··ift.io/v1.kind:· 
00107430:·4d61·6368·696e·6543·6f6e·6669·670a·7370··MachineConfig.sp 
00107440:·6563·3a0a·2020·636f·6e66·6967·3a0a·2020··ec:.··config:.·· 
00107450:·2020·6967·6e69·7469·6f6e·3a0a·2020·2020····ignition:.····001073e0:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod
 001073f0:·653e·696e·636c·7564·6520·6469·7361·626c··e>include·disabl
 00107400:·655f·6b64·756d·702d·746f·6f6c·730a·0a63··e_kdump-tools..c
 00107410:·6c61·7373·2064·6973·6162·6c65·5f6b·6475··lass·disable_kdu
 00107420:·6d70·2d74·6f6f·6c73·207b·0a20·2073·6572··mp-tools·{.··ser
 00107430:·7669·6365·207b·276b·6475·6d70·2d74·6f6f··vice·{'kdump-too
 00107440:·6c73·273a·0a20·2020·2065·6e61·626c·6520··ls':.····enable·
 00107450:·3d26·6774·3b20·6661·6c73·652c·0a20·2020··=&gt;·false,.···
 00107460:·2065·6e73·7572·6520·3d26·6774·3b20·2773···ensure·=&gt;·'s
 00107470:·746f·7070·6564·272c·0a20·207d·0a7d·0a3c··topped',.··}.}.<
 00107480:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di
 00107490:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn·
 001074a0:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat
 001074b0:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap
 001074c0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
 001074d0:·2223·6964·6d32·3235·3631·2220·7461·6269··"#idm22561"·tabi
 001074e0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
 001074f0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
 00107500:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
 00107510:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
 00107520:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
 00107530:·223e·5265·6d65·6469·6174·696f·6e20·4b75··">Remediation·Ku
 00107540:·6265·726e·6574·6573·2073·6e69·7070·6574··bernetes·snippet
 00107550:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
 00107560:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
 00107570:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
 00107580:·2069·643d·2269·646d·3232·3536·3122·3e3c···id="idm22561"><
 00107590:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab
 001075a0:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped
 001075b0:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·
 001075c0:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"
 001075d0:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex
 001075e0:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low
 001075f0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
 00107600:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t
 00107610:·683e·3c74·643e·6d65·6469·756d·3c2f·7464··h><td>medium</td
 00107620:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re
 00107630:·626f·6f74·3a3c·2f74·683e·3c74·643e·7472··boot:</th><td>tr
 00107640:·7565·3c2f·7464·3e3c·2f74·723e·3c74·723e··ue</td></tr><tr>
 00107650:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t
 00107660:·683e·3c74·643e·6469·7361·626c·653c·2f74··h><td>disable</t
 00107670:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><
 00107680:·7072·653e·3c63·6f64·653e·6170·6956·6572··pre><code>apiVer
 00107690:·7369·6f6e·3a20·6d61·6368·696e·6563·6f6e··sion:·machinecon
 001076a0:·6669·6775·7261·7469·6f6e·2e6f·7065·6e73··figuration.opens
 001076b0:·6869·6674·2e69·6f2f·7631·0a6b·696e·643a··hift.io/v1.kind:
 001076c0:·204d·6163·6869·6e65·436f·6e66·6967·0a73···MachineConfig.s
 001076d0:·7065·633a·0a20·2063·6f6e·6669·673a·0a20··pec:.··config:.·
 001076e0:·2020·2069·676e·6974·696f·6e3a·0a20·2020·····ignition:.···
00107460:·2020·7665·7273·696f·6e3a·2033·2e31·2e30····version:·3.1.0001076f0:·2020·2076·6572·7369·6f6e·3a20·332e·312e·····version:·3.1.
00107470:·0a20·2020·2073·7973·7465·6d64·3a0a·2020··.····systemd:.··00107700:·300a·2020·2020·7379·7374·656d·643a·0a20··0.····systemd:.·
00107480:·2020·2020·756e·6974·733a·0a20·2020·2020······units:.·····00107710:·2020·2020·2075·6e69·7473·3a0a·2020·2020·······units:.····
00107490:·202d·206e·616d·653a·206b·6475·6d70·2d74···-·name:·kdump-t 
001074a0:·6f6f·6c73·2e73·6572·7669·6365·0a20·2020··ools.service.··· 
001074b0:·2020·2020·2065·6e61·626c·6564·3a20·6661·······enabled:·fa00107720:·2020·2d20·6e61·6d65·3a20·6b64·756d·702d····-·name:·kdump-
 00107730:·746f·6f6c·732e·7365·7276·6963·650a·2020··tools.service.··
 00107740:·2020·2020·2020·656e·6162·6c65·643a·2066········enabled:·f
001074c0:·6c73·650a·2020·2020·2020·2020·6d61·736b··lse.········mask00107750:·616c·7365·0a20·2020·2020·2020·206d·6173··alse.········mas
001074d0:·3a20·7472·7565·0a20·2020·2020·202d·206e··:·true.······-·n00107760:·6b3a·2074·7275·650a·2020·2020·2020·2d20··k:·true.······-·
001074e0:·616d·653a·206b·6475·6d70·2d74·6f6f·6c73··ame:·kdump-tools00107770:·6e61·6d65·3a20·6b64·756d·702d·746f·6f6c··name:·kdump-tool
001074f0:·2e73·6f63·6b65·740a·2020·2020·2020·2020··.socket.········00107780:·732e·736f·636b·6574·0a20·2020·2020·2020··s.socket.·······
00107500:·656e·6162·6c65·643a·2066·616c·7365·0a20··enabled:·false.·00107790:·2065·6e61·626c·6564·3a20·6661·6c73·650a···enabled:·false.
00107510:·2020·2020·2020·206d·6173·6b3a·2074·7275·········mask:·tru001077a0:·2020·2020·2020·2020·6d61·736b·3a20·7472··········mask:·tr
00107520:·650a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··e.</code></pre>< 
00107530:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b 
00107540:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"· 
00107550:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col 
00107560:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ 
00107570:·6574·3d22·2369·646d·3232·3536·3122·2074··et="#idm22561"·t 
00107580:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role 
00107590:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e 
001075a0:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"· 
001075b0:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate· 
001075c0:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href= 
001075d0:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation 
001075e0:·2050·7570·7065·7420·736e·6970·7065·7420···Puppet·snippet· 
001075f0:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div· 
00107600:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col 
00107610:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"· 
00107620:·6964·3d22·6964·6d32·3235·3631·223e·3c74··id="idm22561"><t 
00107630:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl 
00107640:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped· 
00107650:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t 
00107660:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed"> 
00107670:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi 
00107680:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low< 
00107690:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
001076a0:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th 
001076b0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t 
001076c0:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot 
001076d0:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false< 
Max diff block lines reached; 414/12308 bytes (3.36%) of diff not shown.
1.87 KB
html2text {}
    
Offset 12640, 14 lines modifiedOffset 12640, 27 lines modified
12640 ··-·medium_severity12640 ··-·medium_severity
12641 ··-·no_reboot_needed12641 ··-·no_reboot_needed
12642 ··-·service_kdump_disabled12642 ··-·service_kdump_disabled
12643 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x812643 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
12644 [customizations.services]12644 [customizations.services]
12645 masked·=·["kdump-tools"]12645 masked·=·["kdump-tools"]
 12646 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 12647 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 12648 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 12649 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 12650 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 12651 include·disable_kdump-tools
  
 12652 class·disable_kdump-tools·{
 12653 ··service·{'kdump-tools':
 12654 ····enable·=>·false,
 12655 ····ensure·=>·'stopped',
 12656 ··}
 12657 }
12646 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x812658 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
12647 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low12659 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
12648 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium12660 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
12649 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true12661 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
12650 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable12662 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
12651 apiVersion:·machineconfiguration.openshift.io/v112663 apiVersion:·machineconfiguration.openshift.io/v1
12652 kind:·MachineConfig12664 kind:·MachineConfig
Offset 12659, 27 lines modifiedOffset 12672, 14 lines modified
12659 ······units:12672 ······units:
12660 ······-·name:·kdump-tools.service12673 ······-·name:·kdump-tools.service
12661 ········enabled:·false12674 ········enabled:·false
12662 ········mask:·true12675 ········mask:·true
12663 ······-·name:·kdump-tools.socket12676 ······-·name:·kdump-tools.socket
12664 ········enabled:·false12677 ········enabled:·false
12665 ········mask:·true12678 ········mask:·true
12666 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
12667 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
12668 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
12669 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
12670 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
12671 include·disable_kdump-tools 
  
12672 class·disable_kdump-tools·{ 
12673 ··service·{'kdump-tools': 
12674 ····enable·=>·false, 
12675 ····ensure·=>·'stopped', 
12676 ··} 
12677 } 
12678 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x812679 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
12679 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low12680 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
12680 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low12681 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
12681 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false12682 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
12682 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable12683 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
12683 #·Remediation·is·applicable·only·in·certain·platforms12684 #·Remediation·is·applicable·only·in·certain·platforms
12684 if·dpkg-query·--show·--showformat='${db:Status-Status}12685 if·dpkg-query·--show·--showformat='${db:Status-Status}
312 KB
./usr/share/doc/ssg-debderived/ssg-ubuntu2404-guide-cis_level1_server.html
    
Offset 88994, 95 lines modifiedOffset 88994, 95 lines modified
0015ba10:·612d·7461·7267·6574·3d22·2369·646d·3132··a-target="#idm120015ba10:·612d·7461·7267·6574·3d22·2369·646d·3132··a-target="#idm12
0015ba20:·3739·3022·2074·6162·696e·6465·783d·2230··790"·tabindex="00015ba20:·3739·3022·2074·6162·696e·6465·783d·2230··790"·tabindex="0
0015ba30:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·0015ba30:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
0015ba40:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f0015ba40:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
0015ba50:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act0015ba50:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
0015ba60:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"0015ba60:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
0015ba70:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed0015ba70:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
0015ba80:·6961·7469·6f6e·204b·7562·6572·6e65·7465··iation·Kubernete 
0015ba90:·7320·736e·6970·7065·7420·e287·b23c·2f61··s·snippet·...</a 
0015baa0:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class= 
0015bab0:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse· 
0015bac0:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id 
0015bad0:·6d31·3237·3930·223e·3c74·6162·6c65·2063··m12790"><table·c 
0015bae0:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl 
0015baf0:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table- 
0015bb00:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c 
0015bb10:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t 
0015bb20:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t 
0015bb30:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></ 
0015bb40:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru 
0015bb50:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6d··ption:</th><td>m 
0015bb60:·6564·6975·6d3c·2f74·643e·3c2f·7472·3e3c··edium</td></tr>< 
0015bb70:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</ 
0015bb80:·7468·3e3c·7464·3e74·7275·653c·2f74·643e··th><td>true</td> 
0015bb90:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str 
0015bba0:·6174·6567·793a·3c2f·7468·3e3c·7464·3e64··ategy:</th><td>d 
0015bbb0:·6973·6162·6c65·3c2f·7464·3e3c·2f74·723e··isable</td></tr> 
0015bbc0:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co 
0015bbd0:·6465·3e61·7069·5665·7273·696f·6e3a·206d··de>apiVersion:·m 
0015bbe0:·6163·6869·6e65·636f·6e66·6967·7572·6174··achineconfigurat 
0015bbf0:·696f·6e2e·6f70·656e·7368·6966·742e·696f··ion.openshift.io 
0015bc00:·2f76·310a·6b69·6e64·3a20·4d61·6368·696e··/v1.kind:·Machin 
0015bc10:·6543·6f6e·6669·670a·7370·6563·3a0a·2020··eConfig.spec:.·· 
0015bc20:·636f·6e66·6967·3a0a·2020·2020·6967·6e69··config:.····igni 
0015bc30:·7469·6f6e·3a0a·2020·2020·2020·7665·7273··tion:.······vers 
0015bc40:·696f·6e3a·2033·2e31·2e30·0a20·2020·2073··ion:·3.1.0.····s 
0015bc50:·7973·7465·6d64·3a0a·2020·2020·2020·756e··ystemd:.······un 
0015bc60:·6974·733a·0a20·2020·2020·202d·206e·616d··its:.······-·nam 
0015bc70:·653a·2062·6c75·6574·6f6f·7468·2e73·6572··e:·bluetooth.ser 
0015bc80:·7669·6365·0a20·2020·2020·2020·2065·6e61··vice.········ena 
0015bc90:·626c·6564·3a20·6661·6c73·650a·2020·2020··bled:·false.···· 
0015bca0:·2020·2020·6d61·736b·3a20·7472·7565·0a20······mask:·true.· 
0015bcb0:·2020·2020·202d·206e·616d·653a·2062·6c75·······-·name:·blu 
0015bcc0:·6574·6f6f·7468·2e73·6f63·6b65·740a·2020··etooth.socket.·· 
0015bcd0:·2020·2020·2020·656e·6162·6c65·643a·2066········enabled:·f 
0015bce0:·616c·7365·0a20·2020·2020·2020·206d·6173··alse.········mas 
0015bcf0:·6b3a·2074·7275·650a·3c2f·636f·6465·3e3c··k:·true.</code>< 
0015bd00:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl 
0015bd10:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc 
0015bd20:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl 
0015bd30:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat 
0015bd40:·612d·7461·7267·6574·3d22·2369·646d·3132··a-target="#idm12 
0015bd50:·3739·3122·2074·6162·696e·6465·783d·2230··791"·tabindex="0 
0015bd60:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"· 
0015bd70:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f 
0015bd80:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act 
0015bd90:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal" 
0015bda0:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed 
0015bdb0:·6961·7469·6f6e·2050·7570·7065·7420·736e··iation·Puppet·sn0015ba80:·6961·7469·6f6e·2050·7570·7065·7420·736e··iation·Puppet·sn
0015bdc0:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br0015ba90:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br
0015bdd0:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan0015baa0:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
0015bde0:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll0015bab0:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
0015bdf0:·6170·7365·2220·6964·3d22·6964·6d31·3237··apse"·id="idm1270015bac0:·6170·7365·2220·6964·3d22·6964·6d31·3237··apse"·id="idm127
0015be00:·3931·223e·3c74·6162·6c65·2063·6c61·7373··91"><table·class0015bad0:·3930·223e·3c74·6162·6c65·2063·6c61·7373··90"><table·class
0015be10:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st0015bae0:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st
0015be20:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord0015baf0:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord
0015be30:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde0015bb00:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde
0015be40:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co0015bb10:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co
0015be50:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t0015bb20:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t
0015be60:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><0015bb30:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
0015be70:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio0015bb40:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio
0015be80:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</0015bb50:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</
0015be90:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>0015bb60:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
0015bea0:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td>0015bb70:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td>
0015beb0:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr><0015bb80:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr><
0015bec0:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:0015bb90:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:
0015bed0:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<0015bba0:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<
0015bee0:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table0015bbb0:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table
0015bef0:·3e3c·7072·653e·3c63·6f64·653e·696e·636c··><pre><code>incl0015bbc0:·3e3c·7072·653e·3c63·6f64·653e·696e·636c··><pre><code>incl
0015bf00:·7564·6520·6469·7361·626c·655f·626c·7565··ude·disable_blue0015bbd0:·7564·6520·6469·7361·626c·655f·626c·7565··ude·disable_blue
0015bf10:·746f·6f74·680a·0a63·6c61·7373·2064·6973··tooth..class·dis0015bbe0:·746f·6f74·680a·0a63·6c61·7373·2064·6973··tooth..class·dis
0015bf20:·6162·6c65·5f62·6c75·6574·6f6f·7468·207b··able_bluetooth·{0015bbf0:·6162·6c65·5f62·6c75·6574·6f6f·7468·207b··able_bluetooth·{
0015bf30:·0a20·2073·6572·7669·6365·207b·2762·6c75··.··service·{'blu0015bc00:·0a20·2073·6572·7669·6365·207b·2762·6c75··.··service·{'blu
0015bf40:·6574·6f6f·7468·273a·0a20·2020·2065·6e61··etooth':.····ena0015bc10:·6574·6f6f·7468·273a·0a20·2020·2065·6e61··etooth':.····ena
0015bf50:·626c·6520·3d26·6774·3b20·6661·6c73·652c··ble·=&gt;·false,0015bc20:·626c·6520·3d26·6774·3b20·6661·6c73·652c··ble·=&gt;·false,
0015bf60:·0a20·2020·2065·6e73·7572·6520·3d26·6774··.····ensure·=&gt0015bc30:·0a20·2020·2065·6e73·7572·6520·3d26·6774··.····ensure·=&gt
0015bf70:·3b20·2773·746f·7070·6564·272c·0a20·207d··;·'stopped',.··}0015bc40:·3b20·2773·746f·7070·6564·272c·0a20·207d··;·'stopped',.··}
0015bf80:·0a7d·0a3c·2f63·6f64·653e·3c2f·7072·653e··.}.</code></pre>0015bc50:·0a7d·0a3c·2f63·6f64·653e·3c2f·7072·653e··.}.</code></pre>
 0015bc60:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class="
 0015bc70:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success"
 0015bc80:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co
 0015bc90:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar
 0015bca0:·6765·743d·2223·6964·6d31·3237·3931·2220··get="#idm12791"·
 0015bcb0:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol
 0015bcc0:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-
 0015bcd0:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"
 0015bce0:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate
 0015bcf0:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href
 0015bd00:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio
 0015bd10:·6e20·4b75·6265·726e·6574·6573·2073·6e69··n·Kubernetes·sni
 0015bd20:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>
 0015bd30:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
 0015bd40:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
 0015bd50:·7073·6522·2069·643d·2269·646d·3132·3739··pse"·id="idm1279
 0015bd60:·3122·3e3c·7461·626c·6520·636c·6173·733d··1"><table·class=
 0015bd70:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str
 0015bd80:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde
 0015bd90:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden
 0015bda0:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com
 0015bdb0:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td
 0015bdc0:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
 0015bdd0:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption
 0015bde0:·3a3c·2f74·683e·3c74·643e·6d65·6469·756d··:</th><td>medium
 0015bdf0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
 0015be00:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t
 0015be10:·643e·7472·7565·3c2f·7464·3e3c·2f74·723e··d>true</td></tr>
 0015be20:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy
 0015be30:·3a3c·2f74·683e·3c74·643e·6469·7361·626c··:</th><td>disabl
 0015be40:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab
 0015be50:·6c65·3e3c·7072·653e·3c63·6f64·653e·6170··le><pre><code>ap
 0015be60:·6956·6572·7369·6f6e·3a20·6d61·6368·696e··iVersion:·machin
 0015be70:·6563·6f6e·6669·6775·7261·7469·6f6e·2e6f··econfiguration.o
 0015be80:·7065·6e73·6869·6674·2e69·6f2f·7631·0a6b··penshift.io/v1.k
 0015be90:·696e·643a·204d·6163·6869·6e65·436f·6e66··ind:·MachineConf
 0015bea0:·6967·0a73·7065·633a·0a20·2063·6f6e·6669··ig.spec:.··confi
 0015beb0:·673a·0a20·2020·2069·676e·6974·696f·6e3a··g:.····ignition:
 0015bec0:·0a20·2020·2020·2076·6572·7369·6f6e·3a20··.······version:·
Max diff block lines reached; 265162/276918 bytes (95.75%) of diff not shown.
41.9 KB
html2text {}
    
Offset 17692, 14 lines modifiedOffset 17692, 27 lines modified
17692 ··-·medium_severity17692 ··-·medium_severity
17693 ··-·no_reboot_needed17693 ··-·no_reboot_needed
17694 ··-·service_bluetooth_disabled17694 ··-·service_bluetooth_disabled
17695 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x817695 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
17696 [customizations.services]17696 [customizations.services]
17697 masked·=·["bluetooth"]17697 masked·=·["bluetooth"]
 17698 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 17699 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 17700 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 17701 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 17702 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 17703 include·disable_bluetooth
  
 17704 class·disable_bluetooth·{
 17705 ··service·{'bluetooth':
 17706 ····enable·=>·false,
 17707 ····ensure·=>·'stopped',
 17708 ··}
 17709 }
17698 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x817710 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
17699 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low17711 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
17700 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium17712 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
17701 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true17713 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
17702 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable17714 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
17703 apiVersion:·machineconfiguration.openshift.io/v117715 apiVersion:·machineconfiguration.openshift.io/v1
17704 kind:·MachineConfig17716 kind:·MachineConfig
Offset 17711, 27 lines modifiedOffset 17724, 14 lines modified
17711 ······units:17724 ······units:
17712 ······-·name:·bluetooth.service17725 ······-·name:·bluetooth.service
17713 ········enabled:·false17726 ········enabled:·false
17714 ········mask:·true17727 ········mask:·true
17715 ······-·name:·bluetooth.socket17728 ······-·name:·bluetooth.socket
17716 ········enabled:·false17729 ········enabled:·false
17717 ········mask:·true17730 ········mask:·true
17718 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
17719 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
17720 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
17721 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
17722 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
17723 include·disable_bluetooth 
  
17724 class·disable_bluetooth·{ 
17725 ··service·{'bluetooth': 
17726 ····enable·=>·false, 
17727 ····ensure·=>·'stopped', 
17728 ··} 
17729 } 
17730 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x817731 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
17731 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low17732 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
17732 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low17733 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
17733 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false17734 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
17734 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable17735 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
17735 #·Remediation·is·applicable·only·in·certain·platforms17736 #·Remediation·is·applicable·only·in·certain·platforms
17736 if·dpkg-query·--show·--showformat='${db:Status-Status}17737 if·dpkg-query·--show·--showformat='${db:Status-Status}
Offset 20200, 14 lines modifiedOffset 20200, 27 lines modified
20200 ··-·medium_severity20200 ··-·medium_severity
20201 ··-·no_reboot_needed20201 ··-·no_reboot_needed
20202 ··-·service_autofs_disabled20202 ··-·service_autofs_disabled
20203 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x820203 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
20204 [customizations.services]20204 [customizations.services]
20205 masked·=·["autofs"]20205 masked·=·["autofs"]
 20206 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 20207 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 20208 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 20209 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 20210 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 20211 include·disable_autofs
  
 20212 class·disable_autofs·{
 20213 ··service·{'autofs':
 20214 ····enable·=>·false,
 20215 ····ensure·=>·'stopped',
 20216 ··}
 20217 }
20206 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x820218 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
20207 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low20219 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
20208 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium20220 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
20209 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true20221 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
20210 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable20222 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
20211 apiVersion:·machineconfiguration.openshift.io/v120223 apiVersion:·machineconfiguration.openshift.io/v1
20212 kind:·MachineConfig20224 kind:·MachineConfig
Offset 20219, 27 lines modifiedOffset 20232, 14 lines modified
20219 ······units:20232 ······units:
20220 ······-·name:·autofs.service20233 ······-·name:·autofs.service
20221 ········enabled:·false20234 ········enabled:·false
20222 ········mask:·true20235 ········mask:·true
20223 ······-·name:·autofs.socket20236 ······-·name:·autofs.socket
20224 ········enabled:·false20237 ········enabled:·false
20225 ········mask:·true20238 ········mask:·true
20226 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
20227 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
20228 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
20229 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
20230 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
20231 include·disable_autofs 
  
20232 class·disable_autofs·{ 
20233 ··service·{'autofs': 
20234 ····enable·=>·false, 
20235 ····ensure·=>·'stopped', 
20236 ··} 
20237 } 
20238 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x820239 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
20239 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low20240 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
20240 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low20241 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
20241 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false20242 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
20242 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable20243 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
20243 #·Remediation·is·applicable·only·in·certain·platforms20244 #·Remediation·is·applicable·only·in·certain·platforms
20244 if·(·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'autofs'·2>/dev/null·|·grep·-q·'^installed'·&&·dpkg-20245 if·(·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'autofs'·2>/dev/null·|·grep·-q·'^installed'·&&·dpkg-
Offset 25412, 14 lines modifiedOffset 25412, 27 lines modified
25412 ··-·no_reboot_needed25412 ··-·no_reboot_needed
25413 ··-·service_apport_disabled25413 ··-·service_apport_disabled
25414 ··-·unknown_severity25414 ··-·unknown_severity
25415 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x825415 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
25416 [customizations.services]25416 [customizations.services]
25417 masked·=·["apport"]25417 masked·=·["apport"]
 25418 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 25419 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 25420 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 25421 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 25422 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 25423 include·disable_apport
  
 25424 class·disable_apport·{
Max diff block lines reached; 38400/42901 bytes (89.51%) of diff not shown.
258 KB
./usr/share/doc/ssg-debderived/ssg-ubuntu2404-guide-cis_level1_workstation.html
    
Offset 115848, 94 lines modifiedOffset 115848, 94 lines modified
001c4870:·2d74·6172·6765·743d·2223·6964·6d31·3636··-target="#idm166001c4870:·2d74·6172·6765·743d·2223·6964·6d31·3636··-target="#idm166
001c4880:·3735·2220·7461·6269·6e64·6578·3d22·3022··75"·tabindex="0"001c4880:·3735·2220·7461·6269·6e64·6578·3d22·3022··75"·tabindex="0"
001c4890:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a001c4890:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
001c48a0:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa001c48a0:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
001c48b0:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti001c48b0:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
001c48c0:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·001c48c0:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
001c48d0:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi001c48d0:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
 001c48e0:·6174·696f·6e20·5075·7070·6574·2073·6e69··ation·Puppet·sni
 001c48f0:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>
 001c4900:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
 001c4910:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
 001c4920:·7073·6522·2069·643d·2269·646d·3136·3637··pse"·id="idm1667
 001c4930:·3522·3e3c·7461·626c·6520·636c·6173·733d··5"><table·class=
 001c4940:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str
 001c4950:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde
 001c4960:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden
 001c4970:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com
 001c4980:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td
 001c4990:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
 001c49a0:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption
 001c49b0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
 001c49c0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e52··d></tr><tr><th>R
 001c49d0:·6562·6f6f·743a·3c2f·7468·3e3c·7464·3e66··eboot:</th><td>f
 001c49e0:·616c·7365·3c2f·7464·3e3c·2f74·723e·3c74··alse</td></tr><t
 001c49f0:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<
 001c4a00:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</
 001c4a10:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table>
 001c4a20:·3c70·7265·3e3c·636f·6465·3e69·6e63·6c75··<pre><code>inclu
 001c4a30:·6465·2064·6973·6162·6c65·5f61·7070·6f72··de·disable_appor
 001c4a40:·740a·0a63·6c61·7373·2064·6973·6162·6c65··t..class·disable
 001c4a50:·5f61·7070·6f72·7420·7b0a·2020·7365·7276··_apport·{.··serv
 001c4a60:·6963·6520·7b27·6170·706f·7274·273a·0a20··ice·{'apport':.·
 001c4a70:·2020·2065·6e61·626c·6520·3d26·6774·3b20·····enable·=&gt;·
 001c4a80:·6661·6c73·652c·0a20·2020·2065·6e73·7572··false,.····ensur
 001c4a90:·6520·3d26·6774·3b20·2773·746f·7070·6564··e·=&gt;·'stopped
 001c4aa0:·272c·0a20·207d·0a7d·0a3c·2f63·6f64·653e··',.··}.}.</code>
 001c4ab0:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c
 001c4ac0:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su
 001c4ad0:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg
 001c4ae0:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da
 001c4af0:·7461·2d74·6172·6765·743d·2223·6964·6d31··ta-target="#idm1
 001c4b00:·3636·3736·2220·7461·6269·6e64·6578·3d22··6676"·tabindex="
 001c4b10:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
 001c4b20:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
 001c4b30:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
 001c4b40:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
 001c4b50:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
001c48e0:·6174·696f·6e20·4b75·6265·726e·6574·6573··ation·Kubernetes001c4b60:·6469·6174·696f·6e20·4b75·6265·726e·6574··diation·Kubernet
001c48f0:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>001c4b70:·6573·2073·6e69·7070·6574·20e2·87b2·3c2f··es·snippet·...</
001c4900:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="001c4b80:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
001c4910:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c001c4b90:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
001c4920:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm001c4ba0:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
001c4930:·3136·3637·3522·3e3c·7461·626c·6520·636c··16675"><table·cl001c4bb0:·646d·3136·3637·3622·3e3c·7461·626c·6520··dm16676"><table·
001c4940:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table001c4bc0:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab
001c4950:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b001c4bd0:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table
001c4960:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co001c4be0:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-
001c4970:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th001c4bf0:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><
001c4980:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th001c4c00:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</
001c4990:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t001c4c10:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
001c49a0:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup001c4c20:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr
001c49b0:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6d65··tion:</th><td>me001c4c30:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>
001c49c0:·6469·756d·3c2f·7464·3e3c·2f74·723e·3c74··dium</td></tr><t001c4c40:·6d65·6469·756d·3c2f·7464·3e3c·2f74·723e··medium</td></tr>
001c49d0:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t001c4c50:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:<
001c49e0:·683e·3c74·643e·7472·7565·3c2f·7464·3e3c··h><td>true</td><001c4c60:·2f74·683e·3c74·643e·7472·7565·3c2f·7464··/th><td>true</td
001c49f0:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra001c4c70:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St
001c4a00:·7465·6779·3a3c·2f74·683e·3c74·643e·6469··tegy:</th><td>di001c4c80:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>
001c4a10:·7361·626c·653c·2f74·643e·3c2f·7472·3e3c··sable</td></tr><001c4c90:·6469·7361·626c·653c·2f74·643e·3c2f·7472··disable</td></tr
001c4a20:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod001c4ca0:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c
001c4a30:·653e·6170·6956·6572·7369·6f6e·3a20·6d61··e>apiVersion:·ma001c4cb0:·6f64·653e·6170·6956·6572·7369·6f6e·3a20··ode>apiVersion:·
001c4a40:·6368·696e·6563·6f6e·6669·6775·7261·7469··chineconfigurati001c4cc0:·6d61·6368·696e·6563·6f6e·6669·6775·7261··machineconfigura
001c4a50:·6f6e·2e6f·7065·6e73·6869·6674·2e69·6f2f··on.openshift.io/001c4cd0:·7469·6f6e·2e6f·7065·6e73·6869·6674·2e69··tion.openshift.i
001c4a60:·7631·0a6b·696e·643a·204d·6163·6869·6e65··v1.kind:·Machine001c4ce0:·6f2f·7631·0a6b·696e·643a·204d·6163·6869··o/v1.kind:·Machi
001c4a70:·436f·6e66·6967·0a73·7065·633a·0a20·2063··Config.spec:.··c001c4cf0:·6e65·436f·6e66·6967·0a73·7065·633a·0a20··neConfig.spec:.·
001c4a80:·6f6e·6669·673a·0a20·2020·2069·676e·6974··onfig:.····ignit001c4d00:·2063·6f6e·6669·673a·0a20·2020·2069·676e···config:.····ign
001c4a90:·696f·6e3a·0a20·2020·2020·2076·6572·7369··ion:.······versi001c4d10:·6974·696f·6e3a·0a20·2020·2020·2076·6572··ition:.······ver
001c4aa0:·6f6e·3a20·332e·312e·300a·2020·2020·7379··on:·3.1.0.····sy001c4d20:·7369·6f6e·3a20·332e·312e·300a·2020·2020··sion:·3.1.0.····
001c4ab0:·7374·656d·643a·0a20·2020·2020·2075·6e69··stemd:.······uni001c4d30:·7379·7374·656d·643a·0a20·2020·2020·2075··systemd:.······u
001c4ac0:·7473·3a0a·2020·2020·2020·2d20·6e61·6d65··ts:.······-·name001c4d40:·6e69·7473·3a0a·2020·2020·2020·2d20·6e61··nits:.······-·na
001c4ad0:·3a20·6170·706f·7274·2e73·6572·7669·6365··:·apport.service001c4d50:·6d65·3a20·6170·706f·7274·2e73·6572·7669··me:·apport.servi
001c4ae0:·0a20·2020·2020·2020·2065·6e61·626c·6564··.········enabled001c4d60:·6365·0a20·2020·2020·2020·2065·6e61·626c··ce.········enabl
001c4af0:·3a20·6661·6c73·650a·2020·2020·2020·2020··:·false.········001c4d70:·6564·3a20·6661·6c73·650a·2020·2020·2020··ed:·false.······
001c4b00:·6d61·736b·3a20·7472·7565·0a20·2020·2020··mask:·true.·····001c4d80:·2020·6d61·736b·3a20·7472·7565·0a20·2020····mask:·true.···
001c4b10:·202d·206e·616d·653a·2061·7070·6f72·742e···-·name:·apport.001c4d90:·2020·202d·206e·616d·653a·2061·7070·6f72·····-·name:·appor
001c4b20:·736f·636b·6574·0a20·2020·2020·2020·2065··socket.········e001c4da0:·742e·736f·636b·6574·0a20·2020·2020·2020··t.socket.·······
001c4b30:·6e61·626c·6564·3a20·6661·6c73·650a·2020··nabled:·false.··001c4db0:·2065·6e61·626c·6564·3a20·6661·6c73·650a···enabled:·false.
001c4b40:·2020·2020·2020·6d61·736b·3a20·7472·7565········mask:·true001c4dc0:·2020·2020·2020·2020·6d61·736b·3a20·7472··········mask:·tr
001c4b50:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></ 
001c4b60:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt 
001c4b70:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d 
001c4b80:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll 
001c4b90:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe 
001c4ba0:·743d·2223·6964·6d31·3636·3736·2220·7461··t="#idm16676"·ta 
001c4bb0:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role= 
001c4bc0:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex 
001c4bd0:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t 
001c4be0:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t 
001c4bf0:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href=" 
001c4c00:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation· 
001c4c10:·5075·7070·6574·2073·6e69·7070·6574·20e2··Puppet·snippet·. 
001c4c20:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c 
001c4c30:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll 
001c4c40:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i 
001c4c50:·643d·2269·646d·3136·3637·3622·3e3c·7461··d="idm16676"><ta 
001c4c60:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table 
001c4c70:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t 
001c4c80:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta 
001c4c90:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed">< 
001c4ca0:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit 
001c4cb0:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</ 
001c4cc0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
001c4cd0:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th> 
001c4ce0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
001c4cf0:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot: 
001c4d00:·3c2f·7468·3e3c·7464·3e66·616c·7365·3c2f··</th><td>false</ 
001c4d10:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
001c4d20:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t 
001c4d30:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t 
001c4d40:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre>< 
001c4d50:·636f·6465·3e69·6e63·6c75·6465·2064·6973··code>include·dis 
001c4d60:·6162·6c65·5f61·7070·6f72·740a·0a63·6c61··able_apport..cla 
001c4d70:·7373·2064·6973·6162·6c65·5f61·7070·6f72··ss·disable_appor 
001c4d80:·7420·7b0a·2020·7365·7276·6963·6520·7b27··t·{.··service·{' 
001c4d90:·6170·706f·7274·273a·0a20·2020·2065·6e61··apport':.····ena 
001c4da0:·626c·6520·3d26·6774·3b20·6661·6c73·652c··ble·=&gt;·false, 
001c4db0:·0a20·2020·2065·6e73·7572·6520·3d26·6774··.····ensure·=&gt 
001c4dc0:·3b20·2773·746f·7070·6564·272c·0a20·207d··;·'stopped',.··} 
001c4dd0:·0a7d·0a3c·2f63·6f64·653e·3c2f·7072·653e··.}.</code></pre>001c4dd0:·7565·0a3c·2f63·6f64·653e·3c2f·7072·653e··ue.</code></pre>
Max diff block lines reached; 217026/228646 bytes (94.92%) of diff not shown.
34.5 KB
html2text {}
    
Offset 24424, 14 lines modifiedOffset 24424, 27 lines modified
24424 ··-·no_reboot_needed24424 ··-·no_reboot_needed
24425 ··-·service_apport_disabled24425 ··-·service_apport_disabled
24426 ··-·unknown_severity24426 ··-·unknown_severity
24427 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x824427 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
24428 [customizations.services]24428 [customizations.services]
24429 masked·=·["apport"]24429 masked·=·["apport"]
 24430 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 24431 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 24432 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 24433 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 24434 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 24435 include·disable_apport
  
 24436 class·disable_apport·{
 24437 ··service·{'apport':
 24438 ····enable·=>·false,
 24439 ····ensure·=>·'stopped',
 24440 ··}
 24441 }
24430 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x824442 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
24431 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low24443 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
24432 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium24444 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
24433 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true24445 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
24434 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable24446 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
24435 apiVersion:·machineconfiguration.openshift.io/v124447 apiVersion:·machineconfiguration.openshift.io/v1
24436 kind:·MachineConfig24448 kind:·MachineConfig
Offset 24443, 27 lines modifiedOffset 24456, 14 lines modified
24443 ······units:24456 ······units:
24444 ······-·name:·apport.service24457 ······-·name:·apport.service
24445 ········enabled:·false24458 ········enabled:·false
24446 ········mask:·true24459 ········mask:·true
24447 ······-·name:·apport.socket24460 ······-·name:·apport.socket
24448 ········enabled:·false24461 ········enabled:·false
24449 ········mask:·true24462 ········mask:·true
24450 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
24451 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
24452 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
24453 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
24454 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
24455 include·disable_apport 
  
24456 class·disable_apport·{ 
24457 ··service·{'apport': 
24458 ····enable·=>·false, 
24459 ····ensure·=>·'stopped', 
24460 ··} 
24461 } 
24462 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x824463 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
24463 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low24464 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
24464 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low24465 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
24465 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false24466 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
24466 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable24467 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
24467 #·Remediation·is·applicable·only·in·certain·platforms24468 #·Remediation·is·applicable·only·in·certain·platforms
24468 if·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'apport'·2>/dev/null·|·grep·-q·'^installed';·then24469 if·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'apport'·2>/dev/null·|·grep·-q·'^installed';·then
Offset 27202, 14 lines modifiedOffset 27202, 27 lines modified
27202 ··-·medium_severity27202 ··-·medium_severity
27203 ··-·no_reboot_needed27203 ··-·no_reboot_needed
27204 ··-·service_dhcpd6_disabled27204 ··-·service_dhcpd6_disabled
27205 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x827205 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
27206 [customizations.services]27206 [customizations.services]
27207 masked·=·["isc-dhcp-server6"]27207 masked·=·["isc-dhcp-server6"]
 27208 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 27209 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 27210 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 27211 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 27212 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 27213 include·disable_isc-dhcp-server6
  
 27214 class·disable_isc-dhcp-server6·{
 27215 ··service·{'isc-dhcp-server6':
 27216 ····enable·=>·false,
 27217 ····ensure·=>·'stopped',
 27218 ··}
 27219 }
27208 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x827220 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
27209 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low27221 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
27210 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium27222 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
27211 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true27223 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
27212 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable27224 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
27213 apiVersion:·machineconfiguration.openshift.io/v127225 apiVersion:·machineconfiguration.openshift.io/v1
27214 kind:·MachineConfig27226 kind:·MachineConfig
Offset 27221, 27 lines modifiedOffset 27234, 14 lines modified
27221 ······units:27234 ······units:
27222 ······-·name:·isc-dhcp-server6.service27235 ······-·name:·isc-dhcp-server6.service
27223 ········enabled:·false27236 ········enabled:·false
27224 ········mask:·true27237 ········mask:·true
27225 ······-·name:·isc-dhcp-server6.socket27238 ······-·name:·isc-dhcp-server6.socket
27226 ········enabled:·false27239 ········enabled:·false
27227 ········mask:·true27240 ········mask:·true
27228 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
27229 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
27230 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
27231 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
27232 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
27233 include·disable_isc-dhcp-server6 
  
27234 class·disable_isc-dhcp-server6·{ 
27235 ··service·{'isc-dhcp-server6': 
27236 ····enable·=>·false, 
27237 ····ensure·=>·'stopped', 
27238 ··} 
27239 } 
27240 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x827241 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
27241 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low27242 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
27242 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low27243 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
27243 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false27244 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
27244 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable27245 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
27245 #·Remediation·is·applicable·only·in·certain·platforms27246 #·Remediation·is·applicable·only·in·certain·platforms
27246 if·dpkg-query·--show·--showformat='${db:Status-Status}27247 if·dpkg-query·--show·--showformat='${db:Status-Status}
Offset 27382, 14 lines modifiedOffset 27382, 27 lines modified
27382 ··-·medium_severity27382 ··-·medium_severity
27383 ··-·no_reboot_needed27383 ··-·no_reboot_needed
27384 ··-·service_dhcpd_disabled27384 ··-·service_dhcpd_disabled
27385 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x827385 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
27386 [customizations.services]27386 [customizations.services]
27387 masked·=·["isc-dhcp-server"]27387 masked·=·["isc-dhcp-server"]
 27388 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 27389 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 27390 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 27391 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 27392 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 27393 include·disable_isc-dhcp-server
  
 27394 class·disable_isc-dhcp-server·{
Max diff block lines reached; 30755/35346 bytes (87.01%) of diff not shown.
313 KB
./usr/share/doc/ssg-debderived/ssg-ubuntu2404-guide-cis_level2_server.html
    
Offset 94841, 95 lines modifiedOffset 94841, 95 lines modified
00172780:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="00172780:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
00172790:·2369·646d·3132·3739·3022·2074·6162·696e··#idm12790"·tabin00172790:·2369·646d·3132·3739·3022·2074·6162·696e··#idm12790"·tabin
001727a0:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu001727a0:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
001727b0:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan001727b0:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
001727c0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl001727c0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
001727d0:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r001727d0:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
001727e0:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"001727e0:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
001727f0:·3e52·656d·6564·6961·7469·6f6e·204b·7562··>Remediation·Kub 
00172800:·6572·6e65·7465·7320·736e·6970·7065·7420··ernetes·snippet· 
00172810:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div· 
00172820:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col 
00172830:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"· 
00172840:·6964·3d22·6964·6d31·3237·3930·223e·3c74··id="idm12790"><t 
00172850:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl 
00172860:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped· 
00172870:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t 
00172880:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed"> 
00172890:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi 
001728a0:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low< 
001728b0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
001728c0:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th 
001728d0:·3e3c·7464·3e6d·6564·6975·6d3c·2f74·643e··><td>medium</td> 
001728e0:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb 
001728f0:·6f6f·743a·3c2f·7468·3e3c·7464·3e74·7275··oot:</th><td>tru 
00172900:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr>< 
00172910:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th 
00172920:·3e3c·7464·3e64·6973·6162·6c65·3c2f·7464··><td>disable</td 
00172930:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p 
00172940:·7265·3e3c·636f·6465·3e61·7069·5665·7273··re><code>apiVers 
00172950:·696f·6e3a·206d·6163·6869·6e65·636f·6e66··ion:·machineconf 
00172960:·6967·7572·6174·696f·6e2e·6f70·656e·7368··iguration.opensh 
00172970:·6966·742e·696f·2f76·310a·6b69·6e64·3a20··ift.io/v1.kind:· 
00172980:·4d61·6368·696e·6543·6f6e·6669·670a·7370··MachineConfig.sp 
00172990:·6563·3a0a·2020·636f·6e66·6967·3a0a·2020··ec:.··config:.·· 
001729a0:·2020·6967·6e69·7469·6f6e·3a0a·2020·2020····ignition:.···· 
001729b0:·2020·7665·7273·696f·6e3a·2033·2e31·2e30····version:·3.1.0 
001729c0:·0a20·2020·2073·7973·7465·6d64·3a0a·2020··.····systemd:.·· 
001729d0:·2020·2020·756e·6974·733a·0a20·2020·2020······units:.····· 
001729e0:·202d·206e·616d·653a·2062·6c75·6574·6f6f···-·name:·bluetoo 
001729f0:·7468·2e73·6572·7669·6365·0a20·2020·2020··th.service.····· 
00172a00:·2020·2065·6e61·626c·6564·3a20·6661·6c73·····enabled:·fals 
00172a10:·650a·2020·2020·2020·2020·6d61·736b·3a20··e.········mask:· 
00172a20:·7472·7565·0a20·2020·2020·202d·206e·616d··true.······-·nam 
00172a30:·653a·2062·6c75·6574·6f6f·7468·2e73·6f63··e:·bluetooth.soc 
00172a40:·6b65·740a·2020·2020·2020·2020·656e·6162··ket.········enab 
00172a50:·6c65·643a·2066·616c·7365·0a20·2020·2020··led:·false.····· 
00172a60:·2020·206d·6173·6b3a·2074·7275·650a·3c2f·····mask:·true.</ 
00172a70:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div 
00172a80:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b 
00172a90:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data 
00172aa0:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps 
00172ab0:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target=" 
00172ac0:·2369·646d·3132·3739·3122·2074·6162·696e··#idm12791"·tabin 
00172ad0:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu 
00172ae0:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan 
00172af0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl 
00172b00:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r 
00172b10:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!" 
00172b20:·3e52·656d·6564·6961·7469·6f6e·2050·7570··>Remediation·Pup001727f0:·3e52·656d·6564·6961·7469·6f6e·2050·7570··>Remediation·Pup
00172b30:·7065·7420·736e·6970·7065·7420·e287·b23c··pet·snippet·...<00172800:·7065·7420·736e·6970·7065·7420·e287·b23c··pet·snippet·...<
00172b40:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas00172810:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas
00172b50:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps00172820:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps
00172b60:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="00172830:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="
00172b70:·6964·6d31·3237·3931·223e·3c74·6162·6c65··idm12791"><table00172840:·6964·6d31·3237·3930·223e·3c74·6162·6c65··idm12790"><table
00172b80:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta00172850:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta
00172b90:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl00172860:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl
00172ba0:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table00172870:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table
00172bb0:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>00172880:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>
00172bc0:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<00172890:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<
00172bd0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>001728a0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
00172be0:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis001728b0:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis
00172bf0:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td001728c0:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td
00172c00:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t001728d0:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
00172c10:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t001728e0:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t
00172c20:·683e·3c74·643e·6661·6c73·653c·2f74·643e··h><td>false</td>001728f0:·683e·3c74·643e·6661·6c73·653c·2f74·643e··h><td>false</td>
00172c30:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str00172900:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str
00172c40:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e00172910:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e
00172c50:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr><00172920:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr><
00172c60:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod00172930:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod
00172c70:·653e·696e·636c·7564·6520·6469·7361·626c··e>include·disabl00172940:·653e·696e·636c·7564·6520·6469·7361·626c··e>include·disabl
00172c80:·655f·626c·7565·746f·6f74·680a·0a63·6c61··e_bluetooth..cla00172950:·655f·626c·7565·746f·6f74·680a·0a63·6c61··e_bluetooth..cla
00172c90:·7373·2064·6973·6162·6c65·5f62·6c75·6574··ss·disable_bluet00172960:·7373·2064·6973·6162·6c65·5f62·6c75·6574··ss·disable_bluet
00172ca0:·6f6f·7468·207b·0a20·2073·6572·7669·6365··ooth·{.··service00172970:·6f6f·7468·207b·0a20·2073·6572·7669·6365··ooth·{.··service
00172cb0:·207b·2762·6c75·6574·6f6f·7468·273a·0a20···{'bluetooth':.·00172980:·207b·2762·6c75·6574·6f6f·7468·273a·0a20···{'bluetooth':.·
00172cc0:·2020·2065·6e61·626c·6520·3d26·6774·3b20·····enable·=&gt;·00172990:·2020·2065·6e61·626c·6520·3d26·6774·3b20·····enable·=&gt;·
00172cd0:·6661·6c73·652c·0a20·2020·2065·6e73·7572··false,.····ensur001729a0:·6661·6c73·652c·0a20·2020·2065·6e73·7572··false,.····ensur
00172ce0:·6520·3d26·6774·3b20·2773·746f·7070·6564··e·=&gt;·'stopped001729b0:·6520·3d26·6774·3b20·2773·746f·7070·6564··e·=&gt;·'stopped
00172cf0:·272c·0a20·207d·0a7d·0a3c·2f63·6f64·653e··',.··}.}.</code>001729c0:·272c·0a20·207d·0a7d·0a3c·2f63·6f64·653e··',.··}.}.</code>
 001729d0:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c
 001729e0:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su
 001729f0:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg
 00172a00:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da
 00172a10:·7461·2d74·6172·6765·743d·2223·6964·6d31··ta-target="#idm1
 00172a20:·3237·3931·2220·7461·6269·6e64·6578·3d22··2791"·tabindex="
 00172a30:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
 00172a40:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
 00172a50:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
 00172a60:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
 00172a70:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
 00172a80:·6469·6174·696f·6e20·4b75·6265·726e·6574··diation·Kubernet
 00172a90:·6573·2073·6e69·7070·6574·20e2·87b2·3c2f··es·snippet·...</
 00172aa0:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
 00172ab0:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
 00172ac0:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
 00172ad0:·646d·3132·3739·3122·3e3c·7461·626c·6520··dm12791"><table·
 00172ae0:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab
 00172af0:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table
 00172b00:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-
 00172b10:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><
 00172b20:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</
 00172b30:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
 00172b40:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr
 00172b50:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>
 00172b60:·6d65·6469·756d·3c2f·7464·3e3c·2f74·723e··medium</td></tr>
 00172b70:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:<
 00172b80:·2f74·683e·3c74·643e·7472·7565·3c2f·7464··/th><td>true</td
 00172b90:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St
 00172ba0:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>
 00172bb0:·6469·7361·626c·653c·2f74·643e·3c2f·7472··disable</td></tr
 00172bc0:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c
 00172bd0:·6f64·653e·6170·6956·6572·7369·6f6e·3a20··ode>apiVersion:·
 00172be0:·6d61·6368·696e·6563·6f6e·6669·6775·7261··machineconfigura
 00172bf0:·7469·6f6e·2e6f·7065·6e73·6869·6674·2e69··tion.openshift.i
 00172c00:·6f2f·7631·0a6b·696e·643a·204d·6163·6869··o/v1.kind:·Machi
 00172c10:·6e65·436f·6e66·6967·0a73·7065·633a·0a20··neConfig.spec:.·
 00172c20:·2063·6f6e·6669·673a·0a20·2020·2069·676e···config:.····ign
 00172c30:·6974·696f·6e3a·0a20·2020·2020·2076·6572··ition:.······ver
Max diff block lines reached; 265438/277194 bytes (95.76%) of diff not shown.
41.9 KB
html2text {}
    
Offset 18931, 14 lines modifiedOffset 18931, 27 lines modified
18931 ··-·medium_severity18931 ··-·medium_severity
18932 ··-·no_reboot_needed18932 ··-·no_reboot_needed
18933 ··-·service_bluetooth_disabled18933 ··-·service_bluetooth_disabled
18934 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x818934 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
18935 [customizations.services]18935 [customizations.services]
18936 masked·=·["bluetooth"]18936 masked·=·["bluetooth"]
 18937 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 18938 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 18939 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 18940 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 18941 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 18942 include·disable_bluetooth
  
 18943 class·disable_bluetooth·{
 18944 ··service·{'bluetooth':
 18945 ····enable·=>·false,
 18946 ····ensure·=>·'stopped',
 18947 ··}
 18948 }
18937 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x818949 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
18938 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low18950 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
18939 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium18951 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
18940 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true18952 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
18941 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable18953 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
18942 apiVersion:·machineconfiguration.openshift.io/v118954 apiVersion:·machineconfiguration.openshift.io/v1
18943 kind:·MachineConfig18955 kind:·MachineConfig
Offset 18950, 27 lines modifiedOffset 18963, 14 lines modified
18950 ······units:18963 ······units:
18951 ······-·name:·bluetooth.service18964 ······-·name:·bluetooth.service
18952 ········enabled:·false18965 ········enabled:·false
18953 ········mask:·true18966 ········mask:·true
18954 ······-·name:·bluetooth.socket18967 ······-·name:·bluetooth.socket
18955 ········enabled:·false18968 ········enabled:·false
18956 ········mask:·true18969 ········mask:·true
18957 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
18958 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
18959 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
18960 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
18961 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
18962 include·disable_bluetooth 
  
18963 class·disable_bluetooth·{ 
18964 ··service·{'bluetooth': 
18965 ····enable·=>·false, 
18966 ····ensure·=>·'stopped', 
18967 ··} 
18968 } 
18969 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x818970 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
18970 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low18971 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
18971 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low18972 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
18972 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false18973 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
18973 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable18974 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
18974 #·Remediation·is·applicable·only·in·certain·platforms18975 #·Remediation·is·applicable·only·in·certain·platforms
18975 if·dpkg-query·--show·--showformat='${db:Status-Status}18976 if·dpkg-query·--show·--showformat='${db:Status-Status}
Offset 21439, 14 lines modifiedOffset 21439, 27 lines modified
21439 ··-·medium_severity21439 ··-·medium_severity
21440 ··-·no_reboot_needed21440 ··-·no_reboot_needed
21441 ··-·service_autofs_disabled21441 ··-·service_autofs_disabled
21442 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x821442 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
21443 [customizations.services]21443 [customizations.services]
21444 masked·=·["autofs"]21444 masked·=·["autofs"]
 21445 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 21446 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 21447 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 21448 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 21449 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 21450 include·disable_autofs
  
 21451 class·disable_autofs·{
 21452 ··service·{'autofs':
 21453 ····enable·=>·false,
 21454 ····ensure·=>·'stopped',
 21455 ··}
 21456 }
21445 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x821457 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
21446 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low21458 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
21447 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium21459 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
21448 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true21460 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
21449 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable21461 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
21450 apiVersion:·machineconfiguration.openshift.io/v121462 apiVersion:·machineconfiguration.openshift.io/v1
21451 kind:·MachineConfig21463 kind:·MachineConfig
Offset 21458, 27 lines modifiedOffset 21471, 14 lines modified
21458 ······units:21471 ······units:
21459 ······-·name:·autofs.service21472 ······-·name:·autofs.service
21460 ········enabled:·false21473 ········enabled:·false
21461 ········mask:·true21474 ········mask:·true
21462 ······-·name:·autofs.socket21475 ······-·name:·autofs.socket
21463 ········enabled:·false21476 ········enabled:·false
21464 ········mask:·true21477 ········mask:·true
21465 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
21466 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
21467 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
21468 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
21469 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
21470 include·disable_autofs 
  
21471 class·disable_autofs·{ 
21472 ··service·{'autofs': 
21473 ····enable·=>·false, 
21474 ····ensure·=>·'stopped', 
21475 ··} 
21476 } 
21477 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x821478 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
21478 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low21479 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
21479 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low21480 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
21480 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false21481 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
21481 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable21482 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
21482 #·Remediation·is·applicable·only·in·certain·platforms21483 #·Remediation·is·applicable·only·in·certain·platforms
21483 if·(·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'autofs'·2>/dev/null·|·grep·-q·'^installed'·&&·dpkg-21484 if·(·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'autofs'·2>/dev/null·|·grep·-q·'^installed'·&&·dpkg-
Offset 26836, 14 lines modifiedOffset 26836, 27 lines modified
26836 ··-·no_reboot_needed26836 ··-·no_reboot_needed
26837 ··-·service_apport_disabled26837 ··-·service_apport_disabled
26838 ··-·unknown_severity26838 ··-·unknown_severity
26839 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x826839 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
26840 [customizations.services]26840 [customizations.services]
26841 masked·=·["apport"]26841 masked·=·["apport"]
 26842 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 26843 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 26844 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 26845 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 26846 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 26847 include·disable_apport
  
 26848 class·disable_apport·{
Max diff block lines reached; 38400/42901 bytes (89.51%) of diff not shown.
312 KB
./usr/share/doc/ssg-debderived/ssg-ubuntu2404-guide-cis_level2_workstation.html
    
Offset 94506, 95 lines modifiedOffset 94506, 95 lines modified
00171290:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=00171290:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
001712a0:·2223·6964·6d31·3237·3930·2220·7461·6269··"#idm12790"·tabi001712a0:·2223·6964·6d31·3237·3930·2220·7461·6269··"#idm12790"·tabi
001712b0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b001712b0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
001712c0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa001712c0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
001712d0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit001712d0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
001712e0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·001712e0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
001712f0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!001712f0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
00171300:·223e·5265·6d65·6469·6174·696f·6e20·4b75··">Remediation·Ku 
00171310:·6265·726e·6574·6573·2073·6e69·7070·6574··bernetes·snippet 
00171320:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div 
00171330:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co 
00171340:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse" 
00171350:·2069·643d·2269·646d·3132·3739·3022·3e3c···id="idm12790">< 
00171360:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab 
00171370:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped 
00171380:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered· 
00171390:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed" 
001713a0:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex 
001713b0:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low 
001713c0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
001713d0:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t 
001713e0:·683e·3c74·643e·6d65·6469·756d·3c2f·7464··h><td>medium</td 
001713f0:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re 
00171400:·626f·6f74·3a3c·2f74·683e·3c74·643e·7472··boot:</th><td>tr 
00171410:·7565·3c2f·7464·3e3c·2f74·723e·3c74·723e··ue</td></tr><tr> 
00171420:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t 
00171430:·683e·3c74·643e·6469·7361·626c·653c·2f74··h><td>disable</t 
00171440:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table>< 
00171450:·7072·653e·3c63·6f64·653e·6170·6956·6572··pre><code>apiVer 
00171460:·7369·6f6e·3a20·6d61·6368·696e·6563·6f6e··sion:·machinecon 
00171470:·6669·6775·7261·7469·6f6e·2e6f·7065·6e73··figuration.opens 
00171480:·6869·6674·2e69·6f2f·7631·0a6b·696e·643a··hift.io/v1.kind: 
00171490:·204d·6163·6869·6e65·436f·6e66·6967·0a73···MachineConfig.s 
001714a0:·7065·633a·0a20·2063·6f6e·6669·673a·0a20··pec:.··config:.· 
001714b0:·2020·2069·676e·6974·696f·6e3a·0a20·2020·····ignition:.··· 
001714c0:·2020·2076·6572·7369·6f6e·3a20·332e·312e·····version:·3.1. 
001714d0:·300a·2020·2020·7379·7374·656d·643a·0a20··0.····systemd:.· 
001714e0:·2020·2020·2075·6e69·7473·3a0a·2020·2020·······units:.···· 
001714f0:·2020·2d20·6e61·6d65·3a20·626c·7565·746f····-·name:·blueto 
00171500:·6f74·682e·7365·7276·6963·650a·2020·2020··oth.service.···· 
00171510:·2020·2020·656e·6162·6c65·643a·2066·616c······enabled:·fal 
00171520:·7365·0a20·2020·2020·2020·206d·6173·6b3a··se.········mask: 
00171530:·2074·7275·650a·2020·2020·2020·2d20·6e61···true.······-·na 
00171540:·6d65·3a20·626c·7565·746f·6f74·682e·736f··me:·bluetooth.so 
00171550:·636b·6574·0a20·2020·2020·2020·2065·6e61··cket.········ena 
00171560:·626c·6564·3a20·6661·6c73·650a·2020·2020··bled:·false.···· 
00171570:·2020·2020·6d61·736b·3a20·7472·7565·0a3c······mask:·true.< 
00171580:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di 
00171590:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn· 
001715a0:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat 
001715b0:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap 
001715c0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target= 
001715d0:·2223·6964·6d31·3237·3931·2220·7461·6269··"#idm12791"·tabi 
001715e0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b 
001715f0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa 
00171600:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit 
00171610:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to· 
00171620:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#! 
00171630:·223e·5265·6d65·6469·6174·696f·6e20·5075··">Remediation·Pu00171300:·223e·5265·6d65·6469·6174·696f·6e20·5075··">Remediation·Pu
00171640:·7070·6574·2073·6e69·7070·6574·20e2·87b2··ppet·snippet·...00171310:·7070·6574·2073·6e69·7070·6574·20e2·87b2··ppet·snippet·...
00171650:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla00171320:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
00171660:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap00171330:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
00171670:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=00171340:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
00171680:·2269·646d·3132·3739·3122·3e3c·7461·626c··"idm12791"><tabl00171350:·2269·646d·3132·3739·3022·3e3c·7461·626c··"idm12790"><tabl
00171690:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t00171360:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t
001716a0:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab00171370:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab
001716b0:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl00171380:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl
001716c0:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr00171390:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr
001716d0:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:001713a0:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:
001716e0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td001713b0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
001716f0:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di001713c0:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di
00171700:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t001713d0:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t
00171710:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><001713e0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
00171720:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</001713f0:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</
00171730:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td00171400:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td
00171740:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St00171410:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St
00171750:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>00171420:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>
00171760:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr>00171430:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr>
00171770:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co00171440:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co
00171780:·6465·3e69·6e63·6c75·6465·2064·6973·6162··de>include·disab00171450:·6465·3e69·6e63·6c75·6465·2064·6973·6162··de>include·disab
00171790:·6c65·5f62·6c75·6574·6f6f·7468·0a0a·636c··le_bluetooth..cl00171460:·6c65·5f62·6c75·6574·6f6f·7468·0a0a·636c··le_bluetooth..cl
001717a0:·6173·7320·6469·7361·626c·655f·626c·7565··ass·disable_blue00171470:·6173·7320·6469·7361·626c·655f·626c·7565··ass·disable_blue
001717b0:·746f·6f74·6820·7b0a·2020·7365·7276·6963··tooth·{.··servic00171480:·746f·6f74·6820·7b0a·2020·7365·7276·6963··tooth·{.··servic
001717c0:·6520·7b27·626c·7565·746f·6f74·6827·3a0a··e·{'bluetooth':.00171490:·6520·7b27·626c·7565·746f·6f74·6827·3a0a··e·{'bluetooth':.
001717d0:·2020·2020·656e·6162·6c65·203d·2667·743b······enable·=&gt;001714a0:·2020·2020·656e·6162·6c65·203d·2667·743b······enable·=&gt;
001717e0:·2066·616c·7365·2c0a·2020·2020·656e·7375···false,.····ensu001714b0:·2066·616c·7365·2c0a·2020·2020·656e·7375···false,.····ensu
001717f0:·7265·203d·2667·743b·2027·7374·6f70·7065··re·=&gt;·'stoppe001714c0:·7265·203d·2667·743b·2027·7374·6f70·7065··re·=&gt;·'stoppe
00171800:·6427·2c0a·2020·7d0a·7d0a·3c2f·636f·6465··d',.··}.}.</code001714d0:·6427·2c0a·2020·7d0a·7d0a·3c2f·636f·6465··d',.··}.}.</code
 001714e0:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a·
 001714f0:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s
 00171500:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog
 00171510:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d
 00171520:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
 00171530:·3132·3739·3122·2074·6162·696e·6465·783d··12791"·tabindex=
 00171540:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button
 00171550:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=
 00171560:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A
 00171570:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea
 00171580:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem
 00171590:·6564·6961·7469·6f6e·204b·7562·6572·6e65··ediation·Kuberne
 001715a0:·7465·7320·736e·6970·7065·7420·e287·b23c··tes·snippet·...<
 001715b0:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas
 001715c0:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps
 001715d0:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="
 001715e0:·6964·6d31·3237·3931·223e·3c74·6162·6c65··idm12791"><table
 001715f0:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta
 00171600:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl
 00171610:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table
 00171620:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>
 00171630:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<
 00171640:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
 00171650:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis
 00171660:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td
 00171670:·3e6d·6564·6975·6d3c·2f74·643e·3c2f·7472··>medium</td></tr
 00171680:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot:
 00171690:·3c2f·7468·3e3c·7464·3e74·7275·653c·2f74··</th><td>true</t
 001716a0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S
 001716b0:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td
 001716c0:·3e64·6973·6162·6c65·3c2f·7464·3e3c·2f74··>disable</td></t
 001716d0:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><
 001716e0:·636f·6465·3e61·7069·5665·7273·696f·6e3a··code>apiVersion:
 001716f0:·206d·6163·6869·6e65·636f·6e66·6967·7572···machineconfigur
 00171700:·6174·696f·6e2e·6f70·656e·7368·6966·742e··ation.openshift.
 00171710:·696f·2f76·310a·6b69·6e64·3a20·4d61·6368··io/v1.kind:·Mach
 00171720:·696e·6543·6f6e·6669·670a·7370·6563·3a0a··ineConfig.spec:.
 00171730:·2020·636f·6e66·6967·3a0a·2020·2020·6967····config:.····ig
 00171740:·6e69·7469·6f6e·3a0a·2020·2020·2020·7665··nition:.······ve
Max diff block lines reached; 265024/276780 bytes (95.75%) of diff not shown.
41.9 KB
html2text {}
    
Offset 18852, 14 lines modifiedOffset 18852, 27 lines modified
18852 ··-·medium_severity18852 ··-·medium_severity
18853 ··-·no_reboot_needed18853 ··-·no_reboot_needed
18854 ··-·service_bluetooth_disabled18854 ··-·service_bluetooth_disabled
18855 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x818855 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
18856 [customizations.services]18856 [customizations.services]
18857 masked·=·["bluetooth"]18857 masked·=·["bluetooth"]
 18858 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 18859 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 18860 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 18861 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 18862 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 18863 include·disable_bluetooth
  
 18864 class·disable_bluetooth·{
 18865 ··service·{'bluetooth':
 18866 ····enable·=>·false,
 18867 ····ensure·=>·'stopped',
 18868 ··}
 18869 }
18858 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x818870 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
18859 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low18871 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
18860 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium18872 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
18861 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true18873 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
18862 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable18874 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
18863 apiVersion:·machineconfiguration.openshift.io/v118875 apiVersion:·machineconfiguration.openshift.io/v1
18864 kind:·MachineConfig18876 kind:·MachineConfig
Offset 18871, 27 lines modifiedOffset 18884, 14 lines modified
18871 ······units:18884 ······units:
18872 ······-·name:·bluetooth.service18885 ······-·name:·bluetooth.service
18873 ········enabled:·false18886 ········enabled:·false
18874 ········mask:·true18887 ········mask:·true
18875 ······-·name:·bluetooth.socket18888 ······-·name:·bluetooth.socket
18876 ········enabled:·false18889 ········enabled:·false
18877 ········mask:·true18890 ········mask:·true
18878 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
18879 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
18880 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
18881 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
18882 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
18883 include·disable_bluetooth 
  
18884 class·disable_bluetooth·{ 
18885 ··service·{'bluetooth': 
18886 ····enable·=>·false, 
18887 ····ensure·=>·'stopped', 
18888 ··} 
18889 } 
18890 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x818891 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
18891 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low18892 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
18892 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low18893 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
18893 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false18894 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
18894 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable18895 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
18895 #·Remediation·is·applicable·only·in·certain·platforms18896 #·Remediation·is·applicable·only·in·certain·platforms
18896 if·dpkg-query·--show·--showformat='${db:Status-Status}18897 if·dpkg-query·--show·--showformat='${db:Status-Status}
Offset 21223, 14 lines modifiedOffset 21223, 27 lines modified
21223 ··-·medium_severity21223 ··-·medium_severity
21224 ··-·no_reboot_needed21224 ··-·no_reboot_needed
21225 ··-·service_autofs_disabled21225 ··-·service_autofs_disabled
21226 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x821226 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
21227 [customizations.services]21227 [customizations.services]
21228 masked·=·["autofs"]21228 masked·=·["autofs"]
 21229 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 21230 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 21231 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 21232 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 21233 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 21234 include·disable_autofs
  
 21235 class·disable_autofs·{
 21236 ··service·{'autofs':
 21237 ····enable·=>·false,
 21238 ····ensure·=>·'stopped',
 21239 ··}
 21240 }
21229 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x821241 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
21230 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low21242 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
21231 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium21243 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
21232 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true21244 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
21233 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable21245 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
21234 apiVersion:·machineconfiguration.openshift.io/v121246 apiVersion:·machineconfiguration.openshift.io/v1
21235 kind:·MachineConfig21247 kind:·MachineConfig
Offset 21242, 27 lines modifiedOffset 21255, 14 lines modified
21242 ······units:21255 ······units:
21243 ······-·name:·autofs.service21256 ······-·name:·autofs.service
21244 ········enabled:·false21257 ········enabled:·false
21245 ········mask:·true21258 ········mask:·true
21246 ······-·name:·autofs.socket21259 ······-·name:·autofs.socket
21247 ········enabled:·false21260 ········enabled:·false
21248 ········mask:·true21261 ········mask:·true
21249 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
21250 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
21251 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
21252 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
21253 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
21254 include·disable_autofs 
  
21255 class·disable_autofs·{ 
21256 ··service·{'autofs': 
21257 ····enable·=>·false, 
21258 ····ensure·=>·'stopped', 
21259 ··} 
21260 } 
21261 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x821262 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
21262 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low21263 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
21263 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low21264 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
21264 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false21265 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
21265 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable21266 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
21266 #·Remediation·is·applicable·only·in·certain·platforms21267 #·Remediation·is·applicable·only·in·certain·platforms
21267 if·(·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'autofs'·2>/dev/null·|·grep·-q·'^installed'·&&·dpkg-21268 if·(·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'autofs'·2>/dev/null·|·grep·-q·'^installed'·&&·dpkg-
Offset 26620, 14 lines modifiedOffset 26620, 27 lines modified
26620 ··-·no_reboot_needed26620 ··-·no_reboot_needed
26621 ··-·service_apport_disabled26621 ··-·service_apport_disabled
26622 ··-·unknown_severity26622 ··-·unknown_severity
26623 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x826623 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
26624 [customizations.services]26624 [customizations.services]
26625 masked·=·["apport"]26625 masked·=·["apport"]
 26626 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 26627 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 26628 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 26629 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 26630 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 26631 include·disable_apport
  
 26632 class·disable_apport·{
Max diff block lines reached; 38400/42901 bytes (89.51%) of diff not shown.
717 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu1604-ds.xml
717 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu1604-ds.xml
    
Offset 21, 23 lines modifiedOffset 21, 23 lines modified
21 ····<ds:checks>21 ····<ds:checks>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu1604-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu1604-oval.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu1604-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu1604-oval.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu1604-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu1604-ocil.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu1604-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu1604-ocil.xml"/>
24 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu1604-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu1604-cpe-oval.xml"/>24 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu1604-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu1604-cpe-oval.xml"/>
25 ······<ds:component-ref·id="scap_org.open-scap_cref_oval-com.ubuntu.xenial.usn.oval.xml.bz2"·xlink:href="https://security-metadata.canonical.com/oval/com.ubuntu.xenial.usn.oval.xml.bz2"/>25 ······<ds:component-ref·id="scap_org.open-scap_cref_oval-com.ubuntu.xenial.usn.oval.xml.bz2"·xlink:href="https://security-metadata.canonical.com/oval/com.ubuntu.xenial.usn.oval.xml.bz2"/>
26 ····</ds:checks>26 ····</ds:checks>
27 ··</ds:data-stream>27 ··</ds:data-stream>
28 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu1604-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">28 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu1604-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
29 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">29 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
30 ······<cpe-dict:cpe-item·name="cpe:/o:canonical:ubuntu_linux:16.04::~~lts~~~">30 ······<cpe-dict:cpe-item·name="cpe:/o:canonical:ubuntu_linux:16.04::~~lts~~~">
31 ········<cpe-dict:title·xml:lang="en-us">Ubuntu·release·16.04·(Xenial)</cpe-dict:title>31 ········<cpe-dict:title·xml:lang="en-us">Ubuntu·release·16.04·(Xenial)</cpe-dict:title>
32 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml">oval:ssg-installed_OS_is_ubuntu1604:def:1</cpe-dict:check>32 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml">oval:ssg-installed_OS_is_ubuntu1604:def:1</cpe-dict:check>
33 ······</cpe-dict:cpe-item>33 ······</cpe-dict:cpe-item>
34 ····</cpe-dict:cpe-list>34 ····</cpe-dict:cpe-list>
35 ··</ds:component>35 ··</ds:component>
36 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu1604-xccdf.xml"·timestamp="2025-02-28T20:08:00">36 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu1604-xccdf.xml"·timestamp="2025-03-01T22:08:00">
37 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_UBUNTU-XENIAL"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">37 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_UBUNTU-XENIAL"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
38 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>38 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
39 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Ubuntu·16.04</xccdf-1.2:title>39 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Ubuntu·16.04</xccdf-1.2:title>
40 ······<xccdf-1.2:description>40 ······<xccdf-1.2:description>
41 ········This·guide·presents·a·catalog·of·security-relevant41 ········This·guide·presents·a·catalog·of·security-relevant
42 configuration·settings·for·Ubuntu·16.04.·It·is·a·rendering·of42 configuration·settings·for·Ubuntu·16.04.·It·is·a·rendering·of
43 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)43 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 107, 175 lines modifiedOffset 107, 175 lines modified
107 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>107 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
108 ······<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>108 ······<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
109 ······<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>109 ······<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
110 ······<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>110 ······<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
111 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>111 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
112 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>112 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
113 ······<cpe-lang:platform-specification>113 ······<cpe-lang:platform-specification>
114 ········<cpe-lang:platform·id="machine">114 ········<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">
115 ··········<cpe-lang:logical-test·operator="AND"·negate="false">115 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 116 ············<cpe-lang:logical-test·operator="AND"·negate="true">
 117 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
 118 ············</cpe-lang:logical-test>
 119 ············<cpe-lang:logical-test·operator="AND"·negate="true">
 120 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
 121 ············</cpe-lang:logical-test>
116 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>122 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
117 ··········</cpe-lang:logical-test>123 ··········</cpe-lang:logical-test>
118 ········</cpe-lang:platform>124 ········</cpe-lang:platform>
119 ········<cpe-lang:platform·id="package_pam">125 ········<cpe-lang:platform·id="package_gdm">
120 ··········<cpe-lang:logical-test·operator="AND"·negate="false">126 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
121 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>127 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_gdm:def:1"/>
122 ··········</cpe-lang:logical-test>128 ··········</cpe-lang:logical-test>
123 ········</cpe-lang:platform>129 ········</cpe-lang:platform>
124 ········<cpe-lang:platform·id="not_package_chrony_and_not_package_ntp">130 ········<cpe-lang:platform·id="package_rsyslog">
125 ··········<cpe-lang:logical-test·operator="AND"·negate="false">131 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
126 ············<cpe-lang:logical-test·operator="AND"·negate="true"> 
127 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>132 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>
128 ············</cpe-lang:logical-test> 
129 ············<cpe-lang:logical-test·operator="AND"·negate="true"> 
130 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_ntp:def:1"/> 
131 ············</cpe-lang:logical-test> 
132 ··········</cpe-lang:logical-test>133 ··········</cpe-lang:logical-test>
133 ········</cpe-lang:platform>134 ········</cpe-lang:platform>
134 ········<cpe-lang:platform·id="package_iptables">135 ········<cpe-lang:platform·id="package_logrotate">
135 ··········<cpe-lang:logical-test·operator="AND"·negate="false">136 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
136 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>137 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_logrotate:def:1"/>
137 ··········</cpe-lang:logical-test>138 ··········</cpe-lang:logical-test>
138 ········</cpe-lang:platform>139 ········</cpe-lang:platform>
139 ········<cpe-lang:platform·id="not_container">140 ········<cpe-lang:platform·id="package_chrony">
140 ··········<cpe-lang:logical-test·operator="AND"·negate="true">141 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
141 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_container:def:1"/>142 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
142 ··········</cpe-lang:logical-test>143 ··········</cpe-lang:logical-test>
143 ········</cpe-lang:platform>144 ········</cpe-lang:platform>
144 ········<cpe-lang:platform·id="package_rsyslog">145 ········<cpe-lang:platform·id="package_ufw_and_system_with_kernel">
145 ··········<cpe-lang:logical-test·operator="AND"·negate="false">146 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
146 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>147 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
 148 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
 149 ··········</cpe-lang:logical-test>
 150 ········</cpe-lang:platform>
 151 ········<cpe-lang:platform·id="package_rsh-server">
 152 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 153 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_rsh-server:def:1"/>
147 ··········</cpe-lang:logical-test>154 ··········</cpe-lang:logical-test>
148 ········</cpe-lang:platform>155 ········</cpe-lang:platform>
149 ········<cpe-lang:platform·id="package_systemd">156 ········<cpe-lang:platform·id="package_systemd">
150 ··········<cpe-lang:logical-test·operator="AND"·negate="false">157 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
151 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>158 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>
152 ··········</cpe-lang:logical-test>159 ··········</cpe-lang:logical-test>
153 ········</cpe-lang:platform>160 ········</cpe-lang:platform>
154 ········<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">161 ········<cpe-lang:platform·id="package_iptables_and_service_disabled_firewalld_and_system_with_kernel">
155 ··········<cpe-lang:logical-test·operator="AND"·negate="false">162 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
156 ············<cpe-lang:logical-test·operator="AND"·negate="true"> 
157 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/> 
158 ············</cpe-lang:logical-test> 
159 ············<cpe-lang:logical-test·operator="AND"·negate="true"> 
160 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/> 
161 ············</cpe-lang:logical-test> 
162 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>163 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
 164 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_firewalld:def:1"/>
 165 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
163 ··········</cpe-lang:logical-test>166 ··········</cpe-lang:logical-test>
164 ········</cpe-lang:platform>167 ········</cpe-lang:platform>
165 ········<cpe-lang:platform·id="package_postfix">168 ········<cpe-lang:platform·id="aarch64_arch_or_x86_64_arch">
166 ··········<cpe-lang:logical-test·operator="AND"·negate="false">169 ··········<cpe-lang:logical-test·operator="OR"·negate="false">
 170 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
167 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_postfix:def:1"/>171 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/>
168 ··········</cpe-lang:logical-test>172 ··········</cpe-lang:logical-test>
169 ········</cpe-lang:platform>173 ········</cpe-lang:platform>
170 ········<cpe-lang:platform·id="package_audit">174 ········<cpe-lang:platform·id="not_package_chrony_and_not_package_ntp">
171 ··········<cpe-lang:logical-test·operator="AND"·negate="false">175 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 176 ············<cpe-lang:logical-test·operator="AND"·negate="true">
 177 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
 178 ············</cpe-lang:logical-test>
 179 ············<cpe-lang:logical-test·operator="AND"·negate="true">
172 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_audit:def:1"/>180 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_ntp:def:1"/>
 181 ············</cpe-lang:logical-test>
173 ··········</cpe-lang:logical-test>182 ··········</cpe-lang:logical-test>
174 ········</cpe-lang:platform>183 ········</cpe-lang:platform>
175 ········<cpe-lang:platform·id="package_logrotate">184 ········<cpe-lang:platform·id="package_pam">
176 ··········<cpe-lang:logical-test·operator="AND"·negate="false">185 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
177 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_logrotate:def:1"/>186 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>
178 ··········</cpe-lang:logical-test>187 ··········</cpe-lang:logical-test>
179 ········</cpe-lang:platform>188 ········</cpe-lang:platform>
180 ········<cpe-lang:platform·id="package_ntp">189 ········<cpe-lang:platform·id="machine">
181 ··········<cpe-lang:logical-test·operator="AND"·negate="false">190 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
182 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_ntp:def:1"/>191 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
183 ··········</cpe-lang:logical-test>192 ··········</cpe-lang:logical-test>
184 ········</cpe-lang:platform>193 ········</cpe-lang:platform>
185 ········<cpe-lang:platform·id="package_sudo">194 ········<cpe-lang:platform·id="package_sudo">
186 ··········<cpe-lang:logical-test·operator="AND"·negate="false">195 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
187 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_sudo:def:1"/>196 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_sudo:def:1"/>
188 ··········</cpe-lang:logical-test>197 ··········</cpe-lang:logical-test>
189 ········</cpe-lang:platform>198 ········</cpe-lang:platform>
Max diff block lines reached; 720137/734319 bytes (98.07%) of diff not shown.
659 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu1604-ocil.xml
659 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu1604-ocil.xml
Ordering differences only
    
Offset 3, 5052 lines modifiedOffset 3, 4980 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_syn_cookies_ocil:questionnaire:1"> 
11 ······<ocil:title>Enable·TCP/IP·syncookie·support</ocil:title> 
12 ······<ocil:actions> 
13 ········<ocil:test_action_ref>ocil:ssg-kernel_config_syn_cookies_action:testaction:1</ocil:test_action_ref> 
14 ······</ocil:actions> 
15 ····</ocil:questionnaire> 
16 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_library_dirs_ocil:questionnaire:1"> 
17 ······<ocil:title>Verify·that·Shared·Library·Files·Have·Restrictive·Permissions</ocil:title> 
18 ······<ocil:actions> 
19 ········<ocil:test_action_ref>ocil:ssg-file_permissions_library_dirs_action:testaction:1</ocil:test_action_ref> 
20 ······</ocil:actions> 
21 ····</ocil:questionnaire> 
22 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_time_adjtimex_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_file_deletion_events_rmdir_ocil:questionnaire:1">
 11 ······<ocil:title>Ensure·auditd·Collects·File·Deletion·Events·by·User·-·rmdir</ocil:title>
23 ······<ocil:title>Record·attempts·to·alter·time·through·adjtimex</ocil:title> 
24 ······<ocil:actions> 
25 ········<ocil:test_action_ref>ocil:ssg-audit_rules_time_adjtimex_action:testaction:1</ocil:test_action_ref> 
26 ······</ocil:actions> 
27 ····</ocil:questionnaire> 
28 ····<ocil:questionnaire·id="ocil:ssg-package_chrony_installed_ocil:questionnaire:1"> 
29 ······<ocil:title>The·Chrony·package·is·installed</ocil:title> 
30 ······<ocil:actions>12 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-package_chrony_installed_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-audit_rules_file_deletion_events_rmdir_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>14 ······</ocil:actions>
33 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-auditd_local_events_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-sshd_rekey_limit_ocil:questionnaire:1">
35 ······<ocil:title>Include·Local·Events·in·Audit·Logs</ocil:title>17 ······<ocil:title>Force·frequent·session·key·renegotiation</ocil:title>
36 ······<ocil:actions>18 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-auditd_local_events_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-sshd_rekey_limit_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>20 ······</ocil:actions>
39 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_root_login_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_file_deletion_events_unlinkat_ocil:questionnaire:1">
41 ······<ocil:title>Disable·SSH·Root·Login</ocil:title>23 ······<ocil:title>Ensure·auditd·Collects·File·Deletion·Events·by·User·-·unlinkat</ocil:title>
42 ······<ocil:actions>24 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_root_login_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-audit_rules_file_deletion_events_unlinkat_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>26 ······</ocil:actions>
45 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-sshd_set_loglevel_verbose_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-accounts_logon_fail_delay_ocil:questionnaire:1">
47 ······<ocil:title>Set·SSH·Daemon·LogLevel·to·VERBOSE</ocil:title>29 ······<ocil:title>Ensure·the·Logon·Failure·Delay·is·Set·Correctly·in·login.defs</ocil:title>
48 ······<ocil:actions>30 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-sshd_set_loglevel_verbose_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-accounts_logon_fail_delay_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>32 ······</ocil:actions>
51 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-dir_ownership_library_dirs_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_file_deletion_events_unlink_ocil:questionnaire:1">
53 ······<ocil:title>Verify·that·Shared·Library·Directories·Have·Root·Ownership</ocil:title>35 ······<ocil:title>Ensure·auditd·Collects·File·Deletion·Events·by·User·-·unlink</ocil:title>
54 ······<ocil:actions>36 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-dir_ownership_library_dirs_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-audit_rules_file_deletion_events_unlink_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>38 ······</ocil:actions>
57 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-set_iptables_default_rule_forward_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-service_iptables_enabled_ocil:questionnaire:1">
59 ······<ocil:title>Set·Default·iptables·Policy·for·Forwarded·Packets</ocil:title>41 ······<ocil:title>Verify·iptables·Enabled</ocil:title>
60 ······<ocil:actions>42 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-set_iptables_default_rule_forward_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-service_iptables_enabled_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>44 ······</ocil:actions>
63 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_unmap_kernel_at_el0_ocil:questionnaire:1"> 
65 ······<ocil:title>Unmap·kernel·when·running·in·userspace·(aka·KAISER)</ocil:title>46 ····<ocil:questionnaire·id="ocil:ssg-set_ip6tables_default_rule_ocil:questionnaire:1">
 47 ······<ocil:title>Set·Default·ip6tables·Policy·for·Incoming·Packets</ocil:title>
66 ······<ocil:actions>48 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-kernel_config_unmap_kernel_at_el0_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-set_ip6tables_default_rule_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>50 ······</ocil:actions>
69 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-disallow_bypass_password_sudo_ocil:questionnaire:1"> 
71 ······<ocil:title>Disallow·Configuration·to·Bypass·Password·Requirements·for·Privilege·Escalation</ocil:title>52 ····<ocil:questionnaire·id="ocil:ssg-service_systemd-journald_enabled_ocil:questionnaire:1">
 53 ······<ocil:title>Enable·systemd-journald·Service</ocil:title>
72 ······<ocil:actions>54 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-disallow_bypass_password_sudo_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-service_systemd-journald_enabled_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>56 ······</ocil:actions>
75 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_warn_age_login_defs_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-file_owner_etc_passwd_ocil:questionnaire:1">
77 ······<ocil:title>Set·Password·Warning·Age</ocil:title>59 ······<ocil:title>Verify·User·Who·Owns·passwd·File</ocil:title>
78 ······<ocil:actions>60 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-accounts_password_warn_age_login_defs_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-file_owner_etc_passwd_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>62 ······</ocil:actions>
81 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_backup_etc_group_ocil:questionnaire:1"> 
83 ······<ocil:title>Verify·Group·Who·Owns·Backup·group·File</ocil:title>64 ····<ocil:questionnaire·id="ocil:ssg-postfix_client_configure_relayhost_ocil:questionnaire:1">
 65 ······<ocil:title>Configure·System·to·Forward·All·Mail·through·a·specific·host</ocil:title>
84 ······<ocil:actions>66 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_backup_etc_group_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-postfix_client_configure_relayhost_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>68 ······</ocil:actions>
87 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-service_auditd_enabled_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_x86_vsyscall_emulation_ocil:questionnaire:1">
89 ······<ocil:title>Enable·auditd·Service</ocil:title>71 ······<ocil:title>Disable·x86·vsyscall·emulation</ocil:title>
90 ······<ocil:actions>72 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-service_auditd_enabled_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-kernel_config_x86_vsyscall_emulation_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>74 ······</ocil:actions>
93 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_randomize_base_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-audit_privileged_commands_shutdown_ocil:questionnaire:1">
95 ······<ocil:title>Randomize·the·address·of·the·kernel·image·(KASLR)</ocil:title>77 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·shutdown</ocil:title>
96 ······<ocil:actions>78 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-kernel_config_randomize_base_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-audit_privileged_commands_shutdown_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>80 ······</ocil:actions>
99 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-kernel_module_ipv6_option_disabled_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-package_syslogng_installed_ocil:questionnaire:1">
101 ······<ocil:title>Disable·IPv6·Networking·Support·Automatic·Loading</ocil:title>83 ······<ocil:title>Ensure·syslog-ng·is·Installed</ocil:title>
102 ······<ocil:actions>84 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-kernel_module_ipv6_option_disabled_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-package_syslogng_installed_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>86 ······</ocil:actions>
105 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_disk_error_action_stig_ocil:questionnaire:1"> 
107 ······<ocil:title>Configure·auditd·Disk·Error·Action·on·Disk·Error</ocil:title>88 ····<ocil:questionnaire·id="ocil:ssg-grub2_rng_core_default_quality_argument_ocil:questionnaire:1">
 89 ······<ocil:title>Configure·the·confidence·in·TPM·for·entropy</ocil:title>
108 ······<ocil:actions>90 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-auditd_data_disk_error_action_stig_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-grub2_rng_core_default_quality_argument_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>92 ······</ocil:actions>
111 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-sudo_add_noexec_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-sshd_set_login_grace_time_ocil:questionnaire:1">
113 ······<ocil:title>Ensure·Privileged·Escalated·Commands·Cannot·Execute·Other·Commands·-·sudo·NOEXEC</ocil:title>95 ······<ocil:title>Ensure·SSH·LoginGraceTime·is·configured</ocil:title>
114 ······<ocil:actions>96 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-sudo_add_noexec_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-sshd_set_login_grace_time_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>98 ······</ocil:actions>
117 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_root_password_login_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-restrict_serial_port_logins_ocil:questionnaire:1">
119 ······<ocil:title>Disable·SSH·root·Login·with·a·Password·(Insecure)</ocil:title>101 ······<ocil:title>Restrict·Serial·Port·Root·Logins</ocil:title>
120 ······<ocil:actions>102 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_root_password_login_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-restrict_serial_port_logins_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>104 ······</ocil:actions>
123 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
124 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_time_watch_localtime_ocil:questionnaire:1"> 
Max diff block lines reached; 662405/674342 bytes (98.23%) of diff not shown.
23.7 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu1604-xccdf.xml
23.6 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu1604-xccdf.xml
Ordering differences only
    
Offset 72, 175 lines modifiedOffset 72, 175 lines modified
72 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>72 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
73 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>73 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
74 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>74 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
75 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>75 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
77 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>77 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
78 ··<cpe-lang:platform-specification>78 ··<cpe-lang:platform-specification>
79 ····<cpe-lang:platform·id="machine">79 ····<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">
80 ······<cpe-lang:logical-test·operator="AND"·negate="false">80 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 81 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 82 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
 83 ········</cpe-lang:logical-test>
 84 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 85 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
 86 ········</cpe-lang:logical-test>
81 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>87 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
82 ······</cpe-lang:logical-test>88 ······</cpe-lang:logical-test>
83 ····</cpe-lang:platform>89 ····</cpe-lang:platform>
84 ····<cpe-lang:platform·id="package_pam">90 ····<cpe-lang:platform·id="package_gdm">
85 ······<cpe-lang:logical-test·operator="AND"·negate="false">91 ······<cpe-lang:logical-test·operator="AND"·negate="false">
86 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>92 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_gdm:def:1"/>
87 ······</cpe-lang:logical-test>93 ······</cpe-lang:logical-test>
88 ····</cpe-lang:platform>94 ····</cpe-lang:platform>
89 ····<cpe-lang:platform·id="not_package_chrony_and_not_package_ntp">95 ····<cpe-lang:platform·id="package_rsyslog">
90 ······<cpe-lang:logical-test·operator="AND"·negate="false">96 ······<cpe-lang:logical-test·operator="AND"·negate="false">
91 ········<cpe-lang:logical-test·operator="AND"·negate="true"> 
92 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>97 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>
93 ········</cpe-lang:logical-test> 
94 ········<cpe-lang:logical-test·operator="AND"·negate="true"> 
95 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_ntp:def:1"/> 
96 ········</cpe-lang:logical-test> 
97 ······</cpe-lang:logical-test>98 ······</cpe-lang:logical-test>
98 ····</cpe-lang:platform>99 ····</cpe-lang:platform>
99 ····<cpe-lang:platform·id="package_iptables">100 ····<cpe-lang:platform·id="package_logrotate">
100 ······<cpe-lang:logical-test·operator="AND"·negate="false">101 ······<cpe-lang:logical-test·operator="AND"·negate="false">
101 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>102 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_logrotate:def:1"/>
102 ······</cpe-lang:logical-test>103 ······</cpe-lang:logical-test>
103 ····</cpe-lang:platform>104 ····</cpe-lang:platform>
104 ····<cpe-lang:platform·id="not_container">105 ····<cpe-lang:platform·id="package_chrony">
105 ······<cpe-lang:logical-test·operator="AND"·negate="true">106 ······<cpe-lang:logical-test·operator="AND"·negate="false">
106 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_container:def:1"/>107 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
107 ······</cpe-lang:logical-test>108 ······</cpe-lang:logical-test>
108 ····</cpe-lang:platform>109 ····</cpe-lang:platform>
109 ····<cpe-lang:platform·id="package_rsyslog">110 ····<cpe-lang:platform·id="package_ufw_and_system_with_kernel">
110 ······<cpe-lang:logical-test·operator="AND"·negate="false">111 ······<cpe-lang:logical-test·operator="AND"·negate="false">
111 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>112 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
 113 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
 114 ······</cpe-lang:logical-test>
 115 ····</cpe-lang:platform>
 116 ····<cpe-lang:platform·id="package_rsh-server">
 117 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 118 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_rsh-server:def:1"/>
112 ······</cpe-lang:logical-test>119 ······</cpe-lang:logical-test>
113 ····</cpe-lang:platform>120 ····</cpe-lang:platform>
114 ····<cpe-lang:platform·id="package_systemd">121 ····<cpe-lang:platform·id="package_systemd">
115 ······<cpe-lang:logical-test·operator="AND"·negate="false">122 ······<cpe-lang:logical-test·operator="AND"·negate="false">
116 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>123 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>
117 ······</cpe-lang:logical-test>124 ······</cpe-lang:logical-test>
118 ····</cpe-lang:platform>125 ····</cpe-lang:platform>
119 ····<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">126 ····<cpe-lang:platform·id="package_iptables_and_service_disabled_firewalld_and_system_with_kernel">
120 ······<cpe-lang:logical-test·operator="AND"·negate="false">127 ······<cpe-lang:logical-test·operator="AND"·negate="false">
121 ········<cpe-lang:logical-test·operator="AND"·negate="true"> 
122 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/> 
123 ········</cpe-lang:logical-test> 
124 ········<cpe-lang:logical-test·operator="AND"·negate="true"> 
125 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/> 
126 ········</cpe-lang:logical-test> 
127 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>128 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
 129 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_firewalld:def:1"/>
 130 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
128 ······</cpe-lang:logical-test>131 ······</cpe-lang:logical-test>
129 ····</cpe-lang:platform>132 ····</cpe-lang:platform>
130 ····<cpe-lang:platform·id="package_postfix">133 ····<cpe-lang:platform·id="aarch64_arch_or_x86_64_arch">
131 ······<cpe-lang:logical-test·operator="AND"·negate="false">134 ······<cpe-lang:logical-test·operator="OR"·negate="false">
 135 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
132 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_postfix:def:1"/>136 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/>
133 ······</cpe-lang:logical-test>137 ······</cpe-lang:logical-test>
134 ····</cpe-lang:platform>138 ····</cpe-lang:platform>
135 ····<cpe-lang:platform·id="package_audit">139 ····<cpe-lang:platform·id="not_package_chrony_and_not_package_ntp">
136 ······<cpe-lang:logical-test·operator="AND"·negate="false">140 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 141 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 142 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
 143 ········</cpe-lang:logical-test>
 144 ········<cpe-lang:logical-test·operator="AND"·negate="true">
137 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_audit:def:1"/>145 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_ntp:def:1"/>
 146 ········</cpe-lang:logical-test>
138 ······</cpe-lang:logical-test>147 ······</cpe-lang:logical-test>
139 ····</cpe-lang:platform>148 ····</cpe-lang:platform>
140 ····<cpe-lang:platform·id="package_logrotate">149 ····<cpe-lang:platform·id="package_pam">
141 ······<cpe-lang:logical-test·operator="AND"·negate="false">150 ······<cpe-lang:logical-test·operator="AND"·negate="false">
142 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_logrotate:def:1"/>151 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>
143 ······</cpe-lang:logical-test>152 ······</cpe-lang:logical-test>
144 ····</cpe-lang:platform>153 ····</cpe-lang:platform>
145 ····<cpe-lang:platform·id="package_ntp">154 ····<cpe-lang:platform·id="machine">
146 ······<cpe-lang:logical-test·operator="AND"·negate="false">155 ······<cpe-lang:logical-test·operator="AND"·negate="false">
147 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_ntp:def:1"/>156 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
148 ······</cpe-lang:logical-test>157 ······</cpe-lang:logical-test>
149 ····</cpe-lang:platform>158 ····</cpe-lang:platform>
150 ····<cpe-lang:platform·id="package_sudo">159 ····<cpe-lang:platform·id="package_sudo">
151 ······<cpe-lang:logical-test·operator="AND"·negate="false">160 ······<cpe-lang:logical-test·operator="AND"·negate="false">
152 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_sudo:def:1"/>161 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_sudo:def:1"/>
153 ······</cpe-lang:logical-test>162 ······</cpe-lang:logical-test>
154 ····</cpe-lang:platform>163 ····</cpe-lang:platform>
 164 ····<cpe-lang:platform·id="system_with_kernel">
155 ····<cpe-lang:platform·id="aarch64_arch_or_x86_64_arch"> 
156 ······<cpe-lang:logical-test·operator="OR"·negate="false"> 
157 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/> 
158 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/> 
159 ······</cpe-lang:logical-test> 
160 ····</cpe-lang:platform> 
161 ····<cpe-lang:platform·id="x86_64_arch"> 
162 ······<cpe-lang:logical-test·operator="AND"·negate="false">165 ······<cpe-lang:logical-test·operator="AND"·negate="false">
163 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/>166 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
164 ······</cpe-lang:logical-test>167 ······</cpe-lang:logical-test>
165 ····</cpe-lang:platform>168 ····</cpe-lang:platform>
166 ····<cpe-lang:platform·id="not_aarch64_arch_and_not_s390x_arch">169 ····<cpe-lang:platform·id="not_aarch64_arch_and_not_s390x_arch">
167 ······<cpe-lang:logical-test·operator="AND"·negate="false">170 ······<cpe-lang:logical-test·operator="AND"·negate="false">
168 ········<cpe-lang:logical-test·operator="AND"·negate="true">171 ········<cpe-lang:logical-test·operator="AND"·negate="true">
169 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>172 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
170 ········</cpe-lang:logical-test>173 ········</cpe-lang:logical-test>
171 ········<cpe-lang:logical-test·operator="AND"·negate="true">174 ········<cpe-lang:logical-test·operator="AND"·negate="true">
172 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_s390x:def:1"/>175 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_s390x:def:1"/>
173 ········</cpe-lang:logical-test>176 ········</cpe-lang:logical-test>
174 ······</cpe-lang:logical-test>177 ······</cpe-lang:logical-test>
175 ····</cpe-lang:platform>178 ····</cpe-lang:platform>
176 ····<cpe-lang:platform·id="not_aarch64_arch">179 ····<cpe-lang:platform·id="package_ntp">
177 ······<cpe-lang:logical-test·operator="AND"·negate="true">180 ······<cpe-lang:logical-test·operator="AND"·negate="false">
Max diff block lines reached; 10915/24054 bytes (45.38%) of diff not shown.
754 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu1804-ds.xml
753 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu1804-ds.xml
    
Offset 21, 23 lines modifiedOffset 21, 23 lines modified
21 ····<ds:checks>21 ····<ds:checks>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu1804-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu1804-oval.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu1804-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu1804-oval.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu1804-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu1804-ocil.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu1804-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu1804-ocil.xml"/>
24 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu1804-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu1804-cpe-oval.xml"/>24 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu1804-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu1804-cpe-oval.xml"/>
25 ······<ds:component-ref·id="scap_org.open-scap_cref_oval-com.ubuntu.bionic.usn.oval.xml.bz2"·xlink:href="https://security-metadata.canonical.com/oval/com.ubuntu.bionic.usn.oval.xml.bz2"/>25 ······<ds:component-ref·id="scap_org.open-scap_cref_oval-com.ubuntu.bionic.usn.oval.xml.bz2"·xlink:href="https://security-metadata.canonical.com/oval/com.ubuntu.bionic.usn.oval.xml.bz2"/>
26 ····</ds:checks>26 ····</ds:checks>
27 ··</ds:data-stream>27 ··</ds:data-stream>
28 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu1804-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">28 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu1804-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
29 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">29 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
30 ······<cpe-dict:cpe-item·name="cpe:/o:canonical:ubuntu_linux:18.04::~~lts~~~">30 ······<cpe-dict:cpe-item·name="cpe:/o:canonical:ubuntu_linux:18.04::~~lts~~~">
31 ········<cpe-dict:title·xml:lang="en-us">Ubuntu·release·18.04·(Bionic·Beaver)</cpe-dict:title>31 ········<cpe-dict:title·xml:lang="en-us">Ubuntu·release·18.04·(Bionic·Beaver)</cpe-dict:title>
32 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml">oval:ssg-installed_OS_is_ubuntu1804:def:1</cpe-dict:check>32 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml">oval:ssg-installed_OS_is_ubuntu1804:def:1</cpe-dict:check>
33 ······</cpe-dict:cpe-item>33 ······</cpe-dict:cpe-item>
34 ····</cpe-dict:cpe-list>34 ····</cpe-dict:cpe-list>
35 ··</ds:component>35 ··</ds:component>
36 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu1804-xccdf.xml"·timestamp="2025-02-28T20:08:00">36 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu1804-xccdf.xml"·timestamp="2025-03-01T22:08:00">
37 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_UBUNTU-BIONIC"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">37 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_UBUNTU-BIONIC"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
38 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>38 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
39 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Ubuntu·18.04</xccdf-1.2:title>39 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Ubuntu·18.04</xccdf-1.2:title>
40 ······<xccdf-1.2:description>40 ······<xccdf-1.2:description>
41 ········This·guide·presents·a·catalog·of·security-relevant41 ········This·guide·presents·a·catalog·of·security-relevant
42 configuration·settings·for·Ubuntu·18.04.·It·is·a·rendering·of42 configuration·settings·for·Ubuntu·18.04.·It·is·a·rendering·of
43 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)43 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 107, 196 lines modifiedOffset 107, 196 lines modified
107 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>107 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
108 ······<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>108 ······<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
109 ······<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>109 ······<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
110 ······<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>110 ······<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
111 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>111 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
112 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>112 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
113 ······<cpe-lang:platform-specification>113 ······<cpe-lang:platform-specification>
114 ········<cpe-lang:platform·id="machine">114 ········<cpe-lang:platform·id="mount_var-tmp">
115 ··········<cpe-lang:logical-test·operator="AND"·negate="false"> 
116 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/> 
117 ··········</cpe-lang:logical-test> 
118 ········</cpe-lang:platform> 
119 ········<cpe-lang:platform·id="package_pam"> 
120 ··········<cpe-lang:logical-test·operator="AND"·negate="false">115 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
121 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>116 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-tmp:def:1"/>
122 ··········</cpe-lang:logical-test>117 ··········</cpe-lang:logical-test>
123 ········</cpe-lang:platform>118 ········</cpe-lang:platform>
124 ········<cpe-lang:platform·id="package_autofs_and_system_with_kernel">119 ········<cpe-lang:platform·id="package_autofs_and_system_with_kernel">
125 ··········<cpe-lang:logical-test·operator="AND"·negate="false">120 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
126 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>121 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>
127 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>122 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
128 ··········</cpe-lang:logical-test>123 ··········</cpe-lang:logical-test>
129 ········</cpe-lang:platform>124 ········</cpe-lang:platform>
130 ········<cpe-lang:platform·id="mount_tmp"> 
131 ··········<cpe-lang:logical-test·operator="AND"·negate="false"> 
132 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_tmp:def:1"/> 
133 ··········</cpe-lang:logical-test> 
134 ········</cpe-lang:platform> 
135 ········<cpe-lang:platform·id="not_package_chrony_and_not_package_ntp">125 ········<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">
136 ··········<cpe-lang:logical-test·operator="AND"·negate="false">126 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
137 ············<cpe-lang:logical-test·operator="AND"·negate="true">127 ············<cpe-lang:logical-test·operator="AND"·negate="true">
138 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>128 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
139 ············</cpe-lang:logical-test>129 ············</cpe-lang:logical-test>
140 ············<cpe-lang:logical-test·operator="AND"·negate="true">130 ············<cpe-lang:logical-test·operator="AND"·negate="true">
141 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_ntp:def:1"/>131 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
142 ············</cpe-lang:logical-test>132 ············</cpe-lang:logical-test>
143 ··········</cpe-lang:logical-test> 
144 ········</cpe-lang:platform> 
145 ········<cpe-lang:platform·id="package_iptables"> 
146 ··········<cpe-lang:logical-test·operator="AND"·negate="false"> 
147 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>133 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
148 ··········</cpe-lang:logical-test>134 ··········</cpe-lang:logical-test>
149 ········</cpe-lang:platform>135 ········</cpe-lang:platform>
150 ········<cpe-lang:platform·id="not_container">136 ········<cpe-lang:platform·id="package_gdm">
151 ··········<cpe-lang:logical-test·operator="AND"·negate="true">137 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
152 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_container:def:1"/>138 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_gdm:def:1"/>
153 ··········</cpe-lang:logical-test>139 ··········</cpe-lang:logical-test>
154 ········</cpe-lang:platform>140 ········</cpe-lang:platform>
155 ········<cpe-lang:platform·id="package_rsyslog">141 ········<cpe-lang:platform·id="package_rsyslog">
156 ··········<cpe-lang:logical-test·operator="AND"·negate="false">142 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
157 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>143 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>
158 ··········</cpe-lang:logical-test>144 ··········</cpe-lang:logical-test>
159 ········</cpe-lang:platform>145 ········</cpe-lang:platform>
160 ········<cpe-lang:platform·id="package_systemd">146 ········<cpe-lang:platform·id="package_logrotate">
161 ··········<cpe-lang:logical-test·operator="AND"·negate="false">147 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
162 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>148 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_logrotate:def:1"/>
163 ··········</cpe-lang:logical-test>149 ··········</cpe-lang:logical-test>
164 ········</cpe-lang:platform>150 ········</cpe-lang:platform>
165 ········<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">151 ········<cpe-lang:platform·id="package_chrony">
166 ··········<cpe-lang:logical-test·operator="AND"·negate="false">152 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
167 ············<cpe-lang:logical-test·operator="AND"·negate="true"> 
168 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/> 
169 ············</cpe-lang:logical-test> 
170 ············<cpe-lang:logical-test·operator="AND"·negate="true"> 
171 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>153 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
172 ············</cpe-lang:logical-test> 
173 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/> 
174 ··········</cpe-lang:logical-test>154 ··········</cpe-lang:logical-test>
175 ········</cpe-lang:platform>155 ········</cpe-lang:platform>
176 ········<cpe-lang:platform·id="package_postfix">156 ········<cpe-lang:platform·id="package_ufw_and_system_with_kernel">
177 ··········<cpe-lang:logical-test·operator="AND"·negate="false">157 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
178 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_postfix:def:1"/>158 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
 159 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
179 ··········</cpe-lang:logical-test>160 ··········</cpe-lang:logical-test>
180 ········</cpe-lang:platform>161 ········</cpe-lang:platform>
181 ········<cpe-lang:platform·id="package_audit">162 ········<cpe-lang:platform·id="package_rsh-server">
182 ··········<cpe-lang:logical-test·operator="AND"·negate="false">163 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
183 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_audit:def:1"/>164 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_rsh-server:def:1"/>
184 ··········</cpe-lang:logical-test>165 ··········</cpe-lang:logical-test>
185 ········</cpe-lang:platform>166 ········</cpe-lang:platform>
186 ········<cpe-lang:platform·id="package_logrotate">167 ········<cpe-lang:platform·id="package_systemd">
187 ··········<cpe-lang:logical-test·operator="AND"·negate="false">168 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
188 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_logrotate:def:1"/>169 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>
189 ··········</cpe-lang:logical-test>170 ··········</cpe-lang:logical-test>
190 ········</cpe-lang:platform>171 ········</cpe-lang:platform>
191 ········<cpe-lang:platform·id="package_ntp">172 ········<cpe-lang:platform·id="mount_tmp">
192 ··········<cpe-lang:logical-test·operator="AND"·negate="false">173 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
193 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_ntp:def:1"/>174 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_tmp:def:1"/>
194 ··········</cpe-lang:logical-test>175 ··········</cpe-lang:logical-test>
195 ········</cpe-lang:platform>176 ········</cpe-lang:platform>
196 ········<cpe-lang:platform·id="package_sudo">177 ········<cpe-lang:platform·id="package_iptables_and_service_disabled_firewalld_and_system_with_kernel">
197 ··········<cpe-lang:logical-test·operator="AND"·negate="false">178 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
198 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_sudo:def:1"/>179 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
 180 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_firewalld:def:1"/>
 181 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
199 ··········</cpe-lang:logical-test>182 ··········</cpe-lang:logical-test>
200 ········</cpe-lang:platform>183 ········</cpe-lang:platform>
201 ········<cpe-lang:platform·id="aarch64_arch_or_x86_64_arch">184 ········<cpe-lang:platform·id="aarch64_arch_or_x86_64_arch">
202 ··········<cpe-lang:logical-test·operator="OR"·negate="false">185 ··········<cpe-lang:logical-test·operator="OR"·negate="false">
203 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>186 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
204 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/>187 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/>
205 ··········</cpe-lang:logical-test>188 ··········</cpe-lang:logical-test>
206 ········</cpe-lang:platform>189 ········</cpe-lang:platform>
Max diff block lines reached; 757778/771427 bytes (98.23%) of diff not shown.
690 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu1804-ocil.xml
690 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu1804-ocil.xml
Ordering differences only
    
Offset 3, 3037 lines modifiedOffset 3, 3037 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_debug_fs_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-package_nss-tools_installed_ocil:questionnaire:1">
11 ······<ocil:title>Disable·kernel·debugfs</ocil:title>11 ······<ocil:title>Ensure·nss-tools·is·installed</ocil:title>
12 ······<ocil:actions>12 ······<ocil:actions>
13 ········<ocil:test_action_ref>ocil:ssg-kernel_config_debug_fs_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-package_nss-tools_installed_action:testaction:1</ocil:test_action_ref>
14 ······</ocil:actions>14 ······</ocil:actions>
15 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
16 ····<ocil:questionnaire·id="ocil:ssg-dir_permissions_library_dirs_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-kernel_module_cramfs_disabled_ocil:questionnaire:1">
17 ······<ocil:title>Verify·that·Shared·Library·Directories·Have·Restrictive·Permissions</ocil:title>17 ······<ocil:title>Disable·Mounting·of·cramfs</ocil:title>
18 ······<ocil:actions>18 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-dir_permissions_library_dirs_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-kernel_module_cramfs_disabled_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>20 ······</ocil:actions>
21 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-grub2_slab_nomerge_argument_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_devkmem_ocil:questionnaire:1">
23 ······<ocil:title>Disable·merging·of·slabs·with·similar·size</ocil:title>23 ······<ocil:title>Disable·/dev/kmem·virtual·device·support</ocil:title>
24 ······<ocil:actions>24 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-grub2_slab_nomerge_argument_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-kernel_config_devkmem_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>26 ······</ocil:actions>
27 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-account_passwords_pam_faillock_dir_ocil:questionnaire:1"> 
29 ······<ocil:title>Account·Lockouts·Must·Persist</ocil:title>28 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_umount2_ocil:questionnaire:1">
 29 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·umount2</ocil:title>
30 ······<ocil:actions>30 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-account_passwords_pam_faillock_dir_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_umount2_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>32 ······</ocil:actions>
33 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-package_openldap-clients_removed_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-audit_privileged_commands_init_ocil:questionnaire:1">
35 ······<ocil:title>Ensure·LDAP·client·is·not·installed</ocil:title>35 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·init</ocil:title>
36 ······<ocil:actions>36 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-package_openldap-clients_removed_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-audit_privileged_commands_init_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>38 ······</ocil:actions>
39 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_binfmt_misc_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-selinux_state_ocil:questionnaire:1">
41 ······<ocil:title>Disable·kernel·support·for·MISC·binaries</ocil:title>41 ······<ocil:title>Ensure·SELinux·State·is·Enforcing</ocil:title>
42 ······<ocil:actions>42 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-kernel_config_binfmt_misc_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-selinux_state_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>44 ······</ocil:actions>
45 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-grub2_l1tf_argument_ocil:questionnaire:1"> 
47 ······<ocil:title>Configure·L1·Terminal·Fault·mitigations</ocil:title>46 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_empty_passwords_ocil:questionnaire:1">
 47 ······<ocil:title>Disable·SSH·Access·via·Empty·Passwords</ocil:title>
48 ······<ocil:actions>48 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-grub2_l1tf_argument_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_empty_passwords_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>50 ······</ocil:actions>
51 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_file_deletion_events_unlink_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-no_netrc_files_ocil:questionnaire:1">
53 ······<ocil:title>Ensure·auditd·Collects·File·Deletion·Events·by·User·-·unlink</ocil:title>53 ······<ocil:title>Verify·No·netrc·Files·Exist</ocil:title>
54 ······<ocil:actions>54 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-audit_rules_file_deletion_events_unlink_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-no_netrc_files_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>56 ······</ocil:actions>
57 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-dir_ownership_binary_dirs_ocil:questionnaire:1"> 
59 ······<ocil:title>Verify·that·System·Executable·Have·Root·Ownership</ocil:title>58 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_fchown_ocil:questionnaire:1">
 59 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·fchown</ocil:title>
60 ······<ocil:actions>60 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-dir_ownership_binary_dirs_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_fchown_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>62 ······</ocil:actions>
63 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-package_cron_installed_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-package_MFEhiplsm_installed_ocil:questionnaire:1">
65 ······<ocil:title>Install·the·cron·service</ocil:title>65 ······<ocil:title>Install·the·Host·Intrusion·Prevention·System·(HIPS)·Module</ocil:title>
66 ······<ocil:actions>66 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-package_cron_installed_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-package_MFEhiplsm_installed_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>68 ······</ocil:actions>
69 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-sshd_use_priv_separation_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-grub2_spec_store_bypass_disable_argument_ocil:questionnaire:1">
71 ······<ocil:title>Enable·Use·of·Privilege·Separation</ocil:title>71 ······<ocil:title>Configure·Speculative·Store·Bypass·Mitigation</ocil:title>
72 ······<ocil:actions>72 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-sshd_use_priv_separation_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-grub2_spec_store_bypass_disable_argument_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>74 ······</ocil:actions>
75 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-service_cron_enabled_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_module_sig_hash_ocil:questionnaire:1">
77 ······<ocil:title>Enable·cron·Service</ocil:title>77 ······<ocil:title>Specify·the·hash·to·use·when·signing·modules</ocil:title>
78 ······<ocil:actions>78 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-service_cron_enabled_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-kernel_config_module_sig_hash_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>80 ······</ocil:actions>
81 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_root_login_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_media_export_ocil:questionnaire:1">
83 ······<ocil:title>Disable·SSH·Root·Login</ocil:title>83 ······<ocil:title>Ensure·auditd·Collects·Information·on·Exporting·to·Media·(successful)</ocil:title>
84 ······<ocil:actions>84 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_root_login_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-audit_rules_media_export_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>86 ······</ocil:actions>
87 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_kexec_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-file_groupownership_sshd_private_key_ocil:questionnaire:1">
89 ······<ocil:title>Disable·kexec·system·call</ocil:title>89 ······<ocil:title>Verify·Group·Ownership·on·SSH·Server·Private·*_key·Key·Files</ocil:title>
90 ······<ocil:actions>90 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-kernel_config_kexec_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-file_groupownership_sshd_private_key_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>92 ······</ocil:actions>
93 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_file_deletion_events_unlinkat_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-grub2_enable_iommu_force_ocil:questionnaire:1">
95 ······<ocil:title>Ensure·auditd·Collects·File·Deletion·Events·by·User·-·unlinkat</ocil:title>95 ······<ocil:title>IOMMU·configuration·directive</ocil:title>
96 ······<ocil:actions>96 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-audit_rules_file_deletion_events_unlinkat_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-grub2_enable_iommu_force_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>98 ······</ocil:actions>
99 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_minlen_login_defs_ocil:questionnaire:1"> 
101 ······<ocil:title>Set·Password·Minimum·Length·in·login.defs</ocil:title>100 ····<ocil:questionnaire·id="ocil:ssg-package_openldap-clients_removed_ocil:questionnaire:1">
 101 ······<ocil:title>Ensure·LDAP·client·is·not·installed</ocil:title>
102 ······<ocil:actions>102 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-accounts_password_minlen_login_defs_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-package_openldap-clients_removed_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>104 ······</ocil:actions>
105 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-sudoers_no_command_negation_ocil:questionnaire:1">106 ····<ocil:questionnaire·id="ocil:ssg-file_owner_var_log_ocil:questionnaire:1">
107 ······<ocil:title>Don't·define·allowed·commands·in·sudoers·by·means·of·exclusion</ocil:title>107 ······<ocil:title>Verify·User·Who·Owns·/var/log·Directory</ocil:title>
108 ······<ocil:actions>108 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-sudoers_no_command_negation_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-file_owner_var_log_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>110 ······</ocil:actions>
111 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_bug_ocil:questionnaire:1">112 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_compat_brk_ocil:questionnaire:1">
113 ······<ocil:title>Enable·support·for·BUG()</ocil:title>113 ······<ocil:title>Disable·compatibility·with·brk()</ocil:title>
114 ······<ocil:actions>114 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-kernel_config_bug_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-kernel_config_compat_brk_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>116 ······</ocil:actions>
117 ····</ocil:questionnaire>117 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_all_disable_ipv6_ocil:questionnaire:1">118 ····<ocil:questionnaire·id="ocil:ssg-sysctl_fs_suid_dumpable_ocil:questionnaire:1">
119 ······<ocil:title>Disable·IPv6·Addressing·on·All·IPv6·Interfaces</ocil:title>119 ······<ocil:title>Disable·Core·Dumps·for·SUID·programs</ocil:title>
120 ······<ocil:actions>120 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_all_disable_ipv6_action:testaction:1</ocil:test_action_ref>121 ········<ocil:test_action_ref>ocil:ssg-sysctl_fs_suid_dumpable_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>122 ······</ocil:actions>
123 ····</ocil:questionnaire>123 ····</ocil:questionnaire>
124 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_proc_kcore_ocil:questionnaire:1">124 ····<ocil:questionnaire·id="ocil:ssg-audit_privileged_commands_shutdown_ocil:questionnaire:1">
125 ······<ocil:title>Disable·support·for·/proc/kkcore</ocil:title>125 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·shutdown</ocil:title>
Max diff block lines reached; 693863/706426 bytes (98.22%) of diff not shown.
27.3 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu1804-xccdf.xml
27.2 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu1804-xccdf.xml
Ordering differences only
    
Offset 72, 196 lines modifiedOffset 72, 196 lines modified
72 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>72 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
73 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>73 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
74 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>74 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
75 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>75 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
77 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>77 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
78 ··<cpe-lang:platform-specification>78 ··<cpe-lang:platform-specification>
79 ····<cpe-lang:platform·id="machine">79 ····<cpe-lang:platform·id="mount_var-tmp">
80 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
81 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/> 
82 ······</cpe-lang:logical-test> 
83 ····</cpe-lang:platform> 
84 ····<cpe-lang:platform·id="package_pam"> 
85 ······<cpe-lang:logical-test·operator="AND"·negate="false">80 ······<cpe-lang:logical-test·operator="AND"·negate="false">
86 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>81 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-tmp:def:1"/>
87 ······</cpe-lang:logical-test>82 ······</cpe-lang:logical-test>
88 ····</cpe-lang:platform>83 ····</cpe-lang:platform>
89 ····<cpe-lang:platform·id="package_autofs_and_system_with_kernel">84 ····<cpe-lang:platform·id="package_autofs_and_system_with_kernel">
90 ······<cpe-lang:logical-test·operator="AND"·negate="false">85 ······<cpe-lang:logical-test·operator="AND"·negate="false">
91 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>86 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>
92 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>87 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
93 ······</cpe-lang:logical-test>88 ······</cpe-lang:logical-test>
94 ····</cpe-lang:platform>89 ····</cpe-lang:platform>
95 ····<cpe-lang:platform·id="mount_tmp"> 
96 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
97 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_tmp:def:1"/> 
98 ······</cpe-lang:logical-test> 
99 ····</cpe-lang:platform> 
100 ····<cpe-lang:platform·id="not_package_chrony_and_not_package_ntp">90 ····<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">
101 ······<cpe-lang:logical-test·operator="AND"·negate="false">91 ······<cpe-lang:logical-test·operator="AND"·negate="false">
102 ········<cpe-lang:logical-test·operator="AND"·negate="true">92 ········<cpe-lang:logical-test·operator="AND"·negate="true">
103 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>93 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
104 ········</cpe-lang:logical-test>94 ········</cpe-lang:logical-test>
105 ········<cpe-lang:logical-test·operator="AND"·negate="true">95 ········<cpe-lang:logical-test·operator="AND"·negate="true">
106 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_ntp:def:1"/>96 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
107 ········</cpe-lang:logical-test>97 ········</cpe-lang:logical-test>
108 ······</cpe-lang:logical-test> 
109 ····</cpe-lang:platform> 
110 ····<cpe-lang:platform·id="package_iptables"> 
111 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
112 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>98 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
113 ······</cpe-lang:logical-test>99 ······</cpe-lang:logical-test>
114 ····</cpe-lang:platform>100 ····</cpe-lang:platform>
115 ····<cpe-lang:platform·id="not_container">101 ····<cpe-lang:platform·id="package_gdm">
116 ······<cpe-lang:logical-test·operator="AND"·negate="true">102 ······<cpe-lang:logical-test·operator="AND"·negate="false">
117 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_container:def:1"/>103 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_gdm:def:1"/>
118 ······</cpe-lang:logical-test>104 ······</cpe-lang:logical-test>
119 ····</cpe-lang:platform>105 ····</cpe-lang:platform>
120 ····<cpe-lang:platform·id="package_rsyslog">106 ····<cpe-lang:platform·id="package_rsyslog">
121 ······<cpe-lang:logical-test·operator="AND"·negate="false">107 ······<cpe-lang:logical-test·operator="AND"·negate="false">
122 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>108 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>
123 ······</cpe-lang:logical-test>109 ······</cpe-lang:logical-test>
124 ····</cpe-lang:platform>110 ····</cpe-lang:platform>
125 ····<cpe-lang:platform·id="package_systemd">111 ····<cpe-lang:platform·id="package_logrotate">
126 ······<cpe-lang:logical-test·operator="AND"·negate="false">112 ······<cpe-lang:logical-test·operator="AND"·negate="false">
127 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>113 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_logrotate:def:1"/>
128 ······</cpe-lang:logical-test>114 ······</cpe-lang:logical-test>
129 ····</cpe-lang:platform>115 ····</cpe-lang:platform>
130 ····<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">116 ····<cpe-lang:platform·id="package_chrony">
131 ······<cpe-lang:logical-test·operator="AND"·negate="false">117 ······<cpe-lang:logical-test·operator="AND"·negate="false">
132 ········<cpe-lang:logical-test·operator="AND"·negate="true"> 
133 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/> 
134 ········</cpe-lang:logical-test> 
135 ········<cpe-lang:logical-test·operator="AND"·negate="true"> 
136 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>118 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
137 ········</cpe-lang:logical-test> 
138 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/> 
139 ······</cpe-lang:logical-test>119 ······</cpe-lang:logical-test>
140 ····</cpe-lang:platform>120 ····</cpe-lang:platform>
141 ····<cpe-lang:platform·id="package_postfix">121 ····<cpe-lang:platform·id="package_ufw_and_system_with_kernel">
142 ······<cpe-lang:logical-test·operator="AND"·negate="false">122 ······<cpe-lang:logical-test·operator="AND"·negate="false">
143 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_postfix:def:1"/>123 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
 124 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
144 ······</cpe-lang:logical-test>125 ······</cpe-lang:logical-test>
145 ····</cpe-lang:platform>126 ····</cpe-lang:platform>
146 ····<cpe-lang:platform·id="package_audit">127 ····<cpe-lang:platform·id="package_rsh-server">
147 ······<cpe-lang:logical-test·operator="AND"·negate="false">128 ······<cpe-lang:logical-test·operator="AND"·negate="false">
148 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_audit:def:1"/>129 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_rsh-server:def:1"/>
149 ······</cpe-lang:logical-test>130 ······</cpe-lang:logical-test>
150 ····</cpe-lang:platform>131 ····</cpe-lang:platform>
151 ····<cpe-lang:platform·id="package_logrotate">132 ····<cpe-lang:platform·id="package_systemd">
152 ······<cpe-lang:logical-test·operator="AND"·negate="false">133 ······<cpe-lang:logical-test·operator="AND"·negate="false">
153 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_logrotate:def:1"/>134 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>
154 ······</cpe-lang:logical-test>135 ······</cpe-lang:logical-test>
155 ····</cpe-lang:platform>136 ····</cpe-lang:platform>
156 ····<cpe-lang:platform·id="package_ntp">137 ····<cpe-lang:platform·id="mount_tmp">
157 ······<cpe-lang:logical-test·operator="AND"·negate="false">138 ······<cpe-lang:logical-test·operator="AND"·negate="false">
158 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_ntp:def:1"/>139 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_tmp:def:1"/>
159 ······</cpe-lang:logical-test>140 ······</cpe-lang:logical-test>
160 ····</cpe-lang:platform>141 ····</cpe-lang:platform>
161 ····<cpe-lang:platform·id="package_sudo">142 ····<cpe-lang:platform·id="package_iptables_and_service_disabled_firewalld_and_system_with_kernel">
162 ······<cpe-lang:logical-test·operator="AND"·negate="false">143 ······<cpe-lang:logical-test·operator="AND"·negate="false">
163 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_sudo:def:1"/>144 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
 145 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_firewalld:def:1"/>
 146 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
164 ······</cpe-lang:logical-test>147 ······</cpe-lang:logical-test>
165 ····</cpe-lang:platform>148 ····</cpe-lang:platform>
166 ····<cpe-lang:platform·id="aarch64_arch_or_x86_64_arch">149 ····<cpe-lang:platform·id="aarch64_arch_or_x86_64_arch">
167 ······<cpe-lang:logical-test·operator="OR"·negate="false">150 ······<cpe-lang:logical-test·operator="OR"·negate="false">
168 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>151 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
169 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/>152 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/>
170 ······</cpe-lang:logical-test>153 ······</cpe-lang:logical-test>
171 ····</cpe-lang:platform>154 ····</cpe-lang:platform>
172 ····<cpe-lang:platform·id="x86_64_arch">155 ····<cpe-lang:platform·id="not_package_chrony_and_not_package_ntp">
173 ······<cpe-lang:logical-test·operator="AND"·negate="false">156 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 157 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 158 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
 159 ········</cpe-lang:logical-test>
 160 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 161 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_ntp:def:1"/>
 162 ········</cpe-lang:logical-test>
 163 ······</cpe-lang:logical-test>
 164 ····</cpe-lang:platform>
 165 ····<cpe-lang:platform·id="package_pam">
 166 ······<cpe-lang:logical-test·operator="AND"·negate="false">
174 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/>167 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>
 168 ······</cpe-lang:logical-test>
 169 ····</cpe-lang:platform>
 170 ····<cpe-lang:platform·id="machine">
 171 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 172 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
 173 ······</cpe-lang:logical-test>
 174 ····</cpe-lang:platform>
 175 ····<cpe-lang:platform·id="package_sudo">
 176 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 177 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_sudo:def:1"/>
 178 ······</cpe-lang:logical-test>
Max diff block lines reached; 14816/27745 bytes (53.40%) of diff not shown.
1.42 MB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2004-ds.xml
1.42 MB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2004-ds.xml
    
Offset 19, 23 lines modifiedOffset 19, 23 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu2004-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu2004-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu2004-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu2004-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu2004-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu2004-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu2004-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu2004-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu2004-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu2004-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu2004-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu2004-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2004-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2004-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:canonical:ubuntu_linux:20.04::~~lts~~~">28 ······<cpe-dict:cpe-item·name="cpe:/o:canonical:ubuntu_linux:20.04::~~lts~~~">
29 ········<cpe-dict:title·xml:lang="en-us">Ubuntu·release·20.04·(Focal·Fossa)</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Ubuntu·release·20.04·(Focal·Fossa)</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml">oval:ssg-installed_OS_is_ubuntu2004:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml">oval:ssg-installed_OS_is_ubuntu2004:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ····</cpe-dict:cpe-list>32 ····</cpe-dict:cpe-list>
33 ··</ds:component>33 ··</ds:component>
34 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2004-xccdf.xml"·timestamp="2025-02-28T20:08:00">34 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2004-xccdf.xml"·timestamp="2025-03-01T22:08:00">
35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_UBUNTU_20-04"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_UBUNTU_20-04"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Ubuntu·20.04</xccdf-1.2:title>37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Ubuntu·20.04</xccdf-1.2:title>
38 ······<xccdf-1.2:description>38 ······<xccdf-1.2:description>
39 ········This·guide·presents·a·catalog·of·security-relevant39 ········This·guide·presents·a·catalog·of·security-relevant
40 configuration·settings·for·Ubuntu·20.04.·It·is·a·rendering·of40 configuration·settings·for·Ubuntu·20.04.·It·is·a·rendering·of
41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 105, 337 lines modifiedOffset 105, 337 lines modified
105 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>105 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
106 ······<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>106 ······<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
107 ······<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>107 ······<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
108 ······<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>108 ······<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
109 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>109 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
110 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>110 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
111 ······<cpe-lang:platform-specification>111 ······<cpe-lang:platform-specification>
112 ········<cpe-lang:platform·id="package_nftables_and_service_disabled_firewalld_and_system_with_kernel">112 ········<cpe-lang:platform·id="not_aarch64_arch_and_not_ppc64le_arch_and_system_with_kernel">
113 ··········<cpe-lang:logical-test·operator="AND"·negate="false">113 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 114 ············<cpe-lang:logical-test·operator="AND"·negate="true">
 115 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
 116 ············</cpe-lang:logical-test>
 117 ············<cpe-lang:logical-test·operator="AND"·negate="true">
114 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>118 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_ppc64le:def:1"/>
115 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_firewalld:def:1"/>119 ············</cpe-lang:logical-test>
116 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>120 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
117 ··········</cpe-lang:logical-test>121 ··········</cpe-lang:logical-test>
118 ········</cpe-lang:platform>122 ········</cpe-lang:platform>
119 ········<cpe-lang:platform·id="machine">123 ········<cpe-lang:platform·id="mount_var-tmp">
120 ··········<cpe-lang:logical-test·operator="AND"·negate="false"> 
121 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/> 
122 ··········</cpe-lang:logical-test> 
123 ········</cpe-lang:platform> 
124 ········<cpe-lang:platform·id="package_pam"> 
125 ··········<cpe-lang:logical-test·operator="AND"·negate="false">124 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
126 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>125 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-tmp:def:1"/>
127 ··········</cpe-lang:logical-test>126 ··········</cpe-lang:logical-test>
128 ········</cpe-lang:platform>127 ········</cpe-lang:platform>
129 ········<cpe-lang:platform·id="package_autofs_and_system_with_kernel">128 ········<cpe-lang:platform·id="package_autofs_and_system_with_kernel">
130 ··········<cpe-lang:logical-test·operator="AND"·negate="false">129 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
131 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>130 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>
132 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>131 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
133 ··········</cpe-lang:logical-test>132 ··········</cpe-lang:logical-test>
134 ········</cpe-lang:platform>133 ········</cpe-lang:platform>
135 ········<cpe-lang:platform·id="mount_tmp">134 ········<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">
136 ··········<cpe-lang:logical-test·operator="AND"·negate="false">135 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 136 ············<cpe-lang:logical-test·operator="AND"·negate="true">
 137 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
 138 ············</cpe-lang:logical-test>
 139 ············<cpe-lang:logical-test·operator="AND"·negate="true">
137 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_tmp:def:1"/>140 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
 141 ············</cpe-lang:logical-test>
 142 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
138 ··········</cpe-lang:logical-test>143 ··········</cpe-lang:logical-test>
139 ········</cpe-lang:platform>144 ········</cpe-lang:platform>
140 ········<cpe-lang:platform·id="package_firewalld_and_package_nftables_and_system_with_kernel">145 ········<cpe-lang:platform·id="ipv6_enabled">
141 ··········<cpe-lang:logical-test·operator="AND"·negate="false">146 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
142 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/> 
143 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>147 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-ipv6_enabled:def:1"/>
144 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
145 ··········</cpe-lang:logical-test>148 ··········</cpe-lang:logical-test>
146 ········</cpe-lang:platform>149 ········</cpe-lang:platform>
147 ········<cpe-lang:platform·id="not_s390x_arch">150 ········<cpe-lang:platform·id="package_gdm">
148 ··········<cpe-lang:logical-test·operator="AND"·negate="false">151 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
149 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>152 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-package_gdm:def:1"/>
150 ··········</cpe-lang:logical-test>153 ··········</cpe-lang:logical-test>
151 ········</cpe-lang:platform>154 ········</cpe-lang:platform>
152 ········<cpe-lang:platform·id="not_package_chrony_and_not_package_ntp">155 ········<cpe-lang:platform·id="package_rsyslog">
 156 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 157 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>
 158 ··········</cpe-lang:logical-test>
 159 ········</cpe-lang:platform>
 160 ········<cpe-lang:platform·id="not_osbuild_and_system_with_kernel">
153 ··········<cpe-lang:logical-test·operator="AND"·negate="false">161 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
154 ············<cpe-lang:logical-test·operator="AND"·negate="true">162 ············<cpe-lang:logical-test·operator="AND"·negate="true">
155 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/> 
156 ············</cpe-lang:logical-test> 
157 ············<cpe-lang:logical-test·operator="AND"·negate="true"> 
158 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-package_ntp:def:1"/>163 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_osbuild:def:1"/>
159 ············</cpe-lang:logical-test>164 ············</cpe-lang:logical-test>
 165 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
160 ··········</cpe-lang:logical-test>166 ··········</cpe-lang:logical-test>
161 ········</cpe-lang:platform>167 ········</cpe-lang:platform>
162 ········<cpe-lang:platform·id="uefi">168 ········<cpe-lang:platform·id="package_chrony_or_package_ntp">
163 ··········<cpe-lang:logical-test·operator="AND"·negate="false">169 ··········<cpe-lang:logical-test·operator="OR"·negate="false">
 170 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
164 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>171 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-package_ntp:def:1"/>
165 ··········</cpe-lang:logical-test>172 ··········</cpe-lang:logical-test>
166 ········</cpe-lang:platform>173 ········</cpe-lang:platform>
167 ········<cpe-lang:platform·id="package_bash">174 ········<cpe-lang:platform·id="package_bash">
168 ··········<cpe-lang:logical-test·operator="AND"·negate="false">175 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
169 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>176 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>
170 ··········</cpe-lang:logical-test>177 ··········</cpe-lang:logical-test>
171 ········</cpe-lang:platform>178 ········</cpe-lang:platform>
172 ········<cpe-lang:platform·id="package_iptables">179 ········<cpe-lang:platform·id="uefi">
173 ··········<cpe-lang:logical-test·operator="AND"·negate="false">180 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
174 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>181 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>
175 ··········</cpe-lang:logical-test>182 ··········</cpe-lang:logical-test>
176 ········</cpe-lang:platform>183 ········</cpe-lang:platform>
177 ········<cpe-lang:platform·id="grub2">184 ········<cpe-lang:platform·id="package_logrotate">
178 ··········<cpe-lang:logical-test·operator="AND"·negate="false">185 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
179 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>186 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-package_logrotate:def:1"/>
180 ··········</cpe-lang:logical-test>187 ··········</cpe-lang:logical-test>
181 ········</cpe-lang:platform>188 ········</cpe-lang:platform>
182 ········<cpe-lang:platform·id="package_sssd">189 ········<cpe-lang:platform·id="package_chrony">
183 ··········<cpe-lang:logical-test·operator="AND"·negate="false">190 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
184 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-package_sssd:def:1"/>191 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
185 ··········</cpe-lang:logical-test>192 ··········</cpe-lang:logical-test>
186 ········</cpe-lang:platform>193 ········</cpe-lang:platform>
187 ········<cpe-lang:platform·id="wifi-iface">194 ········<cpe-lang:platform·id="package_sssd">
188 ··········<cpe-lang:logical-test·operator="AND"·negate="false">195 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
189 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_wifi_interface:def:1"/> 
190 ··········</cpe-lang:logical-test> 
Max diff block lines reached; 1477318/1491453 bytes (99.05%) of diff not shown.
1.31 MB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2004-ocil.xml
1.31 MB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2004-ocil.xml
Ordering differences only
    
Offset 3, 4006 lines modifiedOffset 3, 4006 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-dconf_gnome_disable_user_list_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-ntpd_configure_restrictions_ocil:questionnaire:1">
11 ······<ocil:title>Disable·the·GNOME3·Login·User·List</ocil:title>11 ······<ocil:title>Configure·server·restrictions·for·ntpd</ocil:title>
12 ······<ocil:actions>12 ······<ocil:actions>
13 ········<ocil:test_action_ref>ocil:ssg-dconf_gnome_disable_user_list_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-ntpd_configure_restrictions_action:testaction:1</ocil:test_action_ref>
14 ······</ocil:actions>14 ······</ocil:actions>
15 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
16 ····<ocil:questionnaire·id="ocil:ssg-package_nftables_installed_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_module_sig_ocil:questionnaire:1">
17 ······<ocil:title>Install·nftables·Package</ocil:title>17 ······<ocil:title>Enable·module·signature·verification</ocil:title>
18 ······<ocil:actions>18 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-package_nftables_installed_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-kernel_config_module_sig_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>20 ······</ocil:actions>
21 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-harden_ssh_client_crypto_policy_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_space_left_action_ocil:questionnaire:1">
23 ······<ocil:title>Harden·SSH·client·Crypto·Policy</ocil:title>23 ······<ocil:title>Configure·auditd·space_left·Action·on·Low·Disk·Space</ocil:title>
24 ······<ocil:actions>24 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-harden_ssh_client_crypto_policy_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-auditd_data_retention_space_left_action_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>26 ······</ocil:actions>
27 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_lsetxattr_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-sudoers_no_command_negation_ocil:questionnaire:1">
29 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·lsetxattr</ocil:title>29 ······<ocil:title>Don't·define·allowed·commands·in·sudoers·by·means·of·exclusion</ocil:title>
30 ······<ocil:actions>30 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_lsetxattr_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-sudoers_no_command_negation_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>32 ······</ocil:actions>
33 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-accounts_no_uid_except_zero_ocil:questionnaire:1"> 
35 ······<ocil:title>Verify·Only·Root·Has·UID·0</ocil:title>34 ····<ocil:questionnaire·id="ocil:ssg-sysctl_kernel_dmesg_restrict_ocil:questionnaire:1">
 35 ······<ocil:title>Restrict·Access·to·Kernel·Message·Buffer</ocil:title>
36 ······<ocil:actions>36 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-accounts_no_uid_except_zero_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-sysctl_kernel_dmesg_restrict_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>38 ······</ocil:actions>
39 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-set_nftables_base_chain_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_passwd_ocil:questionnaire:1">
41 ······<ocil:title>Ensure·Base·Chains·Exist·for·Nftables</ocil:title>41 ······<ocil:title>Verify·Permissions·on·passwd·File</ocil:title>
42 ······<ocil:actions>42 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-set_nftables_base_chain_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-file_permissions_etc_passwd_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>44 ······</ocil:actions>
45 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-sudo_add_use_pty_ocil:questionnaire:1">46 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_fchownat_ocil:questionnaire:1">
47 ······<ocil:title>Ensure·Only·Users·Logged·In·To·Real·tty·Can·Execute·Sudo·-·sudo·use_pty</ocil:title>47 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·fchownat</ocil:title>
48 ······<ocil:actions>48 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-sudo_add_use_pty_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_fchownat_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>50 ······</ocil:actions>
51 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-rsyslog_encrypt_offload_defaultnetstreamdriver_ocil:questionnaire:1"> 
53 ······<ocil:title>Ensure·Rsyslog·Encrypts·Off-Loaded·Audit·Records</ocil:title>52 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_max_log_file_action_stig_ocil:questionnaire:1">
 53 ······<ocil:title>Configure·auditd·max_log_file_action·Upon·Reaching·Maximum·Log·Size</ocil:title>
54 ······<ocil:actions>54 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-rsyslog_encrypt_offload_defaultnetstreamdriver_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-auditd_data_retention_max_log_file_action_stig_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>56 ······</ocil:actions>
57 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_file_deletion_events_renameat_ocil:questionnaire:1"> 
59 ······<ocil:title>Ensure·auditd·Collects·File·Deletion·Events·by·User·-·renameat</ocil:title>58 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_at_allow_ocil:questionnaire:1">
 59 ······<ocil:title>Verify·Group·Who·Owns·/etc/at.allow·file</ocil:title>
60 ······<ocil:actions>60 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-audit_rules_file_deletion_events_renameat_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_at_allow_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>62 ······</ocil:actions>
63 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_gshadow_ocil:questionnaire:1"> 
65 ······<ocil:title>Verify·Group·Who·Owns·gshadow·File</ocil:title>64 ····<ocil:questionnaire·id="ocil:ssg-package_nss-tools_installed_ocil:questionnaire:1">
 65 ······<ocil:title>Ensure·nss-tools·is·installed</ocil:title>
66 ······<ocil:actions>66 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_gshadow_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-package_nss-tools_installed_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>68 ······</ocil:actions>
69 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-sshd_use_approved_ciphers_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_dcredit_ocil:questionnaire:1">
71 ······<ocil:title>Use·Only·FIPS·140-2·Validated·Ciphers</ocil:title>71 ······<ocil:title>Ensure·PAM·Enforces·Password·Requirements·-·Minimum·Digit·Characters</ocil:title>
72 ······<ocil:actions>72 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-sshd_use_approved_ciphers_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-accounts_password_pam_dcredit_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>74 ······</ocil:actions>
75 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_rp_filter_ocil:questionnaire:1"> 
77 ······<ocil:title>Enable·Kernel·Parameter·to·Use·Reverse·Path·Filtering·on·all·IPv4·Interfaces</ocil:title>76 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_rmmod_ocil:questionnaire:1">
 77 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·rmmod</ocil:title>
78 ······<ocil:actions>78 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_rp_filter_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_rmmod_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>80 ······</ocil:actions>
81 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-policy_temp_passwords_immediate_change_ocil:questionnaire:1"> 
83 ······<ocil:title>Policy·Requires·Immediate·Change·of·Temporary·Passwords</ocil:title>82 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_networkconfig_modification_ocil:questionnaire:1">
 83 ······<ocil:title>Record·Events·that·Modify·the·System's·Network·Environment</ocil:title>
84 ······<ocil:actions>84 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-policy_temp_passwords_immediate_change_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-audit_rules_networkconfig_modification_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>86 ······</ocil:actions>
87 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_chmod_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-package_ufw_removed_ocil:questionnaire:1">
89 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·chmod</ocil:title>89 ······<ocil:title>Remove·ufw·Package</ocil:title>
90 ······<ocil:actions>90 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_chmod_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-package_ufw_removed_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>92 ······</ocil:actions>
93 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_root_login_ocil:questionnaire:1"> 
95 ······<ocil:title>Disable·SSH·Root·Login</ocil:title>94 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_setxattr_ocil:questionnaire:1">
 95 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·setxattr</ocil:title>
96 ······<ocil:actions>96 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_root_login_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_setxattr_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>98 ······</ocil:actions>
99 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-disallow_bypass_password_sudo_ocil:questionnaire:1"> 
101 ······<ocil:title>Disallow·Configuration·to·Bypass·Password·Requirements·for·Privilege·Escalation</ocil:title>100 ····<ocil:questionnaire·id="ocil:ssg-accounts_logon_fail_delay_ocil:questionnaire:1">
 101 ······<ocil:title>Ensure·the·Logon·Failure·Delay·is·Set·Correctly·in·login.defs</ocil:title>
102 ······<ocil:actions>102 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-disallow_bypass_password_sudo_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-accounts_logon_fail_delay_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>104 ······</ocil:actions>
105 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-sudo_remove_nopasswd_ocil:questionnaire:1"> 
107 ······<ocil:title>Ensure·Users·Re-Authenticate·for·Privilege·Escalation·-·sudo·NOPASSWD</ocil:title>106 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_admin_space_left_percentage_ocil:questionnaire:1">
 107 ······<ocil:title>Configure·auditd·admin_space_left·on·Low·Disk·Space</ocil:title>
108 ······<ocil:actions>108 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-sudo_remove_nopasswd_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-auditd_data_retention_admin_space_left_percentage_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>110 ······</ocil:actions>
111 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_module_sig_key_ocil:questionnaire:1">112 ····<ocil:questionnaire·id="ocil:ssg-kernel_module_ipv6_option_disabled_ocil:questionnaire:1">
113 ······<ocil:title>Specify·module·signing·key·to·use</ocil:title>113 ······<ocil:title>Disable·IPv6·Networking·Support·Automatic·Loading</ocil:title>
114 ······<ocil:actions>114 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-kernel_config_module_sig_key_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-kernel_module_ipv6_option_disabled_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>116 ······</ocil:actions>
117 ····</ocil:questionnaire>117 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_kernel_module_loading_finit_ocil:questionnaire:1">118 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_fremovexattr_ocil:questionnaire:1">
119 ······<ocil:title>Ensure·auditd·Collects·Information·on·Kernel·Module·Loading·and·Unloading·-·finit_module</ocil:title>119 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·fremovexattr</ocil:title>
120 ······<ocil:actions>120 ······<ocil:actions>
Max diff block lines reached; 1355488/1368358 bytes (99.06%) of diff not shown.
56.2 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2004-xccdf.xml
56.1 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2004-xccdf.xml
Ordering differences only
    
Offset 72, 337 lines modifiedOffset 72, 337 lines modified
72 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>72 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
73 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>73 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
74 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>74 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
75 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>75 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
77 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>77 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
78 ··<cpe-lang:platform-specification>78 ··<cpe-lang:platform-specification>
79 ····<cpe-lang:platform·id="package_nftables_and_service_disabled_firewalld_and_system_with_kernel">79 ····<cpe-lang:platform·id="not_aarch64_arch_and_not_ppc64le_arch_and_system_with_kernel">
80 ······<cpe-lang:logical-test·operator="AND"·negate="false">80 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 81 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 82 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
 83 ········</cpe-lang:logical-test>
 84 ········<cpe-lang:logical-test·operator="AND"·negate="true">
81 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>85 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_ppc64le:def:1"/>
82 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_firewalld:def:1"/>86 ········</cpe-lang:logical-test>
83 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>87 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
84 ······</cpe-lang:logical-test>88 ······</cpe-lang:logical-test>
85 ····</cpe-lang:platform>89 ····</cpe-lang:platform>
86 ····<cpe-lang:platform·id="machine">90 ····<cpe-lang:platform·id="mount_var-tmp">
87 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
88 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/> 
89 ······</cpe-lang:logical-test> 
90 ····</cpe-lang:platform> 
91 ····<cpe-lang:platform·id="package_pam"> 
92 ······<cpe-lang:logical-test·operator="AND"·negate="false">91 ······<cpe-lang:logical-test·operator="AND"·negate="false">
93 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>92 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-tmp:def:1"/>
94 ······</cpe-lang:logical-test>93 ······</cpe-lang:logical-test>
95 ····</cpe-lang:platform>94 ····</cpe-lang:platform>
96 ····<cpe-lang:platform·id="package_autofs_and_system_with_kernel">95 ····<cpe-lang:platform·id="package_autofs_and_system_with_kernel">
97 ······<cpe-lang:logical-test·operator="AND"·negate="false">96 ······<cpe-lang:logical-test·operator="AND"·negate="false">
98 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>97 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>
99 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>98 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
100 ······</cpe-lang:logical-test>99 ······</cpe-lang:logical-test>
101 ····</cpe-lang:platform>100 ····</cpe-lang:platform>
102 ····<cpe-lang:platform·id="mount_tmp">101 ····<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">
103 ······<cpe-lang:logical-test·operator="AND"·negate="false">102 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 103 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 104 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
 105 ········</cpe-lang:logical-test>
 106 ········<cpe-lang:logical-test·operator="AND"·negate="true">
104 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_tmp:def:1"/>107 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
 108 ········</cpe-lang:logical-test>
 109 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
105 ······</cpe-lang:logical-test>110 ······</cpe-lang:logical-test>
106 ····</cpe-lang:platform>111 ····</cpe-lang:platform>
107 ····<cpe-lang:platform·id="package_firewalld_and_package_nftables_and_system_with_kernel">112 ····<cpe-lang:platform·id="ipv6_enabled">
108 ······<cpe-lang:logical-test·operator="AND"·negate="false">113 ······<cpe-lang:logical-test·operator="AND"·negate="false">
109 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/> 
110 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>114 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-ipv6_enabled:def:1"/>
111 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
112 ······</cpe-lang:logical-test>115 ······</cpe-lang:logical-test>
113 ····</cpe-lang:platform>116 ····</cpe-lang:platform>
114 ····<cpe-lang:platform·id="not_s390x_arch">117 ····<cpe-lang:platform·id="package_gdm">
115 ······<cpe-lang:logical-test·operator="AND"·negate="false">118 ······<cpe-lang:logical-test·operator="AND"·negate="false">
116 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>119 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-package_gdm:def:1"/>
117 ······</cpe-lang:logical-test>120 ······</cpe-lang:logical-test>
118 ····</cpe-lang:platform>121 ····</cpe-lang:platform>
119 ····<cpe-lang:platform·id="not_package_chrony_and_not_package_ntp">122 ····<cpe-lang:platform·id="package_rsyslog">
 123 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 124 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>
 125 ······</cpe-lang:logical-test>
 126 ····</cpe-lang:platform>
 127 ····<cpe-lang:platform·id="not_osbuild_and_system_with_kernel">
120 ······<cpe-lang:logical-test·operator="AND"·negate="false">128 ······<cpe-lang:logical-test·operator="AND"·negate="false">
121 ········<cpe-lang:logical-test·operator="AND"·negate="true">129 ········<cpe-lang:logical-test·operator="AND"·negate="true">
122 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/> 
123 ········</cpe-lang:logical-test> 
124 ········<cpe-lang:logical-test·operator="AND"·negate="true"> 
125 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-package_ntp:def:1"/>130 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_osbuild:def:1"/>
126 ········</cpe-lang:logical-test>131 ········</cpe-lang:logical-test>
 132 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
127 ······</cpe-lang:logical-test>133 ······</cpe-lang:logical-test>
128 ····</cpe-lang:platform>134 ····</cpe-lang:platform>
129 ····<cpe-lang:platform·id="uefi">135 ····<cpe-lang:platform·id="package_chrony_or_package_ntp">
130 ······<cpe-lang:logical-test·operator="AND"·negate="false">136 ······<cpe-lang:logical-test·operator="OR"·negate="false">
 137 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
131 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>138 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-package_ntp:def:1"/>
132 ······</cpe-lang:logical-test>139 ······</cpe-lang:logical-test>
133 ····</cpe-lang:platform>140 ····</cpe-lang:platform>
134 ····<cpe-lang:platform·id="package_bash">141 ····<cpe-lang:platform·id="package_bash">
135 ······<cpe-lang:logical-test·operator="AND"·negate="false">142 ······<cpe-lang:logical-test·operator="AND"·negate="false">
136 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>143 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>
137 ······</cpe-lang:logical-test>144 ······</cpe-lang:logical-test>
138 ····</cpe-lang:platform>145 ····</cpe-lang:platform>
139 ····<cpe-lang:platform·id="package_iptables">146 ····<cpe-lang:platform·id="uefi">
140 ······<cpe-lang:logical-test·operator="AND"·negate="false">147 ······<cpe-lang:logical-test·operator="AND"·negate="false">
141 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>148 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>
142 ······</cpe-lang:logical-test>149 ······</cpe-lang:logical-test>
143 ····</cpe-lang:platform>150 ····</cpe-lang:platform>
144 ····<cpe-lang:platform·id="grub2">151 ····<cpe-lang:platform·id="package_logrotate">
145 ······<cpe-lang:logical-test·operator="AND"·negate="false">152 ······<cpe-lang:logical-test·operator="AND"·negate="false">
146 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>153 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-package_logrotate:def:1"/>
147 ······</cpe-lang:logical-test>154 ······</cpe-lang:logical-test>
148 ····</cpe-lang:platform>155 ····</cpe-lang:platform>
149 ····<cpe-lang:platform·id="package_sssd">156 ····<cpe-lang:platform·id="package_chrony">
150 ······<cpe-lang:logical-test·operator="AND"·negate="false">157 ······<cpe-lang:logical-test·operator="AND"·negate="false">
151 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-package_sssd:def:1"/>158 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
152 ······</cpe-lang:logical-test>159 ······</cpe-lang:logical-test>
153 ····</cpe-lang:platform>160 ····</cpe-lang:platform>
154 ····<cpe-lang:platform·id="wifi-iface">161 ····<cpe-lang:platform·id="package_sssd">
155 ······<cpe-lang:logical-test·operator="AND"·negate="false">162 ······<cpe-lang:logical-test·operator="AND"·negate="false">
156 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_wifi_interface:def:1"/> 
157 ······</cpe-lang:logical-test> 
158 ····</cpe-lang:platform> 
159 ····<cpe-lang:platform·id="not_container"> 
160 ······<cpe-lang:logical-test·operator="AND"·negate="true"> 
161 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_container:def:1"/>163 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-package_sssd:def:1"/>
162 ······</cpe-lang:logical-test>164 ······</cpe-lang:logical-test>
163 ····</cpe-lang:platform>165 ····</cpe-lang:platform>
164 ····<cpe-lang:platform·id="package_rsyslog">166 ····<cpe-lang:platform·id="package_ufw_and_system_with_kernel">
165 ······<cpe-lang:logical-test·operator="AND"·negate="false">167 ······<cpe-lang:logical-test·operator="AND"·negate="false">
166 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>168 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
 169 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
167 ······</cpe-lang:logical-test>170 ······</cpe-lang:logical-test>
168 ····</cpe-lang:platform>171 ····</cpe-lang:platform>
169 ····<cpe-lang:platform·id="package_nftables_and_service_disabled_firewalld">172 ····<cpe-lang:platform·id="package_nftables_and_service_disabled_firewalld_and_service_disabled_ufw">
170 ······<cpe-lang:logical-test·operator="AND"·negate="false">173 ······<cpe-lang:logical-test·operator="AND"·negate="false">
171 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>174 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
172 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_firewalld:def:1"/>175 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_firewalld:def:1"/>
 176 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_ufw:def:1"/>
173 ······</cpe-lang:logical-test>177 ······</cpe-lang:logical-test>
174 ····</cpe-lang:platform>178 ····</cpe-lang:platform>
175 ····<cpe-lang:platform·id="package_systemd">179 ····<cpe-lang:platform·id="package_rsh-server">
176 ······<cpe-lang:logical-test·operator="AND"·negate="false">180 ······<cpe-lang:logical-test·operator="AND"·negate="false">
177 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>181 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-package_rsh-server:def:1"/>
178 ······</cpe-lang:logical-test>182 ······</cpe-lang:logical-test>
179 ····</cpe-lang:platform>183 ····</cpe-lang:platform>
Max diff block lines reached; 43545/57326 bytes (75.96%) of diff not shown.
1.48 MB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2204-ds.xml
1.48 MB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2204-ds.xml
    
Offset 19, 23 lines modifiedOffset 19, 23 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu2204-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu2204-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu2204-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu2204-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu2204-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu2204-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu2204-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu2204-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu2204-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu2204-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu2204-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu2204-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2204-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2204-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:canonical:ubuntu_linux:22.04::~~lts~~~">28 ······<cpe-dict:cpe-item·name="cpe:/o:canonical:ubuntu_linux:22.04::~~lts~~~">
29 ········<cpe-dict:title·xml:lang="en-us">Ubuntu·release·22.04·(Jammy·Jellyfish)</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Ubuntu·release·22.04·(Jammy·Jellyfish)</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml">oval:ssg-installed_OS_is_ubuntu2204:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml">oval:ssg-installed_OS_is_ubuntu2204:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ····</cpe-dict:cpe-list>32 ····</cpe-dict:cpe-list>
33 ··</ds:component>33 ··</ds:component>
34 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2204-xccdf.xml"·timestamp="2025-02-28T20:08:00">34 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2204-xccdf.xml"·timestamp="2025-03-01T22:08:00">
35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_UBUNTU_22-04"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_UBUNTU_22-04"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Ubuntu·22.04</xccdf-1.2:title>37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Ubuntu·22.04</xccdf-1.2:title>
38 ······<xccdf-1.2:description>38 ······<xccdf-1.2:description>
39 ········This·guide·presents·a·catalog·of·security-relevant39 ········This·guide·presents·a·catalog·of·security-relevant
40 configuration·settings·for·Ubuntu·22.04.·It·is·a·rendering·of40 configuration·settings·for·Ubuntu·22.04.·It·is·a·rendering·of
41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 105, 350 lines modifiedOffset 105, 350 lines modified
105 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>105 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
106 ······<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>106 ······<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
107 ······<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>107 ······<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
108 ······<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>108 ······<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
109 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>109 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
110 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>110 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
111 ······<cpe-lang:platform-specification>111 ······<cpe-lang:platform-specification>
112 ········<cpe-lang:platform·id="package_nftables_and_service_disabled_firewalld_and_system_with_kernel">112 ········<cpe-lang:platform·id="not_aarch64_arch_and_not_ppc64le_arch_and_system_with_kernel">
113 ··········<cpe-lang:logical-test·operator="AND"·negate="false">113 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 114 ············<cpe-lang:logical-test·operator="AND"·negate="true">
 115 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
 116 ············</cpe-lang:logical-test>
 117 ············<cpe-lang:logical-test·operator="AND"·negate="true">
114 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>118 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_ppc64le:def:1"/>
115 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_firewalld:def:1"/>119 ············</cpe-lang:logical-test>
116 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>120 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
117 ··········</cpe-lang:logical-test>121 ··········</cpe-lang:logical-test>
118 ········</cpe-lang:platform>122 ········</cpe-lang:platform>
119 ········<cpe-lang:platform·id="machine">123 ········<cpe-lang:platform·id="mount_var-tmp">
120 ··········<cpe-lang:logical-test·operator="AND"·negate="false"> 
121 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/> 
122 ··········</cpe-lang:logical-test> 
123 ········</cpe-lang:platform> 
124 ········<cpe-lang:platform·id="package_pam"> 
125 ··········<cpe-lang:logical-test·operator="AND"·negate="false">124 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
126 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>125 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-tmp:def:1"/>
127 ··········</cpe-lang:logical-test>126 ··········</cpe-lang:logical-test>
128 ········</cpe-lang:platform>127 ········</cpe-lang:platform>
129 ········<cpe-lang:platform·id="package_autofs_and_system_with_kernel">128 ········<cpe-lang:platform·id="package_autofs_and_system_with_kernel">
130 ··········<cpe-lang:logical-test·operator="AND"·negate="false">129 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
131 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>130 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>
132 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>131 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
133 ··········</cpe-lang:logical-test>132 ··········</cpe-lang:logical-test>
134 ········</cpe-lang:platform>133 ········</cpe-lang:platform>
135 ········<cpe-lang:platform·id="mount_tmp">134 ········<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">
136 ··········<cpe-lang:logical-test·operator="AND"·negate="false">135 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 136 ············<cpe-lang:logical-test·operator="AND"·negate="true">
 137 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
 138 ············</cpe-lang:logical-test>
 139 ············<cpe-lang:logical-test·operator="AND"·negate="true">
137 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_tmp:def:1"/>140 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
 141 ············</cpe-lang:logical-test>
 142 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
138 ··········</cpe-lang:logical-test>143 ··········</cpe-lang:logical-test>
139 ········</cpe-lang:platform>144 ········</cpe-lang:platform>
140 ········<cpe-lang:platform·id="package_firewalld_and_package_nftables_and_system_with_kernel">145 ········<cpe-lang:platform·id="ipv6_enabled">
141 ··········<cpe-lang:logical-test·operator="AND"·negate="false">146 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
142 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/> 
143 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>147 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-ipv6_enabled:def:1"/>
144 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
145 ··········</cpe-lang:logical-test>148 ··········</cpe-lang:logical-test>
146 ········</cpe-lang:platform>149 ········</cpe-lang:platform>
147 ········<cpe-lang:platform·id="not_s390x_arch">150 ········<cpe-lang:platform·id="package_gdm">
148 ··········<cpe-lang:logical-test·operator="AND"·negate="false">151 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
149 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>152 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-package_gdm:def:1"/>
150 ··········</cpe-lang:logical-test>153 ··········</cpe-lang:logical-test>
151 ········</cpe-lang:platform>154 ········</cpe-lang:platform>
152 ········<cpe-lang:platform·id="not_package_chrony_and_not_package_ntp">155 ········<cpe-lang:platform·id="package_rsyslog">
153 ··········<cpe-lang:logical-test·operator="AND"·negate="false">156 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
154 ············<cpe-lang:logical-test·operator="AND"·negate="true"> 
155 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>157 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>
156 ············</cpe-lang:logical-test> 
157 ············<cpe-lang:logical-test·operator="AND"·negate="true"> 
158 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-package_ntp:def:1"/> 
159 ············</cpe-lang:logical-test> 
160 ··········</cpe-lang:logical-test>158 ··········</cpe-lang:logical-test>
161 ········</cpe-lang:platform>159 ········</cpe-lang:platform>
162 ········<cpe-lang:platform·id="mount_var-log">160 ········<cpe-lang:platform·id="not_osbuild_and_system_with_kernel">
163 ··········<cpe-lang:logical-test·operator="AND"·negate="false">161 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 162 ············<cpe-lang:logical-test·operator="AND"·negate="true">
164 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-log:def:1"/>163 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_osbuild:def:1"/>
 164 ············</cpe-lang:logical-test>
 165 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
165 ··········</cpe-lang:logical-test>166 ··········</cpe-lang:logical-test>
166 ········</cpe-lang:platform>167 ········</cpe-lang:platform>
167 ········<cpe-lang:platform·id="uefi">168 ········<cpe-lang:platform·id="package_chrony_or_package_ntp">
168 ··········<cpe-lang:logical-test·operator="AND"·negate="false">169 ··········<cpe-lang:logical-test·operator="OR"·negate="false">
 170 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
169 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>171 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-package_ntp:def:1"/>
170 ··········</cpe-lang:logical-test>172 ··········</cpe-lang:logical-test>
171 ········</cpe-lang:platform>173 ········</cpe-lang:platform>
172 ········<cpe-lang:platform·id="package_bash">174 ········<cpe-lang:platform·id="package_bash">
173 ··········<cpe-lang:logical-test·operator="AND"·negate="false">175 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
174 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>176 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>
175 ··········</cpe-lang:logical-test>177 ··········</cpe-lang:logical-test>
176 ········</cpe-lang:platform>178 ········</cpe-lang:platform>
177 ········<cpe-lang:platform·id="package_iptables">179 ········<cpe-lang:platform·id="uefi">
178 ··········<cpe-lang:logical-test·operator="AND"·negate="false">180 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
179 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>181 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>
180 ··········</cpe-lang:logical-test>182 ··········</cpe-lang:logical-test>
181 ········</cpe-lang:platform>183 ········</cpe-lang:platform>
182 ········<cpe-lang:platform·id="grub2">184 ········<cpe-lang:platform·id="package_logrotate">
183 ··········<cpe-lang:logical-test·operator="AND"·negate="false">185 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
184 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>186 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-package_logrotate:def:1"/>
185 ··········</cpe-lang:logical-test>187 ··········</cpe-lang:logical-test>
186 ········</cpe-lang:platform>188 ········</cpe-lang:platform>
187 ········<cpe-lang:platform·id="package_sssd">189 ········<cpe-lang:platform·id="package_chrony">
188 ··········<cpe-lang:logical-test·operator="AND"·negate="false">190 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
189 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-package_sssd:def:1"/>191 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
190 ··········</cpe-lang:logical-test>192 ··········</cpe-lang:logical-test>
191 ········</cpe-lang:platform>193 ········</cpe-lang:platform>
192 ········<cpe-lang:platform·id="wifi-iface">194 ········<cpe-lang:platform·id="package_sssd">
193 ··········<cpe-lang:logical-test·operator="AND"·negate="false">195 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
Max diff block lines reached; 1536888/1551366 bytes (99.07%) of diff not shown.
1.36 MB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2204-ocil.xml
1.36 MB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2204-ocil.xml
Ordering differences only
    
Offset 3, 6528 lines modifiedOffset 3, 6528 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-sudo_remove_no_authenticate_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-permissions_local_var_log_ocil:questionnaire:1">
 11 ······<ocil:title>Verify·permissions·of·log·files</ocil:title>
11 ······<ocil:title>Ensure·Users·Re-Authenticate·for·Privilege·Escalation·-·sudo·!authenticate</ocil:title> 
12 ······<ocil:actions> 
13 ········<ocil:test_action_ref>ocil:ssg-sudo_remove_no_authenticate_action:testaction:1</ocil:test_action_ref> 
14 ······</ocil:actions> 
15 ····</ocil:questionnaire> 
16 ····<ocil:questionnaire·id="ocil:ssg-dir_perms_world_writable_sticky_bits_ocil:questionnaire:1"> 
17 ······<ocil:title>Verify·that·All·World-Writable·Directories·Have·Sticky·Bits·Set</ocil:title> 
18 ······<ocil:actions>12 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-dir_perms_world_writable_sticky_bits_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-permissions_local_var_log_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>14 ······</ocil:actions>
21 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-sudo_add_noexec_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_passwd_ocil:questionnaire:1">
23 ······<ocil:title>Ensure·Privileged·Escalated·Commands·Cannot·Execute·Other·Commands·-·sudo·NOEXEC</ocil:title>17 ······<ocil:title>Verify·Group·Who·Owns·passwd·File</ocil:title>
24 ······<ocil:actions>18 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-sudo_add_noexec_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_passwd_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>20 ······</ocil:actions>
27 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-aide_disable_silentreports_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-package_avahi_removed_ocil:questionnaire:1">
29 ······<ocil:title>Configure·AIDE·To·Notify·Personnel·if·Baseline·Configurations·Are·Altered</ocil:title>23 ······<ocil:title>Uninstall·avahi·Server·Package</ocil:title>
30 ······<ocil:actions>24 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-aide_disable_silentreports_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-package_avahi_removed_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>26 ······</ocil:actions>
33 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_backup_etc_shadow_ocil:questionnaire:1"> 
35 ······<ocil:title>Verify·User·Who·Owns·Backup·shadow·File</ocil:title>28 ····<ocil:questionnaire·id="ocil:ssg-sshd_use_approved_macs_ordered_stig_ocil:questionnaire:1">
 29 ······<ocil:title>Use·Only·FIPS·140-2·Validated·MACs</ocil:title>
36 ······<ocil:actions>30 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_backup_etc_shadow_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-sshd_use_approved_macs_ordered_stig_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>32 ······</ocil:actions>
39 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-set_password_hashing_algorithm_systemauth_ocil:questionnaire:1"> 
41 ······<ocil:title>Set·PAM''s·Password·Hashing·Algorithm</ocil:title>34 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_accept_redirects_ocil:questionnaire:1">
 35 ······<ocil:title>Disable·Accepting·ICMP·Redirects·for·All·IPv4·Interfaces</ocil:title>
42 ······<ocil:actions>36 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-set_password_hashing_algorithm_systemauth_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_accept_redirects_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>38 ······</ocil:actions>
45 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_cron_monthly_ocil:questionnaire:1"> 
47 ······<ocil:title>Verify·Group·Who·Owns·cron.monthly</ocil:title>40 ····<ocil:questionnaire·id="ocil:ssg-rsyslog_encrypt_offload_actionsendstreamdrivermode_ocil:questionnaire:1">
 41 ······<ocil:title>Ensure·Rsyslog·Encrypts·Off-Loaded·Audit·Records</ocil:title>
48 ······<ocil:actions>42 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_cron_monthly_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-rsyslog_encrypt_offload_actionsendstreamdrivermode_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>44 ······</ocil:actions>
51 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_var_log_audit_ocil:questionnaire:1"> 
53 ······<ocil:title>System·Audit·Logs·Must·Have·Mode·0640·or·Less·Permissive</ocil:title>46 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_all_disable_ipv6_ocil:questionnaire:1">
 47 ······<ocil:title>Disable·IPv6·Addressing·on·All·IPv6·Interfaces</ocil:title>
54 ······<ocil:actions>48 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-file_permissions_var_log_audit_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_all_disable_ipv6_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>50 ······</ocil:actions>
57 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_module_sig_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-rsyslog_remote_loghost_ocil:questionnaire:1">
59 ······<ocil:title>Enable·module·signature·verification</ocil:title>53 ······<ocil:title>Ensure·Logs·Sent·To·Remote·Host</ocil:title>
60 ······<ocil:actions>54 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-kernel_config_module_sig_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-rsyslog_remote_loghost_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>56 ······</ocil:actions>
63 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-file_owner_etc_motd_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_root_password_login_ocil:questionnaire:1">
65 ······<ocil:title>Verify·ownership·of·Message·of·the·Day·Banner</ocil:title>59 ······<ocil:title>Disable·SSH·root·Login·with·a·Password·(Insecure)</ocil:title>
66 ······<ocil:actions>60 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-file_owner_etc_motd_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_root_password_login_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>62 ······</ocil:actions>
69 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-gnome_gdm_disable_xdmcp_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-file_groupownership_audit_binaries_ocil:questionnaire:1">
71 ······<ocil:title>Disable·XDMCP·in·GDM</ocil:title>65 ······<ocil:title>Verify·that·audit·tools·are·owned·by·group·root</ocil:title>
72 ······<ocil:actions>66 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-gnome_gdm_disable_xdmcp_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-file_groupownership_audit_binaries_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>68 ······</ocil:actions>
75 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_grub2_cfg_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-sysctl_fs_protected_hardlinks_ocil:questionnaire:1">
77 ······<ocil:title>Verify·/boot/grub/grub.cfg·Permissions</ocil:title>71 ······<ocil:title>Enable·Kernel·Parameter·to·Enforce·DAC·on·Hardlinks</ocil:title>
78 ······<ocil:actions>72 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-file_permissions_grub2_cfg_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-sysctl_fs_protected_hardlinks_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>74 ······</ocil:actions>
81 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_chown_ocil:questionnaire:1"> 
83 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·chown</ocil:title>76 ····<ocil:questionnaire·id="ocil:ssg-sshd_use_strong_macs_ocil:questionnaire:1">
 77 ······<ocil:title>Use·Only·Strong·MACs</ocil:title>
84 ······<ocil:actions>78 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_chown_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-sshd_use_strong_macs_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>80 ······</ocil:actions>
87 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-kernel_module_dccp_disabled_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_debug_sg_ocil:questionnaire:1">
89 ······<ocil:title>Disable·DCCP·Support</ocil:title>83 ······<ocil:title>Enable·checks·on·scatter-gather·(SG)·table·operations</ocil:title>
90 ······<ocil:actions>84 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-kernel_module_dccp_disabled_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-kernel_config_debug_sg_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>86 ······</ocil:actions>
93 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_gssapi_auth_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-smartcard_pam_enabled_ocil:questionnaire:1">
95 ······<ocil:title>Disable·GSSAPI·Authentication</ocil:title>89 ······<ocil:title>Enable·Smart·Card·Logins·in·PAM</ocil:title>
96 ······<ocil:actions>90 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_gssapi_auth_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-smartcard_pam_enabled_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>92 ······</ocil:actions>
99 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_kernel_module_loading_finit_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_rmmod_ocil:questionnaire:1">
101 ······<ocil:title>Ensure·auditd·Collects·Information·on·Kernel·Module·Loading·and·Unloading·-·finit_module</ocil:title>95 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·rmmod</ocil:title>
102 ······<ocil:actions>96 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-audit_rules_kernel_module_loading_finit_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_rmmod_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>98 ······</ocil:actions>
105 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-grub2_disable_recovery_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_disk_full_action_stig_ocil:questionnaire:1">
107 ······<ocil:title>Disable·Recovery·Booting</ocil:title>101 ······<ocil:title>Configure·auditd·Disk·Full·Action·when·Disk·Space·Is·Full</ocil:title>
108 ······<ocil:actions>102 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-grub2_disable_recovery_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-auditd_data_disk_full_action_stig_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>104 ······</ocil:actions>
111 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_page_table_isolation_ocil:questionnaire:1">106 ····<ocil:questionnaire·id="ocil:ssg-no_all_squash_exports_ocil:questionnaire:1">
113 ······<ocil:title>Remove·the·kernel·mapping·in·user·mode</ocil:title>107 ······<ocil:title>Ensure·All-Squashing·Disabled·On·All·Exports</ocil:title>
114 ······<ocil:actions>108 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-kernel_config_page_table_isolation_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-no_all_squash_exports_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>110 ······</ocil:actions>
117 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-dir_permissions_binary_dirs_ocil:questionnaire:1"> 
119 ······<ocil:title>Verify·that·System·Executable·Directories·Have·Restrictive·Permissions</ocil:title>112 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_truncate_ocil:questionnaire:1">
 113 ······<ocil:title>Record·Unsuccessful·Access·Attempts·to·Files·-·truncate</ocil:title>
120 ······<ocil:actions>114 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-dir_permissions_binary_dirs_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_truncate_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>116 ······</ocil:actions>
Max diff block lines reached; 1412451/1424706 bytes (99.14%) of diff not shown.
57.8 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2204-xccdf.xml
57.7 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2204-xccdf.xml
Ordering differences only
    
Offset 72, 350 lines modifiedOffset 72, 350 lines modified
72 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>72 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
73 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>73 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
74 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>74 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
75 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>75 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
77 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>77 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
78 ··<cpe-lang:platform-specification>78 ··<cpe-lang:platform-specification>
79 ····<cpe-lang:platform·id="package_nftables_and_service_disabled_firewalld_and_system_with_kernel">79 ····<cpe-lang:platform·id="not_aarch64_arch_and_not_ppc64le_arch_and_system_with_kernel">
80 ······<cpe-lang:logical-test·operator="AND"·negate="false">80 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 81 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 82 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
 83 ········</cpe-lang:logical-test>
 84 ········<cpe-lang:logical-test·operator="AND"·negate="true">
81 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>85 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_ppc64le:def:1"/>
82 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_firewalld:def:1"/>86 ········</cpe-lang:logical-test>
83 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>87 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
84 ······</cpe-lang:logical-test>88 ······</cpe-lang:logical-test>
85 ····</cpe-lang:platform>89 ····</cpe-lang:platform>
86 ····<cpe-lang:platform·id="machine">90 ····<cpe-lang:platform·id="mount_var-tmp">
87 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
88 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/> 
89 ······</cpe-lang:logical-test> 
90 ····</cpe-lang:platform> 
91 ····<cpe-lang:platform·id="package_pam"> 
92 ······<cpe-lang:logical-test·operator="AND"·negate="false">91 ······<cpe-lang:logical-test·operator="AND"·negate="false">
93 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>92 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-tmp:def:1"/>
94 ······</cpe-lang:logical-test>93 ······</cpe-lang:logical-test>
95 ····</cpe-lang:platform>94 ····</cpe-lang:platform>
96 ····<cpe-lang:platform·id="package_autofs_and_system_with_kernel">95 ····<cpe-lang:platform·id="package_autofs_and_system_with_kernel">
97 ······<cpe-lang:logical-test·operator="AND"·negate="false">96 ······<cpe-lang:logical-test·operator="AND"·negate="false">
98 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>97 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>
99 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>98 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
100 ······</cpe-lang:logical-test>99 ······</cpe-lang:logical-test>
101 ····</cpe-lang:platform>100 ····</cpe-lang:platform>
102 ····<cpe-lang:platform·id="mount_tmp">101 ····<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">
103 ······<cpe-lang:logical-test·operator="AND"·negate="false">102 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 103 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 104 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
 105 ········</cpe-lang:logical-test>
 106 ········<cpe-lang:logical-test·operator="AND"·negate="true">
104 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_tmp:def:1"/>107 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
 108 ········</cpe-lang:logical-test>
 109 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
105 ······</cpe-lang:logical-test>110 ······</cpe-lang:logical-test>
106 ····</cpe-lang:platform>111 ····</cpe-lang:platform>
107 ····<cpe-lang:platform·id="package_firewalld_and_package_nftables_and_system_with_kernel">112 ····<cpe-lang:platform·id="ipv6_enabled">
108 ······<cpe-lang:logical-test·operator="AND"·negate="false">113 ······<cpe-lang:logical-test·operator="AND"·negate="false">
109 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/> 
110 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>114 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-ipv6_enabled:def:1"/>
111 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
112 ······</cpe-lang:logical-test>115 ······</cpe-lang:logical-test>
113 ····</cpe-lang:platform>116 ····</cpe-lang:platform>
114 ····<cpe-lang:platform·id="not_s390x_arch">117 ····<cpe-lang:platform·id="package_gdm">
115 ······<cpe-lang:logical-test·operator="AND"·negate="false">118 ······<cpe-lang:logical-test·operator="AND"·negate="false">
116 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>119 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-package_gdm:def:1"/>
117 ······</cpe-lang:logical-test>120 ······</cpe-lang:logical-test>
118 ····</cpe-lang:platform>121 ····</cpe-lang:platform>
119 ····<cpe-lang:platform·id="not_package_chrony_and_not_package_ntp">122 ····<cpe-lang:platform·id="package_rsyslog">
120 ······<cpe-lang:logical-test·operator="AND"·negate="false">123 ······<cpe-lang:logical-test·operator="AND"·negate="false">
121 ········<cpe-lang:logical-test·operator="AND"·negate="true"> 
122 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>124 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>
123 ········</cpe-lang:logical-test> 
124 ········<cpe-lang:logical-test·operator="AND"·negate="true"> 
125 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-package_ntp:def:1"/> 
126 ········</cpe-lang:logical-test> 
127 ······</cpe-lang:logical-test>125 ······</cpe-lang:logical-test>
128 ····</cpe-lang:platform>126 ····</cpe-lang:platform>
129 ····<cpe-lang:platform·id="mount_var-log">127 ····<cpe-lang:platform·id="not_osbuild_and_system_with_kernel">
130 ······<cpe-lang:logical-test·operator="AND"·negate="false">128 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 129 ········<cpe-lang:logical-test·operator="AND"·negate="true">
131 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-log:def:1"/>130 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_osbuild:def:1"/>
 131 ········</cpe-lang:logical-test>
 132 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
132 ······</cpe-lang:logical-test>133 ······</cpe-lang:logical-test>
133 ····</cpe-lang:platform>134 ····</cpe-lang:platform>
134 ····<cpe-lang:platform·id="uefi">135 ····<cpe-lang:platform·id="package_chrony_or_package_ntp">
135 ······<cpe-lang:logical-test·operator="AND"·negate="false">136 ······<cpe-lang:logical-test·operator="OR"·negate="false">
 137 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
136 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>138 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-package_ntp:def:1"/>
137 ······</cpe-lang:logical-test>139 ······</cpe-lang:logical-test>
138 ····</cpe-lang:platform>140 ····</cpe-lang:platform>
139 ····<cpe-lang:platform·id="package_bash">141 ····<cpe-lang:platform·id="package_bash">
140 ······<cpe-lang:logical-test·operator="AND"·negate="false">142 ······<cpe-lang:logical-test·operator="AND"·negate="false">
141 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>143 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>
142 ······</cpe-lang:logical-test>144 ······</cpe-lang:logical-test>
143 ····</cpe-lang:platform>145 ····</cpe-lang:platform>
144 ····<cpe-lang:platform·id="package_iptables">146 ····<cpe-lang:platform·id="uefi">
145 ······<cpe-lang:logical-test·operator="AND"·negate="false">147 ······<cpe-lang:logical-test·operator="AND"·negate="false">
146 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>148 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>
147 ······</cpe-lang:logical-test>149 ······</cpe-lang:logical-test>
148 ····</cpe-lang:platform>150 ····</cpe-lang:platform>
149 ····<cpe-lang:platform·id="grub2">151 ····<cpe-lang:platform·id="package_logrotate">
150 ······<cpe-lang:logical-test·operator="AND"·negate="false">152 ······<cpe-lang:logical-test·operator="AND"·negate="false">
151 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>153 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-package_logrotate:def:1"/>
152 ······</cpe-lang:logical-test>154 ······</cpe-lang:logical-test>
153 ····</cpe-lang:platform>155 ····</cpe-lang:platform>
154 ····<cpe-lang:platform·id="package_sssd">156 ····<cpe-lang:platform·id="package_chrony">
155 ······<cpe-lang:logical-test·operator="AND"·negate="false">157 ······<cpe-lang:logical-test·operator="AND"·negate="false">
156 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-package_sssd:def:1"/>158 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
157 ······</cpe-lang:logical-test>159 ······</cpe-lang:logical-test>
158 ····</cpe-lang:platform>160 ····</cpe-lang:platform>
159 ····<cpe-lang:platform·id="wifi-iface">161 ····<cpe-lang:platform·id="package_sssd">
160 ······<cpe-lang:logical-test·operator="AND"·negate="false">162 ······<cpe-lang:logical-test·operator="AND"·negate="false">
161 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_wifi_interface:def:1"/> 
162 ······</cpe-lang:logical-test> 
163 ····</cpe-lang:platform> 
164 ····<cpe-lang:platform·id="not_container"> 
165 ······<cpe-lang:logical-test·operator="AND"·negate="true"> 
166 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_container:def:1"/>163 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-package_sssd:def:1"/>
167 ······</cpe-lang:logical-test>164 ······</cpe-lang:logical-test>
168 ····</cpe-lang:platform>165 ····</cpe-lang:platform>
169 ····<cpe-lang:platform·id="package_rsyslog">166 ····<cpe-lang:platform·id="package_ufw_and_system_with_kernel">
170 ······<cpe-lang:logical-test·operator="AND"·negate="false">167 ······<cpe-lang:logical-test·operator="AND"·negate="false">
171 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>168 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
 169 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
172 ······</cpe-lang:logical-test>170 ······</cpe-lang:logical-test>
173 ····</cpe-lang:platform>171 ····</cpe-lang:platform>
174 ····<cpe-lang:platform·id="package_nftables_and_service_disabled_firewalld">172 ····<cpe-lang:platform·id="package_nftables_and_service_disabled_firewalld_and_service_disabled_ufw">
175 ······<cpe-lang:logical-test·operator="AND"·negate="false">173 ······<cpe-lang:logical-test·operator="AND"·negate="false">
176 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>174 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
177 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_firewalld:def:1"/>175 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_firewalld:def:1"/>
 176 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_ufw:def:1"/>
178 ······</cpe-lang:logical-test>177 ······</cpe-lang:logical-test>
179 ····</cpe-lang:platform>178 ····</cpe-lang:platform>
180 ····<cpe-lang:platform·id="package_systemd">179 ····<cpe-lang:platform·id="package_rsh-server">
181 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
182 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/> 
Max diff block lines reached; 45027/58911 bytes (76.43%) of diff not shown.
1000 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2404-ds.xml
1000 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2404-ds.xml
    
Offset 19, 23 lines modifiedOffset 19, 23 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu2404-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu2404-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu2404-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu2404-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu2404-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu2404-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu2404-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu2404-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu2404-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu2404-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu2404-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu2404-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2404-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2404-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:canonical:ubuntu_linux:24.04::~~lts~~~">28 ······<cpe-dict:cpe-item·name="cpe:/o:canonical:ubuntu_linux:24.04::~~lts~~~">
29 ········<cpe-dict:title·xml:lang="en-us">Ubuntu·release·24.04·(Noble·Numbat)</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Ubuntu·release·24.04·(Noble·Numbat)</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml">oval:ssg-installed_OS_is_ubuntu2404:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml">oval:ssg-installed_OS_is_ubuntu2404:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ····</cpe-dict:cpe-list>32 ····</cpe-dict:cpe-list>
33 ··</ds:component>33 ··</ds:component>
34 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2404-xccdf.xml"·timestamp="2025-02-28T20:08:00">34 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2404-xccdf.xml"·timestamp="2025-03-01T22:08:00">
35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_UBUNTU_24-04"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_UBUNTU_24-04"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Ubuntu·24.04</xccdf-1.2:title>37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Ubuntu·24.04</xccdf-1.2:title>
38 ······<xccdf-1.2:description>38 ······<xccdf-1.2:description>
39 ········This·guide·presents·a·catalog·of·security-relevant39 ········This·guide·presents·a·catalog·of·security-relevant
40 configuration·settings·for·Ubuntu·24.04.·It·is·a·rendering·of40 configuration·settings·for·Ubuntu·24.04.·It·is·a·rendering·of
41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 105, 296 lines modifiedOffset 105, 296 lines modified
105 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>105 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
106 ······<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>106 ······<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
107 ······<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>107 ······<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
108 ······<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>108 ······<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
109 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>109 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
110 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>110 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
111 ······<cpe-lang:platform-specification>111 ······<cpe-lang:platform-specification>
112 ········<cpe-lang:platform·id="package_aide_and_package_systemd">112 ········<cpe-lang:platform·id="mount_var-tmp">
113 ··········<cpe-lang:logical-test·operator="AND"·negate="false">113 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
114 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-package_aide:def:1"/> 
115 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>114 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-tmp:def:1"/>
116 ··········</cpe-lang:logical-test>115 ··········</cpe-lang:logical-test>
117 ········</cpe-lang:platform>116 ········</cpe-lang:platform>
118 ········<cpe-lang:platform·id="package_nftables_and_service_disabled_firewalld_and_system_with_kernel">117 ········<cpe-lang:platform·id="package_autofs_and_system_with_kernel">
119 ··········<cpe-lang:logical-test·operator="AND"·negate="false">118 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
120 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>119 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>
121 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_firewalld:def:1"/> 
122 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>120 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
123 ··········</cpe-lang:logical-test>121 ··········</cpe-lang:logical-test>
124 ········</cpe-lang:platform>122 ········</cpe-lang:platform>
125 ········<cpe-lang:platform·id="machine">123 ········<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">
126 ··········<cpe-lang:logical-test·operator="AND"·negate="false">124 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 125 ············<cpe-lang:logical-test·operator="AND"·negate="true">
 126 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
 127 ············</cpe-lang:logical-test>
 128 ············<cpe-lang:logical-test·operator="AND"·negate="true">
 129 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
 130 ············</cpe-lang:logical-test>
127 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>131 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
128 ··········</cpe-lang:logical-test>132 ··········</cpe-lang:logical-test>
129 ········</cpe-lang:platform>133 ········</cpe-lang:platform>
130 ········<cpe-lang:platform·id="package_squid_and_system_with_kernel">134 ········<cpe-lang:platform·id="ipv6_enabled">
131 ··········<cpe-lang:logical-test·operator="AND"·negate="false">135 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
132 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-package_squid:def:1"/>136 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-ipv6_enabled:def:1"/>
133 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
134 ··········</cpe-lang:logical-test>137 ··········</cpe-lang:logical-test>
135 ········</cpe-lang:platform>138 ········</cpe-lang:platform>
136 ········<cpe-lang:platform·id="package_pam">139 ········<cpe-lang:platform·id="package_gdm">
137 ··········<cpe-lang:logical-test·operator="AND"·negate="false">140 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
138 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>141 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-package_gdm:def:1"/>
139 ··········</cpe-lang:logical-test>142 ··········</cpe-lang:logical-test>
140 ········</cpe-lang:platform>143 ········</cpe-lang:platform>
141 ········<cpe-lang:platform·id="package_autofs_and_system_with_kernel">144 ········<cpe-lang:platform·id="package_bash">
142 ··········<cpe-lang:logical-test·operator="AND"·negate="false">145 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
143 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>146 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>
144 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
145 ··········</cpe-lang:logical-test>147 ··········</cpe-lang:logical-test>
146 ········</cpe-lang:platform>148 ········</cpe-lang:platform>
147 ········<cpe-lang:platform·id="mount_tmp">149 ········<cpe-lang:platform·id="uefi">
148 ··········<cpe-lang:logical-test·operator="AND"·negate="false">150 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
149 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_tmp:def:1"/>151 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>
150 ··········</cpe-lang:logical-test>152 ··········</cpe-lang:logical-test>
151 ········</cpe-lang:platform>153 ········</cpe-lang:platform>
152 ········<cpe-lang:platform·id="package_firewalld_and_package_nftables_and_system_with_kernel">154 ········<cpe-lang:platform·id="package_chrony">
153 ··········<cpe-lang:logical-test·operator="AND"·negate="false">155 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
154 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/> 
155 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>156 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
156 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
157 ··········</cpe-lang:logical-test>157 ··········</cpe-lang:logical-test>
158 ········</cpe-lang:platform>158 ········</cpe-lang:platform>
159 ········<cpe-lang:platform·id="not_package_chrony_and_not_package_ntp">159 ········<cpe-lang:platform·id="package_ufw_and_system_with_kernel">
160 ··········<cpe-lang:logical-test·operator="AND"·negate="false">160 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
161 ············<cpe-lang:logical-test·operator="AND"·negate="true"> 
162 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/> 
163 ············</cpe-lang:logical-test> 
164 ············<cpe-lang:logical-test·operator="AND"·negate="true"> 
165 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-package_ntp:def:1"/>161 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
166 ············</cpe-lang:logical-test>162 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
167 ··········</cpe-lang:logical-test>163 ··········</cpe-lang:logical-test>
168 ········</cpe-lang:platform>164 ········</cpe-lang:platform>
169 ········<cpe-lang:platform·id="mount_var-log">165 ········<cpe-lang:platform·id="package_nftables_and_service_disabled_firewalld_and_service_disabled_ufw">
170 ··········<cpe-lang:logical-test·operator="AND"·negate="false">166 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 167 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
 168 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_firewalld:def:1"/>
171 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-log:def:1"/>169 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_ufw:def:1"/>
172 ··········</cpe-lang:logical-test>170 ··········</cpe-lang:logical-test>
173 ········</cpe-lang:platform>171 ········</cpe-lang:platform>
174 ········<cpe-lang:platform·id="uefi">172 ········<cpe-lang:platform·id="package_rsh-server">
175 ··········<cpe-lang:logical-test·operator="AND"·negate="false">173 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
176 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>174 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-package_rsh-server:def:1"/>
177 ··········</cpe-lang:logical-test>175 ··········</cpe-lang:logical-test>
178 ········</cpe-lang:platform>176 ········</cpe-lang:platform>
179 ········<cpe-lang:platform·id="package_bash">177 ········<cpe-lang:platform·id="package_systemd">
180 ··········<cpe-lang:logical-test·operator="AND"·negate="false">178 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
181 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>179 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>
182 ··········</cpe-lang:logical-test>180 ··········</cpe-lang:logical-test>
183 ········</cpe-lang:platform>181 ········</cpe-lang:platform>
184 ········<cpe-lang:platform·id="package_iptables">182 ········<cpe-lang:platform·id="mount_tmp">
185 ··········<cpe-lang:logical-test·operator="AND"·negate="false">183 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
186 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>184 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_tmp:def:1"/>
187 ··········</cpe-lang:logical-test>185 ··········</cpe-lang:logical-test>
188 ········</cpe-lang:platform>186 ········</cpe-lang:platform>
189 ········<cpe-lang:platform·id="grub2">187 ········<cpe-lang:platform·id="package_apport">
190 ··········<cpe-lang:logical-test·operator="AND"·negate="false">188 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
191 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>189 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-package_apport:def:1"/>
192 ··········</cpe-lang:logical-test>190 ··········</cpe-lang:logical-test>
193 ········</cpe-lang:platform>191 ········</cpe-lang:platform>
194 ········<cpe-lang:platform·id="wifi-iface">192 ········<cpe-lang:platform·id="not_package_chrony_and_not_package_ntp">
195 ··········<cpe-lang:logical-test·operator="AND"·negate="false">193 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
196 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_wifi_interface:def:1"/> 
197 ··········</cpe-lang:logical-test> 
198 ········</cpe-lang:platform> 
199 ········<cpe-lang:platform·id="not_container"> 
Max diff block lines reached; 1013151/1028676 bytes (98.49%) of diff not shown.
881 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2404-ocil.xml
881 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2404-ocil.xml
Ordering differences only
    
Offset 3, 6086 lines modifiedOffset 3, 6327 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-file_owner_cron_allow_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_at_allow_ocil:questionnaire:1">
11 ······<ocil:title>Verify·User·Who·Owns·/etc/cron.allow·file</ocil:title>11 ······<ocil:title>Verify·Permissions·on·/etc/at.allow·file</ocil:title>
12 ······<ocil:actions> 
13 ········<ocil:test_action_ref>ocil:ssg-file_owner_cron_allow_action:testaction:1</ocil:test_action_ref> 
14 ······</ocil:actions> 
15 ····</ocil:questionnaire> 
16 ····<ocil:questionnaire·id="ocil:ssg-set_nftables_table_ocil:questionnaire:1"> 
17 ······<ocil:title>Ensure·a·Table·Exists·for·Nftables</ocil:title> 
18 ······<ocil:actions>12 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-set_nftables_table_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-file_permissions_at_allow_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>14 ······</ocil:actions>
21 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-systemd_journal_upload_url_ocil:questionnaire:1"> 
23 ······<ocil:title>Configure·systemd-journal-upload·URL</ocil:title>16 ····<ocil:questionnaire·id="ocil:ssg-set_iptables_default_rule_ocil:questionnaire:1">
 17 ······<ocil:title>Set·Default·iptables·Policy·for·Incoming·Packets</ocil:title>
24 ······<ocil:actions>18 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-systemd_journal_upload_url_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-set_iptables_default_rule_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>20 ······</ocil:actions>
27 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_maxrepeat_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-rsyslog_remote_loghost_ocil:questionnaire:1">
29 ······<ocil:title>Set·Password·Maximum·Consecutive·Repeating·Characters</ocil:title>23 ······<ocil:title>Ensure·Logs·Sent·To·Remote·Host</ocil:title>
30 ······<ocil:actions>24 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-accounts_password_pam_maxrepeat_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-rsyslog_remote_loghost_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>26 ······</ocil:actions>
33 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_pwhistory_remember_ocil:questionnaire:1"> 
35 ······<ocil:title>Limit·Password·Reuse</ocil:title>28 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_fchownat_ocil:questionnaire:1">
 29 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·fchownat</ocil:title>
36 ······<ocil:actions>30 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-accounts_password_pam_pwhistory_remember_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_fchownat_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>32 ······</ocil:actions>
39 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-partition_for_home_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-mount_option_tmp_nodev_ocil:questionnaire:1">
41 ······<ocil:title>Ensure·/home·Located·On·Separate·Partition</ocil:title>35 ······<ocil:title>Add·nodev·Option·to·/tmp</ocil:title>
42 ······<ocil:actions>36 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-partition_for_home_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-mount_option_tmp_nodev_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>38 ······</ocil:actions>
45 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-file_owner_etc_motd_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-mount_option_var_nosuid_ocil:questionnaire:1">
47 ······<ocil:title>Verify·ownership·of·Message·of·the·Day·Banner</ocil:title>41 ······<ocil:title>Add·nosuid·Option·to·/var</ocil:title>
48 ······<ocil:actions>42 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-file_owner_etc_motd_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-mount_option_var_nosuid_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>44 ······</ocil:actions>
51 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_default_accept_ra_ocil:questionnaire:1"> 
53 ······<ocil:title>Disable·Accepting·Router·Advertisements·on·all·IPv6·Interfaces·by·Default</ocil:title>46 ····<ocil:questionnaire·id="ocil:ssg-account_disable_post_pw_expiration_ocil:questionnaire:1">
 47 ······<ocil:title>Set·Account·Expiration·Following·Inactivity</ocil:title>
54 ······<ocil:actions>48 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_default_accept_ra_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-account_disable_post_pw_expiration_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>50 ······</ocil:actions>
57 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_cron_weekly_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-journald_storage_ocil:questionnaire:1">
59 ······<ocil:title>Verify·Permissions·on·cron.weekly</ocil:title>53 ······<ocil:title>Ensure·journald·is·configured·to·write·log·files·to·persistent·disk</ocil:title>
60 ······<ocil:actions>54 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-file_permissions_cron_weekly_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-journald_storage_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>56 ······</ocil:actions>
63 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-set_ufw_default_rule_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_group_ocil:questionnaire:1">
65 ······<ocil:title>Ensure·ufw·Default·Deny·Firewall·Policy</ocil:title>59 ······<ocil:title>Verify·Permissions·on·group·File</ocil:title>
66 ······<ocil:actions>60 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-set_ufw_default_rule_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-file_permissions_etc_group_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>62 ······</ocil:actions>
69 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-mount_option_var_log_nosuid_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-package_aide_installed_ocil:questionnaire:1">
71 ······<ocil:title>Add·nosuid·Option·to·/var/log</ocil:title>65 ······<ocil:title>Install·AIDE</ocil:title>
72 ······<ocil:actions>66 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-mount_option_var_log_nosuid_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-package_aide_installed_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>68 ······</ocil:actions>
75 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-package_samba_removed_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-package_iptables-persistent_installed_ocil:questionnaire:1">
77 ······<ocil:title>Uninstall·Samba·Package</ocil:title>71 ······<ocil:title>Install·iptables-persistent·Package</ocil:title>
78 ······<ocil:actions>72 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-package_samba_removed_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-package_iptables-persistent_installed_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>74 ······</ocil:actions>
81 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-group_unique_id_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-file_groupownership_home_directories_ocil:questionnaire:1">
83 ······<ocil:title>Ensure·All·Groups·on·the·System·Have·Unique·Group·ID</ocil:title>77 ······<ocil:title>All·Interactive·User·Home·Directories·Must·Be·Group-Owned·By·The·Primary·Group</ocil:title>
84 ······<ocil:actions>78 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-group_unique_id_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-file_groupownership_home_directories_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>80 ······</ocil:actions>
87 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_cron_d_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_file_deletion_events_unlinkat_ocil:questionnaire:1">
89 ······<ocil:title>Verify·Group·Who·Owns·cron.d</ocil:title>83 ······<ocil:title>Ensure·auditd·Collects·File·Deletion·Events·by·User·-·unlinkat</ocil:title>
90 ······<ocil:actions>84 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_cron_d_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-audit_rules_file_deletion_events_unlinkat_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>86 ······</ocil:actions>
93 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-file_owner_cron_hourly_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-sudo_add_use_pty_ocil:questionnaire:1">
95 ······<ocil:title>Verify·Owner·on·cron.hourly</ocil:title>89 ······<ocil:title>Ensure·Only·Users·Logged·In·To·Real·tty·Can·Execute·Sudo·-·sudo·use_pty</ocil:title>
96 ······<ocil:actions>90 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-file_owner_cron_hourly_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-sudo_add_use_pty_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>92 ······</ocil:actions>
99 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_cron_daily_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_all_shadowed_ocil:questionnaire:1">
101 ······<ocil:title>Verify·Group·Who·Owns·cron.daily</ocil:title>95 ······<ocil:title>Verify·All·Account·Password·Hashes·are·Shadowed</ocil:title>
102 ······<ocil:actions>96 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_cron_daily_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-accounts_password_all_shadowed_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>98 ······</ocil:actions>
105 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-mount_option_tmp_nosuid_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-sshd_set_max_auth_tries_ocil:questionnaire:1">
107 ······<ocil:title>Add·nosuid·Option·to·/tmp</ocil:title>101 ······<ocil:title>Set·SSH·authentication·attempt·limit</ocil:title>
108 ······<ocil:actions>102 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-mount_option_tmp_nosuid_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-sshd_set_max_auth_tries_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>104 ······</ocil:actions>
111 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-grub2_password_ocil:questionnaire:1">106 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_unauthorized_world_writable_ocil:questionnaire:1">
113 ······<ocil:title>Set·Boot·Loader·Password·in·grub2</ocil:title>107 ······<ocil:title>Ensure·No·World-Writable·Files·Exist</ocil:title>
114 ······<ocil:actions>108 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-grub2_password_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-file_permissions_unauthorized_world_writable_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>110 ······</ocil:actions>
117 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_enforcing_ocil:questionnaire:1">112 ····<ocil:questionnaire·id="ocil:ssg-accounts_minimum_age_login_defs_ocil:questionnaire:1">
119 ······<ocil:title>Ensure·PAM·Enforces·Password·Requirements·-·Enforcing</ocil:title>113 ······<ocil:title>Set·Password·Minimum·Age</ocil:title>
120 ······<ocil:actions>114 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-accounts_password_pam_enforcing_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-accounts_minimum_age_login_defs_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>116 ······</ocil:actions>
123 ····</ocil:questionnaire>117 ····</ocil:questionnaire>
124 ····<ocil:questionnaire·id="ocil:ssg-set_password_hashing_algorithm_logindefs_ocil:questionnaire:1">118 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_maxrepeat_ocil:questionnaire:1">
125 ······<ocil:title>Set·Password·Hashing·Algorithm·in·/etc/login.defs</ocil:title>119 ······<ocil:title>Set·Password·Maximum·Consecutive·Repeating·Characters</ocil:title>
126 ······<ocil:actions>120 ······<ocil:actions>
Max diff block lines reached; 889942/902376 bytes (98.62%) of diff not shown.
79.8 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2404-xccdf.xml
79.7 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2404-xccdf.xml
Ordering differences only
    
Offset 72, 296 lines modifiedOffset 72, 296 lines modified
72 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>72 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
73 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>73 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
74 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>74 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
75 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>75 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
77 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>77 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
78 ··<cpe-lang:platform-specification>78 ··<cpe-lang:platform-specification>
79 ····<cpe-lang:platform·id="package_aide_and_package_systemd">79 ····<cpe-lang:platform·id="mount_var-tmp">
80 ······<cpe-lang:logical-test·operator="AND"·negate="false">80 ······<cpe-lang:logical-test·operator="AND"·negate="false">
81 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-package_aide:def:1"/> 
82 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>81 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-tmp:def:1"/>
83 ······</cpe-lang:logical-test>82 ······</cpe-lang:logical-test>
84 ····</cpe-lang:platform>83 ····</cpe-lang:platform>
85 ····<cpe-lang:platform·id="package_nftables_and_service_disabled_firewalld_and_system_with_kernel">84 ····<cpe-lang:platform·id="package_autofs_and_system_with_kernel">
86 ······<cpe-lang:logical-test·operator="AND"·negate="false">85 ······<cpe-lang:logical-test·operator="AND"·negate="false">
87 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>86 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>
88 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_firewalld:def:1"/> 
89 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>87 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
90 ······</cpe-lang:logical-test>88 ······</cpe-lang:logical-test>
91 ····</cpe-lang:platform>89 ····</cpe-lang:platform>
92 ····<cpe-lang:platform·id="machine">90 ····<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">
93 ······<cpe-lang:logical-test·operator="AND"·negate="false">91 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 92 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 93 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
 94 ········</cpe-lang:logical-test>
 95 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 96 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
 97 ········</cpe-lang:logical-test>
94 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>98 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
95 ······</cpe-lang:logical-test>99 ······</cpe-lang:logical-test>
96 ····</cpe-lang:platform>100 ····</cpe-lang:platform>
97 ····<cpe-lang:platform·id="package_squid_and_system_with_kernel">101 ····<cpe-lang:platform·id="ipv6_enabled">
98 ······<cpe-lang:logical-test·operator="AND"·negate="false">102 ······<cpe-lang:logical-test·operator="AND"·negate="false">
99 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-package_squid:def:1"/>103 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-ipv6_enabled:def:1"/>
100 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
101 ······</cpe-lang:logical-test>104 ······</cpe-lang:logical-test>
102 ····</cpe-lang:platform>105 ····</cpe-lang:platform>
103 ····<cpe-lang:platform·id="package_pam">106 ····<cpe-lang:platform·id="package_gdm">
104 ······<cpe-lang:logical-test·operator="AND"·negate="false">107 ······<cpe-lang:logical-test·operator="AND"·negate="false">
105 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>108 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-package_gdm:def:1"/>
106 ······</cpe-lang:logical-test>109 ······</cpe-lang:logical-test>
107 ····</cpe-lang:platform>110 ····</cpe-lang:platform>
108 ····<cpe-lang:platform·id="package_autofs_and_system_with_kernel">111 ····<cpe-lang:platform·id="package_bash">
109 ······<cpe-lang:logical-test·operator="AND"·negate="false">112 ······<cpe-lang:logical-test·operator="AND"·negate="false">
110 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>113 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>
111 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
112 ······</cpe-lang:logical-test>114 ······</cpe-lang:logical-test>
113 ····</cpe-lang:platform>115 ····</cpe-lang:platform>
114 ····<cpe-lang:platform·id="mount_tmp">116 ····<cpe-lang:platform·id="uefi">
115 ······<cpe-lang:logical-test·operator="AND"·negate="false">117 ······<cpe-lang:logical-test·operator="AND"·negate="false">
116 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_tmp:def:1"/>118 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>
117 ······</cpe-lang:logical-test>119 ······</cpe-lang:logical-test>
118 ····</cpe-lang:platform>120 ····</cpe-lang:platform>
119 ····<cpe-lang:platform·id="package_firewalld_and_package_nftables_and_system_with_kernel">121 ····<cpe-lang:platform·id="package_chrony">
120 ······<cpe-lang:logical-test·operator="AND"·negate="false">122 ······<cpe-lang:logical-test·operator="AND"·negate="false">
121 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/> 
122 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>123 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
123 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
124 ······</cpe-lang:logical-test>124 ······</cpe-lang:logical-test>
125 ····</cpe-lang:platform>125 ····</cpe-lang:platform>
126 ····<cpe-lang:platform·id="not_package_chrony_and_not_package_ntp">126 ····<cpe-lang:platform·id="package_ufw_and_system_with_kernel">
127 ······<cpe-lang:logical-test·operator="AND"·negate="false">127 ······<cpe-lang:logical-test·operator="AND"·negate="false">
128 ········<cpe-lang:logical-test·operator="AND"·negate="true"> 
129 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/> 
130 ········</cpe-lang:logical-test> 
131 ········<cpe-lang:logical-test·operator="AND"·negate="true"> 
132 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-package_ntp:def:1"/>128 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
133 ········</cpe-lang:logical-test>129 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
134 ······</cpe-lang:logical-test>130 ······</cpe-lang:logical-test>
135 ····</cpe-lang:platform>131 ····</cpe-lang:platform>
136 ····<cpe-lang:platform·id="mount_var-log">132 ····<cpe-lang:platform·id="package_nftables_and_service_disabled_firewalld_and_service_disabled_ufw">
137 ······<cpe-lang:logical-test·operator="AND"·negate="false">133 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 134 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
 135 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_firewalld:def:1"/>
138 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-log:def:1"/>136 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_ufw:def:1"/>
139 ······</cpe-lang:logical-test>137 ······</cpe-lang:logical-test>
140 ····</cpe-lang:platform>138 ····</cpe-lang:platform>
141 ····<cpe-lang:platform·id="uefi">139 ····<cpe-lang:platform·id="package_rsh-server">
142 ······<cpe-lang:logical-test·operator="AND"·negate="false">140 ······<cpe-lang:logical-test·operator="AND"·negate="false">
143 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>141 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-package_rsh-server:def:1"/>
144 ······</cpe-lang:logical-test>142 ······</cpe-lang:logical-test>
145 ····</cpe-lang:platform>143 ····</cpe-lang:platform>
146 ····<cpe-lang:platform·id="package_bash">144 ····<cpe-lang:platform·id="package_systemd">
147 ······<cpe-lang:logical-test·operator="AND"·negate="false">145 ······<cpe-lang:logical-test·operator="AND"·negate="false">
148 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>146 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>
149 ······</cpe-lang:logical-test>147 ······</cpe-lang:logical-test>
150 ····</cpe-lang:platform>148 ····</cpe-lang:platform>
151 ····<cpe-lang:platform·id="package_iptables">149 ····<cpe-lang:platform·id="mount_tmp">
152 ······<cpe-lang:logical-test·operator="AND"·negate="false">150 ······<cpe-lang:logical-test·operator="AND"·negate="false">
153 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>151 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_tmp:def:1"/>
154 ······</cpe-lang:logical-test>152 ······</cpe-lang:logical-test>
155 ····</cpe-lang:platform>153 ····</cpe-lang:platform>
156 ····<cpe-lang:platform·id="grub2">154 ····<cpe-lang:platform·id="package_apport">
157 ······<cpe-lang:logical-test·operator="AND"·negate="false">155 ······<cpe-lang:logical-test·operator="AND"·negate="false">
158 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>156 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-package_apport:def:1"/>
159 ······</cpe-lang:logical-test>157 ······</cpe-lang:logical-test>
160 ····</cpe-lang:platform>158 ····</cpe-lang:platform>
161 ····<cpe-lang:platform·id="wifi-iface">159 ····<cpe-lang:platform·id="not_package_chrony_and_not_package_ntp">
162 ······<cpe-lang:logical-test·operator="AND"·negate="false">160 ······<cpe-lang:logical-test·operator="AND"·negate="false">
163 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_wifi_interface:def:1"/> 
164 ······</cpe-lang:logical-test> 
165 ····</cpe-lang:platform> 
166 ····<cpe-lang:platform·id="not_container"> 
167 ······<cpe-lang:logical-test·operator="AND"·negate="true">161 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 162 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
 163 ········</cpe-lang:logical-test>
 164 ········<cpe-lang:logical-test·operator="AND"·negate="true">
168 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_container:def:1"/>165 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-package_ntp:def:1"/>
 166 ········</cpe-lang:logical-test>
169 ······</cpe-lang:logical-test>167 ······</cpe-lang:logical-test>
170 ····</cpe-lang:platform>168 ····</cpe-lang:platform>
171 ····<cpe-lang:platform·id="package_nftables_and_service_disabled_firewalld">169 ····<cpe-lang:platform·id="package_nftables">
172 ······<cpe-lang:logical-test·operator="AND"·negate="false">170 ······<cpe-lang:logical-test·operator="AND"·negate="false">
173 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>171 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
174 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_firewalld:def:1"/> 
175 ······</cpe-lang:logical-test>172 ······</cpe-lang:logical-test>
176 ····</cpe-lang:platform>173 ····</cpe-lang:platform>
177 ····<cpe-lang:platform·id="package_systemd">174 ····<cpe-lang:platform·id="package_pam">
178 ······<cpe-lang:logical-test·operator="AND"·negate="false">175 ······<cpe-lang:logical-test·operator="AND"·negate="false">
179 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>176 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>
180 ······</cpe-lang:logical-test>177 ······</cpe-lang:logical-test>
181 ····</cpe-lang:platform>178 ····</cpe-lang:platform>
182 ····<cpe-lang:platform·id="package_apport">179 ····<cpe-lang:platform·id="package_systemd-timesyncd">
183 ······<cpe-lang:logical-test·operator="AND"·negate="false">180 ······<cpe-lang:logical-test·operator="AND"·negate="false">
184 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-package_apport:def:1"/>181 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-package_systemd-timesyncd:def:1"/>
185 ······</cpe-lang:logical-test>182 ······</cpe-lang:logical-test>
186 ····</cpe-lang:platform>183 ····</cpe-lang:platform>
Max diff block lines reached; 66714/81441 bytes (81.92%) of diff not shown.
3.83 MB
ssg-debian_0.1.76-1_all.deb
367 B
file list
    
Offset 1, 3 lines modifiedOffset 1, 3 lines modified
1 -rw-r--r--···0········0········0········4·2025-03-01·08:08:00.000000·debian-binary1 -rw-r--r--···0········0········0········4·2025-03-01·08:08:00.000000·debian-binary
2 -rw-r--r--···0········0········0·····1976·2025-03-01·08:08:00.000000·control.tar.xz2 -rw-r--r--···0········0········0·····1976·2025-03-01·08:08:00.000000·control.tar.xz
3 -rw-r--r--···0········0········0··1230376·2025-03-01·08:08:00.000000·data.tar.xz3 -rw-r--r--···0········0········0··1230168·2025-03-01·08:08:00.000000·data.tar.xz
98.0 B
control.tar.xz
70.0 B
control.tar
48.0 B
./md5sums
30.0 B
./md5sums
Files differ
3.83 MB
data.tar.xz
3.83 MB
data.tar
752 KB
./usr/share/xml/scap/ssg/content/ssg-debian11-ds.xml
752 KB
./usr/share/xml/scap/ssg/content/ssg-debian11-ds.xml
    
Offset 19, 23 lines modifiedOffset 19, 23 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-debian11-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-debian11-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-debian11-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-debian11-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-debian11-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-debian11-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-debian11-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-debian11-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-debian11-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-debian11-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-debian11-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-debian11-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-debian11-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-debian11-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:debian:debian_linux:11">28 ······<cpe-dict:cpe-item·name="cpe:/o:debian:debian_linux:11">
29 ········<cpe-dict:title·xml:lang="en-us">Debian·Linux·11</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Debian·Linux·11</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml">oval:ssg-installed_OS_is_debian11:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml">oval:ssg-installed_OS_is_debian11:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ····</cpe-dict:cpe-list>32 ····</cpe-dict:cpe-list>
33 ··</ds:component>33 ··</ds:component>
34 ··<ds:component·id="scap_org.open-scap_comp_ssg-debian11-xccdf.xml"·timestamp="2025-02-28T20:08:00">34 ··<ds:component·id="scap_org.open-scap_comp_ssg-debian11-xccdf.xml"·timestamp="2025-03-01T22:08:00">
35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_DEBIAN-11"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_DEBIAN-11"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Debian·11</xccdf-1.2:title>37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Debian·11</xccdf-1.2:title>
38 ······<xccdf-1.2:description>38 ······<xccdf-1.2:description>
39 ········This·guide·presents·a·catalog·of·security-relevant39 ········This·guide·presents·a·catalog·of·security-relevant
40 configuration·settings·for·Debian·11.·It·is·a·rendering·of40 configuration·settings·for·Debian·11.·It·is·a·rendering·of
41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 105, 181 lines modifiedOffset 105, 181 lines modified
105 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>105 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
106 ······<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>106 ······<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
107 ······<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>107 ······<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
108 ······<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>108 ······<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
109 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>109 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
110 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>110 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
111 ······<cpe-lang:platform-specification>111 ······<cpe-lang:platform-specification>
112 ········<cpe-lang:platform·id="machine">112 ········<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">
113 ··········<cpe-lang:logical-test·operator="AND"·negate="false">113 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 114 ············<cpe-lang:logical-test·operator="AND"·negate="true">
 115 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
 116 ············</cpe-lang:logical-test>
 117 ············<cpe-lang:logical-test·operator="AND"·negate="true">
 118 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
 119 ············</cpe-lang:logical-test>
114 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>120 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
115 ··········</cpe-lang:logical-test>121 ··········</cpe-lang:logical-test>
116 ········</cpe-lang:platform>122 ········</cpe-lang:platform>
117 ········<cpe-lang:platform·id="package_pam">123 ········<cpe-lang:platform·id="package_gdm">
118 ··········<cpe-lang:logical-test·operator="AND"·negate="false">124 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
119 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>125 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-package_gdm:def:1"/>
120 ··········</cpe-lang:logical-test>126 ··········</cpe-lang:logical-test>
121 ········</cpe-lang:platform>127 ········</cpe-lang:platform>
122 ········<cpe-lang:platform·id="package_iptables">128 ········<cpe-lang:platform·id="package_rsyslog">
123 ··········<cpe-lang:logical-test·operator="AND"·negate="false">129 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
124 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>130 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>
125 ··········</cpe-lang:logical-test>131 ··········</cpe-lang:logical-test>
126 ········</cpe-lang:platform>132 ········</cpe-lang:platform>
127 ········<cpe-lang:platform·id="package_rsyslog">133 ········<cpe-lang:platform·id="package_logrotate">
128 ··········<cpe-lang:logical-test·operator="AND"·negate="false">134 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 135 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-package_logrotate:def:1"/>
 136 ··········</cpe-lang:logical-test>
 137 ········</cpe-lang:platform>
 138 ········<cpe-lang:platform·id="package_chrony">
 139 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
129 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>140 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
 141 ··········</cpe-lang:logical-test>
 142 ········</cpe-lang:platform>
 143 ········<cpe-lang:platform·id="package_ufw_and_system_with_kernel">
 144 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 145 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
 146 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
 147 ··········</cpe-lang:logical-test>
 148 ········</cpe-lang:platform>
 149 ········<cpe-lang:platform·id="package_rsh-server">
 150 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 151 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-package_rsh-server:def:1"/>
130 ··········</cpe-lang:logical-test>152 ··········</cpe-lang:logical-test>
131 ········</cpe-lang:platform>153 ········</cpe-lang:platform>
132 ········<cpe-lang:platform·id="package_systemd">154 ········<cpe-lang:platform·id="package_systemd">
133 ··········<cpe-lang:logical-test·operator="AND"·negate="false">155 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
134 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>156 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>
135 ··········</cpe-lang:logical-test>157 ··········</cpe-lang:logical-test>
136 ········</cpe-lang:platform>158 ········</cpe-lang:platform>
137 ········<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">159 ········<cpe-lang:platform·id="not_bootc_and_not_container">
138 ··········<cpe-lang:logical-test·operator="AND"·negate="false">160 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
139 ············<cpe-lang:logical-test·operator="AND"·negate="true">161 ············<cpe-lang:logical-test·operator="AND"·negate="true">
140 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>162 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-bootc:def:1"/>
141 ············</cpe-lang:logical-test>163 ············</cpe-lang:logical-test>
142 ············<cpe-lang:logical-test·operator="AND"·negate="true">164 ············<cpe-lang:logical-test·operator="AND"·negate="true">
143 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>165 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_container:def:1"/>
144 ············</cpe-lang:logical-test>166 ············</cpe-lang:logical-test>
145 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/> 
146 ··········</cpe-lang:logical-test>167 ··········</cpe-lang:logical-test>
147 ········</cpe-lang:platform>168 ········</cpe-lang:platform>
 169 ········<cpe-lang:platform·id="package_iptables_and_service_disabled_firewalld_and_system_with_kernel">
148 ········<cpe-lang:platform·id="package_postfix"> 
149 ··········<cpe-lang:logical-test·operator="AND"·negate="false"> 
150 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-package_postfix:def:1"/> 
151 ··········</cpe-lang:logical-test> 
152 ········</cpe-lang:platform> 
153 ········<cpe-lang:platform·id="package_audit"> 
154 ··········<cpe-lang:logical-test·operator="AND"·negate="false">170 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
155 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-package_audit:def:1"/>171 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
 172 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_firewalld:def:1"/>
 173 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
156 ··········</cpe-lang:logical-test>174 ··········</cpe-lang:logical-test>
157 ········</cpe-lang:platform>175 ········</cpe-lang:platform>
158 ········<cpe-lang:platform·id="package_snmpd_and_system_with_kernel">176 ········<cpe-lang:platform·id="aarch64_arch_or_x86_64_arch">
159 ··········<cpe-lang:logical-test·operator="AND"·negate="false">177 ··········<cpe-lang:logical-test·operator="OR"·negate="false">
160 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-package_snmpd:def:1"/>178 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
161 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>179 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/>
162 ··········</cpe-lang:logical-test>180 ··········</cpe-lang:logical-test>
163 ········</cpe-lang:platform>181 ········</cpe-lang:platform>
164 ········<cpe-lang:platform·id="package_logrotate">182 ········<cpe-lang:platform·id="package_pam">
165 ··········<cpe-lang:logical-test·operator="AND"·negate="false">183 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
166 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-package_logrotate:def:1"/>184 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>
167 ··········</cpe-lang:logical-test>185 ··········</cpe-lang:logical-test>
168 ········</cpe-lang:platform>186 ········</cpe-lang:platform>
169 ········<cpe-lang:platform·id="package_ntp">187 ········<cpe-lang:platform·id="machine">
170 ··········<cpe-lang:logical-test·operator="AND"·negate="false">188 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
171 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-package_ntp:def:1"/>189 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
172 ··········</cpe-lang:logical-test>190 ··········</cpe-lang:logical-test>
173 ········</cpe-lang:platform>191 ········</cpe-lang:platform>
174 ········<cpe-lang:platform·id="package_sudo">192 ········<cpe-lang:platform·id="package_sudo">
175 ··········<cpe-lang:logical-test·operator="AND"·negate="false">193 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
176 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-package_sudo:def:1"/>194 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-package_sudo:def:1"/>
177 ··········</cpe-lang:logical-test>195 ··········</cpe-lang:logical-test>
178 ········</cpe-lang:platform>196 ········</cpe-lang:platform>
179 ········<cpe-lang:platform·id="aarch64_arch_or_x86_64_arch"> 
180 ··········<cpe-lang:logical-test·operator="OR"·negate="false"> 
181 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/> 
182 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/> 
Max diff block lines reached; 756788/770255 bytes (98.25%) of diff not shown.
696 KB
./usr/share/xml/scap/ssg/content/ssg-debian11-ocil.xml
696 KB
./usr/share/xml/scap/ssg/content/ssg-debian11-ocil.xml
Ordering differences only
    
Offset 3, 2147 lines modifiedOffset 3, 2147 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-file_groupownership_sshd_pub_key_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_sysadmin_actions_ocil:questionnaire:1">
11 ······<ocil:title>Verify·Group·Ownership·on·SSH·Server·Public·*.pub·Key·Files</ocil:title>11 ······<ocil:title>Ensure·auditd·Collects·System·Administrator·Actions</ocil:title>
12 ······<ocil:actions>12 ······<ocil:actions>
13 ········<ocil:test_action_ref>ocil:ssg-file_groupownership_sshd_pub_key_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-audit_rules_sysadmin_actions_action:testaction:1</ocil:test_action_ref>
14 ······</ocil:actions>14 ······</ocil:actions>
15 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
16 ····<ocil:questionnaire·id="ocil:ssg-file_owner_backup_etc_passwd_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-auditd_write_logs_ocil:questionnaire:1">
17 ······<ocil:title>Verify·User·Who·Owns·Backup·passwd·File</ocil:title>17 ······<ocil:title>Write·Audit·Logs·to·the·Disk</ocil:title>
18 ······<ocil:actions>18 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-file_owner_backup_etc_passwd_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-auditd_write_logs_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>20 ······</ocil:actions>
21 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-grub2_slab_nomerge_argument_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_gshadow_ocil:questionnaire:1">
23 ······<ocil:title>Disable·merging·of·slabs·with·similar·size</ocil:title>23 ······<ocil:title>Verify·Group·Who·Owns·gshadow·File</ocil:title>
24 ······<ocil:actions>24 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-grub2_slab_nomerge_argument_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_gshadow_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>26 ······</ocil:actions>
27 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"> 
29 ······<ocil:title>Write·Audit·Logs·to·the·Disk</ocil:title>28 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_shared_media_ocil:questionnaire:1">
 29 ······<ocil:title>Configure·Sending·and·Accepting·Shared·Media·Redirects·by·Default</ocil:title>
30 ······<ocil:actions>30 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-auditd_write_logs_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_shared_media_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>32 ······</ocil:actions>
33 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_backup_etc_shadow_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_time_adjtimex_ocil:questionnaire:1">
35 ······<ocil:title>Verify·Permissions·on·Backup·shadow·File</ocil:title>35 ······<ocil:title>Record·attempts·to·alter·time·through·adjtimex</ocil:title>
36 ······<ocil:actions>36 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-file_permissions_backup_etc_shadow_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-audit_rules_time_adjtimex_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>38 ······</ocil:actions>
39 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-package_chrony_installed_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-prefer_64bit_os_ocil:questionnaire:1">
41 ······<ocil:title>The·Chrony·package·is·installed</ocil:title>41 ······<ocil:title>Prefer·to·use·a·64-bit·Operating·System·when·supported</ocil:title>
42 ······<ocil:actions>42 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-package_chrony_installed_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-prefer_64bit_os_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>44 ······</ocil:actions>
45 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-rsyslog_files_permissions_ocil:questionnaire:1">46 ····<ocil:questionnaire·id="ocil:ssg-auditd_overflow_action_ocil:questionnaire:1">
47 ······<ocil:title>Ensure·System·Log·Files·Have·Correct·Permissions</ocil:title>47 ······<ocil:title>Appropriate·Action·Must·be·Setup·When·the·Internal·Audit·Event·Queue·is·Full</ocil:title>
48 ······<ocil:actions>48 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-rsyslog_files_permissions_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-auditd_overflow_action_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>50 ······</ocil:actions>
51 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-sshd_enable_warning_banner_ocil:questionnaire:1"> 
53 ······<ocil:title>Enable·SSH·Warning·Banner</ocil:title>52 ····<ocil:questionnaire·id="ocil:ssg-audit_privileged_commands_reboot_ocil:questionnaire:1">
 53 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·reboot</ocil:title>
54 ······<ocil:actions>54 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-sshd_enable_warning_banner_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-audit_privileged_commands_reboot_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>56 ······</ocil:actions>
57 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_user_known_hosts_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_umount_ocil:questionnaire:1">
59 ······<ocil:title>Disable·SSH·Support·for·User·Known·Hosts</ocil:title>59 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·umount</ocil:title>
60 ······<ocil:actions>60 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_user_known_hosts_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_umount_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>62 ······</ocil:actions>
63 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-sshd_enable_pam_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_time_stime_ocil:questionnaire:1">
65 ······<ocil:title>Enable·PAM</ocil:title>65 ······<ocil:title>Record·Attempts·to·Alter·Time·Through·stime</ocil:title>
66 ······<ocil:actions>66 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-sshd_enable_pam_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-audit_rules_time_stime_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>68 ······</ocil:actions>
69 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-sysctl_fs_suid_dumpable_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-auditd_freq_ocil:questionnaire:1">
71 ······<ocil:title>Disable·Core·Dumps·for·SUID·programs</ocil:title>71 ······<ocil:title>Set·number·of·records·to·cause·an·explicit·flush·to·audit·logs</ocil:title>
72 ······<ocil:actions>72 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-sysctl_fs_suid_dumpable_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-auditd_freq_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>74 ······</ocil:actions>
75 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-sysctl_kernel_randomize_va_space_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_devkmem_ocil:questionnaire:1">
77 ······<ocil:title>Enable·Randomized·Layout·of·Virtual·Address·Space</ocil:title>77 ······<ocil:title>Disable·/dev/kmem·virtual·device·support</ocil:title>
78 ······<ocil:actions>78 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-sysctl_kernel_randomize_va_space_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-kernel_config_devkmem_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>80 ······</ocil:actions>
81 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-file_ownership_sshd_pub_key_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-package_postfix_installed_ocil:questionnaire:1">
83 ······<ocil:title>Verify·Ownership·on·SSH·Server·Public·*.pub·Key·Files</ocil:title>83 ······<ocil:title>The·Postfix·package·is·installed</ocil:title>
84 ······<ocil:actions>84 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-file_ownership_sshd_pub_key_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-package_postfix_installed_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>86 ······</ocil:actions>
87 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_module_sig_key_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-auditd_log_format_ocil:questionnaire:1">
89 ······<ocil:title>Specify·module·signing·key·to·use</ocil:title>89 ······<ocil:title>Resolve·information·before·writing·to·audit·logs</ocil:title>
90 ······<ocil:actions>90 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-kernel_config_module_sig_key_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-auditd_log_format_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>92 ······</ocil:actions>
93 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-package_openssh-server_installed_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-service_syslogng_enabled_ocil:questionnaire:1">
95 ······<ocil:title>Install·the·OpenSSH·Server·Package</ocil:title>95 ······<ocil:title>Enable·syslog-ng·Service</ocil:title>
96 ······<ocil:actions>96 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-package_openssh-server_installed_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-service_syslogng_enabled_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>98 ······</ocil:actions>
99 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_empty_passwords_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-package_openssh-server_removed_ocil:questionnaire:1">
101 ······<ocil:title>Disable·SSH·Access·via·Empty·Passwords</ocil:title>101 ······<ocil:title>Remove·the·OpenSSH·Server·Package</ocil:title>
102 ······<ocil:actions>102 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_empty_passwords_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-package_openssh-server_removed_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>104 ······</ocil:actions>
105 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_shadow_ocil:questionnaire:1">106 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_shadow_ocil:questionnaire:1">
107 ······<ocil:title>Verify·Group·Who·Owns·shadow·File</ocil:title>107 ······<ocil:title>Verify·Group·Who·Owns·shadow·File</ocil:title>
108 ······<ocil:actions>108 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_shadow_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_shadow_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>110 ······</ocil:actions>
111 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-dir_ownership_binary_dirs_ocil:questionnaire:1"> 
113 ······<ocil:title>Verify·that·System·Executable·Have·Root·Ownership</ocil:title>112 ····<ocil:questionnaire·id="ocil:ssg-partition_for_var_log_audit_ocil:questionnaire:1">
 113 ······<ocil:title>Ensure·/var/log/audit·Located·On·Separate·Partition</ocil:title>
114 ······<ocil:actions>114 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-dir_ownership_binary_dirs_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-partition_for_var_log_audit_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>116 ······</ocil:actions>
117 ····</ocil:questionnaire>117 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_ocil:questionnaire:1"> 
119 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands</ocil:title>118 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_var_log_messages_ocil:questionnaire:1">
 119 ······<ocil:title>Verify·Permissions·on·/var/log/messages·File</ocil:title>
120 ······<ocil:actions>120 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_action:testaction:1</ocil:test_action_ref>121 ········<ocil:test_action_ref>ocil:ssg-file_permissions_var_log_messages_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>122 ······</ocil:actions>
123 ····</ocil:questionnaire>123 ····</ocil:questionnaire>
124 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_default_disable_ipv6_ocil:questionnaire:1">124 ····<ocil:questionnaire·id="ocil:ssg-partition_for_var_log_ocil:questionnaire:1">
125 ······<ocil:title>Disable·IPv6·Addressing·on·IPv6·Interfaces·by·Default</ocil:title>125 ······<ocil:title>Ensure·/var/log·Located·On·Separate·Partition</ocil:title>
Max diff block lines reached; 700185/712458 bytes (98.28%) of diff not shown.
20.6 KB
./usr/share/xml/scap/ssg/content/ssg-debian11-xccdf.xml
20.5 KB
./usr/share/xml/scap/ssg/content/ssg-debian11-xccdf.xml
Ordering differences only
    
Offset 72, 181 lines modifiedOffset 72, 181 lines modified
72 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>72 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
73 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>73 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
74 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>74 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
75 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>75 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
77 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>77 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
78 ··<cpe-lang:platform-specification>78 ··<cpe-lang:platform-specification>
79 ····<cpe-lang:platform·id="machine">79 ····<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">
80 ······<cpe-lang:logical-test·operator="AND"·negate="false">80 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 81 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 82 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
 83 ········</cpe-lang:logical-test>
 84 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 85 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
 86 ········</cpe-lang:logical-test>
81 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>87 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
82 ······</cpe-lang:logical-test>88 ······</cpe-lang:logical-test>
83 ····</cpe-lang:platform>89 ····</cpe-lang:platform>
84 ····<cpe-lang:platform·id="package_pam">90 ····<cpe-lang:platform·id="package_gdm">
85 ······<cpe-lang:logical-test·operator="AND"·negate="false">91 ······<cpe-lang:logical-test·operator="AND"·negate="false">
86 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>92 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-package_gdm:def:1"/>
87 ······</cpe-lang:logical-test>93 ······</cpe-lang:logical-test>
88 ····</cpe-lang:platform>94 ····</cpe-lang:platform>
89 ····<cpe-lang:platform·id="package_iptables">95 ····<cpe-lang:platform·id="package_rsyslog">
90 ······<cpe-lang:logical-test·operator="AND"·negate="false">96 ······<cpe-lang:logical-test·operator="AND"·negate="false">
91 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>97 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>
92 ······</cpe-lang:logical-test>98 ······</cpe-lang:logical-test>
93 ····</cpe-lang:platform>99 ····</cpe-lang:platform>
94 ····<cpe-lang:platform·id="package_rsyslog">100 ····<cpe-lang:platform·id="package_logrotate">
95 ······<cpe-lang:logical-test·operator="AND"·negate="false">101 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 102 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-package_logrotate:def:1"/>
 103 ······</cpe-lang:logical-test>
 104 ····</cpe-lang:platform>
 105 ····<cpe-lang:platform·id="package_chrony">
 106 ······<cpe-lang:logical-test·operator="AND"·negate="false">
96 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>107 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
 108 ······</cpe-lang:logical-test>
 109 ····</cpe-lang:platform>
 110 ····<cpe-lang:platform·id="package_ufw_and_system_with_kernel">
 111 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 112 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
 113 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
 114 ······</cpe-lang:logical-test>
 115 ····</cpe-lang:platform>
 116 ····<cpe-lang:platform·id="package_rsh-server">
 117 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 118 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-package_rsh-server:def:1"/>
97 ······</cpe-lang:logical-test>119 ······</cpe-lang:logical-test>
98 ····</cpe-lang:platform>120 ····</cpe-lang:platform>
99 ····<cpe-lang:platform·id="package_systemd">121 ····<cpe-lang:platform·id="package_systemd">
100 ······<cpe-lang:logical-test·operator="AND"·negate="false">122 ······<cpe-lang:logical-test·operator="AND"·negate="false">
101 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>123 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>
102 ······</cpe-lang:logical-test>124 ······</cpe-lang:logical-test>
103 ····</cpe-lang:platform>125 ····</cpe-lang:platform>
104 ····<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">126 ····<cpe-lang:platform·id="not_bootc_and_not_container">
105 ······<cpe-lang:logical-test·operator="AND"·negate="false">127 ······<cpe-lang:logical-test·operator="AND"·negate="false">
106 ········<cpe-lang:logical-test·operator="AND"·negate="true">128 ········<cpe-lang:logical-test·operator="AND"·negate="true">
107 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>129 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-bootc:def:1"/>
108 ········</cpe-lang:logical-test>130 ········</cpe-lang:logical-test>
109 ········<cpe-lang:logical-test·operator="AND"·negate="true">131 ········<cpe-lang:logical-test·operator="AND"·negate="true">
110 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>132 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_container:def:1"/>
111 ········</cpe-lang:logical-test>133 ········</cpe-lang:logical-test>
112 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/> 
113 ······</cpe-lang:logical-test>134 ······</cpe-lang:logical-test>
114 ····</cpe-lang:platform>135 ····</cpe-lang:platform>
 136 ····<cpe-lang:platform·id="package_iptables_and_service_disabled_firewalld_and_system_with_kernel">
115 ····<cpe-lang:platform·id="package_postfix"> 
116 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
117 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-package_postfix:def:1"/> 
118 ······</cpe-lang:logical-test> 
119 ····</cpe-lang:platform> 
120 ····<cpe-lang:platform·id="package_audit"> 
121 ······<cpe-lang:logical-test·operator="AND"·negate="false">137 ······<cpe-lang:logical-test·operator="AND"·negate="false">
122 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-package_audit:def:1"/>138 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
 139 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_firewalld:def:1"/>
 140 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
123 ······</cpe-lang:logical-test>141 ······</cpe-lang:logical-test>
124 ····</cpe-lang:platform>142 ····</cpe-lang:platform>
125 ····<cpe-lang:platform·id="package_snmpd_and_system_with_kernel">143 ····<cpe-lang:platform·id="aarch64_arch_or_x86_64_arch">
126 ······<cpe-lang:logical-test·operator="AND"·negate="false">144 ······<cpe-lang:logical-test·operator="OR"·negate="false">
127 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-package_snmpd:def:1"/>145 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
128 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>146 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/>
129 ······</cpe-lang:logical-test>147 ······</cpe-lang:logical-test>
130 ····</cpe-lang:platform>148 ····</cpe-lang:platform>
131 ····<cpe-lang:platform·id="package_logrotate">149 ····<cpe-lang:platform·id="package_pam">
132 ······<cpe-lang:logical-test·operator="AND"·negate="false">150 ······<cpe-lang:logical-test·operator="AND"·negate="false">
133 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-package_logrotate:def:1"/>151 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>
134 ······</cpe-lang:logical-test>152 ······</cpe-lang:logical-test>
135 ····</cpe-lang:platform>153 ····</cpe-lang:platform>
136 ····<cpe-lang:platform·id="package_ntp">154 ····<cpe-lang:platform·id="machine">
137 ······<cpe-lang:logical-test·operator="AND"·negate="false">155 ······<cpe-lang:logical-test·operator="AND"·negate="false">
138 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-package_ntp:def:1"/>156 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
139 ······</cpe-lang:logical-test>157 ······</cpe-lang:logical-test>
140 ····</cpe-lang:platform>158 ····</cpe-lang:platform>
141 ····<cpe-lang:platform·id="package_sudo">159 ····<cpe-lang:platform·id="package_sudo">
142 ······<cpe-lang:logical-test·operator="AND"·negate="false">160 ······<cpe-lang:logical-test·operator="AND"·negate="false">
143 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-package_sudo:def:1"/>161 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-package_sudo:def:1"/>
144 ······</cpe-lang:logical-test>162 ······</cpe-lang:logical-test>
145 ····</cpe-lang:platform>163 ····</cpe-lang:platform>
 164 ····<cpe-lang:platform·id="system_with_kernel">
146 ····<cpe-lang:platform·id="aarch64_arch_or_x86_64_arch"> 
147 ······<cpe-lang:logical-test·operator="OR"·negate="false"> 
148 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/> 
149 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/> 
150 ······</cpe-lang:logical-test> 
151 ····</cpe-lang:platform> 
152 ····<cpe-lang:platform·id="x86_64_arch"> 
153 ······<cpe-lang:logical-test·operator="AND"·negate="false">165 ······<cpe-lang:logical-test·operator="AND"·negate="false">
154 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/>166 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
155 ······</cpe-lang:logical-test>167 ······</cpe-lang:logical-test>
156 ····</cpe-lang:platform>168 ····</cpe-lang:platform>
157 ····<cpe-lang:platform·id="not_aarch64_arch_and_not_s390x_arch">169 ····<cpe-lang:platform·id="not_aarch64_arch_and_not_s390x_arch">
158 ······<cpe-lang:logical-test·operator="AND"·negate="false">170 ······<cpe-lang:logical-test·operator="AND"·negate="false">
159 ········<cpe-lang:logical-test·operator="AND"·negate="true">171 ········<cpe-lang:logical-test·operator="AND"·negate="true">
160 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>172 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
161 ········</cpe-lang:logical-test>173 ········</cpe-lang:logical-test>
162 ········<cpe-lang:logical-test·operator="AND"·negate="true">174 ········<cpe-lang:logical-test·operator="AND"·negate="true">
163 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_s390x:def:1"/>175 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_s390x:def:1"/>
164 ········</cpe-lang:logical-test>176 ········</cpe-lang:logical-test>
165 ······</cpe-lang:logical-test>177 ······</cpe-lang:logical-test>
166 ····</cpe-lang:platform>178 ····</cpe-lang:platform>
 179 ····<cpe-lang:platform·id="package_ntp">
 180 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 181 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-package_ntp:def:1"/>
 182 ······</cpe-lang:logical-test>
 183 ····</cpe-lang:platform>
 184 ····<cpe-lang:platform·id="package_postfix">
Max diff block lines reached; 8028/20807 bytes (38.58%) of diff not shown.
1.22 MB
./usr/share/xml/scap/ssg/content/ssg-debian12-ds.xml
1.22 MB
./usr/share/xml/scap/ssg/content/ssg-debian12-ds.xml
    
Offset 21, 23 lines modifiedOffset 21, 23 lines modified
21 ····<ds:checks>21 ····<ds:checks>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-debian12-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-debian12-oval.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-debian12-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-debian12-oval.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-debian12-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-debian12-ocil.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-debian12-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-debian12-ocil.xml"/>
24 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-debian12-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-debian12-cpe-oval.xml"/>24 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-debian12-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-debian12-cpe-oval.xml"/>
25 ······<ds:component-ref·id="scap_org.open-scap_cref_security-oval-oval-definitions-bookworm.xml.bz2"·xlink:href="https://www.debian.org/security/oval/oval-definitions-bookworm.xml.bz2"/>25 ······<ds:component-ref·id="scap_org.open-scap_cref_security-oval-oval-definitions-bookworm.xml.bz2"·xlink:href="https://www.debian.org/security/oval/oval-definitions-bookworm.xml.bz2"/>
26 ····</ds:checks>26 ····</ds:checks>
27 ··</ds:data-stream>27 ··</ds:data-stream>
28 ··<ds:component·id="scap_org.open-scap_comp_ssg-debian12-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">28 ··<ds:component·id="scap_org.open-scap_comp_ssg-debian12-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
29 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">29 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
30 ······<cpe-dict:cpe-item·name="cpe:/o:debian:debian_linux:12">30 ······<cpe-dict:cpe-item·name="cpe:/o:debian:debian_linux:12">
31 ········<cpe-dict:title·xml:lang="en-us">Debian·Linux·12</cpe-dict:title>31 ········<cpe-dict:title·xml:lang="en-us">Debian·Linux·12</cpe-dict:title>
32 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml">oval:ssg-installed_OS_is_debian12:def:1</cpe-dict:check>32 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml">oval:ssg-installed_OS_is_debian12:def:1</cpe-dict:check>
33 ······</cpe-dict:cpe-item>33 ······</cpe-dict:cpe-item>
34 ····</cpe-dict:cpe-list>34 ····</cpe-dict:cpe-list>
35 ··</ds:component>35 ··</ds:component>
36 ··<ds:component·id="scap_org.open-scap_comp_ssg-debian12-xccdf.xml"·timestamp="2025-02-28T20:08:00">36 ··<ds:component·id="scap_org.open-scap_comp_ssg-debian12-xccdf.xml"·timestamp="2025-03-01T22:08:00">
37 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_DEBIAN-12"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">37 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_DEBIAN-12"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
38 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>38 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
39 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Debian·12</xccdf-1.2:title>39 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Debian·12</xccdf-1.2:title>
40 ······<xccdf-1.2:description>40 ······<xccdf-1.2:description>
41 ········This·guide·presents·a·catalog·of·security-relevant41 ········This·guide·presents·a·catalog·of·security-relevant
42 configuration·settings·for·Debian·12.·It·is·a·rendering·of42 configuration·settings·for·Debian·12.·It·is·a·rendering·of
43 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)43 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 106, 282 lines modifiedOffset 106, 282 lines modified
106 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>106 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
107 ······<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>107 ······<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
108 ······<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>108 ······<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
109 ······<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>109 ······<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
110 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>110 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
111 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>111 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
112 ······<cpe-lang:platform-specification>112 ······<cpe-lang:platform-specification>
113 ········<cpe-lang:platform·id="package_aide_and_package_systemd">113 ········<cpe-lang:platform·id="mount_var-tmp">
114 ··········<cpe-lang:logical-test·operator="AND"·negate="false">114 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
115 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-package_aide:def:1"/> 
116 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/> 
117 ··········</cpe-lang:logical-test> 
118 ········</cpe-lang:platform> 
119 ········<cpe-lang:platform·id="not_bootc"> 
120 ··········<cpe-lang:logical-test·operator="AND"·negate="true"> 
121 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-bootc:def:1"/>115 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-tmp:def:1"/>
122 ··········</cpe-lang:logical-test>116 ··········</cpe-lang:logical-test>
123 ········</cpe-lang:platform>117 ········</cpe-lang:platform>
124 ········<cpe-lang:platform·id="machine">118 ········<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">
125 ··········<cpe-lang:logical-test·operator="AND"·negate="false">119 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 120 ············<cpe-lang:logical-test·operator="AND"·negate="true">
 121 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
 122 ············</cpe-lang:logical-test>
 123 ············<cpe-lang:logical-test·operator="AND"·negate="true">
 124 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
 125 ············</cpe-lang:logical-test>
126 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>126 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
127 ··········</cpe-lang:logical-test>127 ··········</cpe-lang:logical-test>
128 ········</cpe-lang:platform>128 ········</cpe-lang:platform>
129 ········<cpe-lang:platform·id="package_pam">129 ········<cpe-lang:platform·id="ipv6_enabled">
130 ··········<cpe-lang:logical-test·operator="AND"·negate="false">130 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
131 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>131 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-ipv6_enabled:def:1"/>
132 ··········</cpe-lang:logical-test>132 ··········</cpe-lang:logical-test>
133 ········</cpe-lang:platform>133 ········</cpe-lang:platform>
134 ········<cpe-lang:platform·id="mount_tmp">134 ········<cpe-lang:platform·id="package_gdm">
135 ··········<cpe-lang:logical-test·operator="AND"·negate="false">135 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
136 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_tmp:def:1"/>136 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-package_gdm:def:1"/>
137 ··········</cpe-lang:logical-test>137 ··········</cpe-lang:logical-test>
138 ········</cpe-lang:platform>138 ········</cpe-lang:platform>
139 ········<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">139 ········<cpe-lang:platform·id="package_rsyslog">
140 ··········<cpe-lang:logical-test·operator="AND"·negate="false">140 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
141 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>141 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>
142 ··········</cpe-lang:logical-test>142 ··········</cpe-lang:logical-test>
143 ········</cpe-lang:platform>143 ········</cpe-lang:platform>
144 ········<cpe-lang:platform·id="mount_var-log">144 ········<cpe-lang:platform·id="package_bash">
145 ··········<cpe-lang:logical-test·operator="AND"·negate="false">145 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
146 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-log:def:1"/>146 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>
147 ··········</cpe-lang:logical-test>147 ··········</cpe-lang:logical-test>
148 ········</cpe-lang:platform>148 ········</cpe-lang:platform>
149 ········<cpe-lang:platform·id="uefi">149 ········<cpe-lang:platform·id="uefi">
150 ··········<cpe-lang:logical-test·operator="AND"·negate="false">150 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
151 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>151 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>
152 ··········</cpe-lang:logical-test>152 ··········</cpe-lang:logical-test>
153 ········</cpe-lang:platform>153 ········</cpe-lang:platform>
154 ········<cpe-lang:platform·id="package_bash"> 
155 ··········<cpe-lang:logical-test·operator="AND"·negate="false"> 
156 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/> 
157 ··········</cpe-lang:logical-test> 
158 ········</cpe-lang:platform> 
159 ········<cpe-lang:platform·id="package_iptables">154 ········<cpe-lang:platform·id="package_logrotate">
160 ··········<cpe-lang:logical-test·operator="AND"·negate="false">155 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
161 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>156 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-package_logrotate:def:1"/>
162 ··········</cpe-lang:logical-test>157 ··········</cpe-lang:logical-test>
163 ········</cpe-lang:platform>158 ········</cpe-lang:platform>
164 ········<cpe-lang:platform·id="grub2">159 ········<cpe-lang:platform·id="package_chrony">
165 ··········<cpe-lang:logical-test·operator="AND"·negate="false">160 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
166 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>161 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
167 ··········</cpe-lang:logical-test>162 ··········</cpe-lang:logical-test>
168 ········</cpe-lang:platform>163 ········</cpe-lang:platform>
169 ········<cpe-lang:platform·id="package_rsyslog">164 ········<cpe-lang:platform·id="package_ufw_and_system_with_kernel">
170 ··········<cpe-lang:logical-test·operator="AND"·negate="false">165 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
171 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>166 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
 167 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
172 ··········</cpe-lang:logical-test>168 ··········</cpe-lang:logical-test>
173 ········</cpe-lang:platform>169 ········</cpe-lang:platform>
174 ········<cpe-lang:platform·id="package_systemd">170 ········<cpe-lang:platform·id="package_rsh-server">
175 ··········<cpe-lang:logical-test·operator="AND"·negate="false">171 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
176 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>172 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-package_rsh-server:def:1"/>
177 ··········</cpe-lang:logical-test>173 ··········</cpe-lang:logical-test>
178 ········</cpe-lang:platform>174 ········</cpe-lang:platform>
179 ········<cpe-lang:platform·id="mount_var">175 ········<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">
180 ··········<cpe-lang:logical-test·operator="AND"·negate="false">176 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
181 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var:def:1"/>177 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>
182 ··········</cpe-lang:logical-test>178 ··········</cpe-lang:logical-test>
183 ········</cpe-lang:platform>179 ········</cpe-lang:platform>
184 ········<cpe-lang:platform·id="machine_and_package_apparmor">180 ········<cpe-lang:platform·id="mount_srv">
185 ··········<cpe-lang:logical-test·operator="AND"·negate="false">181 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
186 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>182 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_srv:def:1"/>
187 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-package_apparmor:def:1"/> 
188 ··········</cpe-lang:logical-test>183 ··········</cpe-lang:logical-test>
189 ········</cpe-lang:platform>184 ········</cpe-lang:platform>
190 ········<cpe-lang:platform·id="package_libreswan">185 ········<cpe-lang:platform·id="package_systemd">
191 ··········<cpe-lang:logical-test·operator="AND"·negate="false">186 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
192 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-package_libreswan:def:1"/>187 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>
193 ··········</cpe-lang:logical-test>188 ··········</cpe-lang:logical-test>
194 ········</cpe-lang:platform>189 ········</cpe-lang:platform>
195 ········<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">190 ········<cpe-lang:platform·id="not_bootc_and_not_container">
196 ··········<cpe-lang:logical-test·operator="AND"·negate="false">191 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
197 ············<cpe-lang:logical-test·operator="AND"·negate="true">192 ············<cpe-lang:logical-test·operator="AND"·negate="true">
198 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>193 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-bootc:def:1"/>
199 ············</cpe-lang:logical-test>194 ············</cpe-lang:logical-test>
200 ············<cpe-lang:logical-test·operator="AND"·negate="true">195 ············<cpe-lang:logical-test·operator="AND"·negate="true">
201 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>196 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_container:def:1"/>
Max diff block lines reached; 1270116/1284119 bytes (98.91%) of diff not shown.
1.14 MB
./usr/share/xml/scap/ssg/content/ssg-debian12-ocil.xml
1.14 MB
./usr/share/xml/scap/ssg/content/ssg-debian12-ocil.xml
Ordering differences only
    
Offset 3, 8499 lines modifiedOffset 3, 8534 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_page_table_isolation_ocil:questionnaire:1"> 
11 ······<ocil:title>Remove·the·kernel·mapping·in·user·mode</ocil:title>10 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_all_accept_ra_defrtr_ocil:questionnaire:1">
 11 ······<ocil:title>Configure·Accepting·Default·Router·in·Router·Advertisements·on·All·IPv6·Interfaces</ocil:title>
12 ······<ocil:actions>12 ······<ocil:actions>
13 ········<ocil:test_action_ref>ocil:ssg-kernel_config_page_table_isolation_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_all_accept_ra_defrtr_action:testaction:1</ocil:test_action_ref>
14 ······</ocil:actions>14 ······</ocil:actions>
15 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
16 ····<ocil:questionnaire·id="ocil:ssg-sshd_enable_x11_forwarding_ocil:questionnaire:1"> 
17 ······<ocil:title>Enable·Encrypted·X11·Forwarding</ocil:title>16 ····<ocil:questionnaire·id="ocil:ssg-dir_system_commands_group_root_owned_ocil:questionnaire:1">
 17 ······<ocil:title>Verify·that·system·commands·directories·have·root·as·a·group·owner</ocil:title>
18 ······<ocil:actions>18 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-sshd_enable_x11_forwarding_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-dir_system_commands_group_root_owned_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>20 ······</ocil:actions>
21 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-file_owner_etc_shadow_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-file_owner_etc_sestatus_conf_ocil:questionnaire:1">
23 ······<ocil:title>Verify·User·Who·Owns·shadow·File</ocil:title>23 ······<ocil:title>Verify·User·Who·Owns·/etc/sestatus.conf·File</ocil:title>
24 ······<ocil:actions>24 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-file_owner_etc_shadow_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-file_owner_etc_sestatus_conf_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>26 ······</ocil:actions>
27 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_var_log_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-logind_session_timeout_ocil:questionnaire:1">
29 ······<ocil:title>Verify·Permissions·on·/var/log·Directory</ocil:title>29 ······<ocil:title>Configure·Logind·to·terminate·idle·sessions·after·certain·time·of·inactivity</ocil:title>
30 ······<ocil:actions>30 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-file_permissions_var_log_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-logind_session_timeout_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>32 ······</ocil:actions>
33 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_icmp_ignore_bogus_error_responses_ocil:questionnaire:1"> 
35 ······<ocil:title>Enable·Kernel·Parameter·to·Ignore·Bogus·ICMP·Error·Responses·on·IPv4·Interfaces</ocil:title>34 ····<ocil:questionnaire·id="ocil:ssg-package_ypbind_removed_ocil:questionnaire:1">
 35 ······<ocil:title>Remove·NIS·Client</ocil:title>
36 ······<ocil:actions>36 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_icmp_ignore_bogus_error_responses_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-package_ypbind_removed_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>38 ······</ocil:actions>
39 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_ftruncate_ocil:questionnaire:1"> 
41 ······<ocil:title>Record·Unsuccessful·Access·Attempts·to·Files·-·ftruncate</ocil:title>40 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_panic_timeout_ocil:questionnaire:1">
 41 ······<ocil:title>Kernel·panic·timeout</ocil:title>
42 ······<ocil:actions>42 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_ftruncate_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-kernel_config_panic_timeout_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>44 ······</ocil:actions>
45 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-sysctl_kernel_pid_max_ocil:questionnaire:1"> 
47 ······<ocil:title>Configure·maximum·number·of·process·identifiers</ocil:title>46 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_disk_full_action_stig_ocil:questionnaire:1">
 47 ······<ocil:title>Configure·auditd·Disk·Full·Action·when·Disk·Space·Is·Full</ocil:title>
48 ······<ocil:actions>48 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-sysctl_kernel_pid_max_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-auditd_data_disk_full_action_stig_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>50 ······</ocil:actions>
51 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-sysctl_fs_protected_hardlinks_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-audit_privileged_commands_reboot_ocil:questionnaire:1">
53 ······<ocil:title>Enable·Kernel·Parameter·to·Enforce·DAC·on·Hardlinks</ocil:title>53 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·reboot</ocil:title>
54 ······<ocil:actions>54 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-sysctl_fs_protected_hardlinks_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-audit_privileged_commands_reboot_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>56 ······</ocil:actions>
57 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-postfix_client_configure_mail_alias_postmaster_ocil:questionnaire:1"> 
59 ······<ocil:title>Configure·System·to·Forward·All·Mail·From·Postmaster·to·The·Root·Account</ocil:title>58 ····<ocil:questionnaire·id="ocil:ssg-mount_option_nodev_nonroot_local_partitions_ocil:questionnaire:1">
 59 ······<ocil:title>Add·nodev·Option·to·Non-Root·Local·Partitions</ocil:title>
60 ······<ocil:actions>60 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-postfix_client_configure_mail_alias_postmaster_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-mount_option_nodev_nonroot_local_partitions_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>62 ······</ocil:actions>
63 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_space_left_action_ocil:questionnaire:1"> 
65 ······<ocil:title>Configure·auditd·space_left·Action·on·Low·Disk·Space</ocil:title>64 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_retpoline_ocil:questionnaire:1">
 65 ······<ocil:title>Avoid·speculative·indirect·branches·in·kernel</ocil:title>
66 ······<ocil:actions>66 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-auditd_data_retention_space_left_action_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-kernel_config_retpoline_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>68 ······</ocil:actions>
69 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_removexattr_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-dir_permissions_binary_dirs_ocil:questionnaire:1">
71 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·removexattr</ocil:title>71 ······<ocil:title>Verify·that·System·Executable·Directories·Have·Restrictive·Permissions</ocil:title>
72 ······<ocil:actions>72 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_removexattr_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-dir_permissions_binary_dirs_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>74 ······</ocil:actions>
75 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_grub2_cfg_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-aide_verify_acls_ocil:questionnaire:1">
77 ······<ocil:title>Verify·/boot/grub/grub.cfg·Permissions</ocil:title>77 ······<ocil:title>Configure·AIDE·to·Verify·Access·Control·Lists·(ACLs)</ocil:title>
78 ······<ocil:actions>78 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-file_permissions_grub2_cfg_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-aide_verify_acls_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>80 ······</ocil:actions>
81 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_shadow_ocil:questionnaire:1"> 
83 ······<ocil:title>Verify·Permissions·on·shadow·File</ocil:title>82 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_all_max_addresses_ocil:questionnaire:1">
 83 ······<ocil:title>Configure·Maximum·Number·of·Autoconfigured·Addresses·on·All·IPv6·Interfaces</ocil:title>
84 ······<ocil:actions>84 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-file_permissions_etc_shadow_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_all_max_addresses_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>86 ······</ocil:actions>
87 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_refcount_full_ocil:questionnaire:1"> 
89 ······<ocil:title>Perform·full·reference·count·validation</ocil:title>88 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_mac_modification_ocil:questionnaire:1">
 89 ······<ocil:title>Record·Events·that·Modify·the·System's·Mandatory·Access·Controls</ocil:title>
90 ······<ocil:actions>90 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-kernel_config_refcount_full_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-audit_rules_mac_modification_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>92 ······</ocil:actions>
93 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-file_owner_etc_chrony_keys_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-auditd_freq_ocil:questionnaire:1">
95 ······<ocil:title>Verify·User·Who·Owns·/etc/chrony.keys·File</ocil:title>95 ······<ocil:title>Set·number·of·records·to·cause·an·explicit·flush·to·audit·logs</ocil:title>
96 ······<ocil:actions>96 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-file_owner_etc_chrony_keys_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-auditd_freq_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>98 ······</ocil:actions>
99 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_gcc_plugin_stackleak_ocil:questionnaire:1"> 
101 ······<ocil:title>Poison·kernel·stack·before·returning·from·syscalls</ocil:title>100 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_removexattr_ocil:questionnaire:1">
 101 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·removexattr</ocil:title>
102 ······<ocil:actions>102 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-kernel_config_gcc_plugin_stackleak_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_removexattr_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>104 ······</ocil:actions>
105 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_accept_local_ocil:questionnaire:1"> 
107 ······<ocil:title>Disable·Accepting·Packets·Routed·Between·Local·Interfaces</ocil:title>106 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_file_deletion_events_rename_ocil:questionnaire:1">
 107 ······<ocil:title>Ensure·auditd·Collects·File·Deletion·Events·by·User·-·rename</ocil:title>
108 ······<ocil:actions>108 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_accept_local_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-audit_rules_file_deletion_events_rename_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>110 ······</ocil:actions>
111 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_unmap_kernel_at_el0_ocil:questionnaire:1"> 
113 ······<ocil:title>Unmap·kernel·when·running·in·userspace·(aka·KAISER)</ocil:title>112 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_sestatus_conf_ocil:questionnaire:1">
 113 ······<ocil:title>Verify·Group·Who·Owns·/etc/sestatus.conf·File</ocil:title>
114 ······<ocil:actions>114 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-kernel_config_unmap_kernel_at_el0_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_sestatus_conf_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>116 ······</ocil:actions>
117 ····</ocil:questionnaire>117 ····</ocil:questionnaire>
Max diff block lines reached; 1179200/1191880 bytes (98.94%) of diff not shown.
32.7 KB
./usr/share/xml/scap/ssg/content/ssg-debian12-xccdf.xml
32.6 KB
./usr/share/xml/scap/ssg/content/ssg-debian12-xccdf.xml
Ordering differences only
    
Offset 71, 282 lines modifiedOffset 71, 282 lines modified
71 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>71 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
72 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>72 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
73 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>73 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
74 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>74 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
75 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>75 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
77 ··<cpe-lang:platform-specification>77 ··<cpe-lang:platform-specification>
78 ····<cpe-lang:platform·id="package_aide_and_package_systemd">78 ····<cpe-lang:platform·id="mount_var-tmp">
79 ······<cpe-lang:logical-test·operator="AND"·negate="false">79 ······<cpe-lang:logical-test·operator="AND"·negate="false">
80 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-package_aide:def:1"/> 
81 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/> 
82 ······</cpe-lang:logical-test> 
83 ····</cpe-lang:platform> 
84 ····<cpe-lang:platform·id="not_bootc"> 
85 ······<cpe-lang:logical-test·operator="AND"·negate="true"> 
86 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-bootc:def:1"/>80 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-tmp:def:1"/>
87 ······</cpe-lang:logical-test>81 ······</cpe-lang:logical-test>
88 ····</cpe-lang:platform>82 ····</cpe-lang:platform>
89 ····<cpe-lang:platform·id="machine">83 ····<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">
90 ······<cpe-lang:logical-test·operator="AND"·negate="false">84 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 85 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 86 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
 87 ········</cpe-lang:logical-test>
 88 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 89 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
 90 ········</cpe-lang:logical-test>
91 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>91 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
92 ······</cpe-lang:logical-test>92 ······</cpe-lang:logical-test>
93 ····</cpe-lang:platform>93 ····</cpe-lang:platform>
94 ····<cpe-lang:platform·id="package_pam">94 ····<cpe-lang:platform·id="ipv6_enabled">
95 ······<cpe-lang:logical-test·operator="AND"·negate="false">95 ······<cpe-lang:logical-test·operator="AND"·negate="false">
96 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>96 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-ipv6_enabled:def:1"/>
97 ······</cpe-lang:logical-test>97 ······</cpe-lang:logical-test>
98 ····</cpe-lang:platform>98 ····</cpe-lang:platform>
99 ····<cpe-lang:platform·id="mount_tmp">99 ····<cpe-lang:platform·id="package_gdm">
100 ······<cpe-lang:logical-test·operator="AND"·negate="false">100 ······<cpe-lang:logical-test·operator="AND"·negate="false">
101 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_tmp:def:1"/>101 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-package_gdm:def:1"/>
102 ······</cpe-lang:logical-test>102 ······</cpe-lang:logical-test>
103 ····</cpe-lang:platform>103 ····</cpe-lang:platform>
104 ····<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">104 ····<cpe-lang:platform·id="package_rsyslog">
105 ······<cpe-lang:logical-test·operator="AND"·negate="false">105 ······<cpe-lang:logical-test·operator="AND"·negate="false">
106 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>106 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>
107 ······</cpe-lang:logical-test>107 ······</cpe-lang:logical-test>
108 ····</cpe-lang:platform>108 ····</cpe-lang:platform>
109 ····<cpe-lang:platform·id="mount_var-log">109 ····<cpe-lang:platform·id="package_bash">
110 ······<cpe-lang:logical-test·operator="AND"·negate="false">110 ······<cpe-lang:logical-test·operator="AND"·negate="false">
111 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-log:def:1"/>111 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>
112 ······</cpe-lang:logical-test>112 ······</cpe-lang:logical-test>
113 ····</cpe-lang:platform>113 ····</cpe-lang:platform>
114 ····<cpe-lang:platform·id="uefi">114 ····<cpe-lang:platform·id="uefi">
115 ······<cpe-lang:logical-test·operator="AND"·negate="false">115 ······<cpe-lang:logical-test·operator="AND"·negate="false">
116 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>116 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>
117 ······</cpe-lang:logical-test>117 ······</cpe-lang:logical-test>
118 ····</cpe-lang:platform>118 ····</cpe-lang:platform>
119 ····<cpe-lang:platform·id="package_bash"> 
120 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
121 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/> 
122 ······</cpe-lang:logical-test> 
123 ····</cpe-lang:platform> 
124 ····<cpe-lang:platform·id="package_iptables">119 ····<cpe-lang:platform·id="package_logrotate">
125 ······<cpe-lang:logical-test·operator="AND"·negate="false">120 ······<cpe-lang:logical-test·operator="AND"·negate="false">
126 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>121 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-package_logrotate:def:1"/>
127 ······</cpe-lang:logical-test>122 ······</cpe-lang:logical-test>
128 ····</cpe-lang:platform>123 ····</cpe-lang:platform>
129 ····<cpe-lang:platform·id="grub2">124 ····<cpe-lang:platform·id="package_chrony">
130 ······<cpe-lang:logical-test·operator="AND"·negate="false">125 ······<cpe-lang:logical-test·operator="AND"·negate="false">
131 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>126 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
132 ······</cpe-lang:logical-test>127 ······</cpe-lang:logical-test>
133 ····</cpe-lang:platform>128 ····</cpe-lang:platform>
134 ····<cpe-lang:platform·id="package_rsyslog">129 ····<cpe-lang:platform·id="package_ufw_and_system_with_kernel">
135 ······<cpe-lang:logical-test·operator="AND"·negate="false">130 ······<cpe-lang:logical-test·operator="AND"·negate="false">
136 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>131 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
 132 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
137 ······</cpe-lang:logical-test>133 ······</cpe-lang:logical-test>
138 ····</cpe-lang:platform>134 ····</cpe-lang:platform>
139 ····<cpe-lang:platform·id="package_systemd">135 ····<cpe-lang:platform·id="package_rsh-server">
140 ······<cpe-lang:logical-test·operator="AND"·negate="false">136 ······<cpe-lang:logical-test·operator="AND"·negate="false">
141 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>137 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-package_rsh-server:def:1"/>
142 ······</cpe-lang:logical-test>138 ······</cpe-lang:logical-test>
143 ····</cpe-lang:platform>139 ····</cpe-lang:platform>
144 ····<cpe-lang:platform·id="mount_var">140 ····<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">
145 ······<cpe-lang:logical-test·operator="AND"·negate="false">141 ······<cpe-lang:logical-test·operator="AND"·negate="false">
146 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var:def:1"/>142 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>
147 ······</cpe-lang:logical-test>143 ······</cpe-lang:logical-test>
148 ····</cpe-lang:platform>144 ····</cpe-lang:platform>
149 ····<cpe-lang:platform·id="machine_and_package_apparmor">145 ····<cpe-lang:platform·id="mount_srv">
150 ······<cpe-lang:logical-test·operator="AND"·negate="false">146 ······<cpe-lang:logical-test·operator="AND"·negate="false">
151 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>147 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_srv:def:1"/>
152 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-package_apparmor:def:1"/> 
153 ······</cpe-lang:logical-test>148 ······</cpe-lang:logical-test>
154 ····</cpe-lang:platform>149 ····</cpe-lang:platform>
155 ····<cpe-lang:platform·id="package_libreswan">150 ····<cpe-lang:platform·id="package_systemd">
156 ······<cpe-lang:logical-test·operator="AND"·negate="false">151 ······<cpe-lang:logical-test·operator="AND"·negate="false">
157 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-package_libreswan:def:1"/>152 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>
158 ······</cpe-lang:logical-test>153 ······</cpe-lang:logical-test>
159 ····</cpe-lang:platform>154 ····</cpe-lang:platform>
160 ····<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">155 ····<cpe-lang:platform·id="not_bootc_and_not_container">
161 ······<cpe-lang:logical-test·operator="AND"·negate="false">156 ······<cpe-lang:logical-test·operator="AND"·negate="false">
162 ········<cpe-lang:logical-test·operator="AND"·negate="true">157 ········<cpe-lang:logical-test·operator="AND"·negate="true">
163 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>158 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-bootc:def:1"/>
164 ········</cpe-lang:logical-test>159 ········</cpe-lang:logical-test>
165 ········<cpe-lang:logical-test·operator="AND"·negate="true">160 ········<cpe-lang:logical-test·operator="AND"·negate="true">
166 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>161 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_container:def:1"/>
167 ········</cpe-lang:logical-test>162 ········</cpe-lang:logical-test>
168 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/> 
169 ······</cpe-lang:logical-test>163 ······</cpe-lang:logical-test>
170 ····</cpe-lang:platform>164 ····</cpe-lang:platform>
171 ····<cpe-lang:platform·id="non-uefi">165 ····<cpe-lang:platform·id="mount_tmp">
172 ······<cpe-lang:logical-test·operator="AND"·negate="false">166 ······<cpe-lang:logical-test·operator="AND"·negate="false">
173 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_non_uefi:def:1"/>167 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_tmp:def:1"/>
174 ······</cpe-lang:logical-test>168 ······</cpe-lang:logical-test>
175 ····</cpe-lang:platform>169 ····</cpe-lang:platform>
176 ····<cpe-lang:platform·id="package_postfix">170 ····<cpe-lang:platform·id="package_iptables_and_service_disabled_firewalld_and_system_with_kernel">
177 ······<cpe-lang:logical-test·operator="AND"·negate="false">171 ······<cpe-lang:logical-test·operator="AND"·negate="false">
178 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-package_postfix:def:1"/>172 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
 173 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_firewalld:def:1"/>
 174 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
179 ······</cpe-lang:logical-test>175 ······</cpe-lang:logical-test>
180 ····</cpe-lang:platform>176 ····</cpe-lang:platform>
 177 ····<cpe-lang:platform·id="aarch64_arch_or_x86_64_arch">
 178 ······<cpe-lang:logical-test·operator="OR"·negate="false">
 179 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
 180 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/>
 181 ······</cpe-lang:logical-test>
 182 ····</cpe-lang:platform>
181 ····<cpe-lang:platform·id="package_audit">183 ····<cpe-lang:platform·id="package_nftables">
182 ······<cpe-lang:logical-test·operator="AND"·negate="false">184 ······<cpe-lang:logical-test·operator="AND"·negate="false">
Max diff block lines reached; 19195/33255 bytes (57.72%) of diff not shown.
298 MB
ssg-nondebian_0.1.76-1_all.deb
452 B
file list
    
Offset 1, 3 lines modifiedOffset 1, 3 lines modified
1 -rw-r--r--···0········0········0········4·2025-03-01·08:08:00.000000·debian-binary1 -rw-r--r--···0········0········0········4·2025-03-01·08:08:00.000000·debian-binary
2 -rw-r--r--···0········0········0····18184·2025-03-01·08:08:00.000000·control.tar.xz2 -rw-r--r--···0········0········0····18180·2025-03-01·08:08:00.000000·control.tar.xz
3 -rw-r--r--···0········0········0·37077844·2025-03-01·08:08:00.000000·data.tar.xz3 -rw-r--r--···0········0········0·37080936·2025-03-01·08:08:00.000000·data.tar.xz
98.0 B
control.tar.xz
70.0 B
control.tar
48.0 B
./md5sums
30.0 B
./md5sums
Files differ
298 MB
data.tar.xz
298 MB
data.tar
1.04 MB
./usr/share/doc/ssg-nondebian/ssg-al2023-guide-cis.html
    
Offset 15183, 141 lines modifiedOffset 15183, 141 lines modified
0003b4e0:·6172·6765·743d·2223·6964·6d31·3334·3022··arget="#idm1340"0003b4e0:·6172·6765·743d·2223·6964·6d31·3334·3022··arget="#idm1340"
0003b4f0:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro0003b4f0:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro
0003b500:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria0003b500:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria
0003b510:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false0003b510:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false
0003b520:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat0003b520:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat
0003b530:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre0003b530:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre
0003b540:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati0003b540:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati
 0003b550:·6f6e·204f·5342·7569·6c64·2042·6c75·6570··on·OSBuild·Bluep
 0003b560:·7269·6e74·2073·6e69·7070·6574·20e2·87b2··rint·snippet·...
 0003b570:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
 0003b580:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
 0003b590:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
 0003b5a0:·2269·646d·3133·3430·223e·3c70·7265·3e3c··"idm1340"><pre><
0003b550:·6f6e·2041·6e61·636f·6e64·6120·736e·6970··on·Anaconda·snip 
0003b560:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br>< 
0003b570:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel 
0003b580:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap 
0003b590:·7365·2220·6964·3d22·6964·6d31·3334·3022··se"·id="idm1340" 
0003b5a0:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t 
0003b5b0:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip 
0003b5c0:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere 
0003b5d0:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense 
0003b5e0:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl 
0003b5f0:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l 
0003b600:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr> 
0003b610:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:< 
0003b620:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td> 
0003b630:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb 
0003b640:·6f6f·743a·3c2f·7468·3e3c·7464·3e66·616c··oot:</th><td>fal 
0003b650:·7365·3c2f·7464·3e3c·2f74·723e·3c74·723e··se</td></tr><tr> 
0003b660:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t 
0003b670:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td 
0003b680:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p 
0003b690:·7265·3e3c·636f·6465·3e0a·7061·636b·6167··re><code>.packag0003b5b0:·636f·6465·3e0a·5b5b·7061·636b·6167·6573··code>.[[packages
0003b6a0:·6520·2d2d·6164·643d·6169·6465·0a3c·2f63··e·--add=aide.</c0003b5c0:·5d5d·0a6e·616d·6520·3d20·2261·6964·6522··]].name·=·"aide"
 0003b5d0:·0a76·6572·7369·6f6e·203d·2022·2a22·0a3c··.version·=·"*".<
0003b6b0:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div>0003b5e0:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di
0003b6c0:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt0003b5f0:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn·
0003b6d0:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data-0003b600:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat
0003b6e0:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse0003b610:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap
0003b6f0:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#0003b620:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
0003b700:·6964·6d31·3334·3122·2074·6162·696e·6465··idm1341"·tabinde0003b630:·2223·6964·6d31·3334·3122·2074·6162·696e··"#idm1341"·tabin
0003b710:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt0003b640:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
0003b720:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande0003b650:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
0003b730:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=0003b660:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
0003b740:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev0003b670:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
0003b750:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R0003b680:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
0003b760:·656d·6564·6961·7469·6f6e·204f·5342·7569··emediation·OSBui0003b690:·3e52·656d·6564·6961·7469·6f6e·2050·7570··>Remediation·Pup
 0003b6a0:·7065·7420·736e·6970·7065·7420·e287·b23c··pet·snippet·...<
 0003b6b0:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas
 0003b6c0:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps
0003b770:·6c64·2042·6c75·6570·7269·6e74·2073·6e69··ld·Blueprint·sni 
0003b780:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br> 
0003b790:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane 
0003b7a0:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla 
0003b7b0:·7073·6522·2069·643d·2269·646d·3133·3431··pse"·id="idm1341 
0003b7c0:·223e·3c70·7265·3e3c·636f·6465·3e0a·5b5b··"><pre><code>.[[ 
0003b7d0:·7061·636b·6167·6573·5d5d·0a6e·616d·6520··packages]].name· 
0003b7e0:·3d20·2261·6964·6522·0a76·6572·7369·6f6e··=·"aide".version 
0003b7f0:·203d·2022·2a22·0a3c·2f63·6f64·653e·3c2f···=·"*".</code></ 
0003b800:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla 
0003b810:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ 
0003b820:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle 
0003b830:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data0003b6d0:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="
 0003b6e0:·6964·6d31·3334·3122·3e3c·7461·626c·6520··idm1341"><table·
 0003b6f0:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab
 0003b700:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table
 0003b710:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-
 0003b720:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><
 0003b730:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</
 0003b740:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
 0003b750:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr
 0003b760:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>
 0003b770:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
 0003b780:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th
 0003b790:·3e3c·7464·3e66·616c·7365·3c2f·7464·3e3c··><td>false</td><
 0003b7a0:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra
 0003b7b0:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en
0003b840:·2d74·6172·6765·743d·2223·6964·6d31·3334··-target="#idm134 
0003b850:·3222·2074·6162·696e·6465·783d·2230·2220··2"·tabindex="0"· 
0003b860:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar 
0003b870:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal 
0003b880:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ 
0003b890:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h 
0003b8a0:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia 
0003b8b0:·7469·6f6e·2050·7570·7065·7420·736e·6970··tion·Puppet·snip 
0003b8c0:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br>< 
0003b8d0:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel 
0003b8e0:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap 
0003b8f0:·7365·2220·6964·3d22·6964·6d31·3334·3222··se"·id="idm1342" 
0003b900:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t 
0003b910:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip 
0003b920:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere 
0003b930:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense 
0003b940:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl 
0003b950:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l 
0003b960:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>0003b7c0:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></
0003b970:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:<0003b7d0:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code
 0003b7e0:·3e69·6e63·6c75·6465·2069·6e73·7461·6c6c··>include·install
 0003b7f0:·5f61·6964·650a·0a63·6c61·7373·2069·6e73··_aide..class·ins
 0003b800:·7461·6c6c·5f61·6964·6520·7b0a·2020·7061··tall_aide·{.··pa
 0003b810:·636b·6167·6520·7b20·2761·6964·6527·3a0a··ckage·{·'aide':.
 0003b820:·2020·2020·656e·7375·7265·203d·2667·743b······ensure·=&gt;
 0003b830:·2027·696e·7374·616c·6c65·6427·2c0a·2020···'installed',.··
 0003b840:·7d0a·7d0a·3c2f·636f·6465·3e3c·2f70·7265··}.}.</code></pre
 0003b850:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class=
 0003b860:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success
 0003b870:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c
 0003b880:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta
 0003b890:·7267·6574·3d22·2369·646d·3133·3432·2220··rget="#idm1342"·
 0003b8a0:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol
 0003b8b0:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-
 0003b8c0:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"
 0003b8d0:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate
 0003b8e0:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href
 0003b8f0:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio
 0003b900:·6e20·5368·656c·6c20·7363·7269·7074·20e2··n·Shell·script·.
 0003b910:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c
 0003b920:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
 0003b930:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
 0003b940:·643d·2269·646d·3133·3432·223e·3c74·6162··d="idm1342"><tab
 0003b950:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·
 0003b960:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta
 0003b970:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab
 0003b980:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t
 0003b990:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity
0003b980:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>0003b9a0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
Max diff block lines reached; 982934/1001040 bytes (98.19%) of diff not shown.
83.1 KB
html2text {}
    
Offset 159, 21 lines modifiedOffset 159, 14 lines modified
159 ··-·PCI-DSSv4-11.5.2159 ··-·PCI-DSSv4-11.5.2
160 ··-·enable_strategy160 ··-·enable_strategy
161 ··-·low_complexity161 ··-·low_complexity
162 ··-·low_disruption162 ··-·low_disruption
163 ··-·medium_severity163 ··-·medium_severity
164 ··-·no_reboot_needed164 ··-·no_reboot_needed
165 ··-·package_aide_installed165 ··-·package_aide_installed
166 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
167 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
168 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
169 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
170 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
171 package·--add=aide 
172 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8166 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
173 [[packages]]167 [[packages]]
174 name·=·"aide"168 name·=·"aide"
175 version·=·"*"169 version·=·"*"
176 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8170 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
177 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low171 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 198, 14 lines modifiedOffset 191, 21 lines modified
198 if·!·rpm·-q·--quiet·"aide"·;·then191 if·!·rpm·-q·--quiet·"aide"·;·then
199 ····dnf·install·-y·"aide"192 ····dnf·install·-y·"aide"
200 fi193 fi
  
201 else194 else
202 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'195 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
203 fi196 fi
 197 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 198 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 199 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 200 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 201 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 202 package·--add=aide
204 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*203 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
205 Run·the·following·command·to·generate·a·new·database:204 Run·the·following·command·to·generate·a·new·database:
206 $·sudo·/usr/sbin/aide·--init205 $·sudo·/usr/sbin/aide·--init
207 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,206 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,
208 the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a207 the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a
209 secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The208 secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The
210 newly-generated·database·can·be·installed·as·follows:209 newly-generated·database·can·be·installed·as·follows:
Offset 914, 21 lines modifiedOffset 914, 14 lines modified
914 ··-·PCI-DSSv4-2.2.6914 ··-·PCI-DSSv4-2.2.6
915 ··-·enable_strategy915 ··-·enable_strategy
916 ··-·low_complexity916 ··-·low_complexity
917 ··-·low_disruption917 ··-·low_disruption
918 ··-·medium_severity918 ··-·medium_severity
919 ··-·no_reboot_needed919 ··-·no_reboot_needed
920 ··-·package_sudo_installed920 ··-·package_sudo_installed
921 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
922 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
923 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
924 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
925 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
926 package·--add=sudo 
927 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8921 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
928 [[packages]]922 [[packages]]
929 name·=·"sudo"923 name·=·"sudo"
930 version·=·"*"924 version·=·"*"
931 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8925 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
932 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low926 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 953, 14 lines modifiedOffset 946, 21 lines modified
953 if·!·rpm·-q·--quiet·"sudo"·;·then946 if·!·rpm·-q·--quiet·"sudo"·;·then
954 ····dnf·install·-y·"sudo"947 ····dnf·install·-y·"sudo"
955 fi948 fi
  
956 else949 else
957 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'950 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
958 fi951 fi
 952 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 953 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 954 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 955 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 956 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 957 package·--add=sudo
959 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·O\x8On\x8nl\x8ly\x8y·U\x8Us\x8se\x8er\x8rs\x8s·L\x8Lo\x8og\x8gg\x8ge\x8ed\x8d·I\x8In\x8n·T\x8To\x8o·R\x8Re\x8ea\x8al\x8l·t\x8tt\x8ty\x8y·C\x8Ca\x8an\x8n·E\x8Ex\x8xe\x8ec\x8cu\x8ut\x8te\x8e·S\x8Su\x8ud\x8do\x8o·-\x8-·s\x8su\x8ud\x8do\x8o·u\x8us\x8se\x8e_\x8_p\x8pt\x8ty\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*958 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·O\x8On\x8nl\x8ly\x8y·U\x8Us\x8se\x8er\x8rs\x8s·L\x8Lo\x8og\x8gg\x8ge\x8ed\x8d·I\x8In\x8n·T\x8To\x8o·R\x8Re\x8ea\x8al\x8l·t\x8tt\x8ty\x8y·C\x8Ca\x8an\x8n·E\x8Ex\x8xe\x8ec\x8cu\x8ut\x8te\x8e·S\x8Su\x8ud\x8do\x8o·-\x8-·s\x8su\x8ud\x8do\x8o·u\x8us\x8se\x8e_\x8_p\x8pt\x8ty\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
960 The·sudo·use_pty·tag,·when·specified,·will·only·execute·sudo·commands·from·users·logged·in·to·a·real·tty.959 The·sudo·use_pty·tag,·when·specified,·will·only·execute·sudo·commands·from·users·logged·in·to·a·real·tty.
961 This·should·be·enabled·by·making·sure·that·the·use_pty·tag·exists·in·/etc/sudoers·configuration·file·or·any960 This·should·be·enabled·by·making·sure·that·the·use_pty·tag·exists·in·/etc/sudoers·configuration·file·or·any
962 sudo·configuration·snippets·in·/etc/sudoers.d/.961 sudo·configuration·snippets·in·/etc/sudoers.d/.
963 Rationale:··Requiring·that·sudo·commands·be·run·in·a·pseudo-terminal·can·prevent·an·attacker·from·retaining962 Rationale:··Requiring·that·sudo·commands·be·run·in·a·pseudo-terminal·can·prevent·an·attacker·from·retaining
964 ············access·to·the·user's·terminal·after·the·main·program·has·finished·executing.963 ············access·to·the·user's·terminal·after·the·main·program·has·finished·executing.
965 Severity: ··medium964 Severity: ··medium
Offset 13763, 21 lines modifiedOffset 13763, 14 lines modified
13763 ··-·NIST-800-53-CM-6(a)13763 ··-·NIST-800-53-CM-6(a)
13764 ··-·enable_strategy13764 ··-·enable_strategy
13765 ··-·low_complexity13765 ··-·low_complexity
13766 ··-·low_disruption13766 ··-·low_disruption
13767 ··-·medium_severity13767 ··-·medium_severity
13768 ··-·no_reboot_needed13768 ··-·no_reboot_needed
13769 ··-·package_rsyslog_installed13769 ··-·package_rsyslog_installed
13770 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
13771 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
13772 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
13773 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
13774 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
13775 package·--add=rsyslog 
13776 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x813770 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
13777 [[packages]]13771 [[packages]]
13778 name·=·"rsyslog"13772 name·=·"rsyslog"
13779 version·=·"*"13773 version·=·"*"
13780 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x813774 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
13781 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low13775 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 13802, 14 lines modifiedOffset 13795, 21 lines modified
13802 if·!·rpm·-q·--quiet·"rsyslog"·;·then13795 if·!·rpm·-q·--quiet·"rsyslog"·;·then
13803 ····dnf·install·-y·"rsyslog"13796 ····dnf·install·-y·"rsyslog"
13804 fi13797 fi
  
13805 else13798 else
13806 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'13799 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
13807 fi13800 fi
 13801 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 13802 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 13803 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 13804 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 13805 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 13806 package·--add=rsyslog
13808 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·r\x8rs\x8sy\x8ys\x8sl\x8lo\x8og\x8g·D\x8De\x8ef\x8fa\x8au\x8ul\x8lt\x8t·F\x8Fi\x8il\x8le\x8e·P\x8Pe\x8er\x8rm\x8mi\x8is\x8ss\x8si\x8io\x8on\x8ns\x8s·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8ed\x8d·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*13807 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·r\x8rs\x8sy\x8ys\x8sl\x8lo\x8og\x8g·D\x8De\x8ef\x8fa\x8au\x8ul\x8lt\x8t·F\x8Fi\x8il\x8le\x8e·P\x8Pe\x8er\x8rm\x8mi\x8is\x8ss\x8si\x8io\x8on\x8ns\x8s·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8ed\x8d·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
13809 rsyslog·will·create·logfiles·that·do·not·already·exist·on·the·system.·This·settings·controls·what13808 rsyslog·will·create·logfiles·that·do·not·already·exist·on·the·system.·This·settings·controls·what
13810 permissions·will·be·applied·to·these·newly·created·files.13809 permissions·will·be·applied·to·these·newly·created·files.
Max diff block lines reached; 79730/85050 bytes (93.74%) of diff not shown.
971 KB
./usr/share/doc/ssg-nondebian/ssg-al2023-guide-cis_server_l1.html
    
Offset 15149, 141 lines modifiedOffset 15149, 141 lines modified
0003b2c0:·7267·6574·3d22·2369·646d·3133·3430·2220··rget="#idm1340"·0003b2c0:·7267·6574·3d22·2369·646d·3133·3430·2220··rget="#idm1340"·
0003b2d0:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol0003b2d0:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol
0003b2e0:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-0003b2e0:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-
0003b2f0:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"0003b2f0:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"
0003b300:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate0003b300:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate
0003b310:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href0003b310:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href
0003b320:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio0003b320:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio
 0003b330:·6e20·4f53·4275·696c·6420·426c·7565·7072··n·OSBuild·Bluepr
 0003b340:·696e·7420·736e·6970·7065·7420·e287·b23c··int·snippet·...<
 0003b350:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas
 0003b360:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps
 0003b370:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="
 0003b380:·6964·6d31·3334·3022·3e3c·7072·653e·3c63··idm1340"><pre><c
0003b330:·6e20·416e·6163·6f6e·6461·2073·6e69·7070··n·Anaconda·snipp 
0003b340:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d 
0003b350:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel- 
0003b360:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps 
0003b370:·6522·2069·643d·2269·646d·3133·3430·223e··e"·id="idm1340"> 
0003b380:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta 
0003b390:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe 
0003b3a0:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered 
0003b3b0:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed 
0003b3c0:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple 
0003b3d0:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo 
0003b3e0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr>< 
0003b3f0:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</ 
0003b400:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td>< 
0003b410:·2f74·723e·3c74·723e·3c74·683e·5265·626f··/tr><tr><th>Rebo 
0003b420:·6f74·3a3c·2f74·683e·3c74·643e·6661·6c73··ot:</th><td>fals 
0003b430:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr>< 
0003b440:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th 
0003b450:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td> 
0003b460:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr 
0003b470:·653e·3c63·6f64·653e·0a70·6163·6b61·6765··e><code>.package0003b390:·6f64·653e·0a5b·5b70·6163·6b61·6765·735d··ode>.[[packages]
0003b480:·202d·2d61·6464·3d61·6964·650a·3c2f·636f···--add=aide.</co0003b3a0:·5d0a·6e61·6d65·203d·2022·6169·6465·220a··].name·=·"aide".
 0003b3b0:·7665·7273·696f·6e20·3d20·222a·220a·3c2f··version·=·"*".</
0003b490:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div><0003b3c0:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div
0003b4a0:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn0003b3d0:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b
0003b4b0:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t0003b3e0:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data
0003b4c0:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse"0003b3f0:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps
0003b4d0:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i0003b400:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
0003b4e0:·646d·3133·3431·2220·7461·6269·6e64·6578··dm1341"·tabindex0003b410:·2369·646d·3133·3431·2220·7461·6269·6e64··#idm1341"·tabind
0003b4f0:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto0003b420:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
0003b500:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded0003b430:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
0003b510:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="0003b440:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
0003b520:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve0003b450:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
0003b530:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re0003b460:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
0003b540:·6d65·6469·6174·696f·6e20·4f53·4275·696c··mediation·OSBuil0003b470:·5265·6d65·6469·6174·696f·6e20·5075·7070··Remediation·Pupp
0003b550:·6420·426c·7565·7072·696e·7420·736e·6970··d·Blueprint·snip 
0003b560:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br>< 
0003b570:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel 
0003b580:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap 
0003b590:·7365·2220·6964·3d22·6964·6d31·3334·3122··se"·id="idm1341"0003b480:·6574·2073·6e69·7070·6574·20e2·87b2·3c2f··et·snippet·...</
 0003b490:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
 0003b4a0:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
 0003b4b0:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
 0003b4c0:·646d·3133·3431·223e·3c74·6162·6c65·2063··dm1341"><table·c
 0003b4d0:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl
 0003b4e0:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-
 0003b4f0:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c
 0003b500:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t
 0003b510:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t
 0003b520:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
 0003b530:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru
 0003b540:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l
 0003b550:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
 0003b560:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th>
 0003b570:·3c74·643e·6661·6c73·653c·2f74·643e·3c2f··<td>false</td></
 0003b580:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat
 0003b590:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena
 0003b5a0:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t
0003b5a0:·3e3c·7072·653e·3c63·6f64·653e·0a5b·5b70··><pre><code>.[[p0003b5b0:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>
0003b5b0:·6163·6b61·6765·735d·5d0a·6e61·6d65·203d··ackages]].name·= 
0003b5c0:·2022·6169·6465·220a·7665·7273·696f·6e20···"aide".version· 
0003b5d0:·3d20·222a·220a·3c2f·636f·6465·3e3c·2f70··=·"*".</code></p 
0003b5e0:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas 
0003b5f0:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe 
0003b600:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle= 
0003b610:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data- 
0003b620:·7461·7267·6574·3d22·2369·646d·3133·3432··target="#idm1342 
0003b630:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r 
0003b640:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari 
0003b650:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals 
0003b660:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa 
0003b670:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr 
0003b680:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat 
0003b690:·696f·6e20·5075·7070·6574·2073·6e69·7070··ion·Puppet·snipp 
0003b6a0:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d 
0003b6b0:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel- 
0003b6c0:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps 
0003b6d0:·6522·2069·643d·2269·646d·3133·3432·223e··e"·id="idm1342"> 
0003b6e0:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta 
0003b6f0:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe 
0003b700:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered 
0003b710:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed 
0003b720:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple 
0003b730:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo 
0003b740:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr>< 
0003b750:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</0003b5c0:·696e·636c·7564·6520·696e·7374·616c·6c5f··include·install_
 0003b5d0:·6169·6465·0a0a·636c·6173·7320·696e·7374··aide..class·inst
 0003b5e0:·616c·6c5f·6169·6465·207b·0a20·2070·6163··all_aide·{.··pac
 0003b5f0:·6b61·6765·207b·2027·6169·6465·273a·0a20··kage·{·'aide':.·
 0003b600:·2020·2065·6e73·7572·6520·3d26·6774·3b20·····ensure·=&gt;·
 0003b610:·2769·6e73·7461·6c6c·6564·272c·0a20·207d··'installed',.··}
 0003b620:·0a7d·0a3c·2f63·6f64·653e·3c2f·7072·653e··.}.</code></pre>
 0003b630:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class="
 0003b640:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success"
 0003b650:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co
 0003b660:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar
 0003b670:·6765·743d·2223·6964·6d31·3334·3222·2074··get="#idm1342"·t
 0003b680:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
 0003b690:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
 0003b6a0:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
 0003b6b0:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
 0003b6c0:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
 0003b6d0:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
 0003b6e0:·2053·6865·6c6c·2073·6372·6970·7420·e287···Shell·script·..
 0003b6f0:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl
 0003b700:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla
 0003b710:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id
 0003b720:·3d22·6964·6d31·3334·3222·3e3c·7461·626c··="idm1342"><tabl
 0003b730:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t
 0003b740:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab
 0003b750:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl
 0003b760:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr
 0003b770:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:
0003b760:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><0003b780:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
Max diff block lines reached; 900120/918226 bytes (98.03%) of diff not shown.
74.5 KB
html2text {}
    
Offset 154, 21 lines modifiedOffset 154, 14 lines modified
154 ··-·PCI-DSSv4-11.5.2154 ··-·PCI-DSSv4-11.5.2
155 ··-·enable_strategy155 ··-·enable_strategy
156 ··-·low_complexity156 ··-·low_complexity
157 ··-·low_disruption157 ··-·low_disruption
158 ··-·medium_severity158 ··-·medium_severity
159 ··-·no_reboot_needed159 ··-·no_reboot_needed
160 ··-·package_aide_installed160 ··-·package_aide_installed
161 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
162 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
163 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
164 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
165 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
166 package·--add=aide 
167 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8161 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
168 [[packages]]162 [[packages]]
169 name·=·"aide"163 name·=·"aide"
170 version·=·"*"164 version·=·"*"
171 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8165 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
172 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low166 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 193, 14 lines modifiedOffset 186, 21 lines modified
193 if·!·rpm·-q·--quiet·"aide"·;·then186 if·!·rpm·-q·--quiet·"aide"·;·then
194 ····dnf·install·-y·"aide"187 ····dnf·install·-y·"aide"
195 fi188 fi
  
196 else189 else
197 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'190 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
198 fi191 fi
 192 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 193 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 194 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 195 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 196 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 197 package·--add=aide
199 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*198 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
200 Run·the·following·command·to·generate·a·new·database:199 Run·the·following·command·to·generate·a·new·database:
201 $·sudo·/usr/sbin/aide·--init200 $·sudo·/usr/sbin/aide·--init
202 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,201 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,
203 the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a202 the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a
204 secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The203 secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The
205 newly-generated·database·can·be·installed·as·follows:204 newly-generated·database·can·be·installed·as·follows:
Offset 777, 21 lines modifiedOffset 777, 14 lines modified
777 ··-·PCI-DSSv4-2.2.6777 ··-·PCI-DSSv4-2.2.6
778 ··-·enable_strategy778 ··-·enable_strategy
779 ··-·low_complexity779 ··-·low_complexity
780 ··-·low_disruption780 ··-·low_disruption
781 ··-·medium_severity781 ··-·medium_severity
782 ··-·no_reboot_needed782 ··-·no_reboot_needed
783 ··-·package_sudo_installed783 ··-·package_sudo_installed
784 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
785 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
786 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
787 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
788 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
789 package·--add=sudo 
790 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8784 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
791 [[packages]]785 [[packages]]
792 name·=·"sudo"786 name·=·"sudo"
793 version·=·"*"787 version·=·"*"
794 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8788 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
795 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low789 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 816, 14 lines modifiedOffset 809, 21 lines modified
816 if·!·rpm·-q·--quiet·"sudo"·;·then809 if·!·rpm·-q·--quiet·"sudo"·;·then
817 ····dnf·install·-y·"sudo"810 ····dnf·install·-y·"sudo"
818 fi811 fi
  
819 else812 else
820 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'813 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
821 fi814 fi
 815 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 816 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 817 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 818 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 819 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 820 package·--add=sudo
822 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·O\x8On\x8nl\x8ly\x8y·U\x8Us\x8se\x8er\x8rs\x8s·L\x8Lo\x8og\x8gg\x8ge\x8ed\x8d·I\x8In\x8n·T\x8To\x8o·R\x8Re\x8ea\x8al\x8l·t\x8tt\x8ty\x8y·C\x8Ca\x8an\x8n·E\x8Ex\x8xe\x8ec\x8cu\x8ut\x8te\x8e·S\x8Su\x8ud\x8do\x8o·-\x8-·s\x8su\x8ud\x8do\x8o·u\x8us\x8se\x8e_\x8_p\x8pt\x8ty\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*821 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·O\x8On\x8nl\x8ly\x8y·U\x8Us\x8se\x8er\x8rs\x8s·L\x8Lo\x8og\x8gg\x8ge\x8ed\x8d·I\x8In\x8n·T\x8To\x8o·R\x8Re\x8ea\x8al\x8l·t\x8tt\x8ty\x8y·C\x8Ca\x8an\x8n·E\x8Ex\x8xe\x8ec\x8cu\x8ut\x8te\x8e·S\x8Su\x8ud\x8do\x8o·-\x8-·s\x8su\x8ud\x8do\x8o·u\x8us\x8se\x8e_\x8_p\x8pt\x8ty\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
823 The·sudo·use_pty·tag,·when·specified,·will·only·execute·sudo·commands·from·users·logged·in·to·a·real·tty.822 The·sudo·use_pty·tag,·when·specified,·will·only·execute·sudo·commands·from·users·logged·in·to·a·real·tty.
824 This·should·be·enabled·by·making·sure·that·the·use_pty·tag·exists·in·/etc/sudoers·configuration·file·or·any823 This·should·be·enabled·by·making·sure·that·the·use_pty·tag·exists·in·/etc/sudoers·configuration·file·or·any
825 sudo·configuration·snippets·in·/etc/sudoers.d/.824 sudo·configuration·snippets·in·/etc/sudoers.d/.
826 Rationale:··Requiring·that·sudo·commands·be·run·in·a·pseudo-terminal·can·prevent·an·attacker·from·retaining825 Rationale:··Requiring·that·sudo·commands·be·run·in·a·pseudo-terminal·can·prevent·an·attacker·from·retaining
827 ············access·to·the·user's·terminal·after·the·main·program·has·finished·executing.826 ············access·to·the·user's·terminal·after·the·main·program·has·finished·executing.
828 Severity: ··medium827 Severity: ··medium
Offset 13626, 21 lines modifiedOffset 13626, 14 lines modified
13626 ··-·NIST-800-53-CM-6(a)13626 ··-·NIST-800-53-CM-6(a)
13627 ··-·enable_strategy13627 ··-·enable_strategy
13628 ··-·low_complexity13628 ··-·low_complexity
13629 ··-·low_disruption13629 ··-·low_disruption
13630 ··-·medium_severity13630 ··-·medium_severity
13631 ··-·no_reboot_needed13631 ··-·no_reboot_needed
13632 ··-·package_rsyslog_installed13632 ··-·package_rsyslog_installed
13633 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
13634 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
13635 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
13636 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
13637 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
13638 package·--add=rsyslog 
13639 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x813633 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
13640 [[packages]]13634 [[packages]]
13641 name·=·"rsyslog"13635 name·=·"rsyslog"
13642 version·=·"*"13636 version·=·"*"
13643 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x813637 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
13644 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low13638 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 13665, 14 lines modifiedOffset 13658, 21 lines modified
13665 if·!·rpm·-q·--quiet·"rsyslog"·;·then13658 if·!·rpm·-q·--quiet·"rsyslog"·;·then
13666 ····dnf·install·-y·"rsyslog"13659 ····dnf·install·-y·"rsyslog"
13667 fi13660 fi
  
13668 else13661 else
13669 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'13662 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
13670 fi13663 fi
 13664 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 13665 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 13666 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 13667 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 13668 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 13669 package·--add=rsyslog
13671 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·r\x8rs\x8sy\x8ys\x8sl\x8lo\x8og\x8g·D\x8De\x8ef\x8fa\x8au\x8ul\x8lt\x8t·F\x8Fi\x8il\x8le\x8e·P\x8Pe\x8er\x8rm\x8mi\x8is\x8ss\x8si\x8io\x8on\x8ns\x8s·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8ed\x8d·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*13670 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·r\x8rs\x8sy\x8ys\x8sl\x8lo\x8og\x8g·D\x8De\x8ef\x8fa\x8au\x8ul\x8lt\x8t·F\x8Fi\x8il\x8le\x8e·P\x8Pe\x8er\x8rm\x8mi\x8is\x8ss\x8si\x8io\x8on\x8ns\x8s·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8ed\x8d·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
13672 rsyslog·will·create·logfiles·that·do·not·already·exist·on·the·system.·This·settings·controls·what13671 rsyslog·will·create·logfiles·that·do·not·already·exist·on·the·system.·This·settings·controls·what
13673 permissions·will·be·applied·to·these·newly·created·files.13672 permissions·will·be·applied·to·these·newly·created·files.
Max diff block lines reached; 70966/76286 bytes (93.03%) of diff not shown.
1.17 MB
./usr/share/doc/ssg-nondebian/ssg-almalinux9-guide-cis.html
    
Offset 15182, 142 lines modifiedOffset 15182, 142 lines modified
0003b4d0:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="0003b4d0:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
0003b4e0:·2369·646d·3331·3838·2220·7461·6269·6e64··#idm3188"·tabind0003b4e0:·2369·646d·3331·3838·2220·7461·6269·6e64··#idm3188"·tabind
0003b4f0:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but0003b4f0:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
0003b500:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand0003b500:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
0003b510:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title0003b510:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
0003b520:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re0003b520:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
0003b530:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">0003b530:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
0003b540:·5265·6d65·6469·6174·696f·6e20·416e·6163··Remediation·Anac0003b540:·5265·6d65·6469·6174·696f·6e20·4f53·4275··Remediation·OSBu
0003b550:·6f6e·6461·2073·6e69·7070·6574·20e2·87b2··onda·snippet·... 
0003b560:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla 
0003b570:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap0003b550:·696c·6420·426c·7565·7072·696e·7420·736e··ild·Blueprint·sn
 0003b560:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br
 0003b570:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
0003b580:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=0003b580:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
 0003b590:·6170·7365·2220·6964·3d22·6964·6d33·3138··apse"·id="idm318
 0003b5a0:·3822·3e3c·7072·653e·3c63·6f64·653e·0a5b··8"><pre><code>.[
 0003b5b0:·5b70·6163·6b61·6765·735d·5d0a·6e61·6d65··[packages]].name
 0003b5c0:·203d·2022·6169·6465·220a·7665·7273·696f···=·"aide".versio
 0003b5d0:·6e20·3d20·222a·220a·3c2f·636f·6465·3e3c··n·=·"*".</code><
0003b590:·2269·646d·3331·3838·223e·3c74·6162·6c65··"idm3188"><table 
0003b5a0:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta 
0003b5b0:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl 
0003b5c0:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table 
0003b5d0:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr> 
0003b5e0:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:< 
0003b5f0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td> 
0003b600:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis 
0003b610:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td 
0003b620:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t 
0003b630:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t 
0003b640:·683e·3c74·643e·6661·6c73·653c·2f74·643e··h><td>false</td> 
0003b650:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str 
0003b660:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e 
0003b670:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr>< 
0003b680:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod 
0003b690:·653e·0a70·6163·6b61·6765·202d·2d61·6464··e>.package·--add 
0003b6a0:·3d61·6964·650a·3c2f·636f·6465·3e3c·2f70··=aide.</code></p 
0003b6b0:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas0003b5e0:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl
0003b6c0:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe0003b5f0:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc
0003b6d0:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle=0003b600:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl
0003b6e0:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data-0003b610:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat
0003b6f0:·7461·7267·6574·3d22·2369·646d·3331·3839··target="#idm31890003b620:·612d·7461·7267·6574·3d22·2369·646d·3331··a-target="#idm31
0003b700:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r0003b630:·3839·2220·7461·6269·6e64·6578·3d22·3022··89"·tabindex="0"
0003b710:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari0003b640:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
0003b720:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals0003b650:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
0003b730:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa0003b660:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
0003b740:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr0003b670:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
0003b750:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat0003b680:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
0003b760:·696f·6e20·4f53·4275·696c·6420·426c·7565··ion·OSBuild·Blue 
0003b770:·7072·696e·7420·736e·6970·7065·7420·e287··print·snippet·.. 
0003b780:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl 
0003b790:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla 
0003b7a0:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id 
0003b7b0:·3d22·6964·6d33·3138·3922·3e3c·7072·653e··="idm3189"><pre> 
0003b7c0:·3c63·6f64·653e·0a5b·5b70·6163·6b61·6765··<code>.[[package 
0003b7d0:·735d·5d0a·6e61·6d65·203d·2022·6169·6465··s]].name·=·"aide 
0003b7e0:·220a·7665·7273·696f·6e20·3d20·222a·220a··".version·=·"*". 
0003b7f0:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d 
0003b800:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn 
0003b810:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da 
0003b820:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla 
0003b830:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target 
0003b840:·3d22·2369·646d·3331·3930·2220·7461·6269··="#idm3190"·tabi 
0003b850:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b 
0003b860:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa 
0003b870:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit 
0003b880:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to· 
0003b890:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#! 
0003b8a0:·223e·5265·6d65·6469·6174·696f·6e20·5075··">Remediation·Pu 
0003b8b0:·7070·6574·2073·6e69·7070·6574·20e2·87b2··ppet·snippet·... 
0003b8c0:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla 
0003b8d0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap 
0003b8e0:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id= 
0003b8f0:·2269·646d·3331·3930·223e·3c74·6162·6c65··"idm3190"><table 
0003b900:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta 
0003b910:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl 
0003b920:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table 
0003b930:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr> 
0003b940:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:< 
0003b950:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td> 
0003b960:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis 
0003b970:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td0003b690:·6174·696f·6e20·5075·7070·6574·2073·6e69··ation·Puppet·sni
 0003b6a0:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>
 0003b6b0:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
 0003b6c0:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
 0003b6d0:·7073·6522·2069·643d·2269·646d·3331·3839··pse"·id="idm3189
 0003b6e0:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="
 0003b6f0:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri
 0003b700:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border
 0003b710:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens
 0003b720:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp
 0003b730:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>
 0003b740:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
 0003b750:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:
 0003b760:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
 0003b770:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re
 0003b780:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa
 0003b790:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr
 0003b7a0:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</
 0003b7b0:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t
 0003b7c0:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><
 0003b7d0:·7072·653e·3c63·6f64·653e·696e·636c·7564··pre><code>includ
 0003b7e0:·6520·696e·7374·616c·6c5f·6169·6465·0a0a··e·install_aide..
 0003b7f0:·636c·6173·7320·696e·7374·616c·6c5f·6169··class·install_ai
 0003b800:·6465·207b·0a20·2070·6163·6b61·6765·207b··de·{.··package·{
 0003b810:·2027·6169·6465·273a·0a20·2020·2065·6e73···'aide':.····ens
 0003b820:·7572·6520·3d26·6774·3b20·2769·6e73·7461··ure·=&gt;·'insta
 0003b830:·6c6c·6564·272c·0a20·207d·0a7d·0a3c·2f63··lled',.··}.}.</c
 0003b840:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div>
 0003b850:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt
 0003b860:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data-
 0003b870:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse
 0003b880:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
 0003b890:·6964·6d33·3139·3022·2074·6162·696e·6465··idm3190"·tabinde
 0003b8a0:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt
 0003b8b0:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande
 0003b8c0:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=
 0003b8d0:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev
 0003b8e0:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R
 0003b8f0:·656d·6564·6961·7469·6f6e·2053·6865·6c6c··emediation·Shell
 0003b900:·2073·6372·6970·7420·e287·b23c·2f61·3e3c···script·...</a><
 0003b910:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
 0003b920:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
 0003b930:·6c6c·6170·7365·2220·6964·3d22·6964·6d33··llapse"·id="idm3
 0003b940:·3139·3022·3e3c·7461·626c·6520·636c·6173··190"><table·clas
 0003b950:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s
 0003b960:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor
Max diff block lines reached; 1112101/1130345 bytes (98.39%) of diff not shown.
97.6 KB
html2text {}
    
Offset 155, 21 lines modifiedOffset 155, 14 lines modified
155 ··-·PCI-DSSv4-11.5.2155 ··-·PCI-DSSv4-11.5.2
156 ··-·enable_strategy156 ··-·enable_strategy
157 ··-·low_complexity157 ··-·low_complexity
158 ··-·low_disruption158 ··-·low_disruption
159 ··-·medium_severity159 ··-·medium_severity
160 ··-·no_reboot_needed160 ··-·no_reboot_needed
161 ··-·package_aide_installed161 ··-·package_aide_installed
162 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
163 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
164 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
165 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
166 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
167 package·--add=aide 
168 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8162 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
169 [[packages]]163 [[packages]]
170 name·=·"aide"164 name·=·"aide"
171 version·=·"*"165 version·=·"*"
172 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8166 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
173 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low167 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 194, 14 lines modifiedOffset 187, 21 lines modified
194 if·!·rpm·-q·--quiet·"aide"·;·then187 if·!·rpm·-q·--quiet·"aide"·;·then
195 ····dnf·install·-y·"aide"188 ····dnf·install·-y·"aide"
196 fi189 fi
  
197 else190 else
198 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'191 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
199 fi192 fi
 193 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 194 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 195 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 196 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 197 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 198 package·--add=aide
200 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*199 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
201 Run·the·following·command·to·generate·a·new·database:200 Run·the·following·command·to·generate·a·new·database:
202 $·sudo·/usr/sbin/aide·--init201 $·sudo·/usr/sbin/aide·--init
203 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration202 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration
204 file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only203 file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only
205 media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:204 media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
206 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz205 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
Offset 1526, 21 lines modifiedOffset 1526, 14 lines modified
1526 ··-·NIST-800-53-CM-7(b)1526 ··-·NIST-800-53-CM-7(b)
1527 ··-·disable_strategy1527 ··-·disable_strategy
1528 ··-·low_complexity1528 ··-·low_complexity
1529 ··-·low_disruption1529 ··-·low_disruption
1530 ··-·medium_severity1530 ··-·medium_severity
1531 ··-·no_reboot_needed1531 ··-·no_reboot_needed
1532 ··-·package_gdm_removed1532 ··-·package_gdm_removed
1533 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
1534 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
1535 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
1536 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
1537 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable 
  
1538 package·--remove=gdm 
1539 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81533 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1540 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1534 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1541 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1535 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1542 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1536 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1543 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable1537 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
1544 include·remove_gdm1538 include·remove_gdm
  
Offset 1566, 14 lines modifiedOffset 1559, 21 lines modified
1566 if·rpm·-q·--quiet·"gdm"·;·then1559 if·rpm·-q·--quiet·"gdm"·;·then
1567 dnf·remove·-y·--noautoremove·"gdm"1560 dnf·remove·-y·--noautoremove·"gdm"
1568 fi1561 fi
  
1569 else1562 else
1570 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'1563 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
1571 fi1564 fi
 1565 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 1566 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1567 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1568 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1569 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
  
 1570 package·--remove=gdm
1572 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·M\x8Ma\x8ak\x8ke\x8e·s\x8su\x8ur\x8re\x8e·t\x8th\x8ha\x8at\x8t·t\x8th\x8he\x8e·d\x8dc\x8co\x8on\x8nf\x8f·d\x8da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8es\x8s·a\x8ar\x8re\x8e·u\x8up\x8p-\x8-t\x8to\x8o-\x8-d\x8da\x8at\x8te\x8e·w\x8wi\x8it\x8th\x8h·r\x8re\x8eg\x8ga\x8ar\x8rd\x8ds\x8s·t\x8to\x8o·r\x8re\x8es\x8sp\x8pe\x8ec\x8ct\x8ti\x8iv\x8ve\x8e·k\x8ke\x8ey\x8yf\x8fi\x8il\x8le\x8es\x8s·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*1571 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·M\x8Ma\x8ak\x8ke\x8e·s\x8su\x8ur\x8re\x8e·t\x8th\x8ha\x8at\x8t·t\x8th\x8he\x8e·d\x8dc\x8co\x8on\x8nf\x8f·d\x8da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8es\x8s·a\x8ar\x8re\x8e·u\x8up\x8p-\x8-t\x8to\x8o-\x8-d\x8da\x8at\x8te\x8e·w\x8wi\x8it\x8th\x8h·r\x8re\x8eg\x8ga\x8ar\x8rd\x8ds\x8s·t\x8to\x8o·r\x8re\x8es\x8sp\x8pe\x8ec\x8ct\x8ti\x8iv\x8ve\x8e·k\x8ke\x8ey\x8yf\x8fi\x8il\x8le\x8es\x8s·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
1573 By·default,·DConf·uses·a·binary·database·as·a·data·backend.·The·system-level·database·is·compiled·from·keyfiles·in·the·/etc/1572 By·default,·DConf·uses·a·binary·database·as·a·data·backend.·The·system-level·database·is·compiled·from·keyfiles·in·the·/etc/
1574 dconf/db/·directory·by·the1573 dconf/db/·directory·by·the
1575 dconf·update1574 dconf·update
1576 command.·More·specifically,·content·present·in·the·following·directories:1575 command.·More·specifically,·content·present·in·the·following·directories:
1577 /etc/dconf/db/gdm.d1576 /etc/dconf/db/gdm.d
1578 /etc/dconf/db/local.d1577 /etc/dconf/db/local.d
Offset 1684, 21 lines modifiedOffset 1684, 14 lines modified
1684 ··-·PCI-DSSv4-2.2.61684 ··-·PCI-DSSv4-2.2.6
1685 ··-·enable_strategy1685 ··-·enable_strategy
1686 ··-·low_complexity1686 ··-·low_complexity
1687 ··-·low_disruption1687 ··-·low_disruption
1688 ··-·medium_severity1688 ··-·medium_severity
1689 ··-·no_reboot_needed1689 ··-·no_reboot_needed
1690 ··-·package_sudo_installed1690 ··-·package_sudo_installed
1691 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
1692 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
1693 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
1694 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
1695 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
1696 package·--add=sudo 
1697 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81691 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
1698 [[packages]]1692 [[packages]]
1699 name·=·"sudo"1693 name·=·"sudo"
1700 version·=·"*"1694 version·=·"*"
1701 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81695 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1702 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1696 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 1723, 14 lines modifiedOffset 1716, 21 lines modified
1723 if·!·rpm·-q·--quiet·"sudo"·;·then1716 if·!·rpm·-q·--quiet·"sudo"·;·then
1724 ····dnf·install·-y·"sudo"1717 ····dnf·install·-y·"sudo"
1725 fi1718 fi
  
1726 else1719 else
1727 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'1720 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
1728 fi1721 fi
 1722 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 1723 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1724 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1725 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1726 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 1727 package·--add=sudo
1729 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·O\x8On\x8nl\x8ly\x8y·U\x8Us\x8se\x8er\x8rs\x8s·L\x8Lo\x8og\x8gg\x8ge\x8ed\x8d·I\x8In\x8n·T\x8To\x8o·R\x8Re\x8ea\x8al\x8l·t\x8tt\x8ty\x8y·C\x8Ca\x8an\x8n·E\x8Ex\x8xe\x8ec\x8cu\x8ut\x8te\x8e·S\x8Su\x8ud\x8do\x8o·-\x8-·s\x8su\x8ud\x8do\x8o·u\x8us\x8se\x8e_\x8_p\x8pt\x8ty\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*1728 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·O\x8On\x8nl\x8ly\x8y·U\x8Us\x8se\x8er\x8rs\x8s·L\x8Lo\x8og\x8gg\x8ge\x8ed\x8d·I\x8In\x8n·T\x8To\x8o·R\x8Re\x8ea\x8al\x8l·t\x8tt\x8ty\x8y·C\x8Ca\x8an\x8n·E\x8Ex\x8xe\x8ec\x8cu\x8ut\x8te\x8e·S\x8Su\x8ud\x8do\x8o·-\x8-·s\x8su\x8ud\x8do\x8o·u\x8us\x8se\x8e_\x8_p\x8pt\x8ty\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
1730 The·sudo·use_pty·tag,·when·specified,·will·only·execute·sudo·commands·from·users·logged·in·to·a·real·tty.·This·should·be1729 The·sudo·use_pty·tag,·when·specified,·will·only·execute·sudo·commands·from·users·logged·in·to·a·real·tty.·This·should·be
1731 enabled·by·making·sure·that·the·use_pty·tag·exists·in·/etc/sudoers·configuration·file·or·any·sudo·configuration·snippets·in·/1730 enabled·by·making·sure·that·the·use_pty·tag·exists·in·/etc/sudoers·configuration·file·or·any·sudo·configuration·snippets·in·/
Max diff block lines reached; 94646/99884 bytes (94.76%) of diff not shown.
1.07 MB
./usr/share/doc/ssg-nondebian/ssg-almalinux9-guide-cis_server_l1.html
    
Offset 15144, 142 lines modifiedOffset 15144, 142 lines modified
0003b270:·7461·2d74·6172·6765·743d·2223·6964·6d33··ta-target="#idm30003b270:·7461·2d74·6172·6765·743d·2223·6964·6d33··ta-target="#idm3
0003b280:·3138·3822·2074·6162·696e·6465·783d·2230··188"·tabindex="00003b280:·3138·3822·2074·6162·696e·6465·783d·2230··188"·tabindex="0
0003b290:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·0003b290:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
0003b2a0:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f0003b2a0:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
0003b2b0:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act0003b2b0:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
0003b2c0:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"0003b2c0:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
0003b2d0:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed0003b2d0:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
 0003b2e0:·6961·7469·6f6e·204f·5342·7569·6c64·2042··iation·OSBuild·B
 0003b2f0:·6c75·6570·7269·6e74·2073·6e69·7070·6574··lueprint·snippet
 0003b300:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
 0003b310:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
 0003b320:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
 0003b330:·2069·643d·2269·646d·3331·3838·223e·3c70···id="idm3188"><p
0003b2e0:·6961·7469·6f6e·2041·6e61·636f·6e64·6120··iation·Anaconda· 
0003b2f0:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a>< 
0003b300:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p 
0003b310:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co 
0003b320:·6c6c·6170·7365·2220·6964·3d22·6964·6d33··llapse"·id="idm3 
0003b330:·3138·3822·3e3c·7461·626c·6520·636c·6173··188"><table·clas 
0003b340:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s 
0003b350:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor 
0003b360:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond 
0003b370:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C 
0003b380:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th>< 
0003b390:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
0003b3a0:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti 
0003b3b0:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low< 
0003b3c0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0003b3d0:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td 
0003b3e0:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr> 
0003b3f0:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy 
0003b400:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable 
0003b410:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl 
0003b420:·653e·3c70·7265·3e3c·636f·6465·3e0a·7061··e><pre><code>.pa0003b340:·7265·3e3c·636f·6465·3e0a·5b5b·7061·636b··re><code>.[[pack
0003b430:·636b·6167·6520·2d2d·6164·643d·6169·6465··ckage·--add=aide0003b350:·6167·6573·5d5d·0a6e·616d·6520·3d20·2261··ages]].name·=·"a
 0003b360:·6964·6522·0a76·6572·7369·6f6e·203d·2022··ide".version·=·"
0003b440:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></0003b370:·2a22·0a3c·2f63·6f64·653e·3c2f·7072·653e··*".</code></pre>
0003b450:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt0003b380:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class="
0003b460:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d0003b390:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success"
0003b470:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll0003b3a0:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co
0003b480:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe0003b3b0:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar
0003b490:·743d·2223·6964·6d33·3138·3922·2074·6162··t="#idm3189"·tab0003b3c0:·6765·743d·2223·6964·6d33·3138·3922·2074··get="#idm3189"·t
0003b4a0:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="0003b3d0:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
0003b4b0:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp0003b3e0:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
0003b4c0:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti0003b3f0:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
0003b4d0:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to0003b400:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
0003b4e0:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#0003b410:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
0003b4f0:·2122·3e52·656d·6564·6961·7469·6f6e·204f··!">Remediation·O0003b420:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
 0003b430:·2050·7570·7065·7420·736e·6970·7065·7420···Puppet·snippet·
 0003b440:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·
 0003b450:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col
0003b500:·5342·7569·6c64·2042·6c75·6570·7269·6e74··SBuild·Blueprint 
0003b510:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a> 
0003b520:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class=" 
0003b530:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c 
0003b540:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm 
0003b550:·3331·3839·223e·3c70·7265·3e3c·636f·6465··3189"><pre><code 
0003b560:·3e0a·5b5b·7061·636b·6167·6573·5d5d·0a6e··>.[[packages]].n 
0003b570:·616d·6520·3d20·2261·6964·6522·0a76·6572··ame·=·"aide".ver 
0003b580:·7369·6f6e·203d·2022·2a22·0a3c·2f63·6f64··sion·=·"*".</cod 
0003b590:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a 
0003b5a0:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn- 
0003b5b0:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to 
0003b5c0:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"·0003b460:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·
0003b5d0:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id 
0003b5e0:·6d33·3139·3022·2074·6162·696e·6465·783d··m3190"·tabindex= 
0003b5f0:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button 
0003b600:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded= 
0003b610:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A 
0003b620:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea 
0003b630:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem 
0003b640:·6564·6961·7469·6f6e·2050·7570·7065·7420··ediation·Puppet· 
0003b650:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a>< 
0003b660:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p 
0003b670:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co 
0003b680:·6c6c·6170·7365·2220·6964·3d22·6964·6d33··llapse"·id="idm3 
0003b690:·3139·3022·3e3c·7461·626c·6520·636c·6173··190"><table·clas 
0003b6a0:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s 
0003b6b0:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor 
0003b6c0:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond 
0003b6d0:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C 
0003b6e0:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th>< 
0003b6f0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
0003b700:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti0003b470:·6964·3d22·6964·6d33·3138·3922·3e3c·7461··id="idm3189"><ta
 0003b480:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table
 0003b490:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t
 0003b4a0:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta
 0003b4b0:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><
 0003b4c0:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit
 0003b4d0:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</
 0003b4e0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 0003b4f0:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th>
 0003b500:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
 0003b510:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot:
 0003b520:·3c2f·7468·3e3c·7464·3e66·616c·7365·3c2f··</th><td>false</
 0003b530:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 0003b540:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t
 0003b550:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t
 0003b560:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><
 0003b570:·636f·6465·3e69·6e63·6c75·6465·2069·6e73··code>include·ins
 0003b580:·7461·6c6c·5f61·6964·650a·0a63·6c61·7373··tall_aide..class
 0003b590:·2069·6e73·7461·6c6c·5f61·6964·6520·7b0a···install_aide·{.
 0003b5a0:·2020·7061·636b·6167·6520·7b20·2761·6964····package·{·'aid
 0003b5b0:·6527·3a0a·2020·2020·656e·7375·7265·203d··e':.····ensure·=
 0003b5c0:·2667·743b·2027·696e·7374·616c·6c65·6427··&gt;·'installed'
 0003b5d0:·2c0a·2020·7d0a·7d0a·3c2f·636f·6465·3e3c··,.··}.}.</code><
 0003b5e0:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl
 0003b5f0:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc
 0003b600:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl
 0003b610:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat
 0003b620:·612d·7461·7267·6574·3d22·2369·646d·3331··a-target="#idm31
 0003b630:·3930·2220·7461·6269·6e64·6578·3d22·3022··90"·tabindex="0"
 0003b640:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
 0003b650:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
 0003b660:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
 0003b670:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
 0003b680:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
 0003b690:·6174·696f·6e20·5368·656c·6c20·7363·7269··ation·Shell·scri
 0003b6a0:·7074·20e2·87b2·3c2f·613e·3c62·723e·3c64··pt·...</a><br><d
 0003b6b0:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-
 0003b6c0:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps
 0003b6d0:·6522·2069·643d·2269·646d·3331·3930·223e··e"·id="idm3190">
 0003b6e0:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta
 0003b6f0:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe
 0003b700:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered
 0003b710:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed
 0003b720:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple
Max diff block lines reached; 1013048/1031292 bytes (98.23%) of diff not shown.
86.8 KB
html2text {}
    
Offset 149, 21 lines modifiedOffset 149, 14 lines modified
149 ··-·PCI-DSSv4-11.5.2149 ··-·PCI-DSSv4-11.5.2
150 ··-·enable_strategy150 ··-·enable_strategy
151 ··-·low_complexity151 ··-·low_complexity
152 ··-·low_disruption152 ··-·low_disruption
153 ··-·medium_severity153 ··-·medium_severity
154 ··-·no_reboot_needed154 ··-·no_reboot_needed
155 ··-·package_aide_installed155 ··-·package_aide_installed
156 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
157 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
158 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
159 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
160 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
161 package·--add=aide 
162 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8156 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
163 [[packages]]157 [[packages]]
164 name·=·"aide"158 name·=·"aide"
165 version·=·"*"159 version·=·"*"
166 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8160 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
167 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low161 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 188, 14 lines modifiedOffset 181, 21 lines modified
188 if·!·rpm·-q·--quiet·"aide"·;·then181 if·!·rpm·-q·--quiet·"aide"·;·then
189 ····dnf·install·-y·"aide"182 ····dnf·install·-y·"aide"
190 fi183 fi
  
191 else184 else
192 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'185 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
193 fi186 fi
 187 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 188 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 189 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 190 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 191 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 192 package·--add=aide
194 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*193 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
195 Run·the·following·command·to·generate·a·new·database:194 Run·the·following·command·to·generate·a·new·database:
196 $·sudo·/usr/sbin/aide·--init195 $·sudo·/usr/sbin/aide·--init
197 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration196 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration
198 file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only197 file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only
199 media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:198 media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
200 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz199 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
Offset 1466, 21 lines modifiedOffset 1466, 14 lines modified
1466 ··-·PCI-DSSv4-2.2.61466 ··-·PCI-DSSv4-2.2.6
1467 ··-·enable_strategy1467 ··-·enable_strategy
1468 ··-·low_complexity1468 ··-·low_complexity
1469 ··-·low_disruption1469 ··-·low_disruption
1470 ··-·medium_severity1470 ··-·medium_severity
1471 ··-·no_reboot_needed1471 ··-·no_reboot_needed
1472 ··-·package_sudo_installed1472 ··-·package_sudo_installed
1473 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
1474 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
1475 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
1476 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
1477 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
1478 package·--add=sudo 
1479 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81473 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
1480 [[packages]]1474 [[packages]]
1481 name·=·"sudo"1475 name·=·"sudo"
1482 version·=·"*"1476 version·=·"*"
1483 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81477 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1484 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1478 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 1505, 14 lines modifiedOffset 1498, 21 lines modified
1505 if·!·rpm·-q·--quiet·"sudo"·;·then1498 if·!·rpm·-q·--quiet·"sudo"·;·then
1506 ····dnf·install·-y·"sudo"1499 ····dnf·install·-y·"sudo"
1507 fi1500 fi
  
1508 else1501 else
1509 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'1502 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
1510 fi1503 fi
 1504 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 1505 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1506 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1507 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1508 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 1509 package·--add=sudo
1511 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·O\x8On\x8nl\x8ly\x8y·U\x8Us\x8se\x8er\x8rs\x8s·L\x8Lo\x8og\x8gg\x8ge\x8ed\x8d·I\x8In\x8n·T\x8To\x8o·R\x8Re\x8ea\x8al\x8l·t\x8tt\x8ty\x8y·C\x8Ca\x8an\x8n·E\x8Ex\x8xe\x8ec\x8cu\x8ut\x8te\x8e·S\x8Su\x8ud\x8do\x8o·-\x8-·s\x8su\x8ud\x8do\x8o·u\x8us\x8se\x8e_\x8_p\x8pt\x8ty\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*1510 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·O\x8On\x8nl\x8ly\x8y·U\x8Us\x8se\x8er\x8rs\x8s·L\x8Lo\x8og\x8gg\x8ge\x8ed\x8d·I\x8In\x8n·T\x8To\x8o·R\x8Re\x8ea\x8al\x8l·t\x8tt\x8ty\x8y·C\x8Ca\x8an\x8n·E\x8Ex\x8xe\x8ec\x8cu\x8ut\x8te\x8e·S\x8Su\x8ud\x8do\x8o·-\x8-·s\x8su\x8ud\x8do\x8o·u\x8us\x8se\x8e_\x8_p\x8pt\x8ty\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
1512 The·sudo·use_pty·tag,·when·specified,·will·only·execute·sudo·commands·from·users·logged·in·to·a·real·tty.·This·should·be1511 The·sudo·use_pty·tag,·when·specified,·will·only·execute·sudo·commands·from·users·logged·in·to·a·real·tty.·This·should·be
1513 enabled·by·making·sure·that·the·use_pty·tag·exists·in·/etc/sudoers·configuration·file·or·any·sudo·configuration·snippets·in·/1512 enabled·by·making·sure·that·the·use_pty·tag·exists·in·/etc/sudoers·configuration·file·or·any·sudo·configuration·snippets·in·/
1514 etc/sudoers.d/.1513 etc/sudoers.d/.
1515 Rationale:··Requiring·that·sudo·commands·be·run·in·a·pseudo-terminal·can·prevent·an·attacker·from·retaining·access·to·the1514 Rationale:··Requiring·that·sudo·commands·be·run·in·a·pseudo-terminal·can·prevent·an·attacker·from·retaining·access·to·the
1516 ············user's·terminal·after·the·main·program·has·finished·executing.1515 ············user's·terminal·after·the·main·program·has·finished·executing.
1517 Severity: ··medium1516 Severity: ··medium
Offset 9685, 21 lines modifiedOffset 9685, 14 lines modified
9685 ··tags:9685 ··tags:
9686 ··-·enable_strategy9686 ··-·enable_strategy
9687 ··-·low_complexity9687 ··-·low_complexity
9688 ··-·low_disruption9688 ··-·low_disruption
9689 ··-·medium_severity9689 ··-·medium_severity
9690 ··-·no_reboot_needed9690 ··-·no_reboot_needed
9691 ··-·package_pam_pwquality_installed9691 ··-·package_pam_pwquality_installed
9692 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
9693 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
9694 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
9695 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
9696 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
9697 package·--add=libpwquality 
9698 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x89692 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
9699 [[packages]]9693 [[packages]]
9700 name·=·"libpwquality"9694 name·=·"libpwquality"
9701 version·=·"*"9695 version·=·"*"
9702 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x89696 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
9703 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low9697 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 9724, 14 lines modifiedOffset 9717, 21 lines modified
9724 if·!·rpm·-q·--quiet·"libpwquality"·;·then9717 if·!·rpm·-q·--quiet·"libpwquality"·;·then
9725 ····dnf·install·-y·"libpwquality"9718 ····dnf·install·-y·"libpwquality"
9726 fi9719 fi
  
9727 else9720 else
9728 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'9721 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
9729 fi9722 fi
 9723 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 9724 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 9725 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 9726 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 9727 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 9728 package·--add=libpwquality
9730 Group  ·Protect·Accounts·by·Restricting·Password-Based·Login·  Group·contains·4·groups·and·23·rules9729 Group  ·Protect·Accounts·by·Restricting·Password-Based·Login·  Group·contains·4·groups·and·23·rules
9731 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Conventionally,·Unix·shell·accounts·are·accessed·by·providing·a·username·and·password·to·a·login·program,·which·tests9730 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Conventionally,·Unix·shell·accounts·are·accessed·by·providing·a·username·and·password·to·a·login·program,·which·tests
9732 these·values·for·correctness·using·the·/etc/passwd·and·/etc/shadow·files.·Password-based·login·is·vulnerable·to·guessing·of9731 these·values·for·correctness·using·the·/etc/passwd·and·/etc/shadow·files.·Password-based·login·is·vulnerable·to·guessing·of
Max diff block lines reached; 83440/88846 bytes (93.92%) of diff not shown.
1.05 MB
./usr/share/doc/ssg-nondebian/ssg-almalinux9-guide-cis_workstation_l1.html
    
Offset 15135, 142 lines modifiedOffset 15135, 142 lines modified
0003b1e0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=0003b1e0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
0003b1f0:·2223·6964·6d33·3138·3822·2074·6162·696e··"#idm3188"·tabin0003b1f0:·2223·6964·6d33·3138·3822·2074·6162·696e··"#idm3188"·tabin
0003b200:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu0003b200:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
0003b210:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan0003b210:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
0003b220:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl0003b220:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
0003b230:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r0003b230:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
0003b240:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"0003b240:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
0003b250:·3e52·656d·6564·6961·7469·6f6e·2041·6e61··>Remediation·Ana0003b250:·3e52·656d·6564·6961·7469·6f6e·204f·5342··>Remediation·OSB
0003b260:·636f·6e64·6120·736e·6970·7065·7420·e287··conda·snippet·.. 
0003b270:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl 
0003b280:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla0003b260:·7569·6c64·2042·6c75·6570·7269·6e74·2073··uild·Blueprint·s
 0003b270:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b
 0003b280:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
0003b290:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id0003b290:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
 0003b2a0:·6c61·7073·6522·2069·643d·2269·646d·3331··lapse"·id="idm31
 0003b2b0:·3838·223e·3c70·7265·3e3c·636f·6465·3e0a··88"><pre><code>.
 0003b2c0:·5b5b·7061·636b·6167·6573·5d5d·0a6e·616d··[[packages]].nam
 0003b2d0:·6520·3d20·2261·6964·6522·0a76·6572·7369··e·=·"aide".versi
 0003b2e0:·6f6e·203d·2022·2a22·0a3c·2f63·6f64·653e··on·=·"*".</code>
0003b2a0:·3d22·6964·6d33·3138·3822·3e3c·7461·626c··="idm3188"><tabl 
0003b2b0:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t 
0003b2c0:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab 
0003b2d0:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl 
0003b2e0:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr 
0003b2f0:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity: 
0003b300:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td 
0003b310:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di 
0003b320:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t 
0003b330:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr>< 
0003b340:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</ 
0003b350:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td 
0003b360:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St 
0003b370:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td> 
0003b380:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr> 
0003b390:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co 
0003b3a0:·6465·3e0a·7061·636b·6167·6520·2d2d·6164··de>.package·--ad 
0003b3b0:·643d·6169·6465·0a3c·2f63·6f64·653e·3c2f··d=aide.</code></ 
0003b3c0:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla0003b2f0:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c
0003b3d0:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ0003b300:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su
0003b3e0:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle0003b310:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg
0003b3f0:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data0003b320:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da
0003b400:·2d74·6172·6765·743d·2223·6964·6d33·3138··-target="#idm3180003b330:·7461·2d74·6172·6765·743d·2223·6964·6d33··ta-target="#idm3
0003b410:·3922·2074·6162·696e·6465·783d·2230·2220··9"·tabindex="0"·0003b340:·3138·3922·2074·6162·696e·6465·783d·2230··189"·tabindex="0
0003b420:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar0003b350:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
0003b430:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal0003b360:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
0003b440:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ0003b370:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
0003b450:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h0003b380:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
0003b460:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia0003b390:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
0003b470:·7469·6f6e·204f·5342·7569·6c64·2042·6c75··tion·OSBuild·Blu 
0003b480:·6570·7269·6e74·2073·6e69·7070·6574·20e2··eprint·snippet·. 
0003b490:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c 
0003b4a0:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll 
0003b4b0:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i 
0003b4c0:·643d·2269·646d·3331·3839·223e·3c70·7265··d="idm3189"><pre 
0003b4d0:·3e3c·636f·6465·3e0a·5b5b·7061·636b·6167··><code>.[[packag 
0003b4e0:·6573·5d5d·0a6e·616d·6520·3d20·2261·6964··es]].name·=·"aid 
0003b4f0:·6522·0a76·6572·7369·6f6e·203d·2022·2a22··e".version·=·"*" 
0003b500:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></ 
0003b510:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt 
0003b520:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d 
0003b530:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll 
0003b540:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe 
0003b550:·743d·2223·6964·6d33·3139·3022·2074·6162··t="#idm3190"·tab 
0003b560:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role=" 
0003b570:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp 
0003b580:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti 
0003b590:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to 
0003b5a0:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="# 
0003b5b0:·2122·3e52·656d·6564·6961·7469·6f6e·2050··!">Remediation·P 
0003b5c0:·7570·7065·7420·736e·6970·7065·7420·e287··uppet·snippet·.. 
0003b5d0:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl 
0003b5e0:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla0003b3a0:·6961·7469·6f6e·2050·7570·7065·7420·736e··iation·Puppet·sn
 0003b3b0:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br
 0003b3c0:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
 0003b3d0:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
 0003b3e0:·6170·7365·2220·6964·3d22·6964·6d33·3138··apse"·id="idm318
 0003b3f0:·3922·3e3c·7461·626c·6520·636c·6173·733d··9"><table·class=
 0003b400:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str
 0003b410:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde
 0003b420:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden
 0003b430:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com
 0003b440:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td
 0003b450:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
 0003b460:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption
 0003b470:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
 0003b480:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e52··d></tr><tr><th>R
 0003b490:·6562·6f6f·743a·3c2f·7468·3e3c·7464·3e66··eboot:</th><td>f
 0003b4a0:·616c·7365·3c2f·7464·3e3c·2f74·723e·3c74··alse</td></tr><t
 0003b4b0:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<
 0003b4c0:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</
 0003b4d0:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table>
 0003b4e0:·3c70·7265·3e3c·636f·6465·3e69·6e63·6c75··<pre><code>inclu
 0003b4f0:·6465·2069·6e73·7461·6c6c·5f61·6964·650a··de·install_aide.
 0003b500:·0a63·6c61·7373·2069·6e73·7461·6c6c·5f61··.class·install_a
 0003b510:·6964·6520·7b0a·2020·7061·636b·6167·6520··ide·{.··package·
 0003b520:·7b20·2761·6964·6527·3a0a·2020·2020·656e··{·'aide':.····en
 0003b530:·7375·7265·203d·2667·743b·2027·696e·7374··sure·=&gt;·'inst
 0003b540:·616c·6c65·6427·2c0a·2020·7d0a·7d0a·3c2f··alled',.··}.}.</
 0003b550:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div
 0003b560:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b
 0003b570:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data
 0003b580:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps
 0003b590:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
 0003b5a0:·2369·646d·3331·3930·2220·7461·6269·6e64··#idm3190"·tabind
 0003b5b0:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
 0003b5c0:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
 0003b5d0:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
 0003b5e0:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
 0003b5f0:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
 0003b600:·5265·6d65·6469·6174·696f·6e20·5368·656c··Remediation·Shel
 0003b610:·6c20·7363·7269·7074·20e2·87b2·3c2f·613e··l·script·...</a>
 0003b620:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="
0003b5f0:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id0003b630:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c
 0003b640:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm
 0003b650:·3331·3930·223e·3c74·6162·6c65·2063·6c61··3190"><table·cla
 0003b660:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-
 0003b670:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo
 0003b680:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con
 0003b690:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>
 0003b6a0:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>
0003b600:·3d22·6964·6d33·3139·3022·3e3c·7461·626c··="idm3190"><tabl 
0003b610:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t 
0003b620:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab 
0003b630:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl 
0003b640:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr 
0003b650:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity: 
0003b660:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td 
Max diff block lines reached; 994664/1012908 bytes (98.20%) of diff not shown.
85.0 KB
html2text {}
    
Offset 148, 21 lines modifiedOffset 148, 14 lines modified
148 ··-·PCI-DSSv4-11.5.2148 ··-·PCI-DSSv4-11.5.2
149 ··-·enable_strategy149 ··-·enable_strategy
150 ··-·low_complexity150 ··-·low_complexity
151 ··-·low_disruption151 ··-·low_disruption
152 ··-·medium_severity152 ··-·medium_severity
153 ··-·no_reboot_needed153 ··-·no_reboot_needed
154 ··-·package_aide_installed154 ··-·package_aide_installed
155 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
156 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
157 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
158 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
159 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
160 package·--add=aide 
161 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8155 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
162 [[packages]]156 [[packages]]
163 name·=·"aide"157 name·=·"aide"
164 version·=·"*"158 version·=·"*"
165 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8159 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
166 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low160 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 187, 14 lines modifiedOffset 180, 21 lines modified
187 if·!·rpm·-q·--quiet·"aide"·;·then180 if·!·rpm·-q·--quiet·"aide"·;·then
188 ····dnf·install·-y·"aide"181 ····dnf·install·-y·"aide"
189 fi182 fi
  
190 else183 else
191 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'184 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
192 fi185 fi
 186 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 187 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 188 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 189 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 190 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 191 package·--add=aide
193 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*192 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
194 Run·the·following·command·to·generate·a·new·database:193 Run·the·following·command·to·generate·a·new·database:
195 $·sudo·/usr/sbin/aide·--init194 $·sudo·/usr/sbin/aide·--init
196 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration195 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration
197 file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only196 file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only
198 media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:197 media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
199 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz198 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
Offset 1292, 21 lines modifiedOffset 1292, 14 lines modified
1292 ··-·PCI-DSSv4-2.2.61292 ··-·PCI-DSSv4-2.2.6
1293 ··-·enable_strategy1293 ··-·enable_strategy
1294 ··-·low_complexity1294 ··-·low_complexity
1295 ··-·low_disruption1295 ··-·low_disruption
1296 ··-·medium_severity1296 ··-·medium_severity
1297 ··-·no_reboot_needed1297 ··-·no_reboot_needed
1298 ··-·package_sudo_installed1298 ··-·package_sudo_installed
1299 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
1300 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
1301 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
1302 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
1303 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
1304 package·--add=sudo 
1305 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81299 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
1306 [[packages]]1300 [[packages]]
1307 name·=·"sudo"1301 name·=·"sudo"
1308 version·=·"*"1302 version·=·"*"
1309 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81303 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1310 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1304 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 1331, 14 lines modifiedOffset 1324, 21 lines modified
1331 if·!·rpm·-q·--quiet·"sudo"·;·then1324 if·!·rpm·-q·--quiet·"sudo"·;·then
1332 ····dnf·install·-y·"sudo"1325 ····dnf·install·-y·"sudo"
1333 fi1326 fi
  
1334 else1327 else
1335 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'1328 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
1336 fi1329 fi
 1330 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 1331 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1332 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1333 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1334 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 1335 package·--add=sudo
1337 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·O\x8On\x8nl\x8ly\x8y·U\x8Us\x8se\x8er\x8rs\x8s·L\x8Lo\x8og\x8gg\x8ge\x8ed\x8d·I\x8In\x8n·T\x8To\x8o·R\x8Re\x8ea\x8al\x8l·t\x8tt\x8ty\x8y·C\x8Ca\x8an\x8n·E\x8Ex\x8xe\x8ec\x8cu\x8ut\x8te\x8e·S\x8Su\x8ud\x8do\x8o·-\x8-·s\x8su\x8ud\x8do\x8o·u\x8us\x8se\x8e_\x8_p\x8pt\x8ty\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*1336 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·O\x8On\x8nl\x8ly\x8y·U\x8Us\x8se\x8er\x8rs\x8s·L\x8Lo\x8og\x8gg\x8ge\x8ed\x8d·I\x8In\x8n·T\x8To\x8o·R\x8Re\x8ea\x8al\x8l·t\x8tt\x8ty\x8y·C\x8Ca\x8an\x8n·E\x8Ex\x8xe\x8ec\x8cu\x8ut\x8te\x8e·S\x8Su\x8ud\x8do\x8o·-\x8-·s\x8su\x8ud\x8do\x8o·u\x8us\x8se\x8e_\x8_p\x8pt\x8ty\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
1338 The·sudo·use_pty·tag,·when·specified,·will·only·execute·sudo·commands·from·users·logged·in·to·a·real·tty.·This·should·be1337 The·sudo·use_pty·tag,·when·specified,·will·only·execute·sudo·commands·from·users·logged·in·to·a·real·tty.·This·should·be
1339 enabled·by·making·sure·that·the·use_pty·tag·exists·in·/etc/sudoers·configuration·file·or·any·sudo·configuration·snippets·in·/1338 enabled·by·making·sure·that·the·use_pty·tag·exists·in·/etc/sudoers·configuration·file·or·any·sudo·configuration·snippets·in·/
1340 etc/sudoers.d/.1339 etc/sudoers.d/.
1341 Rationale:··Requiring·that·sudo·commands·be·run·in·a·pseudo-terminal·can·prevent·an·attacker·from·retaining·access·to·the1340 Rationale:··Requiring·that·sudo·commands·be·run·in·a·pseudo-terminal·can·prevent·an·attacker·from·retaining·access·to·the
1342 ············user's·terminal·after·the·main·program·has·finished·executing.1341 ············user's·terminal·after·the·main·program·has·finished·executing.
1343 Severity: ··medium1342 Severity: ··medium
Offset 9511, 21 lines modifiedOffset 9511, 14 lines modified
9511 ··tags:9511 ··tags:
9512 ··-·enable_strategy9512 ··-·enable_strategy
9513 ··-·low_complexity9513 ··-·low_complexity
9514 ··-·low_disruption9514 ··-·low_disruption
9515 ··-·medium_severity9515 ··-·medium_severity
9516 ··-·no_reboot_needed9516 ··-·no_reboot_needed
9517 ··-·package_pam_pwquality_installed9517 ··-·package_pam_pwquality_installed
9518 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
9519 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
9520 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
9521 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
9522 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
9523 package·--add=libpwquality 
9524 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x89518 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
9525 [[packages]]9519 [[packages]]
9526 name·=·"libpwquality"9520 name·=·"libpwquality"
9527 version·=·"*"9521 version·=·"*"
9528 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x89522 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
9529 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low9523 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 9550, 14 lines modifiedOffset 9543, 21 lines modified
9550 if·!·rpm·-q·--quiet·"libpwquality"·;·then9543 if·!·rpm·-q·--quiet·"libpwquality"·;·then
9551 ····dnf·install·-y·"libpwquality"9544 ····dnf·install·-y·"libpwquality"
9552 fi9545 fi
  
9553 else9546 else
9554 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'9547 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
9555 fi9548 fi
 9549 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 9550 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 9551 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 9552 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 9553 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 9554 package·--add=libpwquality
9556 Group  ·Protect·Accounts·by·Restricting·Password-Based·Login·  Group·contains·4·groups·and·23·rules9555 Group  ·Protect·Accounts·by·Restricting·Password-Based·Login·  Group·contains·4·groups·and·23·rules
9557 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Conventionally,·Unix·shell·accounts·are·accessed·by·providing·a·username·and·password·to·a·login·program,·which·tests9556 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Conventionally,·Unix·shell·accounts·are·accessed·by·providing·a·username·and·password·to·a·login·program,·which·tests
9558 these·values·for·correctness·using·the·/etc/passwd·and·/etc/shadow·files.·Password-based·login·is·vulnerable·to·guessing·of9557 these·values·for·correctness·using·the·/etc/passwd·and·/etc/shadow·files.·Password-based·login·is·vulnerable·to·guessing·of
Max diff block lines reached; 81622/87028 bytes (93.79%) of diff not shown.
1.12 MB
./usr/share/doc/ssg-nondebian/ssg-almalinux9-guide-cis_workstation_l2.html
    
Offset 15174, 142 lines modifiedOffset 15174, 142 lines modified
0003b450:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target0003b450:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
0003b460:·3d22·2369·646d·3331·3838·2220·7461·6269··="#idm3188"·tabi0003b460:·3d22·2369·646d·3331·3838·2220·7461·6269··="#idm3188"·tabi
0003b470:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b0003b470:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
0003b480:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa0003b480:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
0003b490:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit0003b490:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
0003b4a0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·0003b4a0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
0003b4b0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!0003b4b0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
0003b4c0:·223e·5265·6d65·6469·6174·696f·6e20·416e··">Remediation·An0003b4c0:·223e·5265·6d65·6469·6174·696f·6e20·4f53··">Remediation·OS
0003b4d0:·6163·6f6e·6461·2073·6e69·7070·6574·20e2··aconda·snippet·. 
0003b4e0:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c 
0003b4f0:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll0003b4d0:·4275·696c·6420·426c·7565·7072·696e·7420··Build·Blueprint·
 0003b4e0:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><
 0003b4f0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
0003b500:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i0003b500:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
 0003b510:·6c6c·6170·7365·2220·6964·3d22·6964·6d33··llapse"·id="idm3
 0003b520:·3138·3822·3e3c·7072·653e·3c63·6f64·653e··188"><pre><code>
 0003b530:·0a5b·5b70·6163·6b61·6765·735d·5d0a·6e61··.[[packages]].na
 0003b540:·6d65·203d·2022·6169·6465·220a·7665·7273··me·=·"aide".vers
 0003b550:·696f·6e20·3d20·222a·220a·3c2f·636f·6465··ion·=·"*".</code
0003b510:·643d·2269·646d·3331·3838·223e·3c74·6162··d="idm3188"><tab 
0003b520:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table· 
0003b530:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta 
0003b540:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab 
0003b550:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t 
0003b560:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity 
0003b570:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t 
0003b580:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D 
0003b590:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th>< 
0003b5a0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
0003b5b0:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:< 
0003b5c0:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t 
0003b5d0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S 
0003b5e0:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td 
0003b5f0:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr 
0003b600:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c 
0003b610:·6f64·653e·0a70·6163·6b61·6765·202d·2d61··ode>.package·--a 
0003b620:·6464·3d61·6964·650a·3c2f·636f·6465·3e3c··dd=aide.</code>< 
0003b630:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl0003b560:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a·
0003b640:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc0003b570:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s
0003b650:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl0003b580:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog
0003b660:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat0003b590:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d
0003b670:·612d·7461·7267·6574·3d22·2369·646d·3331··a-target="#idm310003b5a0:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
0003b680:·3839·2220·7461·6269·6e64·6578·3d22·3022··89"·tabindex="0"0003b5b0:·3331·3839·2220·7461·6269·6e64·6578·3d22··3189"·tabindex="
0003b690:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a0003b5c0:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
0003b6a0:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa0003b5d0:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
0003b6b0:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti0003b5e0:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
0003b6c0:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·0003b5f0:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
0003b6d0:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi0003b600:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
0003b6e0:·6174·696f·6e20·4f53·4275·696c·6420·426c··ation·OSBuild·Bl 
0003b6f0:·7565·7072·696e·7420·736e·6970·7065·7420··ueprint·snippet· 
0003b700:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div· 
0003b710:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col 
0003b720:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"· 
0003b730:·6964·3d22·6964·6d33·3138·3922·3e3c·7072··id="idm3189"><pr 
0003b740:·653e·3c63·6f64·653e·0a5b·5b70·6163·6b61··e><code>.[[packa 
0003b750:·6765·735d·5d0a·6e61·6d65·203d·2022·6169··ges]].name·=·"ai 
0003b760:·6465·220a·7665·7273·696f·6e20·3d20·222a··de".version·=·"* 
0003b770:·220a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··".</code></pre>< 
0003b780:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b 
0003b790:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"· 
0003b7a0:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col 
0003b7b0:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ 
0003b7c0:·6574·3d22·2369·646d·3331·3930·2220·7461··et="#idm3190"·ta 
0003b7d0:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role= 
0003b7e0:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex 
0003b7f0:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t 
0003b800:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t 
0003b810:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href=" 
0003b820:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation· 
0003b830:·5075·7070·6574·2073·6e69·7070·6574·20e2··Puppet·snippet·. 
0003b840:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c 
0003b850:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll0003b610:·6469·6174·696f·6e20·5075·7070·6574·2073··diation·Puppet·s
 0003b620:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b
 0003b630:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
 0003b640:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
 0003b650:·6c61·7073·6522·2069·643d·2269·646d·3331··lapse"·id="idm31
 0003b660:·3839·223e·3c74·6162·6c65·2063·6c61·7373··89"><table·class
 0003b670:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st
 0003b680:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord
 0003b690:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde
 0003b6a0:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co
 0003b6b0:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t
 0003b6c0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
 0003b6d0:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio
 0003b6e0:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</
 0003b6f0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 0003b700:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td>
 0003b710:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr><
 0003b720:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:
 0003b730:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<
 0003b740:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table
 0003b750:·3e3c·7072·653e·3c63·6f64·653e·696e·636c··><pre><code>incl
 0003b760:·7564·6520·696e·7374·616c·6c5f·6169·6465··ude·install_aide
 0003b770:·0a0a·636c·6173·7320·696e·7374·616c·6c5f··..class·install_
 0003b780:·6169·6465·207b·0a20·2070·6163·6b61·6765··aide·{.··package
 0003b790:·207b·2027·6169·6465·273a·0a20·2020·2065···{·'aide':.····e
 0003b7a0:·6e73·7572·6520·3d26·6774·3b20·2769·6e73··nsure·=&gt;·'ins
 0003b7b0:·7461·6c6c·6564·272c·0a20·207d·0a7d·0a3c··talled',.··}.}.<
 0003b7c0:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di
 0003b7d0:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn·
 0003b7e0:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat
 0003b7f0:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap
 0003b800:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
 0003b810:·2223·6964·6d33·3139·3022·2074·6162·696e··"#idm3190"·tabin
 0003b820:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
 0003b830:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
 0003b840:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
 0003b850:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
 0003b860:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
 0003b870:·3e52·656d·6564·6961·7469·6f6e·2053·6865··>Remediation·She
 0003b880:·6c6c·2073·6372·6970·7420·e287·b23c·2f61··ll·script·...</a
 0003b890:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
0003b860:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i0003b8a0:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
 0003b8b0:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
 0003b8c0:·6d33·3139·3022·3e3c·7461·626c·6520·636c··m3190"><table·cl
 0003b8d0:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table
 0003b8e0:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b
 0003b8f0:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co
 0003b900:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th
 0003b910:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th
0003b870:·643d·2269·646d·3331·3930·223e·3c74·6162··d="idm3190"><tab 
0003b880:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table· 
0003b890:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta 
0003b8a0:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab 
0003b8b0:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t 
0003b8c0:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity 
0003b8d0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t 
Max diff block lines reached; 1058676/1076920 bytes (98.31%) of diff not shown.
92.1 KB
html2text {}
    
Offset 154, 21 lines modifiedOffset 154, 14 lines modified
154 ··-·PCI-DSSv4-11.5.2154 ··-·PCI-DSSv4-11.5.2
155 ··-·enable_strategy155 ··-·enable_strategy
156 ··-·low_complexity156 ··-·low_complexity
157 ··-·low_disruption157 ··-·low_disruption
158 ··-·medium_severity158 ··-·medium_severity
159 ··-·no_reboot_needed159 ··-·no_reboot_needed
160 ··-·package_aide_installed160 ··-·package_aide_installed
161 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
162 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
163 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
164 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
165 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
166 package·--add=aide 
167 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8161 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
168 [[packages]]162 [[packages]]
169 name·=·"aide"163 name·=·"aide"
170 version·=·"*"164 version·=·"*"
171 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8165 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
172 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low166 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 193, 14 lines modifiedOffset 186, 21 lines modified
193 if·!·rpm·-q·--quiet·"aide"·;·then186 if·!·rpm·-q·--quiet·"aide"·;·then
194 ····dnf·install·-y·"aide"187 ····dnf·install·-y·"aide"
195 fi188 fi
  
196 else189 else
197 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'190 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
198 fi191 fi
 192 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 193 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 194 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 195 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 196 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 197 package·--add=aide
199 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*198 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
200 Run·the·following·command·to·generate·a·new·database:199 Run·the·following·command·to·generate·a·new·database:
201 $·sudo·/usr/sbin/aide·--init200 $·sudo·/usr/sbin/aide·--init
202 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration201 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration
203 file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only202 file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only
204 media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:203 media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
205 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz204 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
Offset 1596, 21 lines modifiedOffset 1596, 14 lines modified
1596 ··-·PCI-DSSv4-2.2.61596 ··-·PCI-DSSv4-2.2.6
1597 ··-·enable_strategy1597 ··-·enable_strategy
1598 ··-·low_complexity1598 ··-·low_complexity
1599 ··-·low_disruption1599 ··-·low_disruption
1600 ··-·medium_severity1600 ··-·medium_severity
1601 ··-·no_reboot_needed1601 ··-·no_reboot_needed
1602 ··-·package_sudo_installed1602 ··-·package_sudo_installed
1603 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
1604 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
1605 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
1606 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
1607 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
1608 package·--add=sudo 
1609 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81603 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
1610 [[packages]]1604 [[packages]]
1611 name·=·"sudo"1605 name·=·"sudo"
1612 version·=·"*"1606 version·=·"*"
1613 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81607 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1614 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1608 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 1635, 14 lines modifiedOffset 1628, 21 lines modified
1635 if·!·rpm·-q·--quiet·"sudo"·;·then1628 if·!·rpm·-q·--quiet·"sudo"·;·then
1636 ····dnf·install·-y·"sudo"1629 ····dnf·install·-y·"sudo"
1637 fi1630 fi
  
1638 else1631 else
1639 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'1632 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
1640 fi1633 fi
 1634 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 1635 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1636 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1637 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1638 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 1639 package·--add=sudo
1641 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·O\x8On\x8nl\x8ly\x8y·U\x8Us\x8se\x8er\x8rs\x8s·L\x8Lo\x8og\x8gg\x8ge\x8ed\x8d·I\x8In\x8n·T\x8To\x8o·R\x8Re\x8ea\x8al\x8l·t\x8tt\x8ty\x8y·C\x8Ca\x8an\x8n·E\x8Ex\x8xe\x8ec\x8cu\x8ut\x8te\x8e·S\x8Su\x8ud\x8do\x8o·-\x8-·s\x8su\x8ud\x8do\x8o·u\x8us\x8se\x8e_\x8_p\x8pt\x8ty\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*1640 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·O\x8On\x8nl\x8ly\x8y·U\x8Us\x8se\x8er\x8rs\x8s·L\x8Lo\x8og\x8gg\x8ge\x8ed\x8d·I\x8In\x8n·T\x8To\x8o·R\x8Re\x8ea\x8al\x8l·t\x8tt\x8ty\x8y·C\x8Ca\x8an\x8n·E\x8Ex\x8xe\x8ec\x8cu\x8ut\x8te\x8e·S\x8Su\x8ud\x8do\x8o·-\x8-·s\x8su\x8ud\x8do\x8o·u\x8us\x8se\x8e_\x8_p\x8pt\x8ty\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
1642 The·sudo·use_pty·tag,·when·specified,·will·only·execute·sudo·commands·from·users·logged·in·to·a·real·tty.·This·should·be1641 The·sudo·use_pty·tag,·when·specified,·will·only·execute·sudo·commands·from·users·logged·in·to·a·real·tty.·This·should·be
1643 enabled·by·making·sure·that·the·use_pty·tag·exists·in·/etc/sudoers·configuration·file·or·any·sudo·configuration·snippets·in·/1642 enabled·by·making·sure·that·the·use_pty·tag·exists·in·/etc/sudoers·configuration·file·or·any·sudo·configuration·snippets·in·/
1644 etc/sudoers.d/.1643 etc/sudoers.d/.
1645 Rationale:··Requiring·that·sudo·commands·be·run·in·a·pseudo-terminal·can·prevent·an·attacker·from·retaining·access·to·the1644 Rationale:··Requiring·that·sudo·commands·be·run·in·a·pseudo-terminal·can·prevent·an·attacker·from·retaining·access·to·the
1646 ············user's·terminal·after·the·main·program·has·finished·executing.1645 ············user's·terminal·after·the·main·program·has·finished·executing.
1647 Severity: ··medium1646 Severity: ··medium
Offset 10741, 21 lines modifiedOffset 10741, 14 lines modified
10741 ··tags:10741 ··tags:
10742 ··-·enable_strategy10742 ··-·enable_strategy
10743 ··-·low_complexity10743 ··-·low_complexity
10744 ··-·low_disruption10744 ··-·low_disruption
10745 ··-·medium_severity10745 ··-·medium_severity
10746 ··-·no_reboot_needed10746 ··-·no_reboot_needed
10747 ··-·package_pam_pwquality_installed10747 ··-·package_pam_pwquality_installed
10748 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
10749 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
10750 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
10751 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
10752 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
10753 package·--add=libpwquality 
10754 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x810748 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
10755 [[packages]]10749 [[packages]]
10756 name·=·"libpwquality"10750 name·=·"libpwquality"
10757 version·=·"*"10751 version·=·"*"
10758 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x810752 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
10759 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low10753 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 10780, 14 lines modifiedOffset 10773, 21 lines modified
10780 if·!·rpm·-q·--quiet·"libpwquality"·;·then10773 if·!·rpm·-q·--quiet·"libpwquality"·;·then
10781 ····dnf·install·-y·"libpwquality"10774 ····dnf·install·-y·"libpwquality"
10782 fi10775 fi
  
10783 else10776 else
10784 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'10777 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
10785 fi10778 fi
 10779 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 10780 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 10781 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 10782 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 10783 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 10784 package·--add=libpwquality
10786 Group  ·Protect·Accounts·by·Restricting·Password-Based·Login·  Group·contains·4·groups·and·25·rules10785 Group  ·Protect·Accounts·by·Restricting·Password-Based·Login·  Group·contains·4·groups·and·25·rules
10787 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Conventionally,·Unix·shell·accounts·are·accessed·by·providing·a·username·and·password·to·a·login·program,·which·tests10786 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Conventionally,·Unix·shell·accounts·are·accessed·by·providing·a·username·and·password·to·a·login·program,·which·tests
10788 these·values·for·correctness·using·the·/etc/passwd·and·/etc/shadow·files.·Password-based·login·is·vulnerable·to·guessing·of10787 these·values·for·correctness·using·the·/etc/passwd·and·/etc/shadow·files.·Password-based·login·is·vulnerable·to·guessing·of
Max diff block lines reached; 88908/94318 bytes (94.26%) of diff not shown.
126 KB
./usr/share/doc/ssg-nondebian/ssg-almalinux9-guide-hipaa.html
    
Offset 35213, 172 lines modifiedOffset 35213, 172 lines modified
000898c0:·6172·6765·743d·2223·6964·6d32·3036·3738··arget="#idm20678000898c0:·6172·6765·743d·2223·6964·6d32·3036·3738··arget="#idm20678
000898d0:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r000898d0:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r
000898e0:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari000898e0:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari
000898f0:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals000898f0:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals
00089900:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa00089900:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa
00089910:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr00089910:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr
00089920:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat00089920:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat
00089930:·696f·6e20·416e·6163·6f6e·6461·2073·6e69··ion·Anaconda·sni00089930:·696f·6e20·4f53·4275·696c·6420·426c·7565··ion·OSBuild·Blue
 00089940:·7072·696e·7420·736e·6970·7065·7420·e287··print·snippet·..
 00089950:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl
 00089960:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla
 00089970:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id
 00089980:·3d22·6964·6d32·3036·3738·223e·3c70·7265··="idm20678"><pre
 00089990:·3e3c·636f·6465·3e0a·5b63·7573·746f·6d69··><code>.[customi
 000899a0:·7a61·7469·6f6e·732e·7365·7276·6963·6573··zations.services
 000899b0:·5d0a·6d61·736b·6564·203d·205b·226b·6475··].masked·=·["kdu
 000899c0:·6d70·225d·0a3c·2f63·6f64·653e·3c2f·7072··mp"].</code></pr
 000899d0:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class
 000899e0:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes
 000899f0:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle="
 00089a00:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t
 00089a10:·6172·6765·743d·2223·6964·6d32·3036·3739··arget="#idm20679
 00089a20:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r
 00089a30:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari
 00089a40:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals
 00089a50:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa
 00089a60:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr
 00089a70:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat
 00089a80:·696f·6e20·5075·7070·6574·2073·6e69·7070··ion·Puppet·snipp
00089940:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>00089a90:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d
00089950:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane00089aa0:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-
00089960:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla00089ab0:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps
00089970:·7073·6522·2069·643d·2269·646d·3230·3637··pse"·id="idm206700089ac0:·6522·2069·643d·2269·646d·3230·3637·3922··e"·id="idm20679"
00089980:·3822·3e3c·7072·653e·3c63·6f64·653e·0a6b··8"><pre><code>.k 
00089990:·6475·6d70·202d·2d64·6973·6162·6c65·0a3c··dump·--disable.< 
000899a0:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di 
000899b0:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn· 
000899c0:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat 
000899d0:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap 
000899e0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target= 
000899f0:·2223·6964·6d32·3036·3739·2220·7461·6269··"#idm20679"·tabi 
00089a00:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b 
00089a10:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa 
00089a20:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit 
00089a30:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to· 
00089a40:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#! 
00089a50:·223e·5265·6d65·6469·6174·696f·6e20·4f53··">Remediation·OS 
00089a60:·4275·696c·6420·426c·7565·7072·696e·7420··Build·Blueprint· 
00089a70:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a>< 
00089a80:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p 
00089a90:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co 
00089aa0:·6c6c·6170·7365·2220·6964·3d22·6964·6d32··llapse"·id="idm2 
00089ab0:·3036·3739·223e·3c70·7265·3e3c·636f·6465··0679"><pre><code 
00089ac0:·3e0a·5b63·7573·746f·6d69·7a61·7469·6f6e··>.[customization 
00089ad0:·732e·7365·7276·6963·6573·5d0a·6d61·736b··s.services].mask 
00089ae0:·6564·203d·205b·226b·6475·6d70·225d·0a3c··ed·=·["kdump"].< 
00089af0:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di 
00089b00:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn· 
00089b10:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat 
00089b20:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap 
00089b30:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target= 
00089b40:·2223·6964·6d32·3036·3830·2220·7461·6269··"#idm20680"·tabi 
00089b50:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b 
00089b60:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa 
00089b70:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit 
00089b80:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to· 
00089b90:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#! 
00089ba0:·223e·5265·6d65·6469·6174·696f·6e20·5075··">Remediation·Pu 
00089bb0:·7070·6574·2073·6e69·7070·6574·20e2·87b2··ppet·snippet·... 
00089bc0:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla 
00089bd0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap 
00089be0:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id= 
00089bf0:·2269·646d·3230·3638·3022·3e3c·7461·626c··"idm20680"><tabl 
00089c00:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t 
00089c10:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab 
00089c20:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl 
00089c30:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr 
00089c40:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity: 
00089c50:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td 
00089c60:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di 
00089c70:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t 
00089c80:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr>< 
00089c90:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</ 
00089ca0:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td 
00089cb0:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St 
00089cc0:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td> 
00089cd0:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr> 
00089ce0:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co 
00089cf0:·6465·3e69·6e63·6c75·6465·2064·6973·6162··de>include·disab 
00089d00:·6c65·5f6b·6475·6d70·0a0a·636c·6173·7320··le_kdump..class· 
00089d10:·6469·7361·626c·655f·6b64·756d·7020·7b0a··disable_kdump·{. 
00089d20:·2020·7365·7276·6963·6520·7b27·6b64·756d····service·{'kdum 
00089d30:·7027·3a0a·2020·2020·656e·6162·6c65·203d··p':.····enable·= 
00089d40:·2667·743b·2066·616c·7365·2c0a·2020·2020··&gt;·false,.···· 
00089d50:·656e·7375·7265·203d·2667·743b·2027·7374··ensure·=&gt;·'st 
00089d60:·6f70·7065·6427·2c0a·2020·7d0a·7d0a·3c2f··opped',.··}.}.</ 
00089d70:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div 
00089d80:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b00089ad0:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t
 00089ae0:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip
 00089af0:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere
 00089b00:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense
 00089b10:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl
00089d90:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data 
00089da0:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps 
00089db0:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target=" 
00089dc0:·2369·646d·3230·3638·3122·2074·6162·696e··#idm20681"·tabin 
00089dd0:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu 
00089de0:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan 
00089df0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl 
00089e00:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r 
00089e10:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!" 
00089e20:·3e52·656d·6564·6961·7469·6f6e·2053·6865··>Remediation·She 
00089e30:·6c6c·2073·6372·6970·7420·e287·b23c·2f61··ll·script·...</a 
00089e40:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class= 
00089e50:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse· 
00089e60:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id 
00089e70:·6d32·3036·3831·223e·3c74·6162·6c65·2063··m20681"><table·c 
00089e80:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl 
00089e90:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table- 
00089ea0:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c 
00089eb0:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t 
00089ec0:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t 
00089ed0:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></ 
00089ee0:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru 
00089ef0:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l00089b20:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l
00089f00:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>00089b30:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
00089f10:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th> 
Max diff block lines reached; 94422/116806 bytes (80.84%) of diff not shown.
11.9 KB
html2text {}
    
Offset 4481, 17 lines modifiedOffset 4481, 14 lines modified
4481 ··-·NIST-800-53-CM-7(b)4481 ··-·NIST-800-53-CM-7(b)
4482 ··-·disable_strategy4482 ··-·disable_strategy
4483 ··-·low_complexity4483 ··-·low_complexity
4484 ··-·low_disruption4484 ··-·low_disruption
4485 ··-·medium_severity4485 ··-·medium_severity
4486 ··-·no_reboot_needed4486 ··-·no_reboot_needed
4487 ··-·service_kdump_disabled4487 ··-·service_kdump_disabled
4488 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
4489 kdump·--disable 
4490 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x84488 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
4491 [customizations.services]4489 [customizations.services]
4492 masked·=·["kdump"]4490 masked·=·["kdump"]
4493 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x84491 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
4494 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low4492 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
4495 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low4493 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
Offset 4530, 14 lines modifiedOffset 4527, 17 lines modified
4530 #·so·let's·reset·the·state·so·OVAL·checks·pass.4527 #·so·let's·reset·the·state·so·OVAL·checks·pass.
4531 #·Service·should·be·'inactive',·not·'failed'·after·reboot·though.4528 #·Service·should·be·'inactive',·not·'failed'·after·reboot·though.
4532 "$SYSTEMCTL_EXEC"·reset-failed·'kdump.service'·||·true4529 "$SYSTEMCTL_EXEC"·reset-failed·'kdump.service'·||·true
  
4533 else4530 else
4534 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'4531 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
4535 fi4532 fi
 4533 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 4534 kdump·--disable
4536 Group  ·Cron·and·At·Daemons·  Group·contains·2·rules4535 Group  ·Cron·and·At·Daemons·  Group·contains·2·rules
4537 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·cron·and·at·services·are·used·to·allow·commands·to·be·executed·at·a·later·time.·The·cron4536 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·cron·and·at·services·are·used·to·allow·commands·to·be·executed·at·a·later·time.·The·cron
4538 service·is·required·by·almost·all·systems·to·perform·necessary·maintenance·tasks,·while·at·may·or·may·not4537 service·is·required·by·almost·all·systems·to·perform·necessary·maintenance·tasks,·while·at·may·or·may·not
4539 be·required·on·a·given·system.·Both·daemons·should·be·configured·defensively.4538 be·required·on·a·given·system.·Both·daemons·should·be·configured·defensively.
4540 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·t\x8th\x8he\x8e·c\x8cr\x8ro\x8on\x8n·s\x8se\x8er\x8rv\x8vi\x8ic\x8ce\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*4539 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·t\x8th\x8he\x8e·c\x8cr\x8ro\x8on\x8n·s\x8se\x8er\x8rv\x8vi\x8ic\x8ce\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
4541 The·Cron·service·should·be·installed.4540 The·Cron·service·should·be·installed.
4542 ············The·cron·service·allow·periodic·job·execution,·needed·for·almost·all·administrative·tasks·and4541 ············The·cron·service·allow·periodic·job·execution,·needed·for·almost·all·administrative·tasks·and
Offset 4593, 21 lines modifiedOffset 4593, 14 lines modified
4593 ··-·PCI-DSSv4-2.2.64593 ··-·PCI-DSSv4-2.2.6
4594 ··-·enable_strategy4594 ··-·enable_strategy
4595 ··-·low_complexity4595 ··-·low_complexity
4596 ··-·low_disruption4596 ··-·low_disruption
4597 ··-·medium_severity4597 ··-·medium_severity
4598 ··-·no_reboot_needed4598 ··-·no_reboot_needed
4599 ··-·package_cron_installed4599 ··-·package_cron_installed
4600 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
4601 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
4602 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
4603 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
4604 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
4605 package·--add=cron 
4606 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x84600 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
4607 [[packages]]4601 [[packages]]
4608 name·=·"cron"4602 name·=·"cron"
4609 version·=·"*"4603 version·=·"*"
4610 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x84604 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
4611 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low4605 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 4632, 14 lines modifiedOffset 4625, 21 lines modified
4632 if·!·rpm·-q·--quiet·"cron"·;·then4625 if·!·rpm·-q·--quiet·"cron"·;·then
4633 ····dnf·install·-y·"cron"4626 ····dnf·install·-y·"cron"
4634 fi4627 fi
  
4635 else4628 else
4636 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'4629 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
4637 fi4630 fi
 4631 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 4632 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 4633 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 4634 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 4635 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 4636 package·--add=cron
4638 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·c\x8cr\x8ro\x8on\x8n·S\x8Se\x8er\x8rv\x8vi\x8ic\x8ce\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*4637 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·c\x8cr\x8ro\x8on\x8n·S\x8Se\x8er\x8rv\x8vi\x8ic\x8ce\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
4639 The·crond·service·is·used·to·execute·commands·at·preconfigured·times.·It·is·required·by·almost·all·systems4638 The·crond·service·is·used·to·execute·commands·at·preconfigured·times.·It·is·required·by·almost·all·systems
4640 to·perform·necessary·maintenance·tasks,·such·as·notifying·root·of·system·activity.·The·crond·service·can4639 to·perform·necessary·maintenance·tasks,·such·as·notifying·root·of·system·activity.·The·crond·service·can
4641 be·enabled·with·the·following·command:4640 be·enabled·with·the·following·command:
4642 $·sudo·systemctl·enable·crond.service4641 $·sudo·systemctl·enable·crond.service
4643 Rationale:··Due·to·its·usage·for·maintenance·and·security-supporting·tasks,·enabling·the·cron·daemon·is4642 Rationale:··Due·to·its·usage·for·maintenance·and·security-supporting·tasks,·enabling·the·cron·daemon·is
4644 ············essential.4643 ············essential.
Offset 4990, 21 lines modifiedOffset 4990, 14 lines modified
4990 ··-·PCI-DSSv4-2.2.44990 ··-·PCI-DSSv4-2.2.4
4991 ··-·disable_strategy4991 ··-·disable_strategy
4992 ··-·low_complexity4992 ··-·low_complexity
4993 ··-·low_disruption4993 ··-·low_disruption
4994 ··-·medium_severity4994 ··-·medium_severity
4995 ··-·no_reboot_needed4995 ··-·no_reboot_needed
4996 ··-·package_talk-server_removed4996 ··-·package_talk-server_removed
4997 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
4998 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
4999 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
5000 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
5001 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable 
  
5002 package·--remove=talk-server 
5003 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x84997 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
5004 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low4998 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
5005 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low4999 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
5006 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false5000 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
5007 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable5001 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
5008 include·remove_talk-server5002 include·remove_talk-server
  
Offset 5024, 14 lines modifiedOffset 5017, 21 lines modified
5024 #»      ···that·depend·on·talk-server.·Execute·this5017 #»      ···that·depend·on·talk-server.·Execute·this
5025 #»      ···remediation·AFTER·testing·on·a·non-production5018 #»      ···remediation·AFTER·testing·on·a·non-production
5026 #»      ···system!5019 #»      ···system!
  
5027 if·rpm·-q·--quiet·"talk-server"·;·then5020 if·rpm·-q·--quiet·"talk-server"·;·then
5028 dnf·remove·-y·--noautoremove·"talk-server"5021 dnf·remove·-y·--noautoremove·"talk-server"
5029 fi5022 fi
 5023 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 5024 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 5025 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 5026 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 5027 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
  
 5028 package·--remove=talk-server
5030 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·U\x8Un\x8ni\x8in\x8ns\x8st\x8ta\x8al\x8ll\x8l·t\x8ta\x8al\x8lk\x8k·P\x8Pa\x8ac\x8ck\x8ka\x8ag\x8ge\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*5029 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·U\x8Un\x8ni\x8in\x8ns\x8st\x8ta\x8al\x8ll\x8l·t\x8ta\x8al\x8lk\x8k·P\x8Pa\x8ac\x8ck\x8ka\x8ag\x8ge\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
5031 The·talk·package·contains·the·client·program·for·the·Internet·talk·protocol,·which·allows·the·user·to5030 The·talk·package·contains·the·client·program·for·the·Internet·talk·protocol,·which·allows·the·user·to
5032 chat·with·other·users·on·different·systems.·Talk·is·a·communication·program·which·copies·lines·from·one5031 chat·with·other·users·on·different·systems.·Talk·is·a·communication·program·which·copies·lines·from·one
5033 terminal·to·the·terminal·of·another·user.·The·talk·package·can·be·removed·with·the·following·command:5032 terminal·to·the·terminal·of·another·user.·The·talk·package·can·be·removed·with·the·following·command:
5034 $·sudo·dnf·remove·talk5033 $·sudo·dnf·remove·talk
5035 ············The·talk·software·presents·a·security·risk·as·it·uses·unencrypted·protocols·for5034 ············The·talk·software·presents·a·security·risk·as·it·uses·unencrypted·protocols·for
5036 Rationale:··communications.·Removing·the·talk·package·decreases·the·risk·of·the·accidental·(or5035 Rationale:··communications.·Removing·the·talk·package·decreases·the·risk·of·the·accidental·(or
Offset 5056, 21 lines modifiedOffset 5056, 14 lines modified
5056 ··-·PCI-DSSv4-2.2.45056 ··-·PCI-DSSv4-2.2.4
5057 ··-·disable_strategy5057 ··-·disable_strategy
5058 ··-·low_complexity5058 ··-·low_complexity
Max diff block lines reached; 6858/12200 bytes (56.21%) of diff not shown.
357 KB
./usr/share/doc/ssg-nondebian/ssg-almalinux9-guide-pci-dss.html
    
Offset 15919, 141 lines modifiedOffset 15919, 141 lines modified
0003e2e0:·6765·743d·2223·6964·6d33·3138·3822·2074··get="#idm3188"·t0003e2e0:·6765·743d·2223·6964·6d33·3138·3822·2074··get="#idm3188"·t
0003e2f0:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role0003e2f0:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
0003e300:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e0003e300:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
0003e310:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·0003e310:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
0003e320:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·0003e320:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
0003e330:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=0003e330:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
0003e340:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation0003e340:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
 0003e350:·204f·5342·7569·6c64·2042·6c75·6570·7269···OSBuild·Bluepri
 0003e360:·6e74·2073·6e69·7070·6574·20e2·87b2·3c2f··nt·snippet·...</
 0003e370:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
 0003e380:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
 0003e390:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
 0003e3a0:·646d·3331·3838·223e·3c70·7265·3e3c·636f··dm3188"><pre><co
 0003e3b0:·6465·3e0a·5b5b·7061·636b·6167·6573·5d5d··de>.[[packages]]
 0003e3c0:·0a6e·616d·6520·3d20·2261·6964·6522·0a76··.name·=·"aide".v
 0003e3d0:·6572·7369·6f6e·203d·2022·2a22·0a3c·2f63··ersion·=·"*".</c
0003e350:·2041·6e61·636f·6e64·6120·736e·6970·7065···Anaconda·snippe 
0003e360:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di 
0003e370:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c 
0003e380:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse 
0003e390:·2220·6964·3d22·6964·6d33·3138·3822·3e3c··"·id="idm3188">< 
0003e3a0:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab 
0003e3b0:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped 
0003e3c0:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered· 
0003e3d0:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed" 
0003e3e0:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex 
0003e3f0:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low 
0003e400:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
0003e410:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t 
0003e420:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></ 
0003e430:·7472·3e3c·7472·3e3c·7468·3e52·6562·6f6f··tr><tr><th>Reboo 
0003e440:·743a·3c2f·7468·3e3c·7464·3e66·616c·7365··t:</th><td>false 
0003e450:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
0003e460:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th> 
0003e470:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td>< 
0003e480:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre 
0003e490:·3e3c·636f·6465·3e0a·7061·636b·6167·6520··><code>.package· 
0003e4a0:·2d2d·6164·643d·6169·6465·0a3c·2f63·6f64··--add=aide.</cod 
0003e4b0:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a0003e3e0:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div>
0003e4c0:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn-0003e3f0:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt
0003e4d0:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to0003e400:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data-
0003e4e0:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"·0003e410:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse
0003e4f0:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id0003e420:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
0003e500:·6d33·3138·3922·2074·6162·696e·6465·783d··m3189"·tabindex=0003e430:·6964·6d33·3138·3922·2074·6162·696e·6465··idm3189"·tabinde
0003e510:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button0003e440:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt
0003e520:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=0003e450:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande
0003e530:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A0003e460:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=
0003e540:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea0003e470:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev
0003e550:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem0003e480:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R
 0003e490:·656d·6564·6961·7469·6f6e·2050·7570·7065··emediation·Puppe
 0003e4a0:·7420·736e·6970·7065·7420·e287·b23c·2f61··t·snippet·...</a
 0003e4b0:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
 0003e4c0:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
0003e560:·6564·6961·7469·6f6e·204f·5342·7569·6c64··ediation·OSBuild 
0003e570:·2042·6c75·6570·7269·6e74·2073·6e69·7070···Blueprint·snipp 
0003e580:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d 
0003e590:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel- 
0003e5a0:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps 
0003e5b0:·6522·2069·643d·2269·646d·3331·3839·223e··e"·id="idm3189"> 
0003e5c0:·3c70·7265·3e3c·636f·6465·3e0a·5b5b·7061··<pre><code>.[[pa 
0003e5d0:·636b·6167·6573·5d5d·0a6e·616d·6520·3d20··ckages]].name·=· 
0003e5e0:·2261·6964·6522·0a76·6572·7369·6f6e·203d··"aide".version·= 
0003e5f0:·2022·2a22·0a3c·2f63·6f64·653e·3c2f·7072···"*".</code></pr 
0003e600:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class 
0003e610:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes 
0003e620:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle=" 
0003e630:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t0003e4d0:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
 0003e4e0:·6d33·3138·3922·3e3c·7461·626c·6520·636c··m3189"><table·cl
 0003e4f0:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table
 0003e500:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b
 0003e510:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co
 0003e520:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th
 0003e530:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th
 0003e540:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
 0003e550:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup
 0003e560:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo
 0003e570:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
 0003e580:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th><
 0003e590:·7464·3e66·616c·7365·3c2f·7464·3e3c·2f74··td>false</td></t
 0003e5a0:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate
 0003e5b0:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab
0003e640:·6172·6765·743d·2223·6964·6d33·3139·3022··arget="#idm3190" 
0003e650:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro 
0003e660:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria 
0003e670:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false 
0003e680:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat 
0003e690:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre 
0003e6a0:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati 
0003e6b0:·6f6e·2050·7570·7065·7420·736e·6970·7065··on·Puppet·snippe 
0003e6c0:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di 
0003e6d0:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c 
0003e6e0:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse 
0003e6f0:·2220·6964·3d22·6964·6d33·3139·3022·3e3c··"·id="idm3190">< 
0003e700:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab 
0003e710:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped 
0003e720:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered· 
0003e730:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed" 
0003e740:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex 
0003e750:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low 
0003e760:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t0003e5c0:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta
0003e770:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t0003e5d0:·626c·653e·3c70·7265·3e3c·636f·6465·3e69··ble><pre><code>i
 0003e5e0:·6e63·6c75·6465·2069·6e73·7461·6c6c·5f61··nclude·install_a
 0003e5f0:·6964·650a·0a63·6c61·7373·2069·6e73·7461··ide..class·insta
 0003e600:·6c6c·5f61·6964·6520·7b0a·2020·7061·636b··ll_aide·{.··pack
 0003e610:·6167·6520·7b20·2761·6964·6527·3a0a·2020··age·{·'aide':.··
 0003e620:·2020·656e·7375·7265·203d·2667·743b·2027····ensure·=&gt;·'
 0003e630:·696e·7374·616c·6c65·6427·2c0a·2020·7d0a··installed',.··}.
 0003e640:·7d0a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··}.</code></pre><
 0003e650:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b
 0003e660:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"·
 0003e670:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col
 0003e680:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ
 0003e690:·6574·3d22·2369·646d·3331·3930·2220·7461··et="#idm3190"·ta
 0003e6a0:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
 0003e6b0:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
 0003e6c0:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
 0003e6d0:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
 0003e6e0:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
 0003e6f0:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
 0003e700:·5368·656c·6c20·7363·7269·7074·20e2·87b2··Shell·script·...
 0003e710:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
 0003e720:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
 0003e730:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
 0003e740:·2269·646d·3331·3930·223e·3c74·6162·6c65··"idm3190"><table
 0003e750:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta
 0003e760:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl
 0003e770:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table
Max diff block lines reached; 312542/330648 bytes (94.52%) of diff not shown.
34.1 KB
html2text {}
    
Offset 223, 21 lines modifiedOffset 223, 14 lines modified
223 ··-·PCI-DSSv4-11.5.2223 ··-·PCI-DSSv4-11.5.2
224 ··-·enable_strategy224 ··-·enable_strategy
225 ··-·low_complexity225 ··-·low_complexity
226 ··-·low_disruption226 ··-·low_disruption
227 ··-·medium_severity227 ··-·medium_severity
228 ··-·no_reboot_needed228 ··-·no_reboot_needed
229 ··-·package_aide_installed229 ··-·package_aide_installed
230 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
231 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
232 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
233 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
234 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
235 package·--add=aide 
236 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8230 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
237 [[packages]]231 [[packages]]
238 name·=·"aide"232 name·=·"aide"
239 version·=·"*"233 version·=·"*"
240 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8234 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
241 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low235 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 262, 14 lines modifiedOffset 255, 21 lines modified
262 if·!·rpm·-q·--quiet·"aide"·;·then255 if·!·rpm·-q·--quiet·"aide"·;·then
263 ····dnf·install·-y·"aide"256 ····dnf·install·-y·"aide"
264 fi257 fi
  
265 else258 else
266 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'259 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
267 fi260 fi
 261 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 262 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 263 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 264 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 265 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 266 package·--add=aide
268 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*267 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
269 Run·the·following·command·to·generate·a·new·database:268 Run·the·following·command·to·generate·a·new·database:
270 $·sudo·/usr/sbin/aide·--init269 $·sudo·/usr/sbin/aide·--init
271 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/270 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/
272 aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides271 aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides
273 additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:272 additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
274 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz273 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
Offset 1524, 21 lines modifiedOffset 1524, 14 lines modified
1524 ··-·PCI-DSSv4-2.2.61524 ··-·PCI-DSSv4-2.2.6
1525 ··-·enable_strategy1525 ··-·enable_strategy
1526 ··-·low_complexity1526 ··-·low_complexity
1527 ··-·low_disruption1527 ··-·low_disruption
1528 ··-·medium_severity1528 ··-·medium_severity
1529 ··-·no_reboot_needed1529 ··-·no_reboot_needed
1530 ··-·package_sudo_installed1530 ··-·package_sudo_installed
1531 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
1532 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
1533 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
1534 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
1535 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
1536 package·--add=sudo 
1537 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81531 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
1538 [[packages]]1532 [[packages]]
1539 name·=·"sudo"1533 name·=·"sudo"
1540 version·=·"*"1534 version·=·"*"
1541 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81535 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1542 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1536 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 1563, 14 lines modifiedOffset 1556, 21 lines modified
1563 if·!·rpm·-q·--quiet·"sudo"·;·then1556 if·!·rpm·-q·--quiet·"sudo"·;·then
1564 ····dnf·install·-y·"sudo"1557 ····dnf·install·-y·"sudo"
1565 fi1558 fi
  
1566 else1559 else
1567 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'1560 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
1568 fi1561 fi
 1562 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 1563 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1564 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1565 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1566 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 1567 package·--add=sudo
1569 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·O\x8On\x8nl\x8ly\x8y·U\x8Us\x8se\x8er\x8rs\x8s·L\x8Lo\x8og\x8gg\x8ge\x8ed\x8d·I\x8In\x8n·T\x8To\x8o·R\x8Re\x8ea\x8al\x8l·t\x8tt\x8ty\x8y·C\x8Ca\x8an\x8n·E\x8Ex\x8xe\x8ec\x8cu\x8ut\x8te\x8e·S\x8Su\x8ud\x8do\x8o·-\x8-·s\x8su\x8ud\x8do\x8o·u\x8us\x8se\x8e_\x8_p\x8pt\x8ty\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*1568 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·O\x8On\x8nl\x8ly\x8y·U\x8Us\x8se\x8er\x8rs\x8s·L\x8Lo\x8og\x8gg\x8ge\x8ed\x8d·I\x8In\x8n·T\x8To\x8o·R\x8Re\x8ea\x8al\x8l·t\x8tt\x8ty\x8y·C\x8Ca\x8an\x8n·E\x8Ex\x8xe\x8ec\x8cu\x8ut\x8te\x8e·S\x8Su\x8ud\x8do\x8o·-\x8-·s\x8su\x8ud\x8do\x8o·u\x8us\x8se\x8e_\x8_p\x8pt\x8ty\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
1570 The·sudo·use_pty·tag,·when·specified,·will·only·execute·sudo·commands·from·users·logged·in·to·a·real·tty.·This·should·be·enabled·by1569 The·sudo·use_pty·tag,·when·specified,·will·only·execute·sudo·commands·from·users·logged·in·to·a·real·tty.·This·should·be·enabled·by
1571 making·sure·that·the·use_pty·tag·exists·in·/etc/sudoers·configuration·file·or·any·sudo·configuration·snippets·in·/etc/sudoers.d/.1570 making·sure·that·the·use_pty·tag·exists·in·/etc/sudoers·configuration·file·or·any·sudo·configuration·snippets·in·/etc/sudoers.d/.
1572 Rationale:··Requiring·that·sudo·commands·be·run·in·a·pseudo-terminal·can·prevent·an·attacker·from·retaining·access·to·the·user's1571 Rationale:··Requiring·that·sudo·commands·be·run·in·a·pseudo-terminal·can·prevent·an·attacker·from·retaining·access·to·the·user's
1573 ············terminal·after·the·main·program·has·finished·executing.1572 ············terminal·after·the·main·program·has·finished·executing.
1574 Severity: ··medium1573 Severity: ··medium
1575 Rule·ID:····xccdf_org.ssgproject.content_rule_sudo_add_use_pty1574 Rule·ID:····xccdf_org.ssgproject.content_rule_sudo_add_use_pty
Offset 2104, 21 lines modifiedOffset 2104, 14 lines modified
2104 ··-·PCI-DSSv4-3.5.1.22104 ··-·PCI-DSSv4-3.5.1.2
2105 ··-·enable_strategy2105 ··-·enable_strategy
2106 ··-·low_complexity2106 ··-·low_complexity
2107 ··-·low_disruption2107 ··-·low_disruption
2108 ··-·medium_severity2108 ··-·medium_severity
2109 ··-·no_reboot_needed2109 ··-·no_reboot_needed
2110 ··-·package_cryptsetup-luks_installed2110 ··-·package_cryptsetup-luks_installed
2111 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
2112 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
2113 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
2114 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
2115 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
2116 package·--add=cryptsetup 
2117 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x82111 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
2118 [[packages]]2112 [[packages]]
2119 name·=·"cryptsetup"2113 name·=·"cryptsetup"
2120 version·=·"*"2114 version·=·"*"
2121 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x82115 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
2122 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low2116 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 2137, 14 lines modifiedOffset 2130, 21 lines modified
2137 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low2130 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
2138 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false2131 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
2139 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable2132 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
2140 if·!·rpm·-q·--quiet·"cryptsetup"·;·then2133 if·!·rpm·-q·--quiet·"cryptsetup"·;·then
2141 ····dnf·install·-y·"cryptsetup"2134 ····dnf·install·-y·"cryptsetup"
2142 fi2135 fi
 2136 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 2137 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 2138 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 2139 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 2140 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 2141 package·--add=cryptsetup
2143 Group  ·Updating·Software·  Group·contains·4·rules2142 Group  ·Updating·Software·  Group·contains·4·rules
2144 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·dnf·command·line·tool·is·used·to·install·and·update·software·packages.·The·system·also·provides·a·graphical·software·update2143 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·dnf·command·line·tool·is·used·to·install·and·update·software·packages.·The·system·also·provides·a·graphical·software·update
2145 tool·in·the·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·menu,·in·the·A\x8Ad\x8dm\x8mi\x8in\x8ni\x8is\x8st\x8tr\x8ra\x8at\x8ti\x8io\x8on\x8n·submenu,·called·S\x8So\x8of\x8ft\x8tw\x8wa\x8ar\x8re\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8e.2144 tool·in·the·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·menu,·in·the·A\x8Ad\x8dm\x8mi\x8in\x8ni\x8is\x8st\x8tr\x8ra\x8at\x8ti\x8io\x8on\x8n·submenu,·called·S\x8So\x8of\x8ft\x8tw\x8wa\x8ar\x8re\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8e.
Max diff block lines reached; 29561/34937 bytes (84.61%) of diff not shown.
1.18 MB
./usr/share/doc/ssg-nondebian/ssg-centos8-guide-anssi_bp28_enhanced.html
    
Offset 15396, 207 lines modifiedOffset 15396, 207 lines modified
0003c230:·6574·3d22·2369·646d·3830·3133·2220·7461··et="#idm8013"·ta0003c230:·6574·3d22·2369·646d·3830·3133·2220·7461··et="#idm8013"·ta
0003c240:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=0003c240:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
0003c250:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex0003c250:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
0003c260:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t0003c260:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
0003c270:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t0003c270:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
0003c280:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="0003c280:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
0003c290:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·0003c290:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
 0003c2a0:·4f53·4275·696c·6420·426c·7565·7072·696e··OSBuild·Blueprin
 0003c2b0:·7420·736e·6970·7065·7420·e287·b23c·2f61··t·snippet·...</a
 0003c2c0:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
 0003c2d0:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
 0003c2e0:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
 0003c2f0:·6d38·3031·3322·3e3c·7072·653e·3c63·6f64··m8013"><pre><cod
 0003c300:·653e·0a5b·5b70·6163·6b61·6765·735d·5d0a··e>.[[packages]].
 0003c310:·6e61·6d65·203d·2022·6169·6465·220a·7665··name·=·"aide".ve
 0003c320:·7273·696f·6e20·3d20·222a·220a·3c2f·636f··rsion·=·"*".</co
0003c2a0:·7363·7269·7074·20e2·87b2·3c2f·613e·3c62··script·...</a><b 
0003c2b0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa 
0003c2c0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col 
0003c2d0:·6c61·7073·6522·2069·643d·2269·646d·3830··lapse"·id="idm80 
0003c2e0:·3133·223e·3c74·6162·6c65·2063·6c61·7373··13"><table·class 
0003c2f0:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st 
0003c300:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord 
0003c310:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde 
0003c320:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co 
0003c330:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t 
0003c340:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr>< 
0003c350:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio 
0003c360:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</ 
0003c370:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
0003c380:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td> 
0003c390:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr>< 
0003c3a0:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy: 
0003c3b0:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable< 
0003c3c0:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table 
0003c3d0:·3e3c·7072·653e·3c63·6f64·653e·0a64·6e66··><pre><code>.dnf 
0003c3e0:·2069·6e73·7461·6c6c·2061·6964·650a·3c2f···install·aide.</ 
0003c3f0:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div0003c330:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div><
0003c400:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b0003c340:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn
0003c410:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data0003c350:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t
0003c420:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps0003c360:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse"
0003c430:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="0003c370:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i
0003c440:·2369·646d·3830·3134·2220·7461·6269·6e64··#idm8014"·tabind0003c380:·646d·3830·3134·2220·7461·6269·6e64·6578··dm8014"·tabindex
0003c450:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but0003c390:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto
0003c460:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand0003c3a0:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded
0003c470:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title0003c3b0:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="
0003c480:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re0003c3c0:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve
0003c490:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">0003c3d0:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re
0003c4a0:·5265·6d65·6469·6174·696f·6e20·416e·6163··Remediation·Anac0003c3e0:·6d65·6469·6174·696f·6e20·5075·7070·6574··mediation·Puppet
0003c4b0:·6f6e·6461·2073·6e69·7070·6574·20e2·87b2··onda·snippet·...0003c3f0:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>
0003c4c0:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla0003c400:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="
0003c4d0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap0003c410:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c
0003c4e0:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=0003c420:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm
0003c4f0:·2269·646d·3830·3134·223e·3c74·6162·6c65··"idm8014"><table0003c430:·3830·3134·223e·3c74·6162·6c65·2063·6c61··8014"><table·cla
0003c500:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta0003c440:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-
0003c510:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl0003c450:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo
0003c520:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table0003c460:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con
0003c530:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>0003c470:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>
0003c540:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<0003c480:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>
0003c550:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>0003c490:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
0003c560:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis0003c4a0:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt
0003c570:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td0003c4b0:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low
0003c580:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t0003c4c0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
0003c590:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t0003c4d0:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t
0003c5a0:·683e·3c74·643e·6661·6c73·653c·2f74·643e··h><td>false</td> 
0003c5b0:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str 
0003c5c0:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e 
0003c5d0:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr><0003c4e0:·643e·6661·6c73·653c·2f74·643e·3c2f·7472··d>false</td></tr
 0003c4f0:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg
 0003c500:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl
0003c5e0:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod 
0003c5f0:·653e·0a70·6163·6b61·6765·202d·2d61·6464··e>.package·--add 
0003c600:·3d61·6964·650a·3c2f·636f·6465·3e3c·2f70··=aide.</code></p 
0003c610:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas 
0003c620:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe 
0003c630:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle= 
0003c640:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data- 
0003c650:·7461·7267·6574·3d22·2369·646d·3830·3135··target="#idm8015 
0003c660:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r 
0003c670:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari 
0003c680:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals 
0003c690:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa 
0003c6a0:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr 
0003c6b0:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat 
0003c6c0:·696f·6e20·4f53·4275·696c·6420·426c·7565··ion·OSBuild·Blue 
0003c6d0:·7072·696e·7420·736e·6970·7065·7420·e287··print·snippet·.. 
0003c6e0:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl 
0003c6f0:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla 
0003c700:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id 
0003c710:·3d22·6964·6d38·3031·3522·3e3c·7072·653e··="idm8015"><pre> 
0003c720:·3c63·6f64·653e·0a5b·5b70·6163·6b61·6765··<code>.[[package 
0003c730:·735d·5d0a·6e61·6d65·203d·2022·6169·6465··s]].name·=·"aide 
0003c740:·220a·7665·7273·696f·6e20·3d20·222a·220a··".version·=·"*". 
0003c750:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d 
0003c760:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn 
0003c770:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da 
0003c780:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla 
0003c790:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target 
0003c7a0:·3d22·2369·646d·3830·3136·2220·7461·6269··="#idm8016"·tabi 
0003c7b0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b 
0003c7c0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa 
0003c7d0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit 
0003c7e0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to· 
0003c7f0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#! 
0003c800:·223e·5265·6d65·6469·6174·696f·6e20·7363··">Remediation·sc 
0003c810:·7269·7074·20e2·87b2·3c2f·613e·3c62·723e··ript·...</a><br> 
0003c820:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane 
0003c830:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla 
0003c840:·7073·6522·2069·643d·2269·646d·3830·3136··pse"·id="idm8016 
0003c850:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class=" 
0003c860:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri 
0003c870:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border 
0003c880:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens 
0003c890:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp 
0003c8a0:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td> 
0003c8b0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr 
0003c8c0:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption: 
0003c8d0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td 
0003c8e0:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re 
0003c8f0:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa 
0003c900:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr0003c510:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab
0003c910:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</ 
0003c920:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t 
0003c930:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table>< 
0003c940:·7072·653e·3c63·6f64·653e·0a70·6163·6b61··pre><code>.packa 
0003c950:·6765·2069·6e73·7461·6c6c·2061·6964·650a··ge·install·aide. 
0003c960:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d 
Max diff block lines reached; 1082424/1109638 bytes (97.55%) of diff not shown.
125 KB
html2text {}
    
Offset 169, 52 lines modifiedOffset 169, 38 lines modified
169 ··-·PCI-DSSv4-11.5.2169 ··-·PCI-DSSv4-11.5.2
170 ··-·enable_strategy170 ··-·enable_strategy
171 ··-·low_complexity171 ··-·low_complexity
172 ··-·low_disruption172 ··-·low_disruption
173 ··-·medium_severity173 ··-·medium_severity
174 ··-·no_reboot_needed174 ··-·no_reboot_needed
175 ··-·package_aide_installed175 ··-·package_aide_installed
176 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
177 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
178 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
179 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
180 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
181 dnf·install·aide 
182 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
183 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
184 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
185 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
186 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
187 package·--add=aide 
188 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8176 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
189 [[packages]]177 [[packages]]
190 name·=·"aide"178 name·=·"aide"
191 version·=·"*"179 version·=·"*"
192 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
193 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
194 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
195 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
196 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
197 package·install·aide 
198 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8180 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
199 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low181 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
200 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low182 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
201 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false183 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
202 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable184 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
203 include·install_aide185 include·install_aide
  
204 class·install_aide·{186 class·install_aide·{
205 ··package·{·'aide':187 ··package·{·'aide':
206 ····ensure·=>·'installed',188 ····ensure·=>·'installed',
207 ··}189 ··}
208 }190 }
 191 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 192 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 193 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 194 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 195 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 196 package·install·aide
209 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8197 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
210 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low198 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
211 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low199 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
212 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false200 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
213 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable201 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
214 #·Remediation·is·applicable·only·in·certain·platforms202 #·Remediation·is·applicable·only·in·certain·platforms
215 if·rpm·--quiet·-q·kernel;·then203 if·rpm·--quiet·-q·kernel;·then
Offset 222, 14 lines modifiedOffset 208, 28 lines modified
222 if·!·rpm·-q·--quiet·"aide"·;·then208 if·!·rpm·-q·--quiet·"aide"·;·then
223 ····yum·install·-y·"aide"209 ····yum·install·-y·"aide"
224 fi210 fi
  
225 else211 else
226 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'212 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
227 fi213 fi
 214 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 215 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 216 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 217 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 218 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 219 package·--add=aide
 220 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 221 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 222 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 223 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 224 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 225 dnf·install·aide
228 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*226 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
229 Run·the·following·command·to·generate·a·new·database:227 Run·the·following·command·to·generate·a·new·database:
230 $·sudo·/usr/sbin/aide·--init228 $·sudo·/usr/sbin/aide·--init
231 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:229 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
232 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz230 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
233 To·initiate·a·manual·check,·run·the·following·command:231 To·initiate·a·manual·check,·run·the·following·command:
234 $·sudo·/usr/sbin/aide·--check232 $·sudo·/usr/sbin/aide·--check
Offset 370, 26 lines modifiedOffset 370, 26 lines modified
370 If·a·system·has·already·been·installed,·and·the·default·partitioning·scheme·was·used,·it·is·possible·but·nontrivial·to·modify·it·to·create·separate·logical·volumes·for·the·directories·listed·above.·The·Logical·Volume·Manager·(LVM)·makes·this·possible.370 If·a·system·has·already·been·installed,·and·the·default·partitioning·scheme·was·used,·it·is·possible·but·nontrivial·to·modify·it·to·create·separate·logical·volumes·for·the·directories·listed·above.·The·Logical·Volume·Manager·(LVM)·makes·this·possible.
371 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/b\x8bo\x8oo\x8ot\x8t·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*371 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/b\x8bo\x8oo\x8ot\x8t·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
372 It·is·recommended·that·the·/boot·directory·resides·on·a·separate·partition.·This·makes·it·easier·to·apply·restrictions·e.g.·through·the·noexec·mount·option.·Eventually,·the·/boot·partition·can·be·configured·not·to·be·mounted·automatically·with·the·noauto·mount·option.372 It·is·recommended·that·the·/boot·directory·resides·on·a·separate·partition.·This·makes·it·easier·to·apply·restrictions·e.g.·through·the·noexec·mount·option.·Eventually,·the·/boot·partition·can·be·configured·not·to·be·mounted·automatically·with·the·noauto·mount·option.
373 Rationale:··The·/boot·partition·contains·the·kernel·and·bootloader·files.·Access·to·this·partition·should·be·restricted.373 Rationale:··The·/boot·partition·contains·the·kernel·and·bootloader·files.·Access·to·this·partition·should·be·restricted.
374 Severity: ··medium374 Severity: ··medium
375 Rule·ID:····xccdf_org.ssgproject.content_rule_partition_for_boot375 Rule·ID:····xccdf_org.ssgproject.content_rule_partition_for_boot
376 References:·_\x8a_\x8n_\x8s_\x8s_\x8i·R28376 References:·_\x8a_\x8n_\x8s_\x8s_\x8i·R28
 377 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 378 [[customizations.filesystem]]
 379 mountpoint·=·"/boot"
 380 size·=·1073741824
377 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8381 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
378 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low382 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
379 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high383 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high
380 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false384 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
381 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable385 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
382 part·/boot386 part·/boot
383 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
384 [[customizations.filesystem]] 
385 mountpoint·=·"/boot" 
386 size·=·1073741824 
387 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/h\x8ho\x8om\x8me\x8e·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*387 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/h\x8ho\x8om\x8me\x8e·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
388 If·user·home·directories·will·be·stored·locally,·create·a·separate·partition·for·/home·at·installation·time·(or·migrate·it·later·using·LVM).·If·/home·will·be·mounted·from·another·system·such·as·an·NFS·server,·then·creating·a·separate·partition·is·not·necessary·at·installation·time,·and·the·mountpoint·can·instead·be·configured·later.388 If·user·home·directories·will·be·stored·locally,·create·a·separate·partition·for·/home·at·installation·time·(or·migrate·it·later·using·LVM).·If·/home·will·be·mounted·from·another·system·such·as·an·NFS·server,·then·creating·a·separate·partition·is·not·necessary·at·installation·time,·and·the·mountpoint·can·instead·be·configured·later.
389 Rationale:··Ensuring·that·/home·is·mounted·on·its·own·partition·enables·the·setting·of·more·restrictive·mount·options,·and·also·helps·ensure·that·users·cannot·trivially·fill·partitions·used·for·log·or·audit·data·storage.389 Rationale:··Ensuring·that·/home·is·mounted·on·its·own·partition·enables·the·setting·of·more·restrictive·mount·options,·and·also·helps·ensure·that·users·cannot·trivially·fill·partitions·used·for·log·or·audit·data·storage.
390 Severity: ··low390 Severity: ··low
391 Rule·ID:····xccdf_org.ssgproject.content_rule_partition_for_home391 Rule·ID:····xccdf_org.ssgproject.content_rule_partition_for_home
392 ············_\x8c_\x8i_\x8s_\x8-_\x8c_\x8s_\x8c········12,·15,·8392 ············_\x8c_\x8i_\x8s_\x8-_\x8c_\x8s_\x8c········12,·15,·8
393 ············_\x8c_\x8o_\x8b_\x8i_\x8t_\x85·········APO13.01,·DSS05.02393 ············_\x8c_\x8o_\x8b_\x8i_\x8t_\x85·········APO13.01,·DSS05.02
Offset 398, 92 lines modifiedOffset 398, 92 lines modified
398 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.3398 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.3
399 References:·_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)399 References:·_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)
400 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4400 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4
401 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227401 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
402 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R28402 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R28
403 ············_\x8c_\x8i_\x8s············1.1.2.3.1403 ············_\x8c_\x8i_\x8s············1.1.2.3.1
Max diff block lines reached; 121855/128206 bytes (95.05%) of diff not shown.
1.27 MB
./usr/share/doc/ssg-nondebian/ssg-centos8-guide-anssi_bp28_high.html
    
Offset 15401, 207 lines modifiedOffset 15401, 207 lines modified
0003c280:·6172·6765·743d·2223·6964·6d38·3031·3322··arget="#idm8013"0003c280:·6172·6765·743d·2223·6964·6d38·3031·3322··arget="#idm8013"
0003c290:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro0003c290:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro
0003c2a0:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria0003c2a0:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria
0003c2b0:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false0003c2b0:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false
0003c2c0:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat0003c2c0:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat
0003c2d0:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre0003c2d0:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre
0003c2e0:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati0003c2e0:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati
 0003c2f0:·6f6e·204f·5342·7569·6c64·2042·6c75·6570··on·OSBuild·Bluep
 0003c300:·7269·6e74·2073·6e69·7070·6574·20e2·87b2··rint·snippet·...
 0003c310:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
 0003c320:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
 0003c330:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
 0003c340:·2269·646d·3830·3133·223e·3c70·7265·3e3c··"idm8013"><pre><
 0003c350:·636f·6465·3e0a·5b5b·7061·636b·6167·6573··code>.[[packages
 0003c360:·5d5d·0a6e·616d·6520·3d20·2261·6964·6522··]].name·=·"aide"
 0003c370:·0a76·6572·7369·6f6e·203d·2022·2a22·0a3c··.version·=·"*".<
0003c2f0:·6f6e·2073·6372·6970·7420·e287·b23c·2f61··on·script·...</a 
0003c300:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class= 
0003c310:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse· 
0003c320:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id 
0003c330:·6d38·3031·3322·3e3c·7461·626c·6520·636c··m8013"><table·cl 
0003c340:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table 
0003c350:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b 
0003c360:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co 
0003c370:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th 
0003c380:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th 
0003c390:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t 
0003c3a0:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup 
0003c3b0:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo 
0003c3c0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr>< 
0003c3d0:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th>< 
0003c3e0:·7464·3e66·616c·7365·3c2f·7464·3e3c·2f74··td>false</td></t 
0003c3f0:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate 
0003c400:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab 
0003c410:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta 
0003c420:·626c·653e·3c70·7265·3e3c·636f·6465·3e0a··ble><pre><code>. 
0003c430:·646e·6620·696e·7374·616c·6c20·6169·6465··dnf·install·aide 
0003c440:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></0003c380:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di
0003c450:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt0003c390:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn·
0003c460:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d0003c3a0:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat
0003c470:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll0003c3b0:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap
0003c480:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe0003c3c0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
0003c490:·743d·2223·6964·6d38·3031·3422·2074·6162··t="#idm8014"·tab0003c3d0:·2223·6964·6d38·3031·3422·2074·6162·696e··"#idm8014"·tabin
0003c4a0:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="0003c3e0:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
0003c4b0:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp0003c3f0:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
0003c4c0:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti0003c400:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
0003c4d0:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to0003c410:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
0003c4e0:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#0003c420:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
0003c4f0:·2122·3e52·656d·6564·6961·7469·6f6e·2041··!">Remediation·A0003c430:·3e52·656d·6564·6961·7469·6f6e·2050·7570··>Remediation·Pup
0003c500:·6e61·636f·6e64·6120·736e·6970·7065·7420··naconda·snippet·0003c440:·7065·7420·736e·6970·7065·7420·e287·b23c··pet·snippet·...<
0003c510:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·0003c450:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas
0003c520:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col0003c460:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps
0003c530:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"· 
0003c540:·6964·3d22·6964·6d38·3031·3422·3e3c·7461··id="idm8014"><ta 
0003c550:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table 
0003c560:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t 
0003c570:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta 
0003c580:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed">< 
0003c590:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit 
0003c5a0:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</ 
0003c5b0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
0003c5c0:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th> 
0003c5d0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
0003c5e0:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot: 
0003c5f0:·3c2f·7468·3e3c·7464·3e66·616c·7365·3c2f··</th><td>false</ 
0003c600:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
0003c610:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t 
0003c620:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t 
0003c630:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre>< 
0003c640:·636f·6465·3e0a·7061·636b·6167·6520·2d2d··code>.package·-- 
0003c650:·6164·643d·6169·6465·0a3c·2f63·6f64·653e··add=aide.</code> 
0003c660:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c 
0003c670:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su 
0003c680:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg 
0003c690:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da0003c470:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="
 0003c480:·6964·6d38·3031·3422·3e3c·7461·626c·6520··idm8014"><table·
0003c6a0:·7461·2d74·6172·6765·743d·2223·6964·6d38··ta-target="#idm8 
0003c6b0:·3031·3522·2074·6162·696e·6465·783d·2230··015"·tabindex="0 
0003c6c0:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"· 
0003c6d0:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f 
0003c6e0:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act 
0003c6f0:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal" 
0003c700:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed 
0003c710:·6961·7469·6f6e·204f·5342·7569·6c64·2042··iation·OSBuild·B 
0003c720:·6c75·6570·7269·6e74·2073·6e69·7070·6574··lueprint·snippet 
0003c730:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div 
0003c740:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co 
0003c750:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse" 
0003c760:·2069·643d·2269·646d·3830·3135·223e·3c70···id="idm8015"><p 
0003c770:·7265·3e3c·636f·6465·3e0a·5b5b·7061·636b··re><code>.[[pack 
0003c780:·6167·6573·5d5d·0a6e·616d·6520·3d20·2261··ages]].name·=·"a 
0003c790:·6964·6522·0a76·6572·7369·6f6e·203d·2022··ide".version·=·" 
0003c7a0:·2a22·0a3c·2f63·6f64·653e·3c2f·7072·653e··*".</code></pre> 
0003c7b0:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class=" 
0003c7c0:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success" 
0003c7d0:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co 
0003c7e0:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar 
0003c7f0:·6765·743d·2223·6964·6d38·3031·3622·2074··get="#idm8016"·t 
0003c800:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role 
0003c810:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e 
0003c820:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"· 
0003c830:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate· 
0003c840:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href= 
0003c850:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation 
0003c860:·2073·6372·6970·7420·e287·b23c·2f61·3e3c···script·...</a>< 
0003c870:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p 
0003c880:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co 
0003c890:·6c6c·6170·7365·2220·6964·3d22·6964·6d38··llapse"·id="idm8 
0003c8a0:·3031·3622·3e3c·7461·626c·6520·636c·6173··016"><table·clas 
0003c8b0:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s0003c490:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab
0003c8c0:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor0003c4a0:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table
0003c8d0:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond0003c4b0:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-
0003c8e0:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C0003c4c0:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><
0003c8f0:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><0003c4d0:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</
0003c900:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>0003c4e0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
0003c910:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti0003c4f0:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr
0003c920:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<0003c500:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>
0003c930:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th0003c510:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
0003c940:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td0003c520:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th
 0003c530:·3e3c·7464·3e66·616c·7365·3c2f·7464·3e3c··><td>false</td><
 0003c540:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra
 0003c550:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en
0003c950:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr>0003c560:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></
0003c960:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy 
0003c970:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable 
0003c980:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl 
0003c990:·653e·3c70·7265·3e3c·636f·6465·3e0a·7061··e><pre><code>.pa0003c570:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code
Max diff block lines reached; 1166211/1193425 bytes (97.72%) of diff not shown.
135 KB
html2text {}
    
Offset 170, 52 lines modifiedOffset 170, 38 lines modified
170 ··-·PCI-DSSv4-11.5.2170 ··-·PCI-DSSv4-11.5.2
171 ··-·enable_strategy171 ··-·enable_strategy
172 ··-·low_complexity172 ··-·low_complexity
173 ··-·low_disruption173 ··-·low_disruption
174 ··-·medium_severity174 ··-·medium_severity
175 ··-·no_reboot_needed175 ··-·no_reboot_needed
176 ··-·package_aide_installed176 ··-·package_aide_installed
177 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
178 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
179 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
180 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
181 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
182 dnf·install·aide 
183 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
184 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
185 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
186 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
187 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
188 package·--add=aide 
189 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8177 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
190 [[packages]]178 [[packages]]
191 name·=·"aide"179 name·=·"aide"
192 version·=·"*"180 version·=·"*"
193 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
194 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
195 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
196 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
197 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
198 package·install·aide 
199 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8181 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
200 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low182 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
201 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low183 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
202 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false184 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
203 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable185 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
204 include·install_aide186 include·install_aide
  
205 class·install_aide·{187 class·install_aide·{
206 ··package·{·'aide':188 ··package·{·'aide':
207 ····ensure·=>·'installed',189 ····ensure·=>·'installed',
208 ··}190 ··}
209 }191 }
 192 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 193 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 194 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 195 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 196 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 197 package·install·aide
210 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8198 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
211 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low199 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
212 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low200 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
213 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false201 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
214 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable202 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
215 #·Remediation·is·applicable·only·in·certain·platforms203 #·Remediation·is·applicable·only·in·certain·platforms
216 if·rpm·--quiet·-q·kernel;·then204 if·rpm·--quiet·-q·kernel;·then
Offset 223, 14 lines modifiedOffset 209, 28 lines modified
223 if·!·rpm·-q·--quiet·"aide"·;·then209 if·!·rpm·-q·--quiet·"aide"·;·then
224 ····yum·install·-y·"aide"210 ····yum·install·-y·"aide"
225 fi211 fi
  
226 else212 else
227 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'213 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
228 fi214 fi
 215 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 216 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 217 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 218 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 219 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 220 package·--add=aide
 221 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 222 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 223 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 224 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 225 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 226 dnf·install·aide
229 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*227 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
230 Run·the·following·command·to·generate·a·new·database:228 Run·the·following·command·to·generate·a·new·database:
231 $·sudo·/usr/sbin/aide·--init229 $·sudo·/usr/sbin/aide·--init
232 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:230 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
233 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz231 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
234 To·initiate·a·manual·check,·run·the·following·command:232 To·initiate·a·manual·check,·run·the·following·command:
235 $·sudo·/usr/sbin/aide·--check233 $·sudo·/usr/sbin/aide·--check
Offset 876, 26 lines modifiedOffset 876, 26 lines modified
876 If·a·system·has·already·been·installed,·and·the·default·partitioning·scheme·was·used,·it·is·possible·but·nontrivial·to·modify·it·to·create·separate·logical·volumes·for·the·directories·listed·above.·The·Logical·Volume·Manager·(LVM)·makes·this·possible.876 If·a·system·has·already·been·installed,·and·the·default·partitioning·scheme·was·used,·it·is·possible·but·nontrivial·to·modify·it·to·create·separate·logical·volumes·for·the·directories·listed·above.·The·Logical·Volume·Manager·(LVM)·makes·this·possible.
877 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/b\x8bo\x8oo\x8ot\x8t·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*877 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/b\x8bo\x8oo\x8ot\x8t·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
878 It·is·recommended·that·the·/boot·directory·resides·on·a·separate·partition.·This·makes·it·easier·to·apply·restrictions·e.g.·through·the·noexec·mount·option.·Eventually,·the·/boot·partition·can·be·configured·not·to·be·mounted·automatically·with·the·noauto·mount·option.878 It·is·recommended·that·the·/boot·directory·resides·on·a·separate·partition.·This·makes·it·easier·to·apply·restrictions·e.g.·through·the·noexec·mount·option.·Eventually,·the·/boot·partition·can·be·configured·not·to·be·mounted·automatically·with·the·noauto·mount·option.
879 Rationale:··The·/boot·partition·contains·the·kernel·and·bootloader·files.·Access·to·this·partition·should·be·restricted.879 Rationale:··The·/boot·partition·contains·the·kernel·and·bootloader·files.·Access·to·this·partition·should·be·restricted.
880 Severity: ··medium880 Severity: ··medium
881 Rule·ID:····xccdf_org.ssgproject.content_rule_partition_for_boot881 Rule·ID:····xccdf_org.ssgproject.content_rule_partition_for_boot
882 References:·_\x8a_\x8n_\x8s_\x8s_\x8i·R28882 References:·_\x8a_\x8n_\x8s_\x8s_\x8i·R28
 883 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 884 [[customizations.filesystem]]
 885 mountpoint·=·"/boot"
 886 size·=·1073741824
883 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8887 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
884 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low888 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
885 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high889 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high
886 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false890 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
887 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable891 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
888 part·/boot892 part·/boot
889 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
890 [[customizations.filesystem]] 
891 mountpoint·=·"/boot" 
892 size·=·1073741824 
893 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/h\x8ho\x8om\x8me\x8e·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*893 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/h\x8ho\x8om\x8me\x8e·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
894 If·user·home·directories·will·be·stored·locally,·create·a·separate·partition·for·/home·at·installation·time·(or·migrate·it·later·using·LVM).·If·/home·will·be·mounted·from·another·system·such·as·an·NFS·server,·then·creating·a·separate·partition·is·not·necessary·at·installation·time,·and·the·mountpoint·can·instead·be·configured·later.894 If·user·home·directories·will·be·stored·locally,·create·a·separate·partition·for·/home·at·installation·time·(or·migrate·it·later·using·LVM).·If·/home·will·be·mounted·from·another·system·such·as·an·NFS·server,·then·creating·a·separate·partition·is·not·necessary·at·installation·time,·and·the·mountpoint·can·instead·be·configured·later.
895 Rationale:··Ensuring·that·/home·is·mounted·on·its·own·partition·enables·the·setting·of·more·restrictive·mount·options,·and·also·helps·ensure·that·users·cannot·trivially·fill·partitions·used·for·log·or·audit·data·storage.895 Rationale:··Ensuring·that·/home·is·mounted·on·its·own·partition·enables·the·setting·of·more·restrictive·mount·options,·and·also·helps·ensure·that·users·cannot·trivially·fill·partitions·used·for·log·or·audit·data·storage.
896 Severity: ··low896 Severity: ··low
897 Rule·ID:····xccdf_org.ssgproject.content_rule_partition_for_home897 Rule·ID:····xccdf_org.ssgproject.content_rule_partition_for_home
898 ············_\x8c_\x8i_\x8s_\x8-_\x8c_\x8s_\x8c········12,·15,·8898 ············_\x8c_\x8i_\x8s_\x8-_\x8c_\x8s_\x8c········12,·15,·8
899 ············_\x8c_\x8o_\x8b_\x8i_\x8t_\x85·········APO13.01,·DSS05.02899 ············_\x8c_\x8o_\x8b_\x8i_\x8t_\x85·········APO13.01,·DSS05.02
Offset 904, 92 lines modifiedOffset 904, 92 lines modified
904 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.3904 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.3
905 References:·_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)905 References:·_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)
906 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4906 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4
907 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227907 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
908 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R28908 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R28
909 ············_\x8c_\x8i_\x8s············1.1.2.3.1909 ············_\x8c_\x8i_\x8s············1.1.2.3.1
Max diff block lines reached; 131889/138240 bytes (95.41%) of diff not shown.
1.07 MB
./usr/share/doc/ssg-nondebian/ssg-centos8-guide-anssi_bp28_intermediary.html
    
Offset 15391, 208 lines modifiedOffset 15391, 208 lines modified
0003c1e0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=0003c1e0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
0003c1f0:·2223·6964·6d38·3031·3322·2074·6162·696e··"#idm8013"·tabin0003c1f0:·2223·6964·6d38·3031·3322·2074·6162·696e··"#idm8013"·tabin
0003c200:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu0003c200:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
0003c210:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan0003c210:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
0003c220:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl0003c220:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
0003c230:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r0003c230:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
0003c240:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"0003c240:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
0003c250:·3e52·656d·6564·6961·7469·6f6e·2073·6372··>Remediation·scr0003c250:·3e52·656d·6564·6961·7469·6f6e·204f·5342··>Remediation·OSB
 0003c260:·7569·6c64·2042·6c75·6570·7269·6e74·2073··uild·Blueprint·s
 0003c270:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b
 0003c280:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
 0003c290:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
 0003c2a0:·6c61·7073·6522·2069·643d·2269·646d·3830··lapse"·id="idm80
 0003c2b0:·3133·223e·3c70·7265·3e3c·636f·6465·3e0a··13"><pre><code>.
 0003c2c0:·5b5b·7061·636b·6167·6573·5d5d·0a6e·616d··[[packages]].nam
 0003c2d0:·6520·3d20·2261·6964·6522·0a76·6572·7369··e·=·"aide".versi
 0003c2e0:·6f6e·203d·2022·2a22·0a3c·2f63·6f64·653e··on·=·"*".</code>
0003c260:·6970·7420·e287·b23c·2f61·3e3c·6272·3e3c··ipt·...</a><br>< 
0003c270:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel 
0003c280:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap 
0003c290:·7365·2220·6964·3d22·6964·6d38·3031·3322··se"·id="idm8013" 
0003c2a0:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t 
0003c2b0:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip 
0003c2c0:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere 
0003c2d0:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense 
0003c2e0:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl 
0003c2f0:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l 
0003c300:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr> 
0003c310:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:< 
0003c320:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td> 
0003c330:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb 
0003c340:·6f6f·743a·3c2f·7468·3e3c·7464·3e66·616c··oot:</th><td>fal 
0003c350:·7365·3c2f·7464·3e3c·2f74·723e·3c74·723e··se</td></tr><tr> 
0003c360:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t 
0003c370:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td 
0003c380:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p 
0003c390:·7265·3e3c·636f·6465·3e0a·646e·6620·696e··re><code>.dnf·in 
0003c3a0:·7374·616c·6c20·6169·6465·0a3c·2f63·6f64··stall·aide.</cod 
0003c3b0:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a0003c2f0:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c
0003c3c0:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn-0003c300:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su
0003c3d0:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to0003c310:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg
0003c3e0:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"·0003c320:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da
0003c3f0:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id0003c330:·7461·2d74·6172·6765·743d·2223·6964·6d38··ta-target="#idm8
0003c400:·6d38·3031·3422·2074·6162·696e·6465·783d··m8014"·tabindex=0003c340:·3031·3422·2074·6162·696e·6465·783d·2230··014"·tabindex="0
0003c410:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button0003c350:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
0003c420:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=0003c360:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
0003c430:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A0003c370:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
0003c440:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea0003c380:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
0003c450:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem0003c390:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
0003c460:·6564·6961·7469·6f6e·2041·6e61·636f·6e64··ediation·Anacond0003c3a0:·6961·7469·6f6e·2050·7570·7065·7420·736e··iation·Puppet·sn
0003c470:·6120·736e·6970·7065·7420·e287·b23c·2f61··a·snippet·...</a0003c3b0:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br
0003c480:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=0003c3c0:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
0003c490:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·0003c3d0:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
0003c4a0:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id0003c3e0:·6170·7365·2220·6964·3d22·6964·6d38·3031··apse"·id="idm801
0003c4b0:·6d38·3031·3422·3e3c·7461·626c·6520·636c··m8014"><table·cl0003c3f0:·3422·3e3c·7461·626c·6520·636c·6173·733d··4"><table·class=
0003c4c0:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table0003c400:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str
0003c4d0:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b0003c410:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde
0003c4e0:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co0003c420:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden
0003c4f0:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th0003c430:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com
0003c500:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th0003c440:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td
0003c510:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t0003c450:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
0003c520:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup0003c460:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption
0003c530:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo0003c470:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
0003c540:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><0003c480:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e52··d></tr><tr><th>R
0003c550:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th><0003c490:·6562·6f6f·743a·3c2f·7468·3e3c·7464·3e66··eboot:</th><td>f
0003c560:·7464·3e66·616c·7365·3c2f·7464·3e3c·2f74··td>false</td></t 
0003c570:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate 
0003c580:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab 
0003c590:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta0003c4a0:·616c·7365·3c2f·7464·3e3c·2f74·723e·3c74··alse</td></tr><t
0003c5a0:·626c·653e·3c70·7265·3e3c·636f·6465·3e0a··ble><pre><code>. 
0003c5b0:·7061·636b·6167·6520·2d2d·6164·643d·6169··package·--add=ai 
0003c5c0:·6465·0a3c·2f63·6f64·653e·3c2f·7072·653e··de.</code></pre> 
0003c5d0:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class=" 
0003c5e0:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success"0003c4b0:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<
 0003c4c0:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</
 0003c4d0:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table>
 0003c4e0:·3c70·7265·3e3c·636f·6465·3e69·6e63·6c75··<pre><code>inclu
 0003c4f0:·6465·2069·6e73·7461·6c6c·5f61·6964·650a··de·install_aide.
 0003c500:·0a63·6c61·7373·2069·6e73·7461·6c6c·5f61··.class·install_a
 0003c510:·6964·6520·7b0a·2020·7061·636b·6167·6520··ide·{.··package·
 0003c520:·7b20·2761·6964·6527·3a0a·2020·2020·656e··{·'aide':.····en
 0003c530:·7375·7265·203d·2667·743b·2027·696e·7374··sure·=&gt;·'inst
 0003c540:·616c·6c65·6427·2c0a·2020·7d0a·7d0a·3c2f··alled',.··}.}.</
 0003c550:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div
 0003c560:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b
 0003c570:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data
 0003c580:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps
0003c5f0:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co0003c590:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
 0003c5a0:·2369·646d·3830·3135·2220·7461·6269·6e64··#idm8015"·tabind
 0003c5b0:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
 0003c5c0:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
 0003c5d0:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
 0003c5e0:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
 0003c5f0:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
 0003c600:·5265·6d65·6469·6174·696f·6e20·7363·7269··Remediation·scri
 0003c610:·7074·20e2·87b2·3c2f·613e·3c62·723e·3c64··pt·...</a><br><d
0003c600:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar 
0003c610:·6765·743d·2223·6964·6d38·3031·3522·2074··get="#idm8015"·t 
0003c620:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role 
0003c630:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e 
0003c640:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"· 
0003c650:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate· 
0003c660:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href= 
0003c670:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation 
0003c680:·204f·5342·7569·6c64·2042·6c75·6570·7269···OSBuild·Bluepri 
0003c690:·6e74·2073·6e69·7070·6574·20e2·87b2·3c2f··nt·snippet·...</ 
0003c6a0:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class 
0003c6b0:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse 
0003c6c0:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i 
0003c6d0:·646d·3830·3135·223e·3c70·7265·3e3c·636f··dm8015"><pre><co 
0003c6e0:·6465·3e0a·5b5b·7061·636b·6167·6573·5d5d··de>.[[packages]] 
0003c6f0:·0a6e·616d·6520·3d20·2261·6964·6522·0a76··.name·=·"aide".v 
0003c700:·6572·7369·6f6e·203d·2022·2a22·0a3c·2f63··ersion·=·"*".</c 
0003c710:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div> 
0003c720:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt 
0003c730:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data- 
0003c740:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse 
0003c750:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="# 
0003c760:·6964·6d38·3031·3622·2074·6162·696e·6465··idm8016"·tabinde 
0003c770:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt 
0003c780:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande 
0003c790:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title= 
0003c7a0:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev 
0003c7b0:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R 
0003c7c0:·656d·6564·6961·7469·6f6e·2073·6372·6970··emediation·scrip 
0003c7d0:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di 
0003c7e0:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c0003c620:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-
Max diff block lines reached; 987575/1014927 bytes (97.31%) of diff not shown.
101 KB
html2text {}
    
Offset 185, 52 lines modifiedOffset 185, 38 lines modified
185 ··-·PCI-DSSv4-11.5.2185 ··-·PCI-DSSv4-11.5.2
186 ··-·enable_strategy186 ··-·enable_strategy
187 ··-·low_complexity187 ··-·low_complexity
188 ··-·low_disruption188 ··-·low_disruption
189 ··-·medium_severity189 ··-·medium_severity
190 ··-·no_reboot_needed190 ··-·no_reboot_needed
191 ··-·package_aide_installed191 ··-·package_aide_installed
192 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
193 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
194 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
195 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
196 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
197 dnf·install·aide 
198 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
199 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
200 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
201 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
202 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
203 package·--add=aide 
204 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8192 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
205 [[packages]]193 [[packages]]
206 name·=·"aide"194 name·=·"aide"
207 version·=·"*"195 version·=·"*"
208 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
209 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
210 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
211 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
212 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
213 package·install·aide 
214 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8196 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
215 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low197 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
216 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low198 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
217 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false199 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
218 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable200 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
219 include·install_aide201 include·install_aide
  
220 class·install_aide·{202 class·install_aide·{
221 ··package·{·'aide':203 ··package·{·'aide':
222 ····ensure·=>·'installed',204 ····ensure·=>·'installed',
223 ··}205 ··}
224 }206 }
 207 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 208 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 209 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 210 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 211 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 212 package·install·aide
225 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8213 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
226 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low214 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
227 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low215 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
228 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false216 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
229 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable217 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
230 #·Remediation·is·applicable·only·in·certain·platforms218 #·Remediation·is·applicable·only·in·certain·platforms
231 if·rpm·--quiet·-q·kernel;·then219 if·rpm·--quiet·-q·kernel;·then
Offset 238, 14 lines modifiedOffset 224, 28 lines modified
238 if·!·rpm·-q·--quiet·"aide"·;·then224 if·!·rpm·-q·--quiet·"aide"·;·then
239 ····yum·install·-y·"aide"225 ····yum·install·-y·"aide"
240 fi226 fi
  
241 else227 else
242 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'228 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
243 fi229 fi
 230 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 231 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 232 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 233 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 234 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 235 package·--add=aide
 236 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 237 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 238 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 239 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 240 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 241 dnf·install·aide
244 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*242 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
245 Run·the·following·command·to·generate·a·new·database:243 Run·the·following·command·to·generate·a·new·database:
246 $·sudo·/usr/sbin/aide·--init244 $·sudo·/usr/sbin/aide·--init
247 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the245 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the
248 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these246 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these
249 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their247 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their
250 integrity.·The·newly-generated·database·can·be·installed·as·follows:248 integrity.·The·newly-generated·database·can·be·installed·as·follows:
Offset 406, 26 lines modifiedOffset 406, 26 lines modified
406 apply·restrictions·e.g.·through·the·noexec·mount·option.·Eventually,·the·/boot·partition·can·be406 apply·restrictions·e.g.·through·the·noexec·mount·option.·Eventually,·the·/boot·partition·can·be
407 configured·not·to·be·mounted·automatically·with·the·noauto·mount·option.407 configured·not·to·be·mounted·automatically·with·the·noauto·mount·option.
408 Rationale:··The·/boot·partition·contains·the·kernel·and·bootloader·files.·Access·to·this·partition408 Rationale:··The·/boot·partition·contains·the·kernel·and·bootloader·files.·Access·to·this·partition
409 ············should·be·restricted.409 ············should·be·restricted.
410 Severity: ··medium410 Severity: ··medium
411 Rule·ID:····xccdf_org.ssgproject.content_rule_partition_for_boot411 Rule·ID:····xccdf_org.ssgproject.content_rule_partition_for_boot
412 References:·_\x8a_\x8n_\x8s_\x8s_\x8i·R28412 References:·_\x8a_\x8n_\x8s_\x8s_\x8i·R28
 413 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 414 [[customizations.filesystem]]
 415 mountpoint·=·"/boot"
 416 size·=·1073741824
413 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8417 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
414 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low418 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
415 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high419 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high
416 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false420 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
417 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable421 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
418 part·/boot422 part·/boot
419 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
420 [[customizations.filesystem]] 
421 mountpoint·=·"/boot" 
422 size·=·1073741824 
423 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/h\x8ho\x8om\x8me\x8e·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*423 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/h\x8ho\x8om\x8me\x8e·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
424 If·user·home·directories·will·be·stored·locally,·create·a·separate·partition·for·/home·at424 If·user·home·directories·will·be·stored·locally,·create·a·separate·partition·for·/home·at
425 installation·time·(or·migrate·it·later·using·LVM).·If·/home·will·be·mounted·from·another·system·such425 installation·time·(or·migrate·it·later·using·LVM).·If·/home·will·be·mounted·from·another·system·such
426 as·an·NFS·server,·then·creating·a·separate·partition·is·not·necessary·at·installation·time,·and·the426 as·an·NFS·server,·then·creating·a·separate·partition·is·not·necessary·at·installation·time,·and·the
427 mountpoint·can·instead·be·configured·later.427 mountpoint·can·instead·be·configured·later.
428 ············Ensuring·that·/home·is·mounted·on·its·own·partition·enables·the·setting·of·more428 ············Ensuring·that·/home·is·mounted·on·its·own·partition·enables·the·setting·of·more
429 Rationale:··restrictive·mount·options,·and·also·helps·ensure·that·users·cannot·trivially·fill429 Rationale:··restrictive·mount·options,·and·also·helps·ensure·that·users·cannot·trivially·fill
Offset 440, 102 lines modifiedOffset 440, 102 lines modified
440 References:·_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.3440 References:·_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.3
441 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)441 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)
442 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4442 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4
443 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227443 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
444 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R28444 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R28
445 ············_\x8c_\x8i_\x8s············1.1.2.3.1445 ············_\x8c_\x8i_\x8s············1.1.2.3.1
Max diff block lines reached; 97780/103231 bytes (94.72%) of diff not shown.
398 KB
./usr/share/doc/ssg-nondebian/ssg-centos8-guide-anssi_bp28_minimal.html
    
Offset 15064, 222 lines modifiedOffset 15064, 222 lines modified
0003ad70:·6172·6765·743d·2223·6964·6d31·3332·3532··arget="#idm132520003ad70:·6172·6765·743d·2223·6964·6d31·3332·3532··arget="#idm13252
0003ad80:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r0003ad80:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r
0003ad90:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari0003ad90:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari
0003ada0:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals0003ada0:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals
0003adb0:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa0003adb0:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa
0003adc0:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr0003adc0:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr
0003add0:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat0003add0:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat
0003ade0:·696f·6e20·7363·7269·7074·20e2·87b2·3c2f··ion·script·...</ 
0003adf0:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class 
0003ae00:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse 
0003ae10:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i 
0003ae20:·646d·3133·3235·3222·3e3c·7461·626c·6520··dm13252"><table· 
0003ae30:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab 
0003ae40:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table 
0003ae50:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table- 
0003ae60:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr>< 
0003ae70:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</ 
0003ae80:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td>< 
0003ae90:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr 
0003aea0:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>0003ade0:·696f·6e20·4f53·4275·696c·6420·426c·7565··ion·OSBuild·Blue
 0003adf0:·7072·696e·7420·736e·6970·7065·7420·e287··print·snippet·..
 0003ae00:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl
 0003ae10:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla
 0003ae20:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id
 0003ae30:·3d22·6964·6d31·3332·3532·223e·3c70·7265··="idm13252"><pre
 0003ae40:·3e3c·636f·6465·3e0a·5b5b·7061·636b·6167··><code>.[[packag
 0003ae50:·6573·5d5d·0a6e·616d·6520·3d20·2264·6e66··es]].name·=·"dnf
 0003ae60:·2d61·7574·6f6d·6174·6963·220a·7665·7273··-automatic".vers
 0003ae70:·696f·6e20·3d20·222a·220a·3c2f·636f·6465··ion·=·"*".</code
 0003ae80:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a·
 0003ae90:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s
 0003aea0:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog
 0003aeb0:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d
 0003aec0:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
 0003aed0:·3133·3235·3322·2074·6162·696e·6465·783d··13253"·tabindex=
 0003aee0:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button
 0003aef0:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=
 0003af00:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A
 0003af10:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea
 0003af20:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem
 0003af30:·6564·6961·7469·6f6e·2050·7570·7065·7420··ediation·Puppet·
 0003af40:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><
 0003af50:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
 0003af60:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
 0003af70:·6c6c·6170·7365·2220·6964·3d22·6964·6d31··llapse"·id="idm1
 0003af80:·3332·3533·223e·3c74·6162·6c65·2063·6c61··3253"><table·cla
 0003af90:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-
 0003afa0:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo
 0003afb0:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con
 0003afc0:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>
 0003afd0:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>
 0003afe0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
 0003aff0:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt
 0003b000:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low
 0003b010:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
 0003b020:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t
 0003b030:·643e·6661·6c73·653c·2f74·643e·3c2f·7472··d>false</td></tr
 0003b040:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg
 0003b050:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl
0003aeb0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr0003b060:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab
 0003b070:·6c65·3e3c·7072·653e·3c63·6f64·653e·696e··le><pre><code>in
 0003b080:·636c·7564·6520·696e·7374·616c·6c5f·646e··clude·install_dn
0003aec0:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th 
0003aed0:·3e3c·7464·3e66·616c·7365·3c2f·7464·3e3c··><td>false</td>< 
0003aee0:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra 
0003aef0:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en 
0003af00:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></ 
0003af10:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code 
0003af20:·3e0a·646e·6620·696e·7374·616c·6c20·646e··>.dnf·install·dn 
0003af30:·662d·6175·746f·6d61·7469·630a·3c2f·636f··f-automatic.</co0003b090:·662d·6175·746f·6d61·7469·630a·0a63·6c61··f-automatic..cla
 0003b0a0:·7373·2069·6e73·7461·6c6c·5f64·6e66·2d61··ss·install_dnf-a
 0003b0b0:·7574·6f6d·6174·6963·207b·0a20·2070·6163··utomatic·{.··pac
 0003b0c0:·6b61·6765·207b·2027·646e·662d·6175·746f··kage·{·'dnf-auto
 0003b0d0:·6d61·7469·6327·3a0a·2020·2020·656e·7375··matic':.····ensu
 0003b0e0:·7265·203d·2667·743b·2027·696e·7374·616c··re·=&gt;·'instal
 0003b0f0:·6c65·6427·2c0a·2020·7d0a·7d0a·3c2f·636f··led',.··}.}.</co
0003af40:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div><0003b100:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div><
0003af50:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn0003b110:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn
0003af60:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t0003b120:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t
0003af70:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse"0003b130:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse"
0003af80:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i0003b140:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i
0003af90:·646d·3133·3235·3322·2074·6162·696e·6465··dm13253"·tabinde0003b150:·646d·3133·3235·3422·2074·6162·696e·6465··dm13254"·tabinde
0003afa0:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt0003b160:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt
0003afb0:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande0003b170:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande
0003afc0:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=0003b180:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=
0003afd0:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev0003b190:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev
0003afe0:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R0003b1a0:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R
0003aff0:·656d·6564·6961·7469·6f6e·2041·6e61·636f··emediation·Anaco0003b1b0:·656d·6564·6961·7469·6f6e·2073·6372·6970··emediation·scrip
 0003b1c0:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di
 0003b1d0:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c
 0003b1e0:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse
 0003b1f0:·2220·6964·3d22·6964·6d31·3332·3534·223e··"·id="idm13254">
 0003b200:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta
 0003b210:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe
 0003b220:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered
 0003b230:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed
 0003b240:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple
 0003b250:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo
 0003b260:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
 0003b270:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</
 0003b280:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
 0003b290:·2f74·723e·3c74·723e·3c74·683e·5265·626f··/tr><tr><th>Rebo
 0003b2a0:·6f74·3a3c·2f74·683e·3c74·643e·6661·6c73··ot:</th><td>fals
0003b000:·6e64·6120·736e·6970·7065·7420·e287·b23c··nda·snippet·...< 
0003b010:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas 
0003b020:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps 
0003b030:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id=" 
0003b040:·6964·6d31·3332·3533·223e·3c74·6162·6c65··idm13253"><table 
0003b050:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta 
0003b060:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl 
0003b070:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table 
0003b080:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr> 
0003b090:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:< 
0003b0a0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td> 
0003b0b0:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis 
0003b0c0:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td 
0003b0d0:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t 
0003b0e0:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t 
0003b0f0:·683e·3c74·643e·6661·6c73·653c·2f74·643e··h><td>false</td> 
0003b100:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str 
0003b110:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e 
0003b120:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr><0003b2b0:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr><
 0003b2c0:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th
 0003b2d0:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td>
 0003b2e0:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr
 0003b2f0:·653e·3c63·6f64·653e·0a70·6163·6b61·6765··e><code>.package
 0003b300:·2069·6e73·7461·6c6c·2064·6e66·2d61·7574···install·dnf-aut
Max diff block lines reached; 335428/364712 bytes (91.97%) of diff not shown.
42.0 KB
html2text {}
    
Offset 143, 52 lines modifiedOffset 143, 38 lines modified
143 ··tags:143 ··tags:
144 ··-·enable_strategy144 ··-·enable_strategy
145 ··-·low_complexity145 ··-·low_complexity
146 ··-·low_disruption146 ··-·low_disruption
147 ··-·medium_severity147 ··-·medium_severity
148 ··-·no_reboot_needed148 ··-·no_reboot_needed
149 ··-·package_dnf-automatic_installed149 ··-·package_dnf-automatic_installed
150 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
151 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
152 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
153 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
154 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
155 dnf·install·dnf-automatic 
156 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
157 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
158 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
159 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
160 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
161 package·--add=dnf-automatic 
162 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8150 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
163 [[packages]]151 [[packages]]
164 name·=·"dnf-automatic"152 name·=·"dnf-automatic"
165 version·=·"*"153 version·=·"*"
166 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
167 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
168 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
169 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
170 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
171 package·install·dnf-automatic 
172 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8154 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
173 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low155 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
174 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low156 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
175 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false157 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
176 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable158 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
177 include·install_dnf-automatic159 include·install_dnf-automatic
  
178 class·install_dnf-automatic·{160 class·install_dnf-automatic·{
179 ··package·{·'dnf-automatic':161 ··package·{·'dnf-automatic':
180 ····ensure·=>·'installed',162 ····ensure·=>·'installed',
181 ··}163 ··}
182 }164 }
 165 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 166 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 167 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 168 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 169 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 170 package·install·dnf-automatic
183 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8171 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
184 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low172 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
185 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low173 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
186 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false174 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
187 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable175 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
188 #·Remediation·is·applicable·only·in·certain·platforms176 #·Remediation·is·applicable·only·in·certain·platforms
189 if·!·(·{·rpm·--quiet·-q·kernel·;}·&&·{·rpm·--quiet·-q·rpm-ostree·;}·&&·{·rpm·--quiet·-177 if·!·(·{·rpm·--quiet·-q·kernel·;}·&&·{·rpm·--quiet·-q·rpm-ostree·;}·&&·{·rpm·--quiet·-
Offset 197, 14 lines modifiedOffset 183, 28 lines modified
197 if·!·rpm·-q·--quiet·"dnf-automatic"·;·then183 if·!·rpm·-q·--quiet·"dnf-automatic"·;·then
198 ····yum·install·-y·"dnf-automatic"184 ····yum·install·-y·"dnf-automatic"
199 fi185 fi
  
200 else186 else
201 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'187 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
202 fi188 fi
 189 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 190 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 191 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 192 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 193 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 194 package·--add=dnf-automatic
 195 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 196 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 197 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 198 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 199 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 200 dnf·install·dnf-automatic
203 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·d\x8dn\x8nf\x8f-\x8-a\x8au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8c·t\x8to\x8o·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·A\x8Av\x8va\x8ai\x8il\x8la\x8ab\x8bl\x8le\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8es\x8s·A\x8Au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8ca\x8al\x8ll\x8ly\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*201 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·d\x8dn\x8nf\x8f-\x8-a\x8au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8c·t\x8to\x8o·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·A\x8Av\x8va\x8ai\x8il\x8la\x8ab\x8bl\x8le\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8es\x8s·A\x8Au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8ca\x8al\x8ll\x8ly\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
204 To·ensure·that·the·packages·comprising·the·available·updates·will·be·automatically·installed202 To·ensure·that·the·packages·comprising·the·available·updates·will·be·automatically·installed
205 by·dnf-automatic,·set·apply_updates·to·yes·under·[commands]·section·in·/etc/dnf/203 by·dnf-automatic,·set·apply_updates·to·yes·under·[commands]·section·in·/etc/dnf/
206 automatic.conf.204 automatic.conf.
207 ············Installing·software·updates·is·a·fundamental·mitigation·against·the·exploitation205 ············Installing·software·updates·is·a·fundamental·mitigation·against·the·exploitation
208 ············of·publicly-known·vulnerabilities.·If·the·most·recent·security·patches·and206 ············of·publicly-known·vulnerabilities.·If·the·most·recent·security·patches·and
209 Rationale:··updates·are·not·installed,·unauthorized·users·may·take·advantage·of·weaknesses·in207 Rationale:··updates·are·not·installed,·unauthorized·users·may·take·advantage·of·weaknesses·in
Offset 10253, 47 lines modifiedOffset 10253, 33 lines modified
10253 ··-·PCI-DSSv4-2.2.410253 ··-·PCI-DSSv4-2.2.4
10254 ··-·disable_strategy10254 ··-·disable_strategy
10255 ··-·low_complexity10255 ··-·low_complexity
10256 ··-·low_disruption10256 ··-·low_disruption
10257 ··-·medium_severity10257 ··-·medium_severity
10258 ··-·no_reboot_needed10258 ··-·no_reboot_needed
10259 ··-·package_dhcp_removed10259 ··-·package_dhcp_removed
10260 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
10261 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
10262 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
10263 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
10264 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable 
  
10265 dnf·remove·dhcp-server 
10266 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
10267 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
10268 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
10269 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
10270 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable 
  
10271 package·--remove=dhcp-server 
10272 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
10273 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
10274 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
10275 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
10276 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable 
  
10277 package·remove·dhcp-server 
10278 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x810260 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
10279 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low10261 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
10280 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low10262 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
10281 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false10263 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
10282 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable10264 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
10283 include·remove_dhcp-server10265 include·remove_dhcp-server
  
10284 class·remove_dhcp-server·{10266 class·remove_dhcp-server·{
10285 ··package·{·'dhcp-server':10267 ··package·{·'dhcp-server':
10286 ····ensure·=>·'purged',10268 ····ensure·=>·'purged',
Max diff block lines reached; 38190/42980 bytes (88.86%) of diff not shown.
1.7 MB
./usr/share/doc/ssg-nondebian/ssg-centos8-guide-cis.html
    
Offset 15448, 208 lines modifiedOffset 15448, 208 lines modified
0003c570:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="0003c570:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
0003c580:·2369·646d·3830·3133·2220·7461·6269·6e64··#idm8013"·tabind0003c580:·2369·646d·3830·3133·2220·7461·6269·6e64··#idm8013"·tabind
0003c590:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but0003c590:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
0003c5a0:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand0003c5a0:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
0003c5b0:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title0003c5b0:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
0003c5c0:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re0003c5c0:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
0003c5d0:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">0003c5d0:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
0003c5e0:·5265·6d65·6469·6174·696f·6e20·7363·7269··Remediation·scri0003c5e0:·5265·6d65·6469·6174·696f·6e20·4f53·4275··Remediation·OSBu
 0003c5f0:·696c·6420·426c·7565·7072·696e·7420·736e··ild·Blueprint·sn
 0003c600:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br
 0003c610:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
 0003c620:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
 0003c630:·6170·7365·2220·6964·3d22·6964·6d38·3031··apse"·id="idm801
 0003c640:·3322·3e3c·7072·653e·3c63·6f64·653e·0a5b··3"><pre><code>.[
 0003c650:·5b70·6163·6b61·6765·735d·5d0a·6e61·6d65··[packages]].name
 0003c660:·203d·2022·6169·6465·220a·7665·7273·696f···=·"aide".versio
 0003c670:·6e20·3d20·222a·220a·3c2f·636f·6465·3e3c··n·=·"*".</code><
0003c5f0:·7074·20e2·87b2·3c2f·613e·3c62·723e·3c64··pt·...</a><br><d 
0003c600:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel- 
0003c610:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps 
0003c620:·6522·2069·643d·2269·646d·3830·3133·223e··e"·id="idm8013"> 
0003c630:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta 
0003c640:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe 
0003c650:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered 
0003c660:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed 
0003c670:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple 
0003c680:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo 
0003c690:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr>< 
0003c6a0:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</ 
0003c6b0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td>< 
0003c6c0:·2f74·723e·3c74·723e·3c74·683e·5265·626f··/tr><tr><th>Rebo 
0003c6d0:·6f74·3a3c·2f74·683e·3c74·643e·6661·6c73··ot:</th><td>fals 
0003c6e0:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr>< 
0003c6f0:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th 
0003c700:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td> 
0003c710:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr 
0003c720:·653e·3c63·6f64·653e·0a64·6e66·2069·6e73··e><code>.dnf·ins 
0003c730:·7461·6c6c·2061·6964·650a·3c2f·636f·6465··tall·aide.</code 
0003c740:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a·0003c680:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl
0003c750:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s0003c690:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc
0003c760:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog0003c6a0:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl
0003c770:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d0003c6b0:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat
0003c780:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm0003c6c0:·612d·7461·7267·6574·3d22·2369·646d·3830··a-target="#idm80
0003c790:·3830·3134·2220·7461·6269·6e64·6578·3d22··8014"·tabindex="0003c6d0:·3134·2220·7461·6269·6e64·6578·3d22·3022··14"·tabindex="0"
0003c7a0:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"0003c6e0:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
0003c7b0:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="0003c6f0:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
0003c7c0:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac0003c700:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
0003c7d0:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal0003c710:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
0003c7e0:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme0003c720:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
0003c7f0:·6469·6174·696f·6e20·416e·6163·6f6e·6461··diation·Anaconda0003c730:·6174·696f·6e20·5075·7070·6574·2073·6e69··ation·Puppet·sni
0003c800:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>0003c740:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>
 0003c750:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
 0003c760:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
 0003c770:·7073·6522·2069·643d·2269·646d·3830·3134··pse"·id="idm8014
0003c810:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="0003c780:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="
0003c820:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c 
0003c830:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm 
0003c840:·3830·3134·223e·3c74·6162·6c65·2063·6c61··8014"><table·cla 
0003c850:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-0003c790:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri
0003c860:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo0003c7a0:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border
0003c870:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con0003c7b0:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens
0003c880:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>0003c7c0:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp
0003c890:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>0003c7d0:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>
0003c8a0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr0003c7e0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
0003c8b0:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt0003c7f0:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:
0003c8c0:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low0003c800:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
0003c8d0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t0003c810:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re
0003c8e0:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t0003c820:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa
0003c8f0:·643e·6661·6c73·653c·2f74·643e·3c2f·7472··d>false</td></tr 
0003c900:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg 
0003c910:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl 
0003c920:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab0003c830:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr
0003c930:·6c65·3e3c·7072·653e·3c63·6f64·653e·0a70··le><pre><code>.p 
0003c940:·6163·6b61·6765·202d·2d61·6464·3d61·6964··ackage·--add=aid 
0003c950:·650a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··e.</code></pre>< 
0003c960:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b 
0003c970:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"· 
0003c980:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col 
0003c990:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ 
0003c9a0:·6574·3d22·2369·646d·3830·3135·2220·7461··et="#idm8015"·ta 
0003c9b0:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role= 
0003c9c0:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex 
0003c9d0:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t 
0003c9e0:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t 
0003c9f0:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href=" 
0003ca00:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation· 
0003ca10:·4f53·4275·696c·6420·426c·7565·7072·696e··OSBuild·Blueprin 
0003ca20:·7420·736e·6970·7065·7420·e287·b23c·2f61··t·snippet·...</a 
0003ca30:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class= 
0003ca40:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse· 
0003ca50:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id 
0003ca60:·6d38·3031·3522·3e3c·7072·653e·3c63·6f64··m8015"><pre><cod 
0003ca70:·653e·0a5b·5b70·6163·6b61·6765·735d·5d0a··e>.[[packages]]. 
0003ca80:·6e61·6d65·203d·2022·6169·6465·220a·7665··name·=·"aide".ve 
0003ca90:·7273·696f·6e20·3d20·222a·220a·3c2f·636f··rsion·=·"*".</co 
0003caa0:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div>< 
0003cab0:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn 
0003cac0:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t 
0003cad0:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse" 
0003cae0:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i 
0003caf0:·646d·3830·3136·2220·7461·6269·6e64·6578··dm8016"·tabindex 
0003cb00:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto 
0003cb10:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded 
0003cb20:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title=" 
0003cb30:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve 
0003cb40:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re 
0003cb50:·6d65·6469·6174·696f·6e20·7363·7269·7074··mediation·script 
0003cb60:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div 
0003cb70:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co 
0003cb80:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse" 
0003cb90:·2069·643d·2269·646d·3830·3136·223e·3c74···id="idm8016"><t 
0003cba0:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl 
0003cbb0:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped· 
0003cbc0:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t 
0003cbd0:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed"> 
0003cbe0:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi 
0003cbf0:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low< 
0003cc00:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0003cc10:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th 
0003cc20:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t 
0003cc30:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot 
0003cc40:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false< 
0003cc50:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0003cc60:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><0003c840:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</
0003cc70:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></0003c850:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t
0003cc80:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>0003c860:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><
0003cc90:·3c63·6f64·653e·0a70·6163·6b61·6765·2069··<code>.package·i 
Max diff block lines reached; 1566093/1593445 bytes (98.28%) of diff not shown.
183 KB
html2text {}
    
Offset 177, 52 lines modifiedOffset 177, 38 lines modified
177 ··-·PCI-DSSv4-11.5.2177 ··-·PCI-DSSv4-11.5.2
178 ··-·enable_strategy178 ··-·enable_strategy
179 ··-·low_complexity179 ··-·low_complexity
180 ··-·low_disruption180 ··-·low_disruption
181 ··-·medium_severity181 ··-·medium_severity
182 ··-·no_reboot_needed182 ··-·no_reboot_needed
183 ··-·package_aide_installed183 ··-·package_aide_installed
184 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
185 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
186 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
187 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
188 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
189 dnf·install·aide 
190 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
191 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
192 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
193 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
194 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
195 package·--add=aide 
196 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8184 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
197 [[packages]]185 [[packages]]
198 name·=·"aide"186 name·=·"aide"
199 version·=·"*"187 version·=·"*"
200 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
201 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
202 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
203 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
204 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
205 package·install·aide 
206 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8188 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
207 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low189 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
208 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low190 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
209 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false191 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
210 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable192 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
211 include·install_aide193 include·install_aide
  
212 class·install_aide·{194 class·install_aide·{
213 ··package·{·'aide':195 ··package·{·'aide':
214 ····ensure·=>·'installed',196 ····ensure·=>·'installed',
215 ··}197 ··}
216 }198 }
 199 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 200 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 201 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 202 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 203 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 204 package·install·aide
217 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8205 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
218 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low206 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
219 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low207 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
220 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false208 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
221 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable209 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
222 #·Remediation·is·applicable·only·in·certain·platforms210 #·Remediation·is·applicable·only·in·certain·platforms
223 if·rpm·--quiet·-q·kernel;·then211 if·rpm·--quiet·-q·kernel;·then
Offset 230, 14 lines modifiedOffset 216, 28 lines modified
230 if·!·rpm·-q·--quiet·"aide"·;·then216 if·!·rpm·-q·--quiet·"aide"·;·then
231 ····yum·install·-y·"aide"217 ····yum·install·-y·"aide"
232 fi218 fi
  
233 else219 else
234 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'220 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
235 fi221 fi
 222 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 223 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 224 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 225 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 226 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 227 package·--add=aide
 228 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 229 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 230 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 231 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 232 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 233 dnf·install·aide
236 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*234 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
237 Run·the·following·command·to·generate·a·new·database:235 Run·the·following·command·to·generate·a·new·database:
238 $·sudo·/usr/sbin/aide·--init236 $·sudo·/usr/sbin/aide·--init
239 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:237 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
240 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz238 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
241 To·initiate·a·manual·check,·run·the·following·command:239 To·initiate·a·manual·check,·run·the·following·command:
242 $·sudo·/usr/sbin/aide·--check240 $·sudo·/usr/sbin/aide·--check
Offset 922, 29 lines modifiedOffset 922, 29 lines modified
922 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.3922 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.3
923 References:·_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)923 References:·_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)
924 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4924 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4
925 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227925 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
926 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R28926 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R28
927 ············_\x8c_\x8i_\x8s············1.1.2.3.1927 ············_\x8c_\x8i_\x8s············1.1.2.3.1
928 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-230328r1017139_rule928 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-230328r1017139_rule
929 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
930 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
931 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high 
932 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
933 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
934 part·/home 
935 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8929 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
936 [[customizations.filesystem]]930 [[customizations.filesystem]]
937 mountpoint·=·"/home"931 mountpoint·=·"/home"
938 size·=·1073741824932 size·=·1073741824
939 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8933 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
940 logvol·/home·1024934 logvol·/home·1024
 935 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 936 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 937 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high
 938 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 939 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 940 part·/home
941 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/t\x8tm\x8mp\x8p·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*941 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/t\x8tm\x8mp\x8p·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
942 The·/tmp·directory·is·a·world-writable·directory·used·for·temporary·file·storage.·Ensure·it·has·its·own·partition·or·logical·volume·at·installation·time,·or·migrate·it·using·LVM.942 The·/tmp·directory·is·a·world-writable·directory·used·for·temporary·file·storage.·Ensure·it·has·its·own·partition·or·logical·volume·at·installation·time,·or·migrate·it·using·LVM.
943 Rationale:··The·/tmp·partition·is·used·as·temporary·storage·by·many·programs.·Placing·/tmp·in·its·own·partition·enables·the·setting·of·more·restrictive·mount·options,·which·can·help·protect·programs·which·use·it.943 Rationale:··The·/tmp·partition·is·used·as·temporary·storage·by·many·programs.·Placing·/tmp·in·its·own·partition·enables·the·setting·of·more·restrictive·mount·options,·which·can·help·protect·programs·which·use·it.
944 Severity: ··low944 Severity: ··low
945 Rule·ID:····xccdf_org.ssgproject.content_rule_partition_for_tmp945 Rule·ID:····xccdf_org.ssgproject.content_rule_partition_for_tmp
946 ············_\x8c_\x8i_\x8s_\x8-_\x8c_\x8s_\x8c········12,·15,·8946 ············_\x8c_\x8i_\x8s_\x8-_\x8c_\x8s_\x8c········12,·15,·8
947 ············_\x8c_\x8o_\x8b_\x8i_\x8t_\x85·········APO13.01,·DSS05.02947 ············_\x8c_\x8o_\x8b_\x8i_\x8t_\x85·········APO13.01,·DSS05.02
Offset 952, 29 lines modifiedOffset 952, 29 lines modified
952 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.5,·SR·3.8,·SR·4.1,·SR·4.3,·SR·5.1,·SR·5.2,·SR·5.3,·SR·7.1,·SR·7.6952 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.5,·SR·3.8,·SR·4.1,·SR·4.3,·SR·5.1,·SR·5.2,·SR·5.3,·SR·7.1,·SR·7.6
Max diff block lines reached; 181317/186911 bytes (97.01%) of diff not shown.
1.51 MB
./usr/share/doc/ssg-nondebian/ssg-centos8-guide-cis_server_l1.html
    
Offset 15410, 207 lines modifiedOffset 15410, 207 lines modified
0003c310:·7461·2d74·6172·6765·743d·2223·6964·6d38··ta-target="#idm80003c310:·7461·2d74·6172·6765·743d·2223·6964·6d38··ta-target="#idm8
0003c320:·3031·3322·2074·6162·696e·6465·783d·2230··013"·tabindex="00003c320:·3031·3322·2074·6162·696e·6465·783d·2230··013"·tabindex="0
0003c330:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·0003c330:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
0003c340:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f0003c340:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
0003c350:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act0003c350:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
0003c360:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"0003c360:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
0003c370:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed0003c370:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
0003c380:·6961·7469·6f6e·2073·6372·6970·7420·e287··iation·script·..0003c380:·6961·7469·6f6e·204f·5342·7569·6c64·2042··iation·OSBuild·B
 0003c390:·6c75·6570·7269·6e74·2073·6e69·7070·6574··lueprint·snippet
 0003c3a0:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
 0003c3b0:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
 0003c3c0:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
 0003c3d0:·2069·643d·2269·646d·3830·3133·223e·3c70···id="idm8013"><p
 0003c3e0:·7265·3e3c·636f·6465·3e0a·5b5b·7061·636b··re><code>.[[pack
 0003c3f0:·6167·6573·5d5d·0a6e·616d·6520·3d20·2261··ages]].name·=·"a
 0003c400:·6964·6522·0a76·6572·7369·6f6e·203d·2022··ide".version·=·"
 0003c410:·2a22·0a3c·2f63·6f64·653e·3c2f·7072·653e··*".</code></pre>
 0003c420:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class="
 0003c430:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success"
 0003c440:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co
 0003c450:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar
 0003c460:·6765·743d·2223·6964·6d38·3031·3422·2074··get="#idm8014"·t
 0003c470:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
 0003c480:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
 0003c490:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
 0003c4a0:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
 0003c4b0:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
 0003c4c0:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
 0003c4d0:·2050·7570·7065·7420·736e·6970·7065·7420···Puppet·snippet·
0003c390:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl0003c4e0:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·
0003c3a0:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla0003c4f0:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col
0003c3b0:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id0003c500:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·
0003c3c0:·3d22·6964·6d38·3031·3322·3e3c·7461·626c··="idm8013"><tabl0003c510:·6964·3d22·6964·6d38·3031·3422·3e3c·7461··id="idm8014"><ta
0003c3d0:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t0003c520:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table
0003c3e0:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab0003c530:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t
0003c3f0:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl0003c540:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta
0003c400:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr0003c550:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><
0003c410:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:0003c560:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit
0003c420:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td0003c570:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</
0003c430:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di 
0003c440:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t 
0003c450:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr>< 
0003c460:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</ 
0003c470:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td 
0003c480:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St0003c580:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 0003c590:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th>
 0003c5a0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
 0003c5b0:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot:
 0003c5c0:·3c2f·7468·3e3c·7464·3e66·616c·7365·3c2f··</th><td>false</
 0003c5d0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
0003c490:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>0003c5e0:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t
0003c4a0:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr>0003c5f0:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t
0003c4b0:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co0003c600:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><
 0003c610:·636f·6465·3e69·6e63·6c75·6465·2069·6e73··code>include·ins
 0003c620:·7461·6c6c·5f61·6964·650a·0a63·6c61·7373··tall_aide..class
 0003c630:·2069·6e73·7461·6c6c·5f61·6964·6520·7b0a···install_aide·{.
 0003c640:·2020·7061·636b·6167·6520·7b20·2761·6964····package·{·'aid
 0003c650:·6527·3a0a·2020·2020·656e·7375·7265·203d··e':.····ensure·=
 0003c660:·2667·743b·2027·696e·7374·616c·6c65·6427··&gt;·'installed'
 0003c670:·2c0a·2020·7d0a·7d0a·3c2f·636f·6465·3e3c··,.··}.}.</code><
 0003c680:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl
0003c4c0:·6465·3e0a·646e·6620·696e·7374·616c·6c20··de>.dnf·install· 
0003c4d0:·6169·6465·0a3c·2f63·6f64·653e·3c2f·7072··aide.</code></pr 
0003c4e0:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class 
0003c4f0:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes 
0003c500:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle=" 
0003c510:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t 
0003c520:·6172·6765·743d·2223·6964·6d38·3031·3422··arget="#idm8014" 
0003c530:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro 
0003c540:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria 
0003c550:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false 
0003c560:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat 
0003c570:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre 
0003c580:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati 
0003c590:·6f6e·2041·6e61·636f·6e64·6120·736e·6970··on·Anaconda·snip 
0003c5a0:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br>< 
0003c5b0:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel 
0003c5c0:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap 
0003c5d0:·7365·2220·6964·3d22·6964·6d38·3031·3422··se"·id="idm8014" 
0003c5e0:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t 
0003c5f0:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip 
0003c600:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere 
0003c610:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense 
0003c620:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl 
0003c630:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l 
0003c640:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr> 
0003c650:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:< 
0003c660:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td> 
0003c670:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb 
0003c680:·6f6f·743a·3c2f·7468·3e3c·7464·3e66·616c··oot:</th><td>fal 
0003c690:·7365·3c2f·7464·3e3c·2f74·723e·3c74·723e··se</td></tr><tr> 
0003c6a0:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t 
0003c6b0:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td 
0003c6c0:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p 
0003c6d0:·7265·3e3c·636f·6465·3e0a·7061·636b·6167··re><code>.packag 
0003c6e0:·6520·2d2d·6164·643d·6169·6465·0a3c·2f63··e·--add=aide.</c 
0003c6f0:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div> 
0003c700:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt 
0003c710:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data- 
0003c720:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse 
0003c730:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="# 
0003c740:·6964·6d38·3031·3522·2074·6162·696e·6465··idm8015"·tabinde 
0003c750:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt 
0003c760:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande 
0003c770:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title= 
0003c780:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev 
0003c790:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R 
0003c7a0:·656d·6564·6961·7469·6f6e·204f·5342·7569··emediation·OSBui 
0003c7b0:·6c64·2042·6c75·6570·7269·6e74·2073·6e69··ld·Blueprint·sni 
0003c7c0:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br> 
0003c7d0:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane 
0003c7e0:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla 
0003c7f0:·7073·6522·2069·643d·2269·646d·3830·3135··pse"·id="idm8015 
0003c800:·223e·3c70·7265·3e3c·636f·6465·3e0a·5b5b··"><pre><code>.[[ 
0003c810:·7061·636b·6167·6573·5d5d·0a6e·616d·6520··packages]].name· 
0003c820:·3d20·2261·6964·6522·0a76·6572·7369·6f6e··=·"aide".version 
0003c830:·203d·2022·2a22·0a3c·2f63·6f64·653e·3c2f···=·"*".</code></ 
0003c840:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla 
0003c850:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ 
0003c860:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle 
0003c870:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data 
0003c880:·2d74·6172·6765·743d·2223·6964·6d38·3031··-target="#idm801 
0003c890:·3622·2074·6162·696e·6465·783d·2230·2220··6"·tabindex="0"· 
0003c8a0:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar 
0003c8b0:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal 
0003c8c0:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ 
0003c8d0:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h 
Max diff block lines reached; 1397248/1424462 bytes (98.09%) of diff not shown.
156 KB
html2text {}
    
Offset 171, 52 lines modifiedOffset 171, 38 lines modified
171 ··-·PCI-DSSv4-11.5.2171 ··-·PCI-DSSv4-11.5.2
172 ··-·enable_strategy172 ··-·enable_strategy
173 ··-·low_complexity173 ··-·low_complexity
174 ··-·low_disruption174 ··-·low_disruption
175 ··-·medium_severity175 ··-·medium_severity
176 ··-·no_reboot_needed176 ··-·no_reboot_needed
177 ··-·package_aide_installed177 ··-·package_aide_installed
178 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
179 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
180 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
181 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
182 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
183 dnf·install·aide 
184 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
185 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
186 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
187 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
188 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
189 package·--add=aide 
190 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8178 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
191 [[packages]]179 [[packages]]
192 name·=·"aide"180 name·=·"aide"
193 version·=·"*"181 version·=·"*"
194 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
195 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
196 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
197 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
198 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
199 package·install·aide 
200 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8182 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
201 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low183 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
202 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low184 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
203 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false185 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
204 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable186 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
205 include·install_aide187 include·install_aide
  
206 class·install_aide·{188 class·install_aide·{
207 ··package·{·'aide':189 ··package·{·'aide':
208 ····ensure·=>·'installed',190 ····ensure·=>·'installed',
209 ··}191 ··}
210 }192 }
 193 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 194 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 195 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 196 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 197 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 198 package·install·aide
211 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8199 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
212 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low200 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
213 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low201 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
214 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false202 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
215 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable203 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
216 #·Remediation·is·applicable·only·in·certain·platforms204 #·Remediation·is·applicable·only·in·certain·platforms
217 if·rpm·--quiet·-q·kernel;·then205 if·rpm·--quiet·-q·kernel;·then
Offset 224, 14 lines modifiedOffset 210, 28 lines modified
224 if·!·rpm·-q·--quiet·"aide"·;·then210 if·!·rpm·-q·--quiet·"aide"·;·then
225 ····yum·install·-y·"aide"211 ····yum·install·-y·"aide"
226 fi212 fi
  
227 else213 else
228 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'214 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
229 fi215 fi
 216 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 217 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 218 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 219 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 220 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 221 package·--add=aide
 222 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 223 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 224 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 225 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 226 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 227 dnf·install·aide
230 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*228 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
231 Run·the·following·command·to·generate·a·new·database:229 Run·the·following·command·to·generate·a·new·database:
232 $·sudo·/usr/sbin/aide·--init230 $·sudo·/usr/sbin/aide·--init
233 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:231 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
234 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz232 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
235 To·initiate·a·manual·check,·run·the·following·command:233 To·initiate·a·manual·check,·run·the·following·command:
236 $·sudo·/usr/sbin/aide·--check234 $·sudo·/usr/sbin/aide·--check
Offset 915, 29 lines modifiedOffset 915, 29 lines modified
915 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.5,·SR·3.8,·SR·4.1,·SR·4.3,·SR·5.1,·SR·5.2,·SR·5.3,·SR·7.1,·SR·7.6915 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.5,·SR·3.8,·SR·4.1,·SR·4.3,·SR·5.1,·SR·5.2,·SR·5.3,·SR·7.1,·SR·7.6
916 References:·_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.3916 References:·_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.3
917 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)917 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)
918 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4918 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4
919 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227919 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
920 ············_\x8c_\x8i_\x8s············1.1.2.1.1920 ············_\x8c_\x8i_\x8s············1.1.2.1.1
921 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-230295r1017106_rule921 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-230295r1017106_rule
922 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
923 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
924 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high 
925 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
926 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
927 part·/tmp 
928 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8922 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
929 [[customizations.filesystem]]923 [[customizations.filesystem]]
930 mountpoint·=·"/tmp"924 mountpoint·=·"/tmp"
931 size·=·1073741824925 size·=·1073741824
932 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8926 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
933 logvol·/tmp·1024927 logvol·/tmp·1024
 928 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 929 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 930 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high
 931 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 932 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 933 part·/tmp
934 Group  ·GNOME·Desktop·Environment·  Group·contains·3·groups·and·10·rules934 Group  ·GNOME·Desktop·Environment·  Group·contains·3·groups·and·10·rules
935 _\x8[_\x8r_\x8e_\x8f_\x8]  ·GNOME·is·a·graphical·desktop·environment·bundled·with·many·Linux·distributions·that·allow·users·to·easily·interact·with·the·operating·system·graphically·rather·than·textually.·The·GNOME·Graphical·Display·Manager·(GDM)·provides·login,·logout,·and·user·switching·contexts·as·well·as·display·server·management.935 _\x8[_\x8r_\x8e_\x8f_\x8]  ·GNOME·is·a·graphical·desktop·environment·bundled·with·many·Linux·distributions·that·allow·users·to·easily·interact·with·the·operating·system·graphically·rather·than·textually.·The·GNOME·Graphical·Display·Manager·(GDM)·provides·login,·logout,·and·user·switching·contexts·as·well·as·display·server·management.
  
936 GNOME·is·developed·by·the·GNOME·Project·and·is·considered·the·default·Red·Hat·Graphical·environment.936 GNOME·is·developed·by·the·GNOME·Project·and·is·considered·the·default·Red·Hat·Graphical·environment.
  
937 For·more·information·on·GNOME·and·the·GNOME·Project,·see·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8w\x8w_\x8w\x8w_\x8w\x8w_\x8.\x8._\x8g\x8g_\x8n\x8n_\x8o\x8o_\x8m\x8m_\x8e\x8e_\x8.\x8._\x8o\x8o_\x8r\x8r_\x8g\x8g.937 For·more·information·on·GNOME·and·the·GNOME·Project,·see·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8w\x8w_\x8w\x8w_\x8w\x8w_\x8.\x8._\x8g\x8g_\x8n\x8n_\x8o\x8o_\x8m\x8m_\x8e\x8e_\x8.\x8._\x8o\x8o_\x8r\x8r_\x8g\x8g.
938 Group  ·Configure·GNOME·Login·Screen·  Group·contains·2·rules938 Group  ·Configure·GNOME·Login·Screen·  Group·contains·2·rules
Offset 2273, 52 lines modifiedOffset 2273, 38 lines modified
2273 ··-·PCI-DSSv4-2.2.62273 ··-·PCI-DSSv4-2.2.6
Max diff block lines reached; 154561/160032 bytes (96.58%) of diff not shown.
1.41 MB
./usr/share/doc/ssg-nondebian/ssg-centos8-guide-cis_workstation_l1.html
    
Offset 15401, 208 lines modifiedOffset 15401, 208 lines modified
0003c280:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=0003c280:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
0003c290:·2223·6964·6d38·3031·3322·2074·6162·696e··"#idm8013"·tabin0003c290:·2223·6964·6d38·3031·3322·2074·6162·696e··"#idm8013"·tabin
0003c2a0:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu0003c2a0:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
0003c2b0:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan0003c2b0:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
0003c2c0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl0003c2c0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
0003c2d0:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r0003c2d0:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
0003c2e0:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"0003c2e0:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
0003c2f0:·3e52·656d·6564·6961·7469·6f6e·2073·6372··>Remediation·scr0003c2f0:·3e52·656d·6564·6961·7469·6f6e·204f·5342··>Remediation·OSB
 0003c300:·7569·6c64·2042·6c75·6570·7269·6e74·2073··uild·Blueprint·s
 0003c310:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b
 0003c320:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
 0003c330:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
 0003c340:·6c61·7073·6522·2069·643d·2269·646d·3830··lapse"·id="idm80
 0003c350:·3133·223e·3c70·7265·3e3c·636f·6465·3e0a··13"><pre><code>.
 0003c360:·5b5b·7061·636b·6167·6573·5d5d·0a6e·616d··[[packages]].nam
 0003c370:·6520·3d20·2261·6964·6522·0a76·6572·7369··e·=·"aide".versi
 0003c380:·6f6e·203d·2022·2a22·0a3c·2f63·6f64·653e··on·=·"*".</code>
0003c300:·6970·7420·e287·b23c·2f61·3e3c·6272·3e3c··ipt·...</a><br>< 
0003c310:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel 
0003c320:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap 
0003c330:·7365·2220·6964·3d22·6964·6d38·3031·3322··se"·id="idm8013" 
0003c340:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t 
0003c350:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip 
0003c360:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere 
0003c370:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense 
0003c380:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl 
0003c390:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l 
0003c3a0:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr> 
0003c3b0:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:< 
0003c3c0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td> 
0003c3d0:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb 
0003c3e0:·6f6f·743a·3c2f·7468·3e3c·7464·3e66·616c··oot:</th><td>fal 
0003c3f0:·7365·3c2f·7464·3e3c·2f74·723e·3c74·723e··se</td></tr><tr> 
0003c400:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t 
0003c410:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td 
0003c420:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p 
0003c430:·7265·3e3c·636f·6465·3e0a·646e·6620·696e··re><code>.dnf·in 
0003c440:·7374·616c·6c20·6169·6465·0a3c·2f63·6f64··stall·aide.</cod 
0003c450:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a0003c390:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c
0003c460:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn-0003c3a0:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su
0003c470:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to0003c3b0:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg
0003c480:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"·0003c3c0:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da
0003c490:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id0003c3d0:·7461·2d74·6172·6765·743d·2223·6964·6d38··ta-target="#idm8
0003c4a0:·6d38·3031·3422·2074·6162·696e·6465·783d··m8014"·tabindex=0003c3e0:·3031·3422·2074·6162·696e·6465·783d·2230··014"·tabindex="0
0003c4b0:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button0003c3f0:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
0003c4c0:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=0003c400:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
0003c4d0:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A0003c410:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
0003c4e0:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea0003c420:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
0003c4f0:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem0003c430:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
0003c500:·6564·6961·7469·6f6e·2041·6e61·636f·6e64··ediation·Anacond0003c440:·6961·7469·6f6e·2050·7570·7065·7420·736e··iation·Puppet·sn
0003c510:·6120·736e·6970·7065·7420·e287·b23c·2f61··a·snippet·...</a0003c450:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br
0003c520:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=0003c460:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
0003c530:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·0003c470:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
0003c540:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id0003c480:·6170·7365·2220·6964·3d22·6964·6d38·3031··apse"·id="idm801
0003c550:·6d38·3031·3422·3e3c·7461·626c·6520·636c··m8014"><table·cl0003c490:·3422·3e3c·7461·626c·6520·636c·6173·733d··4"><table·class=
0003c560:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table0003c4a0:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str
0003c570:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b0003c4b0:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde
0003c580:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co0003c4c0:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden
0003c590:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th0003c4d0:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com
0003c5a0:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th0003c4e0:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td
0003c5b0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t0003c4f0:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
0003c5c0:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup0003c500:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption
 0003c510:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
 0003c520:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e52··d></tr><tr><th>R
 0003c530:·6562·6f6f·743a·3c2f·7468·3e3c·7464·3e66··eboot:</th><td>f
 0003c540:·616c·7365·3c2f·7464·3e3c·2f74·723e·3c74··alse</td></tr><t
 0003c550:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<
 0003c560:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</
 0003c570:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table>
 0003c580:·3c70·7265·3e3c·636f·6465·3e69·6e63·6c75··<pre><code>inclu
 0003c590:·6465·2069·6e73·7461·6c6c·5f61·6964·650a··de·install_aide.
 0003c5a0:·0a63·6c61·7373·2069·6e73·7461·6c6c·5f61··.class·install_a
 0003c5b0:·6964·6520·7b0a·2020·7061·636b·6167·6520··ide·{.··package·
 0003c5c0:·7b20·2761·6964·6527·3a0a·2020·2020·656e··{·'aide':.····en
 0003c5d0:·7375·7265·203d·2667·743b·2027·696e·7374··sure·=&gt;·'inst
 0003c5e0:·616c·6c65·6427·2c0a·2020·7d0a·7d0a·3c2f··alled',.··}.}.</
 0003c5f0:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div
 0003c600:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b
 0003c610:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data
 0003c620:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps
 0003c630:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
 0003c640:·2369·646d·3830·3135·2220·7461·6269·6e64··#idm8015"·tabind
 0003c650:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
 0003c660:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
 0003c670:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
 0003c680:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
 0003c690:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
 0003c6a0:·5265·6d65·6469·6174·696f·6e20·7363·7269··Remediation·scri
 0003c6b0:·7074·20e2·87b2·3c2f·613e·3c62·723e·3c64··pt·...</a><br><d
 0003c6c0:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-
 0003c6d0:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps
 0003c6e0:·6522·2069·643d·2269·646d·3830·3135·223e··e"·id="idm8015">
 0003c6f0:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta
 0003c700:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe
 0003c710:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered
 0003c720:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed
 0003c730:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple
0003c5d0:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo0003c740:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo
0003c5e0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><0003c750:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
0003c5f0:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th>< 
0003c600:·7464·3e66·616c·7365·3c2f·7464·3e3c·2f74··td>false</td></t 
0003c610:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate0003c760:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</
 0003c770:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
 0003c780:·2f74·723e·3c74·723e·3c74·683e·5265·626f··/tr><tr><th>Rebo
0003c620:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab0003c790:·6f74·3a3c·2f74·683e·3c74·643e·6661·6c73··ot:</th><td>fals
0003c630:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta 
0003c640:·626c·653e·3c70·7265·3e3c·636f·6465·3e0a··ble><pre><code>. 
0003c650:·7061·636b·6167·6520·2d2d·6164·643d·6169··package·--add=ai 
0003c660:·6465·0a3c·2f63·6f64·653e·3c2f·7072·653e··de.</code></pre> 
0003c670:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class=" 
0003c680:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success"0003c7a0:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr><
 0003c7b0:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th
 0003c7c0:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td>
 0003c7d0:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr
 0003c7e0:·653e·3c63·6f64·653e·0a70·6163·6b61·6765··e><code>.package
 0003c7f0:·2069·6e73·7461·6c6c·2061·6964·650a·3c2f···install·aide.</
 0003c800:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div
 0003c810:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b
 0003c820:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data
 0003c830:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps
0003c690:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co0003c840:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
 0003c850:·2369·646d·3830·3136·2220·7461·6269·6e64··#idm8016"·tabind
 0003c860:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
 0003c870:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
 0003c880:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
 0003c890:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
 0003c8a0:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
Max diff block lines reached; 1302430/1329782 bytes (97.94%) of diff not shown.
144 KB
html2text {}
    
Offset 170, 52 lines modifiedOffset 170, 38 lines modified
170 ··-·PCI-DSSv4-11.5.2170 ··-·PCI-DSSv4-11.5.2
171 ··-·enable_strategy171 ··-·enable_strategy
172 ··-·low_complexity172 ··-·low_complexity
173 ··-·low_disruption173 ··-·low_disruption
174 ··-·medium_severity174 ··-·medium_severity
175 ··-·no_reboot_needed175 ··-·no_reboot_needed
176 ··-·package_aide_installed176 ··-·package_aide_installed
177 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
178 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
179 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
180 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
181 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
182 dnf·install·aide 
183 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
184 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
185 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
186 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
187 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
188 package·--add=aide 
189 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8177 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
190 [[packages]]178 [[packages]]
191 name·=·"aide"179 name·=·"aide"
192 version·=·"*"180 version·=·"*"
193 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
194 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
195 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
196 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
197 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
198 package·install·aide 
199 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8181 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
200 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low182 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
201 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low183 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
202 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false184 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
203 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable185 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
204 include·install_aide186 include·install_aide
  
205 class·install_aide·{187 class·install_aide·{
206 ··package·{·'aide':188 ··package·{·'aide':
207 ····ensure·=>·'installed',189 ····ensure·=>·'installed',
208 ··}190 ··}
209 }191 }
 192 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 193 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 194 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 195 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 196 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 197 package·install·aide
210 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8198 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
211 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low199 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
212 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low200 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
213 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false201 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
214 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable202 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
215 #·Remediation·is·applicable·only·in·certain·platforms203 #·Remediation·is·applicable·only·in·certain·platforms
216 if·rpm·--quiet·-q·kernel;·then204 if·rpm·--quiet·-q·kernel;·then
Offset 223, 14 lines modifiedOffset 209, 28 lines modified
223 if·!·rpm·-q·--quiet·"aide"·;·then209 if·!·rpm·-q·--quiet·"aide"·;·then
224 ····yum·install·-y·"aide"210 ····yum·install·-y·"aide"
225 fi211 fi
  
226 else212 else
227 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'213 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
228 fi214 fi
 215 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 216 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 217 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 218 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 219 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 220 package·--add=aide
 221 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 222 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 223 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 224 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 225 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 226 dnf·install·aide
229 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*227 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
230 Run·the·following·command·to·generate·a·new·database:228 Run·the·following·command·to·generate·a·new·database:
231 $·sudo·/usr/sbin/aide·--init229 $·sudo·/usr/sbin/aide·--init
232 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:230 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
233 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz231 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
234 To·initiate·a·manual·check,·run·the·following·command:232 To·initiate·a·manual·check,·run·the·following·command:
235 $·sudo·/usr/sbin/aide·--check233 $·sudo·/usr/sbin/aide·--check
Offset 914, 29 lines modifiedOffset 914, 29 lines modified
914 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.5,·SR·3.8,·SR·4.1,·SR·4.3,·SR·5.1,·SR·5.2,·SR·5.3,·SR·7.1,·SR·7.6914 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.5,·SR·3.8,·SR·4.1,·SR·4.3,·SR·5.1,·SR·5.2,·SR·5.3,·SR·7.1,·SR·7.6
915 References:·_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.3915 References:·_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.3
916 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)916 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)
917 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4917 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4
918 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227918 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
919 ············_\x8c_\x8i_\x8s············1.1.2.1.1919 ············_\x8c_\x8i_\x8s············1.1.2.1.1
920 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-230295r1017106_rule920 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-230295r1017106_rule
921 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
922 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
923 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high 
924 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
925 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
926 part·/tmp 
927 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8921 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
928 [[customizations.filesystem]]922 [[customizations.filesystem]]
929 mountpoint·=·"/tmp"923 mountpoint·=·"/tmp"
930 size·=·1073741824924 size·=·1073741824
931 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8925 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
932 logvol·/tmp·1024926 logvol·/tmp·1024
 927 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 928 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 929 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high
 930 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 931 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 932 part·/tmp
933 Group  ·GNOME·Desktop·Environment·  Group·contains·3·groups·and·10·rules933 Group  ·GNOME·Desktop·Environment·  Group·contains·3·groups·and·10·rules
934 _\x8[_\x8r_\x8e_\x8f_\x8]  ·GNOME·is·a·graphical·desktop·environment·bundled·with·many·Linux·distributions·that·allow·users·to·easily·interact·with·the·operating·system·graphically·rather·than·textually.·The·GNOME·Graphical·Display·Manager·(GDM)·provides·login,·logout,·and·user·switching·contexts·as·well·as·display·server·management.934 _\x8[_\x8r_\x8e_\x8f_\x8]  ·GNOME·is·a·graphical·desktop·environment·bundled·with·many·Linux·distributions·that·allow·users·to·easily·interact·with·the·operating·system·graphically·rather·than·textually.·The·GNOME·Graphical·Display·Manager·(GDM)·provides·login,·logout,·and·user·switching·contexts·as·well·as·display·server·management.
  
935 GNOME·is·developed·by·the·GNOME·Project·and·is·considered·the·default·Red·Hat·Graphical·environment.935 GNOME·is·developed·by·the·GNOME·Project·and·is·considered·the·default·Red·Hat·Graphical·environment.
  
936 For·more·information·on·GNOME·and·the·GNOME·Project,·see·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8w\x8w_\x8w\x8w_\x8w\x8w_\x8.\x8._\x8g\x8g_\x8n\x8n_\x8o\x8o_\x8m\x8m_\x8e\x8e_\x8.\x8._\x8o\x8o_\x8r\x8r_\x8g\x8g.936 For·more·information·on·GNOME·and·the·GNOME·Project,·see·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8w\x8w_\x8w\x8w_\x8w\x8w_\x8.\x8._\x8g\x8g_\x8n\x8n_\x8o\x8o_\x8m\x8m_\x8e\x8e_\x8.\x8._\x8o\x8o_\x8r\x8r_\x8g\x8g.
937 Group  ·Configure·GNOME·Login·Screen·  Group·contains·2·rules937 Group  ·Configure·GNOME·Login·Screen·  Group·contains·2·rules
Offset 2272, 52 lines modifiedOffset 2272, 38 lines modified
2272 ··-·PCI-DSSv4-2.2.62272 ··-·PCI-DSSv4-2.2.6
Max diff block lines reached; 142012/147483 bytes (96.29%) of diff not shown.
1.59 MB
./usr/share/doc/ssg-nondebian/ssg-centos8-guide-cis_workstation_l2.html
    
Offset 15440, 207 lines modifiedOffset 15440, 207 lines modified
0003c4f0:·612d·7461·7267·6574·3d22·2369·646d·3830··a-target="#idm800003c4f0:·612d·7461·7267·6574·3d22·2369·646d·3830··a-target="#idm80
0003c500:·3133·2220·7461·6269·6e64·6578·3d22·3022··13"·tabindex="0"0003c500:·3133·2220·7461·6269·6e64·6578·3d22·3022··13"·tabindex="0"
0003c510:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a0003c510:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
0003c520:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa0003c520:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
0003c530:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti0003c530:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
0003c540:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·0003c540:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
0003c550:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi0003c550:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
 0003c560:·6174·696f·6e20·4f53·4275·696c·6420·426c··ation·OSBuild·Bl
 0003c570:·7565·7072·696e·7420·736e·6970·7065·7420··ueprint·snippet·
 0003c580:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·
 0003c590:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col
 0003c5a0:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·
 0003c5b0:·6964·3d22·6964·6d38·3031·3322·3e3c·7072··id="idm8013"><pr
 0003c5c0:·653e·3c63·6f64·653e·0a5b·5b70·6163·6b61··e><code>.[[packa
 0003c5d0:·6765·735d·5d0a·6e61·6d65·203d·2022·6169··ges]].name·=·"ai
 0003c5e0:·6465·220a·7665·7273·696f·6e20·3d20·222a··de".version·=·"*
0003c560:·6174·696f·6e20·7363·7269·7074·20e2·87b2··ation·script·... 
0003c570:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla 
0003c580:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap 
0003c590:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id= 
0003c5a0:·2269·646d·3830·3133·223e·3c74·6162·6c65··"idm8013"><table 
0003c5b0:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta 
0003c5c0:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl 
0003c5d0:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table 
0003c5e0:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr> 
0003c5f0:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:< 
0003c600:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td> 
0003c610:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis 
0003c620:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td 
0003c630:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t 
0003c640:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t 
0003c650:·683e·3c74·643e·6661·6c73·653c·2f74·643e··h><td>false</td> 
0003c660:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str 
0003c670:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e 
0003c680:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr>< 
0003c690:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod 
0003c6a0:·653e·0a64·6e66·2069·6e73·7461·6c6c·2061··e>.dnf·install·a 
0003c6b0:·6964·650a·3c2f·636f·6465·3e3c·2f70·7265··ide.</code></pre0003c5f0:·220a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··".</code></pre><
0003c6c0:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class=0003c600:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b
0003c6d0:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success0003c610:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"·
0003c6e0:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c0003c620:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col
0003c6f0:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta0003c630:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ
0003c700:·7267·6574·3d22·2369·646d·3830·3134·2220··rget="#idm8014"·0003c640:·6574·3d22·2369·646d·3830·3134·2220·7461··et="#idm8014"·ta
0003c710:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol0003c650:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
0003c720:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-0003c660:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
0003c730:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"0003c670:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
0003c740:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate0003c680:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
0003c750:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href0003c690:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
0003c760:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio0003c6a0:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
0003c770:·6e20·416e·6163·6f6e·6461·2073·6e69·7070··n·Anaconda·snipp 
0003c780:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d 
0003c790:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel- 
0003c7a0:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps 
0003c7b0:·6522·2069·643d·2269·646d·3830·3134·223e··e"·id="idm8014"> 
0003c7c0:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta 
0003c7d0:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe 
0003c7e0:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered 
0003c7f0:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed 
0003c800:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple 
0003c810:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo 
0003c820:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr>< 
0003c830:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</ 
0003c840:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td>< 
0003c850:·2f74·723e·3c74·723e·3c74·683e·5265·626f··/tr><tr><th>Rebo 
0003c860:·6f74·3a3c·2f74·683e·3c74·643e·6661·6c73··ot:</th><td>fals 
0003c870:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr>< 
0003c880:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th 
0003c890:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td> 
0003c8a0:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr 
0003c8b0:·653e·3c63·6f64·653e·0a70·6163·6b61·6765··e><code>.package 
0003c8c0:·202d·2d61·6464·3d61·6964·650a·3c2f·636f···--add=aide.</co 
0003c8d0:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div>< 
0003c8e0:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn 
0003c8f0:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t 
0003c900:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse" 
0003c910:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i 
0003c920:·646d·3830·3135·2220·7461·6269·6e64·6578··dm8015"·tabindex 
0003c930:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto 
0003c940:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded 
0003c950:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title=" 
0003c960:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve 
0003c970:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re 
0003c980:·6d65·6469·6174·696f·6e20·4f53·4275·696c··mediation·OSBuil 
0003c990:·6420·426c·7565·7072·696e·7420·736e·6970··d·Blueprint·snip 
0003c9a0:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br>< 
0003c9b0:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel 
0003c9c0:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap 
0003c9d0:·7365·2220·6964·3d22·6964·6d38·3031·3522··se"·id="idm8015" 
0003c9e0:·3e3c·7072·653e·3c63·6f64·653e·0a5b·5b70··><pre><code>.[[p 
0003c9f0:·6163·6b61·6765·735d·5d0a·6e61·6d65·203d··ackages]].name·= 
0003ca00:·2022·6169·6465·220a·7665·7273·696f·6e20···"aide".version· 
0003ca10:·3d20·222a·220a·3c2f·636f·6465·3e3c·2f70··=·"*".</code></p 
0003ca20:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas 
0003ca30:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe 
0003ca40:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle= 
0003ca50:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data- 
0003ca60:·7461·7267·6574·3d22·2369·646d·3830·3136··target="#idm8016 
0003ca70:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r 
0003ca80:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari 
0003ca90:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals 
0003caa0:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa 
0003cab0:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr 
0003cac0:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat 
0003cad0:·696f·6e20·7363·7269·7074·20e2·87b2·3c2f··ion·script·...</ 
0003cae0:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class 
0003caf0:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse 
0003cb00:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i 
0003cb10:·646d·3830·3136·223e·3c74·6162·6c65·2063··dm8016"><table·c 
0003cb20:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl 
0003cb30:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table- 
0003cb40:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c 
0003cb50:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t 
0003cb60:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t 
0003cb70:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></ 
0003cb80:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru 
0003cb90:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l 
0003cba0:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr> 
0003cbb0:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th> 
0003cbc0:·3c74·643e·6661·6c73·653c·2f74·643e·3c2f··<td>false</td></ 
0003cbd0:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat 
0003cbe0:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena 
0003cbf0:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t 
0003cc00:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code> 
0003cc10:·0a70·6163·6b61·6765·2069·6e73·7461·6c6c··.package·install 
0003cc20:·2061·6964·650a·3c2f·636f·6465·3e3c·2f70···aide.</code></p 
0003cc30:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas 
0003cc40:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe 
Max diff block lines reached; 1469237/1496451 bytes (98.18%) of diff not shown.
170 KB
html2text {}
    
Offset 176, 52 lines modifiedOffset 176, 38 lines modified
176 ··-·PCI-DSSv4-11.5.2176 ··-·PCI-DSSv4-11.5.2
177 ··-·enable_strategy177 ··-·enable_strategy
178 ··-·low_complexity178 ··-·low_complexity
179 ··-·low_disruption179 ··-·low_disruption
180 ··-·medium_severity180 ··-·medium_severity
181 ··-·no_reboot_needed181 ··-·no_reboot_needed
182 ··-·package_aide_installed182 ··-·package_aide_installed
183 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
184 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
185 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
186 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
187 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
188 dnf·install·aide 
189 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
190 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
191 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
192 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
193 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
194 package·--add=aide 
195 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8183 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
196 [[packages]]184 [[packages]]
197 name·=·"aide"185 name·=·"aide"
198 version·=·"*"186 version·=·"*"
199 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
200 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
201 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
202 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
203 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
204 package·install·aide 
205 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8187 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
206 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low188 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
207 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low189 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
208 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false190 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
209 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable191 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
210 include·install_aide192 include·install_aide
  
211 class·install_aide·{193 class·install_aide·{
212 ··package·{·'aide':194 ··package·{·'aide':
213 ····ensure·=>·'installed',195 ····ensure·=>·'installed',
214 ··}196 ··}
215 }197 }
 198 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 199 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 200 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 201 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 202 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 203 package·install·aide
216 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8204 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
217 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low205 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
218 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low206 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
219 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false207 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
220 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable208 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
221 #·Remediation·is·applicable·only·in·certain·platforms209 #·Remediation·is·applicable·only·in·certain·platforms
222 if·rpm·--quiet·-q·kernel;·then210 if·rpm·--quiet·-q·kernel;·then
Offset 229, 14 lines modifiedOffset 215, 28 lines modified
229 if·!·rpm·-q·--quiet·"aide"·;·then215 if·!·rpm·-q·--quiet·"aide"·;·then
230 ····yum·install·-y·"aide"216 ····yum·install·-y·"aide"
231 fi217 fi
  
232 else218 else
233 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'219 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
234 fi220 fi
 221 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 222 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 223 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 224 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 225 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 226 package·--add=aide
 227 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 228 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 229 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 230 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 231 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 232 dnf·install·aide
235 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*233 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
236 Run·the·following·command·to·generate·a·new·database:234 Run·the·following·command·to·generate·a·new·database:
237 $·sudo·/usr/sbin/aide·--init235 $·sudo·/usr/sbin/aide·--init
238 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:236 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
239 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz237 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
240 To·initiate·a·manual·check,·run·the·following·command:238 To·initiate·a·manual·check,·run·the·following·command:
241 $·sudo·/usr/sbin/aide·--check239 $·sudo·/usr/sbin/aide·--check
Offset 921, 29 lines modifiedOffset 921, 29 lines modified
921 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.3921 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.3
922 References:·_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)922 References:·_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)
923 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4923 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4
924 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227924 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
925 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R28925 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R28
926 ············_\x8c_\x8i_\x8s············1.1.2.3.1926 ············_\x8c_\x8i_\x8s············1.1.2.3.1
927 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-230328r1017139_rule927 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-230328r1017139_rule
928 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
929 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
930 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high 
931 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
932 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
933 part·/home 
934 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8928 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
935 [[customizations.filesystem]]929 [[customizations.filesystem]]
936 mountpoint·=·"/home"930 mountpoint·=·"/home"
937 size·=·1073741824931 size·=·1073741824
938 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8932 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
939 logvol·/home·1024933 logvol·/home·1024
 934 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 935 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 936 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high
 937 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 938 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 939 part·/home
940 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/t\x8tm\x8mp\x8p·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*940 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/t\x8tm\x8mp\x8p·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
941 The·/tmp·directory·is·a·world-writable·directory·used·for·temporary·file·storage.·Ensure·it·has·its·own·partition·or·logical·volume·at·installation·time,·or·migrate·it·using·LVM.941 The·/tmp·directory·is·a·world-writable·directory·used·for·temporary·file·storage.·Ensure·it·has·its·own·partition·or·logical·volume·at·installation·time,·or·migrate·it·using·LVM.
942 Rationale:··The·/tmp·partition·is·used·as·temporary·storage·by·many·programs.·Placing·/tmp·in·its·own·partition·enables·the·setting·of·more·restrictive·mount·options,·which·can·help·protect·programs·which·use·it.942 Rationale:··The·/tmp·partition·is·used·as·temporary·storage·by·many·programs.·Placing·/tmp·in·its·own·partition·enables·the·setting·of·more·restrictive·mount·options,·which·can·help·protect·programs·which·use·it.
943 Severity: ··low943 Severity: ··low
944 Rule·ID:····xccdf_org.ssgproject.content_rule_partition_for_tmp944 Rule·ID:····xccdf_org.ssgproject.content_rule_partition_for_tmp
945 ············_\x8c_\x8i_\x8s_\x8-_\x8c_\x8s_\x8c········12,·15,·8945 ············_\x8c_\x8i_\x8s_\x8-_\x8c_\x8s_\x8c········12,·15,·8
946 ············_\x8c_\x8o_\x8b_\x8i_\x8t_\x85·········APO13.01,·DSS05.02946 ············_\x8c_\x8o_\x8b_\x8i_\x8t_\x85·········APO13.01,·DSS05.02
Offset 951, 29 lines modifiedOffset 951, 29 lines modified
951 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.5,·SR·3.8,·SR·4.1,·SR·4.3,·SR·5.1,·SR·5.2,·SR·5.3,·SR·7.1,·SR·7.6951 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.5,·SR·3.8,·SR·4.1,·SR·4.3,·SR·5.1,·SR·5.2,·SR·5.3,·SR·7.1,·SR·7.6
Max diff block lines reached; 168783/174377 bytes (96.79%) of diff not shown.
1.65 MB
./usr/share/doc/ssg-nondebian/ssg-centos8-guide-cui.html
    
Offset 15432, 207 lines modifiedOffset 15432, 207 lines modified
0003c470:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm0003c470:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
0003c480:·3830·3133·2220·7461·6269·6e64·6578·3d22··8013"·tabindex="0003c480:·3830·3133·2220·7461·6269·6e64·6578·3d22··8013"·tabindex="
0003c490:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"0003c490:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
0003c4a0:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="0003c4a0:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
0003c4b0:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac0003c4b0:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
0003c4c0:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal0003c4c0:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
0003c4d0:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme0003c4d0:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
0003c4e0:·6469·6174·696f·6e20·7363·7269·7074·20e2··diation·script·.0003c4e0:·6469·6174·696f·6e20·4f53·4275·696c·6420··diation·OSBuild·
 0003c4f0:·426c·7565·7072·696e·7420·736e·6970·7065··Blueprint·snippe
 0003c500:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di
 0003c510:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c
 0003c520:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse
 0003c530:·2220·6964·3d22·6964·6d38·3031·3322·3e3c··"·id="idm8013"><
 0003c540:·7072·653e·3c63·6f64·653e·0a5b·5b70·6163··pre><code>.[[pac
 0003c550:·6b61·6765·735d·5d0a·6e61·6d65·203d·2022··kages]].name·=·"
 0003c560:·6169·6465·220a·7665·7273·696f·6e20·3d20··aide".version·=·
 0003c570:·222a·220a·3c2f·636f·6465·3e3c·2f70·7265··"*".</code></pre
 0003c580:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class=
 0003c590:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success
 0003c5a0:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c
 0003c5b0:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta
 0003c5c0:·7267·6574·3d22·2369·646d·3830·3134·2220··rget="#idm8014"·
 0003c5d0:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol
 0003c5e0:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-
 0003c5f0:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"
 0003c600:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate
 0003c610:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href
 0003c620:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio
 0003c630:·6e20·5075·7070·6574·2073·6e69·7070·6574··n·Puppet·snippet
0003c4f0:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c0003c640:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
0003c500:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll0003c650:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
0003c510:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i0003c660:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
0003c520:·643d·2269·646d·3830·3133·223e·3c74·6162··d="idm8013"><tab0003c670:·2069·643d·2269·646d·3830·3134·223e·3c74···id="idm8014"><t
0003c530:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·0003c680:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl
0003c540:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta0003c690:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·
0003c550:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab0003c6a0:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t
0003c560:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t0003c6b0:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">
0003c570:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity0003c6c0:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi
0003c580:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t0003c6d0:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<
0003c590:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D 
0003c5a0:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th>< 
0003c5b0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
0003c5c0:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:< 
0003c5d0:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t 
0003c5e0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S0003c6e0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 0003c6f0:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th
 0003c700:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
 0003c710:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot
 0003c720:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false<
 0003c730:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
0003c5f0:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td0003c740:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><
0003c600:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr0003c750:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></
0003c610:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c0003c760:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>
 0003c770:·3c63·6f64·653e·696e·636c·7564·6520·696e··<code>include·in
 0003c780:·7374·616c·6c5f·6169·6465·0a0a·636c·6173··stall_aide..clas
 0003c790:·7320·696e·7374·616c·6c5f·6169·6465·207b··s·install_aide·{
 0003c7a0:·0a20·2070·6163·6b61·6765·207b·2027·6169··.··package·{·'ai
 0003c7b0:·6465·273a·0a20·2020·2065·6e73·7572·6520··de':.····ensure·
 0003c7c0:·3d26·6774·3b20·2769·6e73·7461·6c6c·6564··=&gt;·'installed
 0003c7d0:·272c·0a20·207d·0a7d·0a3c·2f63·6f64·653e··',.··}.}.</code>
 0003c7e0:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c
 0003c7f0:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su
 0003c800:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg
0003c620:·6f64·653e·0a64·6e66·2069·6e73·7461·6c6c··ode>.dnf·install 
0003c630:·2061·6964·650a·3c2f·636f·6465·3e3c·2f70···aide.</code></p 
0003c640:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas 
0003c650:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe 
0003c660:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle= 
0003c670:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data- 
0003c680:·7461·7267·6574·3d22·2369·646d·3830·3134··target="#idm8014 
0003c690:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r 
0003c6a0:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari 
0003c6b0:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals 
0003c6c0:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa 
0003c6d0:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr 
0003c6e0:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat 
0003c6f0:·696f·6e20·416e·6163·6f6e·6461·2073·6e69··ion·Anaconda·sni 
0003c700:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br> 
0003c710:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane 
0003c720:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla0003c810:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da
 0003c820:·7461·2d74·6172·6765·743d·2223·6964·6d38··ta-target="#idm8
 0003c830:·3031·3522·2074·6162·696e·6465·783d·2230··015"·tabindex="0
 0003c840:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
 0003c850:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
 0003c860:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
 0003c870:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
 0003c880:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
 0003c890:·6961·7469·6f6e·2073·6372·6970·7420·e287··iation·script·..
 0003c8a0:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl
 0003c8b0:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla
 0003c8c0:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id
 0003c8d0:·3d22·6964·6d38·3031·3522·3e3c·7461·626c··="idm8015"><tabl
 0003c8e0:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t
 0003c8f0:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab
 0003c900:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl
 0003c910:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr
 0003c920:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:
0003c730:·7073·6522·2069·643d·2269·646d·3830·3134··pse"·id="idm8014 
0003c740:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class=" 
0003c750:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri 
0003c760:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border 
0003c770:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens 
0003c780:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp 
0003c790:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td> 
0003c7a0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr 
0003c7b0:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption: 
0003c7c0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td 
0003c7d0:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re 
0003c7e0:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa 
0003c7f0:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr 
0003c800:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</ 
0003c810:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t 
0003c820:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table>< 
0003c830:·7072·653e·3c63·6f64·653e·0a70·6163·6b61··pre><code>.packa 
0003c840:·6765·202d·2d61·6464·3d61·6964·650a·3c2f··ge·--add=aide.</ 
0003c850:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div 
0003c860:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b 
0003c870:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data 
0003c880:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps 
0003c890:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target=" 
0003c8a0:·2369·646d·3830·3135·2220·7461·6269·6e64··#idm8015"·tabind 
0003c8b0:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but 
0003c8c0:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand 
0003c8d0:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title 
0003c8e0:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re 
0003c8f0:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!"> 
0003c900:·5265·6d65·6469·6174·696f·6e20·4f53·4275··Remediation·OSBu 
Max diff block lines reached; 1526872/1554086 bytes (98.25%) of diff not shown.
171 KB
html2text {}
    
Offset 176, 52 lines modifiedOffset 176, 38 lines modified
176 ··-·PCI-DSSv4-11.5.2176 ··-·PCI-DSSv4-11.5.2
177 ··-·enable_strategy177 ··-·enable_strategy
178 ··-·low_complexity178 ··-·low_complexity
179 ··-·low_disruption179 ··-·low_disruption
180 ··-·medium_severity180 ··-·medium_severity
181 ··-·no_reboot_needed181 ··-·no_reboot_needed
182 ··-·package_aide_installed182 ··-·package_aide_installed
183 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
184 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
185 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
186 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
187 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
188 dnf·install·aide 
189 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
190 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
191 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
192 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
193 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
194 package·--add=aide 
195 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8183 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
196 [[packages]]184 [[packages]]
197 name·=·"aide"185 name·=·"aide"
198 version·=·"*"186 version·=·"*"
199 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
200 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
201 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
202 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
203 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
204 package·install·aide 
205 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8187 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
206 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low188 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
207 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low189 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
208 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false190 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
209 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable191 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
210 include·install_aide192 include·install_aide
  
211 class·install_aide·{193 class·install_aide·{
212 ··package·{·'aide':194 ··package·{·'aide':
213 ····ensure·=>·'installed',195 ····ensure·=>·'installed',
214 ··}196 ··}
215 }197 }
 198 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 199 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 200 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 201 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 202 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 203 package·install·aide
216 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8204 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
217 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low205 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
218 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low206 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
219 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false207 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
220 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable208 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
221 #·Remediation·is·applicable·only·in·certain·platforms209 #·Remediation·is·applicable·only·in·certain·platforms
222 if·rpm·--quiet·-q·kernel;·then210 if·rpm·--quiet·-q·kernel;·then
Offset 229, 14 lines modifiedOffset 215, 28 lines modified
229 if·!·rpm·-q·--quiet·"aide"·;·then215 if·!·rpm·-q·--quiet·"aide"·;·then
230 ····yum·install·-y·"aide"216 ····yum·install·-y·"aide"
231 fi217 fi
  
232 else218 else
233 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'219 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
234 fi220 fi
 221 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 222 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 223 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 224 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 225 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 226 package·--add=aide
 227 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 228 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 229 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 230 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 231 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 232 dnf·install·aide
235 Group  ·Federal·Information·Processing·Standard·(FIPS)·  Group·contains·2·rules233 Group  ·Federal·Information·Processing·Standard·(FIPS)·  Group·contains·2·rules
236 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·Federal·Information·Processing·Standard·(FIPS)·is·a·computer·security·standard·which·is·developed·by·the·U.S.·Government·and·industry·working·groups·to·validate·the·quality·of·cryptographic·modules.·The·FIPS·standard·provides·four·security·levels·to·ensure·adequate·coverage·of·different·industries,·implementation·of·cryptographic·modules,·and·organizational·sizes·and·requirements.234 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·Federal·Information·Processing·Standard·(FIPS)·is·a·computer·security·standard·which·is·developed·by·the·U.S.·Government·and·industry·working·groups·to·validate·the·quality·of·cryptographic·modules.·The·FIPS·standard·provides·four·security·levels·to·ensure·adequate·coverage·of·different·industries,·implementation·of·cryptographic·modules,·and·organizational·sizes·and·requirements.
  
237 FIPS·140-2·is·the·current·standard·for·validating·that·mechanisms·used·to·access·cryptographic·modules·utilize·authentication·that·meets·industry·and·government·requirements.·For·government·systems,·this·allows·Security·Levels·1,·2,·3,·or·4·for·use·on·Red·Hat·Enterprise·Linux·8.235 FIPS·140-2·is·the·current·standard·for·validating·that·mechanisms·used·to·access·cryptographic·modules·utilize·authentication·that·meets·industry·and·government·requirements.·For·government·systems,·this·allows·Security·Levels·1,·2,·3,·or·4·for·use·on·Red·Hat·Enterprise·Linux·8.
  
238 See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8c\x8c_\x8s\x8s_\x8r\x8r_\x8c\x8c_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8l\x8l_\x8i\x8i_\x8c\x8c_\x8a\x8a_\x8t\x8t_\x8i\x8i_\x8o\x8o_\x8n\x8n_\x8s\x8s_\x8/\x8/_\x8P\x8P_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x8h\x8h_\x8t\x8t_\x8m\x8m_\x8l\x8l·for·more·information.236 See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8c\x8c_\x8s\x8s_\x8r\x8r_\x8c\x8c_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8l\x8l_\x8i\x8i_\x8c\x8c_\x8a\x8a_\x8t\x8t_\x8i\x8i_\x8o\x8o_\x8n\x8n_\x8s\x8s_\x8/\x8/_\x8P\x8P_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x8h\x8h_\x8t\x8t_\x8m\x8m_\x8l\x8l·for·more·information.
239 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·D\x8Dr\x8ra\x8ac\x8cu\x8ut\x8t·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8du\x8ul\x8le\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*237 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·D\x8Dr\x8ra\x8ac\x8cu\x8ut\x8t·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8du\x8ul\x8le\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
Offset 315, 61 lines modifiedOffset 315, 61 lines modified
315 ··tags:315 ··tags:
316 ··-·enable_strategy316 ··-·enable_strategy
317 ··-·low_complexity317 ··-·low_complexity
318 ··-·low_disruption318 ··-·low_disruption
319 ··-·medium_severity319 ··-·medium_severity
320 ··-·no_reboot_needed320 ··-·no_reboot_needed
321 ··-·package_crypto-policies_installed321 ··-·package_crypto-policies_installed
322 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
323 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
324 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
325 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
326 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
327 dnf·install·crypto-policies 
328 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
329 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
330 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
331 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
332 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
333 package·--add=crypto-policies 
334 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8322 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
335 [[packages]]323 [[packages]]
336 name·=·"crypto-policies"324 name·=·"crypto-policies"
337 version·=·"*"325 version·=·"*"
338 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
339 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
340 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
341 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
342 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
343 package·install·crypto-policies 
344 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8326 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
345 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low327 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
346 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low328 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
347 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false329 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
348 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable330 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
Max diff block lines reached; 170358/175533 bytes (97.05%) of diff not shown.
556 KB
./usr/share/doc/ssg-nondebian/ssg-centos8-guide-e8.html
    
Offset 19797, 277 lines modifiedOffset 19797, 277 lines modified
0004d540:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm0004d540:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
0004d550:·3132·3737·3722·2074·6162·696e·6465·783d··12777"·tabindex=0004d550:·3132·3737·3722·2074·6162·696e·6465·783d··12777"·tabindex=
0004d560:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button0004d560:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button
0004d570:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=0004d570:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=
0004d580:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A0004d580:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A
0004d590:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea0004d590:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea
0004d5a0:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem0004d5a0:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem
 0004d5b0:·6564·6961·7469·6f6e·204f·5342·7569·6c64··ediation·OSBuild
 0004d5c0:·2042·6c75·6570·7269·6e74·2073·6e69·7070···Blueprint·snipp
0004d5b0:·6564·6961·7469·6f6e·2073·6372·6970·7420··ediation·script· 
0004d5c0:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div· 
0004d5d0:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col 
0004d5e0:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"· 
0004d5f0:·6964·3d22·6964·6d31·3237·3737·223e·3c74··id="idm12777"><t 
0004d600:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl 
0004d610:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped· 
0004d620:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t 
0004d630:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed"> 
0004d640:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi 
0004d650:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low< 
0004d660:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0004d670:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th 
0004d680:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t 
0004d690:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot 
0004d6a0:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false< 
0004d6b0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0004d6c0:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th>< 
0004d6d0:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></ 
0004d6e0:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre> 
0004d6f0:·3c63·6f64·653e·0a64·6e66·2069·6e73·7461··<code>.dnf·insta 
0004d700:·6c6c·2072·6561·720a·3c2f·636f·6465·3e3c··ll·rear.</code>< 
0004d710:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl 
0004d720:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc 
0004d730:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl 
0004d740:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat 
0004d750:·612d·7461·7267·6574·3d22·2369·646d·3132··a-target="#idm12 
0004d760:·3737·3822·2074·6162·696e·6465·783d·2230··778"·tabindex="0 
0004d770:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"· 
0004d780:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f 
0004d790:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act 
0004d7a0:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal" 
0004d7b0:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed 
0004d7c0:·6961·7469·6f6e·2041·6e61·636f·6e64·6120··iation·Anaconda· 
0004d7d0:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a>< 
0004d7e0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p 
0004d7f0:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co 
0004d800:·6c6c·6170·7365·2220·6964·3d22·6964·6d31··llapse"·id="idm1 
0004d810:·3237·3738·223e·3c74·6162·6c65·2063·6c61··2778"><table·cla 
0004d820:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table- 
0004d830:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo 
0004d840:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con 
0004d850:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th> 
0004d860:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th> 
0004d870:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
0004d880:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt 
0004d890:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low 
0004d8a0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
0004d8b0:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t 
0004d8c0:·643e·6661·6c73·653c·2f74·643e·3c2f·7472··d>false</td></tr 
0004d8d0:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg 
0004d8e0:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl 
0004d8f0:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab 
0004d900:·6c65·3e3c·7072·653e·3c63·6f64·653e·0a70··le><pre><code>.p 
0004d910:·6163·6b61·6765·202d·2d61·6464·3d72·6561··ackage·--add=rea 
0004d920:·720a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··r.</code></pre>< 
0004d930:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b 
0004d940:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"· 
0004d950:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col 
0004d960:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ 
0004d970:·6574·3d22·2369·646d·3132·3737·3922·2074··et="#idm12779"·t 
0004d980:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role 
0004d990:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e 
0004d9a0:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"· 
0004d9b0:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate· 
0004d9c0:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href= 
0004d9d0:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation 
0004d9e0:·204f·5342·7569·6c64·2042·6c75·6570·7269···OSBuild·Bluepri 
0004d9f0:·6e74·2073·6e69·7070·6574·20e2·87b2·3c2f··nt·snippet·...</ 
0004da00:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class 
0004da10:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse 
0004da20:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i 
0004da30:·646d·3132·3737·3922·3e3c·7072·653e·3c63··dm12779"><pre><c 
0004da40:·6f64·653e·0a5b·5b70·6163·6b61·6765·735d··ode>.[[packages] 
0004da50:·5d0a·6e61·6d65·203d·2022·7265·6172·220a··].name·=·"rear". 
0004da60:·7665·7273·696f·6e20·3d20·222a·220a·3c2f··version·=·"*".</ 
0004da70:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div 
0004da80:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b 
0004da90:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data 
0004daa0:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps 
0004dab0:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target=" 
0004dac0:·2369·646d·3132·3738·3022·2074·6162·696e··#idm12780"·tabin 
0004dad0:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu 
0004dae0:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan 
0004daf0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl 
0004db00:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r 
0004db10:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!" 
0004db20:·3e52·656d·6564·6961·7469·6f6e·2073·6372··>Remediation·scr 
0004db30:·6970·7420·e287·b23c·2f61·3e3c·6272·3e3c··ipt·...</a><br>< 
0004db40:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel 
0004db50:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap 
0004db60:·7365·2220·6964·3d22·6964·6d31·3237·3830··se"·id="idm12780 
0004db70:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class=" 
0004db80:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri 
0004db90:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border 
0004dba0:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens 
0004dbb0:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp 
0004dbc0:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td> 
0004dbd0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr 
0004dbe0:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption: 
0004dbf0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td 
0004dc00:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re 
0004dc10:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa 
0004dc20:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr 
0004dc30:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</ 
0004dc40:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t 
0004dc50:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table>< 
0004dc60:·7072·653e·3c63·6f64·653e·0a70·6163·6b61··pre><code>.packa 
0004dc70:·6765·2069·6e73·7461·6c6c·2072·6561·720a··ge·install·rear. 
0004dc80:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d 
0004dc90:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn 
0004dca0:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da 
0004dcb0:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla 
0004dcc0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target 
0004dcd0:·3d22·2369·646d·3132·3738·3122·2074·6162··="#idm12781"·tab 
0004dce0:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role=" 
0004dcf0:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp 
0004dd00:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti 
Max diff block lines reached; 466912/503786 bytes (92.68%) of diff not shown.
64.2 KB
html2text {}
    
Offset 1175, 52 lines modifiedOffset 1175, 38 lines modified
1175 ··tags:1175 ··tags:
1176 ··-·enable_strategy1176 ··-·enable_strategy
1177 ··-·low_complexity1177 ··-·low_complexity
1178 ··-·low_disruption1178 ··-·low_disruption
1179 ··-·medium_severity1179 ··-·medium_severity
1180 ··-·no_reboot_needed1180 ··-·no_reboot_needed
1181 ··-·package_rear_installed1181 ··-·package_rear_installed
1182 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
1183 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
1184 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
1185 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
1186 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
1187 dnf·install·rear 
1188 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
1189 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
1190 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
1191 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
1192 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
1193 package·--add=rear 
1194 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81182 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
1195 [[packages]]1183 [[packages]]
1196 name·=·"rear"1184 name·=·"rear"
1197 version·=·"*"1185 version·=·"*"
1198 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
1199 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
1200 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
1201 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
1202 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
1203 package·install·rear 
1204 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81186 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1205 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1187 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1206 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1188 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1207 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1189 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1208 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1190 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1209 include·install_rear1191 include·install_rear
  
1210 class·install_rear·{1192 class·install_rear·{
1211 ··package·{·'rear':1193 ··package·{·'rear':
1212 ····ensure·=>·'installed',1194 ····ensure·=>·'installed',
1213 ··}1195 ··}
1214 }1196 }
 1197 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 1198 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1199 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1200 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1201 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 1202 package·install·rear
1215 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81203 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1216 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1204 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1217 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1205 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1218 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1206 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1219 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1207 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1220 #·Remediation·is·applicable·only·in·certain·platforms1208 #·Remediation·is·applicable·only·in·certain·platforms
1221 if·!·(·(·(·(·grep·-sqE·"^.*\.aarch64$"·/proc/sys/kernel/osrelease·||·grep·-sqE·"^aarch64$"·/proc/sys/kernel/arch;·)·&&·grep·-qP·"^ID=[\"']?ol[\"']?$"·"/etc/os-release"·&&·{·real="$(grep·-P·"^VERSION_ID=[\"']?[\w.]+[\"']?$"·/etc/os-release·|·sed·"s/^VERSION_ID=[\"']\?\([^\"']\+\)[\"']\?$/\1/")";·expected="9.0";·printf·"%s\n%s"·"$expected"·"$real"·|·sort·-VC;·}·)·||·(·(·grep·-sqE·"^.*\.aarch64$"·/proc/sys/kernel/osrelease·||·grep·-sqE·"^aarch64$"·/proc/sys/kernel/arch;·)·&&·grep·-qP·"^ID=[\"']?rhel[\"']?$"·"/etc/os-release"·&&·{·real="$(grep·-P·"^VERSION_ID=[\"']?[\w.]+[\"']?$"·/etc/os-release·|·sed·"s/^VERSION_ID=[\"']\?\([^\"']\+\)[\"']\?$/\1/")";·expected="9.0";·printf·"%s\n%s"·"$expected"·"$real"·|·sort·-VC;·}·)·||·(·grep·-qP·"^ID=[\"']?rhel[\"']?$"·"/etc/os-release"·&&·{·real="$(grep·-P·"^VERSION_ID=[\"']?[\w.]+[\"']?$"·/etc/os-release·|·sed·"s/^VERSION_ID=[\"']\?\([^\"']\+\)[\"']\?$/\1/")";·expected="8.4";·printf·"%s\n%s"·"$real"·"$expected"·|·sort·-VC;·}·&&·(·grep·-sqE·"^.*\.s390x$"·/proc/sys/kernel/osrelease·||·grep·-sqE·"^s390x$"·/proc/sys/kernel/arch;·)·)·)·);·then1209 if·!·(·(·(·(·grep·-sqE·"^.*\.aarch64$"·/proc/sys/kernel/osrelease·||·grep·-sqE·"^aarch64$"·/proc/sys/kernel/arch;·)·&&·grep·-qP·"^ID=[\"']?ol[\"']?$"·"/etc/os-release"·&&·{·real="$(grep·-P·"^VERSION_ID=[\"']?[\w.]+[\"']?$"·/etc/os-release·|·sed·"s/^VERSION_ID=[\"']\?\([^\"']\+\)[\"']\?$/\1/")";·expected="9.0";·printf·"%s\n%s"·"$expected"·"$real"·|·sort·-VC;·}·)·||·(·(·grep·-sqE·"^.*\.aarch64$"·/proc/sys/kernel/osrelease·||·grep·-sqE·"^aarch64$"·/proc/sys/kernel/arch;·)·&&·grep·-qP·"^ID=[\"']?rhel[\"']?$"·"/etc/os-release"·&&·{·real="$(grep·-P·"^VERSION_ID=[\"']?[\w.]+[\"']?$"·/etc/os-release·|·sed·"s/^VERSION_ID=[\"']\?\([^\"']\+\)[\"']\?$/\1/")";·expected="9.0";·printf·"%s\n%s"·"$expected"·"$real"·|·sort·-VC;·}·)·||·(·grep·-qP·"^ID=[\"']?rhel[\"']?$"·"/etc/os-release"·&&·{·real="$(grep·-P·"^VERSION_ID=[\"']?[\w.]+[\"']?$"·/etc/os-release·|·sed·"s/^VERSION_ID=[\"']\?\([^\"']\+\)[\"']\?$/\1/")";·expected="8.4";·printf·"%s\n%s"·"$real"·"$expected"·|·sort·-VC;·}·&&·(·grep·-sqE·"^.*\.s390x$"·/proc/sys/kernel/osrelease·||·grep·-sqE·"^s390x$"·/proc/sys/kernel/arch;·)·)·)·);·then
Offset 1228, 14 lines modifiedOffset 1214, 28 lines modified
1228 if·!·rpm·-q·--quiet·"rear"·;·then1214 if·!·rpm·-q·--quiet·"rear"·;·then
1229 ····yum·install·-y·"rear"1215 ····yum·install·-y·"rear"
1230 fi1216 fi
  
1231 else1217 else
1232 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'1218 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
1233 fi1219 fi
 1220 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 1221 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1222 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1223 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1224 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 1225 package·--add=rear
 1226 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 1227 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1228 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1229 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1230 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 1231 dnf·install·rear
1234 Group  ·Updating·Software·  Group·contains·6·rules1232 Group  ·Updating·Software·  Group·contains·6·rules
1235 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·yum·command·line·tool·is·used·to·install·and·update·software·packages.·The·system·also·provides·a·graphical·software·update·tool·in·the·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·menu,·in·the·A\x8Ad\x8dm\x8mi\x8in\x8ni\x8is\x8st\x8tr\x8ra\x8at\x8ti\x8io\x8on\x8n·submenu,·called·S\x8So\x8of\x8ft\x8tw\x8wa\x8ar\x8re\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8e.1233 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·yum·command·line·tool·is·used·to·install·and·update·software·packages.·The·system·also·provides·a·graphical·software·update·tool·in·the·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·menu,·in·the·A\x8Ad\x8dm\x8mi\x8in\x8ni\x8is\x8st\x8tr\x8ra\x8at\x8ti\x8io\x8on\x8n·submenu,·called·S\x8So\x8of\x8ft\x8tw\x8wa\x8ar\x8re\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8e.
  
1236 Red·Hat·Enterprise·Linux·8·systems·contain·an·installed·software·catalog·called·the·RPM·database,·which·records·metadata·of·installed·packages.·Consistently·using·yum·or·the·graphical·S\x8So\x8of\x8ft\x8tw\x8wa\x8ar\x8re\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8e·for·all·software·installation·allows·for·insight·into·the·current·inventory·of·installed·software·on·the·system.1234 Red·Hat·Enterprise·Linux·8·systems·contain·an·installed·software·catalog·called·the·RPM·database,·which·records·metadata·of·installed·packages.·Consistently·using·yum·or·the·graphical·S\x8So\x8of\x8ft\x8tw\x8wa\x8ar\x8re\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8e·for·all·software·installation·allows·for·insight·into·the·current·inventory·of·installed·software·on·the·system.
  
1237 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·d\x8dn\x8nf\x8f-\x8-a\x8au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8c·t\x8to\x8o·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·O\x8On\x8nl\x8ly\x8y·S\x8Se\x8ec\x8cu\x8ur\x8ri\x8it\x8ty\x8y·U\x8Up\x8pd\x8da\x8at\x8te\x8es\x8s·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*1235 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·d\x8dn\x8nf\x8f-\x8-a\x8au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8c·t\x8to\x8o·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·O\x8On\x8nl\x8ly\x8y·S\x8Se\x8ec\x8cu\x8ur\x8ri\x8it\x8ty\x8y·U\x8Up\x8pd\x8da\x8at\x8te\x8es\x8s·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
1238 To·configure·dnf-automatic·to·install·only·security·updates·automatically,·set·upgrade_type·to·security·under·[commands]·section·in·/etc/dnf/automatic.conf.1236 To·configure·dnf-automatic·to·install·only·security·updates·automatically,·set·upgrade_type·to·security·under·[commands]·section·in·/etc/dnf/automatic.conf.
Offset 2361, 52 lines modifiedOffset 2361, 38 lines modified
2361 ··-·NIST-800-53-CM-6(a)2361 ··-·NIST-800-53-CM-6(a)
2362 ··-·enable_strategy2362 ··-·enable_strategy
2363 ··-·low_complexity2363 ··-·low_complexity
2364 ··-·low_disruption2364 ··-·low_disruption
2365 ··-·medium_severity2365 ··-·medium_severity
2366 ··-·no_reboot_needed2366 ··-·no_reboot_needed
2367 ··-·package_rsyslog_installed2367 ··-·package_rsyslog_installed
2368 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
2369 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
2370 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
2371 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
2372 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
2373 dnf·install·rsyslog 
2374 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
2375 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
2376 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
2377 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
2378 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
2379 package·--add=rsyslog 
2380 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x82368 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
2381 [[packages]]2369 [[packages]]
2382 name·=·"rsyslog"2370 name·=·"rsyslog"
2383 version·=·"*"2371 version·=·"*"
2384 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
2385 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
2386 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
2387 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
2388 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
2389 package·install·rsyslog 
2390 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x82372 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
2391 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low2373 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
2392 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low2374 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
2393 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false2375 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
2394 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable2376 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
Max diff block lines reached; 59597/65694 bytes (90.72%) of diff not shown.
359 KB
./usr/share/doc/ssg-nondebian/ssg-centos8-guide-hipaa.html
    
Offset 22314, 129 lines modifiedOffset 22314, 129 lines modified
00057290:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm00057290:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
000572a0:·3136·3930·3822·2074·6162·696e·6465·783d··16908"·tabindex=000572a0:·3136·3930·3822·2074·6162·696e·6465·783d··16908"·tabindex=
000572b0:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button000572b0:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button
000572c0:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=000572c0:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=
000572d0:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A000572d0:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A
000572e0:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea000572e0:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea
000572f0:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem000572f0:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem
00057300:·6564·6961·7469·6f6e·204b·7562·6572·6e65··ediation·Kuberne00057300:·6564·6961·7469·6f6e·2050·7570·7065·7420··ediation·Puppet·
00057310:·7465·7320·736e·6970·7065·7420·e287·b23c··tes·snippet·...<00057310:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><
00057320:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas00057320:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
00057330:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps00057330:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
00057340:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="00057340:·6c6c·6170·7365·2220·6964·3d22·6964·6d31··llapse"·id="idm1
00057350:·6964·6d31·3639·3038·223e·3c74·6162·6c65··idm16908"><table00057350:·3639·3038·223e·3c74·6162·6c65·2063·6c61··6908"><table·cla
00057360:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta00057360:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-
00057370:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl00057370:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo
00057380:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table00057380:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con
00057390:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>00057390:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>
000573a0:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<000573a0:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>
 000573b0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
 000573c0:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt
 000573d0:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low
 000573e0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
 000573f0:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t
 00057400:·643e·6661·6c73·653c·2f74·643e·3c2f·7472··d>false</td></tr
 00057410:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg
 00057420:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl
 00057430:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab
 00057440:·6c65·3e3c·7072·653e·3c63·6f64·653e·696e··le><pre><code>in
 00057450:·636c·7564·6520·6469·7361·626c·655f·6465··clude·disable_de
 00057460:·6275·672d·7368·656c·6c0a·0a63·6c61·7373··bug-shell..class
 00057470:·2064·6973·6162·6c65·5f64·6562·7567·2d73···disable_debug-s
 00057480:·6865·6c6c·207b·0a20·2073·6572·7669·6365··hell·{.··service
 00057490:·207b·2764·6562·7567·2d73·6865·6c6c·273a···{'debug-shell':
 000574a0:·0a20·2020·2065·6e61·626c·6520·3d26·6774··.····enable·=&gt
 000574b0:·3b20·6661·6c73·652c·0a20·2020·2065·6e73··;·false,.····ens
 000574c0:·7572·6520·3d26·6774·3b20·2773·746f·7070··ure·=&gt;·'stopp
 000574d0:·6564·272c·0a20·207d·0a7d·0a3c·2f63·6f64··ed',.··}.}.</cod
 000574e0:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a
 000574f0:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn-
 00057500:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to
 00057510:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"·
 00057520:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
 00057530:·6d31·3639·3039·2220·7461·6269·6e64·6578··m16909"·tabindex
 00057540:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto
 00057550:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded
 00057560:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="
 00057570:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve
 00057580:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re
 00057590:·6d65·6469·6174·696f·6e20·7363·7269·7074··mediation·script
 000575a0:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
 000575b0:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
 000575c0:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
 000575d0:·2069·643d·2269·646d·3136·3930·3922·3e3c···id="idm16909"><
 000575e0:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab
 000575f0:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped
 00057600:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·
 00057610:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"
 00057620:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex
 00057630:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low
 00057640:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
 00057650:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t
000573b0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>00057660:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
000573c0:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis 
000573d0:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td 
000573e0:·3e6d·6564·6975·6d3c·2f74·643e·3c2f·7472··>medium</td></tr 
000573f0:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot:00057670:·7472·3e3c·7472·3e3c·7468·3e52·6562·6f6f··tr><tr><th>Reboo
00057400:·3c2f·7468·3e3c·7464·3e74·7275·653c·2f74··</th><td>true</t00057680:·743a·3c2f·7468·3e3c·7464·3e66·616c·7365··t:</th><td>false
 00057690:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
 000576a0:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th>
 000576b0:·3c74·643e·6469·7361·626c·653c·2f74·643e··<td>disable</td>
 000576c0:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr
 000576d0:·653e·3c63·6f64·653e·0a73·6572·7669·6365··e><code>.service
 000576e0:·2064·6973·6162·6c65·2064·6562·7567·2d73···disable·debug-s
 000576f0:·6865·6c6c·0a3c·2f63·6f64·653e·3c2f·7072··hell.</code></pr
 00057700:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class
 00057710:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes
 00057720:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle="
 00057730:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t
 00057740:·6172·6765·743d·2223·6964·6d31·3639·3130··arget="#idm16910
 00057750:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r
 00057760:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari
 00057770:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals
 00057780:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa
 00057790:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr
 000577a0:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat
 000577b0:·696f·6e20·4b75·6265·726e·6574·6573·2073··ion·Kubernetes·s
 000577c0:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b
 000577d0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
 000577e0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
 000577f0:·6c61·7073·6522·2069·643d·2269·646d·3136··lapse"·id="idm16
 00057800:·3931·3022·3e3c·7461·626c·6520·636c·6173··910"><table·clas
 00057810:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s
 00057820:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor
 00057830:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond
00057410:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S00057840:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C
00057420:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td 
00057430:·3e64·6973·6162·6c65·3c2f·7464·3e3c·2f74··>disable</td></t 
00057440:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre>< 
00057450:·636f·6465·3e61·7069·5665·7273·696f·6e3a··code>apiVersion: 
00057460:·206d·6163·6869·6e65·636f·6e66·6967·7572···machineconfigur 
00057470:·6174·696f·6e2e·6f70·656e·7368·6966·742e··ation.openshift. 
00057480:·696f·2f76·310a·6b69·6e64·3a20·4d61·6368··io/v1.kind:·Mach 
00057490:·696e·6543·6f6e·6669·670a·7370·6563·3a0a··ineConfig.spec:. 
000574a0:·2020·636f·6e66·6967·3a0a·2020·2020·6967····config:.····ig 
000574b0:·6e69·7469·6f6e·3a0a·2020·2020·2020·7665··nition:.······ve 
000574c0:·7273·696f·6e3a·2033·2e31·2e30·0a20·2020··rsion:·3.1.0.··· 
000574d0:·2073·7973·7465·6d64·3a0a·2020·2020·2020···systemd:.······ 
000574e0:·756e·6974·733a·0a20·2020·2020·202d·206e··units:.······-·n 
000574f0:·616d·653a·2064·6562·7567·2d73·6865·6c6c··ame:·debug-shell 
00057500:·2e73·6572·7669·6365·0a20·2020·2020·2020··.service.······· 
00057510:·2065·6e61·626c·6564·3a20·6661·6c73·650a···enabled:·false. 
00057520:·2020·2020·2020·2020·6d61·736b·3a20·7472··········mask:·tr00057850:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><
 00057860:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
 00057870:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti
 00057880:·6f6e·3a3c·2f74·683e·3c74·643e·6d65·6469··on:</th><td>medi
 00057890:·756d·3c2f·7464·3e3c·2f74·723e·3c74·723e··um</td></tr><tr>
 000578a0:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th>
 000578b0:·3c74·643e·7472·7565·3c2f·7464·3e3c·2f74··<td>true</td></t
 000578c0:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate
 000578d0:·6779·3a3c·2f74·683e·3c74·643e·6469·7361··gy:</th><td>disa
 000578e0:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t
 000578f0:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>
 00057900:·6170·6956·6572·7369·6f6e·3a20·6d61·6368··apiVersion:·mach
 00057910:·696e·6563·6f6e·6669·6775·7261·7469·6f6e··ineconfiguration
 00057920:·2e6f·7065·6e73·6869·6674·2e69·6f2f·7631··.openshift.io/v1
 00057930:·0a6b·696e·643a·204d·6163·6869·6e65·436f··.kind:·MachineCo
 00057940:·6e66·6967·0a73·7065·633a·0a20·2063·6f6e··nfig.spec:.··con
Max diff block lines reached; 307884/324334 bytes (94.93%) of diff not shown.
42.3 KB
html2text {}
    
Offset 1719, 14 lines modifiedOffset 1719, 34 lines modified
1719 ··-·medium_severity1719 ··-·medium_severity
1720 ··-·no_reboot_needed1720 ··-·no_reboot_needed
1721 ··-·service_debug-shell_disabled1721 ··-·service_debug-shell_disabled
1722 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81722 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
1723 [customizations.services]1723 [customizations.services]
1724 masked·=·["debug-shell"]1724 masked·=·["debug-shell"]
 1725 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 1726 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1727 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1728 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1729 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 1730 include·disable_debug-shell
  
 1731 class·disable_debug-shell·{
 1732 ··service·{'debug-shell':
 1733 ····enable·=>·false,
 1734 ····ensure·=>·'stopped',
 1735 ··}
 1736 }
 1737 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 1738 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1739 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1740 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1741 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
  
 1742 service·disable·debug-shell
1725 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81743 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1726 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1744 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1727 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium1745 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
1728 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true1746 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
1729 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable1747 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
1730 apiVersion:·machineconfiguration.openshift.io/v11748 apiVersion:·machineconfiguration.openshift.io/v1
1731 kind:·MachineConfig1749 kind:·MachineConfig
Offset 1738, 34 lines modifiedOffset 1758, 14 lines modified
1738 ······units:1758 ······units:
1739 ······-·name:·debug-shell.service1759 ······-·name:·debug-shell.service
1740 ········enabled:·false1760 ········enabled:·false
1741 ········mask:·true1761 ········mask:·true
1742 ······-·name:·debug-shell.socket1762 ······-·name:·debug-shell.socket
1743 ········enabled:·false1763 ········enabled:·false
1744 ········mask:·true1764 ········mask:·true
1745 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
1746 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
1747 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
1748 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
1749 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable 
  
1750 service·disable·debug-shell 
1751 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
1752 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
1753 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
1754 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
1755 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
1756 include·disable_debug-shell 
  
1757 class·disable_debug-shell·{ 
1758 ··service·{'debug-shell': 
1759 ····enable·=>·false, 
1760 ····ensure·=>·'stopped', 
1761 ··} 
1762 } 
1763 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81765 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1764 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1766 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1765 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1767 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1766 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1768 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1767 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable1769 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
1768 #·Remediation·is·applicable·only·in·certain·platforms1770 #·Remediation·is·applicable·only·in·certain·platforms
1769 if·rpm·--quiet·-q·kernel;·then1771 if·rpm·--quiet·-q·kernel;·then
Offset 3445, 14 lines modifiedOffset 3445, 34 lines modified
3445 ··-·medium_severity3445 ··-·medium_severity
3446 ··-·no_reboot_needed3446 ··-·no_reboot_needed
3447 ··-·service_autofs_disabled3447 ··-·service_autofs_disabled
3448 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x83448 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
3449 [customizations.services]3449 [customizations.services]
3450 masked·=·["autofs"]3450 masked·=·["autofs"]
 3451 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 3452 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 3453 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 3454 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 3455 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 3456 include·disable_autofs
  
 3457 class·disable_autofs·{
 3458 ··service·{'autofs':
 3459 ····enable·=>·false,
 3460 ····ensure·=>·'stopped',
 3461 ··}
 3462 }
 3463 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 3464 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 3465 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 3466 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 3467 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
  
 3468 service·disable·autofs
3451 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x83469 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
3452 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low3470 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
3453 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium3471 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
3454 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true3472 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
3455 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable3473 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
3456 apiVersion:·machineconfiguration.openshift.io/v13474 apiVersion:·machineconfiguration.openshift.io/v1
3457 kind:·MachineConfig3475 kind:·MachineConfig
Offset 3464, 34 lines modifiedOffset 3484, 14 lines modified
3464 ······units:3484 ······units:
3465 ······-·name:·autofs.service3485 ······-·name:·autofs.service
3466 ········enabled:·false3486 ········enabled:·false
3467 ········mask:·true3487 ········mask:·true
3468 ······-·name:·autofs.socket3488 ······-·name:·autofs.socket
3469 ········enabled:·false3489 ········enabled:·false
3470 ········mask:·true3490 ········mask:·true
3471 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
3472 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
3473 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
3474 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
3475 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable 
  
3476 service·disable·autofs 
3477 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
3478 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
3479 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
3480 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
3481 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
3482 include·disable_autofs 
  
3483 class·disable_autofs·{ 
Max diff block lines reached; 38844/43247 bytes (89.82%) of diff not shown.
731 KB
./usr/share/doc/ssg-nondebian/ssg-centos8-guide-ism_o.html
    
Offset 17679, 208 lines modifiedOffset 17679, 208 lines modified
000450e0:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id000450e0:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
000450f0:·6d38·3031·3322·2074·6162·696e·6465·783d··m8013"·tabindex=000450f0:·6d38·3031·3322·2074·6162·696e·6465·783d··m8013"·tabindex=
00045100:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button00045100:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button
00045110:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=00045110:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=
00045120:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A00045120:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A
00045130:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea00045130:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea
00045140:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem00045140:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem
00045150:·6564·6961·7469·6f6e·2073·6372·6970·7420··ediation·script·00045150:·6564·6961·7469·6f6e·204f·5342·7569·6c64··ediation·OSBuild
 00045160:·2042·6c75·6570·7269·6e74·2073·6e69·7070···Blueprint·snipp
 00045170:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d
 00045180:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-
 00045190:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps
 000451a0:·6522·2069·643d·2269·646d·3830·3133·223e··e"·id="idm8013">
 000451b0:·3c70·7265·3e3c·636f·6465·3e0a·5b5b·7061··<pre><code>.[[pa
 000451c0:·636b·6167·6573·5d5d·0a6e·616d·6520·3d20··ckages]].name·=·
 000451d0:·2261·6964·6522·0a76·6572·7369·6f6e·203d··"aide".version·=
 000451e0:·2022·2a22·0a3c·2f63·6f64·653e·3c2f·7072···"*".</code></pr
 000451f0:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class
 00045200:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes
 00045210:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle="
 00045220:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t
 00045230:·6172·6765·743d·2223·6964·6d38·3031·3422··arget="#idm8014"
 00045240:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro
 00045250:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria
 00045260:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false
 00045270:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat
 00045280:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre
 00045290:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati
 000452a0:·6f6e·2050·7570·7065·7420·736e·6970·7065··on·Puppet·snippe
00045160:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·000452b0:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di
00045170:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col000452c0:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c
00045180:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·000452d0:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse
00045190:·6964·3d22·6964·6d38·3031·3322·3e3c·7461··id="idm8013"><ta000452e0:·2220·6964·3d22·6964·6d38·3031·3422·3e3c··"·id="idm8014"><
000451a0:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table000452f0:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab
000451b0:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t00045300:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped
000451c0:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta00045310:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·
000451d0:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><00045320:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"
000451e0:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit00045330:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex
000451f0:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</00045340:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low
00045200:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
00045210:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th> 
00045220:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
00045230:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot: 
00045240:·3c2f·7468·3e3c·7464·3e66·616c·7365·3c2f··</th><td>false</ 
00045250:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>00045350:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
 00045360:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t
 00045370:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
 00045380:·7472·3e3c·7472·3e3c·7468·3e52·6562·6f6f··tr><tr><th>Reboo
 00045390:·743a·3c2f·7468·3e3c·7464·3e66·616c·7365··t:</th><td>false
 000453a0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
00045260:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t000453b0:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th>
00045270:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t000453c0:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td><
00045280:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><000453d0:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre
 000453e0:·3e3c·636f·6465·3e69·6e63·6c75·6465·2069··><code>include·i
 000453f0:·6e73·7461·6c6c·5f61·6964·650a·0a63·6c61··nstall_aide..cla
 00045400:·7373·2069·6e73·7461·6c6c·5f61·6964·6520··ss·install_aide·
 00045410:·7b0a·2020·7061·636b·6167·6520·7b20·2761··{.··package·{·'a
 00045420:·6964·6527·3a0a·2020·2020·656e·7375·7265··ide':.····ensure
 00045430:·203d·2667·743b·2027·696e·7374·616c·6c65···=&gt;·'installe
 00045440:·6427·2c0a·2020·7d0a·7d0a·3c2f·636f·6465··d',.··}.}.</code
 00045450:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a·
 00045460:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s
 00045470:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog
 00045480:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d
 00045490:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
 000454a0:·3830·3135·2220·7461·6269·6e64·6578·3d22··8015"·tabindex="
 000454b0:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
 000454c0:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
 000454d0:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
 000454e0:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
 000454f0:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
 00045500:·6469·6174·696f·6e20·7363·7269·7074·20e2··diation·script·.
 00045510:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c
 00045520:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
 00045530:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
 00045540:·643d·2269·646d·3830·3135·223e·3c74·6162··d="idm8015"><tab
 00045550:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·
 00045560:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta
 00045570:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab
 00045580:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t
 00045590:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity
00045290:·636f·6465·3e0a·646e·6620·696e·7374·616c··code>.dnf·instal 
000452a0:·6c20·6169·6465·0a3c·2f63·6f64·653e·3c2f··l·aide.</code></ 
000452b0:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla 
000452c0:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ 
000452d0:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle 
000452e0:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data 
000452f0:·2d74·6172·6765·743d·2223·6964·6d38·3031··-target="#idm801 
00045300:·3422·2074·6162·696e·6465·783d·2230·2220··4"·tabindex="0"· 
00045310:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar 
00045320:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal 
00045330:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ 
00045340:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h 
00045350:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia 
00045360:·7469·6f6e·2041·6e61·636f·6e64·6120·736e··tion·Anaconda·sn 
00045370:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br 
00045380:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan 
00045390:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll 
000453a0:·6170·7365·2220·6964·3d22·6964·6d38·3031··apse"·id="idm801 
000453b0:·3422·3e3c·7461·626c·6520·636c·6173·733d··4"><table·class= 
000453c0:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str 
000453d0:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde 
000453e0:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden 
000453f0:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com 
00045400:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td 
00045410:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t 
00045420:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption 
00045430:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t 
00045440:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e52··d></tr><tr><th>R 
00045450:·6562·6f6f·743a·3c2f·7468·3e3c·7464·3e66··eboot:</th><td>f 
00045460:·616c·7365·3c2f·7464·3e3c·2f74·723e·3c74··alse</td></tr><t 
00045470:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:< 
00045480:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</ 
00045490:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table> 
000454a0:·3c70·7265·3e3c·636f·6465·3e0a·7061·636b··<pre><code>.pack 
000454b0:·6167·6520·2d2d·6164·643d·6169·6465·0a3c··age·--add=aide.< 
000454c0:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di 
000454d0:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn· 
000454e0:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat 
000454f0:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap 
00045500:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target= 
00045510:·2223·6964·6d38·3031·3522·2074·6162·696e··"#idm8015"·tabin 
00045520:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu 
00045530:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan 
00045540:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl 
00045550:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r 
00045560:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!" 
Max diff block lines reached; 633950/661302 bytes (95.86%) of diff not shown.
84.7 KB
html2text {}
    
Offset 750, 52 lines modifiedOffset 750, 38 lines modified
750 ··-·PCI-DSSv4-11.5.2750 ··-·PCI-DSSv4-11.5.2
751 ··-·enable_strategy751 ··-·enable_strategy
752 ··-·low_complexity752 ··-·low_complexity
753 ··-·low_disruption753 ··-·low_disruption
754 ··-·medium_severity754 ··-·medium_severity
755 ··-·no_reboot_needed755 ··-·no_reboot_needed
756 ··-·package_aide_installed756 ··-·package_aide_installed
757 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
758 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
759 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
760 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
761 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
762 dnf·install·aide 
763 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
764 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
765 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
766 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
767 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
768 package·--add=aide 
769 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8757 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
770 [[packages]]758 [[packages]]
771 name·=·"aide"759 name·=·"aide"
772 version·=·"*"760 version·=·"*"
773 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
774 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
775 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
776 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
777 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
778 package·install·aide 
779 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8761 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
780 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low762 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
781 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low763 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
782 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false764 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
783 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable765 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
784 include·install_aide766 include·install_aide
  
785 class·install_aide·{767 class·install_aide·{
786 ··package·{·'aide':768 ··package·{·'aide':
787 ····ensure·=>·'installed',769 ····ensure·=>·'installed',
788 ··}770 ··}
789 }771 }
 772 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 773 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 774 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 775 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 776 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 777 package·install·aide
790 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8778 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
791 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low779 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
792 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low780 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
793 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false781 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
794 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable782 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
795 #·Remediation·is·applicable·only·in·certain·platforms783 #·Remediation·is·applicable·only·in·certain·platforms
796 if·rpm·--quiet·-q·kernel;·then784 if·rpm·--quiet·-q·kernel;·then
Offset 803, 14 lines modifiedOffset 789, 28 lines modified
803 if·!·rpm·-q·--quiet·"aide"·;·then789 if·!·rpm·-q·--quiet·"aide"·;·then
804 ····yum·install·-y·"aide"790 ····yum·install·-y·"aide"
805 fi791 fi
  
806 else792 else
807 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'793 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
808 fi794 fi
 795 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 796 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 797 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 798 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 799 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 800 package·--add=aide
 801 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 802 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 803 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 804 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 805 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 806 dnf·install·aide
809 Group  ·Federal·Information·Processing·Standard·(FIPS)·  Group·contains·1·rule807 Group  ·Federal·Information·Processing·Standard·(FIPS)·  Group·contains·1·rule
810 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·Federal·Information·Processing·Standard·(FIPS)·is·a·computer·security·standard·which·is·developed·by·the·U.S.·Government·and·industry·working·groups·to·validate·the·quality·of·cryptographic·modules.·The·FIPS·standard·provides·four·security·levels·to·ensure·adequate·coverage·of·different·industries,·implementation·of·cryptographic·modules,·and·organizational·sizes·and·requirements.808 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·Federal·Information·Processing·Standard·(FIPS)·is·a·computer·security·standard·which·is·developed·by·the·U.S.·Government·and·industry·working·groups·to·validate·the·quality·of·cryptographic·modules.·The·FIPS·standard·provides·four·security·levels·to·ensure·adequate·coverage·of·different·industries,·implementation·of·cryptographic·modules,·and·organizational·sizes·and·requirements.
  
811 FIPS·140-2·is·the·current·standard·for·validating·that·mechanisms·used·to·access·cryptographic·modules·utilize·authentication·that·meets·industry·and·government·requirements.·For·government·systems,·this·allows·Security·Levels·1,·2,·3,·or·4·for·use·on·Red·Hat·Enterprise·Linux·8.809 FIPS·140-2·is·the·current·standard·for·validating·that·mechanisms·used·to·access·cryptographic·modules·utilize·authentication·that·meets·industry·and·government·requirements.·For·government·systems,·this·allows·Security·Levels·1,·2,·3,·or·4·for·use·on·Red·Hat·Enterprise·Linux·8.
  
812 See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8c\x8c_\x8s\x8s_\x8r\x8r_\x8c\x8c_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8l\x8l_\x8i\x8i_\x8c\x8c_\x8a\x8a_\x8t\x8t_\x8i\x8i_\x8o\x8o_\x8n\x8n_\x8s\x8s_\x8/\x8/_\x8P\x8P_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x8h\x8h_\x8t\x8t_\x8m\x8m_\x8l\x8l·for·more·information.810 See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8c\x8c_\x8s\x8s_\x8r\x8r_\x8c\x8c_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8l\x8l_\x8i\x8i_\x8c\x8c_\x8a\x8a_\x8t\x8t_\x8i\x8i_\x8o\x8o_\x8n\x8n_\x8s\x8s_\x8/\x8/_\x8P\x8P_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x8h\x8h_\x8t\x8t_\x8m\x8m_\x8l\x8l·for·more·information.
813 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8de\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*811 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8de\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
Offset 1177, 52 lines modifiedOffset 1177, 38 lines modified
1177 ··-·PCI-DSSv4-2.2.61177 ··-·PCI-DSSv4-2.2.6
1178 ··-·enable_strategy1178 ··-·enable_strategy
1179 ··-·low_complexity1179 ··-·low_complexity
1180 ··-·low_disruption1180 ··-·low_disruption
1181 ··-·medium_severity1181 ··-·medium_severity
1182 ··-·no_reboot_needed1182 ··-·no_reboot_needed
1183 ··-·package_sudo_installed1183 ··-·package_sudo_installed
1184 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
1185 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
1186 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
1187 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
1188 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
1189 dnf·install·sudo 
1190 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
1191 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
1192 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
1193 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
1194 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
1195 package·--add=sudo 
1196 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81184 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
1197 [[packages]]1185 [[packages]]
1198 name·=·"sudo"1186 name·=·"sudo"
1199 version·=·"*"1187 version·=·"*"
1200 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
1201 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
1202 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
1203 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
1204 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
1205 package·install·sudo 
1206 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81188 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1207 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1189 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1208 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1190 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1209 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1191 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1210 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1192 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
Max diff block lines reached; 81576/86673 bytes (94.12%) of diff not shown.
1.65 MB
./usr/share/doc/ssg-nondebian/ssg-centos8-guide-ospp.html
    
Offset 15405, 208 lines modifiedOffset 15405, 208 lines modified
0003c2c0:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="0003c2c0:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
0003c2d0:·2369·646d·3830·3133·2220·7461·6269·6e64··#idm8013"·tabind0003c2d0:·2369·646d·3830·3133·2220·7461·6269·6e64··#idm8013"·tabind
0003c2e0:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but0003c2e0:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
0003c2f0:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand0003c2f0:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
0003c300:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title0003c300:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
0003c310:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re0003c310:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
0003c320:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">0003c320:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
0003c330:·5265·6d65·6469·6174·696f·6e20·7363·7269··Remediation·scri0003c330:·5265·6d65·6469·6174·696f·6e20·4f53·4275··Remediation·OSBu
 0003c340:·696c·6420·426c·7565·7072·696e·7420·736e··ild·Blueprint·sn
 0003c350:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br
 0003c360:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
 0003c370:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
 0003c380:·6170·7365·2220·6964·3d22·6964·6d38·3031··apse"·id="idm801
 0003c390:·3322·3e3c·7072·653e·3c63·6f64·653e·0a5b··3"><pre><code>.[
 0003c3a0:·5b70·6163·6b61·6765·735d·5d0a·6e61·6d65··[packages]].name
 0003c3b0:·203d·2022·6169·6465·220a·7665·7273·696f···=·"aide".versio
 0003c3c0:·6e20·3d20·222a·220a·3c2f·636f·6465·3e3c··n·=·"*".</code><
0003c340:·7074·20e2·87b2·3c2f·613e·3c62·723e·3c64··pt·...</a><br><d 
0003c350:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel- 
0003c360:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps 
0003c370:·6522·2069·643d·2269·646d·3830·3133·223e··e"·id="idm8013"> 
0003c380:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta 
0003c390:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe 
0003c3a0:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered 
0003c3b0:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed 
0003c3c0:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple 
0003c3d0:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo 
0003c3e0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr>< 
0003c3f0:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</ 
0003c400:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td>< 
0003c410:·2f74·723e·3c74·723e·3c74·683e·5265·626f··/tr><tr><th>Rebo 
0003c420:·6f74·3a3c·2f74·683e·3c74·643e·6661·6c73··ot:</th><td>fals 
0003c430:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr>< 
0003c440:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th 
0003c450:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td> 
0003c460:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr 
0003c470:·653e·3c63·6f64·653e·0a64·6e66·2069·6e73··e><code>.dnf·ins 
0003c480:·7461·6c6c·2061·6964·650a·3c2f·636f·6465··tall·aide.</code 
0003c490:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a·0003c3d0:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl
0003c4a0:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s0003c3e0:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc
0003c4b0:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog0003c3f0:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl
0003c4c0:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d0003c400:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat
0003c4d0:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm0003c410:·612d·7461·7267·6574·3d22·2369·646d·3830··a-target="#idm80
0003c4e0:·3830·3134·2220·7461·6269·6e64·6578·3d22··8014"·tabindex="0003c420:·3134·2220·7461·6269·6e64·6578·3d22·3022··14"·tabindex="0"
0003c4f0:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"0003c430:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
0003c500:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="0003c440:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
0003c510:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac0003c450:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
0003c520:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal0003c460:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
0003c530:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme0003c470:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
0003c540:·6469·6174·696f·6e20·416e·6163·6f6e·6461··diation·Anaconda0003c480:·6174·696f·6e20·5075·7070·6574·2073·6e69··ation·Puppet·sni
0003c550:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>0003c490:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>
0003c560:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="0003c4a0:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
0003c570:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c0003c4b0:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
0003c580:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm0003c4c0:·7073·6522·2069·643d·2269·646d·3830·3134··pse"·id="idm8014
0003c590:·3830·3134·223e·3c74·6162·6c65·2063·6c61··8014"><table·cla0003c4d0:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="
0003c5a0:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-0003c4e0:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri
0003c5b0:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo0003c4f0:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border
0003c5c0:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con0003c500:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens
0003c5d0:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>0003c510:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp
0003c5e0:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>0003c520:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>
0003c5f0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr0003c530:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
0003c600:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt0003c540:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:
0003c610:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low0003c550:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
0003c620:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t0003c560:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re
0003c630:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t0003c570:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa
0003c640:·643e·6661·6c73·653c·2f74·643e·3c2f·7472··d>false</td></tr 
0003c650:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg 
0003c660:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl 
0003c670:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab0003c580:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr
0003c680:·6c65·3e3c·7072·653e·3c63·6f64·653e·0a70··le><pre><code>.p 
0003c690:·6163·6b61·6765·202d·2d61·6464·3d61·6964··ackage·--add=aid 
0003c6a0:·650a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··e.</code></pre>< 
0003c6b0:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b 
0003c6c0:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"· 
0003c6d0:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col 
0003c6e0:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ 
0003c6f0:·6574·3d22·2369·646d·3830·3135·2220·7461··et="#idm8015"·ta 
0003c700:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role= 
0003c710:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex 
0003c720:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t 
0003c730:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t 
0003c740:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href=" 
0003c750:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation· 
0003c760:·4f53·4275·696c·6420·426c·7565·7072·696e··OSBuild·Blueprin 
0003c770:·7420·736e·6970·7065·7420·e287·b23c·2f61··t·snippet·...</a 
0003c780:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class= 
0003c790:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse· 
0003c7a0:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id 
0003c7b0:·6d38·3031·3522·3e3c·7072·653e·3c63·6f64··m8015"><pre><cod 
0003c7c0:·653e·0a5b·5b70·6163·6b61·6765·735d·5d0a··e>.[[packages]]. 
0003c7d0:·6e61·6d65·203d·2022·6169·6465·220a·7665··name·=·"aide".ve 
0003c7e0:·7273·696f·6e20·3d20·222a·220a·3c2f·636f··rsion·=·"*".</co 
0003c7f0:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div>< 
0003c800:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn 
0003c810:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t 
0003c820:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse" 
0003c830:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i 
0003c840:·646d·3830·3136·2220·7461·6269·6e64·6578··dm8016"·tabindex 
0003c850:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto 
0003c860:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded 
0003c870:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title=" 
0003c880:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve 
0003c890:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re 
0003c8a0:·6d65·6469·6174·696f·6e20·7363·7269·7074··mediation·script 
0003c8b0:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div 
0003c8c0:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co 
0003c8d0:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse" 
0003c8e0:·2069·643d·2269·646d·3830·3136·223e·3c74···id="idm8016"><t 
0003c8f0:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl 
0003c900:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped· 
0003c910:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t 
0003c920:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed"> 
0003c930:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi 
0003c940:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low< 
0003c950:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0003c960:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th 
0003c970:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t 
0003c980:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot 
0003c990:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false< 
0003c9a0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0003c9b0:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><0003c590:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</
0003c9c0:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></0003c5a0:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t
0003c9d0:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>0003c5b0:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><
0003c9e0:·3c63·6f64·653e·0a70·6163·6b61·6765·2069··<code>.package·i 
0003c9f0:·6e73·7461·6c6c·2061·6964·650a·3c2f·636f··nstall·aide.</co 
0003ca00:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div>< 
0003ca10:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn 
Max diff block lines reached; 1525837/1553189 bytes (98.24%) of diff not shown.
171 KB
html2text {}
    
Offset 168, 52 lines modifiedOffset 168, 38 lines modified
168 ··-·PCI-DSSv4-11.5.2168 ··-·PCI-DSSv4-11.5.2
169 ··-·enable_strategy169 ··-·enable_strategy
170 ··-·low_complexity170 ··-·low_complexity
171 ··-·low_disruption171 ··-·low_disruption
172 ··-·medium_severity172 ··-·medium_severity
173 ··-·no_reboot_needed173 ··-·no_reboot_needed
174 ··-·package_aide_installed174 ··-·package_aide_installed
175 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
176 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
177 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
178 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
179 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
180 dnf·install·aide 
181 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
182 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
183 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
184 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
185 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
186 package·--add=aide 
187 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8175 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
188 [[packages]]176 [[packages]]
189 name·=·"aide"177 name·=·"aide"
190 version·=·"*"178 version·=·"*"
191 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
192 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
193 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
194 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
195 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
196 package·install·aide 
197 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8179 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
198 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low180 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
199 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low181 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
200 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false182 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
201 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable183 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
202 include·install_aide184 include·install_aide
  
203 class·install_aide·{185 class·install_aide·{
204 ··package·{·'aide':186 ··package·{·'aide':
205 ····ensure·=>·'installed',187 ····ensure·=>·'installed',
206 ··}188 ··}
207 }189 }
 190 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 191 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 192 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 193 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 194 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 195 package·install·aide
208 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8196 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
209 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low197 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
210 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low198 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
211 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false199 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
212 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable200 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
213 #·Remediation·is·applicable·only·in·certain·platforms201 #·Remediation·is·applicable·only·in·certain·platforms
214 if·rpm·--quiet·-q·kernel;·then202 if·rpm·--quiet·-q·kernel;·then
Offset 221, 14 lines modifiedOffset 207, 28 lines modified
221 if·!·rpm·-q·--quiet·"aide"·;·then207 if·!·rpm·-q·--quiet·"aide"·;·then
222 ····yum·install·-y·"aide"208 ····yum·install·-y·"aide"
223 fi209 fi
  
224 else210 else
225 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'211 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
226 fi212 fi
 213 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 214 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 215 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 216 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 217 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 218 package·--add=aide
 219 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 220 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 221 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 222 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 223 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 224 dnf·install·aide
227 Group  ·Federal·Information·Processing·Standard·(FIPS)·  Group·contains·2·rules225 Group  ·Federal·Information·Processing·Standard·(FIPS)·  Group·contains·2·rules
228 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·Federal·Information·Processing·Standard·(FIPS)·is·a·computer·security·standard·which·is·developed·by·the·U.S.·Government·and·industry·working·groups·to·validate·the·quality·of·cryptographic·modules.·The·FIPS·standard·provides·four·security·levels·to·ensure·adequate·coverage·of·different·industries,·implementation·of·cryptographic·modules,·and·organizational·sizes·and·requirements.226 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·Federal·Information·Processing·Standard·(FIPS)·is·a·computer·security·standard·which·is·developed·by·the·U.S.·Government·and·industry·working·groups·to·validate·the·quality·of·cryptographic·modules.·The·FIPS·standard·provides·four·security·levels·to·ensure·adequate·coverage·of·different·industries,·implementation·of·cryptographic·modules,·and·organizational·sizes·and·requirements.
  
229 FIPS·140-2·is·the·current·standard·for·validating·that·mechanisms·used·to·access·cryptographic·modules·utilize·authentication·that·meets·industry·and·government·requirements.·For·government·systems,·this·allows·Security·Levels·1,·2,·3,·or·4·for·use·on·Red·Hat·Enterprise·Linux·8.227 FIPS·140-2·is·the·current·standard·for·validating·that·mechanisms·used·to·access·cryptographic·modules·utilize·authentication·that·meets·industry·and·government·requirements.·For·government·systems,·this·allows·Security·Levels·1,·2,·3,·or·4·for·use·on·Red·Hat·Enterprise·Linux·8.
  
230 See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8c\x8c_\x8s\x8s_\x8r\x8r_\x8c\x8c_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8l\x8l_\x8i\x8i_\x8c\x8c_\x8a\x8a_\x8t\x8t_\x8i\x8i_\x8o\x8o_\x8n\x8n_\x8s\x8s_\x8/\x8/_\x8P\x8P_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x8h\x8h_\x8t\x8t_\x8m\x8m_\x8l\x8l·for·more·information.228 See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8c\x8c_\x8s\x8s_\x8r\x8r_\x8c\x8c_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8l\x8l_\x8i\x8i_\x8c\x8c_\x8a\x8a_\x8t\x8t_\x8i\x8i_\x8o\x8o_\x8n\x8n_\x8s\x8s_\x8/\x8/_\x8P\x8P_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x8h\x8h_\x8t\x8t_\x8m\x8m_\x8l\x8l·for·more·information.
231 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·D\x8Dr\x8ra\x8ac\x8cu\x8ut\x8t·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8du\x8ul\x8le\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*229 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·D\x8Dr\x8ra\x8ac\x8cu\x8ut\x8t·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8du\x8ul\x8le\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
Offset 307, 61 lines modifiedOffset 307, 61 lines modified
307 ··tags:307 ··tags:
308 ··-·enable_strategy308 ··-·enable_strategy
309 ··-·low_complexity309 ··-·low_complexity
310 ··-·low_disruption310 ··-·low_disruption
311 ··-·medium_severity311 ··-·medium_severity
312 ··-·no_reboot_needed312 ··-·no_reboot_needed
313 ··-·package_crypto-policies_installed313 ··-·package_crypto-policies_installed
314 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
315 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
316 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
317 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
318 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
319 dnf·install·crypto-policies 
320 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
321 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
322 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
323 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
324 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
325 package·--add=crypto-policies 
326 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8314 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
327 [[packages]]315 [[packages]]
328 name·=·"crypto-policies"316 name·=·"crypto-policies"
329 version·=·"*"317 version·=·"*"
330 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
331 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
332 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
333 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
334 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
335 package·install·crypto-policies 
336 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8318 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
337 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low319 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
338 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low320 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
339 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false321 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
340 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable322 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
Max diff block lines reached; 170356/175531 bytes (97.05%) of diff not shown.
694 KB
./usr/share/doc/ssg-nondebian/ssg-centos8-guide-pci-dss.html
    
Offset 16931, 208 lines modifiedOffset 16931, 208 lines modified
00042220:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target00042220:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
00042230:·3d22·2369·646d·3830·3133·2220·7461·6269··="#idm8013"·tabi00042230:·3d22·2369·646d·3830·3133·2220·7461·6269··="#idm8013"·tabi
00042240:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b00042240:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
00042250:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa00042250:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
00042260:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit00042260:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
00042270:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·00042270:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
00042280:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!00042280:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
00042290:·223e·5265·6d65·6469·6174·696f·6e20·7363··">Remediation·sc00042290:·223e·5265·6d65·6469·6174·696f·6e20·4f53··">Remediation·OS
 000422a0:·4275·696c·6420·426c·7565·7072·696e·7420··Build·Blueprint·
 000422b0:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><
 000422c0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
 000422d0:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
 000422e0:·6c6c·6170·7365·2220·6964·3d22·6964·6d38··llapse"·id="idm8
 000422f0:·3031·3322·3e3c·7072·653e·3c63·6f64·653e··013"><pre><code>
 00042300:·0a5b·5b70·6163·6b61·6765·735d·5d0a·6e61··.[[packages]].na
 00042310:·6d65·203d·2022·6169·6465·220a·7665·7273··me·=·"aide".vers
 00042320:·696f·6e20·3d20·222a·220a·3c2f·636f·6465··ion·=·"*".</code
000422a0:·7269·7074·20e2·87b2·3c2f·613e·3c62·723e··ript·...</a><br> 
000422b0:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane 
000422c0:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla 
000422d0:·7073·6522·2069·643d·2269·646d·3830·3133··pse"·id="idm8013 
000422e0:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class=" 
000422f0:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri 
00042300:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border 
00042310:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens 
00042320:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp 
00042330:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td> 
00042340:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr 
00042350:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption: 
00042360:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td 
00042370:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re 
00042380:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa 
00042390:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr 
000423a0:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</ 
000423b0:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t 
000423c0:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table>< 
000423d0:·7072·653e·3c63·6f64·653e·0a64·6e66·2069··pre><code>.dnf·i 
000423e0:·6e73·7461·6c6c·2061·6964·650a·3c2f·636f··nstall·aide.</co 
000423f0:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div><00042330:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a·
00042400:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn00042340:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s
00042410:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t00042350:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog
00042420:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse"00042360:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d
00042430:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i00042370:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
00042440:·646d·3830·3134·2220·7461·6269·6e64·6578··dm8014"·tabindex00042380:·3830·3134·2220·7461·6269·6e64·6578·3d22··8014"·tabindex="
00042450:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto00042390:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
00042460:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded000423a0:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
00042470:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="000423b0:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
00042480:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve000423c0:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
00042490:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re000423d0:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
000424a0:·6d65·6469·6174·696f·6e20·416e·6163·6f6e··mediation·Anacon000423e0:·6469·6174·696f·6e20·5075·7070·6574·2073··diation·Puppet·s
000424b0:·6461·2073·6e69·7070·6574·20e2·87b2·3c2f··da·snippet·...</000423f0:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b
000424c0:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class00042400:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
000424d0:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse00042410:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
000424e0:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i00042420:·6c61·7073·6522·2069·643d·2269·646d·3830··lapse"·id="idm80
000424f0:·646d·3830·3134·223e·3c74·6162·6c65·2063··dm8014"><table·c00042430:·3134·223e·3c74·6162·6c65·2063·6c61·7373··14"><table·class
00042500:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl00042440:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st
00042510:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-00042450:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord
00042520:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c00042460:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde
00042530:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t00042470:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co
00042540:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t00042480:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t
00042550:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></00042490:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
00042560:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru000424a0:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio
00042570:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l000424b0:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</
00042580:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>000424c0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
00042590:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th>000424d0:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td>
000425a0:·3c74·643e·6661·6c73·653c·2f74·643e·3c2f··<td>false</td></ 
000425b0:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat 
000425c0:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena 
000425d0:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t000424e0:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr><
 000424f0:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:
 00042500:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<
 00042510:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table
000425e0:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>00042520:·3e3c·7072·653e·3c63·6f64·653e·696e·636c··><pre><code>incl
 00042530:·7564·6520·696e·7374·616c·6c5f·6169·6465··ude·install_aide
 00042540:·0a0a·636c·6173·7320·696e·7374·616c·6c5f··..class·install_
 00042550:·6169·6465·207b·0a20·2070·6163·6b61·6765··aide·{.··package
 00042560:·207b·2027·6169·6465·273a·0a20·2020·2065···{·'aide':.····e
 00042570:·6e73·7572·6520·3d26·6774·3b20·2769·6e73··nsure·=&gt;·'ins
 00042580:·7461·6c6c·6564·272c·0a20·207d·0a7d·0a3c··talled',.··}.}.<
 00042590:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di
 000425a0:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn·
 000425b0:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat
 000425c0:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap
 000425d0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
 000425e0:·2223·6964·6d38·3031·3522·2074·6162·696e··"#idm8015"·tabin
 000425f0:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
 00042600:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
 00042610:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
 00042620:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
 00042630:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
 00042640:·3e52·656d·6564·6961·7469·6f6e·2073·6372··>Remediation·scr
 00042650:·6970·7420·e287·b23c·2f61·3e3c·6272·3e3c··ipt·...</a><br><
000425f0:·0a70·6163·6b61·6765·202d·2d61·6464·3d61··.package·--add=a 
00042600:·6964·650a·3c2f·636f·6465·3e3c·2f70·7265··ide.</code></pre 
00042610:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class= 
00042620:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success 
00042630:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c 
00042640:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta 
00042650:·7267·6574·3d22·2369·646d·3830·3135·2220··rget="#idm8015"· 
00042660:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol 
00042670:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria- 
00042680:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false" 
00042690:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate 
000426a0:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href 
000426b0:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio 
000426c0:·6e20·4f53·4275·696c·6420·426c·7565·7072··n·OSBuild·Bluepr 
000426d0:·696e·7420·736e·6970·7065·7420·e287·b23c··int·snippet·...< 
000426e0:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas 
000426f0:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps 
00042700:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id=" 
00042710:·6964·6d38·3031·3522·3e3c·7072·653e·3c63··idm8015"><pre><c 
00042720:·6f64·653e·0a5b·5b70·6163·6b61·6765·735d··ode>.[[packages] 
00042730:·5d0a·6e61·6d65·203d·2022·6169·6465·220a··].name·=·"aide". 
00042740:·7665·7273·696f·6e20·3d20·222a·220a·3c2f··version·=·"*".</ 
00042750:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div 
00042760:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b 
00042770:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data 
00042780:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps 
00042790:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target=" 
000427a0:·2369·646d·3830·3136·2220·7461·6269·6e64··#idm8016"·tabind 
000427b0:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but 
000427c0:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand 
000427d0:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title 
000427e0:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re 
000427f0:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!"> 
00042800:·5265·6d65·6469·6174·696f·6e20·7363·7269··Remediation·scri 
00042810:·7074·20e2·87b2·3c2f·613e·3c62·723e·3c64··pt·...</a><br><d 
Max diff block lines reached; 599930/627282 bytes (95.64%) of diff not shown.
81.5 KB
html2text {}
    
Offset 566, 52 lines modifiedOffset 566, 38 lines modified
566 ··-·PCI-DSSv4-11.5.2566 ··-·PCI-DSSv4-11.5.2
567 ··-·enable_strategy567 ··-·enable_strategy
568 ··-·low_complexity568 ··-·low_complexity
569 ··-·low_disruption569 ··-·low_disruption
570 ··-·medium_severity570 ··-·medium_severity
571 ··-·no_reboot_needed571 ··-·no_reboot_needed
572 ··-·package_aide_installed572 ··-·package_aide_installed
573 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
574 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
575 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
576 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
577 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
578 dnf·install·aide 
579 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
580 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
581 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
582 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
583 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
584 package·--add=aide 
585 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8573 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
586 [[packages]]574 [[packages]]
587 name·=·"aide"575 name·=·"aide"
588 version·=·"*"576 version·=·"*"
589 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
590 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
591 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
592 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
593 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
594 package·install·aide 
595 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8577 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
596 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low578 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
597 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low579 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
598 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false580 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
599 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable581 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
600 include·install_aide582 include·install_aide
  
601 class·install_aide·{583 class·install_aide·{
602 ··package·{·'aide':584 ··package·{·'aide':
603 ····ensure·=>·'installed',585 ····ensure·=>·'installed',
604 ··}586 ··}
605 }587 }
 588 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 589 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 590 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 591 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 592 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 593 package·install·aide
606 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8594 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
607 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low595 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
608 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low596 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
609 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false597 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
610 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable598 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
611 #·Remediation·is·applicable·only·in·certain·platforms599 #·Remediation·is·applicable·only·in·certain·platforms
612 if·rpm·--quiet·-q·kernel;·then600 if·rpm·--quiet·-q·kernel;·then
Offset 619, 14 lines modifiedOffset 605, 28 lines modified
619 if·!·rpm·-q·--quiet·"aide"·;·then605 if·!·rpm·-q·--quiet·"aide"·;·then
620 ····yum·install·-y·"aide"606 ····yum·install·-y·"aide"
621 fi607 fi
  
622 else608 else
623 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'609 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
624 fi610 fi
 611 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 612 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 613 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 614 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 615 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 616 package·--add=aide
 617 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 618 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 619 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 620 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 621 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 622 dnf·install·aide
625 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*623 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
626 Run·the·following·command·to·generate·a·new·database:624 Run·the·following·command·to·generate·a·new·database:
627 $·sudo·/usr/sbin/aide·--init625 $·sudo·/usr/sbin/aide·--init
628 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:626 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
629 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz627 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
630 To·initiate·a·manual·check,·run·the·following·command:628 To·initiate·a·manual·check,·run·the·following·command:
631 $·sudo·/usr/sbin/aide·--check629 $·sudo·/usr/sbin/aide·--check
Offset 2785, 52 lines modifiedOffset 2785, 38 lines modified
2785 ··-·PCI-DSSv4-2.2.62785 ··-·PCI-DSSv4-2.2.6
2786 ··-·enable_strategy2786 ··-·enable_strategy
2787 ··-·low_complexity2787 ··-·low_complexity
2788 ··-·low_disruption2788 ··-·low_disruption
2789 ··-·medium_severity2789 ··-·medium_severity
2790 ··-·no_reboot_needed2790 ··-·no_reboot_needed
2791 ··-·package_sudo_installed2791 ··-·package_sudo_installed
2792 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
2793 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
2794 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
2795 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
2796 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
2797 dnf·install·sudo 
2798 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
2799 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
2800 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
2801 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
2802 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
2803 package·--add=sudo 
2804 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x82792 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
2805 [[packages]]2793 [[packages]]
2806 name·=·"sudo"2794 name·=·"sudo"
2807 version·=·"*"2795 version·=·"*"
2808 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
2809 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
2810 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
2811 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
2812 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
2813 package·install·sudo 
2814 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x82796 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
2815 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low2797 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
2816 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low2798 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
2817 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false2799 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
2818 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable2800 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
Max diff block lines reached; 78747/83442 bytes (94.37%) of diff not shown.
1.62 MB
./usr/share/doc/ssg-nondebian/ssg-centos8-guide-stig.html
    
Offset 15438, 207 lines modifiedOffset 15438, 207 lines modified
0003c4d0:·7461·7267·6574·3d22·2369·646d·3830·3133··target="#idm80130003c4d0:·7461·7267·6574·3d22·2369·646d·3830·3133··target="#idm8013
0003c4e0:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r0003c4e0:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r
0003c4f0:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari0003c4f0:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari
0003c500:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals0003c500:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals
0003c510:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa0003c510:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa
0003c520:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr0003c520:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr
0003c530:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat0003c530:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat
 0003c540:·696f·6e20·4f53·4275·696c·6420·426c·7565··ion·OSBuild·Blue
 0003c550:·7072·696e·7420·736e·6970·7065·7420·e287··print·snippet·..
 0003c560:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl
 0003c570:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla
 0003c580:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id
 0003c590:·3d22·6964·6d38·3031·3322·3e3c·7072·653e··="idm8013"><pre>
 0003c5a0:·3c63·6f64·653e·0a5b·5b70·6163·6b61·6765··<code>.[[package
 0003c5b0:·735d·5d0a·6e61·6d65·203d·2022·6169·6465··s]].name·=·"aide
 0003c5c0:·220a·7665·7273·696f·6e20·3d20·222a·220a··".version·=·"*".
0003c540:·696f·6e20·7363·7269·7074·20e2·87b2·3c2f··ion·script·...</ 
0003c550:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class 
0003c560:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse 
0003c570:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i 
0003c580:·646d·3830·3133·223e·3c74·6162·6c65·2063··dm8013"><table·c 
0003c590:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl 
0003c5a0:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table- 
0003c5b0:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c 
0003c5c0:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t 
0003c5d0:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t 
0003c5e0:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></ 
0003c5f0:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru 
0003c600:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l 
0003c610:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr> 
0003c620:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th> 
0003c630:·3c74·643e·6661·6c73·653c·2f74·643e·3c2f··<td>false</td></ 
0003c640:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat 
0003c650:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena 
0003c660:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t 
0003c670:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code> 
0003c680:·0a64·6e66·2069·6e73·7461·6c6c·2061·6964··.dnf·install·aid 
0003c690:·650a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··e.</code></pre><0003c5d0:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d
0003c6a0:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b0003c5e0:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn
0003c6b0:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"·0003c5f0:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da
0003c6c0:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col0003c600:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla
0003c6d0:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ0003c610:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
0003c6e0:·6574·3d22·2369·646d·3830·3134·2220·7461··et="#idm8014"·ta0003c620:·3d22·2369·646d·3830·3134·2220·7461·6269··="#idm8014"·tabi
0003c6f0:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=0003c630:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
0003c700:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex0003c640:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
0003c710:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t0003c650:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
0003c720:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t0003c660:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
0003c730:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="0003c670:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
0003c740:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·0003c680:·223e·5265·6d65·6469·6174·696f·6e20·5075··">Remediation·Pu
0003c750:·416e·6163·6f6e·6461·2073·6e69·7070·6574··Anaconda·snippet0003c690:·7070·6574·2073·6e69·7070·6574·20e2·87b2··ppet·snippet·...
0003c760:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div0003c6a0:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
0003c770:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co0003c6b0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
0003c780:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse" 
0003c790:·2069·643d·2269·646d·3830·3134·223e·3c74···id="idm8014"><t 
0003c7a0:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl 
0003c7b0:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped· 
0003c7c0:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t 
0003c7d0:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed"> 
0003c7e0:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi 
0003c7f0:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low< 
0003c800:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0003c810:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th 
0003c820:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t 
0003c830:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot 
0003c840:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false< 
0003c850:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0003c860:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th>< 
0003c870:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></ 
0003c880:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre> 
0003c890:·3c63·6f64·653e·0a70·6163·6b61·6765·202d··<code>.package·- 
0003c8a0:·2d61·6464·3d61·6964·650a·3c2f·636f·6465··-add=aide.</code 
0003c8b0:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a· 
0003c8c0:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s 
0003c8d0:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog 
0003c8e0:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d0003c6c0:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
 0003c6d0:·2269·646d·3830·3134·223e·3c74·6162·6c65··"idm8014"><table
0003c8f0:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm 
0003c900:·3830·3135·2220·7461·6269·6e64·6578·3d22··8015"·tabindex=" 
0003c910:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button" 
0003c920:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded=" 
0003c930:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac 
0003c940:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal 
0003c950:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme 
0003c960:·6469·6174·696f·6e20·4f53·4275·696c·6420··diation·OSBuild· 
0003c970:·426c·7565·7072·696e·7420·736e·6970·7065··Blueprint·snippe 
0003c980:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di 
0003c990:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c 
0003c9a0:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse 
0003c9b0:·2220·6964·3d22·6964·6d38·3031·3522·3e3c··"·id="idm8015">< 
0003c9c0:·7072·653e·3c63·6f64·653e·0a5b·5b70·6163··pre><code>.[[pac 
0003c9d0:·6b61·6765·735d·5d0a·6e61·6d65·203d·2022··kages]].name·=·" 
0003c9e0:·6169·6465·220a·7665·7273·696f·6e20·3d20··aide".version·=· 
0003c9f0:·222a·220a·3c2f·636f·6465·3e3c·2f70·7265··"*".</code></pre 
0003ca00:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class= 
0003ca10:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success 
0003ca20:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c 
0003ca30:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta 
0003ca40:·7267·6574·3d22·2369·646d·3830·3136·2220··rget="#idm8016"· 
0003ca50:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol 
0003ca60:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria- 
0003ca70:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false" 
0003ca80:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate 
0003ca90:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href 
0003caa0:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio 
0003cab0:·6e20·7363·7269·7074·20e2·87b2·3c2f·613e··n·script·...</a> 
0003cac0:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class=" 
0003cad0:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c 
0003cae0:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm 
0003caf0:·3830·3136·223e·3c74·6162·6c65·2063·6c61··8016"><table·cla 
0003cb00:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-0003c6e0:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta
0003cb10:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo0003c6f0:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl
0003cb20:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con0003c700:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table
0003cb30:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>0003c710:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>
0003cb40:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>0003c720:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<
0003cb50:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr0003c730:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
0003cb60:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt0003c740:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis
0003cb70:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low0003c750:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td
0003cb80:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t0003c760:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
0003cb90:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t0003c770:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t
 0003c780:·683e·3c74·643e·6661·6c73·653c·2f74·643e··h><td>false</td>
 0003c790:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str
 0003c7a0:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e
0003cba0:·643e·6661·6c73·653c·2f74·643e·3c2f·7472··d>false</td></tr0003c7b0:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr><
0003cbb0:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg 
0003cbc0:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl 
0003cbd0:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab 
0003cbe0:·6c65·3e3c·7072·653e·3c63·6f64·653e·0a70··le><pre><code>.p0003c7c0:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod
Max diff block lines reached; 1499260/1526474 bytes (98.22%) of diff not shown.
171 KB
html2text {}
    
Offset 174, 52 lines modifiedOffset 174, 38 lines modified
174 ··-·PCI-DSSv4-11.5.2174 ··-·PCI-DSSv4-11.5.2
175 ··-·enable_strategy175 ··-·enable_strategy
176 ··-·low_complexity176 ··-·low_complexity
177 ··-·low_disruption177 ··-·low_disruption
178 ··-·medium_severity178 ··-·medium_severity
179 ··-·no_reboot_needed179 ··-·no_reboot_needed
180 ··-·package_aide_installed180 ··-·package_aide_installed
181 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
182 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
183 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
184 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
185 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
186 dnf·install·aide 
187 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
188 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
189 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
190 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
191 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
192 package·--add=aide 
193 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8181 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
194 [[packages]]182 [[packages]]
195 name·=·"aide"183 name·=·"aide"
196 version·=·"*"184 version·=·"*"
197 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
198 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
199 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
200 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
201 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
202 package·install·aide 
203 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8185 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
204 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low186 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
205 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low187 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
206 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false188 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
207 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable189 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
208 include·install_aide190 include·install_aide
  
209 class·install_aide·{191 class·install_aide·{
210 ··package·{·'aide':192 ··package·{·'aide':
211 ····ensure·=>·'installed',193 ····ensure·=>·'installed',
212 ··}194 ··}
213 }195 }
 196 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 197 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 198 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 199 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 200 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 201 package·install·aide
214 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8202 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
215 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low203 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
216 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low204 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
217 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false205 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
218 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable206 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
219 #·Remediation·is·applicable·only·in·certain·platforms207 #·Remediation·is·applicable·only·in·certain·platforms
220 if·rpm·--quiet·-q·kernel;·then208 if·rpm·--quiet·-q·kernel;·then
Offset 227, 14 lines modifiedOffset 213, 28 lines modified
227 if·!·rpm·-q·--quiet·"aide"·;·then213 if·!·rpm·-q·--quiet·"aide"·;·then
228 ····yum·install·-y·"aide"214 ····yum·install·-y·"aide"
229 fi215 fi
  
230 else216 else
231 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'217 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
232 fi218 fi
 219 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 220 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 221 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 222 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 223 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 224 package·--add=aide
 225 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 226 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 227 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 228 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 229 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 230 dnf·install·aide
233 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*231 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
234 Run·the·following·command·to·generate·a·new·database:232 Run·the·following·command·to·generate·a·new·database:
235 $·sudo·/usr/sbin/aide·--init233 $·sudo·/usr/sbin/aide·--init
236 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:234 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
237 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz235 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
238 To·initiate·a·manual·check,·run·the·following·command:236 To·initiate·a·manual·check,·run·the·following·command:
239 $·sudo·/usr/sbin/aide·--check237 $·sudo·/usr/sbin/aide·--check
Offset 2738, 29 lines modifiedOffset 2738, 29 lines modified
2738 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.32738 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.3
2739 References:·_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)2739 References:·_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)
2740 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-42740 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4
2741 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-002272741 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
2742 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R282742 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R28
2743 ············_\x8c_\x8i_\x8s············1.1.2.3.12743 ············_\x8c_\x8i_\x8s············1.1.2.3.1
2744 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-230328r1017139_rule2744 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-230328r1017139_rule
2745 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
2746 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
2747 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high 
2748 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
2749 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
2750 part·/home 
2751 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x82745 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
2752 [[customizations.filesystem]]2746 [[customizations.filesystem]]
2753 mountpoint·=·"/home"2747 mountpoint·=·"/home"
2754 size·=·10737418242748 size·=·1073741824
2755 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x82749 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
2756 logvol·/home·10242750 logvol·/home·1024
 2751 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 2752 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 2753 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high
 2754 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 2755 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 2756 part·/home
2757 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/t\x8tm\x8mp\x8p·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*2757 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/t\x8tm\x8mp\x8p·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
2758 The·/tmp·directory·is·a·world-writable·directory·used·for·temporary·file·storage.·Ensure·it·has·its·own·partition·or·logical·volume·at·installation·time,·or·migrate·it·using·LVM.2758 The·/tmp·directory·is·a·world-writable·directory·used·for·temporary·file·storage.·Ensure·it·has·its·own·partition·or·logical·volume·at·installation·time,·or·migrate·it·using·LVM.
2759 Rationale:··The·/tmp·partition·is·used·as·temporary·storage·by·many·programs.·Placing·/tmp·in·its·own·partition·enables·the·setting·of·more·restrictive·mount·options,·which·can·help·protect·programs·which·use·it.2759 Rationale:··The·/tmp·partition·is·used·as·temporary·storage·by·many·programs.·Placing·/tmp·in·its·own·partition·enables·the·setting·of·more·restrictive·mount·options,·which·can·help·protect·programs·which·use·it.
2760 Severity: ··low2760 Severity: ··low
2761 Rule·ID:····xccdf_org.ssgproject.content_rule_partition_for_tmp2761 Rule·ID:····xccdf_org.ssgproject.content_rule_partition_for_tmp
2762 ············_\x8c_\x8i_\x8s_\x8-_\x8c_\x8s_\x8c········12,·15,·82762 ············_\x8c_\x8i_\x8s_\x8-_\x8c_\x8s_\x8c········12,·15,·8
2763 ············_\x8c_\x8o_\x8b_\x8i_\x8t_\x85·········APO13.01,·DSS05.022763 ············_\x8c_\x8o_\x8b_\x8i_\x8t_\x85·········APO13.01,·DSS05.02
Offset 2768, 29 lines modifiedOffset 2768, 29 lines modified
2768 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.5,·SR·3.8,·SR·4.1,·SR·4.3,·SR·5.1,·SR·5.2,·SR·5.3,·SR·7.1,·SR·7.62768 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.5,·SR·3.8,·SR·4.1,·SR·4.3,·SR·5.1,·SR·5.2,·SR·5.3,·SR·7.1,·SR·7.6
Max diff block lines reached; 169747/175345 bytes (96.81%) of diff not shown.
1.58 MB
./usr/share/doc/ssg-nondebian/ssg-centos8-guide-stig_gui.html
    
Offset 15457, 207 lines modifiedOffset 15457, 207 lines modified
0003c600:·2d74·6172·6765·743d·2223·6964·6d38·3031··-target="#idm8010003c600:·2d74·6172·6765·743d·2223·6964·6d38·3031··-target="#idm801
0003c610:·3322·2074·6162·696e·6465·783d·2230·2220··3"·tabindex="0"·0003c610:·3322·2074·6162·696e·6465·783d·2230·2220··3"·tabindex="0"·
0003c620:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar0003c620:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar
0003c630:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal0003c630:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal
0003c640:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ0003c640:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ
0003c650:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h0003c650:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h
0003c660:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia0003c660:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia
 0003c670:·7469·6f6e·204f·5342·7569·6c64·2042·6c75··tion·OSBuild·Blu
 0003c680:·6570·7269·6e74·2073·6e69·7070·6574·20e2··eprint·snippet·.
 0003c690:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c
 0003c6a0:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
 0003c6b0:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
 0003c6c0:·643d·2269·646d·3830·3133·223e·3c70·7265··d="idm8013"><pre
 0003c6d0:·3e3c·636f·6465·3e0a·5b5b·7061·636b·6167··><code>.[[packag
 0003c6e0:·6573·5d5d·0a6e·616d·6520·3d20·2261·6964··es]].name·=·"aid
 0003c6f0:·6522·0a76·6572·7369·6f6e·203d·2022·2a22··e".version·=·"*"
0003c670:·7469·6f6e·2073·6372·6970·7420·e287·b23c··tion·script·...< 
0003c680:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas 
0003c690:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps 
0003c6a0:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id=" 
0003c6b0:·6964·6d38·3031·3322·3e3c·7461·626c·6520··idm8013"><table· 
0003c6c0:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab 
0003c6d0:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table 
0003c6e0:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table- 
0003c6f0:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr>< 
0003c700:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</ 
0003c710:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td>< 
0003c720:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr 
0003c730:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td> 
0003c740:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr 
0003c750:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th 
0003c760:·3e3c·7464·3e66·616c·7365·3c2f·7464·3e3c··><td>false</td>< 
0003c770:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra 
0003c780:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en 
0003c790:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></ 
0003c7a0:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code 
0003c7b0:·3e0a·646e·6620·696e·7374·616c·6c20·6169··>.dnf·install·ai 
0003c7c0:·6465·0a3c·2f63·6f64·653e·3c2f·7072·653e··de.</code></pre>0003c700:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></
0003c7d0:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class="0003c710:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt
0003c7e0:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success"0003c720:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d
0003c7f0:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co0003c730:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll
0003c800:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar0003c740:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
0003c810:·6765·743d·2223·6964·6d38·3031·3422·2074··get="#idm8014"·t0003c750:·743d·2223·6964·6d38·3031·3422·2074·6162··t="#idm8014"·tab
0003c820:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role0003c760:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
0003c830:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e0003c770:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
0003c840:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·0003c780:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
0003c850:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·0003c790:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
0003c860:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=0003c7a0:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
0003c870:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation0003c7b0:·2122·3e52·656d·6564·6961·7469·6f6e·2050··!">Remediation·P
0003c880:·2041·6e61·636f·6e64·6120·736e·6970·7065···Anaconda·snippe 
0003c890:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di 
0003c8a0:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c 
0003c8b0:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse 
0003c8c0:·2220·6964·3d22·6964·6d38·3031·3422·3e3c··"·id="idm8014">< 
0003c8d0:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab 
0003c8e0:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped 
0003c8f0:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered· 
0003c900:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed" 
0003c910:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex 
0003c920:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low 
0003c930:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
0003c940:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t 
0003c950:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></ 
0003c960:·7472·3e3c·7472·3e3c·7468·3e52·6562·6f6f··tr><tr><th>Reboo 
0003c970:·743a·3c2f·7468·3e3c·7464·3e66·616c·7365··t:</th><td>false 
0003c980:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
0003c990:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th> 
0003c9a0:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td>< 
0003c9b0:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre 
0003c9c0:·3e3c·636f·6465·3e0a·7061·636b·6167·6520··><code>.package· 
0003c9d0:·2d2d·6164·643d·6169·6465·0a3c·2f63·6f64··--add=aide.</cod 
0003c9e0:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a 
0003c9f0:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn- 
0003ca00:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to 
0003ca10:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"· 
0003ca20:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id 
0003ca30:·6d38·3031·3522·2074·6162·696e·6465·783d··m8015"·tabindex= 
0003ca40:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button 
0003ca50:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded= 
0003ca60:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A 
0003ca70:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea 
0003ca80:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem 
0003ca90:·6564·6961·7469·6f6e·204f·5342·7569·6c64··ediation·OSBuild 
0003caa0:·2042·6c75·6570·7269·6e74·2073·6e69·7070···Blueprint·snipp 
0003cab0:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d 
0003cac0:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel- 
0003cad0:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps 
0003cae0:·6522·2069·643d·2269·646d·3830·3135·223e··e"·id="idm8015"> 
0003caf0:·3c70·7265·3e3c·636f·6465·3e0a·5b5b·7061··<pre><code>.[[pa 
0003cb00:·636b·6167·6573·5d5d·0a6e·616d·6520·3d20··ckages]].name·=· 
0003cb10:·2261·6964·6522·0a76·6572·7369·6f6e·203d··"aide".version·= 
0003cb20:·2022·2a22·0a3c·2f63·6f64·653e·3c2f·7072···"*".</code></pr 
0003cb30:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class 
0003cb40:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes 
0003cb50:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle=" 
0003cb60:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t 
0003cb70:·6172·6765·743d·2223·6964·6d38·3031·3622··arget="#idm8016" 
0003cb80:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro 
0003cb90:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria 
0003cba0:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false 
0003cbb0:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat 
0003cbc0:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre 
0003cbd0:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati 
0003cbe0:·6f6e·2073·6372·6970·7420·e287·b23c·2f61··on·script·...</a 
0003cbf0:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class= 
0003cc00:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse· 
0003cc10:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id 
0003cc20:·6d38·3031·3622·3e3c·7461·626c·6520·636c··m8016"><table·cl 
0003cc30:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table 
0003cc40:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b 
0003cc50:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co 
0003cc60:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th 
0003cc70:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th 
0003cc80:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t 
0003cc90:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup 
0003cca0:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo 
0003ccb0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr>< 
0003ccc0:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th>< 
0003ccd0:·7464·3e66·616c·7365·3c2f·7464·3e3c·2f74··td>false</td></t 
0003cce0:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate 
0003ccf0:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab 
0003cd00:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta 
0003cd10:·626c·653e·3c70·7265·3e3c·636f·6465·3e0a··ble><pre><code>. 
0003cd20:·7061·636b·6167·6520·696e·7374·616c·6c20··package·install· 
0003cd30:·6169·6465·0a3c·2f63·6f64·653e·3c2f·7072··aide.</code></pr 
0003cd40:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class 
0003cd50:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes 
Max diff block lines reached; 1461599/1488813 bytes (98.17%) of diff not shown.
166 KB
html2text {}
    
Offset 179, 52 lines modifiedOffset 179, 38 lines modified
179 ··-·PCI-DSSv4-11.5.2179 ··-·PCI-DSSv4-11.5.2
180 ··-·enable_strategy180 ··-·enable_strategy
181 ··-·low_complexity181 ··-·low_complexity
182 ··-·low_disruption182 ··-·low_disruption
183 ··-·medium_severity183 ··-·medium_severity
184 ··-·no_reboot_needed184 ··-·no_reboot_needed
185 ··-·package_aide_installed185 ··-·package_aide_installed
186 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
187 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
188 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
189 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
190 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
191 dnf·install·aide 
192 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
193 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
194 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
195 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
196 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
197 package·--add=aide 
198 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8186 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
199 [[packages]]187 [[packages]]
200 name·=·"aide"188 name·=·"aide"
201 version·=·"*"189 version·=·"*"
202 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
203 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
204 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
205 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
206 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
207 package·install·aide 
208 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8190 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
209 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low191 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
210 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low192 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
211 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false193 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
212 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable194 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
213 include·install_aide195 include·install_aide
  
214 class·install_aide·{196 class·install_aide·{
215 ··package·{·'aide':197 ··package·{·'aide':
216 ····ensure·=>·'installed',198 ····ensure·=>·'installed',
217 ··}199 ··}
218 }200 }
 201 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 202 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 203 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 204 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 205 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 206 package·install·aide
219 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8207 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
220 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low208 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
221 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low209 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
222 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false210 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
223 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable211 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
224 #·Remediation·is·applicable·only·in·certain·platforms212 #·Remediation·is·applicable·only·in·certain·platforms
225 if·rpm·--quiet·-q·kernel;·then213 if·rpm·--quiet·-q·kernel;·then
Offset 232, 14 lines modifiedOffset 218, 28 lines modified
232 if·!·rpm·-q·--quiet·"aide"·;·then218 if·!·rpm·-q·--quiet·"aide"·;·then
233 ····yum·install·-y·"aide"219 ····yum·install·-y·"aide"
234 fi220 fi
  
235 else221 else
236 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'222 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
237 fi223 fi
 224 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 225 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 226 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 227 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 228 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 229 package·--add=aide
 230 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 231 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 232 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 233 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 234 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 235 dnf·install·aide
238 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*236 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
239 Run·the·following·command·to·generate·a·new·database:237 Run·the·following·command·to·generate·a·new·database:
240 $·sudo·/usr/sbin/aide·--init238 $·sudo·/usr/sbin/aide·--init
241 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:239 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
242 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz240 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
243 To·initiate·a·manual·check,·run·the·following·command:241 To·initiate·a·manual·check,·run·the·following·command:
244 $·sudo·/usr/sbin/aide·--check242 $·sudo·/usr/sbin/aide·--check
Offset 2743, 29 lines modifiedOffset 2743, 29 lines modified
2743 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.32743 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.3
2744 References:·_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)2744 References:·_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)
2745 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-42745 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4
2746 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-002272746 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
2747 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R282747 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R28
2748 ············_\x8c_\x8i_\x8s············1.1.2.3.12748 ············_\x8c_\x8i_\x8s············1.1.2.3.1
2749 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-230328r1017139_rule2749 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-230328r1017139_rule
2750 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
2751 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
2752 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high 
2753 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
2754 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
2755 part·/home 
2756 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x82750 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
2757 [[customizations.filesystem]]2751 [[customizations.filesystem]]
2758 mountpoint·=·"/home"2752 mountpoint·=·"/home"
2759 size·=·10737418242753 size·=·1073741824
2760 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x82754 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
2761 logvol·/home·10242755 logvol·/home·1024
 2756 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 2757 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 2758 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high
 2759 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 2760 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 2761 part·/home
2762 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/t\x8tm\x8mp\x8p·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*2762 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/t\x8tm\x8mp\x8p·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
2763 The·/tmp·directory·is·a·world-writable·directory·used·for·temporary·file·storage.·Ensure·it·has·its·own·partition·or·logical·volume·at·installation·time,·or·migrate·it·using·LVM.2763 The·/tmp·directory·is·a·world-writable·directory·used·for·temporary·file·storage.·Ensure·it·has·its·own·partition·or·logical·volume·at·installation·time,·or·migrate·it·using·LVM.
2764 Rationale:··The·/tmp·partition·is·used·as·temporary·storage·by·many·programs.·Placing·/tmp·in·its·own·partition·enables·the·setting·of·more·restrictive·mount·options,·which·can·help·protect·programs·which·use·it.2764 Rationale:··The·/tmp·partition·is·used·as·temporary·storage·by·many·programs.·Placing·/tmp·in·its·own·partition·enables·the·setting·of·more·restrictive·mount·options,·which·can·help·protect·programs·which·use·it.
2765 Severity: ··low2765 Severity: ··low
2766 Rule·ID:····xccdf_org.ssgproject.content_rule_partition_for_tmp2766 Rule·ID:····xccdf_org.ssgproject.content_rule_partition_for_tmp
2767 ············_\x8c_\x8i_\x8s_\x8-_\x8c_\x8s_\x8c········12,·15,·82767 ············_\x8c_\x8i_\x8s_\x8-_\x8c_\x8s_\x8c········12,·15,·8
2768 ············_\x8c_\x8o_\x8b_\x8i_\x8t_\x85·········APO13.01,·DSS05.022768 ············_\x8c_\x8o_\x8b_\x8i_\x8t_\x85·········APO13.01,·DSS05.02
Offset 2773, 29 lines modifiedOffset 2773, 29 lines modified
2773 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.5,·SR·3.8,·SR·4.1,·SR·4.3,·SR·5.1,·SR·5.2,·SR·5.3,·SR·7.1,·SR·7.62773 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.5,·SR·3.8,·SR·4.1,·SR·4.3,·SR·5.1,·SR·5.2,·SR·5.3,·SR·7.1,·SR·7.6
Max diff block lines reached; 164323/169921 bytes (96.71%) of diff not shown.
991 KB
./usr/share/doc/ssg-nondebian/ssg-cs10-guide-anssi_bp28_enhanced.html
    
Offset 15250, 207 lines modifiedOffset 15250, 207 lines modified
0003b910:·2d74·6172·6765·743d·2223·6964·6d37·3333··-target="#idm7330003b910:·2d74·6172·6765·743d·2223·6964·6d37·3333··-target="#idm733
0003b920:·3222·2074·6162·696e·6465·783d·2230·2220··2"·tabindex="0"·0003b920:·3222·2074·6162·696e·6465·783d·2230·2220··2"·tabindex="0"·
0003b930:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar0003b930:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar
0003b940:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal0003b940:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal
0003b950:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ0003b950:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ
0003b960:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h0003b960:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h
0003b970:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia0003b970:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia
 0003b980:·7469·6f6e·204f·5342·7569·6c64·2042·6c75··tion·OSBuild·Blu
 0003b990:·6570·7269·6e74·2073·6e69·7070·6574·20e2··eprint·snippet·.
 0003b9a0:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c
 0003b9b0:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
 0003b9c0:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
 0003b9d0:·643d·2269·646d·3733·3332·223e·3c70·7265··d="idm7332"><pre
 0003b9e0:·3e3c·636f·6465·3e0a·5b5b·7061·636b·6167··><code>.[[packag
 0003b9f0:·6573·5d5d·0a6e·616d·6520·3d20·2261·6964··es]].name·=·"aid
 0003ba00:·6522·0a76·6572·7369·6f6e·203d·2022·2a22··e".version·=·"*"
0003b980:·7469·6f6e·2073·6372·6970·7420·e287·b23c··tion·script·...< 
0003b990:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas 
0003b9a0:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps 
0003b9b0:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id=" 
0003b9c0:·6964·6d37·3333·3222·3e3c·7461·626c·6520··idm7332"><table· 
0003b9d0:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab 
0003b9e0:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table 
0003b9f0:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table- 
0003ba00:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr>< 
0003ba10:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</ 
0003ba20:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td>< 
0003ba30:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr 
0003ba40:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td> 
0003ba50:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr 
0003ba60:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th 
0003ba70:·3e3c·7464·3e66·616c·7365·3c2f·7464·3e3c··><td>false</td>< 
0003ba80:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra 
0003ba90:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en 
0003baa0:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></ 
0003bab0:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code 
0003bac0:·3e0a·646e·6620·696e·7374·616c·6c20·6169··>.dnf·install·ai 
0003bad0:·6465·0a3c·2f63·6f64·653e·3c2f·7072·653e··de.</code></pre>0003ba10:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></
0003bae0:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class="0003ba20:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt
0003baf0:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success"0003ba30:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d
0003bb00:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co0003ba40:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll
0003bb10:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar0003ba50:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
0003bb20:·6765·743d·2223·6964·6d37·3333·3322·2074··get="#idm7333"·t0003ba60:·743d·2223·6964·6d37·3333·3322·2074·6162··t="#idm7333"·tab
0003bb30:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role0003ba70:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
0003bb40:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e0003ba80:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
0003bb50:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·0003ba90:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
0003bb60:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·0003baa0:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
0003bb70:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=0003bab0:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
0003bb80:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation0003bac0:·2122·3e52·656d·6564·6961·7469·6f6e·2050··!">Remediation·P
0003bb90:·2041·6e61·636f·6e64·6120·736e·6970·7065···Anaconda·snippe0003bad0:·7570·7065·7420·736e·6970·7065·7420·e287··uppet·snippet·..
0003bba0:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di0003bae0:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl
0003bbb0:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c0003baf0:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla
0003bbc0:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse0003bb00:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id
0003bbd0:·2220·6964·3d22·6964·6d37·3333·3322·3e3c··"·id="idm7333"><0003bb10:·3d22·6964·6d37·3333·3322·3e3c·7461·626c··="idm7333"><tabl
0003bbe0:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab0003bb20:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t
0003bbf0:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped0003bb30:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab
0003bc00:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·0003bb40:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl
0003bc10:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"0003bb50:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr
0003bc20:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex0003bb60:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:
0003bc30:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low0003bb70:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
0003bc40:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t0003bb80:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di
0003bc50:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t0003bb90:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t
 0003bba0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
 0003bbb0:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</
 0003bbc0:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td
 0003bbd0:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St
 0003bbe0:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>
 0003bbf0:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr>
 0003bc00:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co
 0003bc10:·6465·3e69·6e63·6c75·6465·2069·6e73·7461··de>include·insta
 0003bc20:·6c6c·5f61·6964·650a·0a63·6c61·7373·2069··ll_aide..class·i
 0003bc30:·6e73·7461·6c6c·5f61·6964·6520·7b0a·2020··nstall_aide·{.··
 0003bc40:·7061·636b·6167·6520·7b20·2761·6964·6527··package·{·'aide'
 0003bc50:·3a0a·2020·2020·656e·7375·7265·203d·2667··:.····ensure·=&g
 0003bc60:·743b·2027·696e·7374·616c·6c65·6427·2c0a··t;·'installed',.
 0003bc70:·2020·7d0a·7d0a·3c2f·636f·6465·3e3c·2f70····}.}.</code></p
 0003bc80:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas
 0003bc90:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe
 0003bca0:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle=
 0003bcb0:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data-
 0003bcc0:·7461·7267·6574·3d22·2369·646d·3733·3334··target="#idm7334
 0003bcd0:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r
 0003bce0:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari
 0003bcf0:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals
 0003bd00:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa
 0003bd10:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr
 0003bd20:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat
 0003bd30:·696f·6e20·7363·7269·7074·20e2·87b2·3c2f··ion·script·...</
 0003bd40:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
 0003bd50:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
 0003bd60:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
 0003bd70:·646d·3733·3334·223e·3c74·6162·6c65·2063··dm7334"><table·c
 0003bd80:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl
 0003bd90:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-
 0003bda0:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c
 0003bdb0:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t
 0003bdc0:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t
0003bc60:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></0003bdd0:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
0003bc70:·7472·3e3c·7472·3e3c·7468·3e52·6562·6f6f··tr><tr><th>Reboo0003bde0:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru
0003bc80:·743a·3c2f·7468·3e3c·7464·3e66·616c·7365··t:</th><td>false0003bdf0:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l
0003bc90:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t0003be00:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
0003bca0:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th> 
0003bcb0:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td>< 
0003bcc0:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre 
0003bcd0:·3e3c·636f·6465·3e0a·7061·636b·6167·6520··><code>.package· 
0003bce0:·2d2d·6164·643d·6169·6465·0a3c·2f63·6f64··--add=aide.</cod 
0003bcf0:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a 
0003bd00:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn- 
0003bd10:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to 
0003bd20:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"· 
0003bd30:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id 
0003bd40:·6d37·3333·3422·2074·6162·696e·6465·783d··m7334"·tabindex= 
0003bd50:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button 
0003bd60:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded= 
0003bd70:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A 
0003bd80:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea 
0003bd90:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem 
0003bda0:·6564·6961·7469·6f6e·204f·5342·7569·6c64··ediation·OSBuild 
0003bdb0:·2042·6c75·6570·7269·6e74·2073·6e69·7070···Blueprint·snipp0003be10:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th>
 0003be20:·3c74·643e·6661·6c73·653c·2f74·643e·3c2f··<td>false</td></
 0003be30:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat
 0003be40:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena
 0003be50:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t
 0003be60:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>
 0003be70:·0a70·6163·6b61·6765·2069·6e73·7461·6c6c··.package·install
 0003be80:·2061·6964·650a·3c2f·636f·6465·3e3c·2f70···aide.</code></p
 0003be90:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas
Max diff block lines reached; 884044/911258 bytes (97.01%) of diff not shown.
101 KB
html2text {}
    
Offset 155, 52 lines modifiedOffset 155, 38 lines modified
155 ··-·PCI-DSSv4-11.5.2155 ··-·PCI-DSSv4-11.5.2
156 ··-·enable_strategy156 ··-·enable_strategy
157 ··-·low_complexity157 ··-·low_complexity
158 ··-·low_disruption158 ··-·low_disruption
159 ··-·medium_severity159 ··-·medium_severity
160 ··-·no_reboot_needed160 ··-·no_reboot_needed
161 ··-·package_aide_installed161 ··-·package_aide_installed
162 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
163 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
164 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
165 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
166 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
167 dnf·install·aide 
168 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
169 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
170 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
171 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
172 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
173 package·--add=aide 
174 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8162 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
175 [[packages]]163 [[packages]]
176 name·=·"aide"164 name·=·"aide"
177 version·=·"*"165 version·=·"*"
178 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
179 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
180 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
181 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
182 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
183 package·install·aide 
184 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8166 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
185 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low167 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
186 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low168 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
187 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false169 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
188 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable170 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
189 include·install_aide171 include·install_aide
  
190 class·install_aide·{172 class·install_aide·{
191 ··package·{·'aide':173 ··package·{·'aide':
192 ····ensure·=>·'installed',174 ····ensure·=>·'installed',
193 ··}175 ··}
194 }176 }
 177 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 178 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 179 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 180 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 181 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 182 package·install·aide
195 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8183 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
196 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low184 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
197 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low185 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
198 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false186 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
199 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable187 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
200 #·Remediation·is·applicable·only·in·certain·platforms188 #·Remediation·is·applicable·only·in·certain·platforms
201 if·rpm·--quiet·-q·kernel;·then189 if·rpm·--quiet·-q·kernel;·then
Offset 208, 14 lines modifiedOffset 194, 28 lines modified
208 if·!·rpm·-q·--quiet·"aide"·;·then194 if·!·rpm·-q·--quiet·"aide"·;·then
209 ····dnf·install·-y·"aide"195 ····dnf·install·-y·"aide"
210 fi196 fi
  
211 else197 else
212 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'198 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
213 fi199 fi
 200 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 201 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 202 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 203 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 204 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 205 package·--add=aide
 206 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 207 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 208 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 209 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 210 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 211 dnf·install·aide
214 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*212 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
215 Run·the·following·command·to·generate·a·new·database:213 Run·the·following·command·to·generate·a·new·database:
216 $·sudo·/usr/sbin/aide·--init214 $·sudo·/usr/sbin/aide·--init
217 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:215 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
218 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz216 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
219 To·initiate·a·manual·check,·run·the·following·command:217 To·initiate·a·manual·check,·run·the·following·command:
220 $·sudo·/usr/sbin/aide·--check218 $·sudo·/usr/sbin/aide·--check
Offset 350, 26 lines modifiedOffset 350, 26 lines modified
350 If·a·system·has·already·been·installed,·and·the·default·partitioning·scheme·was·used,·it·is·possible·but·nontrivial·to·modify·it·to·create·separate·logical·volumes·for·the·directories·listed·above.·The·Logical·Volume·Manager·(LVM)·makes·this·possible.350 If·a·system·has·already·been·installed,·and·the·default·partitioning·scheme·was·used,·it·is·possible·but·nontrivial·to·modify·it·to·create·separate·logical·volumes·for·the·directories·listed·above.·The·Logical·Volume·Manager·(LVM)·makes·this·possible.
351 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/b\x8bo\x8oo\x8ot\x8t·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*351 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/b\x8bo\x8oo\x8ot\x8t·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
352 It·is·recommended·that·the·/boot·directory·resides·on·a·separate·partition.·This·makes·it·easier·to·apply·restrictions·e.g.·through·the·noexec·mount·option.·Eventually,·the·/boot·partition·can·be·configured·not·to·be·mounted·automatically·with·the·noauto·mount·option.352 It·is·recommended·that·the·/boot·directory·resides·on·a·separate·partition.·This·makes·it·easier·to·apply·restrictions·e.g.·through·the·noexec·mount·option.·Eventually,·the·/boot·partition·can·be·configured·not·to·be·mounted·automatically·with·the·noauto·mount·option.
353 Rationale:··The·/boot·partition·contains·the·kernel·and·bootloader·files.·Access·to·this·partition·should·be·restricted.353 Rationale:··The·/boot·partition·contains·the·kernel·and·bootloader·files.·Access·to·this·partition·should·be·restricted.
354 Severity: ··medium354 Severity: ··medium
355 Rule·ID:····xccdf_org.ssgproject.content_rule_partition_for_boot355 Rule·ID:····xccdf_org.ssgproject.content_rule_partition_for_boot
356 References:·_\x8a_\x8n_\x8s_\x8s_\x8i·R28356 References:·_\x8a_\x8n_\x8s_\x8s_\x8i·R28
 357 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 358 [[customizations.filesystem]]
 359 mountpoint·=·"/boot"
 360 size·=·1073741824
357 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8361 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
358 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low362 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
359 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high363 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high
360 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false364 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
361 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable365 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
362 part·/boot366 part·/boot
363 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
364 [[customizations.filesystem]] 
365 mountpoint·=·"/boot" 
366 size·=·1073741824 
367 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/h\x8ho\x8om\x8me\x8e·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*367 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/h\x8ho\x8om\x8me\x8e·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
368 If·user·home·directories·will·be·stored·locally,·create·a·separate·partition·for·/home·at·installation·time·(or·migrate·it·later·using·LVM).·If·/home·will·be·mounted·from·another·system·such·as·an·NFS·server,·then·creating·a·separate·partition·is·not·necessary·at·installation·time,·and·the·mountpoint·can·instead·be·configured·later.368 If·user·home·directories·will·be·stored·locally,·create·a·separate·partition·for·/home·at·installation·time·(or·migrate·it·later·using·LVM).·If·/home·will·be·mounted·from·another·system·such·as·an·NFS·server,·then·creating·a·separate·partition·is·not·necessary·at·installation·time,·and·the·mountpoint·can·instead·be·configured·later.
369 Rationale:··Ensuring·that·/home·is·mounted·on·its·own·partition·enables·the·setting·of·more·restrictive·mount·options,·and·also·helps·ensure·that·users·cannot·trivially·fill·partitions·used·for·log·or·audit·data·storage.369 Rationale:··Ensuring·that·/home·is·mounted·on·its·own·partition·enables·the·setting·of·more·restrictive·mount·options,·and·also·helps·ensure·that·users·cannot·trivially·fill·partitions·used·for·log·or·audit·data·storage.
370 Severity: ··low370 Severity: ··low
371 Rule·ID:····xccdf_org.ssgproject.content_rule_partition_for_home371 Rule·ID:····xccdf_org.ssgproject.content_rule_partition_for_home
372 ············_\x8c_\x8i_\x8s_\x8-_\x8c_\x8s_\x8c········12,·15,·8372 ············_\x8c_\x8i_\x8s_\x8-_\x8c_\x8s_\x8c········12,·15,·8
373 ············_\x8c_\x8o_\x8b_\x8i_\x8t_\x85·········APO13.01,·DSS05.02373 ············_\x8c_\x8o_\x8b_\x8i_\x8t_\x85·········APO13.01,·DSS05.02
Offset 377, 92 lines modifiedOffset 377, 92 lines modified
377 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.5,·SR·3.8,·SR·4.1,·SR·4.3,·SR·5.1,·SR·5.2,·SR·5.3,·SR·7.1,·SR·7.6377 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.5,·SR·3.8,·SR·4.1,·SR·4.3,·SR·5.1,·SR·5.2,·SR·5.3,·SR·7.1,·SR·7.6
378 References:·_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.3378 References:·_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.3
379 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)379 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)
380 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4380 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4
381 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227381 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
382 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R28382 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R28
Max diff block lines reached; 96491/102912 bytes (93.76%) of diff not shown.
1.06 MB
./usr/share/doc/ssg-nondebian/ssg-cs10-guide-anssi_bp28_high.html
    
Offset 15255, 207 lines modifiedOffset 15255, 207 lines modified
0003b960:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm0003b960:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
0003b970:·3733·3332·2220·7461·6269·6e64·6578·3d22··7332"·tabindex="0003b970:·3733·3332·2220·7461·6269·6e64·6578·3d22··7332"·tabindex="
0003b980:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"0003b980:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
0003b990:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="0003b990:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
0003b9a0:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac0003b9a0:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
0003b9b0:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal0003b9b0:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
0003b9c0:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme0003b9c0:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
0003b9d0:·6469·6174·696f·6e20·7363·7269·7074·20e2··diation·script·.0003b9d0:·6469·6174·696f·6e20·4f53·4275·696c·6420··diation·OSBuild·
 0003b9e0:·426c·7565·7072·696e·7420·736e·6970·7065··Blueprint·snippe
 0003b9f0:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di
 0003ba00:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c
 0003ba10:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse
 0003ba20:·2220·6964·3d22·6964·6d37·3333·3222·3e3c··"·id="idm7332"><
 0003ba30:·7072·653e·3c63·6f64·653e·0a5b·5b70·6163··pre><code>.[[pac
 0003ba40:·6b61·6765·735d·5d0a·6e61·6d65·203d·2022··kages]].name·=·"
 0003ba50:·6169·6465·220a·7665·7273·696f·6e20·3d20··aide".version·=·
0003b9e0:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c 
0003b9f0:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll 
0003ba00:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i 
0003ba10:·643d·2269·646d·3733·3332·223e·3c74·6162··d="idm7332"><tab 
0003ba20:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table· 
0003ba30:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta 
0003ba40:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab 
0003ba50:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t 
0003ba60:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity 
0003ba70:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t 
0003ba80:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D 
0003ba90:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th>< 
0003baa0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
0003bab0:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:< 
0003bac0:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t 
0003bad0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S 
0003bae0:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td 
0003baf0:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr 
0003bb00:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c 
0003bb10:·6f64·653e·0a64·6e66·2069·6e73·7461·6c6c··ode>.dnf·install 
0003bb20:·2061·6964·650a·3c2f·636f·6465·3e3c·2f70···aide.</code></p0003ba60:·222a·220a·3c2f·636f·6465·3e3c·2f70·7265··"*".</code></pre
0003bb30:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas0003ba70:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class=
0003bb40:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe0003ba80:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success
0003bb50:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle=0003ba90:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c
0003bb60:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data-0003baa0:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta
0003bb70:·7461·7267·6574·3d22·2369·646d·3733·3333··target="#idm73330003bab0:·7267·6574·3d22·2369·646d·3733·3333·2220··rget="#idm7333"·
0003bb80:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r0003bac0:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol
0003bb90:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari0003bad0:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-
0003bba0:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals0003bae0:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"
0003bbb0:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa0003baf0:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate
0003bbc0:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr0003bb00:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href
0003bbd0:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat0003bb10:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio
0003bbe0:·696f·6e20·416e·6163·6f6e·6461·2073·6e69··ion·Anaconda·sni0003bb20:·6e20·5075·7070·6574·2073·6e69·7070·6574··n·Puppet·snippet
0003bbf0:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>0003bb30:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
0003bc00:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane0003bb40:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
0003bc10:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla0003bb50:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
0003bc20:·7073·6522·2069·643d·2269·646d·3733·3333··pse"·id="idm73330003bb60:·2069·643d·2269·646d·3733·3333·223e·3c74···id="idm7333"><t
0003bc30:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="0003bb70:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl
0003bc40:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri0003bb80:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·
0003bc50:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border0003bb90:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t
0003bc60:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens0003bba0:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">
0003bc70:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp0003bbb0:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi
0003bc80:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>0003bbc0:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<
 0003bbd0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 0003bbe0:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th
 0003bbf0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
 0003bc00:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot
 0003bc10:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false<
0003bc90:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr0003bc20:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
0003bca0:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:0003bc30:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><
 0003bc40:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></
 0003bc50:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>
 0003bc60:·3c63·6f64·653e·696e·636c·7564·6520·696e··<code>include·in
 0003bc70:·7374·616c·6c5f·6169·6465·0a0a·636c·6173··stall_aide..clas
 0003bc80:·7320·696e·7374·616c·6c5f·6169·6465·207b··s·install_aide·{
 0003bc90:·0a20·2070·6163·6b61·6765·207b·2027·6169··.··package·{·'ai
 0003bca0:·6465·273a·0a20·2020·2065·6e73·7572·6520··de':.····ensure·
 0003bcb0:·3d26·6774·3b20·2769·6e73·7461·6c6c·6564··=&gt;·'installed
 0003bcc0:·272c·0a20·207d·0a7d·0a3c·2f63·6f64·653e··',.··}.}.</code>
 0003bcd0:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c
 0003bce0:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su
 0003bcf0:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg
 0003bd00:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da
 0003bd10:·7461·2d74·6172·6765·743d·2223·6964·6d37··ta-target="#idm7
 0003bd20:·3333·3422·2074·6162·696e·6465·783d·2230··334"·tabindex="0
 0003bd30:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
 0003bd40:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
 0003bd50:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
 0003bd60:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
 0003bd70:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
 0003bd80:·6961·7469·6f6e·2073·6372·6970·7420·e287··iation·script·..
 0003bd90:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl
 0003bda0:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla
 0003bdb0:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id
 0003bdc0:·3d22·6964·6d37·3333·3422·3e3c·7461·626c··="idm7334"><tabl
 0003bdd0:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t
 0003bde0:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab
 0003bdf0:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl
 0003be00:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr
 0003be10:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:
0003bcb0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td0003be20:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
0003bcc0:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re0003be30:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di
0003bcd0:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa0003be40:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t
0003bce0:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr0003be50:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
0003bcf0:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</0003be60:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</
0003bd00:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t0003be70:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td
0003bd10:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table>< 
0003bd20:·7072·653e·3c63·6f64·653e·0a70·6163·6b61··pre><code>.packa 
0003bd30:·6765·202d·2d61·6464·3d61·6964·650a·3c2f··ge·--add=aide.</ 
0003bd40:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div 
0003bd50:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b 
0003bd60:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data 
0003bd70:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps 
0003bd80:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target=" 
0003bd90:·2369·646d·3733·3334·2220·7461·6269·6e64··#idm7334"·tabind 
0003bda0:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but 
0003bdb0:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand 
0003bdc0:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title 
0003bdd0:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re 
0003bde0:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!"> 
0003bdf0:·5265·6d65·6469·6174·696f·6e20·4f53·4275··Remediation·OSBu 
0003be00:·696c·6420·426c·7565·7072·696e·7420·736e··ild·Blueprint·sn0003be80:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St
 0003be90:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>
 0003bea0:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr>
 0003beb0:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co
 0003bec0:·6465·3e0a·7061·636b·6167·6520·696e·7374··de>.package·inst
 0003bed0:·616c·6c20·6169·6465·0a3c·2f63·6f64·653e··all·aide.</code>
 0003bee0:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c
 0003bef0:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su
 0003bf00:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg
 0003bf10:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da
Max diff block lines reached; 969004/996218 bytes (97.27%) of diff not shown.
110 KB
html2text {}
    
Offset 156, 52 lines modifiedOffset 156, 38 lines modified
156 ··-·PCI-DSSv4-11.5.2156 ··-·PCI-DSSv4-11.5.2
157 ··-·enable_strategy157 ··-·enable_strategy
158 ··-·low_complexity158 ··-·low_complexity
159 ··-·low_disruption159 ··-·low_disruption
160 ··-·medium_severity160 ··-·medium_severity
161 ··-·no_reboot_needed161 ··-·no_reboot_needed
162 ··-·package_aide_installed162 ··-·package_aide_installed
163 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
164 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
165 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
166 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
167 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
168 dnf·install·aide 
169 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
170 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
171 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
172 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
173 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
174 package·--add=aide 
175 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8163 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
176 [[packages]]164 [[packages]]
177 name·=·"aide"165 name·=·"aide"
178 version·=·"*"166 version·=·"*"
179 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
180 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
181 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
182 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
183 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
184 package·install·aide 
185 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8167 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
186 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low168 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
187 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low169 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
188 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false170 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
189 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable171 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
190 include·install_aide172 include·install_aide
  
191 class·install_aide·{173 class·install_aide·{
192 ··package·{·'aide':174 ··package·{·'aide':
193 ····ensure·=>·'installed',175 ····ensure·=>·'installed',
194 ··}176 ··}
195 }177 }
 178 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 179 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 180 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 181 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 182 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 183 package·install·aide
196 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8184 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
197 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low185 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
198 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low186 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
199 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false187 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
200 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable188 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
201 #·Remediation·is·applicable·only·in·certain·platforms189 #·Remediation·is·applicable·only·in·certain·platforms
202 if·rpm·--quiet·-q·kernel;·then190 if·rpm·--quiet·-q·kernel;·then
Offset 209, 14 lines modifiedOffset 195, 28 lines modified
209 if·!·rpm·-q·--quiet·"aide"·;·then195 if·!·rpm·-q·--quiet·"aide"·;·then
210 ····dnf·install·-y·"aide"196 ····dnf·install·-y·"aide"
211 fi197 fi
  
212 else198 else
213 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'199 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
214 fi200 fi
 201 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 202 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 203 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 204 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 205 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 206 package·--add=aide
 207 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 208 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 209 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 210 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 211 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 212 dnf·install·aide
215 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*213 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
216 Run·the·following·command·to·generate·a·new·database:214 Run·the·following·command·to·generate·a·new·database:
217 $·sudo·/usr/sbin/aide·--init215 $·sudo·/usr/sbin/aide·--init
218 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:216 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
219 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz217 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
220 To·initiate·a·manual·check,·run·the·following·command:218 To·initiate·a·manual·check,·run·the·following·command:
221 $·sudo·/usr/sbin/aide·--check219 $·sudo·/usr/sbin/aide·--check
Offset 844, 26 lines modifiedOffset 844, 26 lines modified
844 If·a·system·has·already·been·installed,·and·the·default·partitioning·scheme·was·used,·it·is·possible·but·nontrivial·to·modify·it·to·create·separate·logical·volumes·for·the·directories·listed·above.·The·Logical·Volume·Manager·(LVM)·makes·this·possible.844 If·a·system·has·already·been·installed,·and·the·default·partitioning·scheme·was·used,·it·is·possible·but·nontrivial·to·modify·it·to·create·separate·logical·volumes·for·the·directories·listed·above.·The·Logical·Volume·Manager·(LVM)·makes·this·possible.
845 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/b\x8bo\x8oo\x8ot\x8t·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*845 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/b\x8bo\x8oo\x8ot\x8t·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
846 It·is·recommended·that·the·/boot·directory·resides·on·a·separate·partition.·This·makes·it·easier·to·apply·restrictions·e.g.·through·the·noexec·mount·option.·Eventually,·the·/boot·partition·can·be·configured·not·to·be·mounted·automatically·with·the·noauto·mount·option.846 It·is·recommended·that·the·/boot·directory·resides·on·a·separate·partition.·This·makes·it·easier·to·apply·restrictions·e.g.·through·the·noexec·mount·option.·Eventually,·the·/boot·partition·can·be·configured·not·to·be·mounted·automatically·with·the·noauto·mount·option.
847 Rationale:··The·/boot·partition·contains·the·kernel·and·bootloader·files.·Access·to·this·partition·should·be·restricted.847 Rationale:··The·/boot·partition·contains·the·kernel·and·bootloader·files.·Access·to·this·partition·should·be·restricted.
848 Severity: ··medium848 Severity: ··medium
849 Rule·ID:····xccdf_org.ssgproject.content_rule_partition_for_boot849 Rule·ID:····xccdf_org.ssgproject.content_rule_partition_for_boot
850 References:·_\x8a_\x8n_\x8s_\x8s_\x8i·R28850 References:·_\x8a_\x8n_\x8s_\x8s_\x8i·R28
 851 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 852 [[customizations.filesystem]]
 853 mountpoint·=·"/boot"
 854 size·=·1073741824
851 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8855 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
852 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low856 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
853 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high857 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high
854 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false858 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
855 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable859 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
856 part·/boot860 part·/boot
857 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
858 [[customizations.filesystem]] 
859 mountpoint·=·"/boot" 
860 size·=·1073741824 
861 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/h\x8ho\x8om\x8me\x8e·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*861 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/h\x8ho\x8om\x8me\x8e·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
862 If·user·home·directories·will·be·stored·locally,·create·a·separate·partition·for·/home·at·installation·time·(or·migrate·it·later·using·LVM).·If·/home·will·be·mounted·from·another·system·such·as·an·NFS·server,·then·creating·a·separate·partition·is·not·necessary·at·installation·time,·and·the·mountpoint·can·instead·be·configured·later.862 If·user·home·directories·will·be·stored·locally,·create·a·separate·partition·for·/home·at·installation·time·(or·migrate·it·later·using·LVM).·If·/home·will·be·mounted·from·another·system·such·as·an·NFS·server,·then·creating·a·separate·partition·is·not·necessary·at·installation·time,·and·the·mountpoint·can·instead·be·configured·later.
863 Rationale:··Ensuring·that·/home·is·mounted·on·its·own·partition·enables·the·setting·of·more·restrictive·mount·options,·and·also·helps·ensure·that·users·cannot·trivially·fill·partitions·used·for·log·or·audit·data·storage.863 Rationale:··Ensuring·that·/home·is·mounted·on·its·own·partition·enables·the·setting·of·more·restrictive·mount·options,·and·also·helps·ensure·that·users·cannot·trivially·fill·partitions·used·for·log·or·audit·data·storage.
864 Severity: ··low864 Severity: ··low
865 Rule·ID:····xccdf_org.ssgproject.content_rule_partition_for_home865 Rule·ID:····xccdf_org.ssgproject.content_rule_partition_for_home
866 ············_\x8c_\x8i_\x8s_\x8-_\x8c_\x8s_\x8c········12,·15,·8866 ············_\x8c_\x8i_\x8s_\x8-_\x8c_\x8s_\x8c········12,·15,·8
867 ············_\x8c_\x8o_\x8b_\x8i_\x8t_\x85·········APO13.01,·DSS05.02867 ············_\x8c_\x8o_\x8b_\x8i_\x8t_\x85·········APO13.01,·DSS05.02
Offset 871, 92 lines modifiedOffset 871, 92 lines modified
871 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.5,·SR·3.8,·SR·4.1,·SR·4.3,·SR·5.1,·SR·5.2,·SR·5.3,·SR·7.1,·SR·7.6871 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.5,·SR·3.8,·SR·4.1,·SR·4.3,·SR·5.1,·SR·5.2,·SR·5.3,·SR·7.1,·SR·7.6
872 References:·_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.3872 References:·_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.3
873 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)873 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)
874 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4874 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4
875 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227875 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
876 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R28876 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R28
Max diff block lines reached; 106570/112991 bytes (94.32%) of diff not shown.
866 KB
./usr/share/doc/ssg-nondebian/ssg-cs10-guide-anssi_bp28_intermediary.html
    
Offset 15246, 207 lines modifiedOffset 15246, 207 lines modified
0003b8d0:·7267·6574·3d22·2369·646d·3733·3332·2220··rget="#idm7332"·0003b8d0:·7267·6574·3d22·2369·646d·3733·3332·2220··rget="#idm7332"·
0003b8e0:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol0003b8e0:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol
0003b8f0:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-0003b8f0:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-
0003b900:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"0003b900:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"
0003b910:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate0003b910:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate
0003b920:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href0003b920:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href
0003b930:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio0003b930:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio
 0003b940:·6e20·4f53·4275·696c·6420·426c·7565·7072··n·OSBuild·Bluepr
 0003b950:·696e·7420·736e·6970·7065·7420·e287·b23c··int·snippet·...<
 0003b960:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas
 0003b970:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps
 0003b980:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="
 0003b990:·6964·6d37·3333·3222·3e3c·7072·653e·3c63··idm7332"><pre><c
 0003b9a0:·6f64·653e·0a5b·5b70·6163·6b61·6765·735d··ode>.[[packages]
 0003b9b0:·5d0a·6e61·6d65·203d·2022·6169·6465·220a··].name·=·"aide".
 0003b9c0:·7665·7273·696f·6e20·3d20·222a·220a·3c2f··version·=·"*".</
0003b940:·6e20·7363·7269·7074·20e2·87b2·3c2f·613e··n·script·...</a> 
0003b950:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class=" 
0003b960:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c 
0003b970:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm 
0003b980:·3733·3332·223e·3c74·6162·6c65·2063·6c61··7332"><table·cla 
0003b990:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table- 
0003b9a0:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo 
0003b9b0:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con 
0003b9c0:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th> 
0003b9d0:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th> 
0003b9e0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
0003b9f0:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt 
0003ba00:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low 
0003ba10:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
0003ba20:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t 
0003ba30:·643e·6661·6c73·653c·2f74·643e·3c2f·7472··d>false</td></tr 
0003ba40:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg 
0003ba50:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl 
0003ba60:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab 
0003ba70:·6c65·3e3c·7072·653e·3c63·6f64·653e·0a64··le><pre><code>.d 
0003ba80:·6e66·2069·6e73·7461·6c6c·2061·6964·650a··nf·install·aide. 
0003ba90:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d0003b9d0:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div
0003baa0:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn0003b9e0:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b
0003bab0:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da0003b9f0:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data
0003bac0:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla0003ba00:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps
0003bad0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target0003ba10:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
0003bae0:·3d22·2369·646d·3733·3333·2220·7461·6269··="#idm7333"·tabi0003ba20:·2369·646d·3733·3333·2220·7461·6269·6e64··#idm7333"·tabind
0003baf0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b0003ba30:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
0003bb00:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa0003ba40:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
0003bb10:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit0003ba50:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
0003bb20:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·0003ba60:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
0003bb30:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!0003ba70:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
0003bb40:·223e·5265·6d65·6469·6174·696f·6e20·416e··">Remediation·An0003ba80:·5265·6d65·6469·6174·696f·6e20·5075·7070··Remediation·Pupp
0003bb50:·6163·6f6e·6461·2073·6e69·7070·6574·20e2··aconda·snippet·.0003ba90:·6574·2073·6e69·7070·6574·20e2·87b2·3c2f··et·snippet·...</
0003bb60:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c0003baa0:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
0003bb70:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll0003bab0:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
0003bb80:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i0003bac0:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
0003bb90:·643d·2269·646d·3733·3333·223e·3c74·6162··d="idm7333"><tab0003bad0:·646d·3733·3333·223e·3c74·6162·6c65·2063··dm7333"><table·c
0003bba0:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·0003bae0:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl
0003bbb0:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta0003baf0:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-
0003bbc0:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab0003bb00:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c
0003bbd0:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t0003bb10:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t
0003bbe0:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity0003bb20:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t
0003bbf0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t0003bb30:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
0003bc00:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D0003bb40:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru
0003bc10:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><0003bb50:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l
 0003bb60:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
 0003bb70:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th>
 0003bb80:·3c74·643e·6661·6c73·653c·2f74·643e·3c2f··<td>false</td></
 0003bb90:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat
 0003bba0:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena
 0003bbb0:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t
 0003bbc0:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>
 0003bbd0:·696e·636c·7564·6520·696e·7374·616c·6c5f··include·install_
 0003bbe0:·6169·6465·0a0a·636c·6173·7320·696e·7374··aide..class·inst
 0003bbf0:·616c·6c5f·6169·6465·207b·0a20·2070·6163··all_aide·{.··pac
 0003bc00:·6b61·6765·207b·2027·6169·6465·273a·0a20··kage·{·'aide':.·
 0003bc10:·2020·2065·6e73·7572·6520·3d26·6774·3b20·····ensure·=&gt;·
 0003bc20:·2769·6e73·7461·6c6c·6564·272c·0a20·207d··'installed',.··}
 0003bc30:·0a7d·0a3c·2f63·6f64·653e·3c2f·7072·653e··.}.</code></pre>
 0003bc40:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class="
 0003bc50:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success"
 0003bc60:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co
 0003bc70:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar
 0003bc80:·6765·743d·2223·6964·6d37·3333·3422·2074··get="#idm7334"·t
 0003bc90:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
 0003bca0:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
 0003bcb0:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
 0003bcc0:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
 0003bcd0:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
 0003bce0:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
 0003bcf0:·2073·6372·6970·7420·e287·b23c·2f61·3e3c···script·...</a><
 0003bd00:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
 0003bd10:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
 0003bd20:·6c6c·6170·7365·2220·6964·3d22·6964·6d37··llapse"·id="idm7
 0003bd30:·3333·3422·3e3c·7461·626c·6520·636c·6173··334"><table·clas
 0003bd40:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s
 0003bd50:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor
 0003bd60:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond
 0003bd70:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C
 0003bd80:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><
0003bc20:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>0003bd90:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
0003bc30:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:< 
0003bc40:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t0003bda0:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti
 0003bdb0:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<
0003bc50:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S0003bdc0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
0003bc60:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td 
0003bc70:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr 
0003bc80:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c 
0003bc90:·6f64·653e·0a70·6163·6b61·6765·202d·2d61··ode>.package·--a 
0003bca0:·6464·3d61·6964·650a·3c2f·636f·6465·3e3c··dd=aide.</code>< 
0003bcb0:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl 
0003bcc0:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc 
0003bcd0:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl 
0003bce0:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat 
0003bcf0:·612d·7461·7267·6574·3d22·2369·646d·3733··a-target="#idm73 
0003bd00:·3334·2220·7461·6269·6e64·6578·3d22·3022··34"·tabindex="0" 
0003bd10:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a 
0003bd20:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa 
0003bd30:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti 
0003bd40:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"· 
0003bd50:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi 
0003bd60:·6174·696f·6e20·4f53·4275·696c·6420·426c··ation·OSBuild·Bl 
0003bd70:·7565·7072·696e·7420·736e·6970·7065·7420··ueprint·snippet·0003bdd0:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td
 0003bde0:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr>
 0003bdf0:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy
 0003be00:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable
 0003be10:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl
 0003be20:·653e·3c70·7265·3e3c·636f·6465·3e0a·7061··e><pre><code>.pa
 0003be30:·636b·6167·6520·696e·7374·616c·6c20·6169··ckage·install·ai
 0003be40:·6465·0a3c·2f63·6f64·653e·3c2f·7072·653e··de.</code></pre>
Max diff block lines reached; 780887/808101 bytes (96.63%) of diff not shown.
76.5 KB
html2text {}
    
Offset 171, 52 lines modifiedOffset 171, 38 lines modified
171 ··-·PCI-DSSv4-11.5.2171 ··-·PCI-DSSv4-11.5.2
172 ··-·enable_strategy172 ··-·enable_strategy
173 ··-·low_complexity173 ··-·low_complexity
174 ··-·low_disruption174 ··-·low_disruption
175 ··-·medium_severity175 ··-·medium_severity
176 ··-·no_reboot_needed176 ··-·no_reboot_needed
177 ··-·package_aide_installed177 ··-·package_aide_installed
178 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
179 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
180 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
181 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
182 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
183 dnf·install·aide 
184 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
185 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
186 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
187 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
188 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
189 package·--add=aide 
190 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8178 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
191 [[packages]]179 [[packages]]
192 name·=·"aide"180 name·=·"aide"
193 version·=·"*"181 version·=·"*"
194 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
195 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
196 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
197 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
198 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
199 package·install·aide 
200 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8182 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
201 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low183 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
202 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low184 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
203 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false185 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
204 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable186 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
205 include·install_aide187 include·install_aide
  
206 class·install_aide·{188 class·install_aide·{
207 ··package·{·'aide':189 ··package·{·'aide':
208 ····ensure·=>·'installed',190 ····ensure·=>·'installed',
209 ··}191 ··}
210 }192 }
 193 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 194 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 195 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 196 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 197 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 198 package·install·aide
211 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8199 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
212 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low200 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
213 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low201 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
214 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false202 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
215 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable203 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
216 #·Remediation·is·applicable·only·in·certain·platforms204 #·Remediation·is·applicable·only·in·certain·platforms
217 if·rpm·--quiet·-q·kernel;·then205 if·rpm·--quiet·-q·kernel;·then
Offset 224, 14 lines modifiedOffset 210, 28 lines modified
224 if·!·rpm·-q·--quiet·"aide"·;·then210 if·!·rpm·-q·--quiet·"aide"·;·then
225 ····dnf·install·-y·"aide"211 ····dnf·install·-y·"aide"
226 fi212 fi
  
227 else213 else
228 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'214 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
229 fi215 fi
 216 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 217 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 218 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 219 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 220 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 221 package·--add=aide
 222 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 223 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 224 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 225 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 226 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 227 dnf·install·aide
230 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*228 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
231 Run·the·following·command·to·generate·a·new·database:229 Run·the·following·command·to·generate·a·new·database:
232 $·sudo·/usr/sbin/aide·--init230 $·sudo·/usr/sbin/aide·--init
233 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the231 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the
234 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these232 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these
235 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their233 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their
236 integrity.·The·newly-generated·database·can·be·installed·as·follows:234 integrity.·The·newly-generated·database·can·be·installed·as·follows:
Offset 386, 26 lines modifiedOffset 386, 26 lines modified
386 apply·restrictions·e.g.·through·the·noexec·mount·option.·Eventually,·the·/boot·partition·can·be386 apply·restrictions·e.g.·through·the·noexec·mount·option.·Eventually,·the·/boot·partition·can·be
387 configured·not·to·be·mounted·automatically·with·the·noauto·mount·option.387 configured·not·to·be·mounted·automatically·with·the·noauto·mount·option.
388 Rationale:··The·/boot·partition·contains·the·kernel·and·bootloader·files.·Access·to·this·partition388 Rationale:··The·/boot·partition·contains·the·kernel·and·bootloader·files.·Access·to·this·partition
389 ············should·be·restricted.389 ············should·be·restricted.
390 Severity: ··medium390 Severity: ··medium
391 Rule·ID:····xccdf_org.ssgproject.content_rule_partition_for_boot391 Rule·ID:····xccdf_org.ssgproject.content_rule_partition_for_boot
392 References:·_\x8a_\x8n_\x8s_\x8s_\x8i·R28392 References:·_\x8a_\x8n_\x8s_\x8s_\x8i·R28
 393 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 394 [[customizations.filesystem]]
 395 mountpoint·=·"/boot"
 396 size·=·1073741824
393 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8397 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
394 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low398 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
395 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high399 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high
396 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false400 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
397 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable401 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
398 part·/boot402 part·/boot
399 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
400 [[customizations.filesystem]] 
401 mountpoint·=·"/boot" 
402 size·=·1073741824 
403 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/h\x8ho\x8om\x8me\x8e·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*403 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/h\x8ho\x8om\x8me\x8e·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
404 If·user·home·directories·will·be·stored·locally,·create·a·separate·partition·for·/home·at404 If·user·home·directories·will·be·stored·locally,·create·a·separate·partition·for·/home·at
405 installation·time·(or·migrate·it·later·using·LVM).·If·/home·will·be·mounted·from·another·system·such405 installation·time·(or·migrate·it·later·using·LVM).·If·/home·will·be·mounted·from·another·system·such
406 as·an·NFS·server,·then·creating·a·separate·partition·is·not·necessary·at·installation·time,·and·the406 as·an·NFS·server,·then·creating·a·separate·partition·is·not·necessary·at·installation·time,·and·the
407 mountpoint·can·instead·be·configured·later.407 mountpoint·can·instead·be·configured·later.
408 ············Ensuring·that·/home·is·mounted·on·its·own·partition·enables·the·setting·of·more408 ············Ensuring·that·/home·is·mounted·on·its·own·partition·enables·the·setting·of·more
409 Rationale:··restrictive·mount·options,·and·also·helps·ensure·that·users·cannot·trivially·fill409 Rationale:··restrictive·mount·options,·and·also·helps·ensure·that·users·cannot·trivially·fill
Offset 419, 102 lines modifiedOffset 419, 102 lines modified
419 ···························7.6419 ···························7.6
420 References:·_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.3420 References:·_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.3
421 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)421 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)
422 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4422 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4
423 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227423 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
424 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R28424 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R28
Max diff block lines reached; 72892/78310 bytes (93.08%) of diff not shown.
173 KB
./usr/share/doc/ssg-nondebian/ssg-cs10-guide-anssi_bp28_minimal.html
    
Offset 14928, 222 lines modifiedOffset 14928, 222 lines modified
0003a4f0:·7461·2d74·6172·6765·743d·2223·6964·6d31··ta-target="#idm10003a4f0:·7461·2d74·6172·6765·743d·2223·6964·6d31··ta-target="#idm1
0003a500:·3035·3433·2220·7461·6269·6e64·6578·3d22··0543"·tabindex="0003a500:·3035·3433·2220·7461·6269·6e64·6578·3d22··0543"·tabindex="
0003a510:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"0003a510:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
0003a520:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="0003a520:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
0003a530:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac0003a530:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
0003a540:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal0003a540:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
0003a550:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme0003a550:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
0003a560:·6469·6174·696f·6e20·7363·7269·7074·20e2··diation·script·.0003a560:·6469·6174·696f·6e20·4f53·4275·696c·6420··diation·OSBuild·
0003a570:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c 
0003a580:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll 
0003a590:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i0003a570:·426c·7565·7072·696e·7420·736e·6970·7065··Blueprint·snippe
 0003a580:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di
 0003a590:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c
 0003a5a0:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse
 0003a5b0:·2220·6964·3d22·6964·6d31·3035·3433·223e··"·id="idm10543">
 0003a5c0:·3c70·7265·3e3c·636f·6465·3e0a·5b5b·7061··<pre><code>.[[pa
 0003a5d0:·636b·6167·6573·5d5d·0a6e·616d·6520·3d20··ckages]].name·=·
 0003a5e0:·2264·6e66·2d61·7574·6f6d·6174·6963·220a··"dnf-automatic".
 0003a5f0:·7665·7273·696f·6e20·3d20·222a·220a·3c2f··version·=·"*".</
 0003a600:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div
 0003a610:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b
 0003a620:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data
 0003a630:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps
 0003a640:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
 0003a650:·2369·646d·3130·3534·3422·2074·6162·696e··#idm10544"·tabin
 0003a660:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
 0003a670:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
 0003a680:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
 0003a690:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
 0003a6a0:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
 0003a6b0:·3e52·656d·6564·6961·7469·6f6e·2050·7570··>Remediation·Pup
 0003a6c0:·7065·7420·736e·6970·7065·7420·e287·b23c··pet·snippet·...<
 0003a6d0:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas
 0003a6e0:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps
 0003a6f0:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="
 0003a700:·6964·6d31·3035·3434·223e·3c74·6162·6c65··idm10544"><table
 0003a710:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta
 0003a720:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl
 0003a730:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table
 0003a740:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>
 0003a750:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<
 0003a760:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
 0003a770:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis
 0003a780:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td
 0003a790:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
 0003a7a0:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t
 0003a7b0:·683e·3c74·643e·6661·6c73·653c·2f74·643e··h><td>false</td>
 0003a7c0:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str
 0003a7d0:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e
 0003a7e0:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr><
 0003a7f0:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod
 0003a800:·653e·696e·636c·7564·6520·696e·7374·616c··e>include·instal
 0003a810:·6c5f·646e·662d·6175·746f·6d61·7469·630a··l_dnf-automatic.
 0003a820:·0a63·6c61·7373·2069·6e73·7461·6c6c·5f64··.class·install_d
 0003a830:·6e66·2d61·7574·6f6d·6174·6963·207b·0a20··nf-automatic·{.·
 0003a840:·2070·6163·6b61·6765·207b·2027·646e·662d···package·{·'dnf-
 0003a850:·6175·746f·6d61·7469·6327·3a0a·2020·2020··automatic':.····
 0003a860:·656e·7375·7265·203d·2667·743b·2027·696e··ensure·=&gt;·'in
 0003a870:·7374·616c·6c65·6427·2c0a·2020·7d0a·7d0a··stalled',.··}.}.
 0003a880:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d
 0003a890:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn
 0003a8a0:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da
 0003a8b0:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla
 0003a8c0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
0003a5a0:·643d·2269·646d·3130·3534·3322·3e3c·7461··d="idm10543"><ta0003a8d0:·3d22·2369·646d·3130·3534·3522·2074·6162··="#idm10545"·tab
0003a5b0:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table 
0003a5c0:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t 
0003a5d0:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta 
0003a5e0:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed">< 
0003a5f0:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit0003a8e0:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
 0003a8f0:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
 0003a900:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
 0003a910:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
 0003a920:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
 0003a930:·2122·3e52·656d·6564·6961·7469·6f6e·2073··!">Remediation·s
 0003a940:·6372·6970·7420·e287·b23c·2f61·3e3c·6272··cript·...</a><br
 0003a950:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
 0003a960:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
 0003a970:·6170·7365·2220·6964·3d22·6964·6d31·3035··apse"·id="idm105
 0003a980:·3435·223e·3c74·6162·6c65·2063·6c61·7373··45"><table·class
 0003a990:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st
 0003a9a0:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord
 0003a9b0:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde
 0003a9c0:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co
 0003a9d0:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t
 0003a9e0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
 0003a9f0:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio
0003a600:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</0003aa00:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</
0003a610:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>0003aa10:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
0003a620:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th> 
0003a630:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
0003a640:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot:0003aa20:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td>
 0003aa30:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr><
 0003aa40:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:
0003a650:·3c2f·7468·3e3c·7464·3e66·616c·7365·3c2f··</th><td>false</0003aa50:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<
 0003aa60:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table
 0003aa70:·3e3c·7072·653e·3c63·6f64·653e·0a70·6163··><pre><code>.pac
 0003aa80:·6b61·6765·2069·6e73·7461·6c6c·2064·6e66··kage·install·dnf
 0003aa90:·2d61·7574·6f6d·6174·6963·0a3c·2f63·6f64··-automatic.</cod
 0003aaa0:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a
 0003aab0:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn-
 0003aac0:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to
0003a660:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
0003a670:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t 
0003a680:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t 
0003a690:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre>< 
0003a6a0:·636f·6465·3e0a·646e·6620·696e·7374·616c··code>.dnf·instal 
0003a6b0:·6c20·646e·662d·6175·746f·6d61·7469·630a··l·dnf-automatic. 
0003a6c0:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d 
0003a6d0:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn 
0003a6e0:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da 
0003a6f0:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla 
0003a700:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target 
0003a710:·3d22·2369·646d·3130·3534·3422·2074·6162··="#idm10544"·tab 
0003a720:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role=" 
0003a730:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp 
0003a740:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti 
0003a750:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to 
0003a760:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="# 
0003a770:·2122·3e52·656d·6564·6961·7469·6f6e·2041··!">Remediation·A 
0003a780:·6e61·636f·6e64·6120·736e·6970·7065·7420··naconda·snippet· 
0003a790:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div· 
0003a7a0:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col 
0003a7b0:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·0003aad0:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"·
 0003aae0:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
 0003aaf0:·6d31·3035·3436·2220·7461·6269·6e64·6578··m10546"·tabindex
 0003ab00:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto
Max diff block lines reached; 128756/158040 bytes (81.47%) of diff not shown.
18.2 KB
html2text {}
    
Offset 132, 52 lines modifiedOffset 132, 38 lines modified
132 ··tags:132 ··tags:
133 ··-·enable_strategy133 ··-·enable_strategy
134 ··-·low_complexity134 ··-·low_complexity
135 ··-·low_disruption135 ··-·low_disruption
136 ··-·medium_severity136 ··-·medium_severity
137 ··-·no_reboot_needed137 ··-·no_reboot_needed
138 ··-·package_dnf-automatic_installed138 ··-·package_dnf-automatic_installed
139 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
140 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
141 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
142 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
143 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
144 dnf·install·dnf-automatic 
145 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
146 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
147 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
148 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
149 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
150 package·--add=dnf-automatic 
151 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8139 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
152 [[packages]]140 [[packages]]
153 name·=·"dnf-automatic"141 name·=·"dnf-automatic"
154 version·=·"*"142 version·=·"*"
155 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
156 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
157 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
158 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
159 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
160 package·install·dnf-automatic 
161 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8143 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
162 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low144 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
163 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low145 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
164 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false146 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
165 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable147 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
166 include·install_dnf-automatic148 include·install_dnf-automatic
  
167 class·install_dnf-automatic·{149 class·install_dnf-automatic·{
168 ··package·{·'dnf-automatic':150 ··package·{·'dnf-automatic':
169 ····ensure·=>·'installed',151 ····ensure·=>·'installed',
170 ··}152 ··}
171 }153 }
 154 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 155 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 156 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 157 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 158 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 159 package·install·dnf-automatic
172 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8160 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
173 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low161 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
174 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low162 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
175 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false163 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
176 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable164 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
177 #·Remediation·is·applicable·only·in·certain·platforms165 #·Remediation·is·applicable·only·in·certain·platforms
178 if·!·(·{·rpm·--quiet·-q·kernel·;}·&&·{·rpm·--quiet·-q·rpm-ostree·;}·&&·{·rpm·--quiet·-166 if·!·(·{·rpm·--quiet·-q·kernel·;}·&&·{·rpm·--quiet·-q·rpm-ostree·;}·&&·{·rpm·--quiet·-
Offset 186, 14 lines modifiedOffset 172, 28 lines modified
186 if·!·rpm·-q·--quiet·"dnf-automatic"·;·then172 if·!·rpm·-q·--quiet·"dnf-automatic"·;·then
187 ····dnf·install·-y·"dnf-automatic"173 ····dnf·install·-y·"dnf-automatic"
188 fi174 fi
  
189 else175 else
190 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'176 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
191 fi177 fi
 178 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 179 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 180 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 181 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 182 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 183 package·--add=dnf-automatic
 184 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 185 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 186 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 187 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 188 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 189 dnf·install·dnf-automatic
192 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·d\x8dn\x8nf\x8f-\x8-a\x8au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8c·t\x8to\x8o·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·A\x8Av\x8va\x8ai\x8il\x8la\x8ab\x8bl\x8le\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8es\x8s·A\x8Au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8ca\x8al\x8ll\x8ly\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*190 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·d\x8dn\x8nf\x8f-\x8-a\x8au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8c·t\x8to\x8o·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·A\x8Av\x8va\x8ai\x8il\x8la\x8ab\x8bl\x8le\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8es\x8s·A\x8Au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8ca\x8al\x8ll\x8ly\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
193 To·ensure·that·the·packages·comprising·the·available·updates·will·be·automatically·installed191 To·ensure·that·the·packages·comprising·the·available·updates·will·be·automatically·installed
194 by·dnf-automatic,·set·apply_updates·to·yes·under·[commands]·section·in·/etc/dnf/192 by·dnf-automatic,·set·apply_updates·to·yes·under·[commands]·section·in·/etc/dnf/
195 automatic.conf.193 automatic.conf.
196 ············Installing·software·updates·is·a·fundamental·mitigation·against·the·exploitation194 ············Installing·software·updates·is·a·fundamental·mitigation·against·the·exploitation
197 ············of·publicly-known·vulnerabilities.·If·the·most·recent·security·patches·and195 ············of·publicly-known·vulnerabilities.·If·the·most·recent·security·patches·and
198 Rationale:··updates·are·not·installed,·unauthorized·users·may·take·advantage·of·weaknesses·in196 Rationale:··updates·are·not·installed,·unauthorized·users·may·take·advantage·of·weaknesses·in
Offset 9289, 47 lines modifiedOffset 9289, 33 lines modified
9289 ··tags:9289 ··tags:
9290 ··-·disable_strategy9290 ··-·disable_strategy
9291 ··-·low_complexity9291 ··-·low_complexity
9292 ··-·low_disruption9292 ··-·low_disruption
9293 ··-·medium_severity9293 ··-·medium_severity
9294 ··-·no_reboot_needed9294 ··-·no_reboot_needed
9295 ··-·package_kea_removed9295 ··-·package_kea_removed
9296 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
9297 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
9298 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
9299 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
9300 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable 
  
9301 dnf·remove·kea 
9302 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
9303 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
9304 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
9305 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
9306 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable 
  
9307 package·--remove=kea 
9308 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
9309 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
9310 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
9311 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
9312 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable 
  
9313 package·remove·kea 
9314 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x89296 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
9315 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low9297 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
9316 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low9298 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
9317 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false9299 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
9318 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable9300 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
9319 include·remove_kea9301 include·remove_kea
  
9320 class·remove_kea·{9302 class·remove_kea·{
9321 ··package·{·'kea':9303 ··package·{·'kea':
9322 ····ensure·=>·'purged',9304 ····ensure·=>·'purged',
Max diff block lines reached; 13931/18658 bytes (74.67%) of diff not shown.
1.64 MB
./usr/share/doc/ssg-nondebian/ssg-cs10-guide-cis.html
    
Offset 15296, 208 lines modifiedOffset 15296, 208 lines modified
0003bbf0:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="0003bbf0:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
0003bc00:·2369·646d·3733·3332·2220·7461·6269·6e64··#idm7332"·tabind0003bc00:·2369·646d·3733·3332·2220·7461·6269·6e64··#idm7332"·tabind
0003bc10:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but0003bc10:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
0003bc20:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand0003bc20:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
0003bc30:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title0003bc30:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
0003bc40:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re0003bc40:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
0003bc50:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">0003bc50:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
0003bc60:·5265·6d65·6469·6174·696f·6e20·7363·7269··Remediation·scri0003bc60:·5265·6d65·6469·6174·696f·6e20·4f53·4275··Remediation·OSBu
 0003bc70:·696c·6420·426c·7565·7072·696e·7420·736e··ild·Blueprint·sn
 0003bc80:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br
 0003bc90:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
 0003bca0:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
 0003bcb0:·6170·7365·2220·6964·3d22·6964·6d37·3333··apse"·id="idm733
 0003bcc0:·3222·3e3c·7072·653e·3c63·6f64·653e·0a5b··2"><pre><code>.[
 0003bcd0:·5b70·6163·6b61·6765·735d·5d0a·6e61·6d65··[packages]].name
 0003bce0:·203d·2022·6169·6465·220a·7665·7273·696f···=·"aide".versio
 0003bcf0:·6e20·3d20·222a·220a·3c2f·636f·6465·3e3c··n·=·"*".</code><
0003bc70:·7074·20e2·87b2·3c2f·613e·3c62·723e·3c64··pt·...</a><br><d 
0003bc80:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel- 
0003bc90:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps 
0003bca0:·6522·2069·643d·2269·646d·3733·3332·223e··e"·id="idm7332"> 
0003bcb0:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta 
0003bcc0:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe 
0003bcd0:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered 
0003bce0:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed 
0003bcf0:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple 
0003bd00:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo 
0003bd10:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr>< 
0003bd20:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</ 
0003bd30:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td>< 
0003bd40:·2f74·723e·3c74·723e·3c74·683e·5265·626f··/tr><tr><th>Rebo 
0003bd50:·6f74·3a3c·2f74·683e·3c74·643e·6661·6c73··ot:</th><td>fals 
0003bd60:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr>< 
0003bd70:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th 
0003bd80:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td> 
0003bd90:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr 
0003bda0:·653e·3c63·6f64·653e·0a64·6e66·2069·6e73··e><code>.dnf·ins 
0003bdb0:·7461·6c6c·2061·6964·650a·3c2f·636f·6465··tall·aide.</code 
0003bdc0:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a·0003bd00:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl
0003bdd0:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s0003bd10:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc
0003bde0:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog0003bd20:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl
0003bdf0:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d0003bd30:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat
0003be00:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm0003bd40:·612d·7461·7267·6574·3d22·2369·646d·3733··a-target="#idm73
0003be10:·3733·3333·2220·7461·6269·6e64·6578·3d22··7333"·tabindex="0003bd50:·3333·2220·7461·6269·6e64·6578·3d22·3022··33"·tabindex="0"
0003be20:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"0003bd60:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
0003be30:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="0003bd70:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
0003be40:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac0003bd80:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
0003be50:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal0003bd90:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
0003be60:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme0003bda0:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
0003be70:·6469·6174·696f·6e20·416e·6163·6f6e·6461··diation·Anaconda0003bdb0:·6174·696f·6e20·5075·7070·6574·2073·6e69··ation·Puppet·sni
0003be80:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>0003bdc0:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>
0003be90:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="0003bdd0:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
0003bea0:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c0003bde0:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
0003beb0:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm0003bdf0:·7073·6522·2069·643d·2269·646d·3733·3333··pse"·id="idm7333
0003bec0:·3733·3333·223e·3c74·6162·6c65·2063·6c61··7333"><table·cla0003be00:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="
0003bed0:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-0003be10:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri
0003bee0:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo0003be20:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border
0003bef0:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con0003be30:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens
0003bf00:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>0003be40:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp
0003bf10:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>0003be50:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>
0003bf20:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr0003be60:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
0003bf30:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt0003be70:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:
0003bf40:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low0003be80:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
0003bf50:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t0003be90:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re
0003bf60:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t0003bea0:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa
0003bf70:·643e·6661·6c73·653c·2f74·643e·3c2f·7472··d>false</td></tr 
0003bf80:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg 
0003bf90:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl 
0003bfa0:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab0003beb0:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr
0003bfb0:·6c65·3e3c·7072·653e·3c63·6f64·653e·0a70··le><pre><code>.p 
0003bfc0:·6163·6b61·6765·202d·2d61·6464·3d61·6964··ackage·--add=aid 
0003bfd0:·650a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··e.</code></pre>< 
0003bfe0:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b 
0003bff0:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"· 
0003c000:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col 
0003c010:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ 
0003c020:·6574·3d22·2369·646d·3733·3334·2220·7461··et="#idm7334"·ta 
0003c030:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role= 
0003c040:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex 
0003c050:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t 
0003c060:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t 
0003c070:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href=" 
0003c080:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation· 
0003c090:·4f53·4275·696c·6420·426c·7565·7072·696e··OSBuild·Blueprin 
0003c0a0:·7420·736e·6970·7065·7420·e287·b23c·2f61··t·snippet·...</a 
0003c0b0:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class= 
0003c0c0:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse· 
0003c0d0:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id 
0003c0e0:·6d37·3333·3422·3e3c·7072·653e·3c63·6f64··m7334"><pre><cod 
0003c0f0:·653e·0a5b·5b70·6163·6b61·6765·735d·5d0a··e>.[[packages]]. 
0003c100:·6e61·6d65·203d·2022·6169·6465·220a·7665··name·=·"aide".ve 
0003c110:·7273·696f·6e20·3d20·222a·220a·3c2f·636f··rsion·=·"*".</co 
0003c120:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div>< 
0003c130:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn 
0003c140:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t 
0003c150:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse" 
0003c160:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i 
0003c170:·646d·3733·3335·2220·7461·6269·6e64·6578··dm7335"·tabindex 
0003c180:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto 
0003c190:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded 
0003c1a0:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title=" 
0003c1b0:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve 
0003c1c0:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re 
0003c1d0:·6d65·6469·6174·696f·6e20·7363·7269·7074··mediation·script 
0003c1e0:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div 
0003c1f0:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co 
0003c200:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse" 
0003c210:·2069·643d·2269·646d·3733·3335·223e·3c74···id="idm7335"><t 
0003c220:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl 
0003c230:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped· 
0003c240:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t 
0003c250:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed"> 
0003c260:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi 
0003c270:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low< 
0003c280:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0003c290:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th 
0003c2a0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t 
0003c2b0:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot 
0003c2c0:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false< 
0003c2d0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0003c2e0:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><0003bec0:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</
0003c2f0:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></ 
0003c300:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre> 
0003c310:·3c63·6f64·653e·0a70·6163·6b61·6765·2069··<code>.package·i 
0003c320:·6e73·7461·6c6c·2061·6964·650a·3c2f·636f··nstall·aide.</co 
0003c330:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div>< 
0003c340:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn 
Max diff block lines reached; 1509772/1537124 bytes (98.22%) of diff not shown.
175 KB
html2text {}
    
Offset 162, 52 lines modifiedOffset 162, 38 lines modified
162 ··-·PCI-DSSv4-11.5.2162 ··-·PCI-DSSv4-11.5.2
163 ··-·enable_strategy163 ··-·enable_strategy
164 ··-·low_complexity164 ··-·low_complexity
165 ··-·low_disruption165 ··-·low_disruption
166 ··-·medium_severity166 ··-·medium_severity
167 ··-·no_reboot_needed167 ··-·no_reboot_needed
168 ··-·package_aide_installed168 ··-·package_aide_installed
169 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
170 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
171 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
172 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
173 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
174 dnf·install·aide 
175 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
176 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
177 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
178 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
179 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
180 package·--add=aide 
181 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8169 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
182 [[packages]]170 [[packages]]
183 name·=·"aide"171 name·=·"aide"
184 version·=·"*"172 version·=·"*"
185 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
186 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
187 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
188 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
189 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
190 package·install·aide 
191 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8173 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
192 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low174 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
193 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low175 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
194 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false176 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
195 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable177 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
196 include·install_aide178 include·install_aide
  
197 class·install_aide·{179 class·install_aide·{
198 ··package·{·'aide':180 ··package·{·'aide':
199 ····ensure·=>·'installed',181 ····ensure·=>·'installed',
200 ··}182 ··}
201 }183 }
 184 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 185 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 186 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 187 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 188 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 189 package·install·aide
202 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8190 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
203 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low191 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
204 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low192 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
205 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false193 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
206 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable194 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
207 #·Remediation·is·applicable·only·in·certain·platforms195 #·Remediation·is·applicable·only·in·certain·platforms
208 if·rpm·--quiet·-q·kernel;·then196 if·rpm·--quiet·-q·kernel;·then
Offset 215, 14 lines modifiedOffset 201, 28 lines modified
215 if·!·rpm·-q·--quiet·"aide"·;·then201 if·!·rpm·-q·--quiet·"aide"·;·then
216 ····dnf·install·-y·"aide"202 ····dnf·install·-y·"aide"
217 fi203 fi
  
218 else204 else
219 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'205 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
220 fi206 fi
 207 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 208 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 209 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 210 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 211 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 212 package·--add=aide
 213 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 214 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 215 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 216 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 217 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 218 dnf·install·aide
221 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*219 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
222 Run·the·following·command·to·generate·a·new·database:220 Run·the·following·command·to·generate·a·new·database:
223 $·sudo·/usr/sbin/aide·--init221 $·sudo·/usr/sbin/aide·--init
224 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:222 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
225 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz223 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
226 To·initiate·a·manual·check,·run·the·following·command:224 To·initiate·a·manual·check,·run·the·following·command:
227 $·sudo·/usr/sbin/aide·--check225 $·sudo·/usr/sbin/aide·--check
Offset 888, 58 lines modifiedOffset 888, 58 lines modified
888 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.5,·SR·3.8,·SR·4.1,·SR·4.3,·SR·5.1,·SR·5.2,·SR·5.3,·SR·7.1,·SR·7.6888 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.5,·SR·3.8,·SR·4.1,·SR·4.3,·SR·5.1,·SR·5.2,·SR·5.3,·SR·7.1,·SR·7.6
889 References:·_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.3889 References:·_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.3
890 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)890 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)
891 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4891 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4
892 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227892 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
893 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R28893 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R28
894 ············_\x8c_\x8i_\x8s············1.1.2.3.1894 ············_\x8c_\x8i_\x8s············1.1.2.3.1
895 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
896 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
897 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high 
898 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
899 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
900 part·/home 
901 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8895 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
902 [[customizations.filesystem]]896 [[customizations.filesystem]]
903 mountpoint·=·"/home"897 mountpoint·=·"/home"
904 size·=·1073741824898 size·=·1073741824
905 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8899 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
906 logvol·/home·1024900 logvol·/home·1024
 901 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 902 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 903 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high
 904 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 905 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 906 part·/home
907 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/t\x8tm\x8mp\x8p·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*907 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/t\x8tm\x8mp\x8p·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
908 The·/tmp·directory·is·a·world-writable·directory·used·for·temporary·file·storage.·Ensure·it·has·its·own·partition·or·logical·volume·at·installation·time,·or·migrate·it·using·LVM.908 The·/tmp·directory·is·a·world-writable·directory·used·for·temporary·file·storage.·Ensure·it·has·its·own·partition·or·logical·volume·at·installation·time,·or·migrate·it·using·LVM.
909 Rationale:··The·/tmp·partition·is·used·as·temporary·storage·by·many·programs.·Placing·/tmp·in·its·own·partition·enables·the·setting·of·more·restrictive·mount·options,·which·can·help·protect·programs·which·use·it.909 Rationale:··The·/tmp·partition·is·used·as·temporary·storage·by·many·programs.·Placing·/tmp·in·its·own·partition·enables·the·setting·of·more·restrictive·mount·options,·which·can·help·protect·programs·which·use·it.
910 Severity: ··low910 Severity: ··low
911 Rule·ID:····xccdf_org.ssgproject.content_rule_partition_for_tmp911 Rule·ID:····xccdf_org.ssgproject.content_rule_partition_for_tmp
912 ············_\x8c_\x8i_\x8s_\x8-_\x8c_\x8s_\x8c········12,·15,·8912 ············_\x8c_\x8i_\x8s_\x8-_\x8c_\x8s_\x8c········12,·15,·8
913 ············_\x8c_\x8o_\x8b_\x8i_\x8t_\x85·········APO13.01,·DSS05.02913 ············_\x8c_\x8o_\x8b_\x8i_\x8t_\x85·········APO13.01,·DSS05.02
914 ············_\x8d_\x8i_\x8s_\x8a···········CCI-000366914 ············_\x8d_\x8i_\x8s_\x8a···········CCI-000366
915 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.5,·SR·3.8,·SR·4.1,·SR·4.3,·SR·5.1,·SR·5.2,·SR·5.3,·SR·7.1,·SR·7.6915 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.5,·SR·3.8,·SR·4.1,·SR·4.3,·SR·5.1,·SR·5.2,·SR·5.3,·SR·7.1,·SR·7.6
Max diff block lines reached; 173038/178727 bytes (96.82%) of diff not shown.
1.45 MB
./usr/share/doc/ssg-nondebian/ssg-cs10-guide-cis_server_l1.html
    
Offset 15258, 207 lines modifiedOffset 15258, 207 lines modified
0003b990:·7461·2d74·6172·6765·743d·2223·6964·6d37··ta-target="#idm70003b990:·7461·2d74·6172·6765·743d·2223·6964·6d37··ta-target="#idm7
0003b9a0:·3333·3222·2074·6162·696e·6465·783d·2230··332"·tabindex="00003b9a0:·3333·3222·2074·6162·696e·6465·783d·2230··332"·tabindex="0
0003b9b0:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·0003b9b0:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
0003b9c0:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f0003b9c0:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
0003b9d0:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act0003b9d0:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
0003b9e0:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"0003b9e0:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
0003b9f0:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed0003b9f0:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
 0003ba00:·6961·7469·6f6e·204f·5342·7569·6c64·2042··iation·OSBuild·B
 0003ba10:·6c75·6570·7269·6e74·2073·6e69·7070·6574··lueprint·snippet
 0003ba20:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
 0003ba30:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
 0003ba40:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
 0003ba50:·2069·643d·2269·646d·3733·3332·223e·3c70···id="idm7332"><p
 0003ba60:·7265·3e3c·636f·6465·3e0a·5b5b·7061·636b··re><code>.[[pack
 0003ba70:·6167·6573·5d5d·0a6e·616d·6520·3d20·2261··ages]].name·=·"a
 0003ba80:·6964·6522·0a76·6572·7369·6f6e·203d·2022··ide".version·=·"
0003ba00:·6961·7469·6f6e·2073·6372·6970·7420·e287··iation·script·.. 
0003ba10:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl 
0003ba20:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla 
0003ba30:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id 
0003ba40:·3d22·6964·6d37·3333·3222·3e3c·7461·626c··="idm7332"><tabl 
0003ba50:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t 
0003ba60:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab 
0003ba70:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl 
0003ba80:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr 
0003ba90:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity: 
0003baa0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td 
0003bab0:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di 
0003bac0:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t 
0003bad0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr>< 
0003bae0:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</ 
0003baf0:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td 
0003bb00:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St 
0003bb10:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td> 
0003bb20:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr> 
0003bb30:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co 
0003bb40:·6465·3e0a·646e·6620·696e·7374·616c·6c20··de>.dnf·install· 
0003bb50:·6169·6465·0a3c·2f63·6f64·653e·3c2f·7072··aide.</code></pr0003ba90:·2a22·0a3c·2f63·6f64·653e·3c2f·7072·653e··*".</code></pre>
0003bb60:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class0003baa0:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class="
0003bb70:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes0003bab0:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success"
0003bb80:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle="0003bac0:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co
0003bb90:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t0003bad0:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar
0003bba0:·6172·6765·743d·2223·6964·6d37·3333·3322··arget="#idm7333"0003bae0:·6765·743d·2223·6964·6d37·3333·3322·2074··get="#idm7333"·t
0003bbb0:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro0003baf0:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
0003bbc0:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria0003bb00:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
0003bbd0:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false0003bb10:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
0003bbe0:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat0003bb20:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
0003bbf0:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre0003bb30:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
0003bc00:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati0003bb40:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
0003bc10:·6f6e·2041·6e61·636f·6e64·6120·736e·6970··on·Anaconda·snip0003bb50:·2050·7570·7065·7420·736e·6970·7065·7420···Puppet·snippet·
0003bc20:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br><0003bb60:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·
0003bc30:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel0003bb70:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col
0003bc40:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap0003bb80:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·
0003bc50:·7365·2220·6964·3d22·6964·6d37·3333·3322··se"·id="idm7333"0003bb90:·6964·3d22·6964·6d37·3333·3322·3e3c·7461··id="idm7333"><ta
0003bc60:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t0003bba0:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table
0003bc70:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip0003bbb0:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t
0003bc80:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere0003bbc0:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta
0003bc90:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense0003bbd0:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><
0003bca0:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl0003bbe0:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit
0003bcb0:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l0003bbf0:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</
0003bcc0:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>0003bc00:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
0003bcd0:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:<0003bc10:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th>
 0003bc20:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
 0003bc30:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot:
 0003bc40:·3c2f·7468·3e3c·7464·3e66·616c·7365·3c2f··</th><td>false</
 0003bc50:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 0003bc60:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t
 0003bc70:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t
 0003bc80:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><
 0003bc90:·636f·6465·3e69·6e63·6c75·6465·2069·6e73··code>include·ins
 0003bca0:·7461·6c6c·5f61·6964·650a·0a63·6c61·7373··tall_aide..class
 0003bcb0:·2069·6e73·7461·6c6c·5f61·6964·6520·7b0a···install_aide·{.
 0003bcc0:·2020·7061·636b·6167·6520·7b20·2761·6964····package·{·'aid
 0003bcd0:·6527·3a0a·2020·2020·656e·7375·7265·203d··e':.····ensure·=
 0003bce0:·2667·743b·2027·696e·7374·616c·6c65·6427··&gt;·'installed'
 0003bcf0:·2c0a·2020·7d0a·7d0a·3c2f·636f·6465·3e3c··,.··}.}.</code><
 0003bd00:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl
 0003bd10:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc
 0003bd20:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl
 0003bd30:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat
 0003bd40:·612d·7461·7267·6574·3d22·2369·646d·3733··a-target="#idm73
 0003bd50:·3334·2220·7461·6269·6e64·6578·3d22·3022··34"·tabindex="0"
 0003bd60:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
 0003bd70:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
 0003bd80:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
 0003bd90:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
 0003bda0:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
 0003bdb0:·6174·696f·6e20·7363·7269·7074·20e2·87b2··ation·script·...
 0003bdc0:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
 0003bdd0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
 0003bde0:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
 0003bdf0:·2269·646d·3733·3334·223e·3c74·6162·6c65··"idm7334"><table
 0003be00:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta
 0003be10:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl
 0003be20:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table
 0003be30:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>
 0003be40:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<
0003bce0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>0003be50:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
 0003be60:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis
 0003be70:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td
 0003be80:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
 0003be90:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t
 0003bea0:·683e·3c74·643e·6661·6c73·653c·2f74·643e··h><td>false</td>
0003bcf0:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb0003beb0:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str
0003bd00:·6f6f·743a·3c2f·7468·3e3c·7464·3e66·616c··oot:</th><td>fal0003bec0:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e
 0003bed0:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr><
 0003bee0:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod
 0003bef0:·653e·0a70·6163·6b61·6765·2069·6e73·7461··e>.package·insta
 0003bf00:·6c6c·2061·6964·650a·3c2f·636f·6465·3e3c··ll·aide.</code><
 0003bf10:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl
 0003bf20:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc
 0003bf30:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl
 0003bf40:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat
 0003bf50:·612d·7461·7267·6574·3d22·2369·646d·3733··a-target="#idm73
 0003bf60:·3335·2220·7461·6269·6e64·6578·3d22·3022··35"·tabindex="0"
 0003bf70:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
 0003bf80:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
 0003bf90:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
 0003bfa0:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
 0003bfb0:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
 0003bfc0:·6174·696f·6e20·5368·656c·6c20·7363·7269··ation·Shell·scri
0003bd10:·7365·3c2f·7464·3e3c·2f74·723e·3c74·723e··se</td></tr><tr> 
0003bd20:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t 
0003bd30:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td 
0003bd40:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p 
0003bd50:·7265·3e3c·636f·6465·3e0a·7061·636b·6167··re><code>.packag 
0003bd60:·6520·2d2d·6164·643d·6169·6465·0a3c·2f63··e·--add=aide.</c 
Max diff block lines reached; 1337885/1365099 bytes (98.01%) of diff not shown.
148 KB
html2text {}
    
Offset 156, 52 lines modifiedOffset 156, 38 lines modified
156 ··-·PCI-DSSv4-11.5.2156 ··-·PCI-DSSv4-11.5.2
157 ··-·enable_strategy157 ··-·enable_strategy
158 ··-·low_complexity158 ··-·low_complexity
159 ··-·low_disruption159 ··-·low_disruption
160 ··-·medium_severity160 ··-·medium_severity
161 ··-·no_reboot_needed161 ··-·no_reboot_needed
162 ··-·package_aide_installed162 ··-·package_aide_installed
163 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
164 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
165 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
166 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
167 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
168 dnf·install·aide 
169 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
170 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
171 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
172 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
173 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
174 package·--add=aide 
175 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8163 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
176 [[packages]]164 [[packages]]
177 name·=·"aide"165 name·=·"aide"
178 version·=·"*"166 version·=·"*"
179 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
180 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
181 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
182 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
183 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
184 package·install·aide 
185 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8167 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
186 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low168 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
187 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low169 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
188 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false170 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
189 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable171 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
190 include·install_aide172 include·install_aide
  
191 class·install_aide·{173 class·install_aide·{
192 ··package·{·'aide':174 ··package·{·'aide':
193 ····ensure·=>·'installed',175 ····ensure·=>·'installed',
194 ··}176 ··}
195 }177 }
 178 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 179 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 180 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 181 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 182 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 183 package·install·aide
196 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8184 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
197 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low185 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
198 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low186 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
199 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false187 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
200 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable188 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
201 #·Remediation·is·applicable·only·in·certain·platforms189 #·Remediation·is·applicable·only·in·certain·platforms
202 if·rpm·--quiet·-q·kernel;·then190 if·rpm·--quiet·-q·kernel;·then
Offset 209, 14 lines modifiedOffset 195, 28 lines modified
209 if·!·rpm·-q·--quiet·"aide"·;·then195 if·!·rpm·-q·--quiet·"aide"·;·then
210 ····dnf·install·-y·"aide"196 ····dnf·install·-y·"aide"
211 fi197 fi
  
212 else198 else
213 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'199 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
214 fi200 fi
 201 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 202 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 203 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 204 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 205 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 206 package·--add=aide
 207 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 208 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 209 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 210 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 211 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 212 dnf·install·aide
215 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*213 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
216 Run·the·following·command·to·generate·a·new·database:214 Run·the·following·command·to·generate·a·new·database:
217 $·sudo·/usr/sbin/aide·--init215 $·sudo·/usr/sbin/aide·--init
218 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:216 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
219 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz217 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
220 To·initiate·a·manual·check,·run·the·following·command:218 To·initiate·a·manual·check,·run·the·following·command:
221 $·sudo·/usr/sbin/aide·--check219 $·sudo·/usr/sbin/aide·--check
Offset 881, 29 lines modifiedOffset 881, 29 lines modified
881 ············_\x8d_\x8i_\x8s_\x8a···········CCI-000366881 ············_\x8d_\x8i_\x8s_\x8a···········CCI-000366
882 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.5,·SR·3.8,·SR·4.1,·SR·4.3,·SR·5.1,·SR·5.2,·SR·5.3,·SR·7.1,·SR·7.6882 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.5,·SR·3.8,·SR·4.1,·SR·4.3,·SR·5.1,·SR·5.2,·SR·5.3,·SR·7.1,·SR·7.6
883 References:·_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.3883 References:·_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.3
884 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)884 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)
885 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4885 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4
886 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227886 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
887 ············_\x8c_\x8i_\x8s············1.1.2.1.1887 ············_\x8c_\x8i_\x8s············1.1.2.1.1
888 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
889 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
890 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high 
891 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
892 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
893 part·/tmp 
894 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8888 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
895 [[customizations.filesystem]]889 [[customizations.filesystem]]
896 mountpoint·=·"/tmp"890 mountpoint·=·"/tmp"
897 size·=·1073741824891 size·=·1073741824
898 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8892 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
899 logvol·/tmp·1024893 logvol·/tmp·1024
 894 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 895 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 896 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high
 897 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 898 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 899 part·/tmp
900 Group  ·GNOME·Desktop·Environment·  Group·contains·3·groups·and·9·rules900 Group  ·GNOME·Desktop·Environment·  Group·contains·3·groups·and·9·rules
901 _\x8[_\x8r_\x8e_\x8f_\x8]  ·GNOME·is·a·graphical·desktop·environment·bundled·with·many·Linux·distributions·that·allow·users·to·easily·interact·with·the·operating·system·graphically·rather·than·textually.·The·GNOME·Graphical·Display·Manager·(GDM)·provides·login,·logout,·and·user·switching·contexts·as·well·as·display·server·management.901 _\x8[_\x8r_\x8e_\x8f_\x8]  ·GNOME·is·a·graphical·desktop·environment·bundled·with·many·Linux·distributions·that·allow·users·to·easily·interact·with·the·operating·system·graphically·rather·than·textually.·The·GNOME·Graphical·Display·Manager·(GDM)·provides·login,·logout,·and·user·switching·contexts·as·well·as·display·server·management.
  
902 GNOME·is·developed·by·the·GNOME·Project·and·is·considered·the·default·Red·Hat·Graphical·environment.902 GNOME·is·developed·by·the·GNOME·Project·and·is·considered·the·default·Red·Hat·Graphical·environment.
  
903 For·more·information·on·GNOME·and·the·GNOME·Project,·see·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8w\x8w_\x8w\x8w_\x8w\x8w_\x8.\x8._\x8g\x8g_\x8n\x8n_\x8o\x8o_\x8m\x8m_\x8e\x8e_\x8.\x8._\x8o\x8o_\x8r\x8r_\x8g\x8g.903 For·more·information·on·GNOME·and·the·GNOME·Project,·see·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8w\x8w_\x8w\x8w_\x8w\x8w_\x8.\x8._\x8g\x8g_\x8n\x8n_\x8o\x8o_\x8m\x8m_\x8e\x8e_\x8.\x8._\x8o\x8o_\x8r\x8r_\x8g\x8g.
904 Group  ·Configure·GNOME·Login·Screen·  Group·contains·1·rule904 Group  ·Configure·GNOME·Login·Screen·  Group·contains·1·rule
Offset 2156, 52 lines modifiedOffset 2156, 38 lines modified
2156 ··-·PCI-DSSv4-2.2.62156 ··-·PCI-DSSv4-2.2.6
Max diff block lines reached; 146236/151687 bytes (96.41%) of diff not shown.
1.34 MB
./usr/share/doc/ssg-nondebian/ssg-cs10-guide-cis_workstation_l1.html
    
Offset 15249, 207 lines modifiedOffset 15249, 207 lines modified
0003b900:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm0003b900:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
0003b910:·3733·3332·2220·7461·6269·6e64·6578·3d22··7332"·tabindex="0003b910:·3733·3332·2220·7461·6269·6e64·6578·3d22··7332"·tabindex="
0003b920:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"0003b920:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
0003b930:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="0003b930:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
0003b940:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac0003b940:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
0003b950:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal0003b950:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
0003b960:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme0003b960:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
0003b970:·6469·6174·696f·6e20·7363·7269·7074·20e2··diation·script·.0003b970:·6469·6174·696f·6e20·4f53·4275·696c·6420··diation·OSBuild·
 0003b980:·426c·7565·7072·696e·7420·736e·6970·7065··Blueprint·snippe
 0003b990:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di
 0003b9a0:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c
 0003b9b0:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse
 0003b9c0:·2220·6964·3d22·6964·6d37·3333·3222·3e3c··"·id="idm7332"><
 0003b9d0:·7072·653e·3c63·6f64·653e·0a5b·5b70·6163··pre><code>.[[pac
 0003b9e0:·6b61·6765·735d·5d0a·6e61·6d65·203d·2022··kages]].name·=·"
 0003b9f0:·6169·6465·220a·7665·7273·696f·6e20·3d20··aide".version·=·
0003b980:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c 
0003b990:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll 
0003b9a0:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i 
0003b9b0:·643d·2269·646d·3733·3332·223e·3c74·6162··d="idm7332"><tab 
0003b9c0:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table· 
0003b9d0:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta 
0003b9e0:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab 
0003b9f0:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t 
0003ba00:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity 
0003ba10:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t 
0003ba20:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D 
0003ba30:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th>< 
0003ba40:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
0003ba50:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:< 
0003ba60:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t 
0003ba70:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S 
0003ba80:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td 
0003ba90:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr 
0003baa0:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c 
0003bab0:·6f64·653e·0a64·6e66·2069·6e73·7461·6c6c··ode>.dnf·install 
0003bac0:·2061·6964·650a·3c2f·636f·6465·3e3c·2f70···aide.</code></p0003ba00:·222a·220a·3c2f·636f·6465·3e3c·2f70·7265··"*".</code></pre
0003bad0:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas0003ba10:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class=
0003bae0:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe0003ba20:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success
0003baf0:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle=0003ba30:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c
0003bb00:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data-0003ba40:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta
0003bb10:·7461·7267·6574·3d22·2369·646d·3733·3333··target="#idm73330003ba50:·7267·6574·3d22·2369·646d·3733·3333·2220··rget="#idm7333"·
0003bb20:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r0003ba60:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol
0003bb30:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari0003ba70:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-
0003bb40:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals0003ba80:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"
0003bb50:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa0003ba90:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate
0003bb60:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr0003baa0:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href
0003bb70:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat0003bab0:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio
0003bb80:·696f·6e20·416e·6163·6f6e·6461·2073·6e69··ion·Anaconda·sni0003bac0:·6e20·5075·7070·6574·2073·6e69·7070·6574··n·Puppet·snippet
0003bb90:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>0003bad0:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
0003bba0:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane0003bae0:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
0003bbb0:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla0003baf0:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
0003bbc0:·7073·6522·2069·643d·2269·646d·3733·3333··pse"·id="idm73330003bb00:·2069·643d·2269·646d·3733·3333·223e·3c74···id="idm7333"><t
0003bbd0:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="0003bb10:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl
0003bbe0:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri0003bb20:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·
0003bbf0:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border0003bb30:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t
0003bc00:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens0003bb40:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">
0003bc10:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp0003bb50:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi
0003bc20:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>0003bb60:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<
 0003bb70:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 0003bb80:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th
 0003bb90:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
 0003bba0:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot
 0003bbb0:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false<
0003bc30:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr0003bbc0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
0003bc40:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:0003bbd0:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><
 0003bbe0:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></
 0003bbf0:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>
 0003bc00:·3c63·6f64·653e·696e·636c·7564·6520·696e··<code>include·in
 0003bc10:·7374·616c·6c5f·6169·6465·0a0a·636c·6173··stall_aide..clas
 0003bc20:·7320·696e·7374·616c·6c5f·6169·6465·207b··s·install_aide·{
 0003bc30:·0a20·2070·6163·6b61·6765·207b·2027·6169··.··package·{·'ai
 0003bc40:·6465·273a·0a20·2020·2065·6e73·7572·6520··de':.····ensure·
 0003bc50:·3d26·6774·3b20·2769·6e73·7461·6c6c·6564··=&gt;·'installed
 0003bc60:·272c·0a20·207d·0a7d·0a3c·2f63·6f64·653e··',.··}.}.</code>
 0003bc70:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c
 0003bc80:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su
 0003bc90:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg
 0003bca0:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da
 0003bcb0:·7461·2d74·6172·6765·743d·2223·6964·6d37··ta-target="#idm7
 0003bcc0:·3333·3422·2074·6162·696e·6465·783d·2230··334"·tabindex="0
 0003bcd0:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
 0003bce0:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
 0003bcf0:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
 0003bd00:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
 0003bd10:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
 0003bd20:·6961·7469·6f6e·2073·6372·6970·7420·e287··iation·script·..
 0003bd30:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl
 0003bd40:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla
 0003bd50:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id
 0003bd60:·3d22·6964·6d37·3333·3422·3e3c·7461·626c··="idm7334"><tabl
 0003bd70:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t
 0003bd80:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab
 0003bd90:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl
 0003bda0:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr
 0003bdb0:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:
0003bc50:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td0003bdc0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
0003bc60:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re0003bdd0:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di
0003bc70:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa0003bde0:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t
0003bc80:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr0003bdf0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
0003bc90:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</0003be00:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</
0003bca0:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t0003be10:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td
0003bcb0:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table>< 
0003bcc0:·7072·653e·3c63·6f64·653e·0a70·6163·6b61··pre><code>.packa 
0003bcd0:·6765·202d·2d61·6464·3d61·6964·650a·3c2f··ge·--add=aide.</ 
0003bce0:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div 
0003bcf0:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b 
0003bd00:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data 
0003bd10:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps 
0003bd20:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target=" 
0003bd30:·2369·646d·3733·3334·2220·7461·6269·6e64··#idm7334"·tabind 
0003bd40:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but 
0003bd50:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand 
0003bd60:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title 
0003bd70:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re 
0003bd80:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!"> 
0003bd90:·5265·6d65·6469·6174·696f·6e20·4f53·4275··Remediation·OSBu 
0003bda0:·696c·6420·426c·7565·7072·696e·7420·736e··ild·Blueprint·sn0003be20:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St
 0003be30:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>
 0003be40:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr>
 0003be50:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co
 0003be60:·6465·3e0a·7061·636b·6167·6520·696e·7374··de>.package·inst
 0003be70:·616c·6c20·6169·6465·0a3c·2f63·6f64·653e··all·aide.</code>
 0003be80:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c
 0003be90:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su
 0003bea0:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg
 0003beb0:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da
Max diff block lines reached; 1243138/1270352 bytes (97.86%) of diff not shown.
136 KB
html2text {}
    
Offset 154, 52 lines modifiedOffset 154, 38 lines modified
154 ··-·PCI-DSSv4-11.5.2154 ··-·PCI-DSSv4-11.5.2
155 ··-·enable_strategy155 ··-·enable_strategy
156 ··-·low_complexity156 ··-·low_complexity
157 ··-·low_disruption157 ··-·low_disruption
158 ··-·medium_severity158 ··-·medium_severity
159 ··-·no_reboot_needed159 ··-·no_reboot_needed
160 ··-·package_aide_installed160 ··-·package_aide_installed
161 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
162 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
163 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
164 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
165 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
166 dnf·install·aide 
167 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
168 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
169 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
170 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
171 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
172 package·--add=aide 
173 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8161 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
174 [[packages]]162 [[packages]]
175 name·=·"aide"163 name·=·"aide"
176 version·=·"*"164 version·=·"*"
177 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
178 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
179 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
180 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
181 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
182 package·install·aide 
183 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8165 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
184 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low166 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
185 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low167 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
186 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false168 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
187 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable169 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
188 include·install_aide170 include·install_aide
  
189 class·install_aide·{171 class·install_aide·{
190 ··package·{·'aide':172 ··package·{·'aide':
191 ····ensure·=>·'installed',173 ····ensure·=>·'installed',
192 ··}174 ··}
193 }175 }
 176 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 177 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 178 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 179 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 180 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 181 package·install·aide
194 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8182 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
195 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low183 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
196 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low184 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
197 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false185 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
198 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable186 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
199 #·Remediation·is·applicable·only·in·certain·platforms187 #·Remediation·is·applicable·only·in·certain·platforms
200 if·rpm·--quiet·-q·kernel;·then188 if·rpm·--quiet·-q·kernel;·then
Offset 207, 14 lines modifiedOffset 193, 28 lines modified
207 if·!·rpm·-q·--quiet·"aide"·;·then193 if·!·rpm·-q·--quiet·"aide"·;·then
208 ····dnf·install·-y·"aide"194 ····dnf·install·-y·"aide"
209 fi195 fi
  
210 else196 else
211 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'197 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
212 fi198 fi
 199 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 200 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 201 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 202 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 203 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 204 package·--add=aide
 205 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 206 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 207 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 208 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 209 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 210 dnf·install·aide
213 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*211 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
214 Run·the·following·command·to·generate·a·new·database:212 Run·the·following·command·to·generate·a·new·database:
215 $·sudo·/usr/sbin/aide·--init213 $·sudo·/usr/sbin/aide·--init
216 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:214 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
217 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz215 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
218 To·initiate·a·manual·check,·run·the·following·command:216 To·initiate·a·manual·check,·run·the·following·command:
219 $·sudo·/usr/sbin/aide·--check217 $·sudo·/usr/sbin/aide·--check
Offset 879, 29 lines modifiedOffset 879, 29 lines modified
879 ············_\x8d_\x8i_\x8s_\x8a···········CCI-000366879 ············_\x8d_\x8i_\x8s_\x8a···········CCI-000366
880 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.5,·SR·3.8,·SR·4.1,·SR·4.3,·SR·5.1,·SR·5.2,·SR·5.3,·SR·7.1,·SR·7.6880 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.5,·SR·3.8,·SR·4.1,·SR·4.3,·SR·5.1,·SR·5.2,·SR·5.3,·SR·7.1,·SR·7.6
881 References:·_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.3881 References:·_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.3
882 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)882 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)
883 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4883 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4
884 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227884 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
885 ············_\x8c_\x8i_\x8s············1.1.2.1.1885 ············_\x8c_\x8i_\x8s············1.1.2.1.1
886 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
887 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
888 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high 
889 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
890 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
891 part·/tmp 
892 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8886 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
893 [[customizations.filesystem]]887 [[customizations.filesystem]]
894 mountpoint·=·"/tmp"888 mountpoint·=·"/tmp"
895 size·=·1073741824889 size·=·1073741824
896 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8890 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
897 logvol·/tmp·1024891 logvol·/tmp·1024
 892 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 893 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 894 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high
 895 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 896 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 897 part·/tmp
898 Group  ·GNOME·Desktop·Environment·  Group·contains·3·groups·and·7·rules898 Group  ·GNOME·Desktop·Environment·  Group·contains·3·groups·and·7·rules
899 _\x8[_\x8r_\x8e_\x8f_\x8]  ·GNOME·is·a·graphical·desktop·environment·bundled·with·many·Linux·distributions·that·allow·users·to·easily·interact·with·the·operating·system·graphically·rather·than·textually.·The·GNOME·Graphical·Display·Manager·(GDM)·provides·login,·logout,·and·user·switching·contexts·as·well·as·display·server·management.899 _\x8[_\x8r_\x8e_\x8f_\x8]  ·GNOME·is·a·graphical·desktop·environment·bundled·with·many·Linux·distributions·that·allow·users·to·easily·interact·with·the·operating·system·graphically·rather·than·textually.·The·GNOME·Graphical·Display·Manager·(GDM)·provides·login,·logout,·and·user·switching·contexts·as·well·as·display·server·management.
  
900 GNOME·is·developed·by·the·GNOME·Project·and·is·considered·the·default·Red·Hat·Graphical·environment.900 GNOME·is·developed·by·the·GNOME·Project·and·is·considered·the·default·Red·Hat·Graphical·environment.
  
901 For·more·information·on·GNOME·and·the·GNOME·Project,·see·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8w\x8w_\x8w\x8w_\x8w\x8w_\x8.\x8._\x8g\x8g_\x8n\x8n_\x8o\x8o_\x8m\x8m_\x8e\x8e_\x8.\x8._\x8o\x8o_\x8r\x8r_\x8g\x8g.901 For·more·information·on·GNOME·and·the·GNOME·Project,·see·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8w\x8w_\x8w\x8w_\x8w\x8w_\x8.\x8._\x8g\x8g_\x8n\x8n_\x8o\x8o_\x8m\x8m_\x8e\x8e_\x8.\x8._\x8o\x8o_\x8r\x8r_\x8g\x8g.
902 Group  ·Configure·GNOME·Login·Screen·  Group·contains·1·rule902 Group  ·Configure·GNOME·Login·Screen·  Group·contains·1·rule
Offset 1814, 52 lines modifiedOffset 1814, 38 lines modified
1814 ··-·PCI-DSSv4-2.2.61814 ··-·PCI-DSSv4-2.2.6
Max diff block lines reached; 133672/139123 bytes (96.08%) of diff not shown.
1.56 MB
./usr/share/doc/ssg-nondebian/ssg-cs10-guide-cis_workstation_l2.html
    
Offset 15288, 207 lines modifiedOffset 15288, 207 lines modified
0003bb70:·6765·743d·2223·6964·6d37·3333·3222·2074··get="#idm7332"·t0003bb70:·6765·743d·2223·6964·6d37·3333·3222·2074··get="#idm7332"·t
0003bb80:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role0003bb80:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
0003bb90:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e0003bb90:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
0003bba0:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·0003bba0:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
0003bbb0:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·0003bbb0:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
0003bbc0:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=0003bbc0:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
0003bbd0:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation0003bbd0:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
 0003bbe0:·204f·5342·7569·6c64·2042·6c75·6570·7269···OSBuild·Bluepri
 0003bbf0:·6e74·2073·6e69·7070·6574·20e2·87b2·3c2f··nt·snippet·...</
 0003bc00:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
 0003bc10:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
 0003bc20:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
 0003bc30:·646d·3733·3332·223e·3c70·7265·3e3c·636f··dm7332"><pre><co
 0003bc40:·6465·3e0a·5b5b·7061·636b·6167·6573·5d5d··de>.[[packages]]
 0003bc50:·0a6e·616d·6520·3d20·2261·6964·6522·0a76··.name·=·"aide".v
 0003bc60:·6572·7369·6f6e·203d·2022·2a22·0a3c·2f63··ersion·=·"*".</c
0003bbe0:·2073·6372·6970·7420·e287·b23c·2f61·3e3c···script·...</a>< 
0003bbf0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p 
0003bc00:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co 
0003bc10:·6c6c·6170·7365·2220·6964·3d22·6964·6d37··llapse"·id="idm7 
0003bc20:·3333·3222·3e3c·7461·626c·6520·636c·6173··332"><table·clas 
0003bc30:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s 
0003bc40:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor 
0003bc50:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond 
0003bc60:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C 
0003bc70:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th>< 
0003bc80:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
0003bc90:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti 
0003bca0:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low< 
0003bcb0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0003bcc0:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td 
0003bcd0:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr> 
0003bce0:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy 
0003bcf0:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable 
0003bd00:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl 
0003bd10:·653e·3c70·7265·3e3c·636f·6465·3e0a·646e··e><pre><code>.dn 
0003bd20:·6620·696e·7374·616c·6c20·6169·6465·0a3c··f·install·aide.< 
0003bd30:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di0003bc70:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div>
0003bd40:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn·0003bc80:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt
0003bd50:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat0003bc90:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data-
0003bd60:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap0003bca0:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse
0003bd70:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=0003bcb0:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
0003bd80:·2223·6964·6d37·3333·3322·2074·6162·696e··"#idm7333"·tabin0003bcc0:·6964·6d37·3333·3322·2074·6162·696e·6465··idm7333"·tabinde
0003bd90:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu0003bcd0:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt
0003bda0:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan0003bce0:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande
0003bdb0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl0003bcf0:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=
0003bdc0:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r0003bd00:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev
0003bdd0:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"0003bd10:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R
0003bde0:·3e52·656d·6564·6961·7469·6f6e·2041·6e61··>Remediation·Ana0003bd20:·656d·6564·6961·7469·6f6e·2050·7570·7065··emediation·Puppe
0003bdf0:·636f·6e64·6120·736e·6970·7065·7420·e287··conda·snippet·..0003bd30:·7420·736e·6970·7065·7420·e287·b23c·2f61··t·snippet·...</a
0003be00:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl0003bd40:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
0003be10:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla0003bd50:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
0003be20:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id0003bd60:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
0003be30:·3d22·6964·6d37·3333·3322·3e3c·7461·626c··="idm7333"><tabl0003bd70:·6d37·3333·3322·3e3c·7461·626c·6520·636c··m7333"><table·cl
0003be40:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t0003bd80:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table
0003be50:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab0003bd90:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b
0003be60:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl0003bda0:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co
0003be70:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr0003bdb0:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th
0003be80:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:0003bdc0:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th
0003be90:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td0003bdd0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
0003bea0:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di0003bde0:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup
0003beb0:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t 
0003bec0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr>< 
0003bed0:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</ 
0003bee0:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td 
0003bef0:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St 
0003bf00:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>0003bdf0:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo
 0003be00:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
 0003be10:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th><
 0003be20:·7464·3e66·616c·7365·3c2f·7464·3e3c·2f74··td>false</td></t
 0003be30:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate
 0003be40:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab
0003bf10:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr> 
0003bf20:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co 
0003bf30:·6465·3e0a·7061·636b·6167·6520·2d2d·6164··de>.package·--ad 
0003bf40:·643d·6169·6465·0a3c·2f63·6f64·653e·3c2f··d=aide.</code></ 
0003bf50:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla 
0003bf60:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ 
0003bf70:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle 
0003bf80:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data 
0003bf90:·2d74·6172·6765·743d·2223·6964·6d37·3333··-target="#idm733 
0003bfa0:·3422·2074·6162·696e·6465·783d·2230·2220··4"·tabindex="0"· 
0003bfb0:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar 
0003bfc0:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal 
0003bfd0:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ 
0003bfe0:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h 
0003bff0:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia 
0003c000:·7469·6f6e·204f·5342·7569·6c64·2042·6c75··tion·OSBuild·Blu 
0003c010:·6570·7269·6e74·2073·6e69·7070·6574·20e2··eprint·snippet·. 
0003c020:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c 
0003c030:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll 
0003c040:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i 
0003c050:·643d·2269·646d·3733·3334·223e·3c70·7265··d="idm7334"><pre 
0003c060:·3e3c·636f·6465·3e0a·5b5b·7061·636b·6167··><code>.[[packag 
0003c070:·6573·5d5d·0a6e·616d·6520·3d20·2261·6964··es]].name·=·"aid 
0003c080:·6522·0a76·6572·7369·6f6e·203d·2022·2a22··e".version·=·"*" 
0003c090:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></ 
0003c0a0:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt 
0003c0b0:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d 
0003c0c0:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll 
0003c0d0:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe 
0003c0e0:·743d·2223·6964·6d37·3333·3522·2074·6162··t="#idm7335"·tab 
0003c0f0:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role=" 
0003c100:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp 
0003c110:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti 
0003c120:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to 
0003c130:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="# 
0003c140:·2122·3e52·656d·6564·6961·7469·6f6e·2073··!">Remediation·s 
0003c150:·6372·6970·7420·e287·b23c·2f61·3e3c·6272··cript·...</a><br 
0003c160:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan 
0003c170:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll 
0003c180:·6170·7365·2220·6964·3d22·6964·6d37·3333··apse"·id="idm733 
0003c190:·3522·3e3c·7461·626c·6520·636c·6173·733d··5"><table·class= 
0003c1a0:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str 
0003c1b0:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde 
0003c1c0:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden 
0003c1d0:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com 
0003c1e0:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td 
0003c1f0:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t 
0003c200:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption 
0003c210:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t 
0003c220:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e52··d></tr><tr><th>R 
0003c230:·6562·6f6f·743a·3c2f·7468·3e3c·7464·3e66··eboot:</th><td>f 
0003c240:·616c·7365·3c2f·7464·3e3c·2f74·723e·3c74··alse</td></tr><t0003be50:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta
0003c250:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:< 
0003c260:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</ 
0003c270:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table> 
Max diff block lines reached; 1438476/1465690 bytes (98.14%) of diff not shown.
166 KB
html2text {}
    
Offset 160, 52 lines modifiedOffset 160, 38 lines modified
160 ··-·PCI-DSSv4-11.5.2160 ··-·PCI-DSSv4-11.5.2
161 ··-·enable_strategy161 ··-·enable_strategy
162 ··-·low_complexity162 ··-·low_complexity
163 ··-·low_disruption163 ··-·low_disruption
164 ··-·medium_severity164 ··-·medium_severity
165 ··-·no_reboot_needed165 ··-·no_reboot_needed
166 ··-·package_aide_installed166 ··-·package_aide_installed
167 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
168 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
169 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
170 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
171 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
172 dnf·install·aide 
173 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
174 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
175 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
176 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
177 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
178 package·--add=aide 
179 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8167 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
180 [[packages]]168 [[packages]]
181 name·=·"aide"169 name·=·"aide"
182 version·=·"*"170 version·=·"*"
183 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
184 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
185 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
186 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
187 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
188 package·install·aide 
189 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8171 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
190 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low172 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
191 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low173 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
192 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false174 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
193 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable175 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
194 include·install_aide176 include·install_aide
  
195 class·install_aide·{177 class·install_aide·{
196 ··package·{·'aide':178 ··package·{·'aide':
197 ····ensure·=>·'installed',179 ····ensure·=>·'installed',
198 ··}180 ··}
199 }181 }
 182 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 183 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 184 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 185 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 186 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 187 package·install·aide
200 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8188 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
201 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low189 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
202 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low190 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
203 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false191 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
204 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable192 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
205 #·Remediation·is·applicable·only·in·certain·platforms193 #·Remediation·is·applicable·only·in·certain·platforms
206 if·rpm·--quiet·-q·kernel;·then194 if·rpm·--quiet·-q·kernel;·then
Offset 213, 14 lines modifiedOffset 199, 28 lines modified
213 if·!·rpm·-q·--quiet·"aide"·;·then199 if·!·rpm·-q·--quiet·"aide"·;·then
214 ····dnf·install·-y·"aide"200 ····dnf·install·-y·"aide"
215 fi201 fi
  
216 else202 else
217 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'203 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
218 fi204 fi
 205 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 206 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 207 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 208 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 209 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 210 package·--add=aide
 211 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 212 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 213 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 214 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 215 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 216 dnf·install·aide
219 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*217 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
220 Run·the·following·command·to·generate·a·new·database:218 Run·the·following·command·to·generate·a·new·database:
221 $·sudo·/usr/sbin/aide·--init219 $·sudo·/usr/sbin/aide·--init
222 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:220 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
223 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz221 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
224 To·initiate·a·manual·check,·run·the·following·command:222 To·initiate·a·manual·check,·run·the·following·command:
225 $·sudo·/usr/sbin/aide·--check223 $·sudo·/usr/sbin/aide·--check
Offset 886, 58 lines modifiedOffset 886, 58 lines modified
886 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.5,·SR·3.8,·SR·4.1,·SR·4.3,·SR·5.1,·SR·5.2,·SR·5.3,·SR·7.1,·SR·7.6886 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.5,·SR·3.8,·SR·4.1,·SR·4.3,·SR·5.1,·SR·5.2,·SR·5.3,·SR·7.1,·SR·7.6
887 References:·_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.3887 References:·_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.3
888 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)888 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)
889 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4889 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4
890 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227890 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
891 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R28891 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R28
892 ············_\x8c_\x8i_\x8s············1.1.2.3.1892 ············_\x8c_\x8i_\x8s············1.1.2.3.1
893 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
894 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
895 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high 
896 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
897 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
898 part·/home 
899 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8893 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
900 [[customizations.filesystem]]894 [[customizations.filesystem]]
901 mountpoint·=·"/home"895 mountpoint·=·"/home"
902 size·=·1073741824896 size·=·1073741824
903 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8897 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
904 logvol·/home·1024898 logvol·/home·1024
 899 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 900 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 901 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high
 902 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 903 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 904 part·/home
905 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/t\x8tm\x8mp\x8p·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*905 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/t\x8tm\x8mp\x8p·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
906 The·/tmp·directory·is·a·world-writable·directory·used·for·temporary·file·storage.·Ensure·it·has·its·own·partition·or·logical·volume·at·installation·time,·or·migrate·it·using·LVM.906 The·/tmp·directory·is·a·world-writable·directory·used·for·temporary·file·storage.·Ensure·it·has·its·own·partition·or·logical·volume·at·installation·time,·or·migrate·it·using·LVM.
907 Rationale:··The·/tmp·partition·is·used·as·temporary·storage·by·many·programs.·Placing·/tmp·in·its·own·partition·enables·the·setting·of·more·restrictive·mount·options,·which·can·help·protect·programs·which·use·it.907 Rationale:··The·/tmp·partition·is·used·as·temporary·storage·by·many·programs.·Placing·/tmp·in·its·own·partition·enables·the·setting·of·more·restrictive·mount·options,·which·can·help·protect·programs·which·use·it.
908 Severity: ··low908 Severity: ··low
909 Rule·ID:····xccdf_org.ssgproject.content_rule_partition_for_tmp909 Rule·ID:····xccdf_org.ssgproject.content_rule_partition_for_tmp
910 ············_\x8c_\x8i_\x8s_\x8-_\x8c_\x8s_\x8c········12,·15,·8910 ············_\x8c_\x8i_\x8s_\x8-_\x8c_\x8s_\x8c········12,·15,·8
911 ············_\x8c_\x8o_\x8b_\x8i_\x8t_\x85·········APO13.01,·DSS05.02911 ············_\x8c_\x8o_\x8b_\x8i_\x8t_\x85·········APO13.01,·DSS05.02
912 ············_\x8d_\x8i_\x8s_\x8a···········CCI-000366912 ············_\x8d_\x8i_\x8s_\x8a···········CCI-000366
913 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.5,·SR·3.8,·SR·4.1,·SR·4.3,·SR·5.1,·SR·5.2,·SR·5.3,·SR·7.1,·SR·7.6913 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.5,·SR·3.8,·SR·4.1,·SR·4.3,·SR·5.1,·SR·5.2,·SR·5.3,·SR·7.1,·SR·7.6
Max diff block lines reached; 164136/169825 bytes (96.65%) of diff not shown.
281 KB
./usr/share/doc/ssg-nondebian/ssg-cs10-guide-e8.html
    
Offset 23225, 210 lines modifiedOffset 23225, 210 lines modified
0005ab80:·7461·2d74·6172·6765·743d·2223·6964·6d32··ta-target="#idm20005ab80:·7461·2d74·6172·6765·743d·2223·6964·6d32··ta-target="#idm2
0005ab90:·3031·3433·2220·7461·6269·6e64·6578·3d22··0143"·tabindex="0005ab90:·3031·3433·2220·7461·6269·6e64·6578·3d22··0143"·tabindex="
0005aba0:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"0005aba0:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
0005abb0:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="0005abb0:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
0005abc0:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac0005abc0:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
0005abd0:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal0005abd0:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
0005abe0:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme0005abe0:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
0005abf0:·6469·6174·696f·6e20·7363·7269·7074·20e2··diation·script·.0005abf0:·6469·6174·696f·6e20·4f53·4275·696c·6420··diation·OSBuild·
0005ac00:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c 
0005ac10:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll0005ac00:·426c·7565·7072·696e·7420·736e·6970·7065··Blueprint·snippe
 0005ac10:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di
 0005ac20:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c
 0005ac30:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse
 0005ac40:·2220·6964·3d22·6964·6d32·3031·3433·223e··"·id="idm20143">
 0005ac50:·3c70·7265·3e3c·636f·6465·3e0a·5b5b·7061··<pre><code>.[[pa
 0005ac60:·636b·6167·6573·5d5d·0a6e·616d·6520·3d20··ckages]].name·=·
 0005ac70:·2272·7379·736c·6f67·220a·7665·7273·696f··"rsyslog".versio
 0005ac80:·6e20·3d20·222a·220a·3c2f·636f·6465·3e3c··n·=·"*".</code><
 0005ac90:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl
 0005aca0:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc
 0005acb0:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl
0005ac20:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i0005acc0:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat
0005ac30:·643d·2269·646d·3230·3134·3322·3e3c·7461··d="idm20143"><ta 
0005ac40:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table 
0005ac50:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t 
0005ac60:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta 
0005ac70:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed">< 
0005ac80:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit0005acd0:·612d·7461·7267·6574·3d22·2369·646d·3230··a-target="#idm20
 0005ace0:·3134·3422·2074·6162·696e·6465·783d·2230··144"·tabindex="0
 0005acf0:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
 0005ad00:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
 0005ad10:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
 0005ad20:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
 0005ad30:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
 0005ad40:·6961·7469·6f6e·2050·7570·7065·7420·736e··iation·Puppet·sn
 0005ad50:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br
 0005ad60:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
 0005ad70:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
 0005ad80:·6170·7365·2220·6964·3d22·6964·6d32·3031··apse"·id="idm201
 0005ad90:·3434·223e·3c74·6162·6c65·2063·6c61·7373··44"><table·class
 0005ada0:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st
 0005adb0:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord
 0005adc0:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde
 0005add0:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co
 0005ade0:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t
 0005adf0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
 0005ae00:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio
0005ac90:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</0005ae10:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</
0005aca0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>0005ae20:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
0005acb0:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th> 
0005acc0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
0005acd0:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot: 
0005ace0:·3c2f·7468·3e3c·7464·3e66·616c·7365·3c2f··</th><td>false</ 
0005acf0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
0005ad00:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t 
0005ad10:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t 
0005ad20:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre>< 
0005ad30:·636f·6465·3e0a·646e·6620·696e·7374·616c··code>.dnf·instal 
0005ad40:·6c20·7273·7973·6c6f·670a·3c2f·636f·6465··l·rsyslog.</code 
0005ad50:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a· 
0005ad60:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s 
0005ad70:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog 
0005ad80:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d 
0005ad90:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm 
0005ada0:·3230·3134·3422·2074·6162·696e·6465·783d··20144"·tabindex= 
0005adb0:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button 
0005adc0:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded= 
0005add0:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A 
0005ade0:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea 
0005adf0:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem 
0005ae00:·6564·6961·7469·6f6e·2041·6e61·636f·6e64··ediation·Anacond 
0005ae10:·6120·736e·6970·7065·7420·e287·b23c·2f61··a·snippet·...</a 
0005ae20:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class= 
0005ae30:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse· 
0005ae40:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id 
0005ae50:·6d32·3031·3434·223e·3c74·6162·6c65·2063··m20144"><table·c 
0005ae60:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl 
0005ae70:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table- 
0005ae80:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c 
0005ae90:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t 
0005aea0:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t 
0005aeb0:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></ 
0005aec0:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru 
0005aed0:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l 
0005aee0:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr> 
0005aef0:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th>0005ae30:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td>
0005af00:·3c74·643e·6661·6c73·653c·2f74·643e·3c2f··<td>false</td></ 
0005af10:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat 
0005af20:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena 
0005af30:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t 
0005af40:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code> 
0005af50:·0a70·6163·6b61·6765·202d·2d61·6464·3d72··.package·--add=r 
0005af60:·7379·736c·6f67·0a3c·2f63·6f64·653e·3c2f··syslog.</code></ 
0005af70:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla 
0005af80:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ 
0005af90:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle 
0005afa0:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data 
0005afb0:·2d74·6172·6765·743d·2223·6964·6d32·3031··-target="#idm201 
0005afc0:·3435·2220·7461·6269·6e64·6578·3d22·3022··45"·tabindex="0" 
0005afd0:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a 
0005afe0:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa 
0005aff0:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti 
0005b000:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"· 
0005b010:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi 
0005b020:·6174·696f·6e20·4f53·4275·696c·6420·426c··ation·OSBuild·Bl 
0005b030:·7565·7072·696e·7420·736e·6970·7065·7420··ueprint·snippet· 
0005b040:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div· 
0005b050:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col 
0005b060:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"· 
0005b070:·6964·3d22·6964·6d32·3031·3435·223e·3c70··id="idm20145"><p 
0005b080:·7265·3e3c·636f·6465·3e0a·5b5b·7061·636b··re><code>.[[pack 
0005b090:·6167·6573·5d5d·0a6e·616d·6520·3d20·2272··ages]].name·=·"r 
0005b0a0:·7379·736c·6f67·220a·7665·7273·696f·6e20··syslog".version· 
0005b0b0:·3d20·222a·220a·3c2f·636f·6465·3e3c·2f70··=·"*".</code></p 
0005b0c0:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas 
0005b0d0:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe 
0005b0e0:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle= 
0005b0f0:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data- 
0005b100:·7461·7267·6574·3d22·2369·646d·3230·3134··target="#idm2014 
0005b110:·3622·2074·6162·696e·6465·783d·2230·2220··6"·tabindex="0"· 
0005b120:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar 
0005b130:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal 
0005b140:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ 
0005b150:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h 
0005b160:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia 
0005b170:·7469·6f6e·2073·6372·6970·7420·e287·b23c··tion·script·...< 
0005b180:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas 
Max diff block lines reached; 226650/254278 bytes (89.13%) of diff not shown.
32.4 KB
html2text {}
    
Offset 1741, 52 lines modifiedOffset 1741, 38 lines modified
1741 ··-·NIST-800-53-CM-6(a)1741 ··-·NIST-800-53-CM-6(a)
1742 ··-·enable_strategy1742 ··-·enable_strategy
1743 ··-·low_complexity1743 ··-·low_complexity
1744 ··-·low_disruption1744 ··-·low_disruption
1745 ··-·medium_severity1745 ··-·medium_severity
1746 ··-·no_reboot_needed1746 ··-·no_reboot_needed
1747 ··-·package_rsyslog_installed1747 ··-·package_rsyslog_installed
1748 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
1749 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
1750 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
1751 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
1752 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
1753 dnf·install·rsyslog 
1754 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
1755 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
1756 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
1757 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
1758 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
1759 package·--add=rsyslog 
1760 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81748 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
1761 [[packages]]1749 [[packages]]
1762 name·=·"rsyslog"1750 name·=·"rsyslog"
1763 version·=·"*"1751 version·=·"*"
1764 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
1765 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
1766 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
1767 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
1768 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
1769 package·install·rsyslog 
1770 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81752 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1771 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1753 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1772 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1754 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1773 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1755 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1774 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1756 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1775 include·install_rsyslog1757 include·install_rsyslog
  
1776 class·install_rsyslog·{1758 class·install_rsyslog·{
1777 ··package·{·'rsyslog':1759 ··package·{·'rsyslog':
1778 ····ensure·=>·'installed',1760 ····ensure·=>·'installed',
1779 ··}1761 ··}
1780 }1762 }
 1763 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 1764 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1765 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1766 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1767 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 1768 package·install·rsyslog
1781 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81769 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1782 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1770 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1783 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1771 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1784 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1772 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1785 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1773 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1786 #·Remediation·is·applicable·only·in·certain·platforms1774 #·Remediation·is·applicable·only·in·certain·platforms
1787 if·rpm·--quiet·-q·kernel;·then1775 if·rpm·--quiet·-q·kernel;·then
Offset 1794, 14 lines modifiedOffset 1780, 28 lines modified
1794 if·!·rpm·-q·--quiet·"rsyslog"·;·then1780 if·!·rpm·-q·--quiet·"rsyslog"·;·then
1795 ····dnf·install·-y·"rsyslog"1781 ····dnf·install·-y·"rsyslog"
1796 fi1782 fi
  
1797 else1783 else
1798 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'1784 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
1799 fi1785 fi
 1786 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 1787 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1788 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1789 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1790 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 1791 package·--add=rsyslog
 1792 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 1793 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1794 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1795 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1796 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 1797 dnf·install·rsyslog
1800 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·r\x8rs\x8sy\x8ys\x8sl\x8lo\x8og\x8g·S\x8Se\x8er\x8rv\x8vi\x8ic\x8ce\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*1798 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·r\x8rs\x8sy\x8ys\x8sl\x8lo\x8og\x8g·S\x8Se\x8er\x8rv\x8vi\x8ic\x8ce\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
1801 The·rsyslog·service·provides·syslog-style·logging·by·default·on·Red·Hat·Enterprise·Linux·10.·The·rsyslog·service·can·be·enabled·with·the·following·command:1799 The·rsyslog·service·provides·syslog-style·logging·by·default·on·Red·Hat·Enterprise·Linux·10.·The·rsyslog·service·can·be·enabled·with·the·following·command:
1802 $·sudo·systemctl·enable·rsyslog.service1800 $·sudo·systemctl·enable·rsyslog.service
1803 Rationale:··The·rsyslog·service·must·be·running·in·order·to·provide·logging·services,·which·are·essential·to·system·administration.1801 Rationale:··The·rsyslog·service·must·be·running·in·order·to·provide·logging·services,·which·are·essential·to·system·administration.
1804 Severity: ··medium1802 Severity: ··medium
1805 Rule·ID:····xccdf_org.ssgproject.content_rule_service_rsyslog_enabled1803 Rule·ID:····xccdf_org.ssgproject.content_rule_service_rsyslog_enabled
1806 ············_\x8c_\x8i_\x8s_\x8-_\x8c_\x8s_\x8c········1,·12,·13,·14,·15,·16,·2,·3,·5,·6,·7,·8,·91804 ············_\x8c_\x8i_\x8s_\x8-_\x8c_\x8s_\x8c········1,·12,·13,·14,·15,·16,·2,·3,·5,·6,·7,·8,·9
Offset 1857, 34 lines modifiedOffset 1857, 34 lines modified
1857 ··-·medium_severity1857 ··-·medium_severity
1858 ··-·no_reboot_needed1858 ··-·no_reboot_needed
1859 ··-·service_rsyslog_enabled1859 ··-·service_rsyslog_enabled
1860 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81860 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
1861 [customizations.services]1861 [customizations.services]
1862 enabled·=·["rsyslog"]1862 enabled·=·["rsyslog"]
1863 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
1864 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
1865 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
1866 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
1867 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable 
  
1868 service·enable·rsyslog 
1869 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81863 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1870 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1864 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1871 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1865 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1872 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1866 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1873 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1867 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1874 include·enable_rsyslog1868 include·enable_rsyslog
  
1875 class·enable_rsyslog·{1869 class·enable_rsyslog·{
1876 ··service·{'rsyslog':1870 ··service·{'rsyslog':
1877 ····enable·=>·true,1871 ····enable·=>·true,
1878 ····ensure·=>·'running',1872 ····ensure·=>·'running',
1879 ··}1873 ··}
1880 }1874 }
 1875 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 1876 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1877 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1878 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1879 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
  
 1880 service·enable·rsyslog
1881 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81881 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1882 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1882 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1883 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1883 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1884 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1884 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
Max diff block lines reached; 28483/33123 bytes (85.99%) of diff not shown.
354 KB
./usr/share/doc/ssg-nondebian/ssg-cs10-guide-hipaa.html
    
Offset 18166, 78 lines modifiedOffset 18166, 78 lines modified
00046f50:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id00046f50:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
00046f60:·6d38·3635·3422·2074·6162·696e·6465·783d··m8654"·tabindex=00046f60:·6d38·3635·3422·2074·6162·696e·6465·783d··m8654"·tabindex=
00046f70:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button00046f70:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button
00046f80:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=00046f80:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=
00046f90:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A00046f90:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A
00046fa0:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea00046fa0:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea
00046fb0:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem00046fb0:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem
00046fc0:·6564·6961·7469·6f6e·2041·6e61·636f·6e64··ediation·Anacond 
00046fd0:·6120·736e·6970·7065·7420·e287·b23c·2f61··a·snippet·...</a 
00046fe0:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class= 
00046ff0:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse· 
00047000:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id 
00047010:·6d38·3635·3422·3e3c·7461·626c·6520·636c··m8654"><table·cl 
00047020:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table 
00047030:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b 
00047040:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co 
00047050:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th 
00047060:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th 
00047070:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t 
00047080:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup 
00047090:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6869··tion:</th><td>hi 
000470a0:·6768·3c2f·7464·3e3c·2f74·723e·3c74·723e··gh</td></tr><tr> 
000470b0:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th> 
000470c0:·3c74·643e·6661·6c73·653c·2f74·643e·3c2f··<td>false</td></ 
000470d0:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat 
000470e0:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena 
000470f0:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t 
00047100:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code> 
00047110:·0a70·6172·7420·2f76·6172·2f6c·6f67·2f61··.part·/var/log/a00046fc0:·6564·6961·7469·6f6e·204f·5342·7569·6c64··ediation·OSBuild
 00046fd0:·2042·6c75·6570·7269·6e74·2073·6e69·7070···Blueprint·snipp
 00046fe0:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d
 00046ff0:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-
 00047000:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps
 00047010:·6522·2069·643d·2269·646d·3836·3534·223e··e"·id="idm8654">
 00047020:·3c70·7265·3e3c·636f·6465·3e0a·5b5b·6375··<pre><code>.[[cu
 00047030:·7374·6f6d·697a·6174·696f·6e73·2e66·696c··stomizations.fil
 00047040:·6573·7973·7465·6d5d·5d0a·6d6f·756e·7470··esystem]].mountp
 00047050:·6f69·6e74·203d·2022·2f76·6172·2f6c·6f67··oint·=·"/var/log
 00047060:·2f61·7564·6974·220a·7369·7a65·203d·2031··/audit".size·=·1
 00047070:·3037·3337·3431·3832·3430·0a3c·2f63·6f64··0737418240.</cod
 00047080:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a
 00047090:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn-
 000470a0:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to
 000470b0:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"·
 000470c0:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
 000470d0:·6d38·3635·3522·2074·6162·696e·6465·783d··m8655"·tabindex=
 000470e0:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button
 000470f0:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=
 00047100:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A
 00047110:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea
 00047120:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem
 00047130:·6564·6961·7469·6f6e·2073·6372·6970·7420··ediation·script·
 00047140:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·
 00047150:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col
 00047160:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·
 00047170:·6964·3d22·6964·6d38·3635·3522·3e3c·7072··id="idm8655"><pr
 00047180:·653e·3c63·6f64·653e·0a6c·6f67·766f·6c20··e><code>.logvol·
 00047190:·2f76·6172·2f6c·6f67·2f61·7564·6974·2031··/var/log/audit·1
00047120:·7564·6974·0a3c·2f63·6f64·653e·3c2f·7072··udit.</code></pr000471a0:·3032·3430·0a3c·2f63·6f64·653e·3c2f·7072··0240.</code></pr
00047130:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class000471b0:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class
00047140:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes000471c0:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes
00047150:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle="000471d0:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle="
00047160:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t000471e0:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t
00047170:·6172·6765·743d·2223·6964·6d38·3635·3522··arget="#idm8655" 
00047180:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro 
00047190:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria 
000471a0:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false 
000471b0:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat 
000471c0:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre 
000471d0:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati 
000471e0:·6f6e·204f·5342·7569·6c64·2042·6c75·6570··on·OSBuild·Bluep 
000471f0:·7269·6e74·2073·6e69·7070·6574·20e2·87b2··rint·snippet·... 
00047200:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla 
00047210:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap 
00047220:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id= 
00047230:·2269·646d·3836·3535·223e·3c70·7265·3e3c··"idm8655"><pre>< 
00047240:·636f·6465·3e0a·5b5b·6375·7374·6f6d·697a··code>.[[customiz 
00047250:·6174·696f·6e73·2e66·696c·6573·7973·7465··ations.filesyste 
00047260:·6d5d·5d0a·6d6f·756e·7470·6f69·6e74·203d··m]].mountpoint·= 
00047270:·2022·2f76·6172·2f6c·6f67·2f61·7564·6974···"/var/log/audit 
00047280:·220a·7369·7a65·203d·2031·3037·3337·3431··".size·=·1073741 
00047290:·3832·3430·0a3c·2f63·6f64·653e·3c2f·7072··8240.</code></pr 
000472a0:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class 
000472b0:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes 
000472c0:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle=" 
000472d0:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t 
000472e0:·6172·6765·743d·2223·6964·6d38·3635·3622··arget="#idm8656"000471f0:·6172·6765·743d·2223·6964·6d38·3635·3622··arget="#idm8656"
000472f0:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro00047200:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro
00047300:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria00047210:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria
00047310:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false00047220:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false
00047320:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat00047230:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat
00047330:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre00047240:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre
00047340:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati00047250:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati
00047350:·6f6e·2073·6372·6970·7420·e287·b23c·2f61··on·script·...</a 
00047360:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class= 
00047370:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse· 
00047380:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id 
00047390:·6d38·3635·3622·3e3c·7072·653e·3c63·6f64··m8656"><pre><cod 
000473a0:·653e·0a6c·6f67·766f·6c20·2f76·6172·2f6c··e>.logvol·/var/l 
000473b0:·6f67·2f61·7564·6974·2031·3032·3430·0a3c··og/audit·10240.<00047260:·6f6e·2041·6e61·636f·6e64·6120·736e·6970··on·Anaconda·snip
 00047270:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br><
 00047280:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
 00047290:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap
 000472a0:·7365·2220·6964·3d22·6964·6d38·3635·3622··se"·id="idm8656"
 000472b0:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t
 000472c0:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip
 000472d0:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere
 000472e0:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense
 000472f0:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl
 00047300:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l
 00047310:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
 00047320:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:<
 00047330:·2f74·683e·3c74·643e·6869·6768·3c2f·7464··/th><td>high</td
 00047340:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re
 00047350:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa
 00047360:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr
 00047370:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</
 00047380:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t
 00047390:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><
 000473a0:·7072·653e·3c63·6f64·653e·0a70·6172·7420··pre><code>.part·
 000473b0:·2f76·6172·2f6c·6f67·2f61·7564·6974·0a3c··/var/log/audit.<
000473c0:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di000473c0:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di
000473d0:·763e·3c2f·6469·763e·3c2f·7464·3e3c·2f74··v></div></td></t000473d0:·763e·3c2f·6469·763e·3c2f·7464·3e3c·2f74··v></div></td></t
000473e0:·723e·3c2f·7462·6f64·793e·3c2f·7461·626c··r></tbody></tabl000473e0:·723e·3c2f·7462·6f64·793e·3c2f·7461·626c··r></tbody></tabl
000473f0:·653e·3c2f·7464·3e3c·2f74·723e·3c74·7220··e></td></tr><tr·000473f0:·653e·3c2f·7464·3e3c·2f74·723e·3c74·7220··e></td></tr><tr·
00047400:·6461·7461·2d74·742d·6964·3d22·6368·696c··data-tt-id="chil00047400:·6461·7461·2d74·742d·6964·3d22·6368·696c··data-tt-id="chil
00047410:·6472·656e·2d78·6363·6466·5f6f·7267·2e73··dren-xccdf_org.s00047410:·6472·656e·2d78·6363·6466·5f6f·7267·2e73··dren-xccdf_org.s
Max diff block lines reached; 309566/319390 bytes (96.92%) of diff not shown.
41.8 KB
html2text {}
    
Offset 723, 29 lines modifiedOffset 723, 29 lines modified
723 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·AU-4,·SC-5(2)723 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·AU-4,·SC-5(2)
724 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-4,·PR.PT-1,·PR.PT-4724 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-4,·PR.PT-1,·PR.PT-4
725 ············_\x8o_\x8s_\x8p_\x8p···········FMT_SMF_EXT.1725 ············_\x8o_\x8s_\x8p_\x8p···········FMT_SMF_EXT.1
726 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000341-GPOS-00132,·SRG-OS-000480-GPOS-00227726 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000341-GPOS-00132,·SRG-OS-000480-GPOS-00227
727 ············_\x8a_\x8p_\x8p_\x8-_\x8s_\x8r_\x8g_\x8-_\x8c_\x8t_\x8r····SRG-APP-000357-CTR-000800727 ············_\x8a_\x8p_\x8p_\x8-_\x8s_\x8r_\x8g_\x8-_\x8c_\x8t_\x8r····SRG-APP-000357-CTR-000800
728 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R71728 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R71
729 ············_\x8c_\x8i_\x8s············1.1.2.7.1729 ············_\x8c_\x8i_\x8s············1.1.2.7.1
730 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
731 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
732 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high 
733 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
734 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
735 part·/var/log/audit 
736 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8730 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
737 [[customizations.filesystem]]731 [[customizations.filesystem]]
738 mountpoint·=·"/var/log/audit"732 mountpoint·=·"/var/log/audit"
739 size·=·10737418240733 size·=·10737418240
740 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8734 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
741 logvol·/var/log/audit·10240735 logvol·/var/log/audit·10240
 736 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 737 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 738 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high
 739 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 740 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 741 part·/var/log/audit
742 Group  ·GNOME·Desktop·Environment·  Group·contains·1·rule742 Group  ·GNOME·Desktop·Environment·  Group·contains·1·rule
743 _\x8[_\x8r_\x8e_\x8f_\x8]  ·GNOME·is·a·graphical·desktop·environment·bundled·with·many·Linux·distributions·that·allow·users·to·easily·interact·with·the·operating·system·graphically·rather·than·textually.·The·GNOME·Graphical·Display·Manager·(GDM)·provides·login,·logout,·and·user·switching·contexts·as·well·as·display·server·management.743 _\x8[_\x8r_\x8e_\x8f_\x8]  ·GNOME·is·a·graphical·desktop·environment·bundled·with·many·Linux·distributions·that·allow·users·to·easily·interact·with·the·operating·system·graphically·rather·than·textually.·The·GNOME·Graphical·Display·Manager·(GDM)·provides·login,·logout,·and·user·switching·contexts·as·well·as·display·server·management.
  
744 GNOME·is·developed·by·the·GNOME·Project·and·is·considered·the·default·Red·Hat·Graphical·environment.744 GNOME·is·developed·by·the·GNOME·Project·and·is·considered·the·default·Red·Hat·Graphical·environment.
  
745 For·more·information·on·GNOME·and·the·GNOME·Project,·see·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8w\x8w_\x8w\x8w_\x8w\x8w_\x8.\x8._\x8g\x8g_\x8n\x8n_\x8o\x8o_\x8m\x8m_\x8e\x8e_\x8.\x8._\x8o\x8o_\x8r\x8r_\x8g\x8g.745 For·more·information·on·GNOME·and·the·GNOME·Project,·see·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8w\x8w_\x8w\x8w_\x8w\x8w_\x8.\x8._\x8g\x8g_\x8n\x8n_\x8o\x8o_\x8m\x8m_\x8e\x8e_\x8.\x8._\x8o\x8o_\x8r\x8r_\x8g\x8g.
746 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·M\x8Ma\x8ak\x8ke\x8e·s\x8su\x8ur\x8re\x8e·t\x8th\x8ha\x8at\x8t·t\x8th\x8he\x8e·d\x8dc\x8co\x8on\x8nf\x8f·d\x8da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8es\x8s·a\x8ar\x8re\x8e·u\x8up\x8p-\x8-t\x8to\x8o-\x8-d\x8da\x8at\x8te\x8e·w\x8wi\x8it\x8th\x8h·r\x8re\x8eg\x8ga\x8ar\x8rd\x8ds\x8s·t\x8to\x8o·r\x8re\x8es\x8sp\x8pe\x8ec\x8ct\x8ti\x8iv\x8ve\x8e·k\x8ke\x8ey\x8yf\x8fi\x8il\x8le\x8es\x8s·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*746 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·M\x8Ma\x8ak\x8ke\x8e·s\x8su\x8ur\x8re\x8e·t\x8th\x8ha\x8at\x8t·t\x8th\x8he\x8e·d\x8dc\x8co\x8on\x8nf\x8f·d\x8da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8es\x8s·a\x8ar\x8re\x8e·u\x8up\x8p-\x8-t\x8to\x8o-\x8-d\x8da\x8at\x8te\x8e·w\x8wi\x8it\x8th\x8h·r\x8re\x8eg\x8ga\x8ar\x8rd\x8ds\x8s·t\x8to\x8o·r\x8re\x8es\x8sp\x8pe\x8ec\x8ct\x8ti\x8iv\x8ve\x8e·k\x8ke\x8ey\x8yf\x8fi\x8il\x8le\x8es\x8s·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
Offset 1427, 14 lines modifiedOffset 1427, 34 lines modified
1427 ··-·medium_severity1427 ··-·medium_severity
1428 ··-·no_reboot_needed1428 ··-·no_reboot_needed
1429 ··-·service_debug-shell_disabled1429 ··-·service_debug-shell_disabled
1430 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81430 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
1431 [customizations.services]1431 [customizations.services]
1432 masked·=·["debug-shell"]1432 masked·=·["debug-shell"]
 1433 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 1434 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1435 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1436 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1437 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 1438 include·disable_debug-shell
  
 1439 class·disable_debug-shell·{
 1440 ··service·{'debug-shell':
 1441 ····enable·=>·false,
 1442 ····ensure·=>·'stopped',
 1443 ··}
 1444 }
 1445 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 1446 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1447 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1448 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1449 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
  
 1450 service·disable·debug-shell
1433 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81451 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1434 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1452 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1435 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium1453 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
1436 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true1454 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
1437 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable1455 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
1438 apiVersion:·machineconfiguration.openshift.io/v11456 apiVersion:·machineconfiguration.openshift.io/v1
1439 kind:·MachineConfig1457 kind:·MachineConfig
Offset 1446, 34 lines modifiedOffset 1466, 14 lines modified
1446 ······units:1466 ······units:
1447 ······-·name:·debug-shell.service1467 ······-·name:·debug-shell.service
1448 ········enabled:·false1468 ········enabled:·false
1449 ········mask:·true1469 ········mask:·true
1450 ······-·name:·debug-shell.socket1470 ······-·name:·debug-shell.socket
1451 ········enabled:·false1471 ········enabled:·false
1452 ········mask:·true1472 ········mask:·true
1453 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
1454 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
1455 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
1456 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
1457 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable 
  
1458 service·disable·debug-shell 
1459 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
1460 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
1461 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
1462 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
1463 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
1464 include·disable_debug-shell 
  
1465 class·disable_debug-shell·{ 
1466 ··service·{'debug-shell': 
1467 ····enable·=>·false, 
1468 ····ensure·=>·'stopped', 
1469 ··} 
1470 } 
1471 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81473 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1472 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1474 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1473 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1475 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1474 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1476 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1475 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable1477 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
1476 #·Remediation·is·applicable·only·in·certain·platforms1478 #·Remediation·is·applicable·only·in·certain·platforms
1477 if·rpm·--quiet·-q·kernel;·then1479 if·rpm·--quiet·-q·kernel;·then
Offset 3423, 52 lines modifiedOffset 3423, 38 lines modified
3423 ··-·NIST-800-53-CM-6(a)3423 ··-·NIST-800-53-CM-6(a)
3424 ··-·enable_strategy3424 ··-·enable_strategy
3425 ··-·low_complexity3425 ··-·low_complexity
3426 ··-·low_disruption3426 ··-·low_disruption
3427 ··-·medium_severity3427 ··-·medium_severity
3428 ··-·no_reboot_needed3428 ··-·no_reboot_needed
3429 ··-·package_rsyslog_installed3429 ··-·package_rsyslog_installed
3430 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
3431 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
3432 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
3433 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
3434 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
3435 dnf·install·rsyslog 
3436 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
3437 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
3438 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
3439 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
3440 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
Max diff block lines reached; 37375/42769 bytes (87.39%) of diff not shown.
650 KB
./usr/share/doc/ssg-nondebian/ssg-cs10-guide-ism_o.html
    
Offset 15275, 207 lines modifiedOffset 15275, 207 lines modified
0003baa0:·6574·3d22·2369·646d·3733·3332·2220·7461··et="#idm7332"·ta0003baa0:·6574·3d22·2369·646d·3733·3332·2220·7461··et="#idm7332"·ta
0003bab0:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=0003bab0:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
0003bac0:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex0003bac0:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
0003bad0:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t0003bad0:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
0003bae0:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t0003bae0:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
0003baf0:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="0003baf0:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
0003bb00:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·0003bb00:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
 0003bb10:·4f53·4275·696c·6420·426c·7565·7072·696e··OSBuild·Blueprin
 0003bb20:·7420·736e·6970·7065·7420·e287·b23c·2f61··t·snippet·...</a
 0003bb30:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
 0003bb40:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
 0003bb50:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
 0003bb60:·6d37·3333·3222·3e3c·7072·653e·3c63·6f64··m7332"><pre><cod
 0003bb70:·653e·0a5b·5b70·6163·6b61·6765·735d·5d0a··e>.[[packages]].
 0003bb80:·6e61·6d65·203d·2022·6169·6465·220a·7665··name·=·"aide".ve
 0003bb90:·7273·696f·6e20·3d20·222a·220a·3c2f·636f··rsion·=·"*".</co
0003bb10:·7363·7269·7074·20e2·87b2·3c2f·613e·3c62··script·...</a><b 
0003bb20:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa 
0003bb30:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col 
0003bb40:·6c61·7073·6522·2069·643d·2269·646d·3733··lapse"·id="idm73 
0003bb50:·3332·223e·3c74·6162·6c65·2063·6c61·7373··32"><table·class 
0003bb60:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st 
0003bb70:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord 
0003bb80:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde 
0003bb90:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co 
0003bba0:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t 
0003bbb0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr>< 
0003bbc0:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio 
0003bbd0:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</ 
0003bbe0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
0003bbf0:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td> 
0003bc00:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr>< 
0003bc10:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy: 
0003bc20:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable< 
0003bc30:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table 
0003bc40:·3e3c·7072·653e·3c63·6f64·653e·0a64·6e66··><pre><code>.dnf 
0003bc50:·2069·6e73·7461·6c6c·2061·6964·650a·3c2f···install·aide.</ 
0003bc60:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div0003bba0:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div><
0003bc70:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b0003bbb0:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn
0003bc80:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data0003bbc0:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t
0003bc90:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps0003bbd0:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse"
0003bca0:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="0003bbe0:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i
0003bcb0:·2369·646d·3733·3333·2220·7461·6269·6e64··#idm7333"·tabind0003bbf0:·646d·3733·3333·2220·7461·6269·6e64·6578··dm7333"·tabindex
0003bcc0:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but0003bc00:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto
0003bcd0:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand0003bc10:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded
0003bce0:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title0003bc20:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="
0003bcf0:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re0003bc30:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve
0003bd00:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">0003bc40:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re
0003bd10:·5265·6d65·6469·6174·696f·6e20·416e·6163··Remediation·Anac0003bc50:·6d65·6469·6174·696f·6e20·5075·7070·6574··mediation·Puppet
0003bd20:·6f6e·6461·2073·6e69·7070·6574·20e2·87b2··onda·snippet·...0003bc60:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>
0003bd30:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla0003bc70:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="
0003bd40:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap0003bc80:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c
0003bd50:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=0003bc90:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm
0003bd60:·2269·646d·3733·3333·223e·3c74·6162·6c65··"idm7333"><table0003bca0:·3733·3333·223e·3c74·6162·6c65·2063·6c61··7333"><table·cla
0003bd70:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta0003bcb0:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-
0003bd80:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl0003bcc0:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo
0003bd90:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table0003bcd0:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con
0003bda0:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>0003bce0:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>
0003bdb0:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<0003bcf0:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>
0003bdc0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>0003bd00:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
0003bdd0:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis0003bd10:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt
0003bde0:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td0003bd20:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low
 0003bd30:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
 0003bd40:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t
 0003bd50:·643e·6661·6c73·653c·2f74·643e·3c2f·7472··d>false</td></tr
 0003bd60:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg
 0003bd70:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl
 0003bd80:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab
 0003bd90:·6c65·3e3c·7072·653e·3c63·6f64·653e·696e··le><pre><code>in
 0003bda0:·636c·7564·6520·696e·7374·616c·6c5f·6169··clude·install_ai
 0003bdb0:·6465·0a0a·636c·6173·7320·696e·7374·616c··de..class·instal
 0003bdc0:·6c5f·6169·6465·207b·0a20·2070·6163·6b61··l_aide·{.··packa
 0003bdd0:·6765·207b·2027·6169·6465·273a·0a20·2020··ge·{·'aide':.···
 0003bde0:·2065·6e73·7572·6520·3d26·6774·3b20·2769···ensure·=&gt;·'i
 0003bdf0:·6e73·7461·6c6c·6564·272c·0a20·207d·0a7d··nstalled',.··}.}
 0003be00:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></
 0003be10:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt
 0003be20:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d
 0003be30:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll
 0003be40:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
 0003be50:·743d·2223·6964·6d37·3333·3422·2074·6162··t="#idm7334"·tab
 0003be60:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
 0003be70:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
 0003be80:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
 0003be90:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
 0003bea0:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
 0003beb0:·2122·3e52·656d·6564·6961·7469·6f6e·2073··!">Remediation·s
 0003bec0:·6372·6970·7420·e287·b23c·2f61·3e3c·6272··cript·...</a><br
 0003bed0:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
 0003bee0:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
 0003bef0:·6170·7365·2220·6964·3d22·6964·6d37·3333··apse"·id="idm733
 0003bf00:·3422·3e3c·7461·626c·6520·636c·6173·733d··4"><table·class=
 0003bf10:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str
 0003bf20:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde
 0003bf30:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden
 0003bf40:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com
 0003bf50:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td
0003bdf0:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t0003bf60:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
0003be00:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t 
0003be10:·683e·3c74·643e·6661·6c73·653c·2f74·643e··h><td>false</td>0003bf70:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption
 0003bf80:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
0003be20:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str0003bf90:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e52··d></tr><tr><th>R
0003be30:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e 
0003be40:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr>< 
0003be50:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod 
0003be60:·653e·0a70·6163·6b61·6765·202d·2d61·6464··e>.package·--add 
0003be70:·3d61·6964·650a·3c2f·636f·6465·3e3c·2f70··=aide.</code></p 
0003be80:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas 
0003be90:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe 
0003bea0:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle= 
0003beb0:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data- 
0003bec0:·7461·7267·6574·3d22·2369·646d·3733·3334··target="#idm7334 
0003bed0:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r 
0003bee0:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari 
0003bef0:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals 
0003bf00:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa 
0003bf10:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr 
0003bf20:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat 
0003bf30:·696f·6e20·4f53·4275·696c·6420·426c·7565··ion·OSBuild·Blue 
0003bf40:·7072·696e·7420·736e·6970·7065·7420·e287··print·snippet·..0003bfa0:·6562·6f6f·743a·3c2f·7468·3e3c·7464·3e66··eboot:</th><td>f
 0003bfb0:·616c·7365·3c2f·7464·3e3c·2f74·723e·3c74··alse</td></tr><t
 0003bfc0:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<
 0003bfd0:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</
 0003bfe0:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table>
 0003bff0:·3c70·7265·3e3c·636f·6465·3e0a·7061·636b··<pre><code>.pack
 0003c000:·6167·6520·696e·7374·616c·6c20·6169·6465··age·install·aide
 0003c010:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></
Max diff block lines reached; 562106/589320 bytes (95.38%) of diff not shown.
74.6 KB
html2text {}
    
Offset 158, 52 lines modifiedOffset 158, 38 lines modified
158 ··-·PCI-DSSv4-11.5.2158 ··-·PCI-DSSv4-11.5.2
159 ··-·enable_strategy159 ··-·enable_strategy
160 ··-·low_complexity160 ··-·low_complexity
161 ··-·low_disruption161 ··-·low_disruption
162 ··-·medium_severity162 ··-·medium_severity
163 ··-·no_reboot_needed163 ··-·no_reboot_needed
164 ··-·package_aide_installed164 ··-·package_aide_installed
165 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
166 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
167 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
168 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
169 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
170 dnf·install·aide 
171 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
172 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
173 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
174 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
175 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
176 package·--add=aide 
177 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8165 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
178 [[packages]]166 [[packages]]
179 name·=·"aide"167 name·=·"aide"
180 version·=·"*"168 version·=·"*"
181 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
182 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
183 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
184 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
185 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
186 package·install·aide 
187 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8169 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
188 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low170 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
189 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low171 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
190 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false172 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
191 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable173 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
192 include·install_aide174 include·install_aide
  
193 class·install_aide·{175 class·install_aide·{
194 ··package·{·'aide':176 ··package·{·'aide':
195 ····ensure·=>·'installed',177 ····ensure·=>·'installed',
196 ··}178 ··}
197 }179 }
 180 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 181 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 182 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 183 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 184 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 185 package·install·aide
198 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8186 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
199 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low187 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
200 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low188 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
201 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false189 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
202 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable190 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
203 #·Remediation·is·applicable·only·in·certain·platforms191 #·Remediation·is·applicable·only·in·certain·platforms
204 if·rpm·--quiet·-q·kernel;·then192 if·rpm·--quiet·-q·kernel;·then
Offset 211, 14 lines modifiedOffset 197, 28 lines modified
211 if·!·rpm·-q·--quiet·"aide"·;·then197 if·!·rpm·-q·--quiet·"aide"·;·then
212 ····dnf·install·-y·"aide"198 ····dnf·install·-y·"aide"
213 fi199 fi
  
214 else200 else
215 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'201 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
216 fi202 fi
 203 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 204 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 205 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 206 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 207 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 208 package·--add=aide
 209 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 210 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 211 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 212 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 213 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 214 dnf·install·aide
217 Group  ·Federal·Information·Processing·Standard·(FIPS)·  Group·contains·2·rules215 Group  ·Federal·Information·Processing·Standard·(FIPS)·  Group·contains·2·rules
218 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·Federal·Information·Processing·Standard·(FIPS)·is·a·computer·security·standard·which·is·developed·by·the·U.S.·Government·and·industry·working·groups·to·validate·the·quality·of·cryptographic·modules.·The·FIPS·standard·provides·four·security·levels·to·ensure·adequate·coverage·of·different·industries,·implementation·of·cryptographic·modules,·and·organizational·sizes·and·requirements.216 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·Federal·Information·Processing·Standard·(FIPS)·is·a·computer·security·standard·which·is·developed·by·the·U.S.·Government·and·industry·working·groups·to·validate·the·quality·of·cryptographic·modules.·The·FIPS·standard·provides·four·security·levels·to·ensure·adequate·coverage·of·different·industries,·implementation·of·cryptographic·modules,·and·organizational·sizes·and·requirements.
  
219 FIPS·140-2·is·the·current·standard·for·validating·that·mechanisms·used·to·access·cryptographic·modules·utilize·authentication·that·meets·industry·and·government·requirements.·For·government·systems,·this·allows·Security·Levels·1,·2,·3,·or·4·for·use·on·Red·Hat·Enterprise·Linux·10.217 FIPS·140-2·is·the·current·standard·for·validating·that·mechanisms·used·to·access·cryptographic·modules·utilize·authentication·that·meets·industry·and·government·requirements.·For·government·systems,·this·allows·Security·Levels·1,·2,·3,·or·4·for·use·on·Red·Hat·Enterprise·Linux·10.
  
220 See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8c\x8c_\x8s\x8s_\x8r\x8r_\x8c\x8c_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8l\x8l_\x8i\x8i_\x8c\x8c_\x8a\x8a_\x8t\x8t_\x8i\x8i_\x8o\x8o_\x8n\x8n_\x8s\x8s_\x8/\x8/_\x8P\x8P_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x8h\x8h_\x8t\x8t_\x8m\x8m_\x8l\x8l·for·more·information.218 See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8c\x8c_\x8s\x8s_\x8r\x8r_\x8c\x8c_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8l\x8l_\x8i\x8i_\x8c\x8c_\x8a\x8a_\x8t\x8t_\x8i\x8i_\x8o\x8o_\x8n\x8n_\x8s\x8s_\x8/\x8/_\x8P\x8P_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x8h\x8h_\x8t\x8t_\x8m\x8m_\x8l\x8l·for·more·information.
221 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8de\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*219 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8de\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
Offset 521, 52 lines modifiedOffset 521, 38 lines modified
521 ··-·PCI-DSSv4-2.2.6521 ··-·PCI-DSSv4-2.2.6
522 ··-·enable_strategy522 ··-·enable_strategy
523 ··-·low_complexity523 ··-·low_complexity
524 ··-·low_disruption524 ··-·low_disruption
525 ··-·medium_severity525 ··-·medium_severity
526 ··-·no_reboot_needed526 ··-·no_reboot_needed
527 ··-·package_sudo_installed527 ··-·package_sudo_installed
528 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
529 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
530 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
531 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
532 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
533 dnf·install·sudo 
534 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
535 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
536 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
537 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
538 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
539 package·--add=sudo 
540 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8528 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
541 [[packages]]529 [[packages]]
542 name·=·"sudo"530 name·=·"sudo"
543 version·=·"*"531 version·=·"*"
544 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
545 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
546 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
547 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
548 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
549 package·install·sudo 
550 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8532 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
551 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low533 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
552 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low534 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
553 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false535 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
554 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable536 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
Max diff block lines reached; 71294/76391 bytes (93.33%) of diff not shown.
651 KB
./usr/share/doc/ssg-nondebian/ssg-cs10-guide-ism_o_secret.html
    
Offset 15278, 208 lines modifiedOffset 15278, 208 lines modified
0003bad0:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe0003bad0:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
0003bae0:·743d·2223·6964·6d37·3333·3222·2074·6162··t="#idm7332"·tab0003bae0:·743d·2223·6964·6d37·3333·3222·2074·6162··t="#idm7332"·tab
0003baf0:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="0003baf0:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
0003bb00:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp0003bb00:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
0003bb10:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti0003bb10:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
0003bb20:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to0003bb20:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
0003bb30:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#0003bb30:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
0003bb40:·2122·3e52·656d·6564·6961·7469·6f6e·2073··!">Remediation·s0003bb40:·2122·3e52·656d·6564·6961·7469·6f6e·204f··!">Remediation·O
 0003bb50:·5342·7569·6c64·2042·6c75·6570·7269·6e74··SBuild·Blueprint
 0003bb60:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>
 0003bb70:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="
 0003bb80:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c
 0003bb90:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm
 0003bba0:·3733·3332·223e·3c70·7265·3e3c·636f·6465··7332"><pre><code
 0003bbb0:·3e0a·5b5b·7061·636b·6167·6573·5d5d·0a6e··>.[[packages]].n
 0003bbc0:·616d·6520·3d20·2261·6964·6522·0a76·6572··ame·=·"aide".ver
 0003bbd0:·7369·6f6e·203d·2022·2a22·0a3c·2f63·6f64··sion·=·"*".</cod
0003bb50:·6372·6970·7420·e287·b23c·2f61·3e3c·6272··cript·...</a><br 
0003bb60:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan 
0003bb70:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll 
0003bb80:·6170·7365·2220·6964·3d22·6964·6d37·3333··apse"·id="idm733 
0003bb90:·3222·3e3c·7461·626c·6520·636c·6173·733d··2"><table·class= 
0003bba0:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str 
0003bbb0:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde 
0003bbc0:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden 
0003bbd0:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com 
0003bbe0:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td 
0003bbf0:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t 
0003bc00:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption 
0003bc10:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t 
0003bc20:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e52··d></tr><tr><th>R 
0003bc30:·6562·6f6f·743a·3c2f·7468·3e3c·7464·3e66··eboot:</th><td>f 
0003bc40:·616c·7365·3c2f·7464·3e3c·2f74·723e·3c74··alse</td></tr><t 
0003bc50:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:< 
0003bc60:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</ 
0003bc70:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table> 
0003bc80:·3c70·7265·3e3c·636f·6465·3e0a·646e·6620··<pre><code>.dnf· 
0003bc90:·696e·7374·616c·6c20·6169·6465·0a3c·2f63··install·aide.</c 
0003bca0:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div>0003bbe0:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a
0003bcb0:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt0003bbf0:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn-
0003bcc0:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data-0003bc00:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to
0003bcd0:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse0003bc10:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"·
0003bce0:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#0003bc20:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
0003bcf0:·6964·6d37·3333·3322·2074·6162·696e·6465··idm7333"·tabinde0003bc30:·6d37·3333·3322·2074·6162·696e·6465·783d··m7333"·tabindex=
0003bd00:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt0003bc40:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button
0003bd10:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande0003bc50:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=
0003bd20:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=0003bc60:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A
0003bd30:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev0003bc70:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea
0003bd40:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R0003bc80:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem
0003bd50:·656d·6564·6961·7469·6f6e·2041·6e61·636f··emediation·Anaco0003bc90:·6564·6961·7469·6f6e·2050·7570·7065·7420··ediation·Puppet·
0003bd60:·6e64·6120·736e·6970·7065·7420·e287·b23c··nda·snippet·...<0003bca0:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><
0003bd70:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas0003bcb0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
0003bd80:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps0003bcc0:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
0003bd90:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="0003bcd0:·6c6c·6170·7365·2220·6964·3d22·6964·6d37··llapse"·id="idm7
0003bda0:·6964·6d37·3333·3322·3e3c·7461·626c·6520··idm7333"><table·0003bce0:·3333·3322·3e3c·7461·626c·6520·636c·6173··333"><table·clas
0003bdb0:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab0003bcf0:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s
0003bdc0:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table0003bd00:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor
0003bdd0:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-0003bd10:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond
0003bde0:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><0003bd20:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C
0003bdf0:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</0003bd30:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><
0003be00:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><0003bd40:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
0003be10:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr0003bd50:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti
0003be20:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>0003bd60:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<
 0003bd70:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 0003bd80:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td
 0003bd90:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr>
 0003bda0:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy
 0003bdb0:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable
 0003bdc0:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl
 0003bdd0:·653e·3c70·7265·3e3c·636f·6465·3e69·6e63··e><pre><code>inc
 0003bde0:·6c75·6465·2069·6e73·7461·6c6c·5f61·6964··lude·install_aid
 0003bdf0:·650a·0a63·6c61·7373·2069·6e73·7461·6c6c··e..class·install
 0003be00:·5f61·6964·6520·7b0a·2020·7061·636b·6167··_aide·{.··packag
 0003be10:·6520·7b20·2761·6964·6527·3a0a·2020·2020··e·{·'aide':.····
 0003be20:·656e·7375·7265·203d·2667·743b·2027·696e··ensure·=&gt;·'in
 0003be30:·7374·616c·6c65·6427·2c0a·2020·7d0a·7d0a··stalled',.··}.}.
 0003be40:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d
 0003be50:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn
 0003be60:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da
 0003be70:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla
 0003be80:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
 0003be90:·3d22·2369·646d·3733·3334·2220·7461·6269··="#idm7334"·tabi
 0003bea0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
 0003beb0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
 0003bec0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
 0003bed0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
 0003bee0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
 0003bef0:·223e·5265·6d65·6469·6174·696f·6e20·7363··">Remediation·sc
 0003bf00:·7269·7074·20e2·87b2·3c2f·613e·3c62·723e··ript·...</a><br>
 0003bf10:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
 0003bf20:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
 0003bf30:·7073·6522·2069·643d·2269·646d·3733·3334··pse"·id="idm7334
 0003bf40:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="
 0003bf50:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri
 0003bf60:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border
 0003bf70:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens
 0003bf80:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp
 0003bf90:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>
0003be30:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr0003bfa0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
0003be40:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th 
0003be50:·3e3c·7464·3e66·616c·7365·3c2f·7464·3e3c··><td>false</td><0003bfb0:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:
 0003bfc0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
0003be60:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra0003bfd0:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re
0003be70:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en0003bfe0:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa
0003be80:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></ 
0003be90:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code 
0003bea0:·3e0a·7061·636b·6167·6520·2d2d·6164·643d··>.package·--add= 
0003beb0:·6169·6465·0a3c·2f63·6f64·653e·3c2f·7072··aide.</code></pr 
0003bec0:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class 
0003bed0:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes 
0003bee0:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle=" 
0003bef0:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t 
0003bf00:·6172·6765·743d·2223·6964·6d37·3333·3422··arget="#idm7334" 
0003bf10:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro 
0003bf20:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria 
0003bf30:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false 
0003bf40:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat 
0003bf50:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre 
0003bf60:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati 
0003bf70:·6f6e·204f·5342·7569·6c64·2042·6c75·6570··on·OSBuild·Bluep 
0003bf80:·7269·6e74·2073·6e69·7070·6574·20e2·87b2··rint·snippet·...0003bff0:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr
 0003c000:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</
 0003c010:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t
 0003c020:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><
 0003c030:·7072·653e·3c63·6f64·653e·0a70·6163·6b61··pre><code>.packa
 0003c040:·6765·2069·6e73·7461·6c6c·2061·6964·650a··ge·install·aide.
 0003c050:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d
Max diff block lines reached; 562244/589596 bytes (95.36%) of diff not shown.
74.6 KB
html2text {}
    
Offset 159, 52 lines modifiedOffset 159, 38 lines modified
159 ··-·PCI-DSSv4-11.5.2159 ··-·PCI-DSSv4-11.5.2
160 ··-·enable_strategy160 ··-·enable_strategy
161 ··-·low_complexity161 ··-·low_complexity
162 ··-·low_disruption162 ··-·low_disruption
163 ··-·medium_severity163 ··-·medium_severity
164 ··-·no_reboot_needed164 ··-·no_reboot_needed
165 ··-·package_aide_installed165 ··-·package_aide_installed
166 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
167 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
168 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
169 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
170 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
171 dnf·install·aide 
172 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
173 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
174 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
175 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
176 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
177 package·--add=aide 
178 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8166 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
179 [[packages]]167 [[packages]]
180 name·=·"aide"168 name·=·"aide"
181 version·=·"*"169 version·=·"*"
182 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
183 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
184 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
185 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
186 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
187 package·install·aide 
188 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8170 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
189 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low171 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
190 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low172 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
191 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false173 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
192 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable174 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
193 include·install_aide175 include·install_aide
  
194 class·install_aide·{176 class·install_aide·{
195 ··package·{·'aide':177 ··package·{·'aide':
196 ····ensure·=>·'installed',178 ····ensure·=>·'installed',
197 ··}179 ··}
198 }180 }
 181 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 182 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 183 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 184 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 185 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 186 package·install·aide
199 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8187 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
200 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low188 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
201 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low189 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
202 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false190 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
203 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable191 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
204 #·Remediation·is·applicable·only·in·certain·platforms192 #·Remediation·is·applicable·only·in·certain·platforms
205 if·rpm·--quiet·-q·kernel;·then193 if·rpm·--quiet·-q·kernel;·then
Offset 212, 14 lines modifiedOffset 198, 28 lines modified
212 if·!·rpm·-q·--quiet·"aide"·;·then198 if·!·rpm·-q·--quiet·"aide"·;·then
213 ····dnf·install·-y·"aide"199 ····dnf·install·-y·"aide"
214 fi200 fi
  
215 else201 else
216 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'202 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
217 fi203 fi
 204 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 205 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 206 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 207 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 208 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 209 package·--add=aide
 210 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 211 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 212 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 213 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 214 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 215 dnf·install·aide
218 Group  ·Federal·Information·Processing·Standard·(FIPS)·  Group·contains·2·rules216 Group  ·Federal·Information·Processing·Standard·(FIPS)·  Group·contains·2·rules
219 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·Federal·Information·Processing·Standard·(FIPS)·is·a·computer·security·standard·which·is·developed·by·the·U.S.·Government·and·industry·working·groups·to·validate·the·quality·of·cryptographic·modules.·The·FIPS·standard·provides·four·security·levels·to·ensure·adequate·coverage·of·different·industries,·implementation·of·cryptographic·modules,·and·organizational·sizes·and·requirements.217 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·Federal·Information·Processing·Standard·(FIPS)·is·a·computer·security·standard·which·is·developed·by·the·U.S.·Government·and·industry·working·groups·to·validate·the·quality·of·cryptographic·modules.·The·FIPS·standard·provides·four·security·levels·to·ensure·adequate·coverage·of·different·industries,·implementation·of·cryptographic·modules,·and·organizational·sizes·and·requirements.
  
220 FIPS·140-2·is·the·current·standard·for·validating·that·mechanisms·used·to·access·cryptographic·modules·utilize·authentication·that·meets·industry·and·government·requirements.·For·government·systems,·this·allows·Security·Levels·1,·2,·3,·or·4·for·use·on·Red·Hat·Enterprise·Linux·10.218 FIPS·140-2·is·the·current·standard·for·validating·that·mechanisms·used·to·access·cryptographic·modules·utilize·authentication·that·meets·industry·and·government·requirements.·For·government·systems,·this·allows·Security·Levels·1,·2,·3,·or·4·for·use·on·Red·Hat·Enterprise·Linux·10.
  
221 See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8c\x8c_\x8s\x8s_\x8r\x8r_\x8c\x8c_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8l\x8l_\x8i\x8i_\x8c\x8c_\x8a\x8a_\x8t\x8t_\x8i\x8i_\x8o\x8o_\x8n\x8n_\x8s\x8s_\x8/\x8/_\x8P\x8P_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x8h\x8h_\x8t\x8t_\x8m\x8m_\x8l\x8l·for·more·information.219 See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8c\x8c_\x8s\x8s_\x8r\x8r_\x8c\x8c_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8l\x8l_\x8i\x8i_\x8c\x8c_\x8a\x8a_\x8t\x8t_\x8i\x8i_\x8o\x8o_\x8n\x8n_\x8s\x8s_\x8/\x8/_\x8P\x8P_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x8h\x8h_\x8t\x8t_\x8m\x8m_\x8l\x8l·for·more·information.
222 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8de\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*220 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8de\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
Offset 522, 52 lines modifiedOffset 522, 38 lines modified
522 ··-·PCI-DSSv4-2.2.6522 ··-·PCI-DSSv4-2.2.6
523 ··-·enable_strategy523 ··-·enable_strategy
524 ··-·low_complexity524 ··-·low_complexity
525 ··-·low_disruption525 ··-·low_disruption
526 ··-·medium_severity526 ··-·medium_severity
527 ··-·no_reboot_needed527 ··-·no_reboot_needed
528 ··-·package_sudo_installed528 ··-·package_sudo_installed
529 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
530 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
531 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
532 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
533 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
534 dnf·install·sudo 
535 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
536 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
537 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
538 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
539 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
540 package·--add=sudo 
541 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8529 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
542 [[packages]]530 [[packages]]
543 name·=·"sudo"531 name·=·"sudo"
544 version·=·"*"532 version·=·"*"
545 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
546 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
547 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
548 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
549 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
550 package·install·sudo 
551 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8533 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
552 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low534 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
553 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low535 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
554 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false536 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
555 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable537 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
Max diff block lines reached; 71294/76391 bytes (93.33%) of diff not shown.
651 KB
./usr/share/doc/ssg-nondebian/ssg-cs10-guide-ism_o_top_secret.html
    
Offset 15276, 207 lines modifiedOffset 15276, 207 lines modified
0003bab0:·7461·2d74·6172·6765·743d·2223·6964·6d37··ta-target="#idm70003bab0:·7461·2d74·6172·6765·743d·2223·6964·6d37··ta-target="#idm7
0003bac0:·3333·3222·2074·6162·696e·6465·783d·2230··332"·tabindex="00003bac0:·3333·3222·2074·6162·696e·6465·783d·2230··332"·tabindex="0
0003bad0:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·0003bad0:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
0003bae0:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f0003bae0:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
0003baf0:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act0003baf0:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
0003bb00:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"0003bb00:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
0003bb10:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed0003bb10:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
 0003bb20:·6961·7469·6f6e·204f·5342·7569·6c64·2042··iation·OSBuild·B
 0003bb30:·6c75·6570·7269·6e74·2073·6e69·7070·6574··lueprint·snippet
 0003bb40:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
 0003bb50:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
 0003bb60:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
 0003bb70:·2069·643d·2269·646d·3733·3332·223e·3c70···id="idm7332"><p
 0003bb80:·7265·3e3c·636f·6465·3e0a·5b5b·7061·636b··re><code>.[[pack
 0003bb90:·6167·6573·5d5d·0a6e·616d·6520·3d20·2261··ages]].name·=·"a
 0003bba0:·6964·6522·0a76·6572·7369·6f6e·203d·2022··ide".version·=·"
0003bb20:·6961·7469·6f6e·2073·6372·6970·7420·e287··iation·script·.. 
0003bb30:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl 
0003bb40:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla 
0003bb50:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id 
0003bb60:·3d22·6964·6d37·3333·3222·3e3c·7461·626c··="idm7332"><tabl 
0003bb70:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t 
0003bb80:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab 
0003bb90:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl 
0003bba0:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr 
0003bbb0:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity: 
0003bbc0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td 
0003bbd0:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di 
0003bbe0:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t 
0003bbf0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr>< 
0003bc00:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</ 
0003bc10:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td 
0003bc20:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St 
0003bc30:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td> 
0003bc40:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr> 
0003bc50:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co 
0003bc60:·6465·3e0a·646e·6620·696e·7374·616c·6c20··de>.dnf·install· 
0003bc70:·6169·6465·0a3c·2f63·6f64·653e·3c2f·7072··aide.</code></pr0003bbb0:·2a22·0a3c·2f63·6f64·653e·3c2f·7072·653e··*".</code></pre>
0003bc80:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class0003bbc0:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class="
0003bc90:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes0003bbd0:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success"
0003bca0:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle="0003bbe0:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co
0003bcb0:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t0003bbf0:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar
0003bcc0:·6172·6765·743d·2223·6964·6d37·3333·3322··arget="#idm7333"0003bc00:·6765·743d·2223·6964·6d37·3333·3322·2074··get="#idm7333"·t
0003bcd0:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro0003bc10:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
0003bce0:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria0003bc20:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
0003bcf0:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false0003bc30:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
0003bd00:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat0003bc40:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
0003bd10:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre0003bc50:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
0003bd20:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati0003bc60:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
0003bd30:·6f6e·2041·6e61·636f·6e64·6120·736e·6970··on·Anaconda·snip0003bc70:·2050·7570·7065·7420·736e·6970·7065·7420···Puppet·snippet·
0003bd40:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br><0003bc80:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·
0003bd50:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel0003bc90:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col
0003bd60:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap0003bca0:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·
0003bd70:·7365·2220·6964·3d22·6964·6d37·3333·3322··se"·id="idm7333"0003bcb0:·6964·3d22·6964·6d37·3333·3322·3e3c·7461··id="idm7333"><ta
0003bd80:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t0003bcc0:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table
0003bd90:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip0003bcd0:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t
0003bda0:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere0003bce0:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta
0003bdb0:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense0003bcf0:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><
0003bdc0:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl0003bd00:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit
0003bdd0:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l0003bd10:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</
0003bde0:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>0003bd20:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
0003bdf0:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:<0003bd30:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th>
 0003bd40:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
 0003bd50:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot:
 0003bd60:·3c2f·7468·3e3c·7464·3e66·616c·7365·3c2f··</th><td>false</
 0003bd70:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 0003bd80:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t
 0003bd90:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t
 0003bda0:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><
 0003bdb0:·636f·6465·3e69·6e63·6c75·6465·2069·6e73··code>include·ins
 0003bdc0:·7461·6c6c·5f61·6964·650a·0a63·6c61·7373··tall_aide..class
 0003bdd0:·2069·6e73·7461·6c6c·5f61·6964·6520·7b0a···install_aide·{.
 0003bde0:·2020·7061·636b·6167·6520·7b20·2761·6964····package·{·'aid
 0003bdf0:·6527·3a0a·2020·2020·656e·7375·7265·203d··e':.····ensure·=
 0003be00:·2667·743b·2027·696e·7374·616c·6c65·6427··&gt;·'installed'
 0003be10:·2c0a·2020·7d0a·7d0a·3c2f·636f·6465·3e3c··,.··}.}.</code><
 0003be20:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl
 0003be30:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc
 0003be40:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl
 0003be50:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat
 0003be60:·612d·7461·7267·6574·3d22·2369·646d·3733··a-target="#idm73
 0003be70:·3334·2220·7461·6269·6e64·6578·3d22·3022··34"·tabindex="0"
 0003be80:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
 0003be90:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
 0003bea0:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
 0003beb0:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
 0003bec0:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
 0003bed0:·6174·696f·6e20·7363·7269·7074·20e2·87b2··ation·script·...
 0003bee0:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
 0003bef0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
 0003bf00:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
 0003bf10:·2269·646d·3733·3334·223e·3c74·6162·6c65··"idm7334"><table
 0003bf20:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta
 0003bf30:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl
 0003bf40:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table
 0003bf50:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>
 0003bf60:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<
0003be00:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>0003bf70:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
 0003bf80:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis
 0003bf90:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td
 0003bfa0:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
 0003bfb0:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t
 0003bfc0:·683e·3c74·643e·6661·6c73·653c·2f74·643e··h><td>false</td>
0003be10:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb0003bfd0:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str
0003be20:·6f6f·743a·3c2f·7468·3e3c·7464·3e66·616c··oot:</th><td>fal0003bfe0:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e
 0003bff0:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr><
 0003c000:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod
 0003c010:·653e·0a70·6163·6b61·6765·2069·6e73·7461··e>.package·insta
 0003c020:·6c6c·2061·6964·650a·3c2f·636f·6465·3e3c··ll·aide.</code><
 0003c030:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl
 0003c040:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc
 0003c050:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl
 0003c060:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat
 0003c070:·612d·7461·7267·6574·3d22·2369·646d·3733··a-target="#idm73
 0003c080:·3335·2220·7461·6269·6e64·6578·3d22·3022··35"·tabindex="0"
 0003c090:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
 0003c0a0:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
 0003c0b0:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
 0003c0c0:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
 0003c0d0:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
 0003c0e0:·6174·696f·6e20·5368·656c·6c20·7363·7269··ation·Shell·scri
0003be30:·7365·3c2f·7464·3e3c·2f74·723e·3c74·723e··se</td></tr><tr> 
0003be40:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t 
0003be50:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td 
0003be60:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p 
0003be70:·7265·3e3c·636f·6465·3e0a·7061·636b·6167··re><code>.packag 
0003be80:·6520·2d2d·6164·643d·6169·6465·0a3c·2f63··e·--add=aide.</c 
Max diff block lines reached; 562658/589872 bytes (95.39%) of diff not shown.
74.6 KB
html2text {}
    
Offset 158, 52 lines modifiedOffset 158, 38 lines modified
158 ··-·PCI-DSSv4-11.5.2158 ··-·PCI-DSSv4-11.5.2
159 ··-·enable_strategy159 ··-·enable_strategy
160 ··-·low_complexity160 ··-·low_complexity
161 ··-·low_disruption161 ··-·low_disruption
162 ··-·medium_severity162 ··-·medium_severity
163 ··-·no_reboot_needed163 ··-·no_reboot_needed
164 ··-·package_aide_installed164 ··-·package_aide_installed
165 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
166 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
167 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
168 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
169 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
170 dnf·install·aide 
171 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
172 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
173 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
174 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
175 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
176 package·--add=aide 
177 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8165 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
178 [[packages]]166 [[packages]]
179 name·=·"aide"167 name·=·"aide"
180 version·=·"*"168 version·=·"*"
181 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
182 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
183 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
184 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
185 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
186 package·install·aide 
187 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8169 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
188 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low170 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
189 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low171 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
190 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false172 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
191 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable173 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
192 include·install_aide174 include·install_aide
  
193 class·install_aide·{175 class·install_aide·{
194 ··package·{·'aide':176 ··package·{·'aide':
195 ····ensure·=>·'installed',177 ····ensure·=>·'installed',
196 ··}178 ··}
197 }179 }
 180 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 181 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 182 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 183 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 184 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 185 package·install·aide
198 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8186 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
199 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low187 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
200 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low188 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
201 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false189 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
202 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable190 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
203 #·Remediation·is·applicable·only·in·certain·platforms191 #·Remediation·is·applicable·only·in·certain·platforms
204 if·rpm·--quiet·-q·kernel;·then192 if·rpm·--quiet·-q·kernel;·then
Offset 211, 14 lines modifiedOffset 197, 28 lines modified
211 if·!·rpm·-q·--quiet·"aide"·;·then197 if·!·rpm·-q·--quiet·"aide"·;·then
212 ····dnf·install·-y·"aide"198 ····dnf·install·-y·"aide"
213 fi199 fi
  
214 else200 else
215 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'201 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
216 fi202 fi
 203 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 204 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 205 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 206 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 207 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 208 package·--add=aide
 209 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 210 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 211 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 212 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 213 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 214 dnf·install·aide
217 Group  ·Federal·Information·Processing·Standard·(FIPS)·  Group·contains·2·rules215 Group  ·Federal·Information·Processing·Standard·(FIPS)·  Group·contains·2·rules
218 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·Federal·Information·Processing·Standard·(FIPS)·is·a·computer·security·standard·which·is·developed·by·the·U.S.·Government·and·industry·working·groups·to·validate·the·quality·of·cryptographic·modules.·The·FIPS·standard·provides·four·security·levels·to·ensure·adequate·coverage·of·different·industries,·implementation·of·cryptographic·modules,·and·organizational·sizes·and·requirements.216 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·Federal·Information·Processing·Standard·(FIPS)·is·a·computer·security·standard·which·is·developed·by·the·U.S.·Government·and·industry·working·groups·to·validate·the·quality·of·cryptographic·modules.·The·FIPS·standard·provides·four·security·levels·to·ensure·adequate·coverage·of·different·industries,·implementation·of·cryptographic·modules,·and·organizational·sizes·and·requirements.
  
219 FIPS·140-2·is·the·current·standard·for·validating·that·mechanisms·used·to·access·cryptographic·modules·utilize·authentication·that·meets·industry·and·government·requirements.·For·government·systems,·this·allows·Security·Levels·1,·2,·3,·or·4·for·use·on·Red·Hat·Enterprise·Linux·10.217 FIPS·140-2·is·the·current·standard·for·validating·that·mechanisms·used·to·access·cryptographic·modules·utilize·authentication·that·meets·industry·and·government·requirements.·For·government·systems,·this·allows·Security·Levels·1,·2,·3,·or·4·for·use·on·Red·Hat·Enterprise·Linux·10.
  
220 See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8c\x8c_\x8s\x8s_\x8r\x8r_\x8c\x8c_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8l\x8l_\x8i\x8i_\x8c\x8c_\x8a\x8a_\x8t\x8t_\x8i\x8i_\x8o\x8o_\x8n\x8n_\x8s\x8s_\x8/\x8/_\x8P\x8P_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x8h\x8h_\x8t\x8t_\x8m\x8m_\x8l\x8l·for·more·information.218 See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8c\x8c_\x8s\x8s_\x8r\x8r_\x8c\x8c_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8l\x8l_\x8i\x8i_\x8c\x8c_\x8a\x8a_\x8t\x8t_\x8i\x8i_\x8o\x8o_\x8n\x8n_\x8s\x8s_\x8/\x8/_\x8P\x8P_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x8h\x8h_\x8t\x8t_\x8m\x8m_\x8l\x8l·for·more·information.
221 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8de\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*219 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8de\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
Offset 521, 52 lines modifiedOffset 521, 38 lines modified
521 ··-·PCI-DSSv4-2.2.6521 ··-·PCI-DSSv4-2.2.6
522 ··-·enable_strategy522 ··-·enable_strategy
523 ··-·low_complexity523 ··-·low_complexity
524 ··-·low_disruption524 ··-·low_disruption
525 ··-·medium_severity525 ··-·medium_severity
526 ··-·no_reboot_needed526 ··-·no_reboot_needed
527 ··-·package_sudo_installed527 ··-·package_sudo_installed
528 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
529 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
530 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
531 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
532 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
533 dnf·install·sudo 
534 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
535 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
536 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
537 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
538 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
539 package·--add=sudo 
540 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8528 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
541 [[packages]]529 [[packages]]
542 name·=·"sudo"530 name·=·"sudo"
543 version·=·"*"531 version·=·"*"
544 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
545 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
546 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
547 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
548 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
549 package·install·sudo 
550 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8532 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
551 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low533 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
552 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low534 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
553 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false535 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
554 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable536 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
Max diff block lines reached; 71294/76391 bytes (93.33%) of diff not shown.
656 KB
./usr/share/doc/ssg-nondebian/ssg-cs10-guide-ospp.html
    
Offset 15525, 203 lines modifiedOffset 15525, 203 lines modified
0003ca40:·2d74·6172·6765·743d·2223·6964·6d37·3935··-target="#idm7950003ca40:·2d74·6172·6765·743d·2223·6964·6d37·3935··-target="#idm795
0003ca50:·3622·2074·6162·696e·6465·783d·2230·2220··6"·tabindex="0"·0003ca50:·3622·2074·6162·696e·6465·783d·2230·2220··6"·tabindex="0"·
0003ca60:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar0003ca60:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar
0003ca70:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal0003ca70:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal
0003ca80:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ0003ca80:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ
0003ca90:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h0003ca90:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h
0003caa0:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia0003caa0:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia
 0003cab0:·7469·6f6e·204f·5342·7569·6c64·2042·6c75··tion·OSBuild·Blu
 0003cac0:·6570·7269·6e74·2073·6e69·7070·6574·20e2··eprint·snippet·.
 0003cad0:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c
 0003cae0:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
 0003caf0:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
 0003cb00:·643d·2269·646d·3739·3536·223e·3c70·7265··d="idm7956"><pre
 0003cb10:·3e3c·636f·6465·3e0a·5b5b·7061·636b·6167··><code>.[[packag
 0003cb20:·6573·5d5d·0a6e·616d·6520·3d20·2263·7279··es]].name·=·"cry
 0003cb30:·7074·6f2d·706f·6c69·6369·6573·220a·7665··pto-policies".ve
 0003cb40:·7273·696f·6e20·3d20·222a·220a·3c2f·636f··rsion·=·"*".</co
0003cab0:·7469·6f6e·2073·6372·6970·7420·e287·b23c··tion·script·...< 
0003cac0:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas 
0003cad0:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps 
0003cae0:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id=" 
0003caf0:·6964·6d37·3935·3622·3e3c·7461·626c·6520··idm7956"><table· 
0003cb00:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab 
0003cb10:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table 
0003cb20:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table- 
0003cb30:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr>< 
0003cb40:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</ 
0003cb50:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td>< 
0003cb60:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr 
0003cb70:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td> 
0003cb80:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr 
0003cb90:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th 
0003cba0:·3e3c·7464·3e66·616c·7365·3c2f·7464·3e3c··><td>false</td>< 
0003cbb0:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra 
0003cbc0:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en 
0003cbd0:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></ 
0003cbe0:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code 
0003cbf0:·3e0a·646e·6620·696e·7374·616c·6c20·6372··>.dnf·install·cr 
0003cc00:·7970·746f·2d70·6f6c·6963·6965·730a·3c2f··ypto-policies.</ 
0003cc10:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div0003cb50:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div><
0003cc20:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b0003cb60:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn
0003cc30:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data0003cb70:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t
0003cc40:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps0003cb80:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse"
0003cc50:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="0003cb90:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i
0003cc60:·2369·646d·3739·3537·2220·7461·6269·6e64··#idm7957"·tabind0003cba0:·646d·3739·3537·2220·7461·6269·6e64·6578··dm7957"·tabindex
0003cc70:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but0003cbb0:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto
0003cc80:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand0003cbc0:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded
0003cc90:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title0003cbd0:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="
0003cca0:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re0003cbe0:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve
0003ccb0:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">0003cbf0:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re
 0003cc00:·6d65·6469·6174·696f·6e20·5075·7070·6574··mediation·Puppet
0003ccc0:·5265·6d65·6469·6174·696f·6e20·416e·6163··Remediation·Anac 
0003ccd0:·6f6e·6461·2073·6e69·7070·6574·20e2·87b2··onda·snippet·... 
0003cce0:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla 
0003ccf0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap 
0003cd00:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id= 
0003cd10:·2269·646d·3739·3537·223e·3c74·6162·6c65··"idm7957"><table 
0003cd20:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta 
0003cd30:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl 
0003cd40:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table 
0003cd50:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr> 
0003cd60:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:< 
0003cd70:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td> 
0003cd80:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis 
0003cd90:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td 
0003cda0:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t 
0003cdb0:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t 
0003cdc0:·683e·3c74·643e·6661·6c73·653c·2f74·643e··h><td>false</td> 
0003cdd0:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str 
0003cde0:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e 
0003cdf0:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr>< 
0003ce00:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod 
0003ce10:·653e·0a70·6163·6b61·6765·202d·2d61·6464··e>.package·--add 
0003ce20:·3d63·7279·7074·6f2d·706f·6c69·6369·6573··=crypto-policies 
0003ce30:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></ 
0003ce40:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt 
0003ce50:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d 
0003ce60:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll 
0003ce70:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe 
0003ce80:·743d·2223·6964·6d37·3935·3822·2074·6162··t="#idm7958"·tab 
0003ce90:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role=" 
0003cea0:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp 
0003ceb0:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti 
0003cec0:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to 
0003ced0:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="# 
0003cee0:·2122·3e52·656d·6564·6961·7469·6f6e·204f··!">Remediation·O 
0003cef0:·5342·7569·6c64·2042·6c75·6570·7269·6e74··SBuild·Blueprint 
0003cf00:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>0003cc10:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>
0003cf10:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="0003cc20:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="
0003cf20:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c0003cc30:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c
0003cf30:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm0003cc40:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm
0003cf40:·3739·3538·223e·3c70·7265·3e3c·636f·6465··7958"><pre><code 
0003cf50:·3e0a·5b5b·7061·636b·6167·6573·5d5d·0a6e··>.[[packages]].n 
0003cf60:·616d·6520·3d20·2263·7279·7074·6f2d·706f··ame·=·"crypto-po 
0003cf70:·6c69·6369·6573·220a·7665·7273·696f·6e20··licies".version· 
0003cf80:·3d20·222a·220a·3c2f·636f·6465·3e3c·2f70··=·"*".</code></p 
0003cf90:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas 
0003cfa0:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe 
0003cfb0:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle= 
0003cfc0:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data- 
0003cfd0:·7461·7267·6574·3d22·2369·646d·3739·3539··target="#idm7959 
0003cfe0:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r 
0003cff0:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari 
0003d000:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals 
0003d010:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa 
0003d020:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr 
0003d030:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat 
0003d040:·696f·6e20·7363·7269·7074·20e2·87b2·3c2f··ion·script·...</ 
0003d050:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class 
0003d060:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse 
0003d070:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i 
0003d080:·646d·3739·3539·223e·3c74·6162·6c65·2063··dm7959"><table·c0003cc50:·3739·3537·223e·3c74·6162·6c65·2063·6c61··7957"><table·cla
0003d090:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl0003cc60:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-
0003d0a0:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-0003cc70:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo
0003d0b0:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c0003cc80:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con
0003d0c0:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t0003cc90:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>
0003d0d0:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t0003cca0:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>
0003d0e0:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></0003ccb0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
0003d0f0:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru0003ccc0:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt
0003d100:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l0003ccd0:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low
0003d110:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>0003cce0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
0003d120:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th>0003ccf0:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t
0003d130:·3c74·643e·6661·6c73·653c·2f74·643e·3c2f··<td>false</td></0003cd00:·643e·6661·6c73·653c·2f74·643e·3c2f·7472··d>false</td></tr
0003d140:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat0003cd10:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg
0003d150:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena0003cd20:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl
0003d160:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t0003cd30:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab
0003d170:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>0003cd40:·6c65·3e3c·7072·653e·3c63·6f64·653e·696e··le><pre><code>in
Max diff block lines reached; 571270/597932 bytes (95.54%) of diff not shown.
72.0 KB
html2text {}
    
Offset 161, 61 lines modifiedOffset 161, 61 lines modified
161 ··tags:161 ··tags:
162 ··-·enable_strategy162 ··-·enable_strategy
163 ··-·low_complexity163 ··-·low_complexity
164 ··-·low_disruption164 ··-·low_disruption
165 ··-·medium_severity165 ··-·medium_severity
166 ··-·no_reboot_needed166 ··-·no_reboot_needed
167 ··-·package_crypto-policies_installed167 ··-·package_crypto-policies_installed
168 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
169 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
170 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
171 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
172 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
173 dnf·install·crypto-policies 
174 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
175 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
176 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
177 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
178 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
179 package·--add=crypto-policies 
180 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8168 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
181 [[packages]]169 [[packages]]
182 name·=·"crypto-policies"170 name·=·"crypto-policies"
183 version·=·"*"171 version·=·"*"
184 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
185 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
186 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
187 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
188 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
189 package·install·crypto-policies 
190 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8172 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
191 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low173 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
192 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low174 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
193 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false175 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
194 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable176 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
195 include·install_crypto-policies177 include·install_crypto-policies
  
196 class·install_crypto-policies·{178 class·install_crypto-policies·{
197 ··package·{·'crypto-policies':179 ··package·{·'crypto-policies':
198 ····ensure·=>·'installed',180 ····ensure·=>·'installed',
199 ··}181 ··}
200 }182 }
 183 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 184 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 185 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 186 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 187 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 188 package·install·crypto-policies
201 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8189 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
202 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low190 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
203 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low191 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
204 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false192 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
205 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable193 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
206 if·!·rpm·-q·--quiet·"crypto-policies"·;·then194 if·!·rpm·-q·--quiet·"crypto-policies"·;·then
207 ····dnf·install·-y·"crypto-policies"195 ····dnf·install·-y·"crypto-policies"
208 fi196 fi
 197 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 198 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 199 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 200 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 201 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 202 package·--add=crypto-policies
 203 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 204 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 205 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 206 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 207 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 208 dnf·install·crypto-policies
209 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8og\x8gr\x8ra\x8ap\x8ph\x8hy\x8y·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*209 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8og\x8gr\x8ra\x8ap\x8ph\x8hy\x8y·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
210 To·configure·the·system·cryptography·policy·to·use·ciphers·only·from·the·FIPS:OSPP·policy,·run·the·following·command:210 To·configure·the·system·cryptography·policy·to·use·ciphers·only·from·the·FIPS:OSPP·policy,·run·the·following·command:
211 $·sudo·update-crypto-policies·--set·FIPS:OSPP211 $·sudo·update-crypto-policies·--set·FIPS:OSPP
212 The·rule·checks·if·settings·for·selected·crypto·policy·are·configured·as·expected.·Configuration·files·in·the·/etc/crypto-policies/back-ends·are·either·symlinks·to·correct·files·provided·by·Crypto-policies·package·or·they·are·regular·files·in·case·crypto·policy·customizations·are·applied.·Crypto·policies·may·be·customized·by·crypto·policy·modules,·in·which·case·it·is·delimited·from·the·base·policy·using·a·colon.212 The·rule·checks·if·settings·for·selected·crypto·policy·are·configured·as·expected.·Configuration·files·in·the·/etc/crypto-policies/back-ends·are·either·symlinks·to·correct·files·provided·by·Crypto-policies·package·or·they·are·regular·files·in·case·crypto·policy·customizations·are·applied.·Crypto·policies·may·be·customized·by·crypto·policy·modules,·in·which·case·it·is·delimited·from·the·base·policy·using·a·colon.
213 Warning: ·The·system·needs·to·be·rebooted·for·these·changes·to·take·effect.213 Warning: ·The·system·needs·to·be·rebooted·for·these·changes·to·take·effect.
214 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8n\x8n_\x8v\x8v_\x8l\x8l_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8/\x8/_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8/\x8/_\x8N\x8N_\x8I\x8I_\x8S\x8S_\x8T\x8T_\x8.\x8._\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x81\x81_\x84\x84_\x80\x80_\x8-\x8-_\x82\x82_\x8.\x8._\x8p\x8p_\x8d\x8d_\x8f\x8f·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.214 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8n\x8n_\x8v\x8v_\x8l\x8l_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8/\x8/_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8/\x8/_\x8N\x8N_\x8I\x8I_\x8S\x8S_\x8T\x8T_\x8.\x8._\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x81\x81_\x84\x84_\x80\x80_\x8-\x8-_\x82\x82_\x8.\x8._\x8p\x8p_\x8d\x8d_\x8f\x8f·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.
215 Rationale:··Centralized·cryptographic·policies·simplify·applying·secure·ciphers·across·an·operating·system·and·the·applications·that·run·on·that·operating·system.·Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.215 Rationale:··Centralized·cryptographic·policies·simplify·applying·secure·ciphers·across·an·operating·system·and·the·applications·that·run·on·that·operating·system.·Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.
Offset 534, 29 lines modifiedOffset 534, 29 lines modified
534 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·AU-4,·SC-5(2)534 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·AU-4,·SC-5(2)
535 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-4,·PR.PT-1,·PR.PT-4535 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-4,·PR.PT-1,·PR.PT-4
536 ············_\x8o_\x8s_\x8p_\x8p···········FMT_SMF_EXT.1536 ············_\x8o_\x8s_\x8p_\x8p···········FMT_SMF_EXT.1
537 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000341-GPOS-00132,·SRG-OS-000480-GPOS-00227537 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000341-GPOS-00132,·SRG-OS-000480-GPOS-00227
538 ············_\x8a_\x8p_\x8p_\x8-_\x8s_\x8r_\x8g_\x8-_\x8c_\x8t_\x8r····SRG-APP-000357-CTR-000800538 ············_\x8a_\x8p_\x8p_\x8-_\x8s_\x8r_\x8g_\x8-_\x8c_\x8t_\x8r····SRG-APP-000357-CTR-000800
539 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R71539 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R71
540 ············_\x8c_\x8i_\x8s············1.1.2.7.1540 ············_\x8c_\x8i_\x8s············1.1.2.7.1
541 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
542 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
543 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high 
544 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
545 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
546 part·/var/log/audit 
547 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8541 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
548 [[customizations.filesystem]]542 [[customizations.filesystem]]
549 mountpoint·=·"/var/log/audit"543 mountpoint·=·"/var/log/audit"
550 size·=·10737418240544 size·=·10737418240
551 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8545 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
552 logvol·/var/log/audit·10240546 logvol·/var/log/audit·10240
 547 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 548 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 549 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high
 550 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 551 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 552 part·/var/log/audit
553 Group  ·Sudo·  Group·contains·1·rule553 Group  ·Sudo·  Group·contains·1·rule
554 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Sudo,·which·stands·for·"su·'do'",·provides·the·ability·to·delegate·authority·to·certain·users,·groups·of·users,·or·system·administrators.·When·configured·for·system·users·and/or·groups,·Sudo·can·allow·a·user·or·group·to·execute·privileged·commands·that·normally·only·root·is·allowed·to·execute.554 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Sudo,·which·stands·for·"su·'do'",·provides·the·ability·to·delegate·authority·to·certain·users,·groups·of·users,·or·system·administrators.·When·configured·for·system·users·and/or·groups,·Sudo·can·allow·a·user·or·group·to·execute·privileged·commands·that·normally·only·root·is·allowed·to·execute.
  
555 For·more·information·on·Sudo·and·addition·Sudo·configuration·options,·see·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8w\x8w_\x8w\x8w_\x8w\x8w_\x8.\x8._\x8s\x8s_\x8u\x8u_\x8d\x8d_\x8o\x8o_\x8.\x8._\x8w\x8w_\x8s\x8s.555 For·more·information·on·Sudo·and·addition·Sudo·configuration·options,·see·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8w\x8w_\x8w\x8w_\x8w\x8w_\x8.\x8._\x8s\x8s_\x8u\x8u_\x8d\x8d_\x8o\x8o_\x8.\x8._\x8w\x8w_\x8s\x8s.
556 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·s\x8su\x8ud\x8do\x8o·P\x8Pa\x8ac\x8ck\x8ka\x8ag\x8ge\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*556 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·s\x8su\x8ud\x8do\x8o·P\x8Pa\x8ac\x8ck\x8ka\x8ag\x8ge\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
557 The·sudo·package·can·be·installed·with·the·following·command:557 The·sudo·package·can·be·installed·with·the·following·command:
558 $·sudo·dnf·install·sudo558 $·sudo·dnf·install·sudo
Offset 601, 52 lines modifiedOffset 601, 38 lines modified
601 ··-·PCI-DSSv4-2.2.6601 ··-·PCI-DSSv4-2.2.6
602 ··-·enable_strategy602 ··-·enable_strategy
603 ··-·low_complexity603 ··-·low_complexity
604 ··-·low_disruption604 ··-·low_disruption
605 ··-·medium_severity605 ··-·medium_severity
606 ··-·no_reboot_needed606 ··-·no_reboot_needed
607 ··-·package_sudo_installed607 ··-·package_sudo_installed
Max diff block lines reached; 65947/73669 bytes (89.52%) of diff not shown.
610 KB
./usr/share/doc/ssg-nondebian/ssg-cs10-guide-pci-dss.html
    
Offset 16786, 207 lines modifiedOffset 16786, 207 lines modified
00041910:·7461·2d74·6172·6765·743d·2223·6964·6d37··ta-target="#idm700041910:·7461·2d74·6172·6765·743d·2223·6964·6d37··ta-target="#idm7
00041920:·3333·3222·2074·6162·696e·6465·783d·2230··332"·tabindex="000041920:·3333·3222·2074·6162·696e·6465·783d·2230··332"·tabindex="0
00041930:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·00041930:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
00041940:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f00041940:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
00041950:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act00041950:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
00041960:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"00041960:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
00041970:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed00041970:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
 00041980:·6961·7469·6f6e·204f·5342·7569·6c64·2042··iation·OSBuild·B
 00041990:·6c75·6570·7269·6e74·2073·6e69·7070·6574··lueprint·snippet
 000419a0:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
 000419b0:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
 000419c0:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
 000419d0:·2069·643d·2269·646d·3733·3332·223e·3c70···id="idm7332"><p
 000419e0:·7265·3e3c·636f·6465·3e0a·5b5b·7061·636b··re><code>.[[pack
 000419f0:·6167·6573·5d5d·0a6e·616d·6520·3d20·2261··ages]].name·=·"a
 00041a00:·6964·6522·0a76·6572·7369·6f6e·203d·2022··ide".version·=·"
00041980:·6961·7469·6f6e·2073·6372·6970·7420·e287··iation·script·.. 
00041990:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl 
000419a0:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla 
000419b0:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id 
000419c0:·3d22·6964·6d37·3333·3222·3e3c·7461·626c··="idm7332"><tabl 
000419d0:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t 
000419e0:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab 
000419f0:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl 
00041a00:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr 
00041a10:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity: 
00041a20:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td 
00041a30:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di 
00041a40:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t 
00041a50:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr>< 
00041a60:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</ 
00041a70:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td 
00041a80:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St 
00041a90:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td> 
00041aa0:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr> 
00041ab0:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co 
00041ac0:·6465·3e0a·646e·6620·696e·7374·616c·6c20··de>.dnf·install· 
00041ad0:·6169·6465·0a3c·2f63·6f64·653e·3c2f·7072··aide.</code></pr00041a10:·2a22·0a3c·2f63·6f64·653e·3c2f·7072·653e··*".</code></pre>
00041ae0:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class00041a20:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class="
00041af0:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes00041a30:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success"
00041b00:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle="00041a40:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co
00041b10:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t00041a50:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar
00041b20:·6172·6765·743d·2223·6964·6d37·3333·3322··arget="#idm7333"00041a60:·6765·743d·2223·6964·6d37·3333·3322·2074··get="#idm7333"·t
00041b30:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro00041a70:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
00041b40:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria00041a80:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
00041b50:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false00041a90:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
00041b60:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat00041aa0:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
00041b70:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre00041ab0:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
00041b80:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati00041ac0:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
00041b90:·6f6e·2041·6e61·636f·6e64·6120·736e·6970··on·Anaconda·snip00041ad0:·2050·7570·7065·7420·736e·6970·7065·7420···Puppet·snippet·
00041ba0:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br><00041ae0:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·
00041bb0:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel00041af0:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col
00041bc0:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap00041b00:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·
00041bd0:·7365·2220·6964·3d22·6964·6d37·3333·3322··se"·id="idm7333"00041b10:·6964·3d22·6964·6d37·3333·3322·3e3c·7461··id="idm7333"><ta
00041be0:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t 
00041bf0:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip 
00041c00:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere 
00041c10:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense 
00041c20:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl 
00041c30:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l 
00041c40:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr> 
00041c50:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:< 
00041c60:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td> 
00041c70:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb 
00041c80:·6f6f·743a·3c2f·7468·3e3c·7464·3e66·616c··oot:</th><td>fal 
00041c90:·7365·3c2f·7464·3e3c·2f74·723e·3c74·723e··se</td></tr><tr> 
00041ca0:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t 
00041cb0:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td 
00041cc0:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p 
00041cd0:·7265·3e3c·636f·6465·3e0a·7061·636b·6167··re><code>.packag 
00041ce0:·6520·2d2d·6164·643d·6169·6465·0a3c·2f63··e·--add=aide.</c 
00041cf0:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div> 
00041d00:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt 
00041d10:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data- 
00041d20:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse 
00041d30:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="# 
00041d40:·6964·6d37·3333·3422·2074·6162·696e·6465··idm7334"·tabinde 
00041d50:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt 
00041d60:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande 
00041d70:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title= 
00041d80:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev 
00041d90:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R 
00041da0:·656d·6564·6961·7469·6f6e·204f·5342·7569··emediation·OSBui 
00041db0:·6c64·2042·6c75·6570·7269·6e74·2073·6e69··ld·Blueprint·sni 
00041dc0:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br> 
00041dd0:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane 
00041de0:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla 
00041df0:·7073·6522·2069·643d·2269·646d·3733·3334··pse"·id="idm7334 
00041e00:·223e·3c70·7265·3e3c·636f·6465·3e0a·5b5b··"><pre><code>.[[ 
00041e10:·7061·636b·6167·6573·5d5d·0a6e·616d·6520··packages]].name· 
00041e20:·3d20·2261·6964·6522·0a76·6572·7369·6f6e··=·"aide".version 
00041e30:·203d·2022·2a22·0a3c·2f63·6f64·653e·3c2f···=·"*".</code></ 
00041e40:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla 
00041e50:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ 
00041e60:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle 
00041e70:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data 
00041e80:·2d74·6172·6765·743d·2223·6964·6d37·3333··-target="#idm733 
00041e90:·3522·2074·6162·696e·6465·783d·2230·2220··5"·tabindex="0"· 
00041ea0:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar 
00041eb0:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal 
00041ec0:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ 
00041ed0:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h 
00041ee0:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia 
00041ef0:·7469·6f6e·2073·6372·6970·7420·e287·b23c··tion·script·...< 
00041f00:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas 
00041f10:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps 
00041f20:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id=" 
00041f30:·6964·6d37·3333·3522·3e3c·7461·626c·6520··idm7335"><table· 
00041f40:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab 
00041f50:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table 
00041f60:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table- 
00041f70:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr>< 
00041f80:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</ 
00041f90:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td>< 
00041fa0:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr 
00041fb0:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td> 
00041fc0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr 
00041fd0:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th 
00041fe0:·3e3c·7464·3e66·616c·7365·3c2f·7464·3e3c··><td>false</td>< 
00041ff0:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra 
00042000:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en 
00042010:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></ 
00042020:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code 
00042030:·3e0a·7061·636b·6167·6520·696e·7374·616c··>.package·instal 
00042040:·6c20·6169·6465·0a3c·2f63·6f64·653e·3c2f··l·aide.</code></ 
00042050:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla 
00042060:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ 
Max diff block lines reached; 524214/551428 bytes (95.06%) of diff not shown.
71.1 KB
html2text {}
    
Offset 552, 52 lines modifiedOffset 552, 38 lines modified
552 ··-·PCI-DSSv4-11.5.2552 ··-·PCI-DSSv4-11.5.2
553 ··-·enable_strategy553 ··-·enable_strategy
554 ··-·low_complexity554 ··-·low_complexity
555 ··-·low_disruption555 ··-·low_disruption
556 ··-·medium_severity556 ··-·medium_severity
557 ··-·no_reboot_needed557 ··-·no_reboot_needed
558 ··-·package_aide_installed558 ··-·package_aide_installed
559 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
560 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
561 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
562 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
563 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
564 dnf·install·aide 
565 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
566 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
567 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
568 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
569 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
570 package·--add=aide 
571 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8559 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
572 [[packages]]560 [[packages]]
573 name·=·"aide"561 name·=·"aide"
574 version·=·"*"562 version·=·"*"
575 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
576 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
577 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
578 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
579 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
580 package·install·aide 
581 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8563 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
582 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low564 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
583 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low565 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
584 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false566 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
585 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable567 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
586 include·install_aide568 include·install_aide
  
587 class·install_aide·{569 class·install_aide·{
588 ··package·{·'aide':570 ··package·{·'aide':
589 ····ensure·=>·'installed',571 ····ensure·=>·'installed',
590 ··}572 ··}
591 }573 }
 574 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 575 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 576 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 577 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 578 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 579 package·install·aide
592 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8580 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
593 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low581 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
594 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low582 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
595 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false583 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
596 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable584 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
597 #·Remediation·is·applicable·only·in·certain·platforms585 #·Remediation·is·applicable·only·in·certain·platforms
598 if·rpm·--quiet·-q·kernel;·then586 if·rpm·--quiet·-q·kernel;·then
Offset 605, 14 lines modifiedOffset 591, 28 lines modified
605 if·!·rpm·-q·--quiet·"aide"·;·then591 if·!·rpm·-q·--quiet·"aide"·;·then
606 ····dnf·install·-y·"aide"592 ····dnf·install·-y·"aide"
607 fi593 fi
  
608 else594 else
609 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'595 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
610 fi596 fi
 597 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 598 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 599 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 600 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 601 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 602 package·--add=aide
 603 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 604 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 605 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 606 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 607 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 608 dnf·install·aide
611 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*609 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
612 Run·the·following·command·to·generate·a·new·database:610 Run·the·following·command·to·generate·a·new·database:
613 $·sudo·/usr/sbin/aide·--init611 $·sudo·/usr/sbin/aide·--init
614 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:612 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
615 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz613 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
616 To·initiate·a·manual·check,·run·the·following·command:614 To·initiate·a·manual·check,·run·the·following·command:
617 $·sudo·/usr/sbin/aide·--check615 $·sudo·/usr/sbin/aide·--check
Offset 2717, 52 lines modifiedOffset 2717, 38 lines modified
2717 ··-·PCI-DSSv4-2.2.62717 ··-·PCI-DSSv4-2.2.6
2718 ··-·enable_strategy2718 ··-·enable_strategy
2719 ··-·low_complexity2719 ··-·low_complexity
2720 ··-·low_disruption2720 ··-·low_disruption
2721 ··-·medium_severity2721 ··-·medium_severity
2722 ··-·no_reboot_needed2722 ··-·no_reboot_needed
2723 ··-·package_sudo_installed2723 ··-·package_sudo_installed
2724 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
2725 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
2726 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
2727 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
2728 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
2729 dnf·install·sudo 
2730 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
2731 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
2732 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
2733 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
2734 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
2735 package·--add=sudo 
2736 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x82724 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
2737 [[packages]]2725 [[packages]]
2738 name·=·"sudo"2726 name·=·"sudo"
2739 version·=·"*"2727 version·=·"*"
2740 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
2741 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
2742 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
2743 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
2744 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
2745 package·install·sudo 
2746 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x82728 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
2747 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low2729 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
2748 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low2730 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
2749 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false2731 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
2750 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable2732 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
Max diff block lines reached; 68076/72771 bytes (93.55%) of diff not shown.
1.86 MB
./usr/share/doc/ssg-nondebian/ssg-cs10-guide-stig.html
    
Offset 15283, 208 lines modifiedOffset 15283, 208 lines modified
0003bb20:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#0003bb20:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
0003bb30:·6964·6d37·3333·3222·2074·6162·696e·6465··idm7332"·tabinde0003bb30:·6964·6d37·3333·3222·2074·6162·696e·6465··idm7332"·tabinde
0003bb40:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt0003bb40:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt
0003bb50:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande0003bb50:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande
0003bb60:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=0003bb60:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=
0003bb70:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev0003bb70:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev
0003bb80:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R0003bb80:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R
0003bb90:·656d·6564·6961·7469·6f6e·2073·6372·6970··emediation·scrip0003bb90:·656d·6564·6961·7469·6f6e·204f·5342·7569··emediation·OSBui
 0003bba0:·6c64·2042·6c75·6570·7269·6e74·2073·6e69··ld·Blueprint·sni
 0003bbb0:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>
 0003bbc0:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
 0003bbd0:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
 0003bbe0:·7073·6522·2069·643d·2269·646d·3733·3332··pse"·id="idm7332
 0003bbf0:·223e·3c70·7265·3e3c·636f·6465·3e0a·5b5b··"><pre><code>.[[
 0003bc00:·7061·636b·6167·6573·5d5d·0a6e·616d·6520··packages]].name·
 0003bc10:·3d20·2261·6964·6522·0a76·6572·7369·6f6e··=·"aide".version
 0003bc20:·203d·2022·2a22·0a3c·2f63·6f64·653e·3c2f···=·"*".</code></
0003bba0:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di 
0003bbb0:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c 
0003bbc0:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse 
0003bbd0:·2220·6964·3d22·6964·6d37·3333·3222·3e3c··"·id="idm7332">< 
0003bbe0:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab 
0003bbf0:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped 
0003bc00:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered· 
0003bc10:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed" 
0003bc20:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex 
0003bc30:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low 
0003bc40:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
0003bc50:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t 
0003bc60:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></ 
0003bc70:·7472·3e3c·7472·3e3c·7468·3e52·6562·6f6f··tr><tr><th>Reboo 
0003bc80:·743a·3c2f·7468·3e3c·7464·3e66·616c·7365··t:</th><td>false 
0003bc90:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
0003bca0:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th> 
0003bcb0:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td>< 
0003bcc0:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre 
0003bcd0:·3e3c·636f·6465·3e0a·646e·6620·696e·7374··><code>.dnf·inst 
0003bce0:·616c·6c20·6169·6465·0a3c·2f63·6f64·653e··all·aide.</code> 
0003bcf0:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c0003bc30:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla
0003bd00:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su0003bc40:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ
0003bd10:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg0003bc50:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle
0003bd20:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da0003bc60:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data
0003bd30:·7461·2d74·6172·6765·743d·2223·6964·6d37··ta-target="#idm70003bc70:·2d74·6172·6765·743d·2223·6964·6d37·3333··-target="#idm733
0003bd40:·3333·3322·2074·6162·696e·6465·783d·2230··333"·tabindex="00003bc80:·3322·2074·6162·696e·6465·783d·2230·2220··3"·tabindex="0"·
0003bd50:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·0003bc90:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar
0003bd60:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f0003bca0:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal
0003bd70:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act0003bcb0:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ
0003bd80:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"0003bcc0:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h
0003bd90:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed0003bcd0:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia
0003bda0:·6961·7469·6f6e·2041·6e61·636f·6e64·6120··iation·Anaconda·0003bce0:·7469·6f6e·2050·7570·7065·7420·736e·6970··tion·Puppet·snip
0003bdb0:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><0003bcf0:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br><
0003bdc0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p0003bd00:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
0003bdd0:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co0003bd10:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap
0003bde0:·6c6c·6170·7365·2220·6964·3d22·6964·6d37··llapse"·id="idm70003bd20:·7365·2220·6964·3d22·6964·6d37·3333·3322··se"·id="idm7333"
0003bdf0:·3333·3322·3e3c·7461·626c·6520·636c·6173··333"><table·clas0003bd30:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t
0003be00:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s0003bd40:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip
0003be10:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor0003bd50:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere
0003be20:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond0003bd60:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense
0003be30:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C0003bd70:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl
0003be40:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><0003bd80:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l
0003be50:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>0003bd90:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
0003be60:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti0003bda0:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:<
 0003bdb0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
 0003bdc0:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb
 0003bdd0:·6f6f·743a·3c2f·7468·3e3c·7464·3e66·616c··oot:</th><td>fal
 0003bde0:·7365·3c2f·7464·3e3c·2f74·723e·3c74·723e··se</td></tr><tr>
 0003bdf0:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t
 0003be00:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td
 0003be10:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p
 0003be20:·7265·3e3c·636f·6465·3e69·6e63·6c75·6465··re><code>include
 0003be30:·2069·6e73·7461·6c6c·5f61·6964·650a·0a63···install_aide..c
 0003be40:·6c61·7373·2069·6e73·7461·6c6c·5f61·6964··lass·install_aid
 0003be50:·6520·7b0a·2020·7061·636b·6167·6520·7b20··e·{.··package·{·
 0003be60:·2761·6964·6527·3a0a·2020·2020·656e·7375··'aide':.····ensu
 0003be70:·7265·203d·2667·743b·2027·696e·7374·616c··re·=&gt;·'instal
 0003be80:·6c65·6427·2c0a·2020·7d0a·7d0a·3c2f·636f··led',.··}.}.</co
 0003be90:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div><
 0003bea0:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn
 0003beb0:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t
 0003bec0:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse"
 0003bed0:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i
 0003bee0:·646d·3733·3334·2220·7461·6269·6e64·6578··dm7334"·tabindex
 0003bef0:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto
 0003bf00:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded
 0003bf10:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="
 0003bf20:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve
 0003bf30:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re
 0003bf40:·6d65·6469·6174·696f·6e20·7363·7269·7074··mediation·script
 0003bf50:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
 0003bf60:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
 0003bf70:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
 0003bf80:·2069·643d·2269·646d·3733·3334·223e·3c74···id="idm7334"><t
 0003bf90:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl
 0003bfa0:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·
 0003bfb0:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t
 0003bfc0:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">
 0003bfd0:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi
0003be70:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<0003bfe0:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<
0003be80:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th0003bff0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
0003be90:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td 
0003bea0:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr> 
0003beb0:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy0003c000:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th
 0003c010:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
 0003c020:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot
0003bec0:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable0003c030:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false<
0003bed0:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl 
0003bee0:·653e·3c70·7265·3e3c·636f·6465·3e0a·7061··e><pre><code>.pa 
0003bef0:·636b·6167·6520·2d2d·6164·643d·6169·6465··ckage·--add=aide 
0003bf00:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></ 
0003bf10:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt 
0003bf20:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d 
0003bf30:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll 
0003bf40:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe 
0003bf50:·743d·2223·6964·6d37·3333·3422·2074·6162··t="#idm7334"·tab 
0003bf60:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role=" 
0003bf70:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp 
0003bf80:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti 
0003bf90:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to 
0003bfa0:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="# 
0003bfb0:·2122·3e52·656d·6564·6961·7469·6f6e·204f··!">Remediation·O 
0003bfc0:·5342·7569·6c64·2042·6c75·6570·7269·6e74··SBuild·Blueprint0003c040:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 0003c050:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><
 0003c060:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></
 0003c070:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>
 0003c080:·3c63·6f64·653e·0a70·6163·6b61·6765·2069··<code>.package·i
 0003c090:·6e73·7461·6c6c·2061·6964·650a·3c2f·636f··nstall·aide.</co
 0003c0a0:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div><
Max diff block lines reached; 1720788/1748140 bytes (98.44%) of diff not shown.
198 KB
html2text {}
    
Offset 158, 52 lines modifiedOffset 158, 38 lines modified
158 ··-·PCI-DSSv4-11.5.2158 ··-·PCI-DSSv4-11.5.2
159 ··-·enable_strategy159 ··-·enable_strategy
160 ··-·low_complexity160 ··-·low_complexity
161 ··-·low_disruption161 ··-·low_disruption
162 ··-·medium_severity162 ··-·medium_severity
163 ··-·no_reboot_needed163 ··-·no_reboot_needed
164 ··-·package_aide_installed164 ··-·package_aide_installed
165 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
166 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
167 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
168 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
169 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
170 dnf·install·aide 
171 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
172 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
173 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
174 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
175 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
176 package·--add=aide 
177 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8165 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
178 [[packages]]166 [[packages]]
179 name·=·"aide"167 name·=·"aide"
180 version·=·"*"168 version·=·"*"
181 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
182 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
183 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
184 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
185 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
186 package·install·aide 
187 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8169 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
188 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low170 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
189 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low171 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
190 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false172 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
191 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable173 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
192 include·install_aide174 include·install_aide
  
193 class·install_aide·{175 class·install_aide·{
194 ··package·{·'aide':176 ··package·{·'aide':
195 ····ensure·=>·'installed',177 ····ensure·=>·'installed',
196 ··}178 ··}
197 }179 }
 180 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 181 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 182 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 183 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 184 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 185 package·install·aide
198 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8186 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
199 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low187 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
200 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low188 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
201 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false189 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
202 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable190 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
203 #·Remediation·is·applicable·only·in·certain·platforms191 #·Remediation·is·applicable·only·in·certain·platforms
204 if·rpm·--quiet·-q·kernel;·then192 if·rpm·--quiet·-q·kernel;·then
Offset 211, 14 lines modifiedOffset 197, 28 lines modified
211 if·!·rpm·-q·--quiet·"aide"·;·then197 if·!·rpm·-q·--quiet·"aide"·;·then
212 ····dnf·install·-y·"aide"198 ····dnf·install·-y·"aide"
213 fi199 fi
  
214 else200 else
215 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'201 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
216 fi202 fi
 203 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 204 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 205 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 206 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 207 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 208 package·--add=aide
 209 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 210 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 211 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 212 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 213 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 214 dnf·install·aide
217 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*215 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
218 Run·the·following·command·to·generate·a·new·database:216 Run·the·following·command·to·generate·a·new·database:
219 $·sudo·/usr/sbin/aide·--init217 $·sudo·/usr/sbin/aide·--init
220 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:218 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
221 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz219 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
222 To·initiate·a·manual·check,·run·the·following·command:220 To·initiate·a·manual·check,·run·the·following·command:
223 $·sudo·/usr/sbin/aide·--check221 $·sudo·/usr/sbin/aide·--check
Offset 2031, 61 lines modifiedOffset 2031, 61 lines modified
2031 ··tags:2031 ··tags:
2032 ··-·enable_strategy2032 ··-·enable_strategy
2033 ··-·low_complexity2033 ··-·low_complexity
2034 ··-·low_disruption2034 ··-·low_disruption
2035 ··-·medium_severity2035 ··-·medium_severity
2036 ··-·no_reboot_needed2036 ··-·no_reboot_needed
2037 ··-·package_crypto-policies_installed2037 ··-·package_crypto-policies_installed
2038 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
2039 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
2040 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
2041 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
2042 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
2043 dnf·install·crypto-policies 
2044 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
2045 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
2046 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
2047 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
2048 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
2049 package·--add=crypto-policies 
2050 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x82038 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
2051 [[packages]]2039 [[packages]]
2052 name·=·"crypto-policies"2040 name·=·"crypto-policies"
2053 version·=·"*"2041 version·=·"*"
2054 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
2055 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
2056 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
2057 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
2058 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
2059 package·install·crypto-policies 
2060 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x82042 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
2061 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low2043 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
2062 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low2044 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
2063 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false2045 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
2064 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable2046 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
Max diff block lines reached; 197499/202248 bytes (97.65%) of diff not shown.
1.81 MB
./usr/share/doc/ssg-nondebian/ssg-cs10-guide-stig_gui.html
    
Offset 15278, 208 lines modifiedOffset 15278, 208 lines modified
0003bad0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=0003bad0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
0003bae0:·2223·6964·6d37·3333·3222·2074·6162·696e··"#idm7332"·tabin0003bae0:·2223·6964·6d37·3333·3222·2074·6162·696e··"#idm7332"·tabin
0003baf0:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu0003baf0:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
0003bb00:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan0003bb00:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
0003bb10:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl0003bb10:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
0003bb20:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r0003bb20:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
0003bb30:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"0003bb30:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
0003bb40:·3e52·656d·6564·6961·7469·6f6e·2073·6372··>Remediation·scr0003bb40:·3e52·656d·6564·6961·7469·6f6e·204f·5342··>Remediation·OSB
 0003bb50:·7569·6c64·2042·6c75·6570·7269·6e74·2073··uild·Blueprint·s
 0003bb60:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b
 0003bb70:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
 0003bb80:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
 0003bb90:·6c61·7073·6522·2069·643d·2269·646d·3733··lapse"·id="idm73
 0003bba0:·3332·223e·3c70·7265·3e3c·636f·6465·3e0a··32"><pre><code>.
 0003bbb0:·5b5b·7061·636b·6167·6573·5d5d·0a6e·616d··[[packages]].nam
 0003bbc0:·6520·3d20·2261·6964·6522·0a76·6572·7369··e·=·"aide".versi
 0003bbd0:·6f6e·203d·2022·2a22·0a3c·2f63·6f64·653e··on·=·"*".</code>
0003bb50:·6970·7420·e287·b23c·2f61·3e3c·6272·3e3c··ipt·...</a><br>< 
0003bb60:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel 
0003bb70:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap 
0003bb80:·7365·2220·6964·3d22·6964·6d37·3333·3222··se"·id="idm7332" 
0003bb90:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t 
0003bba0:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip 
0003bbb0:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere 
0003bbc0:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense 
0003bbd0:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl 
0003bbe0:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l 
0003bbf0:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr> 
0003bc00:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:< 
0003bc10:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td> 
0003bc20:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb 
0003bc30:·6f6f·743a·3c2f·7468·3e3c·7464·3e66·616c··oot:</th><td>fal 
0003bc40:·7365·3c2f·7464·3e3c·2f74·723e·3c74·723e··se</td></tr><tr> 
0003bc50:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t 
0003bc60:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td 
0003bc70:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p 
0003bc80:·7265·3e3c·636f·6465·3e0a·646e·6620·696e··re><code>.dnf·in 
0003bc90:·7374·616c·6c20·6169·6465·0a3c·2f63·6f64··stall·aide.</cod 
0003bca0:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a0003bbe0:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c
0003bcb0:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn-0003bbf0:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su
0003bcc0:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to0003bc00:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg
0003bcd0:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"·0003bc10:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da
0003bce0:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id0003bc20:·7461·2d74·6172·6765·743d·2223·6964·6d37··ta-target="#idm7
0003bcf0:·6d37·3333·3322·2074·6162·696e·6465·783d··m7333"·tabindex=0003bc30:·3333·3322·2074·6162·696e·6465·783d·2230··333"·tabindex="0
0003bd00:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button0003bc40:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
0003bd10:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=0003bc50:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
0003bd20:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A0003bc60:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
0003bd30:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea0003bc70:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
0003bd40:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem0003bc80:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
0003bd50:·6564·6961·7469·6f6e·2041·6e61·636f·6e64··ediation·Anacond0003bc90:·6961·7469·6f6e·2050·7570·7065·7420·736e··iation·Puppet·sn
0003bd60:·6120·736e·6970·7065·7420·e287·b23c·2f61··a·snippet·...</a0003bca0:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br
0003bd70:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=0003bcb0:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
0003bd80:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·0003bcc0:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
0003bd90:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id0003bcd0:·6170·7365·2220·6964·3d22·6964·6d37·3333··apse"·id="idm733
0003bda0:·6d37·3333·3322·3e3c·7461·626c·6520·636c··m7333"><table·cl0003bce0:·3322·3e3c·7461·626c·6520·636c·6173·733d··3"><table·class=
0003bdb0:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table0003bcf0:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str
0003bdc0:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b0003bd00:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde
0003bdd0:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co0003bd10:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden
0003bde0:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th0003bd20:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com
0003bdf0:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th0003bd30:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td
0003be00:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t0003bd40:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
0003be10:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup0003bd50:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption
 0003bd60:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
 0003bd70:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e52··d></tr><tr><th>R
 0003bd80:·6562·6f6f·743a·3c2f·7468·3e3c·7464·3e66··eboot:</th><td>f
 0003bd90:·616c·7365·3c2f·7464·3e3c·2f74·723e·3c74··alse</td></tr><t
 0003bda0:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<
 0003bdb0:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</
 0003bdc0:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table>
 0003bdd0:·3c70·7265·3e3c·636f·6465·3e69·6e63·6c75··<pre><code>inclu
 0003bde0:·6465·2069·6e73·7461·6c6c·5f61·6964·650a··de·install_aide.
 0003bdf0:·0a63·6c61·7373·2069·6e73·7461·6c6c·5f61··.class·install_a
 0003be00:·6964·6520·7b0a·2020·7061·636b·6167·6520··ide·{.··package·
 0003be10:·7b20·2761·6964·6527·3a0a·2020·2020·656e··{·'aide':.····en
 0003be20:·7375·7265·203d·2667·743b·2027·696e·7374··sure·=&gt;·'inst
 0003be30:·616c·6c65·6427·2c0a·2020·7d0a·7d0a·3c2f··alled',.··}.}.</
 0003be40:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div
 0003be50:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b
 0003be60:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data
 0003be70:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps
 0003be80:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
 0003be90:·2369·646d·3733·3334·2220·7461·6269·6e64··#idm7334"·tabind
 0003bea0:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
 0003beb0:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
 0003bec0:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
 0003bed0:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
 0003bee0:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
 0003bef0:·5265·6d65·6469·6174·696f·6e20·7363·7269··Remediation·scri
 0003bf00:·7074·20e2·87b2·3c2f·613e·3c62·723e·3c64··pt·...</a><br><d
 0003bf10:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-
 0003bf20:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps
 0003bf30:·6522·2069·643d·2269·646d·3733·3334·223e··e"·id="idm7334">
 0003bf40:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta
 0003bf50:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe
 0003bf60:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered
 0003bf70:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed
 0003bf80:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple
0003be20:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo0003bf90:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo
0003be30:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><0003bfa0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
0003be40:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th>< 
0003be50:·7464·3e66·616c·7365·3c2f·7464·3e3c·2f74··td>false</td></t 
0003be60:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate0003bfb0:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</
 0003bfc0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
 0003bfd0:·2f74·723e·3c74·723e·3c74·683e·5265·626f··/tr><tr><th>Rebo
0003be70:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab0003bfe0:·6f74·3a3c·2f74·683e·3c74·643e·6661·6c73··ot:</th><td>fals
0003be80:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta 
0003be90:·626c·653e·3c70·7265·3e3c·636f·6465·3e0a··ble><pre><code>. 
0003bea0:·7061·636b·6167·6520·2d2d·6164·643d·6169··package·--add=ai 
0003beb0:·6465·0a3c·2f63·6f64·653e·3c2f·7072·653e··de.</code></pre> 
0003bec0:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class=" 
0003bed0:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success" 
0003bee0:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co 
0003bef0:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar 
0003bf00:·6765·743d·2223·6964·6d37·3333·3422·2074··get="#idm7334"·t 
0003bf10:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role 
0003bf20:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e 
0003bf30:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"· 
0003bf40:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate· 
0003bf50:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href= 
0003bf60:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation 
0003bf70:·204f·5342·7569·6c64·2042·6c75·6570·7269···OSBuild·Bluepri 
0003bf80:·6e74·2073·6e69·7070·6574·20e2·87b2·3c2f··nt·snippet·...</0003bff0:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr><
 0003c000:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th
 0003c010:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td>
 0003c020:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr
 0003c030:·653e·3c63·6f64·653e·0a70·6163·6b61·6765··e><code>.package
 0003c040:·2069·6e73·7461·6c6c·2061·6964·650a·3c2f···install·aide.</
Max diff block lines reached; 1674845/1702197 bytes (98.39%) of diff not shown.
191 KB
html2text {}
    
Offset 157, 52 lines modifiedOffset 157, 38 lines modified
157 ··-·PCI-DSSv4-11.5.2157 ··-·PCI-DSSv4-11.5.2
158 ··-·enable_strategy158 ··-·enable_strategy
159 ··-·low_complexity159 ··-·low_complexity
160 ··-·low_disruption160 ··-·low_disruption
161 ··-·medium_severity161 ··-·medium_severity
162 ··-·no_reboot_needed162 ··-·no_reboot_needed
163 ··-·package_aide_installed163 ··-·package_aide_installed
164 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
165 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
166 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
167 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
168 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
169 dnf·install·aide 
170 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
171 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
172 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
173 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
174 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
175 package·--add=aide 
176 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8164 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
177 [[packages]]165 [[packages]]
178 name·=·"aide"166 name·=·"aide"
179 version·=·"*"167 version·=·"*"
180 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
181 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
182 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
183 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
184 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
185 package·install·aide 
186 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8168 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
187 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low169 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
188 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low170 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
189 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false171 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
190 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable172 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
191 include·install_aide173 include·install_aide
  
192 class·install_aide·{174 class·install_aide·{
193 ··package·{·'aide':175 ··package·{·'aide':
194 ····ensure·=>·'installed',176 ····ensure·=>·'installed',
195 ··}177 ··}
196 }178 }
 179 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 180 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 181 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 182 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 183 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 184 package·install·aide
197 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8185 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
198 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low186 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
199 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low187 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
200 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false188 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
201 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable189 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
202 #·Remediation·is·applicable·only·in·certain·platforms190 #·Remediation·is·applicable·only·in·certain·platforms
203 if·rpm·--quiet·-q·kernel;·then191 if·rpm·--quiet·-q·kernel;·then
Offset 210, 14 lines modifiedOffset 196, 28 lines modified
210 if·!·rpm·-q·--quiet·"aide"·;·then196 if·!·rpm·-q·--quiet·"aide"·;·then
211 ····dnf·install·-y·"aide"197 ····dnf·install·-y·"aide"
212 fi198 fi
  
213 else199 else
214 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'200 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
215 fi201 fi
 202 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 203 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 204 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 205 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 206 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 207 package·--add=aide
 208 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 209 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 210 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 211 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 212 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 213 dnf·install·aide
216 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*214 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
217 Run·the·following·command·to·generate·a·new·database:215 Run·the·following·command·to·generate·a·new·database:
218 $·sudo·/usr/sbin/aide·--init216 $·sudo·/usr/sbin/aide·--init
219 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:217 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
220 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz218 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
221 To·initiate·a·manual·check,·run·the·following·command:219 To·initiate·a·manual·check,·run·the·following·command:
222 $·sudo·/usr/sbin/aide·--check220 $·sudo·/usr/sbin/aide·--check
Offset 2030, 61 lines modifiedOffset 2030, 61 lines modified
2030 ··tags:2030 ··tags:
2031 ··-·enable_strategy2031 ··-·enable_strategy
2032 ··-·low_complexity2032 ··-·low_complexity
2033 ··-·low_disruption2033 ··-·low_disruption
2034 ··-·medium_severity2034 ··-·medium_severity
2035 ··-·no_reboot_needed2035 ··-·no_reboot_needed
2036 ··-·package_crypto-policies_installed2036 ··-·package_crypto-policies_installed
2037 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
2038 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
2039 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
2040 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
2041 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
2042 dnf·install·crypto-policies 
2043 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
2044 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
2045 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
2046 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
2047 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
2048 package·--add=crypto-policies 
2049 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x82037 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
2050 [[packages]]2038 [[packages]]
2051 name·=·"crypto-policies"2039 name·=·"crypto-policies"
2052 version·=·"*"2040 version·=·"*"
2053 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
2054 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
2055 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
2056 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
2057 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
2058 package·install·crypto-policies 
2059 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x82041 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
2060 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low2042 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
2061 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low2043 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
2062 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false2044 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
2063 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable2045 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
Max diff block lines reached; 190908/195657 bytes (97.57%) of diff not shown.
1.15 MB
./usr/share/doc/ssg-nondebian/ssg-cs9-guide-anssi_bp28_enhanced.html
    
Offset 15256, 208 lines modifiedOffset 15256, 208 lines modified
0003b970:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe0003b970:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
0003b980:·743d·2223·6964·6d38·3438·3122·2074·6162··t="#idm8481"·tab0003b980:·743d·2223·6964·6d38·3438·3122·2074·6162··t="#idm8481"·tab
0003b990:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="0003b990:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
0003b9a0:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp0003b9a0:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
0003b9b0:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti0003b9b0:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
0003b9c0:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to0003b9c0:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
0003b9d0:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#0003b9d0:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
0003b9e0:·2122·3e52·656d·6564·6961·7469·6f6e·2073··!">Remediation·s0003b9e0:·2122·3e52·656d·6564·6961·7469·6f6e·204f··!">Remediation·O
 0003b9f0:·5342·7569·6c64·2042·6c75·6570·7269·6e74··SBuild·Blueprint
 0003ba00:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>
 0003ba10:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="
 0003ba20:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c
 0003ba30:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm
 0003ba40:·3834·3831·223e·3c70·7265·3e3c·636f·6465··8481"><pre><code
 0003ba50:·3e0a·5b5b·7061·636b·6167·6573·5d5d·0a6e··>.[[packages]].n
 0003ba60:·616d·6520·3d20·2261·6964·6522·0a76·6572··ame·=·"aide".ver
 0003ba70:·7369·6f6e·203d·2022·2a22·0a3c·2f63·6f64··sion·=·"*".</cod
0003b9f0:·6372·6970·7420·e287·b23c·2f61·3e3c·6272··cript·...</a><br 
0003ba00:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan 
0003ba10:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll 
0003ba20:·6170·7365·2220·6964·3d22·6964·6d38·3438··apse"·id="idm848 
0003ba30:·3122·3e3c·7461·626c·6520·636c·6173·733d··1"><table·class= 
0003ba40:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str 
0003ba50:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde 
0003ba60:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden 
0003ba70:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com 
0003ba80:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td 
0003ba90:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t 
0003baa0:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption 
0003bab0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t 
0003bac0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e52··d></tr><tr><th>R 
0003bad0:·6562·6f6f·743a·3c2f·7468·3e3c·7464·3e66··eboot:</th><td>f 
0003bae0:·616c·7365·3c2f·7464·3e3c·2f74·723e·3c74··alse</td></tr><t 
0003baf0:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:< 
0003bb00:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</ 
0003bb10:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table> 
0003bb20:·3c70·7265·3e3c·636f·6465·3e0a·646e·6620··<pre><code>.dnf· 
0003bb30:·696e·7374·616c·6c20·6169·6465·0a3c·2f63··install·aide.</c 
0003bb40:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div>0003ba80:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a
0003bb50:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt0003ba90:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn-
0003bb60:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data-0003baa0:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to
0003bb70:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse0003bab0:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"·
0003bb80:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#0003bac0:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
0003bb90:·6964·6d38·3438·3222·2074·6162·696e·6465··idm8482"·tabinde0003bad0:·6d38·3438·3222·2074·6162·696e·6465·783d··m8482"·tabindex=
0003bba0:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt0003bae0:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button
0003bbb0:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande0003baf0:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=
0003bbc0:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=0003bb00:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A
0003bbd0:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev0003bb10:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea
0003bbe0:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R0003bb20:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem
0003bbf0:·656d·6564·6961·7469·6f6e·2041·6e61·636f··emediation·Anaco0003bb30:·6564·6961·7469·6f6e·2050·7570·7065·7420··ediation·Puppet·
0003bc00:·6e64·6120·736e·6970·7065·7420·e287·b23c··nda·snippet·...<0003bb40:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><
0003bc10:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas0003bb50:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
0003bc20:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps0003bb60:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
0003bc30:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="0003bb70:·6c6c·6170·7365·2220·6964·3d22·6964·6d38··llapse"·id="idm8
0003bc40:·6964·6d38·3438·3222·3e3c·7461·626c·6520··idm8482"><table·0003bb80:·3438·3222·3e3c·7461·626c·6520·636c·6173··482"><table·clas
0003bc50:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab0003bb90:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s
0003bc60:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table0003bba0:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor
0003bc70:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-0003bbb0:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond
0003bc80:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><0003bbc0:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C
0003bc90:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</0003bbd0:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><
0003bca0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><0003bbe0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
0003bcb0:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr0003bbf0:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti
0003bcc0:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>0003bc00:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<
 0003bc10:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 0003bc20:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td
 0003bc30:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr>
 0003bc40:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy
 0003bc50:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable
 0003bc60:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl
 0003bc70:·653e·3c70·7265·3e3c·636f·6465·3e69·6e63··e><pre><code>inc
 0003bc80:·6c75·6465·2069·6e73·7461·6c6c·5f61·6964··lude·install_aid
 0003bc90:·650a·0a63·6c61·7373·2069·6e73·7461·6c6c··e..class·install
 0003bca0:·5f61·6964·6520·7b0a·2020·7061·636b·6167··_aide·{.··packag
 0003bcb0:·6520·7b20·2761·6964·6527·3a0a·2020·2020··e·{·'aide':.····
 0003bcc0:·656e·7375·7265·203d·2667·743b·2027·696e··ensure·=&gt;·'in
 0003bcd0:·7374·616c·6c65·6427·2c0a·2020·7d0a·7d0a··stalled',.··}.}.
 0003bce0:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d
 0003bcf0:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn
 0003bd00:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da
 0003bd10:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla
 0003bd20:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
 0003bd30:·3d22·2369·646d·3834·3833·2220·7461·6269··="#idm8483"·tabi
 0003bd40:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
 0003bd50:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
 0003bd60:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
 0003bd70:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
 0003bd80:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
 0003bd90:·223e·5265·6d65·6469·6174·696f·6e20·7363··">Remediation·sc
 0003bda0:·7269·7074·20e2·87b2·3c2f·613e·3c62·723e··ript·...</a><br>
 0003bdb0:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
 0003bdc0:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
 0003bdd0:·7073·6522·2069·643d·2269·646d·3834·3833··pse"·id="idm8483
 0003bde0:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="
 0003bdf0:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri
 0003be00:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border
 0003be10:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens
 0003be20:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp
 0003be30:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>
0003bcd0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr0003be40:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
0003bce0:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th 
0003bcf0:·3e3c·7464·3e66·616c·7365·3c2f·7464·3e3c··><td>false</td><0003be50:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:
 0003be60:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
0003bd00:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra0003be70:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re
0003bd10:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en0003be80:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa
0003bd20:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></ 
0003bd30:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code 
0003bd40:·3e0a·7061·636b·6167·6520·2d2d·6164·643d··>.package·--add= 
0003bd50:·6169·6465·0a3c·2f63·6f64·653e·3c2f·7072··aide.</code></pr 
0003bd60:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class 
0003bd70:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes0003be90:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr
 0003bea0:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</
 0003beb0:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t
 0003bec0:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><
 0003bed0:·7072·653e·3c63·6f64·653e·0a70·6163·6b61··pre><code>.packa
 0003bee0:·6765·2069·6e73·7461·6c6c·2061·6964·650a··ge·install·aide.
 0003bef0:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d
 0003bf00:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn
 0003bf10:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da
 0003bf20:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla
0003bd80:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle="0003bf30:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
 0003bf40:·3d22·2369·646d·3834·3834·2220·7461·6269··="#idm8484"·tabi
 0003bf50:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
 0003bf60:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
 0003bf70:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
 0003bf80:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
 0003bf90:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
 0003bfa0:·223e·5265·6d65·6469·6174·696f·6e20·5368··">Remediation·Sh
Max diff block lines reached; 1057851/1085203 bytes (97.48%) of diff not shown.
120 KB
html2text {}
    
Offset 157, 52 lines modifiedOffset 157, 38 lines modified
157 ··-·PCI-DSSv4-11.5.2157 ··-·PCI-DSSv4-11.5.2
158 ··-·enable_strategy158 ··-·enable_strategy
159 ··-·low_complexity159 ··-·low_complexity
160 ··-·low_disruption160 ··-·low_disruption
161 ··-·medium_severity161 ··-·medium_severity
162 ··-·no_reboot_needed162 ··-·no_reboot_needed
163 ··-·package_aide_installed163 ··-·package_aide_installed
164 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
165 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
166 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
167 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
168 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
169 dnf·install·aide 
170 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
171 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
172 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
173 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
174 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
175 package·--add=aide 
176 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8164 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
177 [[packages]]165 [[packages]]
178 name·=·"aide"166 name·=·"aide"
179 version·=·"*"167 version·=·"*"
180 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
181 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
182 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
183 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
184 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
185 package·install·aide 
186 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8168 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
187 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low169 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
188 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low170 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
189 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false171 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
190 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable172 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
191 include·install_aide173 include·install_aide
  
192 class·install_aide·{174 class·install_aide·{
193 ··package·{·'aide':175 ··package·{·'aide':
194 ····ensure·=>·'installed',176 ····ensure·=>·'installed',
195 ··}177 ··}
196 }178 }
 179 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 180 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 181 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 182 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 183 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 184 package·install·aide
197 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8185 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
198 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low186 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
199 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low187 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
200 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false188 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
201 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable189 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
202 #·Remediation·is·applicable·only·in·certain·platforms190 #·Remediation·is·applicable·only·in·certain·platforms
203 if·rpm·--quiet·-q·kernel;·then191 if·rpm·--quiet·-q·kernel;·then
Offset 210, 14 lines modifiedOffset 196, 28 lines modified
210 if·!·rpm·-q·--quiet·"aide"·;·then196 if·!·rpm·-q·--quiet·"aide"·;·then
211 ····dnf·install·-y·"aide"197 ····dnf·install·-y·"aide"
212 fi198 fi
  
213 else199 else
214 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'200 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
215 fi201 fi
 202 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 203 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 204 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 205 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 206 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 207 package·--add=aide
 208 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 209 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 210 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 211 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 212 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 213 dnf·install·aide
216 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*214 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
217 Run·the·following·command·to·generate·a·new·database:215 Run·the·following·command·to·generate·a·new·database:
218 $·sudo·/usr/sbin/aide·--init216 $·sudo·/usr/sbin/aide·--init
219 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:217 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
220 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz218 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
221 To·initiate·a·manual·check,·run·the·following·command:219 To·initiate·a·manual·check,·run·the·following·command:
222 $·sudo·/usr/sbin/aide·--check220 $·sudo·/usr/sbin/aide·--check
Offset 368, 50 lines modifiedOffset 368, 50 lines modified
368 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.3368 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.3
369 References:·_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)369 References:·_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)
370 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4370 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4
371 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227371 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
372 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R28372 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R28
373 ············_\x8c_\x8i_\x8s············1.1.2.3.1373 ············_\x8c_\x8i_\x8s············1.1.2.3.1
374 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-257843r991589_rule374 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-257843r991589_rule
375 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
376 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
377 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high 
378 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
379 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
380 part·/home 
381 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8375 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
382 [[customizations.filesystem]]376 [[customizations.filesystem]]
383 mountpoint·=·"/home"377 mountpoint·=·"/home"
384 size·=·1073741824378 size·=·1073741824
385 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8379 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
386 logvol·/home·1024380 logvol·/home·1024
387 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/s\x8sr\x8rv\x8v·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8* 
388 If·a·file·server·(FTP,·TFTP...)·is·hosted·locally,·create·a·separate·partition·for·/srv·at·installation·time·(or·migrate·it·later·using·LVM).·If·/srv·will·be·mounted·from·another·system·such·as·an·NFS·server,·then·creating·a·separate·partition·is·not·necessary·at·installation·time,·and·the·mountpoint·can·instead·be·configured·later. 
389 Rationale:··Srv·deserves·files·for·local·network·file·server·such·as·FTP.·Ensuring·that·/srv·is·mounted·on·its·own·partition·enables·the·setting·of·more·restrictive·mount·options,·and·also·helps·ensure·that·users·cannot·trivially·fill·partitions·used·for·log·or·audit·data·storage. 
390 Severity: ··unknown 
391 Rule·ID:····xccdf_org.ssgproject.content_rule_partition_for_srv 
392 References:·_\x8a_\x8n_\x8s_\x8s_\x8i·R28 
393 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8381 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
394 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low382 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
395 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high383 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high
396 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false384 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
397 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable385 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
398 part·/srv386 part·/home
 387 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/s\x8sr\x8rv\x8v·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
 388 If·a·file·server·(FTP,·TFTP...)·is·hosted·locally,·create·a·separate·partition·for·/srv·at·installation·time·(or·migrate·it·later·using·LVM).·If·/srv·will·be·mounted·from·another·system·such·as·an·NFS·server,·then·creating·a·separate·partition·is·not·necessary·at·installation·time,·and·the·mountpoint·can·instead·be·configured·later.
 389 Rationale:··Srv·deserves·files·for·local·network·file·server·such·as·FTP.·Ensuring·that·/srv·is·mounted·on·its·own·partition·enables·the·setting·of·more·restrictive·mount·options,·and·also·helps·ensure·that·users·cannot·trivially·fill·partitions·used·for·log·or·audit·data·storage.
Max diff block lines reached; 116627/123185 bytes (94.68%) of diff not shown.
1.24 MB
./usr/share/doc/ssg-nondebian/ssg-cs9-guide-anssi_bp28_high.html
    
Offset 15262, 207 lines modifiedOffset 15262, 207 lines modified
0003b9d0:·7267·6574·3d22·2369·646d·3834·3831·2220··rget="#idm8481"·0003b9d0:·7267·6574·3d22·2369·646d·3834·3831·2220··rget="#idm8481"·
0003b9e0:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol0003b9e0:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol
0003b9f0:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-0003b9f0:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-
0003ba00:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"0003ba00:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"
0003ba10:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate0003ba10:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate
0003ba20:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href0003ba20:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href
0003ba30:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio0003ba30:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio
 0003ba40:·6e20·4f53·4275·696c·6420·426c·7565·7072··n·OSBuild·Bluepr
 0003ba50:·696e·7420·736e·6970·7065·7420·e287·b23c··int·snippet·...<
 0003ba60:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas
 0003ba70:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps
 0003ba80:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="
 0003ba90:·6964·6d38·3438·3122·3e3c·7072·653e·3c63··idm8481"><pre><c
 0003baa0:·6f64·653e·0a5b·5b70·6163·6b61·6765·735d··ode>.[[packages]
 0003bab0:·5d0a·6e61·6d65·203d·2022·6169·6465·220a··].name·=·"aide".
 0003bac0:·7665·7273·696f·6e20·3d20·222a·220a·3c2f··version·=·"*".</
0003ba40:·6e20·7363·7269·7074·20e2·87b2·3c2f·613e··n·script·...</a> 
0003ba50:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class=" 
0003ba60:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c 
0003ba70:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm 
0003ba80:·3834·3831·223e·3c74·6162·6c65·2063·6c61··8481"><table·cla 
0003ba90:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table- 
0003baa0:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo 
0003bab0:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con 
0003bac0:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th> 
0003bad0:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th> 
0003bae0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
0003baf0:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt 
0003bb00:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low 
0003bb10:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
0003bb20:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t 
0003bb30:·643e·6661·6c73·653c·2f74·643e·3c2f·7472··d>false</td></tr 
0003bb40:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg 
0003bb50:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl 
0003bb60:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab 
0003bb70:·6c65·3e3c·7072·653e·3c63·6f64·653e·0a64··le><pre><code>.d 
0003bb80:·6e66·2069·6e73·7461·6c6c·2061·6964·650a··nf·install·aide. 
0003bb90:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d0003bad0:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div
0003bba0:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn0003bae0:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b
0003bbb0:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da0003baf0:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data
0003bbc0:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla0003bb00:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps
0003bbd0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target0003bb10:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
0003bbe0:·3d22·2369·646d·3834·3832·2220·7461·6269··="#idm8482"·tabi0003bb20:·2369·646d·3834·3832·2220·7461·6269·6e64··#idm8482"·tabind
0003bbf0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b0003bb30:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
0003bc00:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa0003bb40:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
0003bc10:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit0003bb50:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
0003bc20:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·0003bb60:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
0003bc30:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!0003bb70:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
0003bc40:·223e·5265·6d65·6469·6174·696f·6e20·416e··">Remediation·An0003bb80:·5265·6d65·6469·6174·696f·6e20·5075·7070··Remediation·Pupp
0003bc50:·6163·6f6e·6461·2073·6e69·7070·6574·20e2··aconda·snippet·.0003bb90:·6574·2073·6e69·7070·6574·20e2·87b2·3c2f··et·snippet·...</
0003bc60:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c0003bba0:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
0003bc70:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll0003bbb0:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
0003bc80:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i0003bbc0:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
0003bc90:·643d·2269·646d·3834·3832·223e·3c74·6162··d="idm8482"><tab0003bbd0:·646d·3834·3832·223e·3c74·6162·6c65·2063··dm8482"><table·c
0003bca0:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·0003bbe0:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl
0003bcb0:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta0003bbf0:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-
0003bcc0:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab0003bc00:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c
0003bcd0:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t0003bc10:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t
0003bce0:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity0003bc20:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t
0003bcf0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t0003bc30:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
0003bd00:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D0003bc40:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru
0003bd10:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><0003bc50:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l
 0003bc60:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
 0003bc70:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th>
 0003bc80:·3c74·643e·6661·6c73·653c·2f74·643e·3c2f··<td>false</td></
 0003bc90:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat
 0003bca0:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena
 0003bcb0:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t
 0003bcc0:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>
 0003bcd0:·696e·636c·7564·6520·696e·7374·616c·6c5f··include·install_
 0003bce0:·6169·6465·0a0a·636c·6173·7320·696e·7374··aide..class·inst
 0003bcf0:·616c·6c5f·6169·6465·207b·0a20·2070·6163··all_aide·{.··pac
 0003bd00:·6b61·6765·207b·2027·6169·6465·273a·0a20··kage·{·'aide':.·
 0003bd10:·2020·2065·6e73·7572·6520·3d26·6774·3b20·····ensure·=&gt;·
 0003bd20:·2769·6e73·7461·6c6c·6564·272c·0a20·207d··'installed',.··}
 0003bd30:·0a7d·0a3c·2f63·6f64·653e·3c2f·7072·653e··.}.</code></pre>
 0003bd40:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class="
 0003bd50:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success"
 0003bd60:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co
 0003bd70:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar
 0003bd80:·6765·743d·2223·6964·6d38·3438·3322·2074··get="#idm8483"·t
 0003bd90:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
 0003bda0:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
 0003bdb0:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
 0003bdc0:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
 0003bdd0:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
 0003bde0:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
 0003bdf0:·2073·6372·6970·7420·e287·b23c·2f61·3e3c···script·...</a><
 0003be00:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
 0003be10:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
 0003be20:·6c6c·6170·7365·2220·6964·3d22·6964·6d38··llapse"·id="idm8
 0003be30:·3438·3322·3e3c·7461·626c·6520·636c·6173··483"><table·clas
 0003be40:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s
 0003be50:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor
 0003be60:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond
 0003be70:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C
 0003be80:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><
0003bd20:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>0003be90:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
0003bd30:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:< 
0003bd40:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t0003bea0:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti
 0003beb0:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<
0003bd50:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S0003bec0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
0003bd60:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td 
0003bd70:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr 
0003bd80:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c 
0003bd90:·6f64·653e·0a70·6163·6b61·6765·202d·2d61··ode>.package·--a 
0003bda0:·6464·3d61·6964·650a·3c2f·636f·6465·3e3c··dd=aide.</code>< 
0003bdb0:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl 
0003bdc0:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc 
0003bdd0:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl 
0003bde0:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat 
0003bdf0:·612d·7461·7267·6574·3d22·2369·646d·3834··a-target="#idm84 
0003be00:·3833·2220·7461·6269·6e64·6578·3d22·3022··83"·tabindex="0" 
0003be10:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a 
0003be20:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa 
0003be30:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti 
0003be40:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"· 
0003be50:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi 
0003be60:·6174·696f·6e20·4f53·4275·696c·6420·426c··ation·OSBuild·Bl 
0003be70:·7565·7072·696e·7420·736e·6970·7065·7420··ueprint·snippet·0003bed0:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td
 0003bee0:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr>
 0003bef0:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy
 0003bf00:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable
 0003bf10:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl
 0003bf20:·653e·3c70·7265·3e3c·636f·6465·3e0a·7061··e><pre><code>.pa
 0003bf30:·636b·6167·6520·696e·7374·616c·6c20·6169··ckage·install·ai
 0003bf40:·6465·0a3c·2f63·6f64·653e·3c2f·7072·653e··de.</code></pre>
Max diff block lines reached; 1141914/1169128 bytes (97.67%) of diff not shown.
130 KB
html2text {}
    
Offset 158, 52 lines modifiedOffset 158, 38 lines modified
158 ··-·PCI-DSSv4-11.5.2158 ··-·PCI-DSSv4-11.5.2
159 ··-·enable_strategy159 ··-·enable_strategy
160 ··-·low_complexity160 ··-·low_complexity
161 ··-·low_disruption161 ··-·low_disruption
162 ··-·medium_severity162 ··-·medium_severity
163 ··-·no_reboot_needed163 ··-·no_reboot_needed
164 ··-·package_aide_installed164 ··-·package_aide_installed
165 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
166 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
167 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
168 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
169 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
170 dnf·install·aide 
171 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
172 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
173 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
174 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
175 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
176 package·--add=aide 
177 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8165 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
178 [[packages]]166 [[packages]]
179 name·=·"aide"167 name·=·"aide"
180 version·=·"*"168 version·=·"*"
181 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
182 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
183 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
184 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
185 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
186 package·install·aide 
187 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8169 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
188 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low170 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
189 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low171 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
190 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false172 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
191 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable173 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
192 include·install_aide174 include·install_aide
  
193 class·install_aide·{175 class·install_aide·{
194 ··package·{·'aide':176 ··package·{·'aide':
195 ····ensure·=>·'installed',177 ····ensure·=>·'installed',
196 ··}178 ··}
197 }179 }
 180 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 181 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 182 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 183 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 184 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 185 package·install·aide
198 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8186 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
199 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low187 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
200 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low188 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
201 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false189 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
202 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable190 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
203 #·Remediation·is·applicable·only·in·certain·platforms191 #·Remediation·is·applicable·only·in·certain·platforms
204 if·rpm·--quiet·-q·kernel;·then192 if·rpm·--quiet·-q·kernel;·then
Offset 211, 14 lines modifiedOffset 197, 28 lines modified
211 if·!·rpm·-q·--quiet·"aide"·;·then197 if·!·rpm·-q·--quiet·"aide"·;·then
212 ····dnf·install·-y·"aide"198 ····dnf·install·-y·"aide"
213 fi199 fi
  
214 else200 else
215 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'201 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
216 fi202 fi
 203 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 204 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 205 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 206 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 207 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 208 package·--add=aide
 209 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 210 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 211 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 212 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 213 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 214 dnf·install·aide
217 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*215 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
218 Run·the·following·command·to·generate·a·new·database:216 Run·the·following·command·to·generate·a·new·database:
219 $·sudo·/usr/sbin/aide·--init217 $·sudo·/usr/sbin/aide·--init
220 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:218 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
221 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz219 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
222 To·initiate·a·manual·check,·run·the·following·command:220 To·initiate·a·manual·check,·run·the·following·command:
223 $·sudo·/usr/sbin/aide·--check221 $·sudo·/usr/sbin/aide·--check
Offset 881, 50 lines modifiedOffset 881, 50 lines modified
881 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.3881 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.3
882 References:·_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)882 References:·_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)
883 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4883 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4
884 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227884 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
885 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R28885 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R28
886 ············_\x8c_\x8i_\x8s············1.1.2.3.1886 ············_\x8c_\x8i_\x8s············1.1.2.3.1
887 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-257843r991589_rule887 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-257843r991589_rule
888 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
889 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
890 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high 
891 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
892 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
893 part·/home 
894 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8888 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
895 [[customizations.filesystem]]889 [[customizations.filesystem]]
896 mountpoint·=·"/home"890 mountpoint·=·"/home"
897 size·=·1073741824891 size·=·1073741824
898 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8892 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
899 logvol·/home·1024893 logvol·/home·1024
900 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/s\x8sr\x8rv\x8v·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8* 
901 If·a·file·server·(FTP,·TFTP...)·is·hosted·locally,·create·a·separate·partition·for·/srv·at·installation·time·(or·migrate·it·later·using·LVM).·If·/srv·will·be·mounted·from·another·system·such·as·an·NFS·server,·then·creating·a·separate·partition·is·not·necessary·at·installation·time,·and·the·mountpoint·can·instead·be·configured·later. 
902 Rationale:··Srv·deserves·files·for·local·network·file·server·such·as·FTP.·Ensuring·that·/srv·is·mounted·on·its·own·partition·enables·the·setting·of·more·restrictive·mount·options,·and·also·helps·ensure·that·users·cannot·trivially·fill·partitions·used·for·log·or·audit·data·storage. 
903 Severity: ··unknown 
904 Rule·ID:····xccdf_org.ssgproject.content_rule_partition_for_srv 
905 References:·_\x8a_\x8n_\x8s_\x8s_\x8i·R28 
906 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8894 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
907 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low895 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
908 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high896 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high
909 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false897 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
910 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable898 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
911 part·/srv899 part·/home
 900 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/s\x8sr\x8rv\x8v·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
 901 If·a·file·server·(FTP,·TFTP...)·is·hosted·locally,·create·a·separate·partition·for·/srv·at·installation·time·(or·migrate·it·later·using·LVM).·If·/srv·will·be·mounted·from·another·system·such·as·an·NFS·server,·then·creating·a·separate·partition·is·not·necessary·at·installation·time,·and·the·mountpoint·can·instead·be·configured·later.
 902 Rationale:··Srv·deserves·files·for·local·network·file·server·such·as·FTP.·Ensuring·that·/srv·is·mounted·on·its·own·partition·enables·the·setting·of·more·restrictive·mount·options,·and·also·helps·ensure·that·users·cannot·trivially·fill·partitions·used·for·log·or·audit·data·storage.
Max diff block lines reached; 126706/133264 bytes (95.08%) of diff not shown.
1.04 MB
./usr/share/doc/ssg-nondebian/ssg-cs9-guide-anssi_bp28_intermediary.html
    
Offset 15252, 208 lines modifiedOffset 15252, 208 lines modified
0003b930:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="0003b930:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
0003b940:·2369·646d·3834·3831·2220·7461·6269·6e64··#idm8481"·tabind0003b940:·2369·646d·3834·3831·2220·7461·6269·6e64··#idm8481"·tabind
0003b950:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but0003b950:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
0003b960:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand0003b960:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
0003b970:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title0003b970:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
0003b980:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re0003b980:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
0003b990:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">0003b990:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
0003b9a0:·5265·6d65·6469·6174·696f·6e20·7363·7269··Remediation·scri0003b9a0:·5265·6d65·6469·6174·696f·6e20·4f53·4275··Remediation·OSBu
 0003b9b0:·696c·6420·426c·7565·7072·696e·7420·736e··ild·Blueprint·sn
 0003b9c0:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br
 0003b9d0:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
 0003b9e0:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
 0003b9f0:·6170·7365·2220·6964·3d22·6964·6d38·3438··apse"·id="idm848
 0003ba00:·3122·3e3c·7072·653e·3c63·6f64·653e·0a5b··1"><pre><code>.[
 0003ba10:·5b70·6163·6b61·6765·735d·5d0a·6e61·6d65··[packages]].name
 0003ba20:·203d·2022·6169·6465·220a·7665·7273·696f···=·"aide".versio
 0003ba30:·6e20·3d20·222a·220a·3c2f·636f·6465·3e3c··n·=·"*".</code><
0003b9b0:·7074·20e2·87b2·3c2f·613e·3c62·723e·3c64··pt·...</a><br><d 
0003b9c0:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel- 
0003b9d0:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps 
0003b9e0:·6522·2069·643d·2269·646d·3834·3831·223e··e"·id="idm8481"> 
0003b9f0:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta 
0003ba00:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe 
0003ba10:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered 
0003ba20:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed 
0003ba30:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple 
0003ba40:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo 
0003ba50:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr>< 
0003ba60:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</ 
0003ba70:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td>< 
0003ba80:·2f74·723e·3c74·723e·3c74·683e·5265·626f··/tr><tr><th>Rebo 
0003ba90:·6f74·3a3c·2f74·683e·3c74·643e·6661·6c73··ot:</th><td>fals 
0003baa0:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr>< 
0003bab0:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th 
0003bac0:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td> 
0003bad0:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr 
0003bae0:·653e·3c63·6f64·653e·0a64·6e66·2069·6e73··e><code>.dnf·ins 
0003baf0:·7461·6c6c·2061·6964·650a·3c2f·636f·6465··tall·aide.</code 
0003bb00:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a·0003ba40:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl
0003bb10:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s0003ba50:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc
0003bb20:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog0003ba60:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl
0003bb30:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d0003ba70:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat
0003bb40:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm0003ba80:·612d·7461·7267·6574·3d22·2369·646d·3834··a-target="#idm84
0003bb50:·3834·3832·2220·7461·6269·6e64·6578·3d22··8482"·tabindex="0003ba90:·3832·2220·7461·6269·6e64·6578·3d22·3022··82"·tabindex="0"
0003bb60:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"0003baa0:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
0003bb70:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="0003bab0:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
0003bb80:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac0003bac0:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
0003bb90:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal0003bad0:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
0003bba0:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme0003bae0:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
0003bbb0:·6469·6174·696f·6e20·416e·6163·6f6e·6461··diation·Anaconda0003baf0:·6174·696f·6e20·5075·7070·6574·2073·6e69··ation·Puppet·sni
0003bbc0:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>0003bb00:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>
0003bbd0:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="0003bb10:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
0003bbe0:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c0003bb20:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
0003bbf0:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm0003bb30:·7073·6522·2069·643d·2269·646d·3834·3832··pse"·id="idm8482
0003bc00:·3834·3832·223e·3c74·6162·6c65·2063·6c61··8482"><table·cla0003bb40:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="
0003bc10:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-0003bb50:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri
0003bc20:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo0003bb60:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border
0003bc30:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con0003bb70:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens
0003bc40:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>0003bb80:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp
0003bc50:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>0003bb90:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>
0003bc60:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr0003bba0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
0003bc70:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt0003bbb0:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:
 0003bbc0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
 0003bbd0:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re
 0003bbe0:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa
 0003bbf0:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr
 0003bc00:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</
 0003bc10:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t
 0003bc20:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><
 0003bc30:·7072·653e·3c63·6f64·653e·696e·636c·7564··pre><code>includ
 0003bc40:·6520·696e·7374·616c·6c5f·6169·6465·0a0a··e·install_aide..
 0003bc50:·636c·6173·7320·696e·7374·616c·6c5f·6169··class·install_ai
 0003bc60:·6465·207b·0a20·2070·6163·6b61·6765·207b··de·{.··package·{
 0003bc70:·2027·6169·6465·273a·0a20·2020·2065·6e73···'aide':.····ens
 0003bc80:·7572·6520·3d26·6774·3b20·2769·6e73·7461··ure·=&gt;·'insta
 0003bc90:·6c6c·6564·272c·0a20·207d·0a7d·0a3c·2f63··lled',.··}.}.</c
 0003bca0:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div>
 0003bcb0:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt
 0003bcc0:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data-
 0003bcd0:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse
 0003bce0:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
 0003bcf0:·6964·6d38·3438·3322·2074·6162·696e·6465··idm8483"·tabinde
 0003bd00:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt
 0003bd10:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande
 0003bd20:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=
 0003bd30:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev
 0003bd40:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R
 0003bd50:·656d·6564·6961·7469·6f6e·2073·6372·6970··emediation·scrip
 0003bd60:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di
 0003bd70:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c
 0003bd80:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse
 0003bd90:·2220·6964·3d22·6964·6d38·3438·3322·3e3c··"·id="idm8483"><
 0003bda0:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab
 0003bdb0:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped
 0003bdc0:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·
 0003bdd0:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"
 0003bde0:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex
0003bc80:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low0003bdf0:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low
0003bc90:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t0003be00:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
0003bca0:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t 
0003bcb0:·643e·6661·6c73·653c·2f74·643e·3c2f·7472··d>false</td></tr 
0003bcc0:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg0003be10:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t
 0003be20:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
 0003be30:·7472·3e3c·7472·3e3c·7468·3e52·6562·6f6f··tr><tr><th>Reboo
0003bcd0:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl0003be40:·743a·3c2f·7468·3e3c·7464·3e66·616c·7365··t:</th><td>false
0003bce0:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab 
0003bcf0:·6c65·3e3c·7072·653e·3c63·6f64·653e·0a70··le><pre><code>.p 
0003bd00:·6163·6b61·6765·202d·2d61·6464·3d61·6964··ackage·--add=aid 
0003bd10:·650a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··e.</code></pre>< 
0003bd20:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b 
0003bd30:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"· 
0003bd40:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col 
0003bd50:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ 
0003bd60:·6574·3d22·2369·646d·3834·3833·2220·7461··et="#idm8483"·ta 
0003bd70:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role= 
0003bd80:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex 
0003bd90:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t 
0003bda0:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t 
0003bdb0:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href=" 
0003bdc0:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation· 
0003bdd0:·4f53·4275·696c·6420·426c·7565·7072·696e··OSBuild·Blueprin0003be50:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
 0003be60:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th>
 0003be70:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td><
 0003be80:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre
 0003be90:·3e3c·636f·6465·3e0a·7061·636b·6167·6520··><code>.package·
 0003bea0:·696e·7374·616c·6c20·6169·6465·0a3c·2f63··install·aide.</c
 0003beb0:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div>
Max diff block lines reached; 962588/989940 bytes (97.24%) of diff not shown.
96.4 KB
html2text {}
    
Offset 173, 52 lines modifiedOffset 173, 38 lines modified
173 ··-·PCI-DSSv4-11.5.2173 ··-·PCI-DSSv4-11.5.2
174 ··-·enable_strategy174 ··-·enable_strategy
175 ··-·low_complexity175 ··-·low_complexity
176 ··-·low_disruption176 ··-·low_disruption
177 ··-·medium_severity177 ··-·medium_severity
178 ··-·no_reboot_needed178 ··-·no_reboot_needed
179 ··-·package_aide_installed179 ··-·package_aide_installed
180 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
181 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
182 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
183 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
184 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
185 dnf·install·aide 
186 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
187 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
188 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
189 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
190 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
191 package·--add=aide 
192 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8180 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
193 [[packages]]181 [[packages]]
194 name·=·"aide"182 name·=·"aide"
195 version·=·"*"183 version·=·"*"
196 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
197 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
198 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
199 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
200 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
201 package·install·aide 
202 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8184 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
203 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low185 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
204 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low186 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
205 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false187 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
206 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable188 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
207 include·install_aide189 include·install_aide
  
208 class·install_aide·{190 class·install_aide·{
209 ··package·{·'aide':191 ··package·{·'aide':
210 ····ensure·=>·'installed',192 ····ensure·=>·'installed',
211 ··}193 ··}
212 }194 }
 195 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 196 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 197 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 198 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 199 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 200 package·install·aide
213 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8201 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
214 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low202 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
215 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low203 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
216 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false204 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
217 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable205 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
218 #·Remediation·is·applicable·only·in·certain·platforms206 #·Remediation·is·applicable·only·in·certain·platforms
219 if·rpm·--quiet·-q·kernel;·then207 if·rpm·--quiet·-q·kernel;·then
Offset 226, 14 lines modifiedOffset 212, 28 lines modified
226 if·!·rpm·-q·--quiet·"aide"·;·then212 if·!·rpm·-q·--quiet·"aide"·;·then
227 ····dnf·install·-y·"aide"213 ····dnf·install·-y·"aide"
228 fi214 fi
  
229 else215 else
230 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'216 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
231 fi217 fi
 218 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 219 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 220 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 221 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 222 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 223 package·--add=aide
 224 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 225 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 226 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 227 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 228 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 229 dnf·install·aide
232 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*230 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
233 Run·the·following·command·to·generate·a·new·database:231 Run·the·following·command·to·generate·a·new·database:
234 $·sudo·/usr/sbin/aide·--init232 $·sudo·/usr/sbin/aide·--init
235 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the233 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the
236 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these234 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these
237 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their235 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their
238 integrity.·The·newly-generated·database·can·be·installed·as·follows:236 integrity.·The·newly-generated·database·can·be·installed·as·follows:
Offset 407, 56 lines modifiedOffset 407, 56 lines modified
407 References:·_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.3407 References:·_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.3
408 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)408 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)
409 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4409 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4
410 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227410 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
411 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R28411 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R28
412 ············_\x8c_\x8i_\x8s············1.1.2.3.1412 ············_\x8c_\x8i_\x8s············1.1.2.3.1
413 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-257843r991589_rule413 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-257843r991589_rule
414 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
415 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
416 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high 
417 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
418 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
419 part·/home 
420 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8414 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
421 [[customizations.filesystem]]415 [[customizations.filesystem]]
422 mountpoint·=·"/home"416 mountpoint·=·"/home"
423 size·=·1073741824417 size·=·1073741824
424 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8418 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
425 logvol·/home·1024419 logvol·/home·1024
 420 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 421 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 422 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high
 423 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 424 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 425 part·/home
426 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/s\x8sr\x8rv\x8v·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*426 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/s\x8sr\x8rv\x8v·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
427 If·a·file·server·(FTP,·TFTP...)·is·hosted·locally,·create·a·separate·partition·for·/srv·at427 If·a·file·server·(FTP,·TFTP...)·is·hosted·locally,·create·a·separate·partition·for·/srv·at
428 installation·time·(or·migrate·it·later·using·LVM).·If·/srv·will·be·mounted·from·another·system·such428 installation·time·(or·migrate·it·later·using·LVM).·If·/srv·will·be·mounted·from·another·system·such
429 as·an·NFS·server,·then·creating·a·separate·partition·is·not·necessary·at·installation·time,·and·the429 as·an·NFS·server,·then·creating·a·separate·partition·is·not·necessary·at·installation·time,·and·the
430 mountpoint·can·instead·be·configured·later.430 mountpoint·can·instead·be·configured·later.
431 ············Srv·deserves·files·for·local·network·file·server·such·as·FTP.·Ensuring·that·/srv·is431 ············Srv·deserves·files·for·local·network·file·server·such·as·FTP.·Ensuring·that·/srv·is
432 Rationale:··mounted·on·its·own·partition·enables·the·setting·of·more·restrictive·mount·options,·and432 Rationale:··mounted·on·its·own·partition·enables·the·setting·of·more·restrictive·mount·options,·and
433 ············also·helps·ensure·that·users·cannot·trivially·fill·partitions·used·for·log·or·audit·data433 ············also·helps·ensure·that·users·cannot·trivially·fill·partitions·used·for·log·or·audit·data
434 ············storage.434 ············storage.
Max diff block lines reached; 93380/98679 bytes (94.63%) of diff not shown.
400 KB
./usr/share/doc/ssg-nondebian/ssg-cs9-guide-anssi_bp28_minimal.html
    
Offset 14929, 222 lines modifiedOffset 14929, 222 lines modified
0003a500:·2d74·6172·6765·743d·2223·6964·6d31·3236··-target="#idm1260003a500:·2d74·6172·6765·743d·2223·6964·6d31·3236··-target="#idm126
0003a510:·3732·2220·7461·6269·6e64·6578·3d22·3022··72"·tabindex="0"0003a510:·3732·2220·7461·6269·6e64·6578·3d22·3022··72"·tabindex="0"
0003a520:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a0003a520:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
0003a530:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa0003a530:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
0003a540:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti0003a540:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
0003a550:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·0003a550:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
0003a560:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi0003a560:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
0003a570:·6174·696f·6e20·7363·7269·7074·20e2·87b2··ation·script·... 
0003a580:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla 
0003a590:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap 
0003a5a0:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id= 
0003a5b0:·2269·646d·3132·3637·3222·3e3c·7461·626c··"idm12672"><tabl0003a570:·6174·696f·6e20·4f53·4275·696c·6420·426c··ation·OSBuild·Bl
 0003a580:·7565·7072·696e·7420·736e·6970·7065·7420··ueprint·snippet·
 0003a590:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·
 0003a5a0:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col
 0003a5b0:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·
 0003a5c0:·6964·3d22·6964·6d31·3236·3732·223e·3c70··id="idm12672"><p
 0003a5d0:·7265·3e3c·636f·6465·3e0a·5b5b·7061·636b··re><code>.[[pack
 0003a5e0:·6167·6573·5d5d·0a6e·616d·6520·3d20·2264··ages]].name·=·"d
 0003a5f0:·6e66·2d61·7574·6f6d·6174·6963·220a·7665··nf-automatic".ve
 0003a600:·7273·696f·6e20·3d20·222a·220a·3c2f·636f··rsion·=·"*".</co
 0003a610:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div><
0003a5c0:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t0003a620:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn
0003a5d0:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab 
0003a5e0:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl 
0003a5f0:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr 
0003a600:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:0003a630:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t
 0003a640:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse"
 0003a650:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i
 0003a660:·646d·3132·3637·3322·2074·6162·696e·6465··dm12673"·tabinde
 0003a670:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt
 0003a680:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande
 0003a690:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=
 0003a6a0:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev
 0003a6b0:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R
 0003a6c0:·656d·6564·6961·7469·6f6e·2050·7570·7065··emediation·Puppe
 0003a6d0:·7420·736e·6970·7065·7420·e287·b23c·2f61··t·snippet·...</a
 0003a6e0:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
 0003a6f0:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
 0003a700:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
 0003a710:·6d31·3236·3733·223e·3c74·6162·6c65·2063··m12673"><table·c
 0003a720:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl
 0003a730:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-
 0003a740:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c
 0003a750:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t
 0003a760:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t
 0003a770:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
 0003a780:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru
 0003a790:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l
 0003a7a0:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
 0003a7b0:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th>
 0003a7c0:·3c74·643e·6661·6c73·653c·2f74·643e·3c2f··<td>false</td></
 0003a7d0:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat
 0003a7e0:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena
 0003a7f0:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t
 0003a800:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>
 0003a810:·696e·636c·7564·6520·696e·7374·616c·6c5f··include·install_
 0003a820:·646e·662d·6175·746f·6d61·7469·630a·0a63··dnf-automatic..c
 0003a830:·6c61·7373·2069·6e73·7461·6c6c·5f64·6e66··lass·install_dnf
 0003a840:·2d61·7574·6f6d·6174·6963·207b·0a20·2070··-automatic·{.··p
 0003a850:·6163·6b61·6765·207b·2027·646e·662d·6175··ackage·{·'dnf-au
 0003a860:·746f·6d61·7469·6327·3a0a·2020·2020·656e··tomatic':.····en
 0003a870:·7375·7265·203d·2667·743b·2027·696e·7374··sure·=&gt;·'inst
 0003a880:·616c·6c65·6427·2c0a·2020·7d0a·7d0a·3c2f··alled',.··}.}.</
 0003a890:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div
 0003a8a0:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b
 0003a8b0:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data
 0003a8c0:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps
 0003a8d0:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
 0003a8e0:·2369·646d·3132·3637·3422·2074·6162·696e··#idm12674"·tabin
 0003a8f0:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
 0003a900:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
 0003a910:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
 0003a920:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
 0003a930:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
 0003a940:·3e52·656d·6564·6961·7469·6f6e·2073·6372··>Remediation·scr
 0003a950:·6970·7420·e287·b23c·2f61·3e3c·6272·3e3c··ipt·...</a><br><
 0003a960:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
 0003a970:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap
 0003a980:·7365·2220·6964·3d22·6964·6d31·3236·3734··se"·id="idm12674
 0003a990:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="
 0003a9a0:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri
 0003a9b0:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border
 0003a9c0:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens
 0003a9d0:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp
 0003a9e0:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>
 0003a9f0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
 0003aa00:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:
0003a610:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td0003aa10:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
0003a620:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di0003aa20:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re
0003a630:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t0003aa30:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa
0003a640:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><0003aa40:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr
0003a650:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</0003aa50:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</
0003a660:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td0003aa60:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t
 0003aa70:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><
 0003aa80:·7072·653e·3c63·6f64·653e·0a70·6163·6b61··pre><code>.packa
 0003aa90:·6765·2069·6e73·7461·6c6c·2064·6e66·2d61··ge·install·dnf-a
 0003aaa0:·7574·6f6d·6174·6963·0a3c·2f63·6f64·653e··utomatic.</code>
 0003aab0:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c
 0003aac0:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su
 0003aad0:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg
0003a670:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St 
0003a680:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td> 
0003a690:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr> 
0003a6a0:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co 
0003a6b0:·6465·3e0a·646e·6620·696e·7374·616c·6c20··de>.dnf·install· 
0003a6c0:·646e·662d·6175·746f·6d61·7469·630a·3c2f··dnf-automatic.</ 
0003a6d0:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div 
0003a6e0:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b 
0003a6f0:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data 
0003a700:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps 
0003a710:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target=" 
0003a720:·2369·646d·3132·3637·3322·2074·6162·696e··#idm12673"·tabin 
0003a730:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu 
0003a740:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan 
0003a750:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl 
0003a760:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r 
0003a770:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!" 
0003a780:·3e52·656d·6564·6961·7469·6f6e·2041·6e61··>Remediation·Ana 
0003a790:·636f·6e64·6120·736e·6970·7065·7420·e287··conda·snippet·.. 
0003a7a0:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl 
0003a7b0:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla 
0003a7c0:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id0003aae0:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da
0003a7d0:·3d22·6964·6d31·3236·3733·223e·3c74·6162··="idm12673"><tab 
0003a7e0:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table· 
0003a7f0:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta 
0003a800:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab 
Max diff block lines reached; 337084/366368 bytes (92.01%) of diff not shown.
42.2 KB
html2text {}
    
Offset 132, 52 lines modifiedOffset 132, 38 lines modified
132 ··tags:132 ··tags:
133 ··-·enable_strategy133 ··-·enable_strategy
134 ··-·low_complexity134 ··-·low_complexity
135 ··-·low_disruption135 ··-·low_disruption
136 ··-·medium_severity136 ··-·medium_severity
137 ··-·no_reboot_needed137 ··-·no_reboot_needed
138 ··-·package_dnf-automatic_installed138 ··-·package_dnf-automatic_installed
139 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
140 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
141 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
142 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
143 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
144 dnf·install·dnf-automatic 
145 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
146 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
147 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
148 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
149 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
150 package·--add=dnf-automatic 
151 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8139 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
152 [[packages]]140 [[packages]]
153 name·=·"dnf-automatic"141 name·=·"dnf-automatic"
154 version·=·"*"142 version·=·"*"
155 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
156 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
157 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
158 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
159 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
160 package·install·dnf-automatic 
161 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8143 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
162 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low144 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
163 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low145 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
164 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false146 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
165 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable147 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
166 include·install_dnf-automatic148 include·install_dnf-automatic
  
167 class·install_dnf-automatic·{149 class·install_dnf-automatic·{
168 ··package·{·'dnf-automatic':150 ··package·{·'dnf-automatic':
169 ····ensure·=>·'installed',151 ····ensure·=>·'installed',
170 ··}152 ··}
171 }153 }
 154 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 155 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 156 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 157 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 158 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 159 package·install·dnf-automatic
172 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8160 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
173 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low161 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
174 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low162 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
175 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false163 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
176 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable164 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
177 #·Remediation·is·applicable·only·in·certain·platforms165 #·Remediation·is·applicable·only·in·certain·platforms
178 if·!·(·{·rpm·--quiet·-q·kernel·;}·&&·{·rpm·--quiet·-q·rpm-ostree·;}·&&·{·rpm·--quiet·-166 if·!·(·{·rpm·--quiet·-q·kernel·;}·&&·{·rpm·--quiet·-q·rpm-ostree·;}·&&·{·rpm·--quiet·-
Offset 186, 14 lines modifiedOffset 172, 28 lines modified
186 if·!·rpm·-q·--quiet·"dnf-automatic"·;·then172 if·!·rpm·-q·--quiet·"dnf-automatic"·;·then
187 ····dnf·install·-y·"dnf-automatic"173 ····dnf·install·-y·"dnf-automatic"
188 fi174 fi
  
189 else175 else
190 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'176 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
191 fi177 fi
 178 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 179 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 180 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 181 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 182 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 183 package·--add=dnf-automatic
 184 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 185 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 186 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 187 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 188 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 189 dnf·install·dnf-automatic
192 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·d\x8dn\x8nf\x8f-\x8-a\x8au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8c·t\x8to\x8o·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·A\x8Av\x8va\x8ai\x8il\x8la\x8ab\x8bl\x8le\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8es\x8s·A\x8Au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8ca\x8al\x8ll\x8ly\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*190 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·d\x8dn\x8nf\x8f-\x8-a\x8au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8c·t\x8to\x8o·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·A\x8Av\x8va\x8ai\x8il\x8la\x8ab\x8bl\x8le\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8es\x8s·A\x8Au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8ca\x8al\x8ll\x8ly\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
193 To·ensure·that·the·packages·comprising·the·available·updates·will·be·automatically·installed191 To·ensure·that·the·packages·comprising·the·available·updates·will·be·automatically·installed
194 by·dnf-automatic,·set·apply_updates·to·yes·under·[commands]·section·in·/etc/dnf/192 by·dnf-automatic,·set·apply_updates·to·yes·under·[commands]·section·in·/etc/dnf/
195 automatic.conf.193 automatic.conf.
196 ············Installing·software·updates·is·a·fundamental·mitigation·against·the·exploitation194 ············Installing·software·updates·is·a·fundamental·mitigation·against·the·exploitation
197 ············of·publicly-known·vulnerabilities.·If·the·most·recent·security·patches·and195 ············of·publicly-known·vulnerabilities.·If·the·most·recent·security·patches·and
198 Rationale:··updates·are·not·installed,·unauthorized·users·may·take·advantage·of·weaknesses·in196 Rationale:··updates·are·not·installed,·unauthorized·users·may·take·advantage·of·weaknesses·in
Offset 10226, 47 lines modifiedOffset 10226, 33 lines modified
10226 ··-·PCI-DSSv4-2.2.410226 ··-·PCI-DSSv4-2.2.4
10227 ··-·disable_strategy10227 ··-·disable_strategy
10228 ··-·low_complexity10228 ··-·low_complexity
10229 ··-·low_disruption10229 ··-·low_disruption
10230 ··-·medium_severity10230 ··-·medium_severity
10231 ··-·no_reboot_needed10231 ··-·no_reboot_needed
10232 ··-·package_dhcp_removed10232 ··-·package_dhcp_removed
10233 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
10234 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
10235 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
10236 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
10237 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable 
  
10238 dnf·remove·dhcp-server 
10239 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
10240 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
10241 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
10242 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
10243 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable 
  
10244 package·--remove=dhcp-server 
10245 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
10246 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
10247 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
10248 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
10249 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable 
  
10250 package·remove·dhcp-server 
10251 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x810233 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
10252 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low10234 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
10253 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low10235 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
10254 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false10236 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
10255 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable10237 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
10256 include·remove_dhcp-server10238 include·remove_dhcp-server
  
10257 class·remove_dhcp-server·{10239 class·remove_dhcp-server·{
10258 ··package·{·'dhcp-server':10240 ··package·{·'dhcp-server':
10259 ····ensure·=>·'purged',10241 ····ensure·=>·'purged',
Max diff block lines reached; 38398/43188 bytes (88.91%) of diff not shown.
433 KB
./usr/share/doc/ssg-nondebian/ssg-cs9-guide-ccn_advanced.html
    
Offset 22081, 201 lines modifiedOffset 22081, 201 lines modified
00056400:·6172·6765·743d·2223·6964·6d31·3233·3439··arget="#idm1234900056400:·6172·6765·743d·2223·6964·6d31·3233·3439··arget="#idm12349
00056410:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r00056410:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r
00056420:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari00056420:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari
00056430:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals00056430:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals
00056440:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa00056440:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa
00056450:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr00056450:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr
00056460:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat00056460:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat
00056470:·696f·6e20·7363·7269·7074·20e2·87b2·3c2f··ion·script·...</ 
00056480:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class 
00056490:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse 
000564a0:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i 
000564b0:·646d·3132·3334·3922·3e3c·7461·626c·6520··dm12349"><table· 
000564c0:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab 
000564d0:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table 
000564e0:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table- 
000564f0:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr>< 
00056500:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</00056470:·696f·6e20·4f53·4275·696c·6420·426c·7565··ion·OSBuild·Blue
 00056480:·7072·696e·7420·736e·6970·7065·7420·e287··print·snippet·..
 00056490:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl
 000564a0:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla
 000564b0:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id
 000564c0:·3d22·6964·6d31·3233·3439·223e·3c70·7265··="idm12349"><pre
 000564d0:·3e3c·636f·6465·3e0a·5b5b·7061·636b·6167··><code>.[[packag
 000564e0:·6573·5d5d·0a6e·616d·6520·3d20·2263·7279··es]].name·=·"cry
 000564f0:·7074·7365·7475·7022·0a76·6572·7369·6f6e··ptsetup".version
 00056500:·203d·2022·2a22·0a3c·2f63·6f64·653e·3c2f···=·"*".</code></
 00056510:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla
 00056520:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ
 00056530:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle
 00056540:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data
 00056550:·2d74·6172·6765·743d·2223·6964·6d31·3233··-target="#idm123
 00056560:·3530·2220·7461·6269·6e64·6578·3d22·3022··50"·tabindex="0"
 00056570:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
 00056580:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
 00056590:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
 000565a0:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
 000565b0:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
 000565c0:·6174·696f·6e20·5075·7070·6574·2073·6e69··ation·Puppet·sni
 000565d0:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>
 000565e0:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
 000565f0:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
 00056600:·7073·6522·2069·643d·2269·646d·3132·3335··pse"·id="idm1235
 00056610:·3022·3e3c·7461·626c·6520·636c·6173·733d··0"><table·class=
 00056620:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str
 00056630:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde
 00056640:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden
 00056650:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com
 00056660:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td
 00056670:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
 00056680:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption
 00056690:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
 000566a0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e52··d></tr><tr><th>R
 000566b0:·6562·6f6f·743a·3c2f·7468·3e3c·7464·3e66··eboot:</th><td>f
 000566c0:·616c·7365·3c2f·7464·3e3c·2f74·723e·3c74··alse</td></tr><t
 000566d0:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<
 000566e0:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</
 000566f0:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table>
 00056700:·3c70·7265·3e3c·636f·6465·3e69·6e63·6c75··<pre><code>inclu
 00056710:·6465·2069·6e73·7461·6c6c·5f63·7279·7074··de·install_crypt
 00056720:·7365·7475·700a·0a63·6c61·7373·2069·6e73··setup..class·ins
 00056730:·7461·6c6c·5f63·7279·7074·7365·7475·7020··tall_cryptsetup·
 00056740:·7b0a·2020·7061·636b·6167·6520·7b20·2763··{.··package·{·'c
 00056750:·7279·7074·7365·7475·7027·3a0a·2020·2020··ryptsetup':.····
 00056760:·656e·7375·7265·203d·2667·743b·2027·696e··ensure·=&gt;·'in
 00056770:·7374·616c·6c65·6427·2c0a·2020·7d0a·7d0a··stalled',.··}.}.
 00056780:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d
 00056790:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn
 000567a0:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da
 000567b0:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla
 000567c0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
 000567d0:·3d22·2369·646d·3132·3335·3122·2074·6162··="#idm12351"·tab
 000567e0:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
 000567f0:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
 00056800:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
 00056810:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
 00056820:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
 00056830:·2122·3e52·656d·6564·6961·7469·6f6e·2073··!">Remediation·s
 00056840:·6372·6970·7420·e287·b23c·2f61·3e3c·6272··cript·...</a><br
 00056850:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
 00056860:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
 00056870:·6170·7365·2220·6964·3d22·6964·6d31·3233··apse"·id="idm123
 00056880:·3531·223e·3c74·6162·6c65·2063·6c61·7373··51"><table·class
 00056890:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st
 000568a0:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord
 000568b0:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde
 000568c0:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co
 000568d0:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t
 000568e0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
 000568f0:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio
00056510:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><00056900:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</
00056520:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr00056910:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
00056530:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>00056920:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td>
 00056930:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr><
 00056940:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:
 00056950:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<
 00056960:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table
 00056970:·3e3c·7072·653e·3c63·6f64·653e·0a70·6163··><pre><code>.pac
 00056980:·6b61·6765·2069·6e73·7461·6c6c·2063·7279··kage·install·cry
 00056990:·7074·7365·7475·700a·3c2f·636f·6465·3e3c··ptsetup.</code><
 000569a0:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl
 000569b0:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc
 000569c0:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl
 000569d0:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat
 000569e0:·612d·7461·7267·6574·3d22·2369·646d·3132··a-target="#idm12
 000569f0:·3335·3222·2074·6162·696e·6465·783d·2230··352"·tabindex="0
 00056a00:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
 00056a10:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
 00056a20:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
 00056a30:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
 00056a40:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
 00056a50:·6961·7469·6f6e·2053·6865·6c6c·2073·6372··iation·Shell·scr
 00056a60:·6970·7420·e287·b23c·2f61·3e3c·6272·3e3c··ipt·...</a><br><
 00056a70:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
 00056a80:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap
 00056a90:·7365·2220·6964·3d22·6964·6d31·3233·3532··se"·id="idm12352
 00056aa0:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="
 00056ab0:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri
 00056ac0:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border
 00056ad0:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens
 00056ae0:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp
 00056af0:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>
00056540:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr00056b00:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
00056550:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th 
00056560:·3e3c·7464·3e66·616c·7365·3c2f·7464·3e3c··><td>false</td><00056b10:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:
 00056b20:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
00056570:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra00056b30:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re
00056580:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en 
Max diff block lines reached; 364738/391124 bytes (93.25%) of diff not shown.
51.4 KB
html2text {}
    
Offset 1769, 61 lines modifiedOffset 1769, 61 lines modified
1769 ··-·PCI-DSSv4-3.5.1.21769 ··-·PCI-DSSv4-3.5.1.2
1770 ··-·enable_strategy1770 ··-·enable_strategy
1771 ··-·low_complexity1771 ··-·low_complexity
1772 ··-·low_disruption1772 ··-·low_disruption
1773 ··-·medium_severity1773 ··-·medium_severity
1774 ··-·no_reboot_needed1774 ··-·no_reboot_needed
1775 ··-·package_cryptsetup-luks_installed1775 ··-·package_cryptsetup-luks_installed
1776 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
1777 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
1778 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
1779 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
1780 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
1781 dnf·install·cryptsetup 
1782 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
1783 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
1784 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
1785 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
1786 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
1787 package·--add=cryptsetup 
1788 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81776 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
1789 [[packages]]1777 [[packages]]
1790 name·=·"cryptsetup"1778 name·=·"cryptsetup"
1791 version·=·"*"1779 version·=·"*"
1792 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
1793 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
1794 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
1795 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
1796 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
1797 package·install·cryptsetup 
1798 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81780 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1799 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1781 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1800 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1782 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1801 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1783 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1802 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1784 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1803 include·install_cryptsetup1785 include·install_cryptsetup
  
1804 class·install_cryptsetup·{1786 class·install_cryptsetup·{
1805 ··package·{·'cryptsetup':1787 ··package·{·'cryptsetup':
1806 ····ensure·=>·'installed',1788 ····ensure·=>·'installed',
1807 ··}1789 ··}
1808 }1790 }
 1791 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 1792 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1793 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1794 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1795 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 1796 package·install·cryptsetup
1809 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81797 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1810 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1798 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1811 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1799 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1812 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1800 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1813 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1801 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
1814 if·!·rpm·-q·--quiet·"cryptsetup"·;·then1802 if·!·rpm·-q·--quiet·"cryptsetup"·;·then
1815 ····dnf·install·-y·"cryptsetup"1803 ····dnf·install·-y·"cryptsetup"
1816 fi1804 fi
 1805 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 1806 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1807 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1808 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1809 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 1810 package·--add=cryptsetup
 1811 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 1812 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1813 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1814 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1815 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 1816 dnf·install·cryptsetup
1817 Group  ·Account·and·Access·Control·  Group·contains·13·groups·and·29·rules1817 Group  ·Account·and·Access·Control·  Group·contains·13·groups·and·29·rules
1818 _\x8[_\x8r_\x8e_\x8f_\x8]  ·In·traditional·Unix·security,·if·an·attacker·gains·shell·access·to·a·certain·login·account,·they·can·perform·any·action·or·access·any·file·to·which·that·account·has·access.·Therefore,·making·it·more·difficult·for·unauthorized·people·to·gain·shell·access·to·accounts,·particularly·to·privileged·accounts,·is·a·necessary·part·of·securing·a·system.·This·section·introduces·mechanisms·for·restricting·access·to·accounts·under·Red·Hat·Enterprise·Linux·9.1818 _\x8[_\x8r_\x8e_\x8f_\x8]  ·In·traditional·Unix·security,·if·an·attacker·gains·shell·access·to·a·certain·login·account,·they·can·perform·any·action·or·access·any·file·to·which·that·account·has·access.·Therefore,·making·it·more·difficult·for·unauthorized·people·to·gain·shell·access·to·accounts,·particularly·to·privileged·accounts,·is·a·necessary·part·of·securing·a·system.·This·section·introduces·mechanisms·for·restricting·access·to·accounts·under·Red·Hat·Enterprise·Linux·9.
1819 Group  ·Warning·Banners·for·System·Accesses·  Group·contains·1·group·and·5·rules1819 Group  ·Warning·Banners·for·System·Accesses·  Group·contains·1·group·and·5·rules
1820 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Each·system·should·expose·as·little·information·about·itself·as·possible.1820 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Each·system·should·expose·as·little·information·about·itself·as·possible.
  
1821 System·banners,·which·are·typically·displayed·just·before·a·login·prompt,·give·out·information·about·the·service·or·the·host's·operating·system.·This·might·include·the·distribution·name·and·the·system·kernel·version,·and·the·particular·version·of·a·network·service.·This·information·can·assist·intruders·in·gaining·access·to·the·system·as·it·can·reveal·whether·the·system·is·running·vulnerable·software.·Most·network·services·can·be·configured·to·limit·what·information·is·displayed.1821 System·banners,·which·are·typically·displayed·just·before·a·login·prompt,·give·out·information·about·the·service·or·the·host's·operating·system.·This·might·include·the·distribution·name·and·the·system·kernel·version,·and·the·particular·version·of·a·network·service.·This·information·can·assist·intruders·in·gaining·access·to·the·system·as·it·can·reveal·whether·the·system·is·running·vulnerable·software.·Most·network·services·can·be·configured·to·limit·what·information·is·displayed.
  
Offset 9058, 52 lines modifiedOffset 9058, 38 lines modified
9058 ··-·PCI-DSSv4-1.2.19058 ··-·PCI-DSSv4-1.2.1
9059 ··-·enable_strategy9059 ··-·enable_strategy
9060 ··-·low_complexity9060 ··-·low_complexity
9061 ··-·low_disruption9061 ··-·low_disruption
9062 ··-·medium_severity9062 ··-·medium_severity
9063 ··-·no_reboot_needed9063 ··-·no_reboot_needed
9064 ··-·package_firewalld_installed9064 ··-·package_firewalld_installed
9065 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
9066 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
9067 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
9068 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
9069 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
9070 dnf·install·firewalld 
9071 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
9072 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
9073 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
9074 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
9075 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
9076 package·--add=firewalld 
9077 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x89065 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
9078 [[packages]]9066 [[packages]]
9079 name·=·"firewalld"9067 name·=·"firewalld"
9080 version·=·"*"9068 version·=·"*"
9081 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
9082 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
9083 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
9084 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
9085 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
9086 package·install·firewalld 
9087 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x89069 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
9088 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low9070 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
9089 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low9071 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
9090 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false9072 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
9091 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable9073 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
9092 include·install_firewalld9074 include·install_firewalld
  
9093 class·install_firewalld·{9075 class·install_firewalld·{
9094 ··package·{·'firewalld':9076 ··package·{·'firewalld':
9095 ····ensure·=>·'installed',9077 ····ensure·=>·'installed',
9096 ··}9078 ··}
Max diff block lines reached; 47419/52597 bytes (90.16%) of diff not shown.
113 KB
./usr/share/doc/ssg-nondebian/ssg-cs9-guide-ccn_basic.html
    
Offset 36613, 210 lines modifiedOffset 36613, 210 lines modified
0008f040:·743d·2223·6964·6d32·3530·3230·2220·7461··t="#idm25020"·ta0008f040:·743d·2223·6964·6d32·3530·3230·2220·7461··t="#idm25020"·ta
0008f050:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=0008f050:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
0008f060:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex0008f060:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
0008f070:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t0008f070:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
0008f080:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t0008f080:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
0008f090:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="0008f090:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
0008f0a0:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·0008f0a0:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
0008f0b0:·7363·7269·7074·20e2·87b2·3c2f·613e·3c62··script·...</a><b 
0008f0c0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa 
0008f0d0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col 
0008f0e0:·6c61·7073·6522·2069·643d·2269·646d·3235··lapse"·id="idm25 
0008f0f0:·3032·3022·3e3c·7461·626c·6520·636c·6173··020"><table·clas 
0008f100:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s 
0008f110:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor 
0008f120:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond 
0008f130:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C 
0008f140:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><0008f0b0:·4f53·4275·696c·6420·426c·7565·7072·696e··OSBuild·Blueprin
 0008f0c0:·7420·736e·6970·7065·7420·e287·b23c·2f61··t·snippet·...</a
 0008f0d0:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
 0008f0e0:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
 0008f0f0:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
 0008f100:·6d32·3530·3230·223e·3c70·7265·3e3c·636f··m25020"><pre><co
 0008f110:·6465·3e0a·5b5b·7061·636b·6167·6573·5d5d··de>.[[packages]]
 0008f120:·0a6e·616d·6520·3d20·2266·6972·6577·616c··.name·=·"firewal
 0008f130:·6c64·220a·7665·7273·696f·6e20·3d20·222a··ld".version·=·"*
 0008f140:·220a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··".</code></pre><
 0008f150:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b
 0008f160:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"·
 0008f170:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col
 0008f180:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ
 0008f190:·6574·3d22·2369·646d·3235·3032·3122·2074··et="#idm25021"·t
 0008f1a0:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
 0008f1b0:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
 0008f1c0:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
 0008f1d0:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
 0008f1e0:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
 0008f1f0:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
 0008f200:·2050·7570·7065·7420·736e·6970·7065·7420···Puppet·snippet·
 0008f210:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·
 0008f220:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col
 0008f230:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·
 0008f240:·6964·3d22·6964·6d32·3530·3231·223e·3c74··id="idm25021"><t
 0008f250:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl
 0008f260:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·
 0008f270:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t
 0008f280:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">
 0008f290:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi
 0008f2a0:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<
 0008f2b0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 0008f2c0:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th
 0008f2d0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
 0008f2e0:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot
 0008f2f0:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false<
 0008f300:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 0008f310:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><
 0008f320:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></
 0008f330:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>
 0008f340:·3c63·6f64·653e·696e·636c·7564·6520·696e··<code>include·in
 0008f350:·7374·616c·6c5f·6669·7265·7761·6c6c·640a··stall_firewalld.
 0008f360:·0a63·6c61·7373·2069·6e73·7461·6c6c·5f66··.class·install_f
 0008f370:·6972·6577·616c·6c64·207b·0a20·2070·6163··irewalld·{.··pac
 0008f380:·6b61·6765·207b·2027·6669·7265·7761·6c6c··kage·{·'firewall
 0008f390:·6427·3a0a·2020·2020·656e·7375·7265·203d··d':.····ensure·=
 0008f3a0:·2667·743b·2027·696e·7374·616c·6c65·6427··&gt;·'installed'
 0008f3b0:·2c0a·2020·7d0a·7d0a·3c2f·636f·6465·3e3c··,.··}.}.</code><
 0008f3c0:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl
 0008f3d0:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc
 0008f3e0:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl
 0008f3f0:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat
 0008f400:·612d·7461·7267·6574·3d22·2369·646d·3235··a-target="#idm25
 0008f410:·3032·3222·2074·6162·696e·6465·783d·2230··022"·tabindex="0
 0008f420:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
 0008f430:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
 0008f440:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
 0008f450:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
 0008f460:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
 0008f470:·6961·7469·6f6e·2073·6372·6970·7420·e287··iation·script·..
 0008f480:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl
 0008f490:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla
 0008f4a0:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id
 0008f4b0:·3d22·6964·6d32·3530·3232·223e·3c74·6162··="idm25022"><tab
 0008f4c0:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·
 0008f4d0:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta
 0008f4e0:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab
 0008f4f0:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t
 0008f500:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity
 0008f510:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
 0008f520:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D
 0008f530:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><
0008f150:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>0008f540:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
0008f160:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti 
0008f170:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<0008f550:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:<
 0008f560:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t
0008f180:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th0008f570:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S
0008f190:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td 
0008f1a0:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr> 
0008f1b0:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy 
0008f1c0:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable 
0008f1d0:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl 
0008f1e0:·653e·3c70·7265·3e3c·636f·6465·3e0a·646e··e><pre><code>.dn 
0008f1f0:·6620·696e·7374·616c·6c20·6669·7265·7761··f·install·firewa 
0008f200:·6c6c·640a·3c2f·636f·6465·3e3c·2f70·7265··lld.</code></pre 
0008f210:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class= 
0008f220:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success 
0008f230:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c 
0008f240:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta 
0008f250:·7267·6574·3d22·2369·646d·3235·3032·3122··rget="#idm25021" 
0008f260:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro 
0008f270:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria 
0008f280:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false 
0008f290:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat 
0008f2a0:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre 
0008f2b0:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati 
0008f2c0:·6f6e·2041·6e61·636f·6e64·6120·736e·6970··on·Anaconda·snip 
0008f2d0:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br>< 
0008f2e0:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel 
0008f2f0:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap 
0008f300:·7365·2220·6964·3d22·6964·6d32·3530·3231··se"·id="idm25021 
0008f310:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class=" 
0008f320:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri 
0008f330:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border 
0008f340:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens 
0008f350:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp0008f580:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td
 0008f590:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr
 0008f5a0:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c
 0008f5b0:·6f64·653e·0a70·6163·6b61·6765·2069·6e73··ode>.package·ins
 0008f5c0:·7461·6c6c·2066·6972·6577·616c·6c64·0a3c··tall·firewalld.<
Max diff block lines reached; 74630/102258 bytes (72.98%) of diff not shown.
13.1 KB
html2text {}
    
Offset 5317, 52 lines modifiedOffset 5317, 38 lines modified
5317 ··-·PCI-DSSv4-1.2.15317 ··-·PCI-DSSv4-1.2.1
5318 ··-·enable_strategy5318 ··-·enable_strategy
5319 ··-·low_complexity5319 ··-·low_complexity
5320 ··-·low_disruption5320 ··-·low_disruption
5321 ··-·medium_severity5321 ··-·medium_severity
5322 ··-·no_reboot_needed5322 ··-·no_reboot_needed
5323 ··-·package_firewalld_installed5323 ··-·package_firewalld_installed
5324 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
5325 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
5326 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
5327 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
5328 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
5329 dnf·install·firewalld 
5330 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
5331 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
5332 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
5333 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
5334 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
5335 package·--add=firewalld 
5336 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x85324 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
5337 [[packages]]5325 [[packages]]
5338 name·=·"firewalld"5326 name·=·"firewalld"
5339 version·=·"*"5327 version·=·"*"
5340 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
5341 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
5342 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
5343 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
5344 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
5345 package·install·firewalld 
5346 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x85328 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
5347 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low5329 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
5348 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low5330 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
5349 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false5331 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
5350 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable5332 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
5351 include·install_firewalld5333 include·install_firewalld
  
5352 class·install_firewalld·{5334 class·install_firewalld·{
5353 ··package·{·'firewalld':5335 ··package·{·'firewalld':
5354 ····ensure·=>·'installed',5336 ····ensure·=>·'installed',
5355 ··}5337 ··}
5356 }5338 }
 5339 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 5340 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 5341 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 5342 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 5343 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 5344 package·install·firewalld
5357 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x85345 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
5358 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low5346 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
5359 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low5347 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
5360 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false5348 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
5361 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable5349 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
5362 #·Remediation·is·applicable·only·in·certain·platforms5350 #·Remediation·is·applicable·only·in·certain·platforms
5363 if·rpm·--quiet·-q·kernel;·then5351 if·rpm·--quiet·-q·kernel;·then
Offset 5370, 14 lines modifiedOffset 5356, 28 lines modified
5370 if·!·rpm·-q·--quiet·"firewalld"·;·then5356 if·!·rpm·-q·--quiet·"firewalld"·;·then
5371 ····dnf·install·-y·"firewalld"5357 ····dnf·install·-y·"firewalld"
5372 fi5358 fi
  
5373 else5359 else
5374 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'5360 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
5375 fi5361 fi
 5362 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 5363 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 5364 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 5365 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 5366 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 5367 package·--add=firewalld
 5368 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 5369 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 5370 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 5371 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 5372 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 5373 dnf·install·firewalld
5376 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·f\x8fi\x8ir\x8re\x8ew\x8wa\x8al\x8ll\x8ld\x8d·E\x8En\x8na\x8ab\x8bl\x8le\x8ed\x8d·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*5374 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·f\x8fi\x8ir\x8re\x8ew\x8wa\x8al\x8ll\x8ld\x8d·E\x8En\x8na\x8ab\x8bl\x8le\x8ed\x8d·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
5377 The·firewalld·service·can·be·enabled·with·the·following·command:5375 The·firewalld·service·can·be·enabled·with·the·following·command:
5378 $·sudo·systemctl·enable·firewalld.service5376 $·sudo·systemctl·enable·firewalld.service
5379 Rationale:··Access·control·methods·provide·the·ability·to·enhance·system·security·posture·by·restricting·services·and·known·good·IP·addresses·and·address·ranges.·This·prevents·connections·from·unknown·hosts·and·protocols.5377 Rationale:··Access·control·methods·provide·the·ability·to·enhance·system·security·posture·by·restricting·services·and·known·good·IP·addresses·and·address·ranges.·This·prevents·connections·from·unknown·hosts·and·protocols.
5380 Severity: ··medium5378 Severity: ··medium
5381 Rule·ID:····xccdf_org.ssgproject.content_rule_service_firewalld_enabled5379 Rule·ID:····xccdf_org.ssgproject.content_rule_service_firewalld_enabled
5382 ············_\x8c_\x8i_\x8s_\x8-_\x8c_\x8s_\x8c········11,·3,·95380 ············_\x8c_\x8i_\x8s_\x8-_\x8c_\x8s_\x8c········11,·3,·9
Offset 5457, 34 lines modifiedOffset 5457, 34 lines modified
5457 ··-·medium_severity5457 ··-·medium_severity
5458 ··-·no_reboot_needed5458 ··-·no_reboot_needed
5459 ··-·service_firewalld_enabled5459 ··-·service_firewalld_enabled
5460 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x85460 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
5461 [customizations.services]5461 [customizations.services]
5462 enabled·=·["firewalld"]5462 enabled·=·["firewalld"]
5463 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
5464 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
5465 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
5466 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
5467 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable 
  
5468 service·enable·firewalld 
5469 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x85463 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
5470 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low5464 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
5471 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low5465 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
5472 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false5466 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
5473 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable5467 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
5474 include·enable_firewalld5468 include·enable_firewalld
  
5475 class·enable_firewalld·{5469 class·enable_firewalld·{
5476 ··service·{'firewalld':5470 ··service·{'firewalld':
5477 ····enable·=>·true,5471 ····enable·=>·true,
5478 ····ensure·=>·'running',5472 ····ensure·=>·'running',
5479 ··}5473 ··}
5480 }5474 }
 5475 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 5476 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 5477 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 5478 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 5479 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
  
 5480 service·enable·firewalld
5481 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x85481 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
5482 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low5482 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
5483 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low5483 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
5484 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false5484 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
Max diff block lines reached; 8694/13345 bytes (65.15%) of diff not shown.
404 KB
./usr/share/doc/ssg-nondebian/ssg-cs9-guide-ccn_intermediate.html
    
Offset 42506, 211 lines modifiedOffset 42506, 211 lines modified
000a6090:·7267·6574·3d22·2369·646d·3235·3032·3022··rget="#idm25020"000a6090:·7267·6574·3d22·2369·646d·3235·3032·3022··rget="#idm25020"
000a60a0:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro000a60a0:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro
000a60b0:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria000a60b0:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria
000a60c0:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false000a60c0:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false
000a60d0:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat000a60d0:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat
000a60e0:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre000a60e0:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre
000a60f0:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati000a60f0:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati
000a6100:·6f6e·2073·6372·6970·7420·e287·b23c·2f61··on·script·...</a 
000a6110:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class= 
000a6120:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·000a6100:·6f6e·204f·5342·7569·6c64·2042·6c75·6570··on·OSBuild·Bluep
 000a6110:·7269·6e74·2073·6e69·7070·6574·20e2·87b2··rint·snippet·...
 000a6120:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
 000a6130:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
 000a6140:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
 000a6150:·2269·646d·3235·3032·3022·3e3c·7072·653e··"idm25020"><pre>
 000a6160:·3c63·6f64·653e·0a5b·5b70·6163·6b61·6765··<code>.[[package
 000a6170:·735d·5d0a·6e61·6d65·203d·2022·6669·7265··s]].name·=·"fire
 000a6180:·7761·6c6c·6422·0a76·6572·7369·6f6e·203d··walld".version·=
 000a6190:·2022·2a22·0a3c·2f63·6f64·653e·3c2f·7072···"*".</code></pr
 000a61a0:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class
 000a61b0:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes
 000a61c0:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle="
000a6130:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id000a61d0:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t
000a6140:·6d32·3530·3230·223e·3c74·6162·6c65·2063··m25020"><table·c 
000a6150:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl 
000a6160:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table- 
000a6170:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c 
000a6180:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t 
000a6190:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t 
000a61a0:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></ 
000a61b0:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru000a61e0:·6172·6765·743d·2223·6964·6d32·3530·3231··arget="#idm25021
 000a61f0:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r
 000a6200:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari
 000a6210:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals
 000a6220:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa
 000a6230:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr
 000a6240:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat
 000a6250:·696f·6e20·5075·7070·6574·2073·6e69·7070··ion·Puppet·snipp
 000a6260:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d
 000a6270:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-
 000a6280:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps
 000a6290:·6522·2069·643d·2269·646d·3235·3032·3122··e"·id="idm25021"
 000a62a0:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t
 000a62b0:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip
 000a62c0:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere
 000a62d0:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense
 000a62e0:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl
000a61c0:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l000a62f0:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l
000a61d0:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>000a6300:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
000a61e0:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th> 
000a61f0:·3c74·643e·6661·6c73·653c·2f74·643e·3c2f··<td>false</td></000a6310:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:<
 000a6320:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
000a6200:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat000a6330:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb
000a6210:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena000a6340:·6f6f·743a·3c2f·7468·3e3c·7464·3e66·616c··oot:</th><td>fal
 000a6350:·7365·3c2f·7464·3e3c·2f74·723e·3c74·723e··se</td></tr><tr>
 000a6360:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t
 000a6370:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td
 000a6380:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p
 000a6390:·7265·3e3c·636f·6465·3e69·6e63·6c75·6465··re><code>include
 000a63a0:·2069·6e73·7461·6c6c·5f66·6972·6577·616c···install_firewal
 000a63b0:·6c64·0a0a·636c·6173·7320·696e·7374·616c··ld..class·instal
 000a63c0:·6c5f·6669·7265·7761·6c6c·6420·7b0a·2020··l_firewalld·{.··
 000a63d0:·7061·636b·6167·6520·7b20·2766·6972·6577··package·{·'firew
 000a63e0:·616c·6c64·273a·0a20·2020·2065·6e73·7572··alld':.····ensur
 000a63f0:·6520·3d26·6774·3b20·2769·6e73·7461·6c6c··e·=&gt;·'install
 000a6400:·6564·272c·0a20·207d·0a7d·0a3c·2f63·6f64··ed',.··}.}.</cod
 000a6410:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a
 000a6420:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn-
 000a6430:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to
 000a6440:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"·
 000a6450:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
 000a6460:·6d32·3530·3232·2220·7461·6269·6e64·6578··m25022"·tabindex
 000a6470:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto
 000a6480:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded
 000a6490:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="
 000a64a0:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve
 000a64b0:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re
 000a64c0:·6d65·6469·6174·696f·6e20·7363·7269·7074··mediation·script
 000a64d0:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
 000a64e0:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
 000a64f0:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
 000a6500:·2069·643d·2269·646d·3235·3032·3222·3e3c···id="idm25022"><
 000a6510:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab
 000a6520:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped
 000a6530:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·
 000a6540:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"
 000a6550:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex
 000a6560:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low
 000a6570:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
 000a6580:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t
 000a6590:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
 000a65a0:·7472·3e3c·7472·3e3c·7468·3e52·6562·6f6f··tr><tr><th>Reboo
 000a65b0:·743a·3c2f·7468·3e3c·7464·3e66·616c·7365··t:</th><td>false
 000a65c0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
 000a65d0:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th>
 000a65e0:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td><
 000a65f0:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre
 000a6600:·3e3c·636f·6465·3e0a·7061·636b·6167·6520··><code>.package·
 000a6610:·696e·7374·616c·6c20·6669·7265·7761·6c6c··install·firewall
 000a6620:·640a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··d.</code></pre><
 000a6630:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b
 000a6640:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"·
 000a6650:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col
 000a6660:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ
 000a6670:·6574·3d22·2369·646d·3235·3032·3322·2074··et="#idm25023"·t
 000a6680:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
 000a6690:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
 000a66a0:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
 000a66b0:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
 000a66c0:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
 000a66d0:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
 000a66e0:·2053·6865·6c6c·2073·6372·6970·7420·e287···Shell·script·..
 000a66f0:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl
 000a6700:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla
 000a6710:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id
 000a6720:·3d22·6964·6d32·3530·3233·223e·3c74·6162··="idm25023"><tab
 000a6730:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·
 000a6740:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta
 000a6750:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab
 000a6760:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t
 000a6770:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity
 000a6780:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
 000a6790:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D
 000a67a0:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><
 000a67b0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
 000a67c0:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:<
 000a67d0:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t
Max diff block lines reached; 336696/364462 bytes (92.38%) of diff not shown.
47.7 KB
html2text {}
    
Offset 6712, 52 lines modifiedOffset 6712, 38 lines modified
6712 ··-·PCI-DSSv4-1.2.16712 ··-·PCI-DSSv4-1.2.1
6713 ··-·enable_strategy6713 ··-·enable_strategy
6714 ··-·low_complexity6714 ··-·low_complexity
6715 ··-·low_disruption6715 ··-·low_disruption
6716 ··-·medium_severity6716 ··-·medium_severity
6717 ··-·no_reboot_needed6717 ··-·no_reboot_needed
6718 ··-·package_firewalld_installed6718 ··-·package_firewalld_installed
6719 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
6720 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
6721 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
6722 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
6723 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
6724 dnf·install·firewalld 
6725 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
6726 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
6727 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
6728 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
6729 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
6730 package·--add=firewalld 
6731 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x86719 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
6732 [[packages]]6720 [[packages]]
6733 name·=·"firewalld"6721 name·=·"firewalld"
6734 version·=·"*"6722 version·=·"*"
6735 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
6736 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
6737 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
6738 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
6739 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
6740 package·install·firewalld 
6741 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x86723 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
6742 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low6724 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
6743 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low6725 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
6744 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false6726 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
6745 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable6727 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
6746 include·install_firewalld6728 include·install_firewalld
  
6747 class·install_firewalld·{6729 class·install_firewalld·{
6748 ··package·{·'firewalld':6730 ··package·{·'firewalld':
6749 ····ensure·=>·'installed',6731 ····ensure·=>·'installed',
6750 ··}6732 ··}
6751 }6733 }
 6734 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 6735 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 6736 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 6737 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 6738 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 6739 package·install·firewalld
6752 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x86740 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
6753 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low6741 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
6754 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low6742 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
6755 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false6743 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
6756 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable6744 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
6757 #·Remediation·is·applicable·only·in·certain·platforms6745 #·Remediation·is·applicable·only·in·certain·platforms
6758 if·rpm·--quiet·-q·kernel;·then6746 if·rpm·--quiet·-q·kernel;·then
Offset 6765, 14 lines modifiedOffset 6751, 28 lines modified
6765 if·!·rpm·-q·--quiet·"firewalld"·;·then6751 if·!·rpm·-q·--quiet·"firewalld"·;·then
6766 ····dnf·install·-y·"firewalld"6752 ····dnf·install·-y·"firewalld"
6767 fi6753 fi
  
6768 else6754 else
6769 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'6755 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
6770 fi6756 fi
 6757 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 6758 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 6759 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 6760 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 6761 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 6762 package·--add=firewalld
 6763 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 6764 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 6765 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 6766 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 6767 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 6768 dnf·install·firewalld
6771 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·f\x8fi\x8ir\x8re\x8ew\x8wa\x8al\x8ll\x8ld\x8d·E\x8En\x8na\x8ab\x8bl\x8le\x8ed\x8d·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*6769 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·f\x8fi\x8ir\x8re\x8ew\x8wa\x8al\x8ll\x8ld\x8d·E\x8En\x8na\x8ab\x8bl\x8le\x8ed\x8d·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
6772 The·firewalld·service·can·be·enabled·with·the·following·command:6770 The·firewalld·service·can·be·enabled·with·the·following·command:
6773 $·sudo·systemctl·enable·firewalld.service6771 $·sudo·systemctl·enable·firewalld.service
6774 Rationale:··Access·control·methods·provide·the·ability·to·enhance·system·security·posture·by·restricting·services·and·known·good·IP·addresses·and·address·ranges.·This·prevents·connections·from·unknown·hosts·and·protocols.6772 Rationale:··Access·control·methods·provide·the·ability·to·enhance·system·security·posture·by·restricting·services·and·known·good·IP·addresses·and·address·ranges.·This·prevents·connections·from·unknown·hosts·and·protocols.
6775 Severity: ··medium6773 Severity: ··medium
6776 Rule·ID:····xccdf_org.ssgproject.content_rule_service_firewalld_enabled6774 Rule·ID:····xccdf_org.ssgproject.content_rule_service_firewalld_enabled
6777 ············_\x8c_\x8i_\x8s_\x8-_\x8c_\x8s_\x8c········11,·3,·96775 ············_\x8c_\x8i_\x8s_\x8-_\x8c_\x8s_\x8c········11,·3,·9
Offset 6852, 34 lines modifiedOffset 6852, 34 lines modified
6852 ··-·medium_severity6852 ··-·medium_severity
6853 ··-·no_reboot_needed6853 ··-·no_reboot_needed
6854 ··-·service_firewalld_enabled6854 ··-·service_firewalld_enabled
6855 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x86855 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
6856 [customizations.services]6856 [customizations.services]
6857 enabled·=·["firewalld"]6857 enabled·=·["firewalld"]
6858 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
6859 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
6860 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
6861 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
6862 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable 
  
6863 service·enable·firewalld 
6864 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x86858 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
6865 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low6859 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
6866 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low6860 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
6867 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false6861 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
6868 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable6862 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
6869 include·enable_firewalld6863 include·enable_firewalld
  
6870 class·enable_firewalld·{6864 class·enable_firewalld·{
6871 ··service·{'firewalld':6865 ··service·{'firewalld':
6872 ····enable·=>·true,6866 ····enable·=>·true,
6873 ····ensure·=>·'running',6867 ····ensure·=>·'running',
6874 ··}6868 ··}
6875 }6869 }
 6870 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 6871 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 6872 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 6873 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 6874 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
  
 6875 service·enable·firewalld
6876 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x86876 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
6877 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low6877 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
6878 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low6878 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
6879 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false6879 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
Max diff block lines reached; 44217/48868 bytes (90.48%) of diff not shown.
1.78 MB
./usr/share/doc/ssg-nondebian/ssg-cs9-guide-cis.html
    
Offset 15313, 208 lines modifiedOffset 15313, 208 lines modified
0003bd00:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe0003bd00:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
0003bd10:·743d·2223·6964·6d38·3438·3122·2074·6162··t="#idm8481"·tab0003bd10:·743d·2223·6964·6d38·3438·3122·2074·6162··t="#idm8481"·tab
0003bd20:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="0003bd20:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
0003bd30:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp0003bd30:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
0003bd40:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti0003bd40:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
0003bd50:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to0003bd50:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
0003bd60:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#0003bd60:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
0003bd70:·2122·3e52·656d·6564·6961·7469·6f6e·2073··!">Remediation·s0003bd70:·2122·3e52·656d·6564·6961·7469·6f6e·204f··!">Remediation·O
 0003bd80:·5342·7569·6c64·2042·6c75·6570·7269·6e74··SBuild·Blueprint
 0003bd90:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>
 0003bda0:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="
 0003bdb0:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c
 0003bdc0:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm
 0003bdd0:·3834·3831·223e·3c70·7265·3e3c·636f·6465··8481"><pre><code
 0003bde0:·3e0a·5b5b·7061·636b·6167·6573·5d5d·0a6e··>.[[packages]].n
 0003bdf0:·616d·6520·3d20·2261·6964·6522·0a76·6572··ame·=·"aide".ver
 0003be00:·7369·6f6e·203d·2022·2a22·0a3c·2f63·6f64··sion·=·"*".</cod
0003bd80:·6372·6970·7420·e287·b23c·2f61·3e3c·6272··cript·...</a><br 
0003bd90:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan 
0003bda0:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll 
0003bdb0:·6170·7365·2220·6964·3d22·6964·6d38·3438··apse"·id="idm848 
0003bdc0:·3122·3e3c·7461·626c·6520·636c·6173·733d··1"><table·class= 
0003bdd0:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str 
0003bde0:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde 
0003bdf0:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden 
0003be00:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com 
0003be10:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td 
0003be20:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t 
0003be30:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption 
0003be40:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t 
0003be50:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e52··d></tr><tr><th>R 
0003be60:·6562·6f6f·743a·3c2f·7468·3e3c·7464·3e66··eboot:</th><td>f 
0003be70:·616c·7365·3c2f·7464·3e3c·2f74·723e·3c74··alse</td></tr><t 
0003be80:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:< 
0003be90:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</ 
0003bea0:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table> 
0003beb0:·3c70·7265·3e3c·636f·6465·3e0a·646e·6620··<pre><code>.dnf· 
0003bec0:·696e·7374·616c·6c20·6169·6465·0a3c·2f63··install·aide.</c 
0003bed0:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div>0003be10:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a
0003bee0:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt0003be20:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn-
0003bef0:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data-0003be30:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to
0003bf00:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse0003be40:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"·
0003bf10:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#0003be50:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
0003bf20:·6964·6d38·3438·3222·2074·6162·696e·6465··idm8482"·tabinde0003be60:·6d38·3438·3222·2074·6162·696e·6465·783d··m8482"·tabindex=
0003bf30:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt0003be70:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button
0003bf40:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande0003be80:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=
0003bf50:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=0003be90:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A
0003bf60:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev0003bea0:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea
0003bf70:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R0003beb0:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem
0003bf80:·656d·6564·6961·7469·6f6e·2041·6e61·636f··emediation·Anaco0003bec0:·6564·6961·7469·6f6e·2050·7570·7065·7420··ediation·Puppet·
0003bf90:·6e64·6120·736e·6970·7065·7420·e287·b23c··nda·snippet·...<0003bed0:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><
0003bfa0:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas0003bee0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
0003bfb0:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps0003bef0:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
0003bfc0:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="0003bf00:·6c6c·6170·7365·2220·6964·3d22·6964·6d38··llapse"·id="idm8
0003bfd0:·6964·6d38·3438·3222·3e3c·7461·626c·6520··idm8482"><table·0003bf10:·3438·3222·3e3c·7461·626c·6520·636c·6173··482"><table·clas
0003bfe0:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab0003bf20:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s
0003bff0:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table0003bf30:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor
 0003bf40:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond
 0003bf50:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C
 0003bf60:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><
 0003bf70:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
 0003bf80:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti
 0003bf90:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<
 0003bfa0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 0003bfb0:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td
0003c000:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table- 
0003c010:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr>< 
0003c020:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</ 
0003c030:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td>< 
0003c040:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr 
0003c050:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td> 
0003c060:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr 
0003c070:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th 
0003c080:·3e3c·7464·3e66·616c·7365·3c2f·7464·3e3c··><td>false</td>< 
0003c090:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra 
0003c0a0:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en 
0003c0b0:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></0003bfc0:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr>
 0003bfd0:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy
 0003bfe0:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable
 0003bff0:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl
0003c0c0:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code0003c000:·653e·3c70·7265·3e3c·636f·6465·3e69·6e63··e><pre><code>inc
 0003c010:·6c75·6465·2069·6e73·7461·6c6c·5f61·6964··lude·install_aid
 0003c020:·650a·0a63·6c61·7373·2069·6e73·7461·6c6c··e..class·install
 0003c030:·5f61·6964·6520·7b0a·2020·7061·636b·6167··_aide·{.··packag
 0003c040:·6520·7b20·2761·6964·6527·3a0a·2020·2020··e·{·'aide':.····
 0003c050:·656e·7375·7265·203d·2667·743b·2027·696e··ensure·=&gt;·'in
 0003c060:·7374·616c·6c65·6427·2c0a·2020·7d0a·7d0a··stalled',.··}.}.
 0003c070:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d
0003c0d0:·3e0a·7061·636b·6167·6520·2d2d·6164·643d··>.package·--add= 
0003c0e0:·6169·6465·0a3c·2f63·6f64·653e·3c2f·7072··aide.</code></pr 
0003c0f0:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class 
0003c100:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes 
0003c110:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle=" 
0003c120:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t 
0003c130:·6172·6765·743d·2223·6964·6d38·3438·3322··arget="#idm8483" 
0003c140:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro 
0003c150:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria 
0003c160:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false 
0003c170:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat 
0003c180:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre 
0003c190:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati 
0003c1a0:·6f6e·204f·5342·7569·6c64·2042·6c75·6570··on·OSBuild·Bluep 
0003c1b0:·7269·6e74·2073·6e69·7070·6574·20e2·87b2··rint·snippet·... 
0003c1c0:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla 
0003c1d0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap 
0003c1e0:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id= 
0003c1f0:·2269·646d·3834·3833·223e·3c70·7265·3e3c··"idm8483"><pre>< 
0003c200:·636f·6465·3e0a·5b5b·7061·636b·6167·6573··code>.[[packages 
0003c210:·5d5d·0a6e·616d·6520·3d20·2261·6964·6522··]].name·=·"aide" 
0003c220:·0a76·6572·7369·6f6e·203d·2022·2a22·0a3c··.version·=·"*".< 
0003c230:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di 
0003c240:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn·0003c080:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn
0003c250:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat 
0003c260:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap 
0003c270:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target= 
0003c280:·2223·6964·6d38·3438·3422·2074·6162·696e··"#idm8484"·tabin 
0003c290:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu 
0003c2a0:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan 
0003c2b0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl 
0003c2c0:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r 
0003c2d0:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!" 
0003c2e0:·3e52·656d·6564·6961·7469·6f6e·2073·6372··>Remediation·scr 
0003c2f0:·6970·7420·e287·b23c·2f61·3e3c·6272·3e3c··ipt·...</a><br>< 
0003c300:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel 
0003c310:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap 
0003c320:·7365·2220·6964·3d22·6964·6d38·3438·3422··se"·id="idm8484" 
0003c330:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t 
Max diff block lines reached; 1642816/1670168 bytes (98.36%) of diff not shown.
192 KB
html2text {}
    
Offset 166, 52 lines modifiedOffset 166, 38 lines modified
166 ··-·PCI-DSSv4-11.5.2166 ··-·PCI-DSSv4-11.5.2
167 ··-·enable_strategy167 ··-·enable_strategy
168 ··-·low_complexity168 ··-·low_complexity
169 ··-·low_disruption169 ··-·low_disruption
170 ··-·medium_severity170 ··-·medium_severity
171 ··-·no_reboot_needed171 ··-·no_reboot_needed
172 ··-·package_aide_installed172 ··-·package_aide_installed
173 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
174 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
175 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
176 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
177 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
178 dnf·install·aide 
179 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
180 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
181 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
182 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
183 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
184 package·--add=aide 
185 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8173 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
186 [[packages]]174 [[packages]]
187 name·=·"aide"175 name·=·"aide"
188 version·=·"*"176 version·=·"*"
189 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
190 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
191 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
192 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
193 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
194 package·install·aide 
195 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8177 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
196 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low178 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
197 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low179 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
198 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false180 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
199 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable181 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
200 include·install_aide182 include·install_aide
  
201 class·install_aide·{183 class·install_aide·{
202 ··package·{·'aide':184 ··package·{·'aide':
203 ····ensure·=>·'installed',185 ····ensure·=>·'installed',
204 ··}186 ··}
205 }187 }
 188 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 189 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 190 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 191 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 192 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 193 package·install·aide
206 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8194 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
207 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low195 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
208 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low196 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
209 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false197 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
210 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable198 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
211 #·Remediation·is·applicable·only·in·certain·platforms199 #·Remediation·is·applicable·only·in·certain·platforms
212 if·rpm·--quiet·-q·kernel;·then200 if·rpm·--quiet·-q·kernel;·then
Offset 219, 14 lines modifiedOffset 205, 28 lines modified
219 if·!·rpm·-q·--quiet·"aide"·;·then205 if·!·rpm·-q·--quiet·"aide"·;·then
220 ····dnf·install·-y·"aide"206 ····dnf·install·-y·"aide"
221 fi207 fi
  
222 else208 else
223 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'209 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
224 fi210 fi
 211 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 212 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 213 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 214 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 215 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 216 package·--add=aide
 217 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 218 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 219 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 220 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 221 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 222 dnf·install·aide
225 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*223 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
226 Run·the·following·command·to·generate·a·new·database:224 Run·the·following·command·to·generate·a·new·database:
227 $·sudo·/usr/sbin/aide·--init225 $·sudo·/usr/sbin/aide·--init
228 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:226 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
229 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz227 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
230 To·initiate·a·manual·check,·run·the·following·command:228 To·initiate·a·manual·check,·run·the·following·command:
231 $·sudo·/usr/sbin/aide·--check229 $·sudo·/usr/sbin/aide·--check
Offset 922, 29 lines modifiedOffset 922, 29 lines modified
922 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.3922 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.3
923 References:·_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)923 References:·_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)
924 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4924 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4
925 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227925 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
926 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R28926 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R28
927 ············_\x8c_\x8i_\x8s············1.1.2.3.1927 ············_\x8c_\x8i_\x8s············1.1.2.3.1
928 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-257843r991589_rule928 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-257843r991589_rule
929 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
930 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
931 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high 
932 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
933 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
934 part·/home 
935 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8929 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
936 [[customizations.filesystem]]930 [[customizations.filesystem]]
937 mountpoint·=·"/home"931 mountpoint·=·"/home"
938 size·=·1073741824932 size·=·1073741824
939 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8933 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
940 logvol·/home·1024934 logvol·/home·1024
 935 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 936 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 937 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high
 938 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 939 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 940 part·/home
941 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/t\x8tm\x8mp\x8p·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*941 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/t\x8tm\x8mp\x8p·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
942 The·/tmp·directory·is·a·world-writable·directory·used·for·temporary·file·storage.·Ensure·it·has·its·own·partition·or·logical·volume·at·installation·time,·or·migrate·it·using·LVM.942 The·/tmp·directory·is·a·world-writable·directory·used·for·temporary·file·storage.·Ensure·it·has·its·own·partition·or·logical·volume·at·installation·time,·or·migrate·it·using·LVM.
943 Rationale:··The·/tmp·partition·is·used·as·temporary·storage·by·many·programs.·Placing·/tmp·in·its·own·partition·enables·the·setting·of·more·restrictive·mount·options,·which·can·help·protect·programs·which·use·it.943 Rationale:··The·/tmp·partition·is·used·as·temporary·storage·by·many·programs.·Placing·/tmp·in·its·own·partition·enables·the·setting·of·more·restrictive·mount·options,·which·can·help·protect·programs·which·use·it.
944 Severity: ··low944 Severity: ··low
945 Rule·ID:····xccdf_org.ssgproject.content_rule_partition_for_tmp945 Rule·ID:····xccdf_org.ssgproject.content_rule_partition_for_tmp
946 ············_\x8c_\x8i_\x8s_\x8-_\x8c_\x8s_\x8c········12,·15,·8946 ············_\x8c_\x8i_\x8s_\x8-_\x8c_\x8s_\x8c········12,·15,·8
947 ············_\x8c_\x8o_\x8b_\x8i_\x8t_\x85·········APO13.01,·DSS05.02947 ············_\x8c_\x8o_\x8b_\x8i_\x8t_\x85·········APO13.01,·DSS05.02
Offset 952, 29 lines modifiedOffset 952, 29 lines modified
952 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.5,·SR·3.8,·SR·4.1,·SR·4.3,·SR·5.1,·SR·5.2,·SR·5.3,·SR·7.1,·SR·7.6952 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.5,·SR·3.8,·SR·4.1,·SR·4.3,·SR·5.1,·SR·5.2,·SR·5.3,·SR·7.1,·SR·7.6
Max diff block lines reached; 190717/196310 bytes (97.15%) of diff not shown.
1.56 MB
./usr/share/doc/ssg-nondebian/ssg-cs9-guide-cis_server_l1.html
    
Offset 15275, 208 lines modifiedOffset 15275, 208 lines modified
0003baa0:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i0003baa0:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i
0003bab0:·646d·3834·3831·2220·7461·6269·6e64·6578··dm8481"·tabindex0003bab0:·646d·3834·3831·2220·7461·6269·6e64·6578··dm8481"·tabindex
0003bac0:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto0003bac0:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto
0003bad0:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded0003bad0:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded
0003bae0:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="0003bae0:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="
0003baf0:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve0003baf0:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve
0003bb00:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re0003bb00:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re
0003bb10:·6d65·6469·6174·696f·6e20·7363·7269·7074··mediation·script0003bb10:·6d65·6469·6174·696f·6e20·4f53·4275·696c··mediation·OSBuil
 0003bb20:·6420·426c·7565·7072·696e·7420·736e·6970··d·Blueprint·snip
 0003bb30:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br><
 0003bb40:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
 0003bb50:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap
 0003bb60:·7365·2220·6964·3d22·6964·6d38·3438·3122··se"·id="idm8481"
 0003bb70:·3e3c·7072·653e·3c63·6f64·653e·0a5b·5b70··><pre><code>.[[p
 0003bb80:·6163·6b61·6765·735d·5d0a·6e61·6d65·203d··ackages]].name·=
 0003bb90:·2022·6169·6465·220a·7665·7273·696f·6e20···"aide".version·
 0003bba0:·3d20·222a·220a·3c2f·636f·6465·3e3c·2f70··=·"*".</code></p
0003bb20:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div 
0003bb30:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co 
0003bb40:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse" 
0003bb50:·2069·643d·2269·646d·3834·3831·223e·3c74···id="idm8481"><t 
0003bb60:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl 
0003bb70:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped· 
0003bb80:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t 
0003bb90:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed"> 
0003bba0:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi 
0003bbb0:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low< 
0003bbc0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0003bbd0:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th 
0003bbe0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t 
0003bbf0:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot 
0003bc00:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false< 
0003bc10:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0003bc20:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th>< 
0003bc30:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></ 
0003bc40:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre> 
0003bc50:·3c63·6f64·653e·0a64·6e66·2069·6e73·7461··<code>.dnf·insta 
0003bc60:·6c6c·2061·6964·650a·3c2f·636f·6465·3e3c··ll·aide.</code>< 
0003bc70:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl0003bbb0:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas
0003bc80:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc0003bbc0:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe
0003bc90:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl0003bbd0:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle=
0003bca0:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat0003bbe0:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data-
0003bcb0:·612d·7461·7267·6574·3d22·2369·646d·3834··a-target="#idm840003bbf0:·7461·7267·6574·3d22·2369·646d·3834·3832··target="#idm8482
0003bcc0:·3832·2220·7461·6269·6e64·6578·3d22·3022··82"·tabindex="0"0003bc00:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r
0003bcd0:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a0003bc10:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari
0003bce0:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa0003bc20:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals
0003bcf0:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti0003bc30:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa
0003bd00:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·0003bc40:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr
0003bd10:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi0003bc50:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat
0003bd20:·6174·696f·6e20·416e·6163·6f6e·6461·2073··ation·Anaconda·s0003bc60:·696f·6e20·5075·7070·6574·2073·6e69·7070··ion·Puppet·snipp
0003bd30:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b0003bc70:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d
0003bd40:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa0003bc80:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-
0003bd50:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col0003bc90:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps
0003bd60:·6c61·7073·6522·2069·643d·2269·646d·3834··lapse"·id="idm840003bca0:·6522·2069·643d·2269·646d·3834·3832·223e··e"·id="idm8482">
0003bd70:·3832·223e·3c74·6162·6c65·2063·6c61·7373··82"><table·class0003bcb0:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta
0003bd80:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st0003bcc0:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe
0003bd90:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord0003bcd0:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered
0003bda0:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde0003bce0:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed
0003bdb0:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co0003bcf0:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple
0003bdc0:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t0003bd00:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo
0003bdd0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><0003bd10:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
0003bde0:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio0003bd20:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</
 0003bd30:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
 0003bd40:·2f74·723e·3c74·723e·3c74·683e·5265·626f··/tr><tr><th>Rebo
 0003bd50:·6f74·3a3c·2f74·683e·3c74·643e·6661·6c73··ot:</th><td>fals
 0003bd60:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr><
 0003bd70:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th
 0003bd80:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td>
 0003bd90:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr
 0003bda0:·653e·3c63·6f64·653e·696e·636c·7564·6520··e><code>include·
 0003bdb0:·696e·7374·616c·6c5f·6169·6465·0a0a·636c··install_aide..cl
 0003bdc0:·6173·7320·696e·7374·616c·6c5f·6169·6465··ass·install_aide
 0003bdd0:·207b·0a20·2070·6163·6b61·6765·207b·2027···{.··package·{·'
 0003bde0:·6169·6465·273a·0a20·2020·2065·6e73·7572··aide':.····ensur
 0003bdf0:·6520·3d26·6774·3b20·2769·6e73·7461·6c6c··e·=&gt;·'install
 0003be00:·6564·272c·0a20·207d·0a7d·0a3c·2f63·6f64··ed',.··}.}.</cod
 0003be10:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a
 0003be20:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn-
 0003be30:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to
 0003be40:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"·
 0003be50:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
 0003be60:·6d38·3438·3322·2074·6162·696e·6465·783d··m8483"·tabindex=
 0003be70:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button
 0003be80:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=
 0003be90:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A
 0003bea0:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea
 0003beb0:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem
 0003bec0:·6564·6961·7469·6f6e·2073·6372·6970·7420··ediation·script·
 0003bed0:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·
 0003bee0:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col
 0003bef0:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·
 0003bf00:·6964·3d22·6964·6d38·3438·3322·3e3c·7461··id="idm8483"><ta
 0003bf10:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table
 0003bf20:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t
 0003bf30:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta
 0003bf40:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><
 0003bf50:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit
0003bdf0:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</0003bf60:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</
0003be00:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>0003bf70:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
0003be10:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td> 
0003be20:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr>< 
0003be30:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:0003bf80:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th>
 0003bf90:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
 0003bfa0:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot:
0003be40:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<0003bfb0:·3c2f·7468·3e3c·7464·3e66·616c·7365·3c2f··</th><td>false</
0003be50:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table 
0003be60:·3e3c·7072·653e·3c63·6f64·653e·0a70·6163··><pre><code>.pac 
0003be70:·6b61·6765·202d·2d61·6464·3d61·6964·650a··kage·--add=aide. 
0003be80:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d 
0003be90:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn 
0003bea0:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da 
0003beb0:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla 
0003bec0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target 
0003bed0:·3d22·2369·646d·3834·3833·2220·7461·6269··="#idm8483"·tabi 
0003bee0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b 
0003bef0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa 
0003bf00:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit 
0003bf10:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to· 
0003bf20:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#! 
0003bf30:·223e·5265·6d65·6469·6174·696f·6e20·4f53··">Remediation·OS 
0003bf40:·4275·696c·6420·426c·7565·7072·696e·7420··Build·Blueprint·0003bfc0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 0003bfd0:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t
 0003bfe0:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t
 0003bff0:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><
 0003c000:·636f·6465·3e0a·7061·636b·6167·6520·696e··code>.package·in
 0003c010:·7374·616c·6c20·6169·6465·0a3c·2f63·6f64··stall·aide.</cod
 0003c020:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a
Max diff block lines reached; 1445300/1472652 bytes (98.14%) of diff not shown.
162 KB
html2text {}
    
Offset 160, 52 lines modifiedOffset 160, 38 lines modified
160 ··-·PCI-DSSv4-11.5.2160 ··-·PCI-DSSv4-11.5.2
161 ··-·enable_strategy161 ··-·enable_strategy
162 ··-·low_complexity162 ··-·low_complexity
163 ··-·low_disruption163 ··-·low_disruption
164 ··-·medium_severity164 ··-·medium_severity
165 ··-·no_reboot_needed165 ··-·no_reboot_needed
166 ··-·package_aide_installed166 ··-·package_aide_installed
167 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
168 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
169 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
170 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
171 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
172 dnf·install·aide 
173 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
174 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
175 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
176 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
177 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
178 package·--add=aide 
179 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8167 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
180 [[packages]]168 [[packages]]
181 name·=·"aide"169 name·=·"aide"
182 version·=·"*"170 version·=·"*"
183 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
184 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
185 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
186 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
187 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
188 package·install·aide 
189 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8171 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
190 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low172 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
191 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low173 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
192 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false174 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
193 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable175 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
194 include·install_aide176 include·install_aide
  
195 class·install_aide·{177 class·install_aide·{
196 ··package·{·'aide':178 ··package·{·'aide':
197 ····ensure·=>·'installed',179 ····ensure·=>·'installed',
198 ··}180 ··}
199 }181 }
 182 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 183 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 184 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 185 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 186 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 187 package·install·aide
200 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8188 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
201 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low189 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
202 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low190 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
203 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false191 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
204 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable192 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
205 #·Remediation·is·applicable·only·in·certain·platforms193 #·Remediation·is·applicable·only·in·certain·platforms
206 if·rpm·--quiet·-q·kernel;·then194 if·rpm·--quiet·-q·kernel;·then
Offset 213, 14 lines modifiedOffset 199, 28 lines modified
213 if·!·rpm·-q·--quiet·"aide"·;·then199 if·!·rpm·-q·--quiet·"aide"·;·then
214 ····dnf·install·-y·"aide"200 ····dnf·install·-y·"aide"
215 fi201 fi
  
216 else202 else
217 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'203 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
218 fi204 fi
 205 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 206 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 207 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 208 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 209 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 210 package·--add=aide
 211 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 212 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 213 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 214 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 215 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 216 dnf·install·aide
219 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*217 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
220 Run·the·following·command·to·generate·a·new·database:218 Run·the·following·command·to·generate·a·new·database:
221 $·sudo·/usr/sbin/aide·--init219 $·sudo·/usr/sbin/aide·--init
222 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:220 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
223 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz221 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
224 To·initiate·a·manual·check,·run·the·following·command:222 To·initiate·a·manual·check,·run·the·following·command:
225 $·sudo·/usr/sbin/aide·--check223 $·sudo·/usr/sbin/aide·--check
Offset 915, 29 lines modifiedOffset 915, 29 lines modified
915 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.5,·SR·3.8,·SR·4.1,·SR·4.3,·SR·5.1,·SR·5.2,·SR·5.3,·SR·7.1,·SR·7.6915 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.5,·SR·3.8,·SR·4.1,·SR·4.3,·SR·5.1,·SR·5.2,·SR·5.3,·SR·7.1,·SR·7.6
916 References:·_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.3916 References:·_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.3
917 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)917 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)
918 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4918 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4
919 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227919 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
920 ············_\x8c_\x8i_\x8s············1.1.2.1.1920 ············_\x8c_\x8i_\x8s············1.1.2.1.1
921 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-257844r1044918_rule921 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-257844r1044918_rule
922 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
923 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
924 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high 
925 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
926 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
927 part·/tmp 
928 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8922 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
929 [[customizations.filesystem]]923 [[customizations.filesystem]]
930 mountpoint·=·"/tmp"924 mountpoint·=·"/tmp"
931 size·=·1073741824925 size·=·1073741824
932 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8926 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
933 logvol·/tmp·1024927 logvol·/tmp·1024
 928 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 929 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 930 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high
 931 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 932 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 933 part·/tmp
934 Group  ·GNOME·Desktop·Environment·  Group·contains·3·groups·and·10·rules934 Group  ·GNOME·Desktop·Environment·  Group·contains·3·groups·and·10·rules
935 _\x8[_\x8r_\x8e_\x8f_\x8]  ·GNOME·is·a·graphical·desktop·environment·bundled·with·many·Linux·distributions·that·allow·users·to·easily·interact·with·the·operating·system·graphically·rather·than·textually.·The·GNOME·Graphical·Display·Manager·(GDM)·provides·login,·logout,·and·user·switching·contexts·as·well·as·display·server·management.935 _\x8[_\x8r_\x8e_\x8f_\x8]  ·GNOME·is·a·graphical·desktop·environment·bundled·with·many·Linux·distributions·that·allow·users·to·easily·interact·with·the·operating·system·graphically·rather·than·textually.·The·GNOME·Graphical·Display·Manager·(GDM)·provides·login,·logout,·and·user·switching·contexts·as·well·as·display·server·management.
  
936 GNOME·is·developed·by·the·GNOME·Project·and·is·considered·the·default·Red·Hat·Graphical·environment.936 GNOME·is·developed·by·the·GNOME·Project·and·is·considered·the·default·Red·Hat·Graphical·environment.
  
937 For·more·information·on·GNOME·and·the·GNOME·Project,·see·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8w\x8w_\x8w\x8w_\x8w\x8w_\x8.\x8._\x8g\x8g_\x8n\x8n_\x8o\x8o_\x8m\x8m_\x8e\x8e_\x8.\x8._\x8o\x8o_\x8r\x8r_\x8g\x8g.937 For·more·information·on·GNOME·and·the·GNOME·Project,·see·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8w\x8w_\x8w\x8w_\x8w\x8w_\x8.\x8._\x8g\x8g_\x8n\x8n_\x8o\x8o_\x8m\x8m_\x8e\x8e_\x8.\x8._\x8o\x8o_\x8r\x8r_\x8g\x8g.
938 Group  ·Configure·GNOME·Login·Screen·  Group·contains·2·rules938 Group  ·Configure·GNOME·Login·Screen·  Group·contains·2·rules
Offset 2298, 52 lines modifiedOffset 2298, 38 lines modified
2298 ··-·PCI-DSSv4-2.2.62298 ··-·PCI-DSSv4-2.2.6
Max diff block lines reached; 160239/165710 bytes (96.70%) of diff not shown.
1.46 MB
./usr/share/doc/ssg-nondebian/ssg-cs9-guide-cis_workstation_l1.html
    
Offset 15267, 207 lines modifiedOffset 15267, 207 lines modified
0003ba20:·6574·3d22·2369·646d·3834·3831·2220·7461··et="#idm8481"·ta0003ba20:·6574·3d22·2369·646d·3834·3831·2220·7461··et="#idm8481"·ta
0003ba30:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=0003ba30:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
0003ba40:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex0003ba40:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
0003ba50:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t0003ba50:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
0003ba60:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t0003ba60:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
0003ba70:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="0003ba70:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
0003ba80:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·0003ba80:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
 0003ba90:·4f53·4275·696c·6420·426c·7565·7072·696e··OSBuild·Blueprin
 0003baa0:·7420·736e·6970·7065·7420·e287·b23c·2f61··t·snippet·...</a
 0003bab0:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
 0003bac0:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
 0003bad0:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
 0003bae0:·6d38·3438·3122·3e3c·7072·653e·3c63·6f64··m8481"><pre><cod
 0003baf0:·653e·0a5b·5b70·6163·6b61·6765·735d·5d0a··e>.[[packages]].
 0003bb00:·6e61·6d65·203d·2022·6169·6465·220a·7665··name·=·"aide".ve
 0003bb10:·7273·696f·6e20·3d20·222a·220a·3c2f·636f··rsion·=·"*".</co
0003ba90:·7363·7269·7074·20e2·87b2·3c2f·613e·3c62··script·...</a><b 
0003baa0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa 
0003bab0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col 
0003bac0:·6c61·7073·6522·2069·643d·2269·646d·3834··lapse"·id="idm84 
0003bad0:·3831·223e·3c74·6162·6c65·2063·6c61·7373··81"><table·class 
0003bae0:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st 
0003baf0:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord 
0003bb00:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde 
0003bb10:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co 
0003bb20:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t 
0003bb30:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr>< 
0003bb40:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio 
0003bb50:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</ 
0003bb60:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
0003bb70:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td> 
0003bb80:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr>< 
0003bb90:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy: 
0003bba0:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable< 
0003bbb0:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table 
0003bbc0:·3e3c·7072·653e·3c63·6f64·653e·0a64·6e66··><pre><code>.dnf 
0003bbd0:·2069·6e73·7461·6c6c·2061·6964·650a·3c2f···install·aide.</ 
0003bbe0:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div0003bb20:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div><
0003bbf0:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b0003bb30:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn
0003bc00:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data0003bb40:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t
0003bc10:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps0003bb50:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse"
0003bc20:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="0003bb60:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i
0003bc30:·2369·646d·3834·3832·2220·7461·6269·6e64··#idm8482"·tabind0003bb70:·646d·3834·3832·2220·7461·6269·6e64·6578··dm8482"·tabindex
0003bc40:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but0003bb80:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto
0003bc50:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand0003bb90:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded
0003bc60:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title0003bba0:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="
0003bc70:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re0003bbb0:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve
0003bc80:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">0003bbc0:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re
0003bc90:·5265·6d65·6469·6174·696f·6e20·416e·6163··Remediation·Anac0003bbd0:·6d65·6469·6174·696f·6e20·5075·7070·6574··mediation·Puppet
0003bca0:·6f6e·6461·2073·6e69·7070·6574·20e2·87b2··onda·snippet·...0003bbe0:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>
0003bcb0:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla0003bbf0:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="
0003bcc0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap0003bc00:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c
0003bcd0:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=0003bc10:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm
0003bce0:·2269·646d·3834·3832·223e·3c74·6162·6c65··"idm8482"><table0003bc20:·3834·3832·223e·3c74·6162·6c65·2063·6c61··8482"><table·cla
0003bcf0:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta0003bc30:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-
0003bd00:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl0003bc40:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo
0003bd10:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table0003bc50:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con
0003bd20:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>0003bc60:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>
0003bd30:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<0003bc70:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>
0003bd40:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>0003bc80:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
0003bd50:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis0003bc90:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt
0003bd60:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td0003bca0:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low
 0003bcb0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
 0003bcc0:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t
 0003bcd0:·643e·6661·6c73·653c·2f74·643e·3c2f·7472··d>false</td></tr
 0003bce0:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg
 0003bcf0:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl
 0003bd00:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab
 0003bd10:·6c65·3e3c·7072·653e·3c63·6f64·653e·696e··le><pre><code>in
 0003bd20:·636c·7564·6520·696e·7374·616c·6c5f·6169··clude·install_ai
 0003bd30:·6465·0a0a·636c·6173·7320·696e·7374·616c··de..class·instal
 0003bd40:·6c5f·6169·6465·207b·0a20·2070·6163·6b61··l_aide·{.··packa
 0003bd50:·6765·207b·2027·6169·6465·273a·0a20·2020··ge·{·'aide':.···
 0003bd60:·2065·6e73·7572·6520·3d26·6774·3b20·2769···ensure·=&gt;·'i
 0003bd70:·6e73·7461·6c6c·6564·272c·0a20·207d·0a7d··nstalled',.··}.}
 0003bd80:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></
 0003bd90:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt
 0003bda0:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d
 0003bdb0:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll
 0003bdc0:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
 0003bdd0:·743d·2223·6964·6d38·3438·3322·2074·6162··t="#idm8483"·tab
 0003bde0:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
 0003bdf0:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
 0003be00:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
 0003be10:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
 0003be20:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
 0003be30:·2122·3e52·656d·6564·6961·7469·6f6e·2073··!">Remediation·s
 0003be40:·6372·6970·7420·e287·b23c·2f61·3e3c·6272··cript·...</a><br
 0003be50:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
 0003be60:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
 0003be70:·6170·7365·2220·6964·3d22·6964·6d38·3438··apse"·id="idm848
 0003be80:·3322·3e3c·7461·626c·6520·636c·6173·733d··3"><table·class=
 0003be90:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str
 0003bea0:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde
 0003beb0:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden
 0003bec0:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com
 0003bed0:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td
0003bd70:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t0003bee0:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
0003bd80:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t 
0003bd90:·683e·3c74·643e·6661·6c73·653c·2f74·643e··h><td>false</td>0003bef0:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption
 0003bf00:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
0003bda0:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str0003bf10:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e52··d></tr><tr><th>R
0003bdb0:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e 
0003bdc0:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr>< 
0003bdd0:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod 
0003bde0:·653e·0a70·6163·6b61·6765·202d·2d61·6464··e>.package·--add 
0003bdf0:·3d61·6964·650a·3c2f·636f·6465·3e3c·2f70··=aide.</code></p 
0003be00:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas 
0003be10:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe0003bf20:·6562·6f6f·743a·3c2f·7468·3e3c·7464·3e66··eboot:</th><td>f
 0003bf30:·616c·7365·3c2f·7464·3e3c·2f74·723e·3c74··alse</td></tr><t
 0003bf40:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<
 0003bf50:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</
 0003bf60:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table>
 0003bf70:·3c70·7265·3e3c·636f·6465·3e0a·7061·636b··<pre><code>.pack
 0003bf80:·6167·6520·696e·7374·616c·6c20·6169·6465··age·install·aide
 0003bf90:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></
 0003bfa0:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt
 0003bfb0:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d
 0003bfc0:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll
0003be20:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle=0003bfd0:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
 0003bfe0:·743d·2223·6964·6d38·3438·3422·2074·6162··t="#idm8484"·tab
 0003bff0:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
 0003c000:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
 0003c010:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
 0003c020:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
 0003c030:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
 0003c040:·2122·3e52·656d·6564·6961·7469·6f6e·2053··!">Remediation·S
Max diff block lines reached; 1350760/1377974 bytes (98.03%) of diff not shown.
150 KB
html2text {}
    
Offset 159, 52 lines modifiedOffset 159, 38 lines modified
159 ··-·PCI-DSSv4-11.5.2159 ··-·PCI-DSSv4-11.5.2
160 ··-·enable_strategy160 ··-·enable_strategy
161 ··-·low_complexity161 ··-·low_complexity
162 ··-·low_disruption162 ··-·low_disruption
163 ··-·medium_severity163 ··-·medium_severity
164 ··-·no_reboot_needed164 ··-·no_reboot_needed
165 ··-·package_aide_installed165 ··-·package_aide_installed
166 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
167 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
168 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
169 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
170 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
171 dnf·install·aide 
172 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
173 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
174 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
175 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
176 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
177 package·--add=aide 
178 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8166 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
179 [[packages]]167 [[packages]]
180 name·=·"aide"168 name·=·"aide"
181 version·=·"*"169 version·=·"*"
182 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
183 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
184 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
185 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
186 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
187 package·install·aide 
188 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8170 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
189 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low171 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
190 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low172 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
191 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false173 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
192 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable174 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
193 include·install_aide175 include·install_aide
  
194 class·install_aide·{176 class·install_aide·{
195 ··package·{·'aide':177 ··package·{·'aide':
196 ····ensure·=>·'installed',178 ····ensure·=>·'installed',
197 ··}179 ··}
198 }180 }
 181 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 182 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 183 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 184 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 185 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 186 package·install·aide
199 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8187 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
200 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low188 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
201 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low189 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
202 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false190 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
203 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable191 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
204 #·Remediation·is·applicable·only·in·certain·platforms192 #·Remediation·is·applicable·only·in·certain·platforms
205 if·rpm·--quiet·-q·kernel;·then193 if·rpm·--quiet·-q·kernel;·then
Offset 212, 14 lines modifiedOffset 198, 28 lines modified
212 if·!·rpm·-q·--quiet·"aide"·;·then198 if·!·rpm·-q·--quiet·"aide"·;·then
213 ····dnf·install·-y·"aide"199 ····dnf·install·-y·"aide"
214 fi200 fi
  
215 else201 else
216 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'202 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
217 fi203 fi
 204 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 205 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 206 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 207 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 208 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 209 package·--add=aide
 210 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 211 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 212 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 213 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 214 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 215 dnf·install·aide
218 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*216 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
219 Run·the·following·command·to·generate·a·new·database:217 Run·the·following·command·to·generate·a·new·database:
220 $·sudo·/usr/sbin/aide·--init218 $·sudo·/usr/sbin/aide·--init
221 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:219 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
222 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz220 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
223 To·initiate·a·manual·check,·run·the·following·command:221 To·initiate·a·manual·check,·run·the·following·command:
224 $·sudo·/usr/sbin/aide·--check222 $·sudo·/usr/sbin/aide·--check
Offset 914, 29 lines modifiedOffset 914, 29 lines modified
914 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.5,·SR·3.8,·SR·4.1,·SR·4.3,·SR·5.1,·SR·5.2,·SR·5.3,·SR·7.1,·SR·7.6914 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.5,·SR·3.8,·SR·4.1,·SR·4.3,·SR·5.1,·SR·5.2,·SR·5.3,·SR·7.1,·SR·7.6
915 References:·_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.3915 References:·_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.3
916 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)916 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)
917 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4917 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4
918 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227918 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
919 ············_\x8c_\x8i_\x8s············1.1.2.1.1919 ············_\x8c_\x8i_\x8s············1.1.2.1.1
920 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-257844r1044918_rule920 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-257844r1044918_rule
921 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
922 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
923 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high 
924 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
925 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
926 part·/tmp 
927 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8921 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
928 [[customizations.filesystem]]922 [[customizations.filesystem]]
929 mountpoint·=·"/tmp"923 mountpoint·=·"/tmp"
930 size·=·1073741824924 size·=·1073741824
931 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8925 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
932 logvol·/tmp·1024926 logvol·/tmp·1024
 927 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 928 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 929 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high
 930 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 931 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 932 part·/tmp
933 Group  ·GNOME·Desktop·Environment·  Group·contains·3·groups·and·8·rules933 Group  ·GNOME·Desktop·Environment·  Group·contains·3·groups·and·8·rules
934 _\x8[_\x8r_\x8e_\x8f_\x8]  ·GNOME·is·a·graphical·desktop·environment·bundled·with·many·Linux·distributions·that·allow·users·to·easily·interact·with·the·operating·system·graphically·rather·than·textually.·The·GNOME·Graphical·Display·Manager·(GDM)·provides·login,·logout,·and·user·switching·contexts·as·well·as·display·server·management.934 _\x8[_\x8r_\x8e_\x8f_\x8]  ·GNOME·is·a·graphical·desktop·environment·bundled·with·many·Linux·distributions·that·allow·users·to·easily·interact·with·the·operating·system·graphically·rather·than·textually.·The·GNOME·Graphical·Display·Manager·(GDM)·provides·login,·logout,·and·user·switching·contexts·as·well·as·display·server·management.
  
935 GNOME·is·developed·by·the·GNOME·Project·and·is·considered·the·default·Red·Hat·Graphical·environment.935 GNOME·is·developed·by·the·GNOME·Project·and·is·considered·the·default·Red·Hat·Graphical·environment.
  
936 For·more·information·on·GNOME·and·the·GNOME·Project,·see·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8w\x8w_\x8w\x8w_\x8w\x8w_\x8.\x8._\x8g\x8g_\x8n\x8n_\x8o\x8o_\x8m\x8m_\x8e\x8e_\x8.\x8._\x8o\x8o_\x8r\x8r_\x8g\x8g.936 For·more·information·on·GNOME·and·the·GNOME·Project,·see·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8w\x8w_\x8w\x8w_\x8w\x8w_\x8.\x8._\x8g\x8g_\x8n\x8n_\x8o\x8o_\x8m\x8m_\x8e\x8e_\x8.\x8._\x8o\x8o_\x8r\x8r_\x8g\x8g.
937 Group  ·Configure·GNOME·Login·Screen·  Group·contains·2·rules937 Group  ·Configure·GNOME·Login·Screen·  Group·contains·2·rules
Offset 1948, 52 lines modifiedOffset 1948, 38 lines modified
1948 ··-·PCI-DSSv4-2.2.61948 ··-·PCI-DSSv4-2.2.6
Max diff block lines reached; 147675/153145 bytes (96.43%) of diff not shown.
1.68 MB
./usr/share/doc/ssg-nondebian/ssg-cs9-guide-cis_workstation_l2.html
    
Offset 15305, 208 lines modifiedOffset 15305, 208 lines modified
0003bc80:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id0003bc80:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
0003bc90:·6d38·3438·3122·2074·6162·696e·6465·783d··m8481"·tabindex=0003bc90:·6d38·3438·3122·2074·6162·696e·6465·783d··m8481"·tabindex=
0003bca0:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button0003bca0:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button
0003bcb0:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=0003bcb0:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=
0003bcc0:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A0003bcc0:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A
0003bcd0:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea0003bcd0:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea
0003bce0:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem0003bce0:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem
 0003bcf0:·6564·6961·7469·6f6e·204f·5342·7569·6c64··ediation·OSBuild
 0003bd00:·2042·6c75·6570·7269·6e74·2073·6e69·7070···Blueprint·snipp
 0003bd10:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d
 0003bd20:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-
 0003bd30:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps
 0003bd40:·6522·2069·643d·2269·646d·3834·3831·223e··e"·id="idm8481">
 0003bd50:·3c70·7265·3e3c·636f·6465·3e0a·5b5b·7061··<pre><code>.[[pa
 0003bd60:·636b·6167·6573·5d5d·0a6e·616d·6520·3d20··ckages]].name·=·
 0003bd70:·2261·6964·6522·0a76·6572·7369·6f6e·203d··"aide".version·=
 0003bd80:·2022·2a22·0a3c·2f63·6f64·653e·3c2f·7072···"*".</code></pr
0003bcf0:·6564·6961·7469·6f6e·2073·6372·6970·7420··ediation·script· 
0003bd00:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div· 
0003bd10:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col 
0003bd20:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"· 
0003bd30:·6964·3d22·6964·6d38·3438·3122·3e3c·7461··id="idm8481"><ta 
0003bd40:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table 
0003bd50:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t 
0003bd60:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta 
0003bd70:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed">< 
0003bd80:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit 
0003bd90:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</ 
0003bda0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
0003bdb0:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th> 
0003bdc0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
0003bdd0:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot: 
0003bde0:·3c2f·7468·3e3c·7464·3e66·616c·7365·3c2f··</th><td>false</ 
0003bdf0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
0003be00:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t 
0003be10:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t 
0003be20:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre>< 
0003be30:·636f·6465·3e0a·646e·6620·696e·7374·616c··code>.dnf·instal 
0003be40:·6c20·6169·6465·0a3c·2f63·6f64·653e·3c2f··l·aide.</code></ 
0003be50:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla0003bd90:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class
0003be60:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ0003bda0:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes
0003be70:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle0003bdb0:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle="
0003be80:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data0003bdc0:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t
0003be90:·2d74·6172·6765·743d·2223·6964·6d38·3438··-target="#idm8480003bdd0:·6172·6765·743d·2223·6964·6d38·3438·3222··arget="#idm8482"
0003bea0:·3222·2074·6162·696e·6465·783d·2230·2220··2"·tabindex="0"·0003bde0:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro
0003beb0:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar0003bdf0:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria
0003bec0:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal0003be00:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false
0003bed0:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ0003be10:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat
0003bee0:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h0003be20:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre
0003bef0:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia0003be30:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati
0003bf00:·7469·6f6e·2041·6e61·636f·6e64·6120·736e··tion·Anaconda·sn0003be40:·6f6e·2050·7570·7065·7420·736e·6970·7065··on·Puppet·snippe
0003bf10:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br0003be50:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di
0003bf20:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan0003be60:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c
0003bf30:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll0003be70:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse
0003bf40:·6170·7365·2220·6964·3d22·6964·6d38·3438··apse"·id="idm8480003be80:·2220·6964·3d22·6964·6d38·3438·3222·3e3c··"·id="idm8482"><
0003bf50:·3222·3e3c·7461·626c·6520·636c·6173·733d··2"><table·class=0003be90:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab
0003bf60:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str0003bea0:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped
0003bf70:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde0003beb0:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·
0003bf80:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden0003bec0:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"
0003bf90:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com0003bed0:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex
0003bfa0:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td0003bee0:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low
0003bfb0:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t0003bef0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
0003bfc0:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption0003bf00:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t
0003bfd0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t0003bf10:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
0003bfe0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e52··d></tr><tr><th>R0003bf20:·7472·3e3c·7472·3e3c·7468·3e52·6562·6f6f··tr><tr><th>Reboo
0003bff0:·6562·6f6f·743a·3c2f·7468·3e3c·7464·3e66··eboot:</th><td>f0003bf30:·743a·3c2f·7468·3e3c·7464·3e66·616c·7365··t:</th><td>false
0003c000:·616c·7365·3c2f·7464·3e3c·2f74·723e·3c74··alse</td></tr><t 
0003c010:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:< 
0003c020:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</ 
0003c030:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table> 
0003c040:·3c70·7265·3e3c·636f·6465·3e0a·7061·636b··<pre><code>.pack 
0003c050:·6167·6520·2d2d·6164·643d·6169·6465·0a3c··age·--add=aide.< 
0003c060:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di0003bf40:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
 0003bf50:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th>
 0003bf60:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td><
 0003bf70:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre
 0003bf80:·3e3c·636f·6465·3e69·6e63·6c75·6465·2069··><code>include·i
 0003bf90:·6e73·7461·6c6c·5f61·6964·650a·0a63·6c61··nstall_aide..cla
 0003bfa0:·7373·2069·6e73·7461·6c6c·5f61·6964·6520··ss·install_aide·
 0003bfb0:·7b0a·2020·7061·636b·6167·6520·7b20·2761··{.··package·{·'a
 0003bfc0:·6964·6527·3a0a·2020·2020·656e·7375·7265··ide':.····ensure
 0003bfd0:·203d·2667·743b·2027·696e·7374·616c·6c65···=&gt;·'installe
 0003bfe0:·6427·2c0a·2020·7d0a·7d0a·3c2f·636f·6465··d',.··}.}.</code
 0003bff0:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a·
 0003c000:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s
 0003c010:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog
 0003c020:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d
 0003c030:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
 0003c040:·3834·3833·2220·7461·6269·6e64·6578·3d22··8483"·tabindex="
 0003c050:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
 0003c060:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
 0003c070:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
 0003c080:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
 0003c090:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
 0003c0a0:·6469·6174·696f·6e20·7363·7269·7074·20e2··diation·script·.
 0003c0b0:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c
 0003c0c0:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
 0003c0d0:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
 0003c0e0:·643d·2269·646d·3834·3833·223e·3c74·6162··d="idm8483"><tab
0003c070:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn·0003c0f0:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·
 0003c100:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta
 0003c110:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab
 0003c120:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t
 0003c130:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity
0003c080:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat 
0003c090:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap 
0003c0a0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target= 
0003c0b0:·2223·6964·6d38·3438·3322·2074·6162·696e··"#idm8483"·tabin 
0003c0c0:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu 
0003c0d0:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan 
0003c0e0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl 
0003c0f0:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r 
0003c100:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!" 
0003c110:·3e52·656d·6564·6961·7469·6f6e·204f·5342··>Remediation·OSB 
0003c120:·7569·6c64·2042·6c75·6570·7269·6e74·2073··uild·Blueprint·s 
0003c130:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b 
0003c140:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa 
0003c150:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col 
0003c160:·6c61·7073·6522·2069·643d·2269·646d·3834··lapse"·id="idm84 
0003c170:·3833·223e·3c70·7265·3e3c·636f·6465·3e0a··83"><pre><code>. 
0003c180:·5b5b·7061·636b·6167·6573·5d5d·0a6e·616d··[[packages]].nam 
0003c190:·6520·3d20·2261·6964·6522·0a76·6572·7369··e·=·"aide".versi 
0003c1a0:·6f6e·203d·2022·2a22·0a3c·2f63·6f64·653e··on·=·"*".</code> 
0003c1b0:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c 
0003c1c0:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su 
0003c1d0:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg 
0003c1e0:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da 
Max diff block lines reached; 1545891/1573243 bytes (98.26%) of diff not shown.
179 KB
html2text {}
    
Offset 165, 52 lines modifiedOffset 165, 38 lines modified
165 ··-·PCI-DSSv4-11.5.2165 ··-·PCI-DSSv4-11.5.2
166 ··-·enable_strategy166 ··-·enable_strategy
167 ··-·low_complexity167 ··-·low_complexity
168 ··-·low_disruption168 ··-·low_disruption
169 ··-·medium_severity169 ··-·medium_severity
170 ··-·no_reboot_needed170 ··-·no_reboot_needed
171 ··-·package_aide_installed171 ··-·package_aide_installed
172 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
173 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
174 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
175 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
176 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
177 dnf·install·aide 
178 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
179 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
180 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
181 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
182 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
183 package·--add=aide 
184 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8172 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
185 [[packages]]173 [[packages]]
186 name·=·"aide"174 name·=·"aide"
187 version·=·"*"175 version·=·"*"
188 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
189 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
190 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
191 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
192 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
193 package·install·aide 
194 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8176 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
195 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low177 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
196 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low178 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
197 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false179 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
198 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable180 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
199 include·install_aide181 include·install_aide
  
200 class·install_aide·{182 class·install_aide·{
201 ··package·{·'aide':183 ··package·{·'aide':
202 ····ensure·=>·'installed',184 ····ensure·=>·'installed',
203 ··}185 ··}
204 }186 }
 187 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 188 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 189 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 190 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 191 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 192 package·install·aide
205 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8193 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
206 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low194 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
207 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low195 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
208 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false196 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
209 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable197 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
210 #·Remediation·is·applicable·only·in·certain·platforms198 #·Remediation·is·applicable·only·in·certain·platforms
211 if·rpm·--quiet·-q·kernel;·then199 if·rpm·--quiet·-q·kernel;·then
Offset 218, 14 lines modifiedOffset 204, 28 lines modified
218 if·!·rpm·-q·--quiet·"aide"·;·then204 if·!·rpm·-q·--quiet·"aide"·;·then
219 ····dnf·install·-y·"aide"205 ····dnf·install·-y·"aide"
220 fi206 fi
  
221 else207 else
222 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'208 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
223 fi209 fi
 210 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 211 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 212 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 213 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 214 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 215 package·--add=aide
 216 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 217 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 218 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 219 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 220 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 221 dnf·install·aide
224 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*222 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
225 Run·the·following·command·to·generate·a·new·database:223 Run·the·following·command·to·generate·a·new·database:
226 $·sudo·/usr/sbin/aide·--init224 $·sudo·/usr/sbin/aide·--init
227 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:225 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
228 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz226 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
229 To·initiate·a·manual·check,·run·the·following·command:227 To·initiate·a·manual·check,·run·the·following·command:
230 $·sudo·/usr/sbin/aide·--check228 $·sudo·/usr/sbin/aide·--check
Offset 921, 29 lines modifiedOffset 921, 29 lines modified
921 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.3921 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.3
922 References:·_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)922 References:·_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)
923 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4923 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4
924 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227924 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
925 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R28925 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R28
926 ············_\x8c_\x8i_\x8s············1.1.2.3.1926 ············_\x8c_\x8i_\x8s············1.1.2.3.1
927 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-257843r991589_rule927 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-257843r991589_rule
928 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
929 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
930 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high 
931 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
932 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
933 part·/home 
934 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8928 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
935 [[customizations.filesystem]]929 [[customizations.filesystem]]
936 mountpoint·=·"/home"930 mountpoint·=·"/home"
937 size·=·1073741824931 size·=·1073741824
938 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8932 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
939 logvol·/home·1024933 logvol·/home·1024
 934 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 935 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 936 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high
 937 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 938 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 939 part·/home
940 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/t\x8tm\x8mp\x8p·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*940 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/t\x8tm\x8mp\x8p·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
941 The·/tmp·directory·is·a·world-writable·directory·used·for·temporary·file·storage.·Ensure·it·has·its·own·partition·or·logical·volume·at·installation·time,·or·migrate·it·using·LVM.941 The·/tmp·directory·is·a·world-writable·directory·used·for·temporary·file·storage.·Ensure·it·has·its·own·partition·or·logical·volume·at·installation·time,·or·migrate·it·using·LVM.
942 Rationale:··The·/tmp·partition·is·used·as·temporary·storage·by·many·programs.·Placing·/tmp·in·its·own·partition·enables·the·setting·of·more·restrictive·mount·options,·which·can·help·protect·programs·which·use·it.942 Rationale:··The·/tmp·partition·is·used·as·temporary·storage·by·many·programs.·Placing·/tmp·in·its·own·partition·enables·the·setting·of·more·restrictive·mount·options,·which·can·help·protect·programs·which·use·it.
943 Severity: ··low943 Severity: ··low
944 Rule·ID:····xccdf_org.ssgproject.content_rule_partition_for_tmp944 Rule·ID:····xccdf_org.ssgproject.content_rule_partition_for_tmp
945 ············_\x8c_\x8i_\x8s_\x8-_\x8c_\x8s_\x8c········12,·15,·8945 ············_\x8c_\x8i_\x8s_\x8-_\x8c_\x8s_\x8c········12,·15,·8
946 ············_\x8c_\x8o_\x8b_\x8i_\x8t_\x85·········APO13.01,·DSS05.02946 ············_\x8c_\x8o_\x8b_\x8i_\x8t_\x85·········APO13.01,·DSS05.02
Offset 951, 29 lines modifiedOffset 951, 29 lines modified
951 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.5,·SR·3.8,·SR·4.1,·SR·4.3,·SR·5.1,·SR·5.2,·SR·5.3,·SR·7.1,·SR·7.6951 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.5,·SR·3.8,·SR·4.1,·SR·4.3,·SR·5.1,·SR·5.2,·SR·5.3,·SR·7.1,·SR·7.6
Max diff block lines reached; 178135/183728 bytes (96.96%) of diff not shown.
654 KB
./usr/share/doc/ssg-nondebian/ssg-cs9-guide-cui.html
    
Offset 15885, 203 lines modifiedOffset 15885, 203 lines modified
0003e0c0:·7461·2d74·6172·6765·743d·2223·6964·6d39··ta-target="#idm90003e0c0:·7461·2d74·6172·6765·743d·2223·6964·6d39··ta-target="#idm9
0003e0d0:·3136·3422·2074·6162·696e·6465·783d·2230··164"·tabindex="00003e0d0:·3136·3422·2074·6162·696e·6465·783d·2230··164"·tabindex="0
0003e0e0:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·0003e0e0:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
0003e0f0:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f0003e0f0:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
0003e100:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act0003e100:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
0003e110:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"0003e110:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
0003e120:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed0003e120:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
 0003e130:·6961·7469·6f6e·204f·5342·7569·6c64·2042··iation·OSBuild·B
 0003e140:·6c75·6570·7269·6e74·2073·6e69·7070·6574··lueprint·snippet
0003e130:·6961·7469·6f6e·2073·6372·6970·7420·e287··iation·script·.. 
0003e140:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl 
0003e150:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla 
0003e160:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id 
0003e170:·3d22·6964·6d39·3136·3422·3e3c·7461·626c··="idm9164"><tabl 
0003e180:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t 
0003e190:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab 
0003e1a0:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl 
0003e1b0:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr 
0003e1c0:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity: 
0003e1d0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td 
0003e1e0:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di 
0003e1f0:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t 
0003e200:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr>< 
0003e210:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</ 
0003e220:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td 
0003e230:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St 
0003e240:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td> 
0003e250:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr> 
0003e260:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co 
0003e270:·6465·3e0a·646e·6620·696e·7374·616c·6c20··de>.dnf·install· 
0003e280:·6372·7970·746f·2d70·6f6c·6963·6965·730a··crypto-policies. 
0003e290:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d 
0003e2a0:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn 
0003e2b0:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da 
0003e2c0:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla 
0003e2d0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target 
0003e2e0:·3d22·2369·646d·3931·3635·2220·7461·6269··="#idm9165"·tabi 
0003e2f0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b 
0003e300:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa 
0003e310:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit 
0003e320:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to· 
0003e330:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#! 
0003e340:·223e·5265·6d65·6469·6174·696f·6e20·416e··">Remediation·An 
0003e350:·6163·6f6e·6461·2073·6e69·7070·6574·20e2··aconda·snippet·. 
0003e360:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c0003e150:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
0003e370:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll0003e160:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
0003e380:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i0003e170:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
0003e390:·643d·2269·646d·3931·3635·223e·3c74·6162··d="idm9165"><tab0003e180:·2069·643d·2269·646d·3931·3634·223e·3c70···id="idm9164"><p
 0003e190:·7265·3e3c·636f·6465·3e0a·5b5b·7061·636b··re><code>.[[pack
 0003e1a0:·6167·6573·5d5d·0a6e·616d·6520·3d20·2263··ages]].name·=·"c
0003e3a0:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table· 
0003e3b0:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta 
0003e3c0:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab 
0003e3d0:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t 
0003e3e0:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity 
0003e3f0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t 
0003e400:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D 
0003e410:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th>< 
0003e420:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
0003e430:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:< 
0003e440:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t 
0003e450:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S 
0003e460:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td 
0003e470:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr 
0003e480:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c 
0003e490:·6f64·653e·0a70·6163·6b61·6765·202d·2d61··ode>.package·--a 
0003e4a0:·6464·3d63·7279·7074·6f2d·706f·6c69·6369··dd=crypto-polici0003e1b0:·7279·7074·6f2d·706f·6c69·6369·6573·220a··rypto-policies".
0003e4b0:·6573·0a3c·2f63·6f64·653e·3c2f·7072·653e··es.</code></pre> 
0003e4c0:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class=" 
0003e4d0:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success"0003e1c0:·7665·7273·696f·6e20·3d20·222a·220a·3c2f··version·=·"*".</
 0003e1d0:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div
 0003e1e0:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b
 0003e1f0:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data
 0003e200:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps
0003e4e0:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co0003e210:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
 0003e220:·2369·646d·3931·3635·2220·7461·6269·6e64··#idm9165"·tabind
 0003e230:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
 0003e240:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
 0003e250:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
 0003e260:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
 0003e270:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
 0003e280:·5265·6d65·6469·6174·696f·6e20·5075·7070··Remediation·Pupp
0003e4f0:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar 
0003e500:·6765·743d·2223·6964·6d39·3136·3622·2074··get="#idm9166"·t 
0003e510:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role 
0003e520:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e 
0003e530:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"· 
0003e540:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate· 
0003e550:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href= 
0003e560:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation 
0003e570:·204f·5342·7569·6c64·2042·6c75·6570·7269···OSBuild·Bluepri 
0003e580:·6e74·2073·6e69·7070·6574·20e2·87b2·3c2f··nt·snippet·...</0003e290:·6574·2073·6e69·7070·6574·20e2·87b2·3c2f··et·snippet·...</
0003e590:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class0003e2a0:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
0003e5a0:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse0003e2b0:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
0003e5b0:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i0003e2c0:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
0003e5c0:·646d·3931·3636·223e·3c70·7265·3e3c·636f··dm9166"><pre><co 
0003e5d0:·6465·3e0a·5b5b·7061·636b·6167·6573·5d5d··de>.[[packages]] 
0003e5e0:·0a6e·616d·6520·3d20·2263·7279·7074·6f2d··.name·=·"crypto- 
0003e5f0:·706f·6c69·6369·6573·220a·7665·7273·696f··policies".versio 
0003e600:·6e20·3d20·222a·220a·3c2f·636f·6465·3e3c··n·=·"*".</code>< 
0003e610:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl 
0003e620:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc 
0003e630:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl 
0003e640:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat 
0003e650:·612d·7461·7267·6574·3d22·2369·646d·3931··a-target="#idm91 
0003e660:·3637·2220·7461·6269·6e64·6578·3d22·3022··67"·tabindex="0" 
0003e670:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a 
0003e680:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa 
0003e690:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti 
0003e6a0:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"· 
0003e6b0:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi 
0003e6c0:·6174·696f·6e20·7363·7269·7074·20e2·87b2··ation·script·... 
0003e6d0:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla 
0003e6e0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap 
0003e6f0:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id= 
0003e700:·2269·646d·3931·3637·223e·3c74·6162·6c65··"idm9167"><table0003e2d0:·646d·3931·3635·223e·3c74·6162·6c65·2063··dm9165"><table·c
0003e710:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta0003e2e0:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl
0003e720:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl0003e2f0:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-
0003e730:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table0003e300:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c
0003e740:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>0003e310:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t
0003e750:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<0003e320:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t
0003e760:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>0003e330:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
0003e770:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis0003e340:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru
0003e780:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td0003e350:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l
0003e790:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t0003e360:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
0003e7a0:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t0003e370:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th>
0003e7b0:·683e·3c74·643e·6661·6c73·653c·2f74·643e··h><td>false</td>0003e380:·3c74·643e·6661·6c73·653c·2f74·643e·3c2f··<td>false</td></
Max diff block lines reached; 568788/595450 bytes (95.52%) of diff not shown.
72.0 KB
html2text {}
    
Offset 187, 61 lines modifiedOffset 187, 61 lines modified
187 ··-·DISA-STIG-RHEL-09-215100187 ··-·DISA-STIG-RHEL-09-215100
188 ··-·enable_strategy188 ··-·enable_strategy
189 ··-·low_complexity189 ··-·low_complexity
190 ··-·low_disruption190 ··-·low_disruption
191 ··-·medium_severity191 ··-·medium_severity
192 ··-·no_reboot_needed192 ··-·no_reboot_needed
193 ··-·package_crypto-policies_installed193 ··-·package_crypto-policies_installed
194 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
195 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
196 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
197 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
198 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
199 dnf·install·crypto-policies 
200 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
201 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
202 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
203 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
204 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
205 package·--add=crypto-policies 
206 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8194 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
207 [[packages]]195 [[packages]]
208 name·=·"crypto-policies"196 name·=·"crypto-policies"
209 version·=·"*"197 version·=·"*"
210 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
211 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
212 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
213 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
214 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
215 package·install·crypto-policies 
216 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8198 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
217 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low199 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
218 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low200 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
219 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false201 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
220 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable202 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
221 include·install_crypto-policies203 include·install_crypto-policies
  
222 class·install_crypto-policies·{204 class·install_crypto-policies·{
223 ··package·{·'crypto-policies':205 ··package·{·'crypto-policies':
224 ····ensure·=>·'installed',206 ····ensure·=>·'installed',
225 ··}207 ··}
226 }208 }
 209 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 210 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 211 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 212 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 213 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 214 package·install·crypto-policies
227 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8215 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
228 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low216 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
229 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low217 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
230 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false218 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
231 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable219 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
232 if·!·rpm·-q·--quiet·"crypto-policies"·;·then220 if·!·rpm·-q·--quiet·"crypto-policies"·;·then
233 ····dnf·install·-y·"crypto-policies"221 ····dnf·install·-y·"crypto-policies"
234 fi222 fi
 223 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 224 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 225 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 226 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 227 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 228 package·--add=crypto-policies
 229 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 230 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 231 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 232 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 233 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 234 dnf·install·crypto-policies
235 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8og\x8gr\x8ra\x8ap\x8ph\x8hy\x8y·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*235 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8og\x8gr\x8ra\x8ap\x8ph\x8hy\x8y·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
236 To·configure·the·system·cryptography·policy·to·use·ciphers·only·from·the·FIPS·policy,·run·the·following·command:236 To·configure·the·system·cryptography·policy·to·use·ciphers·only·from·the·FIPS·policy,·run·the·following·command:
237 $·sudo·update-crypto-policies·--set·FIPS237 $·sudo·update-crypto-policies·--set·FIPS
238 The·rule·checks·if·settings·for·selected·crypto·policy·are·configured·as·expected.·Configuration·files·in·the·/etc/crypto-policies/back-ends·are·either·symlinks·to·correct·files·provided·by·Crypto-policies·package·or·they·are·regular·files·in·case·crypto·policy·customizations·are·applied.·Crypto·policies·may·be·customized·by·crypto·policy·modules,·in·which·case·it·is·delimited·from·the·base·policy·using·a·colon.238 The·rule·checks·if·settings·for·selected·crypto·policy·are·configured·as·expected.·Configuration·files·in·the·/etc/crypto-policies/back-ends·are·either·symlinks·to·correct·files·provided·by·Crypto-policies·package·or·they·are·regular·files·in·case·crypto·policy·customizations·are·applied.·Crypto·policies·may·be·customized·by·crypto·policy·modules,·in·which·case·it·is·delimited·from·the·base·policy·using·a·colon.
239 Warning: ·The·system·needs·to·be·rebooted·for·these·changes·to·take·effect.239 Warning: ·The·system·needs·to·be·rebooted·for·these·changes·to·take·effect.
240 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8n\x8n_\x8v\x8v_\x8l\x8l_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8/\x8/_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8/\x8/_\x8N\x8N_\x8I\x8I_\x8S\x8S_\x8T\x8T_\x8.\x8._\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x81\x81_\x84\x84_\x80\x80_\x8-\x8-_\x82\x82_\x8.\x8._\x8p\x8p_\x8d\x8d_\x8f\x8f·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.240 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8n\x8n_\x8v\x8v_\x8l\x8l_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8/\x8/_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8/\x8/_\x8N\x8N_\x8I\x8I_\x8S\x8S_\x8T\x8T_\x8.\x8._\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x81\x81_\x84\x84_\x80\x80_\x8-\x8-_\x82\x82_\x8.\x8._\x8p\x8p_\x8d\x8d_\x8f\x8f·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.
241 Rationale:··Centralized·cryptographic·policies·simplify·applying·secure·ciphers·across·an·operating·system·and·the·applications·that·run·on·that·operating·system.·Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.241 Rationale:··Centralized·cryptographic·policies·simplify·applying·secure·ciphers·across·an·operating·system·and·the·applications·that·run·on·that·operating·system.·Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.
Offset 574, 29 lines modifiedOffset 574, 29 lines modified
574 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-4,·PR.PT-1,·PR.PT-4574 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-4,·PR.PT-1,·PR.PT-4
575 ············_\x8o_\x8s_\x8p_\x8p···········FMT_SMF_EXT.1575 ············_\x8o_\x8s_\x8p_\x8p···········FMT_SMF_EXT.1
576 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000341-GPOS-00132,·SRG-OS-000480-GPOS-00227576 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000341-GPOS-00132,·SRG-OS-000480-GPOS-00227
577 ············_\x8a_\x8p_\x8p_\x8-_\x8s_\x8r_\x8g_\x8-_\x8c_\x8t_\x8r····SRG-APP-000357-CTR-000800577 ············_\x8a_\x8p_\x8p_\x8-_\x8s_\x8r_\x8g_\x8-_\x8c_\x8t_\x8r····SRG-APP-000357-CTR-000800
578 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R71578 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R71
579 ············_\x8c_\x8i_\x8s············1.1.2.7.1579 ············_\x8c_\x8i_\x8s············1.1.2.7.1
580 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-257847r1044924_rule580 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-257847r1044924_rule
581 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
582 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
583 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high 
584 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
585 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
586 part·/var/log/audit 
587 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8581 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
588 [[customizations.filesystem]]582 [[customizations.filesystem]]
589 mountpoint·=·"/var/log/audit"583 mountpoint·=·"/var/log/audit"
590 size·=·10737418240584 size·=·10737418240
591 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8585 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
592 logvol·/var/log/audit·10240586 logvol·/var/log/audit·10240
 587 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 588 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 589 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high
 590 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 591 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 592 part·/var/log/audit
593 Group  ·Sudo·  Group·contains·1·rule593 Group  ·Sudo·  Group·contains·1·rule
594 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Sudo,·which·stands·for·"su·'do'",·provides·the·ability·to·delegate·authority·to·certain·users,·groups·of·users,·or·system·administrators.·When·configured·for·system·users·and/or·groups,·Sudo·can·allow·a·user·or·group·to·execute·privileged·commands·that·normally·only·root·is·allowed·to·execute.594 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Sudo,·which·stands·for·"su·'do'",·provides·the·ability·to·delegate·authority·to·certain·users,·groups·of·users,·or·system·administrators.·When·configured·for·system·users·and/or·groups,·Sudo·can·allow·a·user·or·group·to·execute·privileged·commands·that·normally·only·root·is·allowed·to·execute.
  
595 For·more·information·on·Sudo·and·addition·Sudo·configuration·options,·see·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8w\x8w_\x8w\x8w_\x8w\x8w_\x8.\x8._\x8s\x8s_\x8u\x8u_\x8d\x8d_\x8o\x8o_\x8.\x8._\x8w\x8w_\x8s\x8s.595 For·more·information·on·Sudo·and·addition·Sudo·configuration·options,·see·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8w\x8w_\x8w\x8w_\x8w\x8w_\x8.\x8._\x8s\x8s_\x8u\x8u_\x8d\x8d_\x8o\x8o_\x8.\x8._\x8w\x8w_\x8s\x8s.
596 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·s\x8su\x8ud\x8do\x8o·P\x8Pa\x8ac\x8ck\x8ka\x8ag\x8ge\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*596 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·s\x8su\x8ud\x8do\x8o·P\x8Pa\x8ac\x8ck\x8ka\x8ag\x8ge\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
597 The·sudo·package·can·be·installed·with·the·following·command:597 The·sudo·package·can·be·installed·with·the·following·command:
598 $·sudo·dnf·install·sudo598 $·sudo·dnf·install·sudo
Offset 644, 52 lines modifiedOffset 644, 38 lines modified
644 ··-·PCI-DSSv4-2.2.6644 ··-·PCI-DSSv4-2.2.6
645 ··-·enable_strategy645 ··-·enable_strategy
646 ··-·low_complexity646 ··-·low_complexity
647 ··-·low_disruption647 ··-·low_disruption
648 ··-·medium_severity648 ··-·medium_severity
649 ··-·no_reboot_needed649 ··-·no_reboot_needed
650 ··-·package_sudo_installed650 ··-·package_sudo_installed
Max diff block lines reached; 66002/73741 bytes (89.51%) of diff not shown.
523 KB
./usr/share/doc/ssg-nondebian/ssg-cs9-guide-e8.html
    
Offset 19649, 278 lines modifiedOffset 19649, 278 lines modified
0004cc00:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i0004cc00:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i
0004cc10:·646d·3132·3433·3622·2074·6162·696e·6465··dm12436"·tabinde0004cc10:·646d·3132·3433·3622·2074·6162·696e·6465··dm12436"·tabinde
0004cc20:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt0004cc20:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt
0004cc30:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande0004cc30:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande
0004cc40:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=0004cc40:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=
0004cc50:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev0004cc50:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev
0004cc60:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R0004cc60:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R
0004cc70:·656d·6564·6961·7469·6f6e·2073·6372·6970··emediation·scrip0004cc70:·656d·6564·6961·7469·6f6e·204f·5342·7569··emediation·OSBui
 0004cc80:·6c64·2042·6c75·6570·7269·6e74·2073·6e69··ld·Blueprint·sni
 0004cc90:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>
0004cc80:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di 
0004cc90:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c 
0004cca0:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse 
0004ccb0:·2220·6964·3d22·6964·6d31·3234·3336·223e··"·id="idm12436"> 
0004ccc0:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta0004cca0:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
 0004ccb0:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
 0004ccc0:·7073·6522·2069·643d·2269·646d·3132·3433··pse"·id="idm1243
 0004ccd0:·3622·3e3c·7072·653e·3c63·6f64·653e·0a5b··6"><pre><code>.[
 0004cce0:·5b70·6163·6b61·6765·735d·5d0a·6e61·6d65··[packages]].name
 0004ccf0:·203d·2022·7265·6172·220a·7665·7273·696f···=·"rear".versio
 0004cd00:·6e20·3d20·222a·220a·3c2f·636f·6465·3e3c··n·=·"*".</code><
0004ccd0:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe 
0004cce0:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered 
0004ccf0:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed 
0004cd00:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple 
0004cd10:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo 
0004cd20:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr>< 
0004cd30:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</ 
0004cd40:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td>< 
0004cd50:·2f74·723e·3c74·723e·3c74·683e·5265·626f··/tr><tr><th>Rebo 
0004cd60:·6f74·3a3c·2f74·683e·3c74·643e·6661·6c73··ot:</th><td>fals 
0004cd70:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr>< 
0004cd80:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th 
0004cd90:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td> 
0004cda0:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr 
0004cdb0:·653e·3c63·6f64·653e·0a64·6e66·2069·6e73··e><code>.dnf·ins 
0004cdc0:·7461·6c6c·2072·6561·720a·3c2f·636f·6465··tall·rear.</code 
0004cdd0:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a·0004cd10:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl
0004cde0:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s0004cd20:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc
0004cdf0:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog0004cd30:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl
0004ce00:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d0004cd40:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat
0004ce10:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm0004cd50:·612d·7461·7267·6574·3d22·2369·646d·3132··a-target="#idm12
0004ce20:·3132·3433·3722·2074·6162·696e·6465·783d··12437"·tabindex=0004cd60:·3433·3722·2074·6162·696e·6465·783d·2230··437"·tabindex="0
0004ce30:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button0004cd70:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
0004ce40:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=0004cd80:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
0004ce50:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A0004cd90:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
0004ce60:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea0004cda0:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
0004ce70:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem0004cdb0:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
 0004cdc0:·6961·7469·6f6e·2050·7570·7065·7420·736e··iation·Puppet·sn
0004ce80:·6564·6961·7469·6f6e·2041·6e61·636f·6e64··ediation·Anacond 
0004ce90:·6120·736e·6970·7065·7420·e287·b23c·2f61··a·snippet·...</a 
0004cea0:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class= 
0004ceb0:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse· 
0004cec0:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id 
0004ced0:·6d31·3234·3337·223e·3c74·6162·6c65·2063··m12437"><table·c 
0004cee0:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl 
0004cef0:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table- 
0004cf00:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c 
0004cf10:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t 
0004cf20:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t 
0004cf30:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></ 
0004cf40:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru 
0004cf50:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l 
0004cf60:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr> 
0004cf70:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th> 
0004cf80:·3c74·643e·6661·6c73·653c·2f74·643e·3c2f··<td>false</td></ 
0004cf90:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat 
0004cfa0:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena 
0004cfb0:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t 
0004cfc0:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code> 
0004cfd0:·0a70·6163·6b61·6765·202d·2d61·6464·3d72··.package·--add=r 
0004cfe0:·6561·720a·3c2f·636f·6465·3e3c·2f70·7265··ear.</code></pre 
0004cff0:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class= 
0004d000:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success 
0004d010:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c 
0004d020:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta 
0004d030:·7267·6574·3d22·2369·646d·3132·3433·3822··rget="#idm12438" 
0004d040:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro 
0004d050:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria 
0004d060:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false 
0004d070:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat 
0004d080:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre 
0004d090:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati 
0004d0a0:·6f6e·204f·5342·7569·6c64·2042·6c75·6570··on·OSBuild·Bluep 
0004d0b0:·7269·6e74·2073·6e69·7070·6574·20e2·87b2··rint·snippet·... 
0004d0c0:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla 
0004d0d0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap 
0004d0e0:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id= 
0004d0f0:·2269·646d·3132·3433·3822·3e3c·7072·653e··"idm12438"><pre> 
0004d100:·3c63·6f64·653e·0a5b·5b70·6163·6b61·6765··<code>.[[package 
0004d110:·735d·5d0a·6e61·6d65·203d·2022·7265·6172··s]].name·=·"rear 
0004d120:·220a·7665·7273·696f·6e20·3d20·222a·220a··".version·=·"*". 
0004d130:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d 
0004d140:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn 
0004d150:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da 
0004d160:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla 
0004d170:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target 
0004d180:·3d22·2369·646d·3132·3433·3922·2074·6162··="#idm12439"·tab 
0004d190:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role=" 
0004d1a0:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp 
0004d1b0:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti 
0004d1c0:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to 
0004d1d0:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="# 
0004d1e0:·2122·3e52·656d·6564·6961·7469·6f6e·2073··!">Remediation·s 
0004d1f0:·6372·6970·7420·e287·b23c·2f61·3e3c·6272··cript·...</a><br0004cdd0:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br
0004d200:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan0004cde0:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
0004d210:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll0004cdf0:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
0004d220:·6170·7365·2220·6964·3d22·6964·6d31·3234··apse"·id="idm1240004ce00:·6170·7365·2220·6964·3d22·6964·6d31·3234··apse"·id="idm124
0004d230:·3339·223e·3c74·6162·6c65·2063·6c61·7373··39"><table·class0004ce10:·3337·223e·3c74·6162·6c65·2063·6c61·7373··37"><table·class
0004d240:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st0004ce20:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st
0004d250:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord0004ce30:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord
0004d260:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde0004ce40:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde
0004d270:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co0004ce50:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co
0004d280:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t0004ce60:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t
0004d290:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><0004ce70:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
0004d2a0:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio0004ce80:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio
0004d2b0:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</0004ce90:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</
0004d2c0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>0004cea0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
0004d2d0:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td>0004ceb0:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td>
0004d2e0:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr><0004cec0:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr><
0004d2f0:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:0004ced0:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:
0004d300:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<0004cee0:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<
0004d310:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table0004cef0:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table
0004d320:·3e3c·7072·653e·3c63·6f64·653e·0a70·6163··><pre><code>.pac0004cf00:·3e3c·7072·653e·3c63·6f64·653e·696e·636c··><pre><code>incl
0004d330:·6b61·6765·2069·6e73·7461·6c6c·2072·6561··kage·install·rea 
0004d340:·720a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··r.</code></pre>< 
0004d350:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b 
Max diff block lines reached; 435944/472956 bytes (92.17%) of diff not shown.
61.1 KB
html2text {}
    
Offset 1167, 52 lines modifiedOffset 1167, 38 lines modified
1167 ··tags:1167 ··tags:
1168 ··-·enable_strategy1168 ··-·enable_strategy
1169 ··-·low_complexity1169 ··-·low_complexity
1170 ··-·low_disruption1170 ··-·low_disruption
1171 ··-·medium_severity1171 ··-·medium_severity
1172 ··-·no_reboot_needed1172 ··-·no_reboot_needed
1173 ··-·package_rear_installed1173 ··-·package_rear_installed
1174 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
1175 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
1176 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
1177 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
1178 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
1179 dnf·install·rear 
1180 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
1181 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
1182 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
1183 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
1184 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
1185 package·--add=rear 
1186 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81174 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
1187 [[packages]]1175 [[packages]]
1188 name·=·"rear"1176 name·=·"rear"
1189 version·=·"*"1177 version·=·"*"
1190 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
1191 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
1192 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
1193 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
1194 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
1195 package·install·rear 
1196 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81178 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1197 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1179 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1198 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1180 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1199 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1181 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1200 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1182 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1201 include·install_rear1183 include·install_rear
  
1202 class·install_rear·{1184 class·install_rear·{
1203 ··package·{·'rear':1185 ··package·{·'rear':
1204 ····ensure·=>·'installed',1186 ····ensure·=>·'installed',
1205 ··}1187 ··}
1206 }1188 }
 1189 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 1190 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1191 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1192 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1193 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 1194 package·install·rear
1207 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81195 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1208 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1196 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1209 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1197 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1210 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1198 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1211 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1199 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1212 #·Remediation·is·applicable·only·in·certain·platforms1200 #·Remediation·is·applicable·only·in·certain·platforms
1213 if·!·(·(·(·(·grep·-sqE·"^.*\.aarch64$"·/proc/sys/kernel/osrelease·||·grep·-sqE·"^aarch64$"·/proc/sys/kernel/arch;·)·&&·grep·-qP·"^ID=[\"']?ol[\"']?$"·"/etc/os-release"·&&·{·real="$(grep·-P·"^VERSION_ID=[\"']?[\w.]+[\"']?$"·/etc/os-release·|·sed·"s/^VERSION_ID=[\"']\?\([^\"']\+\)[\"']\?$/\1/")";·expected="9.0";·printf·"%s\n%s"·"$expected"·"$real"·|·sort·-VC;·}·)·||·(·(·grep·-sqE·"^.*\.aarch64$"·/proc/sys/kernel/osrelease·||·grep·-sqE·"^aarch64$"·/proc/sys/kernel/arch;·)·&&·grep·-qP·"^ID=[\"']?rhel[\"']?$"·"/etc/os-release"·&&·{·real="$(grep·-P·"^VERSION_ID=[\"']?[\w.]+[\"']?$"·/etc/os-release·|·sed·"s/^VERSION_ID=[\"']\?\([^\"']\+\)[\"']\?$/\1/")";·expected="9.0";·printf·"%s\n%s"·"$expected"·"$real"·|·sort·-VC;·}·)·||·(·grep·-qP·"^ID=[\"']?rhel[\"']?$"·"/etc/os-release"·&&·{·real="$(grep·-P·"^VERSION_ID=[\"']?[\w.]+[\"']?$"·/etc/os-release·|·sed·"s/^VERSION_ID=[\"']\?\([^\"']\+\)[\"']\?$/\1/")";·expected="8.4";·printf·"%s\n%s"·"$real"·"$expected"·|·sort·-VC;·}·&&·(·grep·-sqE·"^.*\.s390x$"·/proc/sys/kernel/osrelease·||·grep·-sqE·"^s390x$"·/proc/sys/kernel/arch;·)·)·)·);·then1201 if·!·(·(·(·(·grep·-sqE·"^.*\.aarch64$"·/proc/sys/kernel/osrelease·||·grep·-sqE·"^aarch64$"·/proc/sys/kernel/arch;·)·&&·grep·-qP·"^ID=[\"']?ol[\"']?$"·"/etc/os-release"·&&·{·real="$(grep·-P·"^VERSION_ID=[\"']?[\w.]+[\"']?$"·/etc/os-release·|·sed·"s/^VERSION_ID=[\"']\?\([^\"']\+\)[\"']\?$/\1/")";·expected="9.0";·printf·"%s\n%s"·"$expected"·"$real"·|·sort·-VC;·}·)·||·(·(·grep·-sqE·"^.*\.aarch64$"·/proc/sys/kernel/osrelease·||·grep·-sqE·"^aarch64$"·/proc/sys/kernel/arch;·)·&&·grep·-qP·"^ID=[\"']?rhel[\"']?$"·"/etc/os-release"·&&·{·real="$(grep·-P·"^VERSION_ID=[\"']?[\w.]+[\"']?$"·/etc/os-release·|·sed·"s/^VERSION_ID=[\"']\?\([^\"']\+\)[\"']\?$/\1/")";·expected="9.0";·printf·"%s\n%s"·"$expected"·"$real"·|·sort·-VC;·}·)·||·(·grep·-qP·"^ID=[\"']?rhel[\"']?$"·"/etc/os-release"·&&·{·real="$(grep·-P·"^VERSION_ID=[\"']?[\w.]+[\"']?$"·/etc/os-release·|·sed·"s/^VERSION_ID=[\"']\?\([^\"']\+\)[\"']\?$/\1/")";·expected="8.4";·printf·"%s\n%s"·"$real"·"$expected"·|·sort·-VC;·}·&&·(·grep·-sqE·"^.*\.s390x$"·/proc/sys/kernel/osrelease·||·grep·-sqE·"^s390x$"·/proc/sys/kernel/arch;·)·)·)·);·then
Offset 1220, 14 lines modifiedOffset 1206, 28 lines modified
1220 if·!·rpm·-q·--quiet·"rear"·;·then1206 if·!·rpm·-q·--quiet·"rear"·;·then
1221 ····dnf·install·-y·"rear"1207 ····dnf·install·-y·"rear"
1222 fi1208 fi
  
1223 else1209 else
1224 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'1210 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
1225 fi1211 fi
 1212 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 1213 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1214 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1215 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1216 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 1217 package·--add=rear
 1218 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 1219 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1220 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1221 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1222 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 1223 dnf·install·rear
1226 Group  ·Updating·Software·  Group·contains·6·rules1224 Group  ·Updating·Software·  Group·contains·6·rules
1227 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·dnf·command·line·tool·is·used·to·install·and·update·software·packages.·The·system·also·provides·a·graphical·software·update·tool·in·the·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·menu,·in·the·A\x8Ad\x8dm\x8mi\x8in\x8ni\x8is\x8st\x8tr\x8ra\x8at\x8ti\x8io\x8on\x8n·submenu,·called·S\x8So\x8of\x8ft\x8tw\x8wa\x8ar\x8re\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8e.1225 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·dnf·command·line·tool·is·used·to·install·and·update·software·packages.·The·system·also·provides·a·graphical·software·update·tool·in·the·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·menu,·in·the·A\x8Ad\x8dm\x8mi\x8in\x8ni\x8is\x8st\x8tr\x8ra\x8at\x8ti\x8io\x8on\x8n·submenu,·called·S\x8So\x8of\x8ft\x8tw\x8wa\x8ar\x8re\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8e.
  
1228 Red·Hat·Enterprise·Linux·9·systems·contain·an·installed·software·catalog·called·the·RPM·database,·which·records·metadata·of·installed·packages.·Consistently·using·dnf·or·the·graphical·S\x8So\x8of\x8ft\x8tw\x8wa\x8ar\x8re\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8e·for·all·software·installation·allows·for·insight·into·the·current·inventory·of·installed·software·on·the·system.1226 Red·Hat·Enterprise·Linux·9·systems·contain·an·installed·software·catalog·called·the·RPM·database,·which·records·metadata·of·installed·packages.·Consistently·using·dnf·or·the·graphical·S\x8So\x8of\x8ft\x8tw\x8wa\x8ar\x8re\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8e·for·all·software·installation·allows·for·insight·into·the·current·inventory·of·installed·software·on·the·system.
  
1229 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·d\x8dn\x8nf\x8f-\x8-a\x8au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8c·t\x8to\x8o·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·O\x8On\x8nl\x8ly\x8y·S\x8Se\x8ec\x8cu\x8ur\x8ri\x8it\x8ty\x8y·U\x8Up\x8pd\x8da\x8at\x8te\x8es\x8s·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*1227 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·d\x8dn\x8nf\x8f-\x8-a\x8au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8c·t\x8to\x8o·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·O\x8On\x8nl\x8ly\x8y·S\x8Se\x8ec\x8cu\x8ur\x8ri\x8it\x8ty\x8y·U\x8Up\x8pd\x8da\x8at\x8te\x8es\x8s·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
1230 To·configure·dnf-automatic·to·install·only·security·updates·automatically,·set·upgrade_type·to·security·under·[commands]·section·in·/etc/dnf/automatic.conf.1228 To·configure·dnf-automatic·to·install·only·security·updates·automatically,·set·upgrade_type·to·security·under·[commands]·section·in·/etc/dnf/automatic.conf.
Offset 2354, 52 lines modifiedOffset 2354, 38 lines modified
2354 ··-·NIST-800-53-CM-6(a)2354 ··-·NIST-800-53-CM-6(a)
2355 ··-·enable_strategy2355 ··-·enable_strategy
2356 ··-·low_complexity2356 ··-·low_complexity
2357 ··-·low_disruption2357 ··-·low_disruption
2358 ··-·medium_severity2358 ··-·medium_severity
2359 ··-·no_reboot_needed2359 ··-·no_reboot_needed
2360 ··-·package_rsyslog_installed2360 ··-·package_rsyslog_installed
2361 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
2362 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
2363 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
2364 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
2365 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
2366 dnf·install·rsyslog 
2367 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
2368 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
2369 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
2370 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
2371 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
2372 package·--add=rsyslog 
2373 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x82361 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
2374 [[packages]]2362 [[packages]]
2375 name·=·"rsyslog"2363 name·=·"rsyslog"
2376 version·=·"*"2364 version·=·"*"
2377 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
2378 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
2379 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
2380 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
2381 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
2382 package·install·rsyslog 
2383 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x82365 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
2384 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low2366 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
2385 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low2367 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
2386 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false2368 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
2387 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable2369 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
Max diff block lines reached; 56405/62502 bytes (90.25%) of diff not shown.
259 KB
./usr/share/doc/ssg-nondebian/ssg-cs9-guide-hipaa.html
    
Offset 22207, 129 lines modifiedOffset 22207, 129 lines modified
00056be0:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="00056be0:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
00056bf0:·2369·646d·3136·3238·3222·2074·6162·696e··#idm16282"·tabin00056bf0:·2369·646d·3136·3238·3222·2074·6162·696e··#idm16282"·tabin
00056c00:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu00056c00:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
00056c10:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan00056c10:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
00056c20:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl00056c20:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
00056c30:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r00056c30:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
00056c40:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"00056c40:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
00056c50:·3e52·656d·6564·6961·7469·6f6e·204b·7562··>Remediation·Kub00056c50:·3e52·656d·6564·6961·7469·6f6e·2050·7570··>Remediation·Pup
00056c60:·6572·6e65·7465·7320·736e·6970·7065·7420··ernetes·snippet·00056c60:·7065·7420·736e·6970·7065·7420·e287·b23c··pet·snippet·...<
00056c70:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·00056c70:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas
00056c80:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col00056c80:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps
00056c90:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·00056c90:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="
00056ca0:·6964·3d22·6964·6d31·3632·3832·223e·3c74··id="idm16282"><t00056ca0:·6964·6d31·3632·3832·223e·3c74·6162·6c65··idm16282"><table
00056cb0:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl00056cb0:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta
00056cc0:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·00056cc0:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl
00056cd0:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t00056cd0:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table
00056ce0:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">00056ce0:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>
00056cf0:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi00056cf0:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<
00056d00:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<00056d00:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
00056d10:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th00056d10:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis
00056d20:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th00056d20:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td
00056d30:·3e3c·7464·3e6d·6564·6975·6d3c·2f74·643e··><td>medium</td>00056d30:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
 00056d40:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t
 00056d50:·683e·3c74·643e·6661·6c73·653c·2f74·643e··h><td>false</td>
00056d40:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb00056d60:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str
 00056d70:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e
 00056d80:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr><
 00056d90:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod
 00056da0:·653e·696e·636c·7564·6520·6469·7361·626c··e>include·disabl
 00056db0:·655f·6465·6275·672d·7368·656c·6c0a·0a63··e_debug-shell..c
 00056dc0:·6c61·7373·2064·6973·6162·6c65·5f64·6562··lass·disable_deb
 00056dd0:·7567·2d73·6865·6c6c·207b·0a20·2073·6572··ug-shell·{.··ser
 00056de0:·7669·6365·207b·2764·6562·7567·2d73·6865··vice·{'debug-she
 00056df0:·6c6c·273a·0a20·2020·2065·6e61·626c·6520··ll':.····enable·
 00056e00:·3d26·6774·3b20·6661·6c73·652c·0a20·2020··=&gt;·false,.···
 00056e10:·2065·6e73·7572·6520·3d26·6774·3b20·2773···ensure·=&gt;·'s
 00056e20:·746f·7070·6564·272c·0a20·207d·0a7d·0a3c··topped',.··}.}.<
 00056e30:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di
 00056e40:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn·
 00056e50:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat
 00056e60:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap
 00056e70:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
 00056e80:·2223·6964·6d31·3632·3833·2220·7461·6269··"#idm16283"·tabi
 00056e90:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
 00056ea0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
 00056eb0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
 00056ec0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
 00056ed0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
 00056ee0:·223e·5265·6d65·6469·6174·696f·6e20·7363··">Remediation·sc
 00056ef0:·7269·7074·20e2·87b2·3c2f·613e·3c62·723e··ript·...</a><br>
 00056f00:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
 00056f10:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
 00056f20:·7073·6522·2069·643d·2269·646d·3136·3238··pse"·id="idm1628
 00056f30:·3322·3e3c·7461·626c·6520·636c·6173·733d··3"><table·class=
 00056f40:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str
 00056f50:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde
 00056f60:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden
 00056f70:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com
 00056f80:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td
 00056f90:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
 00056fa0:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption
 00056fb0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
 00056fc0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e52··d></tr><tr><th>R
00056d50:·6f6f·743a·3c2f·7468·3e3c·7464·3e74·7275··oot:</th><td>tru00056fd0:·6562·6f6f·743a·3c2f·7468·3e3c·7464·3e66··eboot:</th><td>f
00056d60:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr>< 
00056d70:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th 
00056d80:·3e3c·7464·3e64·6973·6162·6c65·3c2f·7464··><td>disable</td 
00056d90:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p 
00056da0:·7265·3e3c·636f·6465·3e61·7069·5665·7273··re><code>apiVers 
00056db0:·696f·6e3a·206d·6163·6869·6e65·636f·6e66··ion:·machineconf 
00056dc0:·6967·7572·6174·696f·6e2e·6f70·656e·7368··iguration.opensh 
00056dd0:·6966·742e·696f·2f76·310a·6b69·6e64·3a20··ift.io/v1.kind:·00056fe0:·616c·7365·3c2f·7464·3e3c·2f74·723e·3c74··alse</td></tr><t
 00056ff0:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<
 00057000:·2f74·683e·3c74·643e·6469·7361·626c·653c··/th><td>disable<
 00057010:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table
 00057020:·3e3c·7072·653e·3c63·6f64·653e·0a73·6572··><pre><code>.ser
 00057030:·7669·6365·2064·6973·6162·6c65·2064·6562··vice·disable·deb
 00057040:·7567·2d73·6865·6c6c·0a3c·2f63·6f64·653e··ug-shell.</code>
 00057050:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c
 00057060:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su
 00057070:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg
 00057080:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da
 00057090:·7461·2d74·6172·6765·743d·2223·6964·6d31··ta-target="#idm1
 000570a0:·3632·3834·2220·7461·6269·6e64·6578·3d22··6284"·tabindex="
 000570b0:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
 000570c0:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
 000570d0:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
 000570e0:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
 000570f0:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
 00057100:·6469·6174·696f·6e20·4b75·6265·726e·6574··diation·Kubernet
 00057110:·6573·2073·6e69·7070·6574·20e2·87b2·3c2f··es·snippet·...</
 00057120:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
 00057130:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
 00057140:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
 00057150:·646d·3136·3238·3422·3e3c·7461·626c·6520··dm16284"><table·
 00057160:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab
 00057170:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table
 00057180:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-
 00057190:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><
 000571a0:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</
 000571b0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
 000571c0:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr
 000571d0:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>
 000571e0:·6d65·6469·756d·3c2f·7464·3e3c·2f74·723e··medium</td></tr>
 000571f0:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:<
 00057200:·2f74·683e·3c74·643e·7472·7565·3c2f·7464··/th><td>true</td
 00057210:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St
 00057220:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>
 00057230:·6469·7361·626c·653c·2f74·643e·3c2f·7472··disable</td></tr
 00057240:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c
 00057250:·6f64·653e·6170·6956·6572·7369·6f6e·3a20··ode>apiVersion:·
00056de0:·4d61·6368·696e·6543·6f6e·6669·670a·7370··MachineConfig.sp00057260:·6d61·6368·696e·6563·6f6e·6669·6775·7261··machineconfigura
 00057270:·7469·6f6e·2e6f·7065·6e73·6869·6674·2e69··tion.openshift.i
 00057280:·6f2f·7631·0a6b·696e·643a·204d·6163·6869··o/v1.kind:·Machi
 00057290:·6e65·436f·6e66·6967·0a73·7065·633a·0a20··neConfig.spec:.·
 000572a0:·2063·6f6e·6669·673a·0a20·2020·2069·676e···config:.····ign
 000572b0:·6974·696f·6e3a·0a20·2020·2020·2076·6572··ition:.······ver
 000572c0:·7369·6f6e·3a20·332e·312e·300a·2020·2020··sion:·3.1.0.····
 000572d0:·7379·7374·656d·643a·0a20·2020·2020·2075··systemd:.······u
 000572e0:·6e69·7473·3a0a·2020·2020·2020·2d20·6e61··nits:.······-·na
 000572f0:·6d65·3a20·6465·6275·672d·7368·656c·6c2e··me:·debug-shell.
00056df0:·6563·3a0a·2020·636f·6e66·6967·3a0a·2020··ec:.··config:.·· 
00056e00:·2020·6967·6e69·7469·6f6e·3a0a·2020·2020····ignition:.···· 
00056e10:·2020·7665·7273·696f·6e3a·2033·2e31·2e30····version:·3.1.0 
00056e20:·0a20·2020·2073·7973·7465·6d64·3a0a·2020··.····systemd:.·· 
00056e30:·2020·2020·756e·6974·733a·0a20·2020·2020······units:.····· 
00056e40:·202d·206e·616d·653a·2064·6562·7567·2d73···-·name:·debug-s 
Max diff block lines reached; 217630/234080 bytes (92.97%) of diff not shown.
30.2 KB
html2text {}
    
Offset 1714, 14 lines modifiedOffset 1714, 34 lines modified
1714 ··-·medium_severity1714 ··-·medium_severity
1715 ··-·no_reboot_needed1715 ··-·no_reboot_needed
1716 ··-·service_debug-shell_disabled1716 ··-·service_debug-shell_disabled
1717 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81717 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
1718 [customizations.services]1718 [customizations.services]
1719 masked·=·["debug-shell"]1719 masked·=·["debug-shell"]
 1720 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 1721 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1722 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1723 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1724 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 1725 include·disable_debug-shell
  
 1726 class·disable_debug-shell·{
 1727 ··service·{'debug-shell':
 1728 ····enable·=>·false,
 1729 ····ensure·=>·'stopped',
 1730 ··}
 1731 }
 1732 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 1733 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1734 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1735 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1736 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
  
 1737 service·disable·debug-shell
1720 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81738 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1721 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1739 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1722 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium1740 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
1723 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true1741 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
1724 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable1742 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
1725 apiVersion:·machineconfiguration.openshift.io/v11743 apiVersion:·machineconfiguration.openshift.io/v1
1726 kind:·MachineConfig1744 kind:·MachineConfig
Offset 1733, 34 lines modifiedOffset 1753, 14 lines modified
1733 ······units:1753 ······units:
1734 ······-·name:·debug-shell.service1754 ······-·name:·debug-shell.service
1735 ········enabled:·false1755 ········enabled:·false
1736 ········mask:·true1756 ········mask:·true
1737 ······-·name:·debug-shell.socket1757 ······-·name:·debug-shell.socket
1738 ········enabled:·false1758 ········enabled:·false
1739 ········mask:·true1759 ········mask:·true
1740 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
1741 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
1742 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
1743 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
1744 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable 
  
1745 service·disable·debug-shell 
1746 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
1747 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
1748 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
1749 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
1750 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
1751 include·disable_debug-shell 
  
1752 class·disable_debug-shell·{ 
1753 ··service·{'debug-shell': 
1754 ····enable·=>·false, 
1755 ····ensure·=>·'stopped', 
1756 ··} 
1757 } 
1758 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81760 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1759 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1761 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1760 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1762 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1761 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1763 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1762 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable1764 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
1763 #·Remediation·is·applicable·only·in·certain·platforms1765 #·Remediation·is·applicable·only·in·certain·platforms
1764 if·rpm·--quiet·-q·kernel;·then1766 if·rpm·--quiet·-q·kernel;·then
Offset 3456, 14 lines modifiedOffset 3456, 34 lines modified
3456 ··-·medium_severity3456 ··-·medium_severity
3457 ··-·no_reboot_needed3457 ··-·no_reboot_needed
3458 ··-·service_autofs_disabled3458 ··-·service_autofs_disabled
3459 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x83459 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
3460 [customizations.services]3460 [customizations.services]
3461 masked·=·["autofs"]3461 masked·=·["autofs"]
 3462 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 3463 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 3464 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 3465 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 3466 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 3467 include·disable_autofs
  
 3468 class·disable_autofs·{
 3469 ··service·{'autofs':
 3470 ····enable·=>·false,
 3471 ····ensure·=>·'stopped',
 3472 ··}
 3473 }
 3474 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 3475 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 3476 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 3477 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 3478 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
  
 3479 service·disable·autofs
3462 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x83480 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
3463 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low3481 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
3464 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium3482 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
3465 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true3483 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
3466 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable3484 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
3467 apiVersion:·machineconfiguration.openshift.io/v13485 apiVersion:·machineconfiguration.openshift.io/v1
3468 kind:·MachineConfig3486 kind:·MachineConfig
Offset 3475, 34 lines modifiedOffset 3495, 14 lines modified
3475 ······units:3495 ······units:
3476 ······-·name:·autofs.service3496 ······-·name:·autofs.service
3477 ········enabled:·false3497 ········enabled:·false
3478 ········mask:·true3498 ········mask:·true
3479 ······-·name:·autofs.socket3499 ······-·name:·autofs.socket
3480 ········enabled:·false3500 ········enabled:·false
3481 ········mask:·true3501 ········mask:·true
3482 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
3483 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
3484 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
3485 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
3486 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable 
  
3487 service·disable·autofs 
3488 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
3489 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
3490 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
3491 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
3492 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
3493 include·disable_autofs 
  
3494 class·disable_autofs·{ 
Max diff block lines reached; 26513/30916 bytes (85.76%) of diff not shown.
696 KB
./usr/share/doc/ssg-nondebian/ssg-cs9-guide-ism_o.html
    
Offset 17544, 208 lines modifiedOffset 17544, 208 lines modified
00044870:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="00044870:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
00044880:·2369·646d·3834·3831·2220·7461·6269·6e64··#idm8481"·tabind00044880:·2369·646d·3834·3831·2220·7461·6269·6e64··#idm8481"·tabind
00044890:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but00044890:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
000448a0:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand000448a0:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
000448b0:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title000448b0:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
000448c0:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re000448c0:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
000448d0:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">000448d0:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
000448e0:·5265·6d65·6469·6174·696f·6e20·7363·7269··Remediation·scri000448e0:·5265·6d65·6469·6174·696f·6e20·4f53·4275··Remediation·OSBu
 000448f0:·696c·6420·426c·7565·7072·696e·7420·736e··ild·Blueprint·sn
 00044900:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br
 00044910:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
 00044920:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
 00044930:·6170·7365·2220·6964·3d22·6964·6d38·3438··apse"·id="idm848
 00044940:·3122·3e3c·7072·653e·3c63·6f64·653e·0a5b··1"><pre><code>.[
 00044950:·5b70·6163·6b61·6765·735d·5d0a·6e61·6d65··[packages]].name
 00044960:·203d·2022·6169·6465·220a·7665·7273·696f···=·"aide".versio
 00044970:·6e20·3d20·222a·220a·3c2f·636f·6465·3e3c··n·=·"*".</code><
000448f0:·7074·20e2·87b2·3c2f·613e·3c62·723e·3c64··pt·...</a><br><d 
00044900:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel- 
00044910:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps 
00044920:·6522·2069·643d·2269·646d·3834·3831·223e··e"·id="idm8481"> 
00044930:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta 
00044940:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe 
00044950:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered 
00044960:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed 
00044970:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple 
00044980:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo 
00044990:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr>< 
000449a0:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</ 
000449b0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td>< 
000449c0:·2f74·723e·3c74·723e·3c74·683e·5265·626f··/tr><tr><th>Rebo 
000449d0:·6f74·3a3c·2f74·683e·3c74·643e·6661·6c73··ot:</th><td>fals 
000449e0:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr>< 
000449f0:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th 
00044a00:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td> 
00044a10:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr 
00044a20:·653e·3c63·6f64·653e·0a64·6e66·2069·6e73··e><code>.dnf·ins 
00044a30:·7461·6c6c·2061·6964·650a·3c2f·636f·6465··tall·aide.</code 
00044a40:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a·00044980:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl
00044a50:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s00044990:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc
00044a60:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog000449a0:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl
00044a70:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d000449b0:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat
00044a80:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm000449c0:·612d·7461·7267·6574·3d22·2369·646d·3834··a-target="#idm84
00044a90:·3834·3832·2220·7461·6269·6e64·6578·3d22··8482"·tabindex="000449d0:·3832·2220·7461·6269·6e64·6578·3d22·3022··82"·tabindex="0"
00044aa0:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"000449e0:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
00044ab0:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="000449f0:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
00044ac0:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac00044a00:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
00044ad0:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal00044a10:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
00044ae0:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme00044a20:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
00044af0:·6469·6174·696f·6e20·416e·6163·6f6e·6461··diation·Anaconda00044a30:·6174·696f·6e20·5075·7070·6574·2073·6e69··ation·Puppet·sni
00044b00:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>00044a40:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>
00044b10:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="00044a50:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
00044b20:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c00044a60:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
00044b30:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm00044a70:·7073·6522·2069·643d·2269·646d·3834·3832··pse"·id="idm8482
00044b40:·3834·3832·223e·3c74·6162·6c65·2063·6c61··8482"><table·cla00044a80:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="
00044b50:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-00044a90:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri
00044b60:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo00044aa0:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border
00044b70:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con00044ab0:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens
00044b80:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>00044ac0:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp
00044b90:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>00044ad0:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>
00044ba0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr00044ae0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
00044bb0:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt00044af0:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:
 00044b00:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
 00044b10:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re
 00044b20:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa
 00044b30:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr
 00044b40:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</
 00044b50:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t
 00044b60:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><
 00044b70:·7072·653e·3c63·6f64·653e·696e·636c·7564··pre><code>includ
 00044b80:·6520·696e·7374·616c·6c5f·6169·6465·0a0a··e·install_aide..
 00044b90:·636c·6173·7320·696e·7374·616c·6c5f·6169··class·install_ai
 00044ba0:·6465·207b·0a20·2070·6163·6b61·6765·207b··de·{.··package·{
 00044bb0:·2027·6169·6465·273a·0a20·2020·2065·6e73···'aide':.····ens
 00044bc0:·7572·6520·3d26·6774·3b20·2769·6e73·7461··ure·=&gt;·'insta
 00044bd0:·6c6c·6564·272c·0a20·207d·0a7d·0a3c·2f63··lled',.··}.}.</c
 00044be0:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div>
 00044bf0:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt
 00044c00:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data-
 00044c10:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse
 00044c20:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
 00044c30:·6964·6d38·3438·3322·2074·6162·696e·6465··idm8483"·tabinde
 00044c40:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt
 00044c50:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande
 00044c60:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=
 00044c70:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev
 00044c80:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R
 00044c90:·656d·6564·6961·7469·6f6e·2073·6372·6970··emediation·scrip
 00044ca0:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di
 00044cb0:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c
 00044cc0:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse
 00044cd0:·2220·6964·3d22·6964·6d38·3438·3322·3e3c··"·id="idm8483"><
 00044ce0:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab
 00044cf0:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped
 00044d00:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·
 00044d10:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"
 00044d20:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex
00044bc0:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low00044d30:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low
00044bd0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t00044d40:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
00044be0:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t 
00044bf0:·643e·6661·6c73·653c·2f74·643e·3c2f·7472··d>false</td></tr 
00044c00:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg00044d50:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t
 00044d60:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
 00044d70:·7472·3e3c·7472·3e3c·7468·3e52·6562·6f6f··tr><tr><th>Reboo
00044c10:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl00044d80:·743a·3c2f·7468·3e3c·7464·3e66·616c·7365··t:</th><td>false
00044c20:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab 
00044c30:·6c65·3e3c·7072·653e·3c63·6f64·653e·0a70··le><pre><code>.p 
00044c40:·6163·6b61·6765·202d·2d61·6464·3d61·6964··ackage·--add=aid 
00044c50:·650a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··e.</code></pre>< 
00044c60:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b 
00044c70:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"· 
00044c80:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col 
00044c90:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ 
00044ca0:·6574·3d22·2369·646d·3834·3833·2220·7461··et="#idm8483"·ta 
00044cb0:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role= 
00044cc0:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex 
00044cd0:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t 
00044ce0:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t 
00044cf0:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href=" 
00044d00:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation· 
00044d10:·4f53·4275·696c·6420·426c·7565·7072·696e··OSBuild·Blueprin00044d90:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
 00044da0:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th>
 00044db0:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td><
 00044dc0:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre
 00044dd0:·3e3c·636f·6465·3e0a·7061·636b·6167·6520··><code>.package·
 00044de0:·696e·7374·616c·6c20·6169·6465·0a3c·2f63··install·aide.</c
 00044df0:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div>
Max diff block lines reached; 602570/629922 bytes (95.66%) of diff not shown.
81.0 KB
html2text {}
    
Offset 739, 52 lines modifiedOffset 739, 38 lines modified
739 ··-·PCI-DSSv4-11.5.2739 ··-·PCI-DSSv4-11.5.2
740 ··-·enable_strategy740 ··-·enable_strategy
741 ··-·low_complexity741 ··-·low_complexity
742 ··-·low_disruption742 ··-·low_disruption
743 ··-·medium_severity743 ··-·medium_severity
744 ··-·no_reboot_needed744 ··-·no_reboot_needed
745 ··-·package_aide_installed745 ··-·package_aide_installed
746 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
747 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
748 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
749 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
750 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
751 dnf·install·aide 
752 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
753 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
754 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
755 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
756 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
757 package·--add=aide 
758 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8746 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
759 [[packages]]747 [[packages]]
760 name·=·"aide"748 name·=·"aide"
761 version·=·"*"749 version·=·"*"
762 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
763 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
764 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
765 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
766 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
767 package·install·aide 
768 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8750 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
769 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low751 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
770 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low752 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
771 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false753 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
772 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable754 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
773 include·install_aide755 include·install_aide
  
774 class·install_aide·{756 class·install_aide·{
775 ··package·{·'aide':757 ··package·{·'aide':
776 ····ensure·=>·'installed',758 ····ensure·=>·'installed',
777 ··}759 ··}
778 }760 }
 761 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 762 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 763 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 764 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 765 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 766 package·install·aide
779 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8767 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
780 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low768 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
781 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low769 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
782 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false770 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
783 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable771 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
784 #·Remediation·is·applicable·only·in·certain·platforms772 #·Remediation·is·applicable·only·in·certain·platforms
785 if·rpm·--quiet·-q·kernel;·then773 if·rpm·--quiet·-q·kernel;·then
Offset 792, 14 lines modifiedOffset 778, 28 lines modified
792 if·!·rpm·-q·--quiet·"aide"·;·then778 if·!·rpm·-q·--quiet·"aide"·;·then
793 ····dnf·install·-y·"aide"779 ····dnf·install·-y·"aide"
794 fi780 fi
  
795 else781 else
796 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'782 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
797 fi783 fi
 784 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 785 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 786 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 787 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 788 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 789 package·--add=aide
 790 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 791 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 792 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 793 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 794 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 795 dnf·install·aide
798 Group  ·Federal·Information·Processing·Standard·(FIPS)·  Group·contains·2·rules796 Group  ·Federal·Information·Processing·Standard·(FIPS)·  Group·contains·2·rules
799 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·Federal·Information·Processing·Standard·(FIPS)·is·a·computer·security·standard·which·is·developed·by·the·U.S.·Government·and·industry·working·groups·to·validate·the·quality·of·cryptographic·modules.·The·FIPS·standard·provides·four·security·levels·to·ensure·adequate·coverage·of·different·industries,·implementation·of·cryptographic·modules,·and·organizational·sizes·and·requirements.797 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·Federal·Information·Processing·Standard·(FIPS)·is·a·computer·security·standard·which·is·developed·by·the·U.S.·Government·and·industry·working·groups·to·validate·the·quality·of·cryptographic·modules.·The·FIPS·standard·provides·four·security·levels·to·ensure·adequate·coverage·of·different·industries,·implementation·of·cryptographic·modules,·and·organizational·sizes·and·requirements.
  
800 FIPS·140-2·is·the·current·standard·for·validating·that·mechanisms·used·to·access·cryptographic·modules·utilize·authentication·that·meets·industry·and·government·requirements.·For·government·systems,·this·allows·Security·Levels·1,·2,·3,·or·4·for·use·on·Red·Hat·Enterprise·Linux·9.798 FIPS·140-2·is·the·current·standard·for·validating·that·mechanisms·used·to·access·cryptographic·modules·utilize·authentication·that·meets·industry·and·government·requirements.·For·government·systems,·this·allows·Security·Levels·1,·2,·3,·or·4·for·use·on·Red·Hat·Enterprise·Linux·9.
  
801 See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8c\x8c_\x8s\x8s_\x8r\x8r_\x8c\x8c_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8l\x8l_\x8i\x8i_\x8c\x8c_\x8a\x8a_\x8t\x8t_\x8i\x8i_\x8o\x8o_\x8n\x8n_\x8s\x8s_\x8/\x8/_\x8P\x8P_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x8h\x8h_\x8t\x8t_\x8m\x8m_\x8l\x8l·for·more·information.799 See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8c\x8c_\x8s\x8s_\x8r\x8r_\x8c\x8c_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8l\x8l_\x8i\x8i_\x8c\x8c_\x8a\x8a_\x8t\x8t_\x8i\x8i_\x8o\x8o_\x8n\x8n_\x8s\x8s_\x8/\x8/_\x8P\x8P_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x8h\x8h_\x8t\x8t_\x8m\x8m_\x8l\x8l·for·more·information.
802 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·D\x8Dr\x8ra\x8ac\x8cu\x8ut\x8t·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8du\x8ul\x8le\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*800 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·D\x8Dr\x8ra\x8ac\x8cu\x8ut\x8t·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8du\x8ul\x8le\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
Offset 1079, 52 lines modifiedOffset 1079, 38 lines modified
1079 ··-·PCI-DSSv4-2.2.61079 ··-·PCI-DSSv4-2.2.6
1080 ··-·enable_strategy1080 ··-·enable_strategy
1081 ··-·low_complexity1081 ··-·low_complexity
1082 ··-·low_disruption1082 ··-·low_disruption
1083 ··-·medium_severity1083 ··-·medium_severity
1084 ··-·no_reboot_needed1084 ··-·no_reboot_needed
1085 ··-·package_sudo_installed1085 ··-·package_sudo_installed
1086 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
1087 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
1088 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
1089 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
1090 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
1091 dnf·install·sudo 
1092 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
1093 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
1094 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
1095 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
1096 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
1097 package·--add=sudo 
1098 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81086 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
1099 [[packages]]1087 [[packages]]
1100 name·=·"sudo"1088 name·=·"sudo"
1101 version·=·"*"1089 version·=·"*"
1102 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
1103 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
1104 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
1105 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
1106 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
1107 package·install·sudo 
1108 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81090 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1109 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1091 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1110 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1092 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1111 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1093 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1112 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1094 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
Max diff block lines reached; 77822/82945 bytes (93.82%) of diff not shown.
654 KB
./usr/share/doc/ssg-nondebian/ssg-cs9-guide-ospp.html
    
Offset 15853, 203 lines modifiedOffset 15853, 203 lines modified
0003dec0:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm0003dec0:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
0003ded0:·3931·3634·2220·7461·6269·6e64·6578·3d22··9164"·tabindex="0003ded0:·3931·3634·2220·7461·6269·6e64·6578·3d22··9164"·tabindex="
0003dee0:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"0003dee0:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
0003def0:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="0003def0:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
0003df00:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac0003df00:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
0003df10:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal0003df10:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
0003df20:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme0003df20:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
0003df30:·6469·6174·696f·6e20·7363·7269·7074·20e2··diation·script·.0003df30:·6469·6174·696f·6e20·4f53·4275·696c·6420··diation·OSBuild·
 0003df40:·426c·7565·7072·696e·7420·736e·6970·7065··Blueprint·snippe
 0003df50:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di
 0003df60:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c
 0003df70:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse
 0003df80:·2220·6964·3d22·6964·6d39·3136·3422·3e3c··"·id="idm9164"><
 0003df90:·7072·653e·3c63·6f64·653e·0a5b·5b70·6163··pre><code>.[[pac
 0003dfa0:·6b61·6765·735d·5d0a·6e61·6d65·203d·2022··kages]].name·=·"
 0003dfb0:·6372·7970·746f·2d70·6f6c·6963·6965·7322··crypto-policies"
 0003dfc0:·0a76·6572·7369·6f6e·203d·2022·2a22·0a3c··.version·=·"*".<
0003df40:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c 
0003df50:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll 
0003df60:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i 
0003df70:·643d·2269·646d·3931·3634·223e·3c74·6162··d="idm9164"><tab 
0003df80:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table· 
0003df90:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta 
0003dfa0:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab 
0003dfb0:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t 
0003dfc0:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity 
0003dfd0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t 
0003dfe0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D 
0003dff0:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th>< 
0003e000:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
0003e010:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:< 
0003e020:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t 
0003e030:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S 
0003e040:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td 
0003e050:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr 
0003e060:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c 
0003e070:·6f64·653e·0a64·6e66·2069·6e73·7461·6c6c··ode>.dnf·install 
0003e080:·2063·7279·7074·6f2d·706f·6c69·6369·6573···crypto-policies 
0003e090:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></0003dfd0:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di
0003e0a0:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt0003dfe0:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn·
0003e0b0:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d0003dff0:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat
0003e0c0:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll0003e000:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap
0003e0d0:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe0003e010:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
0003e0e0:·743d·2223·6964·6d39·3136·3522·2074·6162··t="#idm9165"·tab0003e020:·2223·6964·6d39·3136·3522·2074·6162·696e··"#idm9165"·tabin
0003e0f0:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="0003e030:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
0003e100:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp0003e040:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
0003e110:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti0003e050:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
0003e120:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to0003e060:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
0003e130:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#0003e070:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
0003e140:·2122·3e52·656d·6564·6961·7469·6f6e·2041··!">Remediation·A0003e080:·3e52·656d·6564·6961·7469·6f6e·2050·7570··>Remediation·Pup
0003e150:·6e61·636f·6e64·6120·736e·6970·7065·7420··naconda·snippet· 
0003e160:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div· 
0003e170:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col 
0003e180:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"· 
0003e190:·6964·3d22·6964·6d39·3136·3522·3e3c·7461··id="idm9165"><ta 
0003e1a0:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table 
0003e1b0:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t 
0003e1c0:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta 
0003e1d0:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed">< 
0003e1e0:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit 
0003e1f0:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</ 
0003e200:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
0003e210:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th> 
0003e220:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
0003e230:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot: 
0003e240:·3c2f·7468·3e3c·7464·3e66·616c·7365·3c2f··</th><td>false</ 
0003e250:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
0003e260:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t 
0003e270:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t 
0003e280:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre>< 
0003e290:·636f·6465·3e0a·7061·636b·6167·6520·2d2d··code>.package·-- 
0003e2a0:·6164·643d·6372·7970·746f·2d70·6f6c·6963··add=crypto-polic 
0003e2b0:·6965·730a·3c2f·636f·6465·3e3c·2f70·7265··ies.</code></pre 
0003e2c0:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class= 
0003e2d0:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success 
0003e2e0:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c 
0003e2f0:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta 
0003e300:·7267·6574·3d22·2369·646d·3931·3636·2220··rget="#idm9166"· 
0003e310:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol 
0003e320:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria- 
0003e330:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false" 
0003e340:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate 
0003e350:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href 
0003e360:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio 
0003e370:·6e20·4f53·4275·696c·6420·426c·7565·7072··n·OSBuild·Bluepr 
0003e380:·696e·7420·736e·6970·7065·7420·e287·b23c··int·snippet·...<0003e090:·7065·7420·736e·6970·7065·7420·e287·b23c··pet·snippet·...<
0003e390:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas0003e0a0:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas
0003e3a0:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps0003e0b0:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps
0003e3b0:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="0003e0c0:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="
0003e3c0:·6964·6d39·3136·3622·3e3c·7072·653e·3c63··idm9166"><pre><c 
0003e3d0:·6f64·653e·0a5b·5b70·6163·6b61·6765·735d··ode>.[[packages] 
0003e3e0:·5d0a·6e61·6d65·203d·2022·6372·7970·746f··].name·=·"crypto 
0003e3f0:·2d70·6f6c·6963·6965·7322·0a76·6572·7369··-policies".versi 
0003e400:·6f6e·203d·2022·2a22·0a3c·2f63·6f64·653e··on·=·"*".</code> 
0003e410:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c 
0003e420:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su 
0003e430:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg 
0003e440:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da 
0003e450:·7461·2d74·6172·6765·743d·2223·6964·6d39··ta-target="#idm9 
0003e460:·3136·3722·2074·6162·696e·6465·783d·2230··167"·tabindex="0 
0003e470:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"· 
0003e480:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f 
0003e490:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act 
0003e4a0:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal" 
0003e4b0:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed 
0003e4c0:·6961·7469·6f6e·2073·6372·6970·7420·e287··iation·script·.. 
0003e4d0:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl 
0003e4e0:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla 
0003e4f0:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id 
0003e500:·3d22·6964·6d39·3136·3722·3e3c·7461·626c··="idm9167"><tabl0003e0d0:·6964·6d39·3136·3522·3e3c·7461·626c·6520··idm9165"><table·
0003e510:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t0003e0e0:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab
0003e520:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab0003e0f0:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table
0003e530:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl0003e100:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-
0003e540:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr0003e110:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><
0003e550:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:0003e120:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</
0003e560:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td0003e130:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
0003e570:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di0003e140:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr
0003e580:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t0003e150:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>
0003e590:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr>< 
0003e5a0:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</ 
0003e5b0:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td 
0003e5c0:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St 
0003e5d0:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td> 
0003e5e0:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr> 
0003e5f0:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co 
0003e600:·6465·3e0a·7061·636b·6167·6520·696e·7374··de>.package·inst 
0003e610:·616c·6c20·6372·7970·746f·2d70·6f6c·6963··all·crypto-polic 
Max diff block lines reached; 568788/595450 bytes (95.52%) of diff not shown.
72.0 KB
html2text {}
    
Offset 178, 61 lines modifiedOffset 178, 61 lines modified
178 ··-·DISA-STIG-RHEL-09-215100178 ··-·DISA-STIG-RHEL-09-215100
179 ··-·enable_strategy179 ··-·enable_strategy
180 ··-·low_complexity180 ··-·low_complexity
181 ··-·low_disruption181 ··-·low_disruption
182 ··-·medium_severity182 ··-·medium_severity
183 ··-·no_reboot_needed183 ··-·no_reboot_needed
184 ··-·package_crypto-policies_installed184 ··-·package_crypto-policies_installed
185 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
186 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
187 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
188 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
189 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
190 dnf·install·crypto-policies 
191 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
192 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
193 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
194 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
195 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
196 package·--add=crypto-policies 
197 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8185 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
198 [[packages]]186 [[packages]]
199 name·=·"crypto-policies"187 name·=·"crypto-policies"
200 version·=·"*"188 version·=·"*"
201 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
202 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
203 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
204 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
205 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
206 package·install·crypto-policies 
207 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8189 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
208 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low190 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
209 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low191 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
210 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false192 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
211 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable193 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
212 include·install_crypto-policies194 include·install_crypto-policies
  
213 class·install_crypto-policies·{195 class·install_crypto-policies·{
214 ··package·{·'crypto-policies':196 ··package·{·'crypto-policies':
215 ····ensure·=>·'installed',197 ····ensure·=>·'installed',
216 ··}198 ··}
217 }199 }
 200 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 201 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 202 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 203 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 204 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 205 package·install·crypto-policies
218 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8206 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
219 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low207 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
220 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low208 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
221 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false209 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
222 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable210 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
223 if·!·rpm·-q·--quiet·"crypto-policies"·;·then211 if·!·rpm·-q·--quiet·"crypto-policies"·;·then
224 ····dnf·install·-y·"crypto-policies"212 ····dnf·install·-y·"crypto-policies"
225 fi213 fi
 214 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 215 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 216 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 217 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 218 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 219 package·--add=crypto-policies
 220 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 221 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 222 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 223 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 224 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 225 dnf·install·crypto-policies
226 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8og\x8gr\x8ra\x8ap\x8ph\x8hy\x8y·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*226 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8og\x8gr\x8ra\x8ap\x8ph\x8hy\x8y·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
227 To·configure·the·system·cryptography·policy·to·use·ciphers·only·from·the·FIPS:OSPP·policy,·run·the·following·command:227 To·configure·the·system·cryptography·policy·to·use·ciphers·only·from·the·FIPS:OSPP·policy,·run·the·following·command:
228 $·sudo·update-crypto-policies·--set·FIPS:OSPP228 $·sudo·update-crypto-policies·--set·FIPS:OSPP
229 The·rule·checks·if·settings·for·selected·crypto·policy·are·configured·as·expected.·Configuration·files·in·the·/etc/crypto-policies/back-ends·are·either·symlinks·to·correct·files·provided·by·Crypto-policies·package·or·they·are·regular·files·in·case·crypto·policy·customizations·are·applied.·Crypto·policies·may·be·customized·by·crypto·policy·modules,·in·which·case·it·is·delimited·from·the·base·policy·using·a·colon.229 The·rule·checks·if·settings·for·selected·crypto·policy·are·configured·as·expected.·Configuration·files·in·the·/etc/crypto-policies/back-ends·are·either·symlinks·to·correct·files·provided·by·Crypto-policies·package·or·they·are·regular·files·in·case·crypto·policy·customizations·are·applied.·Crypto·policies·may·be·customized·by·crypto·policy·modules,·in·which·case·it·is·delimited·from·the·base·policy·using·a·colon.
230 Warning: ·The·system·needs·to·be·rebooted·for·these·changes·to·take·effect.230 Warning: ·The·system·needs·to·be·rebooted·for·these·changes·to·take·effect.
231 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8n\x8n_\x8v\x8v_\x8l\x8l_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8/\x8/_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8/\x8/_\x8N\x8N_\x8I\x8I_\x8S\x8S_\x8T\x8T_\x8.\x8._\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x81\x81_\x84\x84_\x80\x80_\x8-\x8-_\x82\x82_\x8.\x8._\x8p\x8p_\x8d\x8d_\x8f\x8f·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.231 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8n\x8n_\x8v\x8v_\x8l\x8l_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8/\x8/_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8/\x8/_\x8N\x8N_\x8I\x8I_\x8S\x8S_\x8T\x8T_\x8.\x8._\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x81\x81_\x84\x84_\x80\x80_\x8-\x8-_\x82\x82_\x8.\x8._\x8p\x8p_\x8d\x8d_\x8f\x8f·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.
232 Rationale:··Centralized·cryptographic·policies·simplify·applying·secure·ciphers·across·an·operating·system·and·the·applications·that·run·on·that·operating·system.·Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.232 Rationale:··Centralized·cryptographic·policies·simplify·applying·secure·ciphers·across·an·operating·system·and·the·applications·that·run·on·that·operating·system.·Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.
Offset 565, 29 lines modifiedOffset 565, 29 lines modified
565 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-4,·PR.PT-1,·PR.PT-4565 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-4,·PR.PT-1,·PR.PT-4
566 ············_\x8o_\x8s_\x8p_\x8p···········FMT_SMF_EXT.1566 ············_\x8o_\x8s_\x8p_\x8p···········FMT_SMF_EXT.1
567 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000341-GPOS-00132,·SRG-OS-000480-GPOS-00227567 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000341-GPOS-00132,·SRG-OS-000480-GPOS-00227
568 ············_\x8a_\x8p_\x8p_\x8-_\x8s_\x8r_\x8g_\x8-_\x8c_\x8t_\x8r····SRG-APP-000357-CTR-000800568 ············_\x8a_\x8p_\x8p_\x8-_\x8s_\x8r_\x8g_\x8-_\x8c_\x8t_\x8r····SRG-APP-000357-CTR-000800
569 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R71569 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R71
570 ············_\x8c_\x8i_\x8s············1.1.2.7.1570 ············_\x8c_\x8i_\x8s············1.1.2.7.1
571 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-257847r1044924_rule571 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-257847r1044924_rule
572 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
573 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
574 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high 
575 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
576 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
577 part·/var/log/audit 
578 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8572 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
579 [[customizations.filesystem]]573 [[customizations.filesystem]]
580 mountpoint·=·"/var/log/audit"574 mountpoint·=·"/var/log/audit"
581 size·=·10737418240575 size·=·10737418240
582 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8576 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
583 logvol·/var/log/audit·10240577 logvol·/var/log/audit·10240
 578 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 579 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 580 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high
 581 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 582 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 583 part·/var/log/audit
584 Group  ·Sudo·  Group·contains·1·rule584 Group  ·Sudo·  Group·contains·1·rule
585 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Sudo,·which·stands·for·"su·'do'",·provides·the·ability·to·delegate·authority·to·certain·users,·groups·of·users,·or·system·administrators.·When·configured·for·system·users·and/or·groups,·Sudo·can·allow·a·user·or·group·to·execute·privileged·commands·that·normally·only·root·is·allowed·to·execute.585 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Sudo,·which·stands·for·"su·'do'",·provides·the·ability·to·delegate·authority·to·certain·users,·groups·of·users,·or·system·administrators.·When·configured·for·system·users·and/or·groups,·Sudo·can·allow·a·user·or·group·to·execute·privileged·commands·that·normally·only·root·is·allowed·to·execute.
  
586 For·more·information·on·Sudo·and·addition·Sudo·configuration·options,·see·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8w\x8w_\x8w\x8w_\x8w\x8w_\x8.\x8._\x8s\x8s_\x8u\x8u_\x8d\x8d_\x8o\x8o_\x8.\x8._\x8w\x8w_\x8s\x8s.586 For·more·information·on·Sudo·and·addition·Sudo·configuration·options,·see·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8w\x8w_\x8w\x8w_\x8w\x8w_\x8.\x8._\x8s\x8s_\x8u\x8u_\x8d\x8d_\x8o\x8o_\x8.\x8._\x8w\x8w_\x8s\x8s.
587 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·s\x8su\x8ud\x8do\x8o·P\x8Pa\x8ac\x8ck\x8ka\x8ag\x8ge\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*587 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·s\x8su\x8ud\x8do\x8o·P\x8Pa\x8ac\x8ck\x8ka\x8ag\x8ge\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
588 The·sudo·package·can·be·installed·with·the·following·command:588 The·sudo·package·can·be·installed·with·the·following·command:
589 $·sudo·dnf·install·sudo589 $·sudo·dnf·install·sudo
Offset 635, 52 lines modifiedOffset 635, 38 lines modified
635 ··-·PCI-DSSv4-2.2.6635 ··-·PCI-DSSv4-2.2.6
636 ··-·enable_strategy636 ··-·enable_strategy
637 ··-·low_complexity637 ··-·low_complexity
638 ··-·low_disruption638 ··-·low_disruption
639 ··-·medium_severity639 ··-·medium_severity
640 ··-·no_reboot_needed640 ··-·no_reboot_needed
641 ··-·package_sudo_installed641 ··-·package_sudo_installed
Max diff block lines reached; 66002/73751 bytes (89.49%) of diff not shown.
639 KB
./usr/share/doc/ssg-nondebian/ssg-cs9-guide-pci-dss.html
    
Offset 16797, 207 lines modifiedOffset 16797, 207 lines modified
000419c0:·6765·743d·2223·6964·6d38·3438·3122·2074··get="#idm8481"·t000419c0:·6765·743d·2223·6964·6d38·3438·3122·2074··get="#idm8481"·t
000419d0:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role000419d0:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
000419e0:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e000419e0:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
000419f0:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·000419f0:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
00041a00:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·00041a00:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
00041a10:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=00041a10:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
00041a20:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation00041a20:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
 00041a30:·204f·5342·7569·6c64·2042·6c75·6570·7269···OSBuild·Bluepri
 00041a40:·6e74·2073·6e69·7070·6574·20e2·87b2·3c2f··nt·snippet·...</
 00041a50:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
 00041a60:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
 00041a70:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
 00041a80:·646d·3834·3831·223e·3c70·7265·3e3c·636f··dm8481"><pre><co
 00041a90:·6465·3e0a·5b5b·7061·636b·6167·6573·5d5d··de>.[[packages]]
 00041aa0:·0a6e·616d·6520·3d20·2261·6964·6522·0a76··.name·=·"aide".v
 00041ab0:·6572·7369·6f6e·203d·2022·2a22·0a3c·2f63··ersion·=·"*".</c
00041a30:·2073·6372·6970·7420·e287·b23c·2f61·3e3c···script·...</a>< 
00041a40:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p 
00041a50:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co 
00041a60:·6c6c·6170·7365·2220·6964·3d22·6964·6d38··llapse"·id="idm8 
00041a70:·3438·3122·3e3c·7461·626c·6520·636c·6173··481"><table·clas 
00041a80:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s 
00041a90:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor 
00041aa0:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond 
00041ab0:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C 
00041ac0:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th>< 
00041ad0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
00041ae0:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti 
00041af0:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low< 
00041b00:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
00041b10:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td 
00041b20:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr> 
00041b30:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy 
00041b40:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable 
00041b50:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl 
00041b60:·653e·3c70·7265·3e3c·636f·6465·3e0a·646e··e><pre><code>.dn 
00041b70:·6620·696e·7374·616c·6c20·6169·6465·0a3c··f·install·aide.< 
00041b80:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di00041ac0:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div>
00041b90:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn·00041ad0:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt
00041ba0:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat00041ae0:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data-
00041bb0:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap00041af0:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse
00041bc0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=00041b00:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
00041bd0:·2223·6964·6d38·3438·3222·2074·6162·696e··"#idm8482"·tabin00041b10:·6964·6d38·3438·3222·2074·6162·696e·6465··idm8482"·tabinde
00041be0:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu00041b20:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt
00041bf0:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan00041b30:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande
00041c00:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl00041b40:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=
00041c10:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r00041b50:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev
00041c20:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"00041b60:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R
00041c30:·3e52·656d·6564·6961·7469·6f6e·2041·6e61··>Remediation·Ana 
00041c40:·636f·6e64·6120·736e·6970·7065·7420·e287··conda·snippet·..00041b70:·656d·6564·6961·7469·6f6e·2050·7570·7065··emediation·Puppe
 00041b80:·7420·736e·6970·7065·7420·e287·b23c·2f61··t·snippet·...</a
00041c50:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl00041b90:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
00041c60:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla00041ba0:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
00041c70:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id00041bb0:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
00041c80:·3d22·6964·6d38·3438·3222·3e3c·7461·626c··="idm8482"><tabl00041bc0:·6d38·3438·3222·3e3c·7461·626c·6520·636c··m8482"><table·cl
00041c90:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t00041bd0:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table
00041ca0:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab00041be0:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b
00041cb0:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl00041bf0:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co
00041cc0:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr00041c00:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th
00041cd0:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:00041c10:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th
00041ce0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td00041c20:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
00041cf0:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di00041c30:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup
00041d00:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t00041c40:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo
 00041c50:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
 00041c60:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th><
 00041c70:·7464·3e66·616c·7365·3c2f·7464·3e3c·2f74··td>false</td></t
 00041c80:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate
 00041c90:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab
 00041ca0:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta
 00041cb0:·626c·653e·3c70·7265·3e3c·636f·6465·3e69··ble><pre><code>i
 00041cc0:·6e63·6c75·6465·2069·6e73·7461·6c6c·5f61··nclude·install_a
 00041cd0:·6964·650a·0a63·6c61·7373·2069·6e73·7461··ide..class·insta
 00041ce0:·6c6c·5f61·6964·6520·7b0a·2020·7061·636b··ll_aide·{.··pack
 00041cf0:·6167·6520·7b20·2761·6964·6527·3a0a·2020··age·{·'aide':.··
 00041d00:·2020·656e·7375·7265·203d·2667·743b·2027····ensure·=&gt;·'
 00041d10:·696e·7374·616c·6c65·6427·2c0a·2020·7d0a··installed',.··}.
 00041d20:·7d0a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··}.</code></pre><
 00041d30:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b
 00041d40:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"·
 00041d50:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col
 00041d60:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ
 00041d70:·6574·3d22·2369·646d·3834·3833·2220·7461··et="#idm8483"·ta
 00041d80:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
 00041d90:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
 00041da0:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
 00041db0:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
 00041dc0:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
 00041dd0:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
 00041de0:·7363·7269·7074·20e2·87b2·3c2f·613e·3c62··script·...</a><b
 00041df0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
 00041e00:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
 00041e10:·6c61·7073·6522·2069·643d·2269·646d·3834··lapse"·id="idm84
 00041e20:·3833·223e·3c74·6162·6c65·2063·6c61·7373··83"><table·class
 00041e30:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st
 00041e40:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord
 00041e50:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde
 00041e60:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co
 00041e70:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t
00041d10:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><00041e80:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
00041d20:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</ 
00041d30:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td00041e90:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio
 00041ea0:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</
00041d40:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St00041eb0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
00041d50:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>00041ec0:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td>
00041d60:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr> 
00041d70:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co 
00041d80:·6465·3e0a·7061·636b·6167·6520·2d2d·6164··de>.package·--ad 
00041d90:·643d·6169·6465·0a3c·2f63·6f64·653e·3c2f··d=aide.</code></ 
00041da0:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla 
00041db0:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ 
00041dc0:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle 
00041dd0:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data 
00041de0:·2d74·6172·6765·743d·2223·6964·6d38·3438··-target="#idm848 
00041df0:·3322·2074·6162·696e·6465·783d·2230·2220··3"·tabindex="0"· 
00041e00:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar 
00041e10:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal 
00041e20:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ 
00041e30:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h 
00041e40:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia 
00041e50:·7469·6f6e·204f·5342·7569·6c64·2042·6c75··tion·OSBuild·Blu 
00041e60:·6570·7269·6e74·2073·6e69·7070·6574·20e2··eprint·snippet·.00041ed0:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr><
 00041ee0:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:
 00041ef0:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<
 00041f00:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table
 00041f10:·3e3c·7072·653e·3c63·6f64·653e·0a70·6163··><pre><code>.pac
 00041f20:·6b61·6765·2069·6e73·7461·6c6c·2061·6964··kage·install·aid
 00041f30:·650a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··e.</code></pre><
Max diff block lines reached; 550602/577816 bytes (95.29%) of diff not shown.
74.6 KB
html2text {}
    
Offset 555, 52 lines modifiedOffset 555, 38 lines modified
555 ··-·PCI-DSSv4-11.5.2555 ··-·PCI-DSSv4-11.5.2
556 ··-·enable_strategy556 ··-·enable_strategy
557 ··-·low_complexity557 ··-·low_complexity
558 ··-·low_disruption558 ··-·low_disruption
559 ··-·medium_severity559 ··-·medium_severity
560 ··-·no_reboot_needed560 ··-·no_reboot_needed
561 ··-·package_aide_installed561 ··-·package_aide_installed
562 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
563 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
564 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
565 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
566 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
567 dnf·install·aide 
568 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
569 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
570 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
571 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
572 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
573 package·--add=aide 
574 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8562 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
575 [[packages]]563 [[packages]]
576 name·=·"aide"564 name·=·"aide"
577 version·=·"*"565 version·=·"*"
578 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
579 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
580 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
581 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
582 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
583 package·install·aide 
584 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8566 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
585 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low567 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
586 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low568 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
587 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false569 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
588 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable570 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
589 include·install_aide571 include·install_aide
  
590 class·install_aide·{572 class·install_aide·{
591 ··package·{·'aide':573 ··package·{·'aide':
592 ····ensure·=>·'installed',574 ····ensure·=>·'installed',
593 ··}575 ··}
594 }576 }
 577 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 578 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 579 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 580 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 581 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 582 package·install·aide
595 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8583 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
596 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low584 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
597 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low585 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
598 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false586 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
599 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable587 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
600 #·Remediation·is·applicable·only·in·certain·platforms588 #·Remediation·is·applicable·only·in·certain·platforms
601 if·rpm·--quiet·-q·kernel;·then589 if·rpm·--quiet·-q·kernel;·then
Offset 608, 14 lines modifiedOffset 594, 28 lines modified
608 if·!·rpm·-q·--quiet·"aide"·;·then594 if·!·rpm·-q·--quiet·"aide"·;·then
609 ····dnf·install·-y·"aide"595 ····dnf·install·-y·"aide"
610 fi596 fi
  
611 else597 else
612 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'598 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
613 fi599 fi
 600 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 601 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 602 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 603 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 604 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 605 package·--add=aide
 606 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 607 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 608 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 609 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 610 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 611 dnf·install·aide
614 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*612 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
615 Run·the·following·command·to·generate·a·new·database:613 Run·the·following·command·to·generate·a·new·database:
616 $·sudo·/usr/sbin/aide·--init614 $·sudo·/usr/sbin/aide·--init
617 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:615 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
618 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz616 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
619 To·initiate·a·manual·check,·run·the·following·command:617 To·initiate·a·manual·check,·run·the·following·command:
620 $·sudo·/usr/sbin/aide·--check618 $·sudo·/usr/sbin/aide·--check
Offset 2731, 52 lines modifiedOffset 2731, 38 lines modified
2731 ··-·PCI-DSSv4-2.2.62731 ··-·PCI-DSSv4-2.2.6
2732 ··-·enable_strategy2732 ··-·enable_strategy
2733 ··-·low_complexity2733 ··-·low_complexity
2734 ··-·low_disruption2734 ··-·low_disruption
2735 ··-·medium_severity2735 ··-·medium_severity
2736 ··-·no_reboot_needed2736 ··-·no_reboot_needed
2737 ··-·package_sudo_installed2737 ··-·package_sudo_installed
2738 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
2739 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
2740 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
2741 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
2742 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
2743 dnf·install·sudo 
2744 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
2745 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
2746 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
2747 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
2748 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
2749 package·--add=sudo 
2750 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x82738 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
2751 [[packages]]2739 [[packages]]
2752 name·=·"sudo"2740 name·=·"sudo"
2753 version·=·"*"2741 version·=·"*"
2754 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
2755 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
2756 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
2757 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
2758 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
2759 package·install·sudo 
2760 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x82742 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
2761 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low2743 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
2762 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low2744 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
2763 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false2745 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
2764 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable2746 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
Max diff block lines reached; 71651/76346 bytes (93.85%) of diff not shown.
1.86 MB
./usr/share/doc/ssg-nondebian/ssg-cs9-guide-stig.html
    
Offset 15308, 207 lines modifiedOffset 15308, 207 lines modified
0003bcb0:·7267·6574·3d22·2369·646d·3834·3831·2220··rget="#idm8481"·0003bcb0:·7267·6574·3d22·2369·646d·3834·3831·2220··rget="#idm8481"·
0003bcc0:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol0003bcc0:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol
0003bcd0:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-0003bcd0:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-
0003bce0:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"0003bce0:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"
0003bcf0:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate0003bcf0:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate
0003bd00:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href0003bd00:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href
0003bd10:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio0003bd10:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio
 0003bd20:·6e20·4f53·4275·696c·6420·426c·7565·7072··n·OSBuild·Bluepr
 0003bd30:·696e·7420·736e·6970·7065·7420·e287·b23c··int·snippet·...<
 0003bd40:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas
 0003bd50:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps
 0003bd60:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="
 0003bd70:·6964·6d38·3438·3122·3e3c·7072·653e·3c63··idm8481"><pre><c
 0003bd80:·6f64·653e·0a5b·5b70·6163·6b61·6765·735d··ode>.[[packages]
 0003bd90:·5d0a·6e61·6d65·203d·2022·6169·6465·220a··].name·=·"aide".
 0003bda0:·7665·7273·696f·6e20·3d20·222a·220a·3c2f··version·=·"*".</
0003bd20:·6e20·7363·7269·7074·20e2·87b2·3c2f·613e··n·script·...</a> 
0003bd30:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class=" 
0003bd40:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c 
0003bd50:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm 
0003bd60:·3834·3831·223e·3c74·6162·6c65·2063·6c61··8481"><table·cla 
0003bd70:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table- 
0003bd80:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo 
0003bd90:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con 
0003bda0:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th> 
0003bdb0:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th> 
0003bdc0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
0003bdd0:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt 
0003bde0:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low 
0003bdf0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
0003be00:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t 
0003be10:·643e·6661·6c73·653c·2f74·643e·3c2f·7472··d>false</td></tr 
0003be20:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg 
0003be30:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl 
0003be40:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab 
0003be50:·6c65·3e3c·7072·653e·3c63·6f64·653e·0a64··le><pre><code>.d 
0003be60:·6e66·2069·6e73·7461·6c6c·2061·6964·650a··nf·install·aide. 
0003be70:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d0003bdb0:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div
0003be80:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn0003bdc0:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b
0003be90:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da0003bdd0:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data
0003bea0:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla0003bde0:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps
0003beb0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target0003bdf0:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
0003bec0:·3d22·2369·646d·3834·3832·2220·7461·6269··="#idm8482"·tabi0003be00:·2369·646d·3834·3832·2220·7461·6269·6e64··#idm8482"·tabind
0003bed0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b0003be10:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
0003bee0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa0003be20:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
0003bef0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit0003be30:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
0003bf00:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·0003be40:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
0003bf10:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!0003be50:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
0003bf20:·223e·5265·6d65·6469·6174·696f·6e20·416e··">Remediation·An0003be60:·5265·6d65·6469·6174·696f·6e20·5075·7070··Remediation·Pupp
0003bf30:·6163·6f6e·6461·2073·6e69·7070·6574·20e2··aconda·snippet·.0003be70:·6574·2073·6e69·7070·6574·20e2·87b2·3c2f··et·snippet·...</
0003bf40:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c0003be80:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
0003bf50:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll0003be90:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
0003bf60:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i0003bea0:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
0003bf70:·643d·2269·646d·3834·3832·223e·3c74·6162··d="idm8482"><tab0003beb0:·646d·3834·3832·223e·3c74·6162·6c65·2063··dm8482"><table·c
0003bf80:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·0003bec0:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl
0003bf90:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta0003bed0:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-
0003bfa0:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab0003bee0:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c
0003bfb0:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t0003bef0:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t
0003bfc0:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity0003bf00:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t
0003bfd0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t0003bf10:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
0003bfe0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D0003bf20:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru
0003bff0:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><0003bf30:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l
 0003bf40:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
 0003bf50:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th>
 0003bf60:·3c74·643e·6661·6c73·653c·2f74·643e·3c2f··<td>false</td></
 0003bf70:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat
 0003bf80:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena
0003c000:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
0003c010:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:< 
0003c020:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t 
0003c030:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S 
0003c040:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td 
0003c050:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr 
0003c060:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c 
0003c070:·6f64·653e·0a70·6163·6b61·6765·202d·2d61··ode>.package·--a 
0003c080:·6464·3d61·6964·650a·3c2f·636f·6465·3e3c··dd=aide.</code>< 
0003c090:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl 
0003c0a0:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc 
0003c0b0:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl 
0003c0c0:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat 
0003c0d0:·612d·7461·7267·6574·3d22·2369·646d·3834··a-target="#idm84 
0003c0e0:·3833·2220·7461·6269·6e64·6578·3d22·3022··83"·tabindex="0" 
0003c0f0:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a 
0003c100:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa 
0003c110:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti 
0003c120:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"· 
0003c130:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi 
0003c140:·6174·696f·6e20·4f53·4275·696c·6420·426c··ation·OSBuild·Bl 
0003c150:·7565·7072·696e·7420·736e·6970·7065·7420··ueprint·snippet· 
0003c160:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div· 
0003c170:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col 
0003c180:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"· 
0003c190:·6964·3d22·6964·6d38·3438·3322·3e3c·7072··id="idm8483"><pr 
0003c1a0:·653e·3c63·6f64·653e·0a5b·5b70·6163·6b61··e><code>.[[packa 
0003c1b0:·6765·735d·5d0a·6e61·6d65·203d·2022·6169··ges]].name·=·"ai 
0003c1c0:·6465·220a·7665·7273·696f·6e20·3d20·222a··de".version·=·"* 
0003c1d0:·220a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··".</code></pre>< 
0003c1e0:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b 
0003c1f0:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"· 
0003c200:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col 
0003c210:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ 
0003c220:·6574·3d22·2369·646d·3834·3834·2220·7461··et="#idm8484"·ta 
0003c230:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role= 
0003c240:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex 
0003c250:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t 
0003c260:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t 
0003c270:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href=" 
0003c280:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation· 
0003c290:·7363·7269·7074·20e2·87b2·3c2f·613e·3c62··script·...</a><b 
0003c2a0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa 
0003c2b0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col 
0003c2c0:·6c61·7073·6522·2069·643d·2269·646d·3834··lapse"·id="idm84 
0003c2d0:·3834·223e·3c74·6162·6c65·2063·6c61·7373··84"><table·class 
0003c2e0:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st 
0003c2f0:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord 
0003c300:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde 
0003c310:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co 
0003c320:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t 
0003c330:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr>< 
0003c340:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio 
0003c350:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</ 
0003c360:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
0003c370:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td> 
0003c380:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr><0003bf90:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t
0003c390:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy: 
0003c3a0:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable< 
0003c3b0:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table 
Max diff block lines reached; 1725710/1752924 bytes (98.45%) of diff not shown.
196 KB
html2text {}
    
Offset 164, 52 lines modifiedOffset 164, 38 lines modified
164 ··-·PCI-DSSv4-11.5.2164 ··-·PCI-DSSv4-11.5.2
165 ··-·enable_strategy165 ··-·enable_strategy
166 ··-·low_complexity166 ··-·low_complexity
167 ··-·low_disruption167 ··-·low_disruption
168 ··-·medium_severity168 ··-·medium_severity
169 ··-·no_reboot_needed169 ··-·no_reboot_needed
170 ··-·package_aide_installed170 ··-·package_aide_installed
171 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
172 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
173 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
174 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
175 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
176 dnf·install·aide 
177 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
178 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
179 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
180 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
181 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
182 package·--add=aide 
183 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8171 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
184 [[packages]]172 [[packages]]
185 name·=·"aide"173 name·=·"aide"
186 version·=·"*"174 version·=·"*"
187 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
188 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
189 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
190 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
191 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
192 package·install·aide 
193 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8175 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
194 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low176 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
195 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low177 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
196 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false178 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
197 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable179 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
198 include·install_aide180 include·install_aide
  
199 class·install_aide·{181 class·install_aide·{
200 ··package·{·'aide':182 ··package·{·'aide':
201 ····ensure·=>·'installed',183 ····ensure·=>·'installed',
202 ··}184 ··}
203 }185 }
 186 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 187 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 188 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 189 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 190 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 191 package·install·aide
204 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8192 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
205 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low193 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
206 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low194 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
207 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false195 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
208 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable196 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
209 #·Remediation·is·applicable·only·in·certain·platforms197 #·Remediation·is·applicable·only·in·certain·platforms
210 if·rpm·--quiet·-q·kernel;·then198 if·rpm·--quiet·-q·kernel;·then
Offset 217, 14 lines modifiedOffset 203, 28 lines modified
217 if·!·rpm·-q·--quiet·"aide"·;·then203 if·!·rpm·-q·--quiet·"aide"·;·then
218 ····dnf·install·-y·"aide"204 ····dnf·install·-y·"aide"
219 fi205 fi
  
220 else206 else
221 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'207 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
222 fi208 fi
 209 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 210 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 211 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 212 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 213 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 214 package·--add=aide
 215 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 216 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 217 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 218 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 219 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 220 dnf·install·aide
223 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*221 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
224 Run·the·following·command·to·generate·a·new·database:222 Run·the·following·command·to·generate·a·new·database:
225 $·sudo·/usr/sbin/aide·--init223 $·sudo·/usr/sbin/aide·--init
226 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:224 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
227 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz225 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
228 To·initiate·a·manual·check,·run·the·following·command:226 To·initiate·a·manual·check,·run·the·following·command:
229 $·sudo·/usr/sbin/aide·--check227 $·sudo·/usr/sbin/aide·--check
Offset 2129, 61 lines modifiedOffset 2129, 61 lines modified
2129 ··-·DISA-STIG-RHEL-09-2151002129 ··-·DISA-STIG-RHEL-09-215100
2130 ··-·enable_strategy2130 ··-·enable_strategy
2131 ··-·low_complexity2131 ··-·low_complexity
2132 ··-·low_disruption2132 ··-·low_disruption
2133 ··-·medium_severity2133 ··-·medium_severity
2134 ··-·no_reboot_needed2134 ··-·no_reboot_needed
2135 ··-·package_crypto-policies_installed2135 ··-·package_crypto-policies_installed
2136 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
2137 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
2138 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
2139 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
2140 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
2141 dnf·install·crypto-policies 
2142 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
2143 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
2144 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
2145 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
2146 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
2147 package·--add=crypto-policies 
2148 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x82136 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
2149 [[packages]]2137 [[packages]]
2150 name·=·"crypto-policies"2138 name·=·"crypto-policies"
2151 version·=·"*"2139 version·=·"*"
2152 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
2153 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
2154 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
2155 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
2156 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
2157 package·install·crypto-policies 
2158 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x82140 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
2159 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low2141 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
2160 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low2142 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
2161 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false2143 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
2162 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable2144 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
Max diff block lines reached; 196400/201170 bytes (97.63%) of diff not shown.
1.83 MB
./usr/share/doc/ssg-nondebian/ssg-cs9-guide-stig_gui.html
    
Offset 15326, 208 lines modifiedOffset 15326, 208 lines modified
0003bdd0:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#0003bdd0:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
0003bde0:·6964·6d38·3438·3122·2074·6162·696e·6465··idm8481"·tabinde0003bde0:·6964·6d38·3438·3122·2074·6162·696e·6465··idm8481"·tabinde
0003bdf0:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt0003bdf0:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt
0003be00:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande0003be00:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande
0003be10:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=0003be10:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=
0003be20:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev0003be20:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev
0003be30:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R0003be30:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R
0003be40:·656d·6564·6961·7469·6f6e·2073·6372·6970··emediation·scrip0003be40:·656d·6564·6961·7469·6f6e·204f·5342·7569··emediation·OSBui
 0003be50:·6c64·2042·6c75·6570·7269·6e74·2073·6e69··ld·Blueprint·sni
 0003be60:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>
 0003be70:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
 0003be80:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
 0003be90:·7073·6522·2069·643d·2269·646d·3834·3831··pse"·id="idm8481
 0003bea0:·223e·3c70·7265·3e3c·636f·6465·3e0a·5b5b··"><pre><code>.[[
 0003beb0:·7061·636b·6167·6573·5d5d·0a6e·616d·6520··packages]].name·
 0003bec0:·3d20·2261·6964·6522·0a76·6572·7369·6f6e··=·"aide".version
 0003bed0:·203d·2022·2a22·0a3c·2f63·6f64·653e·3c2f···=·"*".</code></
0003be50:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di 
0003be60:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c 
0003be70:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse 
0003be80:·2220·6964·3d22·6964·6d38·3438·3122·3e3c··"·id="idm8481">< 
0003be90:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab 
0003bea0:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped 
0003beb0:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered· 
0003bec0:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed" 
0003bed0:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex 
0003bee0:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low 
0003bef0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
0003bf00:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t 
0003bf10:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></ 
0003bf20:·7472·3e3c·7472·3e3c·7468·3e52·6562·6f6f··tr><tr><th>Reboo 
0003bf30:·743a·3c2f·7468·3e3c·7464·3e66·616c·7365··t:</th><td>false 
0003bf40:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
0003bf50:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th> 
0003bf60:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td>< 
0003bf70:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre 
0003bf80:·3e3c·636f·6465·3e0a·646e·6620·696e·7374··><code>.dnf·inst 
0003bf90:·616c·6c20·6169·6465·0a3c·2f63·6f64·653e··all·aide.</code> 
0003bfa0:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c0003bee0:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla
0003bfb0:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su0003bef0:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ
0003bfc0:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg0003bf00:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle
0003bfd0:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da0003bf10:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data
0003bfe0:·7461·2d74·6172·6765·743d·2223·6964·6d38··ta-target="#idm80003bf20:·2d74·6172·6765·743d·2223·6964·6d38·3438··-target="#idm848
0003bff0:·3438·3222·2074·6162·696e·6465·783d·2230··482"·tabindex="00003bf30:·3222·2074·6162·696e·6465·783d·2230·2220··2"·tabindex="0"·
0003c000:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·0003bf40:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar
0003c010:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f0003bf50:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal
0003c020:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act0003bf60:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ
0003c030:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"0003bf70:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h
0003c040:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed0003bf80:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia
 0003bf90:·7469·6f6e·2050·7570·7065·7420·736e·6970··tion·Puppet·snip
0003c050:·6961·7469·6f6e·2041·6e61·636f·6e64·6120··iation·Anaconda· 
0003c060:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a>< 
0003c070:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p 
0003c080:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co 
0003c090:·6c6c·6170·7365·2220·6964·3d22·6964·6d38··llapse"·id="idm8 
0003c0a0:·3438·3222·3e3c·7461·626c·6520·636c·6173··482"><table·clas 
0003c0b0:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s 
0003c0c0:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor 
0003c0d0:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond 
0003c0e0:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C 
0003c0f0:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th>< 
0003c100:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
0003c110:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti 
0003c120:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low< 
0003c130:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0003c140:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td 
0003c150:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr> 
0003c160:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy 
0003c170:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable 
0003c180:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl 
0003c190:·653e·3c70·7265·3e3c·636f·6465·3e0a·7061··e><pre><code>.pa 
0003c1a0:·636b·6167·6520·2d2d·6164·643d·6169·6465··ckage·--add=aide 
0003c1b0:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></ 
0003c1c0:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt 
0003c1d0:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d 
0003c1e0:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll 
0003c1f0:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe 
0003c200:·743d·2223·6964·6d38·3438·3322·2074·6162··t="#idm8483"·tab 
0003c210:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role=" 
0003c220:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp 
0003c230:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti 
0003c240:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to 
0003c250:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="# 
0003c260:·2122·3e52·656d·6564·6961·7469·6f6e·204f··!">Remediation·O 
0003c270:·5342·7569·6c64·2042·6c75·6570·7269·6e74··SBuild·Blueprint 
0003c280:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a> 
0003c290:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class=" 
0003c2a0:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c 
0003c2b0:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm 
0003c2c0:·3834·3833·223e·3c70·7265·3e3c·636f·6465··8483"><pre><code 
0003c2d0:·3e0a·5b5b·7061·636b·6167·6573·5d5d·0a6e··>.[[packages]].n 
0003c2e0:·616d·6520·3d20·2261·6964·6522·0a76·6572··ame·=·"aide".ver 
0003c2f0:·7369·6f6e·203d·2022·2a22·0a3c·2f63·6f64··sion·=·"*".</cod 
0003c300:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a 
0003c310:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn- 
0003c320:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to 
0003c330:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"· 
0003c340:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id 
0003c350:·6d38·3438·3422·2074·6162·696e·6465·783d··m8484"·tabindex= 
0003c360:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button 
0003c370:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded= 
0003c380:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A 
0003c390:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea 
0003c3a0:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem 
0003c3b0:·6564·6961·7469·6f6e·2073·6372·6970·7420··ediation·script· 
0003c3c0:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·0003bfa0:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br><
0003c3d0:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col0003bfb0:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
0003c3e0:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·0003bfc0:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap
0003c3f0:·6964·3d22·6964·6d38·3438·3422·3e3c·7461··id="idm8484"><ta 
0003c400:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table 
0003c410:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t0003bfd0:·7365·2220·6964·3d22·6964·6d38·3438·3222··se"·id="idm8482"
 0003bfe0:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t
 0003bff0:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip
0003c420:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta0003c000:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere
0003c430:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><0003c010:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense
0003c440:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit0003c020:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl
0003c450:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</ 
0003c460:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
0003c470:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th> 
0003c480:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
0003c490:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot: 
0003c4a0:·3c2f·7468·3e3c·7464·3e66·616c·7365·3c2f··</th><td>false</ 
0003c4b0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
0003c4c0:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t 
0003c4d0:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t 
0003c4e0:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre>< 
0003c4f0:·636f·6465·3e0a·7061·636b·6167·6520·696e··code>.package·in 
Max diff block lines reached; 1692325/1719677 bytes (98.41%) of diff not shown.
191 KB
html2text {}
    
Offset 169, 52 lines modifiedOffset 169, 38 lines modified
169 ··-·PCI-DSSv4-11.5.2169 ··-·PCI-DSSv4-11.5.2
170 ··-·enable_strategy170 ··-·enable_strategy
171 ··-·low_complexity171 ··-·low_complexity
172 ··-·low_disruption172 ··-·low_disruption
173 ··-·medium_severity173 ··-·medium_severity
174 ··-·no_reboot_needed174 ··-·no_reboot_needed
175 ··-·package_aide_installed175 ··-·package_aide_installed
176 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
177 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
178 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
179 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
180 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
181 dnf·install·aide 
182 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
183 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
184 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
185 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
186 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
187 package·--add=aide 
188 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8176 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
189 [[packages]]177 [[packages]]
190 name·=·"aide"178 name·=·"aide"
191 version·=·"*"179 version·=·"*"
192 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
193 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
194 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
195 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
196 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
197 package·install·aide 
198 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8180 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
199 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low181 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
200 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low182 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
201 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false183 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
202 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable184 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
203 include·install_aide185 include·install_aide
  
204 class·install_aide·{186 class·install_aide·{
205 ··package·{·'aide':187 ··package·{·'aide':
206 ····ensure·=>·'installed',188 ····ensure·=>·'installed',
207 ··}189 ··}
208 }190 }
 191 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 192 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 193 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 194 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 195 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 196 package·install·aide
209 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8197 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
210 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low198 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
211 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low199 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
212 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false200 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
213 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable201 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
214 #·Remediation·is·applicable·only·in·certain·platforms202 #·Remediation·is·applicable·only·in·certain·platforms
215 if·rpm·--quiet·-q·kernel;·then203 if·rpm·--quiet·-q·kernel;·then
Offset 222, 14 lines modifiedOffset 208, 28 lines modified
222 if·!·rpm·-q·--quiet·"aide"·;·then208 if·!·rpm·-q·--quiet·"aide"·;·then
223 ····dnf·install·-y·"aide"209 ····dnf·install·-y·"aide"
224 fi210 fi
  
225 else211 else
226 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'212 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
227 fi213 fi
 214 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 215 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 216 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 217 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 218 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 219 package·--add=aide
 220 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 221 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 222 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 223 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 224 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 225 dnf·install·aide
228 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*226 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
229 Run·the·following·command·to·generate·a·new·database:227 Run·the·following·command·to·generate·a·new·database:
230 $·sudo·/usr/sbin/aide·--init228 $·sudo·/usr/sbin/aide·--init
231 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:229 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
232 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz230 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
233 To·initiate·a·manual·check,·run·the·following·command:231 To·initiate·a·manual·check,·run·the·following·command:
234 $·sudo·/usr/sbin/aide·--check232 $·sudo·/usr/sbin/aide·--check
Offset 2134, 61 lines modifiedOffset 2134, 61 lines modified
2134 ··-·DISA-STIG-RHEL-09-2151002134 ··-·DISA-STIG-RHEL-09-215100
2135 ··-·enable_strategy2135 ··-·enable_strategy
2136 ··-·low_complexity2136 ··-·low_complexity
2137 ··-·low_disruption2137 ··-·low_disruption
2138 ··-·medium_severity2138 ··-·medium_severity
2139 ··-·no_reboot_needed2139 ··-·no_reboot_needed
2140 ··-·package_crypto-policies_installed2140 ··-·package_crypto-policies_installed
2141 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
2142 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
2143 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
2144 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
2145 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
2146 dnf·install·crypto-policies 
2147 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
2148 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
2149 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
2150 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
2151 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
2152 package·--add=crypto-policies 
2153 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x82141 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
2154 [[packages]]2142 [[packages]]
2155 name·=·"crypto-policies"2143 name·=·"crypto-policies"
2156 version·=·"*"2144 version·=·"*"
2157 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
2158 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
2159 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
2160 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
2161 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
2162 package·install·crypto-policies 
2163 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x82145 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
2164 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low2146 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
2165 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low2147 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
2166 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false2148 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
2167 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable2149 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
Max diff block lines reached; 190719/195489 bytes (97.56%) of diff not shown.
996 KB
./usr/share/doc/ssg-nondebian/ssg-fedora-guide-cusp_fedora.html
    
Offset 18669, 207 lines modifiedOffset 18669, 207 lines modified
00048ec0:·612d·7461·7267·6574·3d22·2369·646d·3530··a-target="#idm5000048ec0:·612d·7461·7267·6574·3d22·2369·646d·3530··a-target="#idm50
00048ed0:·3934·2220·7461·6269·6e64·6578·3d22·3022··94"·tabindex="0"00048ed0:·3934·2220·7461·6269·6e64·6578·3d22·3022··94"·tabindex="0"
00048ee0:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a00048ee0:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
00048ef0:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa00048ef0:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
00048f00:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti00048f00:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
00048f10:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·00048f10:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
00048f20:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi00048f20:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
 00048f30:·6174·696f·6e20·4f53·4275·696c·6420·426c··ation·OSBuild·Bl
 00048f40:·7565·7072·696e·7420·736e·6970·7065·7420··ueprint·snippet·
 00048f50:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·
 00048f60:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col
 00048f70:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·
 00048f80:·6964·3d22·6964·6d35·3039·3422·3e3c·7072··id="idm5094"><pr
 00048f90:·653e·3c63·6f64·653e·0a5b·5b70·6163·6b61··e><code>.[[packa
 00048fa0:·6765·735d·5d0a·6e61·6d65·203d·2022·7375··ges]].name·=·"su
 00048fb0:·646f·220a·7665·7273·696f·6e20·3d20·222a··do".version·=·"*
00048f30:·6174·696f·6e20·7363·7269·7074·20e2·87b2··ation·script·... 
00048f40:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla 
00048f50:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap 
00048f60:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id= 
00048f70:·2269·646d·3530·3934·223e·3c74·6162·6c65··"idm5094"><table 
00048f80:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta 
00048f90:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl 
00048fa0:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table 
00048fb0:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr> 
00048fc0:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:< 
00048fd0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td> 
00048fe0:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis 
00048ff0:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td 
00049000:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t 
00049010:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t 
00049020:·683e·3c74·643e·6661·6c73·653c·2f74·643e··h><td>false</td> 
00049030:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str 
00049040:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e 
00049050:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr>< 
00049060:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod 
00049070:·653e·0a64·6e66·2069·6e73·7461·6c6c·2073··e>.dnf·install·s 
00049080:·7564·6f0a·3c2f·636f·6465·3e3c·2f70·7265··udo.</code></pre00048fc0:·220a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··".</code></pre><
00049090:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class=00048fd0:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b
000490a0:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success00048fe0:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"·
000490b0:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c00048ff0:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col
000490c0:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta00049000:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ
000490d0:·7267·6574·3d22·2369·646d·3530·3935·2220··rget="#idm5095"·00049010:·6574·3d22·2369·646d·3530·3935·2220·7461··et="#idm5095"·ta
000490e0:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol00049020:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
000490f0:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-00049030:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
00049100:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"00049040:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
00049110:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate00049050:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
00049120:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href00049060:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
00049130:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio00049070:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
00049140:·6e20·416e·6163·6f6e·6461·2073·6e69·7070··n·Anaconda·snipp00049080:·5075·7070·6574·2073·6e69·7070·6574·20e2··Puppet·snippet·.
00049150:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d00049090:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c
00049160:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-000490a0:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
00049170:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps000490b0:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
00049180:·6522·2069·643d·2269·646d·3530·3935·223e··e"·id="idm5095">000490c0:·643d·2269·646d·3530·3935·223e·3c74·6162··d="idm5095"><tab
00049190:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta000490d0:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·
000491a0:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe000490e0:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta
000491b0:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered000490f0:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab
000491c0:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed00049100:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t
000491d0:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple00049110:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity
000491e0:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo00049120:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
000491f0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><00049130:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D
00049200:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</00049140:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><
00049210:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><00049150:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
00049220:·2f74·723e·3c74·723e·3c74·683e·5265·626f··/tr><tr><th>Rebo00049160:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:<
00049230:·6f74·3a3c·2f74·683e·3c74·643e·6661·6c73··ot:</th><td>fals00049170:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t
00049240:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr><00049180:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S
00049250:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th00049190:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td
00049260:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td>000491a0:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr
00049270:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr000491b0:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c
 000491c0:·6f64·653e·696e·636c·7564·6520·696e·7374··ode>include·inst
 000491d0:·616c·6c5f·7375·646f·0a0a·636c·6173·7320··all_sudo..class·
 000491e0:·696e·7374·616c·6c5f·7375·646f·207b·0a20··install_sudo·{.·
 000491f0:·2070·6163·6b61·6765·207b·2027·7375·646f···package·{·'sudo
 00049200:·273a·0a20·2020·2065·6e73·7572·6520·3d26··':.····ensure·=&
 00049210:·6774·3b20·2769·6e73·7461·6c6c·6564·272c··gt;·'installed',
 00049220:·0a20·207d·0a7d·0a3c·2f63·6f64·653e·3c2f··.··}.}.</code></
 00049230:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla
 00049240:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ
00049280:·653e·3c63·6f64·653e·0a70·6163·6b61·6765··e><code>.package 
00049290:·202d·2d61·6464·3d73·7564·6f0a·3c2f·636f···--add=sudo.</co 
000492a0:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div>< 
000492b0:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn 
000492c0:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t 
000492d0:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse" 
000492e0:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i 
000492f0:·646d·3530·3936·2220·7461·6269·6e64·6578··dm5096"·tabindex 
00049300:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto 
00049310:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded 
00049320:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title=" 
00049330:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve 
00049340:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re 
00049350:·6d65·6469·6174·696f·6e20·4f53·4275·696c··mediation·OSBuil 
00049360:·6420·426c·7565·7072·696e·7420·736e·6970··d·Blueprint·snip 
00049370:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br>< 
00049380:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel 
00049390:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap 
000493a0:·7365·2220·6964·3d22·6964·6d35·3039·3622··se"·id="idm5096" 
000493b0:·3e3c·7072·653e·3c63·6f64·653e·0a5b·5b70··><pre><code>.[[p 
000493c0:·6163·6b61·6765·735d·5d0a·6e61·6d65·203d··ackages]].name·= 
000493d0:·2022·7375·646f·220a·7665·7273·696f·6e20···"sudo".version· 
000493e0:·3d20·222a·220a·3c2f·636f·6465·3e3c·2f70··=·"*".</code></p 
000493f0:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas 
00049400:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe 
00049410:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle= 
00049420:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data- 
00049430:·7461·7267·6574·3d22·2369·646d·3530·3937··target="#idm5097 
00049440:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r 
00049450:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari 
00049460:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals 
00049470:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa 
00049480:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr 
00049490:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat 
000494a0:·696f·6e20·7363·7269·7074·20e2·87b2·3c2f··ion·script·...</ 
000494b0:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class 
000494c0:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse 
000494d0:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i 
000494e0:·646d·3530·3937·223e·3c74·6162·6c65·2063··dm5097"><table·c 
000494f0:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl 
00049500:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table- 
00049510:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c 
00049520:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t 
00049530:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t 
00049540:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></ 
00049550:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru 
00049560:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l 
00049570:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr> 
00049580:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th> 
Max diff block lines reached; 874578/901792 bytes (96.98%) of diff not shown.
115 KB
html2text {}
    
Offset 891, 52 lines modifiedOffset 891, 38 lines modified
891 ··-·PCI-DSSv4-2.2.6891 ··-·PCI-DSSv4-2.2.6
892 ··-·enable_strategy892 ··-·enable_strategy
893 ··-·low_complexity893 ··-·low_complexity
894 ··-·low_disruption894 ··-·low_disruption
895 ··-·medium_severity895 ··-·medium_severity
896 ··-·no_reboot_needed896 ··-·no_reboot_needed
897 ··-·package_sudo_installed897 ··-·package_sudo_installed
898 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
899 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
900 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
901 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
902 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
903 dnf·install·sudo 
904 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
905 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
906 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
907 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
908 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
909 package·--add=sudo 
910 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8898 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
911 [[packages]]899 [[packages]]
912 name·=·"sudo"900 name·=·"sudo"
913 version·=·"*"901 version·=·"*"
914 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
915 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
916 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
917 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
918 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
919 package·install·sudo 
920 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8902 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
921 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low903 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
922 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low904 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
923 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false905 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
924 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable906 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
925 include·install_sudo907 include·install_sudo
  
926 class·install_sudo·{908 class·install_sudo·{
927 ··package·{·'sudo':909 ··package·{·'sudo':
928 ····ensure·=>·'installed',910 ····ensure·=>·'installed',
929 ··}911 ··}
930 }912 }
 913 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 914 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 915 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 916 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 917 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 918 package·install·sudo
931 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8919 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
932 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low920 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
933 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low921 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
934 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false922 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
935 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable923 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
936 #·Remediation·is·applicable·only·in·certain·platforms924 #·Remediation·is·applicable·only·in·certain·platforms
937 if·rpm·--quiet·-q·kernel;·then925 if·rpm·--quiet·-q·kernel;·then
Offset 944, 14 lines modifiedOffset 930, 28 lines modified
944 if·!·rpm·-q·--quiet·"sudo"·;·then930 if·!·rpm·-q·--quiet·"sudo"·;·then
945 ····dnf·install·-y·"sudo"931 ····dnf·install·-y·"sudo"
946 fi932 fi
  
947 else933 else
948 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'934 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
949 fi935 fi
 936 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 937 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 938 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 939 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 940 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 941 package·--add=sudo
 942 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 943 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 944 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 945 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 946 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 947 dnf·install·sudo
950 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·O\x8On\x8nl\x8ly\x8y·U\x8Us\x8se\x8er\x8rs\x8s·L\x8Lo\x8og\x8gg\x8ge\x8ed\x8d·I\x8In\x8n·T\x8To\x8o·R\x8Re\x8ea\x8al\x8l·t\x8tt\x8ty\x8y·C\x8Ca\x8an\x8n·E\x8Ex\x8xe\x8ec\x8cu\x8ut\x8te\x8e·S\x8Su\x8ud\x8do\x8o·-\x8-·s\x8su\x8ud\x8do\x8o·u\x8us\x8se\x8e_\x8_p\x8pt\x8ty\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*948 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·O\x8On\x8nl\x8ly\x8y·U\x8Us\x8se\x8er\x8rs\x8s·L\x8Lo\x8og\x8gg\x8ge\x8ed\x8d·I\x8In\x8n·T\x8To\x8o·R\x8Re\x8ea\x8al\x8l·t\x8tt\x8ty\x8y·C\x8Ca\x8an\x8n·E\x8Ex\x8xe\x8ec\x8cu\x8ut\x8te\x8e·S\x8Su\x8ud\x8do\x8o·-\x8-·s\x8su\x8ud\x8do\x8o·u\x8us\x8se\x8e_\x8_p\x8pt\x8ty\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
951 The·sudo·use_pty·tag,·when·specified,·will·only·execute·sudo·commands·from·users·logged·in·to·a·real·tty.·This·should·be·enabled·by·making·sure·that·the·use_pty·tag·exists·in·/etc/sudoers·configuration·file·or·any·sudo·configuration·snippets·in·/etc/sudoers.d/.949 The·sudo·use_pty·tag,·when·specified,·will·only·execute·sudo·commands·from·users·logged·in·to·a·real·tty.·This·should·be·enabled·by·making·sure·that·the·use_pty·tag·exists·in·/etc/sudoers·configuration·file·or·any·sudo·configuration·snippets·in·/etc/sudoers.d/.
952 Rationale:··Requiring·that·sudo·commands·be·run·in·a·pseudo-terminal·can·prevent·an·attacker·from·retaining·access·to·the·user's·terminal·after·the·main·program·has·finished·executing.950 Rationale:··Requiring·that·sudo·commands·be·run·in·a·pseudo-terminal·can·prevent·an·attacker·from·retaining·access·to·the·user's·terminal·after·the·main·program·has·finished·executing.
953 Severity: ··medium951 Severity: ··medium
954 Rule·ID:····xccdf_org.ssgproject.content_rule_sudo_add_use_pty952 Rule·ID:····xccdf_org.ssgproject.content_rule_sudo_add_use_pty
955 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s··Req-10.2.5953 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s··Req-10.2.5
956 References:·_\x8a_\x8n_\x8s_\x8s_\x8i···R39954 References:·_\x8a_\x8n_\x8s_\x8s_\x8i···R39
Offset 1601, 61 lines modifiedOffset 1601, 61 lines modified
1601 ··tags:1601 ··tags:
1602 ··-·enable_strategy1602 ··-·enable_strategy
1603 ··-·low_complexity1603 ··-·low_complexity
1604 ··-·low_disruption1604 ··-·low_disruption
1605 ··-·medium_severity1605 ··-·medium_severity
1606 ··-·no_reboot_needed1606 ··-·no_reboot_needed
1607 ··-·package_gnome_software_installed1607 ··-·package_gnome_software_installed
1608 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
1609 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
1610 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
1611 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
1612 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
1613 dnf·install·gnome-software 
1614 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
1615 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
1616 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
1617 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
1618 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
1619 package·--add=gnome-software 
1620 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81608 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
1621 [[packages]]1609 [[packages]]
1622 name·=·"gnome-software"1610 name·=·"gnome-software"
1623 version·=·"*"1611 version·=·"*"
1624 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
1625 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
1626 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
1627 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
1628 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
1629 package·install·gnome-software 
1630 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81612 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1631 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1613 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1632 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1614 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1633 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1615 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1634 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1616 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
Max diff block lines reached; 112795/117659 bytes (95.87%) of diff not shown.
241 KB
./usr/share/doc/ssg-nondebian/ssg-fedora-guide-ospp.html
    
Offset 25200, 215 lines modifiedOffset 25200, 215 lines modified
000626f0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target000626f0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
00062700:·3d22·2369·646d·3536·3437·2220·7461·6269··="#idm5647"·tabi00062700:·3d22·2369·646d·3536·3437·2220·7461·6269··="#idm5647"·tabi
00062710:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b00062710:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
00062720:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa00062720:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
00062730:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit00062730:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
00062740:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·00062740:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
00062750:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!00062750:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
00062760:·223e·5265·6d65·6469·6174·696f·6e20·7363··">Remediation·sc00062760:·223e·5265·6d65·6469·6174·696f·6e20·4f53··">Remediation·OS
00062770:·7269·7074·20e2·87b2·3c2f·613e·3c62·723e··ript·...</a><br> 
00062780:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane 
00062790:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla 
000627a0:·7073·6522·2069·643d·2269·646d·3536·3437··pse"·id="idm5647 
000627b0:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class=" 
000627c0:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri 
000627d0:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border 
000627e0:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens 
000627f0:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp00062770:·4275·696c·6420·426c·7565·7072·696e·7420··Build·Blueprint·
 00062780:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><
 00062790:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
 000627a0:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
 000627b0:·6c6c·6170·7365·2220·6964·3d22·6964·6d35··llapse"·id="idm5
 000627c0:·3634·3722·3e3c·7072·653e·3c63·6f64·653e··647"><pre><code>
 000627d0:·0a5b·5b70·6163·6b61·6765·735d·5d0a·6e61··.[[packages]].na
 000627e0:·6d65·203d·2022·726e·672d·746f·6f6c·7322··me·=·"rng-tools"
 000627f0:·0a76·6572·7369·6f6e·203d·2022·2a22·0a3c··.version·=·"*".<
 00062800:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di
 00062810:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn·
 00062820:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat
 00062830:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap
 00062840:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
 00062850:·2223·6964·6d35·3634·3822·2074·6162·696e··"#idm5648"·tabin
 00062860:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
 00062870:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
 00062880:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
 00062890:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
 000628a0:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
 000628b0:·3e52·656d·6564·6961·7469·6f6e·2050·7570··>Remediation·Pup
 000628c0:·7065·7420·736e·6970·7065·7420·e287·b23c··pet·snippet·...<
 000628d0:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas
 000628e0:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps
 000628f0:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="
 00062900:·6964·6d35·3634·3822·3e3c·7461·626c·6520··idm5648"><table·
 00062910:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab
 00062920:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table
 00062930:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-
 00062940:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><
 00062950:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</
 00062960:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
 00062970:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr
00062800:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>00062980:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>
00062810:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr00062990:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
00062820:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption: 
00062830:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td000629a0:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th
 000629b0:·3e3c·7464·3e66·616c·7365·3c2f·7464·3e3c··><td>false</td><
00062840:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re000629c0:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra
00062850:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa000629d0:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en
00062860:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr 
00062870:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</ 
00062880:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t 
00062890:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table>< 
000628a0:·7072·653e·3c63·6f64·653e·0a64·6e66·2069··pre><code>.dnf·i 
000628b0:·6e73·7461·6c6c·2072·6e67·2d74·6f6f·6c73··nstall·rng-tools000629e0:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></
 000629f0:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code
 00062a00:·3e69·6e63·6c75·6465·2069·6e73·7461·6c6c··>include·install
 00062a10:·5f72·6e67·2d74·6f6f·6c73·0a0a·636c·6173··_rng-tools..clas
 00062a20:·7320·696e·7374·616c·6c5f·726e·672d·746f··s·install_rng-to
 00062a30:·6f6c·7320·7b0a·2020·7061·636b·6167·6520··ols·{.··package·
 00062a40:·7b20·2772·6e67·2d74·6f6f·6c73·273a·0a20··{·'rng-tools':.·
 00062a50:·2020·2065·6e73·7572·6520·3d26·6774·3b20·····ensure·=&gt;·
 00062a60:·2769·6e73·7461·6c6c·6564·272c·0a20·207d··'installed',.··}
000628c0:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></00062a70:·0a7d·0a3c·2f63·6f64·653e·3c2f·7072·653e··.}.</code></pre>
000628d0:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt00062a80:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class="
000628e0:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d00062a90:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success"
000628f0:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll00062aa0:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co
00062900:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe00062ab0:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar
00062910:·743d·2223·6964·6d35·3634·3822·2074·6162··t="#idm5648"·tab00062ac0:·6765·743d·2223·6964·6d35·3634·3922·2074··get="#idm5649"·t
00062920:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="00062ad0:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
00062930:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp00062ae0:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
00062940:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti00062af0:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
00062950:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to00062b00:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
00062960:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#00062b10:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
00062970:·2122·3e52·656d·6564·6961·7469·6f6e·2041··!">Remediation·A00062b20:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
00062980:·6e61·636f·6e64·6120·736e·6970·7065·7420··naconda·snippet· 
00062990:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div· 
000629a0:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col 
000629b0:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"· 
000629c0:·6964·3d22·6964·6d35·3634·3822·3e3c·7461··id="idm5648"><ta 
000629d0:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table 
000629e0:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t 
000629f0:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta 
00062a00:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed">< 
00062a10:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit 
00062a20:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</ 
00062a30:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
00062a40:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th> 
00062a50:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
00062a60:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot: 
00062a70:·3c2f·7468·3e3c·7464·3e66·616c·7365·3c2f··</th><td>false</ 
00062a80:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
00062a90:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t 
00062aa0:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t 
00062ab0:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre>< 
00062ac0:·636f·6465·3e0a·7061·636b·6167·6520·2d2d··code>.package·-- 
00062ad0:·6164·643d·726e·672d·746f·6f6c·730a·3c2f··add=rng-tools.</ 
00062ae0:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div 
00062af0:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b 
00062b00:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data 
00062b10:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps 
00062b20:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target=" 
00062b30:·2369·646d·3536·3439·2220·7461·6269·6e64··#idm5649"·tabind 
00062b40:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but 
00062b50:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand 
00062b60:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title 
00062b70:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re 
00062b80:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!"> 
00062b90:·5265·6d65·6469·6174·696f·6e20·4f53·4275··Remediation·OSBu 
00062ba0:·696c·6420·426c·7565·7072·696e·7420·736e··ild·Blueprint·sn 
00062bb0:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br00062b30:·2073·6372·6970·7420·e287·b23c·2f61·3e3c···script·...</a><
00062bc0:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan00062b40:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
00062bd0:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll00062b50:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
00062be0:·6170·7365·2220·6964·3d22·6964·6d35·3634··apse"·id="idm56400062b60:·6c6c·6170·7365·2220·6964·3d22·6964·6d35··llapse"·id="idm5
 00062b70:·3634·3922·3e3c·7461·626c·6520·636c·6173··649"><table·clas
 00062b80:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s
 00062b90:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor
 00062ba0:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond
00062bf0:·3922·3e3c·7072·653e·3c63·6f64·653e·0a5b··9"><pre><code>.[ 
00062c00:·5b70·6163·6b61·6765·735d·5d0a·6e61·6d65··[packages]].name 
Max diff block lines reached; 188206/216524 bytes (86.92%) of diff not shown.
29.0 KB
html2text {}
    
Offset 2531, 52 lines modifiedOffset 2531, 38 lines modified
2531 ··tags:2531 ··tags:
2532 ··-·enable_strategy2532 ··-·enable_strategy
2533 ··-·low_complexity2533 ··-·low_complexity
2534 ··-·low_disruption2534 ··-·low_disruption
2535 ··-·low_severity2535 ··-·low_severity
2536 ··-·no_reboot_needed2536 ··-·no_reboot_needed
2537 ··-·package_rng-tools_installed2537 ··-·package_rng-tools_installed
2538 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
2539 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
2540 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
2541 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
2542 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
2543 dnf·install·rng-tools 
2544 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
2545 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
2546 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
2547 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
2548 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
2549 package·--add=rng-tools 
2550 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x82538 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
2551 [[packages]]2539 [[packages]]
2552 name·=·"rng-tools"2540 name·=·"rng-tools"
2553 version·=·"*"2541 version·=·"*"
2554 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
2555 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
2556 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
2557 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
2558 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
2559 package·install·rng-tools 
2560 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x82542 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
2561 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low2543 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
2562 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low2544 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
2563 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false2545 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
2564 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable2546 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
2565 include·install_rng-tools2547 include·install_rng-tools
  
2566 class·install_rng-tools·{2548 class·install_rng-tools·{
2567 ··package·{·'rng-tools':2549 ··package·{·'rng-tools':
2568 ····ensure·=>·'installed',2550 ····ensure·=>·'installed',
2569 ··}2551 ··}
2570 }2552 }
 2553 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 2554 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 2555 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 2556 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 2557 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 2558 package·install·rng-tools
2571 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x82559 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
2572 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low2560 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
2573 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low2561 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
2574 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false2562 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
2575 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable2563 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
2576 #·Remediation·is·applicable·only·in·certain·platforms2564 #·Remediation·is·applicable·only·in·certain·platforms
2577 if·(·!·(·[·"$(sysctl·-a·|·grep·-c·'fips_enabled.*1')"·-eq·1·]·)·&&·rpm·--quiet·-q·kernel·);·then2565 if·(·!·(·[·"$(sysctl·-a·|·grep·-c·'fips_enabled.*1')"·-eq·1·]·)·&&·rpm·--quiet·-q·kernel·);·then
Offset 2584, 14 lines modifiedOffset 2570, 28 lines modified
2584 if·!·rpm·-q·--quiet·"rng-tools"·;·then2570 if·!·rpm·-q·--quiet·"rng-tools"·;·then
2585 ····dnf·install·-y·"rng-tools"2571 ····dnf·install·-y·"rng-tools"
2586 fi2572 fi
  
2587 else2573 else
2588 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'2574 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
2589 fi2575 fi
 2576 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 2577 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 2578 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 2579 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 2580 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 2581 package·--add=rng-tools
 2582 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 2583 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 2584 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 2585 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 2586 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 2587 dnf·install·rng-tools
2590 Group  ·Updating·Software·  Group·contains·8·rules2588 Group  ·Updating·Software·  Group·contains·8·rules
2591 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·dnf·command·line·tool·is·used·to·install·and·update·software·packages.·The·system·also·provides·a·graphical·software·update·tool·in·the·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·menu,·in·the·A\x8Ad\x8dm\x8mi\x8in\x8ni\x8is\x8st\x8tr\x8ra\x8at\x8ti\x8io\x8on\x8n·submenu,·called·S\x8So\x8of\x8ft\x8tw\x8wa\x8ar\x8re\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8e.2589 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·dnf·command·line·tool·is·used·to·install·and·update·software·packages.·The·system·also·provides·a·graphical·software·update·tool·in·the·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·menu,·in·the·A\x8Ad\x8dm\x8mi\x8in\x8ni\x8is\x8st\x8tr\x8ra\x8at\x8ti\x8io\x8on\x8n·submenu,·called·S\x8So\x8of\x8ft\x8tw\x8wa\x8ar\x8re\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8e.
  
2592 Fedora·systems·contain·an·installed·software·catalog·called·the·RPM·database,·which·records·metadata·of·installed·packages.·Consistently·using·dnf·or·the·graphical·S\x8So\x8of\x8ft\x8tw\x8wa\x8ar\x8re\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8e·for·all·software·installation·allows·for·insight·into·the·current·inventory·of·installed·software·on·the·system.2590 Fedora·systems·contain·an·installed·software·catalog·called·the·RPM·database,·which·records·metadata·of·installed·packages.·Consistently·using·dnf·or·the·graphical·S\x8So\x8of\x8ft\x8tw\x8wa\x8ar\x8re\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8e·for·all·software·installation·allows·for·insight·into·the·current·inventory·of·installed·software·on·the·system.
  
2593 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·d\x8dn\x8nf\x8f-\x8-a\x8au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8c·P\x8Pa\x8ac\x8ck\x8ka\x8ag\x8ge\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*2591 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·d\x8dn\x8nf\x8f-\x8-a\x8au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8c·P\x8Pa\x8ac\x8ck\x8ka\x8ag\x8ge\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
2594 The·dnf-automatic·package·can·be·installed·with·the·following·command:2592 The·dnf-automatic·package·can·be·installed·with·the·following·command:
Offset 2628, 52 lines modifiedOffset 2628, 38 lines modified
2628 ··tags:2628 ··tags:
2629 ··-·enable_strategy2629 ··-·enable_strategy
2630 ··-·low_complexity2630 ··-·low_complexity
2631 ··-·low_disruption2631 ··-·low_disruption
2632 ··-·medium_severity2632 ··-·medium_severity
2633 ··-·no_reboot_needed2633 ··-·no_reboot_needed
2634 ··-·package_dnf-automatic_installed2634 ··-·package_dnf-automatic_installed
2635 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
2636 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
2637 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
2638 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
2639 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
2640 dnf·install·dnf-automatic 
2641 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
2642 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
2643 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
2644 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
2645 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
2646 package·--add=dnf-automatic 
2647 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x82635 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
2648 [[packages]]2636 [[packages]]
2649 name·=·"dnf-automatic"2637 name·=·"dnf-automatic"
2650 version·=·"*"2638 version·=·"*"
2651 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
2652 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
2653 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
2654 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
2655 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
2656 package·install·dnf-automatic 
2657 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x82639 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
2658 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low2640 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
2659 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low2641 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
2660 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false2642 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
2661 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable2643 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
Max diff block lines reached; 24642/29649 bytes (83.11%) of diff not shown.
179 KB
./usr/share/doc/ssg-nondebian/ssg-fedora-guide-pci-dss.html
    
Offset 16702, 207 lines modifiedOffset 16702, 207 lines modified
000413d0:·7461·2d74·6172·6765·743d·2223·6964·6d32··ta-target="#idm2000413d0:·7461·2d74·6172·6765·743d·2223·6964·6d32··ta-target="#idm2
000413e0:·3130·3622·2074·6162·696e·6465·783d·2230··106"·tabindex="0000413e0:·3130·3622·2074·6162·696e·6465·783d·2230··106"·tabindex="0
000413f0:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·000413f0:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
00041400:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f00041400:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
00041410:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act00041410:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
00041420:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"00041420:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
00041430:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed00041430:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
 00041440:·6961·7469·6f6e·204f·5342·7569·6c64·2042··iation·OSBuild·B
 00041450:·6c75·6570·7269·6e74·2073·6e69·7070·6574··lueprint·snippet
 00041460:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
 00041470:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
 00041480:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
 00041490:·2069·643d·2269·646d·3231·3036·223e·3c70···id="idm2106"><p
 000414a0:·7265·3e3c·636f·6465·3e0a·5b5b·7061·636b··re><code>.[[pack
 000414b0:·6167·6573·5d5d·0a6e·616d·6520·3d20·2261··ages]].name·=·"a
 000414c0:·6964·6522·0a76·6572·7369·6f6e·203d·2022··ide".version·=·"
00041440:·6961·7469·6f6e·2073·6372·6970·7420·e287··iation·script·.. 
00041450:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl 
00041460:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla 
00041470:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id 
00041480:·3d22·6964·6d32·3130·3622·3e3c·7461·626c··="idm2106"><tabl 
00041490:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t 
000414a0:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab 
000414b0:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl 
000414c0:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr 
000414d0:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity: 
000414e0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td 
000414f0:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di 
00041500:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t 
00041510:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr>< 
00041520:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</ 
00041530:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td 
00041540:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St 
00041550:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td> 
00041560:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr> 
00041570:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co 
00041580:·6465·3e0a·646e·6620·696e·7374·616c·6c20··de>.dnf·install· 
00041590:·6169·6465·0a3c·2f63·6f64·653e·3c2f·7072··aide.</code></pr000414d0:·2a22·0a3c·2f63·6f64·653e·3c2f·7072·653e··*".</code></pre>
000415a0:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class000414e0:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class="
000415b0:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes000414f0:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success"
000415c0:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle="00041500:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co
000415d0:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t00041510:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar
000415e0:·6172·6765·743d·2223·6964·6d32·3130·3722··arget="#idm2107"00041520:·6765·743d·2223·6964·6d32·3130·3722·2074··get="#idm2107"·t
000415f0:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro00041530:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
00041600:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria00041540:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
00041610:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false00041550:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
00041620:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat00041560:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
00041630:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre00041570:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
00041640:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati00041580:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
00041650:·6f6e·2041·6e61·636f·6e64·6120·736e·6970··on·Anaconda·snip00041590:·2050·7570·7065·7420·736e·6970·7065·7420···Puppet·snippet·
00041660:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br><000415a0:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·
00041670:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel 
00041680:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap 
00041690:·7365·2220·6964·3d22·6964·6d32·3130·3722··se"·id="idm2107" 
000416a0:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t 
000416b0:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip 
000416c0:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere 
000416d0:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense 
000416e0:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl 
000416f0:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l 
00041700:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr> 
00041710:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:< 
00041720:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td> 
00041730:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb 
00041740:·6f6f·743a·3c2f·7468·3e3c·7464·3e66·616c··oot:</th><td>fal 
00041750:·7365·3c2f·7464·3e3c·2f74·723e·3c74·723e··se</td></tr><tr> 
00041760:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t 
00041770:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td 
00041780:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p 
00041790:·7265·3e3c·636f·6465·3e0a·7061·636b·6167··re><code>.packag 
000417a0:·6520·2d2d·6164·643d·6169·6465·0a3c·2f63··e·--add=aide.</c 
000417b0:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div> 
000417c0:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt 
000417d0:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data- 
000417e0:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse 
000417f0:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="# 
00041800:·6964·6d32·3130·3822·2074·6162·696e·6465··idm2108"·tabinde 
00041810:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt 
00041820:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande 
00041830:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title= 
00041840:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev 
00041850:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R 
00041860:·656d·6564·6961·7469·6f6e·204f·5342·7569··emediation·OSBui 
00041870:·6c64·2042·6c75·6570·7269·6e74·2073·6e69··ld·Blueprint·sni 
00041880:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br> 
00041890:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane 
000418a0:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla 
000418b0:·7073·6522·2069·643d·2269·646d·3231·3038··pse"·id="idm2108 
000418c0:·223e·3c70·7265·3e3c·636f·6465·3e0a·5b5b··"><pre><code>.[[ 
000418d0:·7061·636b·6167·6573·5d5d·0a6e·616d·6520··packages]].name· 
000418e0:·3d20·2261·6964·6522·0a76·6572·7369·6f6e··=·"aide".version 
000418f0:·203d·2022·2a22·0a3c·2f63·6f64·653e·3c2f···=·"*".</code></ 
00041900:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla 
00041910:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ 
00041920:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle 
00041930:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data 
00041940:·2d74·6172·6765·743d·2223·6964·6d32·3130··-target="#idm210 
00041950:·3922·2074·6162·696e·6465·783d·2230·2220··9"·tabindex="0"· 
00041960:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar 
00041970:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal 
00041980:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ 
00041990:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h 
000419a0:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia 
000419b0:·7469·6f6e·2073·6372·6970·7420·e287·b23c··tion·script·...< 
000419c0:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas 
000419d0:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps 
000419e0:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id=" 
000419f0:·6964·6d32·3130·3922·3e3c·7461·626c·6520··idm2109"><table· 
00041a00:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab 
00041a10:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table 
00041a20:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table- 
00041a30:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr>< 
00041a40:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</ 
00041a50:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td>< 
00041a60:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr 
00041a70:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td> 
00041a80:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr 
00041a90:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th 
00041aa0:·3e3c·7464·3e66·616c·7365·3c2f·7464·3e3c··><td>false</td>< 
00041ab0:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra 
00041ac0:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en 
00041ad0:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></ 
00041ae0:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code 
00041af0:·3e0a·7061·636b·6167·6520·696e·7374·616c··>.package·instal 
00041b00:·6c20·6169·6465·0a3c·2f63·6f64·653e·3c2f··l·aide.</code></ 
00041b10:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla 
00041b20:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ 
Max diff block lines reached; 135410/162624 bytes (83.27%) of diff not shown.
20.1 KB
html2text {}
    
Offset 534, 52 lines modifiedOffset 534, 38 lines modified
534 ··-·PCI-DSSv4-11.5.2534 ··-·PCI-DSSv4-11.5.2
535 ··-·enable_strategy535 ··-·enable_strategy
536 ··-·low_complexity536 ··-·low_complexity
537 ··-·low_disruption537 ··-·low_disruption
538 ··-·medium_severity538 ··-·medium_severity
539 ··-·no_reboot_needed539 ··-·no_reboot_needed
540 ··-·package_aide_installed540 ··-·package_aide_installed
541 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
542 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
543 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
544 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
545 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
546 dnf·install·aide 
547 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
548 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
549 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
550 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
551 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
552 package·--add=aide 
553 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8541 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
554 [[packages]]542 [[packages]]
555 name·=·"aide"543 name·=·"aide"
556 version·=·"*"544 version·=·"*"
557 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
558 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
559 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
560 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
561 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
562 package·install·aide 
563 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8545 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
564 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low546 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
565 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low547 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
566 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false548 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
567 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable549 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
568 include·install_aide550 include·install_aide
  
569 class·install_aide·{551 class·install_aide·{
570 ··package·{·'aide':552 ··package·{·'aide':
571 ····ensure·=>·'installed',553 ····ensure·=>·'installed',
572 ··}554 ··}
573 }555 }
 556 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 557 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 558 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 559 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 560 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 561 package·install·aide
574 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8562 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
575 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low563 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
576 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low564 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
577 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false565 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
578 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable566 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
579 #·Remediation·is·applicable·only·in·certain·platforms567 #·Remediation·is·applicable·only·in·certain·platforms
580 if·rpm·--quiet·-q·kernel;·then568 if·rpm·--quiet·-q·kernel;·then
Offset 587, 14 lines modifiedOffset 573, 28 lines modified
587 if·!·rpm·-q·--quiet·"aide"·;·then573 if·!·rpm·-q·--quiet·"aide"·;·then
588 ····dnf·install·-y·"aide"574 ····dnf·install·-y·"aide"
589 fi575 fi
  
590 else576 else
591 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'577 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
592 fi578 fi
 579 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 580 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 581 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 582 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 583 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 584 package·--add=aide
 585 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 586 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 587 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 588 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 589 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 590 dnf·install·aide
593 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*591 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
594 Run·the·following·command·to·generate·a·new·database:592 Run·the·following·command·to·generate·a·new·database:
595 $·sudo·/usr/sbin/aide·--init593 $·sudo·/usr/sbin/aide·--init
596 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:594 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
597 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz595 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
598 To·initiate·a·manual·check,·run·the·following·command:596 To·initiate·a·manual·check,·run·the·following·command:
599 $·sudo·/usr/sbin/aide·--check597 $·sudo·/usr/sbin/aide·--check
Offset 7649, 52 lines modifiedOffset 7649, 38 lines modified
7649 ··-·NIST-800-53-CM-6(a)7649 ··-·NIST-800-53-CM-6(a)
7650 ··-·enable_strategy7650 ··-·enable_strategy
7651 ··-·low_complexity7651 ··-·low_complexity
7652 ··-·low_disruption7652 ··-·low_disruption
7653 ··-·medium_severity7653 ··-·medium_severity
7654 ··-·no_reboot_needed7654 ··-·no_reboot_needed
7655 ··-·package_opensc_installed7655 ··-·package_opensc_installed
7656 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
7657 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
7658 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
7659 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
7660 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
7661 dnf·install·opensc 
7662 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
7663 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
7664 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
7665 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
7666 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
7667 package·--add=opensc 
7668 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x87656 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
7669 [[packages]]7657 [[packages]]
7670 name·=·"opensc"7658 name·=·"opensc"
7671 version·=·"*"7659 version·=·"*"
7672 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
7673 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
7674 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
7675 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
7676 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
7677 package·install·opensc 
7678 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x87660 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
7679 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low7661 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
7680 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low7662 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
7681 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false7663 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
7682 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable7664 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
Max diff block lines reached; 15807/20518 bytes (77.04%) of diff not shown.
26.4 KB
./usr/share/doc/ssg-nondebian/ssg-fedora-guide-standard.html
    
Offset 29992, 77 lines modifiedOffset 29992, 77 lines modified
00075270:·6765·743d·2223·6964·6d31·3732·3833·2220··get="#idm17283"·00075270:·6765·743d·2223·6964·6d31·3732·3833·2220··get="#idm17283"·
00075280:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol00075280:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol
00075290:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-00075290:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-
000752a0:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"000752a0:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"
000752b0:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate000752b0:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate
000752c0:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href000752c0:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href
000752d0:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio000752d0:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio
 000752e0:·6e20·5075·7070·6574·2073·6e69·7070·6574··n·Puppet·snippet
 000752f0:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
 00075300:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
 00075310:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
 00075320:·2069·643d·2269·646d·3137·3238·3322·3e3c···id="idm17283"><
 00075330:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab
 00075340:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped
 00075350:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·
 00075360:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"
 00075370:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex
000752e0:·6e20·7363·7269·7074·20e2·87b2·3c2f·613e··n·script·...</a> 
000752f0:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class=" 
00075300:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c 
00075310:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm 
00075320:·3137·3238·3322·3e3c·7461·626c·6520·636c··17283"><table·cl 
00075330:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table 
00075340:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b 
00075350:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co 
00075360:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th 
00075370:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th 
00075380:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t 
00075390:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup 
000753a0:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo 
000753b0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr>< 
000753c0:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th>< 
000753d0:·7464·3e66·616c·7365·3c2f·7464·3e3c·2f74··td>false</td></t 
000753e0:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate 
000753f0:·6779·3a3c·2f74·683e·3c74·643e·6469·7361··gy:</th><td>disa 
00075400:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t 
00075410:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code> 
00075420:·0a73·6572·7669·6365·2065·6e61·626c·6520··.service·enable· 
00075430:·6669·7265·7761·6c6c·640a·3c2f·636f·6465··firewalld.</code 
00075440:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a· 
00075450:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s 
00075460:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog 
00075470:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d 
00075480:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm 
00075490:·3137·3238·3422·2074·6162·696e·6465·783d··17284"·tabindex= 
000754a0:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button 
000754b0:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded= 
000754c0:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A 
000754d0:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea 
000754e0:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem 
000754f0:·6564·6961·7469·6f6e·2050·7570·7065·7420··ediation·Puppet· 
00075500:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a>< 
00075510:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p 
00075520:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co 
00075530:·6c6c·6170·7365·2220·6964·3d22·6964·6d31··llapse"·id="idm1 
00075540:·3732·3834·223e·3c74·6162·6c65·2063·6c61··7284"><table·cla 
00075550:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table- 
00075560:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo 
00075570:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con 
00075580:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th> 
00075590:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th> 
000755a0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
000755b0:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt 
000755c0:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low00075380:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low
000755d0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t00075390:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
000755e0:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t 
000755f0:·643e·6661·6c73·653c·2f74·643e·3c2f·7472··d>false</td></tr 
00075600:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg000753a0:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t
 000753b0:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
 000753c0:·7472·3e3c·7472·3e3c·7468·3e52·6562·6f6f··tr><tr><th>Reboo
 000753d0:·743a·3c2f·7468·3e3c·7464·3e66·616c·7365··t:</th><td>false
 000753e0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
 000753f0:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th>
 00075400:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td><
 00075410:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre
 00075420:·3e3c·636f·6465·3e69·6e63·6c75·6465·2065··><code>include·e
 00075430:·6e61·626c·655f·6669·7265·7761·6c6c·640a··nable_firewalld.
 00075440:·0a63·6c61·7373·2065·6e61·626c·655f·6669··.class·enable_fi
 00075450:·7265·7761·6c6c·6420·7b0a·2020·7365·7276··rewalld·{.··serv
 00075460:·6963·6520·7b27·6669·7265·7761·6c6c·6427··ice·{'firewalld'
 00075470:·3a0a·2020·2020·656e·6162·6c65·203d·2667··:.····enable·=&g
 00075480:·743b·2074·7275·652c·0a20·2020·2065·6e73··t;·true,.····ens
 00075490:·7572·6520·3d26·6774·3b20·2772·756e·6e69··ure·=&gt;·'runni
 000754a0:·6e67·272c·0a20·207d·0a7d·0a3c·2f63·6f64··ng',.··}.}.</cod
 000754b0:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a
 000754c0:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn-
 000754d0:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to
 000754e0:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"·
 000754f0:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
 00075500:·6d31·3732·3834·2220·7461·6269·6e64·6578··m17284"·tabindex
 00075510:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto
 00075520:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded
 00075530:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="
 00075540:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve
 00075550:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re
 00075560:·6d65·6469·6174·696f·6e20·7363·7269·7074··mediation·script
 00075570:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
 00075580:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
 00075590:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
 000755a0:·2069·643d·2269·646d·3137·3238·3422·3e3c···id="idm17284"><
 000755b0:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab
 000755c0:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped
 000755d0:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·
 000755e0:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"
 000755f0:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex
 00075600:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low
 00075610:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
 00075620:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t
 00075630:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
 00075640:·7472·3e3c·7472·3e3c·7468·3e52·6562·6f6f··tr><tr><th>Reboo
00075610:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl00075650:·743a·3c2f·7468·3e3c·7464·3e66·616c·7365··t:</th><td>false
 00075660:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
 00075670:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th>
 00075680:·3c74·643e·6469·7361·626c·653c·2f74·643e··<td>disable</td>
 00075690:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr
 000756a0:·653e·3c63·6f64·653e·0a73·6572·7669·6365··e><code>.service
 000756b0:·2065·6e61·626c·6520·6669·7265·7761·6c6c···enable·firewall
00075620:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab 
00075630:·6c65·3e3c·7072·653e·3c63·6f64·653e·696e··le><pre><code>in 
00075640:·636c·7564·6520·656e·6162·6c65·5f66·6972··clude·enable_fir 
00075650:·6577·616c·6c64·0a0a·636c·6173·7320·656e··ewalld..class·en 
00075660:·6162·6c65·5f66·6972·6577·616c·6c64·207b··able_firewalld·{ 
00075670:·0a20·2073·6572·7669·6365·207b·2766·6972··.··service·{'fir 
00075680:·6577·616c·6c64·273a·0a20·2020·2065·6e61··ewalld':.····ena 
00075690:·626c·6520·3d26·6774·3b20·7472·7565·2c0a··ble·=&gt;·true,. 
000756a0:·2020·2020·656e·7375·7265·203d·2667·743b······ensure·=&gt; 
000756b0:·2027·7275·6e6e·696e·6727·2c0a·2020·7d0a···'running',.··}. 
Max diff block lines reached; 14104/23376 bytes (60.34%) of diff not shown.
3.48 KB
html2text {}
    
Offset 3090, 34 lines modifiedOffset 3090, 34 lines modified
3090 ··-·medium_severity3090 ··-·medium_severity
3091 ··-·no_reboot_needed3091 ··-·no_reboot_needed
3092 ··-·service_firewalld_enabled3092 ··-·service_firewalld_enabled
3093 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x83093 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
3094 [customizations.services]3094 [customizations.services]
3095 enabled·=·["firewalld"]3095 enabled·=·["firewalld"]
3096 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
3097 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
3098 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
3099 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
3100 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable 
  
3101 service·enable·firewalld 
3102 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x83096 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
3103 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low3097 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
3104 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low3098 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
3105 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false3099 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
3106 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable3100 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
3107 include·enable_firewalld3101 include·enable_firewalld
  
3108 class·enable_firewalld·{3102 class·enable_firewalld·{
3109 ··service·{'firewalld':3103 ··service·{'firewalld':
3110 ····enable·=>·true,3104 ····enable·=>·true,
3111 ····ensure·=>·'running',3105 ····ensure·=>·'running',
3112 ··}3106 ··}
3113 }3107 }
 3108 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 3109 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 3110 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 3111 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 3112 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
  
 3113 service·enable·firewalld
3114 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x83114 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
3115 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low3115 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
3116 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low3116 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
3117 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false3117 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
3118 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable3118 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
3119 #·Remediation·is·applicable·only·in·certain·platforms3119 #·Remediation·is·applicable·only·in·certain·platforms
3120 if·rpm·--quiet·-q·kernel·&&·{·rpm·--quiet·-q·firewalld;·};·then3120 if·rpm·--quiet·-q·kernel·&&·{·rpm·--quiet·-q·firewalld;·};·then
Offset 24522, 46 lines modifiedOffset 24522, 46 lines modified
24522 ··-·medium_severity24522 ··-·medium_severity
24523 ··-·no_reboot_needed24523 ··-·no_reboot_needed
24524 ··-·service_auditd_enabled24524 ··-·service_auditd_enabled
24525 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x824525 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
24526 [customizations.services]24526 [customizations.services]
24527 enabled·=·["auditd"]24527 enabled·=·["auditd"]
24528 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
24529 --- 
24530 apiVersion:·machineconfiguration.openshift.io/v1 
24531 kind:·MachineConfig 
24532 spec: 
24533 ··config: 
24534 ····ignition: 
24535 ······version:·3.1.0 
24536 ····systemd: 
24537 ······units: 
24538 ······-·name:·auditd.service 
24539 ········enabled:·true 
24540 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
24541 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
24542 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
24543 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
24544 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable 
  
24545 service·enable·auditd 
24546 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x824528 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
24547 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low24529 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
24548 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low24530 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
24549 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false24531 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
24550 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable24532 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
24551 include·enable_auditd24533 include·enable_auditd
  
24552 class·enable_auditd·{24534 class·enable_auditd·{
24553 ··service·{'auditd':24535 ··service·{'auditd':
24554 ····enable·=>·true,24536 ····enable·=>·true,
24555 ····ensure·=>·'running',24537 ····ensure·=>·'running',
24556 ··}24538 ··}
24557 }24539 }
 24540 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 24541 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 24542 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 24543 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 24544 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
  
 24545 service·enable·auditd
 24546 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 24547 ---
 24548 apiVersion:·machineconfiguration.openshift.io/v1
 24549 kind:·MachineConfig
 24550 spec:
 24551 ··config:
 24552 ····ignition:
 24553 ······version:·3.1.0
 24554 ····systemd:
 24555 ······units:
 24556 ······-·name:·auditd.service
 24557 ········enabled:·true
24558 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x824558 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
24559 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low24559 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
24560 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low24560 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
24561 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false24561 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
24562 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable24562 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
24563 #·Remediation·is·applicable·only·in·certain·platforms24563 #·Remediation·is·applicable·only·in·certain·platforms
24564 if·rpm·--quiet·-q·kernel·&&·{·rpm·--quiet·-q·audit;·};·then24564 if·rpm·--quiet·-q·kernel·&&·{·rpm·--quiet·-q·audit;·};·then
660 KB
./usr/share/doc/ssg-nondebian/ssg-ol10-guide-anssi_bp28_enhanced.html
    
Offset 15127, 143 lines modifiedOffset 15127, 143 lines modified
0003b160:·2d74·6172·6765·743d·2223·6964·6d35·3039··-target="#idm5090003b160:·2d74·6172·6765·743d·2223·6964·6d35·3039··-target="#idm509
0003b170:·3822·2074·6162·696e·6465·783d·2230·2220··8"·tabindex="0"·0003b170:·3822·2074·6162·696e·6465·783d·2230·2220··8"·tabindex="0"·
0003b180:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar0003b180:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar
0003b190:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal0003b190:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal
0003b1a0:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ0003b1a0:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ
0003b1b0:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h0003b1b0:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h
0003b1c0:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia0003b1c0:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia
 0003b1d0:·7469·6f6e·204f·5342·7569·6c64·2042·6c75··tion·OSBuild·Blu
 0003b1e0:·6570·7269·6e74·2073·6e69·7070·6574·20e2··eprint·snippet·.
 0003b1f0:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c
 0003b200:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
 0003b210:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
 0003b220:·643d·2269·646d·3530·3938·223e·3c70·7265··d="idm5098"><pre
 0003b230:·3e3c·636f·6465·3e0a·5b5b·7061·636b·6167··><code>.[[packag
 0003b240:·6573·5d5d·0a6e·616d·6520·3d20·2261·6964··es]].name·=·"aid
 0003b250:·6522·0a76·6572·7369·6f6e·203d·2022·2a22··e".version·=·"*"
 0003b260:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></
 0003b270:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt
 0003b280:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d
 0003b290:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll
 0003b2a0:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
 0003b2b0:·743d·2223·6964·6d35·3039·3922·2074·6162··t="#idm5099"·tab
 0003b2c0:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
 0003b2d0:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
 0003b2e0:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
 0003b2f0:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
 0003b300:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
 0003b310:·2122·3e52·656d·6564·6961·7469·6f6e·2050··!">Remediation·P
 0003b320:·7570·7065·7420·736e·6970·7065·7420·e287··uppet·snippet·..
 0003b330:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl
 0003b340:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla
 0003b350:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id
 0003b360:·3d22·6964·6d35·3039·3922·3e3c·7461·626c··="idm5099"><tabl
 0003b370:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t
 0003b380:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab
 0003b390:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl
 0003b3a0:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr
 0003b3b0:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:
 0003b3c0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
 0003b3d0:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di
 0003b3e0:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t
 0003b3f0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
 0003b400:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</
 0003b410:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td
 0003b420:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St
 0003b430:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>
 0003b440:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr>
 0003b450:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co
 0003b460:·6465·3e69·6e63·6c75·6465·2069·6e73·7461··de>include·insta
 0003b470:·6c6c·5f61·6964·650a·0a63·6c61·7373·2069··ll_aide..class·i
 0003b480:·6e73·7461·6c6c·5f61·6964·6520·7b0a·2020··nstall_aide·{.··
 0003b490:·7061·636b·6167·6520·7b20·2761·6964·6527··package·{·'aide'
 0003b4a0:·3a0a·2020·2020·656e·7375·7265·203d·2667··:.····ensure·=&g
 0003b4b0:·743b·2027·696e·7374·616c·6c65·6427·2c0a··t;·'installed',.
 0003b4c0:·2020·7d0a·7d0a·3c2f·636f·6465·3e3c·2f70····}.}.</code></p
 0003b4d0:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas
 0003b4e0:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe
 0003b4f0:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle=
 0003b500:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data-
 0003b510:·7461·7267·6574·3d22·2369·646d·3531·3030··target="#idm5100
 0003b520:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r
 0003b530:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari
 0003b540:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals
 0003b550:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa
 0003b560:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr
 0003b570:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat
 0003b580:·696f·6e20·5368·656c·6c20·7363·7269·7074··ion·Shell·script
 0003b590:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
 0003b5a0:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
 0003b5b0:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
 0003b5c0:·2069·643d·2269·646d·3531·3030·223e·3c74···id="idm5100"><t
 0003b5d0:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl
 0003b5e0:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·
 0003b5f0:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t
 0003b600:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">
 0003b610:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi
 0003b620:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<
 0003b630:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 0003b640:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th
 0003b650:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
 0003b660:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot
 0003b670:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false<
 0003b680:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 0003b690:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><
 0003b6a0:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></
 0003b6b0:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>
 0003b6c0:·3c63·6f64·653e·2320·5265·6d65·6469·6174··<code>#·Remediat
 0003b6d0:·696f·6e20·6973·2061·7070·6c69·6361·626c··ion·is·applicabl
 0003b6e0:·6520·6f6e·6c79·2069·6e20·6365·7274·6169··e·only·in·certai
 0003b6f0:·6e20·706c·6174·666f·726d·730a·6966·2072··n·platforms.if·r
 0003b700:·706d·202d·2d71·7569·6574·202d·7120·6b65··pm·--quiet·-q·ke
 0003b710:·726e·656c·207c·7c20·7270·6d20·2d2d·7175··rnel·||·rpm·--qu
 0003b720:·6965·7420·2d71·206b·6572·6e65·6c2d·7565··iet·-q·kernel-ue
 0003b730:·6b3b·2074·6865·6e0a·0a69·6620·2120·7270··k;·then..if·!·rp
 0003b740:·6d20·2d71·202d·2d71·7569·6574·2022·6169··m·-q·--quiet·"ai
 0003b750:·6465·2220·3b20·7468·656e·0a20·2020·2064··de"·;·then.····d
 0003b760:·6e66·2069·6e73·7461·6c6c·202d·7920·2261··nf·install·-y·"a
 0003b770:·6964·6522·0a66·690a·0a65·6c73·650a·2020··ide".fi..else.··
 0003b780:·2020·2667·743b·2661·6d70·3b32·2065·6368····&gt;&amp;2·ech
 0003b790:·6f20·2752·656d·6564·6961·7469·6f6e·2069··o·'Remediation·i
 0003b7a0:·7320·6e6f·7420·6170·706c·6963·6162·6c65··s·not·applicable
 0003b7b0:·2c20·6e6f·7468·696e·6720·7761·7320·646f··,·nothing·was·do
 0003b7c0:·6e65·270a·6669·0a3c·2f63·6f64·653e·3c2f··ne'.fi.</code></
 0003b7d0:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla
 0003b7e0:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ
 0003b7f0:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle
 0003b800:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data
 0003b810:·2d74·6172·6765·743d·2223·6964·6d35·3130··-target="#idm510
 0003b820:·3122·2074·6162·696e·6465·783d·2230·2220··1"·tabindex="0"·
 0003b830:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar
 0003b840:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal
 0003b850:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ
 0003b860:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h
 0003b870:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia
0003b1d0:·7469·6f6e·2041·6e61·636f·6e64·6120·736e··tion·Anaconda·sn0003b880:·7469·6f6e·2041·6e61·636f·6e64·6120·736e··tion·Anaconda·sn
0003b1e0:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br0003b890:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br
0003b1f0:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan0003b8a0:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
0003b200:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll0003b8b0:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
0003b210:·6170·7365·2220·6964·3d22·6964·6d35·3039··apse"·id="idm5090003b8c0:·6170·7365·2220·6964·3d22·6964·6d35·3130··apse"·id="idm510
0003b220:·3822·3e3c·7461·626c·6520·636c·6173·733d··8"><table·class=0003b8d0:·3122·3e3c·7461·626c·6520·636c·6173·733d··1"><table·class=
0003b230:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str0003b8e0:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str
0003b240:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde0003b8f0:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde
0003b250:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden0003b900:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden
0003b260:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com0003b910:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com
0003b270:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td0003b920:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td
0003b280:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t0003b930:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
0003b290:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption0003b940:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption
Max diff block lines reached; 607347/625729 bytes (97.06%) of diff not shown.
49.3 KB
html2text {}
    
Offset 152, 21 lines modifiedOffset 152, 14 lines modified
152 ··-·PCI-DSSv4-11.5.2152 ··-·PCI-DSSv4-11.5.2
153 ··-·enable_strategy153 ··-·enable_strategy
154 ··-·low_complexity154 ··-·low_complexity
155 ··-·low_disruption155 ··-·low_disruption
156 ··-·medium_severity156 ··-·medium_severity
157 ··-·no_reboot_needed157 ··-·no_reboot_needed
158 ··-·package_aide_installed158 ··-·package_aide_installed
159 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
160 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
161 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
162 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
163 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
164 package·--add=aide 
165 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8159 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
166 [[packages]]160 [[packages]]
167 name·=·"aide"161 name·=·"aide"
168 version·=·"*"162 version·=·"*"
169 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8163 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
170 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low164 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 191, 14 lines modifiedOffset 184, 21 lines modified
191 if·!·rpm·-q·--quiet·"aide"·;·then184 if·!·rpm·-q·--quiet·"aide"·;·then
192 ····dnf·install·-y·"aide"185 ····dnf·install·-y·"aide"
193 fi186 fi
  
194 else187 else
195 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'188 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
196 fi189 fi
 190 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 191 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 192 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 193 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 194 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 195 package·--add=aide
197 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*196 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
198 Run·the·following·command·to·generate·a·new·database:197 Run·the·following·command·to·generate·a·new·database:
199 $·sudo·/usr/sbin/aide·--init198 $·sudo·/usr/sbin/aide·--init
200 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the199 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the
201 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these200 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these
202 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their201 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their
203 integrity.·The·newly-generated·database·can·be·installed·as·follows:202 integrity.·The·newly-generated·database·can·be·installed·as·follows:
Offset 583, 21 lines modifiedOffset 583, 14 lines modified
583 ··tags:583 ··tags:
584 ··-·enable_strategy584 ··-·enable_strategy
585 ··-·low_complexity585 ··-·low_complexity
586 ··-·low_disruption586 ··-·low_disruption
587 ··-·low_severity587 ··-·low_severity
588 ··-·no_reboot_needed588 ··-·no_reboot_needed
589 ··-·systemd_tmp_mount_enabled589 ··-·systemd_tmp_mount_enabled
590 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
591 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
592 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
593 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
594 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
595 services·--enabled=tmp.mount 
596 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8590 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
597 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low591 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
598 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low592 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
599 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false593 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
600 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable594 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
601 #·Remediation·is·applicable·only·in·certain·platforms595 #·Remediation·is·applicable·only·in·certain·platforms
602 if·(·!·(·{·rpm·--quiet·-q·kernel·;}·&&·{·rpm·--quiet·-q·rpm-ostree·;}·&&·{·rpm·--quiet·-q·bootc·;}·&&596 if·(·!·(·{·rpm·--quiet·-q·kernel·;}·&&·{·rpm·--quiet·-q·rpm-ostree·;}·&&·{·rpm·--quiet·-q·bootc·;}·&&
Offset 610, 14 lines modifiedOffset 603, 21 lines modified
610 ··"$SYSTEMCTL_EXEC"·start·'tmp.mount'603 ··"$SYSTEMCTL_EXEC"·start·'tmp.mount'
611 fi604 fi
612 "$SYSTEMCTL_EXEC"·enable·'tmp.mount'605 "$SYSTEMCTL_EXEC"·enable·'tmp.mount'
  
613 else606 else
614 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'607 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
615 fi608 fi
 609 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 610 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 611 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 612 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 613 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 614 services·--enabled=tmp.mount
616 Group  ·Sudo·  Group·contains·17·rules615 Group  ·Sudo·  Group·contains·17·rules
617 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Sudo,·which·stands·for·"su·'do'",·provides·the·ability·to·delegate·authority·to·certain616 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Sudo,·which·stands·for·"su·'do'",·provides·the·ability·to·delegate·authority·to·certain
618 users,·groups·of·users,·or·system·administrators.·When·configured·for·system·users·and/or·groups,617 users,·groups·of·users,·or·system·administrators.·When·configured·for·system·users·and/or·groups,
619 Sudo·can·allow·a·user·or·group·to·execute·privileged·commands·that·normally·only·root·is·allowed·to618 Sudo·can·allow·a·user·or·group·to·execute·privileged·commands·that·normally·only·root·is·allowed·to
620 execute.619 execute.
  
621 For·more·information·on·Sudo·and·addition·Sudo·configuration·options,·see·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8w\x8w_\x8w\x8w_\x8w\x8w_\x8.\x8._\x8s\x8s_\x8u\x8u_\x8d\x8d_\x8o\x8o_\x8.\x8._\x8w\x8w_\x8s\x8s.620 For·more·information·on·Sudo·and·addition·Sudo·configuration·options,·see·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8w\x8w_\x8w\x8w_\x8w\x8w_\x8.\x8._\x8s\x8s_\x8u\x8u_\x8d\x8d_\x8o\x8o_\x8.\x8._\x8w\x8w_\x8s\x8s.
Offset 666, 21 lines modifiedOffset 666, 14 lines modified
666 ··-·PCI-DSSv4-2.2.6666 ··-·PCI-DSSv4-2.2.6
667 ··-·enable_strategy667 ··-·enable_strategy
668 ··-·low_complexity668 ··-·low_complexity
669 ··-·low_disruption669 ··-·low_disruption
670 ··-·medium_severity670 ··-·medium_severity
671 ··-·no_reboot_needed671 ··-·no_reboot_needed
672 ··-·package_sudo_installed672 ··-·package_sudo_installed
673 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
674 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
675 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
676 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
677 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
678 package·--add=sudo 
679 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8673 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
680 [[packages]]674 [[packages]]
681 name·=·"sudo"675 name·=·"sudo"
682 version·=·"*"676 version·=·"*"
683 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8677 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
684 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low678 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 705, 14 lines modifiedOffset 698, 21 lines modified
705 if·!·rpm·-q·--quiet·"sudo"·;·then698 if·!·rpm·-q·--quiet·"sudo"·;·then
706 ····dnf·install·-y·"sudo"699 ····dnf·install·-y·"sudo"
707 fi700 fi
  
708 else701 else
709 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'702 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
710 fi703 fi
 704 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 705 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 706 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 707 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 708 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 709 package·--add=sudo
711 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·G\x8Gr\x8ro\x8ou\x8up\x8p·W\x8Wh\x8ho\x8o·O\x8Ow\x8wn\x8ns\x8s·/\x8/e\x8et\x8tc\x8c/\x8/s\x8su\x8ud\x8do\x8oe\x8er\x8rs\x8s.\x8.d\x8d·D\x8Di\x8ir\x8re\x8ec\x8ct\x8to\x8or\x8ry\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*710 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·G\x8Gr\x8ro\x8ou\x8up\x8p·W\x8Wh\x8ho\x8o·O\x8Ow\x8wn\x8ns\x8s·/\x8/e\x8et\x8tc\x8c/\x8/s\x8su\x8ud\x8do\x8oe\x8er\x8rs\x8s.\x8.d\x8d·D\x8Di\x8ir\x8re\x8ec\x8ct\x8to\x8or\x8ry\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
712 To·properly·set·the·group·owner·of·/etc/sudoers.d,·run·the·command:711 To·properly·set·the·group·owner·of·/etc/sudoers.d,·run·the·command:
713 $·sudo·chgrp·root·/etc/sudoers.d712 $·sudo·chgrp·root·/etc/sudoers.d
Max diff block lines reached; 45295/50420 bytes (89.84%) of diff not shown.
722 KB
./usr/share/doc/ssg-nondebian/ssg-ol10-guide-anssi_bp28_high.html
    
Offset 15132, 144 lines modifiedOffset 15132, 144 lines modified
0003b1b0:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm0003b1b0:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
0003b1c0:·3530·3938·2220·7461·6269·6e64·6578·3d22··5098"·tabindex="0003b1c0:·3530·3938·2220·7461·6269·6e64·6578·3d22··5098"·tabindex="
0003b1d0:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"0003b1d0:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
0003b1e0:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="0003b1e0:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
0003b1f0:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac0003b1f0:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
0003b200:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal0003b200:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
0003b210:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme0003b210:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
 0003b220:·6469·6174·696f·6e20·4f53·4275·696c·6420··diation·OSBuild·
 0003b230:·426c·7565·7072·696e·7420·736e·6970·7065··Blueprint·snippe
 0003b240:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di
 0003b250:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c
 0003b260:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse
 0003b270:·2220·6964·3d22·6964·6d35·3039·3822·3e3c··"·id="idm5098"><
 0003b280:·7072·653e·3c63·6f64·653e·0a5b·5b70·6163··pre><code>.[[pac
 0003b290:·6b61·6765·735d·5d0a·6e61·6d65·203d·2022··kages]].name·=·"
 0003b2a0:·6169·6465·220a·7665·7273·696f·6e20·3d20··aide".version·=·
 0003b2b0:·222a·220a·3c2f·636f·6465·3e3c·2f70·7265··"*".</code></pre
 0003b2c0:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class=
 0003b2d0:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success
 0003b2e0:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c
 0003b2f0:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta
 0003b300:·7267·6574·3d22·2369·646d·3530·3939·2220··rget="#idm5099"·
 0003b310:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol
 0003b320:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-
 0003b330:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"
 0003b340:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate
 0003b350:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href
 0003b360:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio
 0003b370:·6e20·5075·7070·6574·2073·6e69·7070·6574··n·Puppet·snippet
 0003b380:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
 0003b390:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
 0003b3a0:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
 0003b3b0:·2069·643d·2269·646d·3530·3939·223e·3c74···id="idm5099"><t
 0003b3c0:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl
 0003b3d0:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·
 0003b3e0:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t
 0003b3f0:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">
 0003b400:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi
 0003b410:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<
 0003b420:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 0003b430:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th
 0003b440:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
 0003b450:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot
 0003b460:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false<
 0003b470:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 0003b480:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><
 0003b490:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></
 0003b4a0:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>
 0003b4b0:·3c63·6f64·653e·696e·636c·7564·6520·696e··<code>include·in
 0003b4c0:·7374·616c·6c5f·6169·6465·0a0a·636c·6173··stall_aide..clas
 0003b4d0:·7320·696e·7374·616c·6c5f·6169·6465·207b··s·install_aide·{
 0003b4e0:·0a20·2070·6163·6b61·6765·207b·2027·6169··.··package·{·'ai
 0003b4f0:·6465·273a·0a20·2020·2065·6e73·7572·6520··de':.····ensure·
 0003b500:·3d26·6774·3b20·2769·6e73·7461·6c6c·6564··=&gt;·'installed
 0003b510:·272c·0a20·207d·0a7d·0a3c·2f63·6f64·653e··',.··}.}.</code>
 0003b520:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c
 0003b530:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su
 0003b540:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg
 0003b550:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da
 0003b560:·7461·2d74·6172·6765·743d·2223·6964·6d35··ta-target="#idm5
 0003b570:·3130·3022·2074·6162·696e·6465·783d·2230··100"·tabindex="0
 0003b580:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
 0003b590:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
 0003b5a0:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
 0003b5b0:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
 0003b5c0:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
 0003b5d0:·6961·7469·6f6e·2053·6865·6c6c·2073·6372··iation·Shell·scr
 0003b5e0:·6970·7420·e287·b23c·2f61·3e3c·6272·3e3c··ipt·...</a><br><
 0003b5f0:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
 0003b600:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap
 0003b610:·7365·2220·6964·3d22·6964·6d35·3130·3022··se"·id="idm5100"
 0003b620:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t
 0003b630:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip
 0003b640:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere
 0003b650:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense
 0003b660:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl
 0003b670:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l
 0003b680:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
 0003b690:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:<
 0003b6a0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
 0003b6b0:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb
 0003b6c0:·6f6f·743a·3c2f·7468·3e3c·7464·3e66·616c··oot:</th><td>fal
 0003b6d0:·7365·3c2f·7464·3e3c·2f74·723e·3c74·723e··se</td></tr><tr>
 0003b6e0:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t
 0003b6f0:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td
 0003b700:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p
 0003b710:·7265·3e3c·636f·6465·3e23·2052·656d·6564··re><code>#·Remed
 0003b720:·6961·7469·6f6e·2069·7320·6170·706c·6963··iation·is·applic
 0003b730:·6162·6c65·206f·6e6c·7920·696e·2063·6572··able·only·in·cer
 0003b740:·7461·696e·2070·6c61·7466·6f72·6d73·0a69··tain·platforms.i
 0003b750:·6620·7270·6d20·2d2d·7175·6965·7420·2d71··f·rpm·--quiet·-q
 0003b760:·206b·6572·6e65·6c20·7c7c·2072·706d·202d···kernel·||·rpm·-
 0003b770:·2d71·7569·6574·202d·7120·6b65·726e·656c··-quiet·-q·kernel
 0003b780:·2d75·656b·3b20·7468·656e·0a0a·6966·2021··-uek;·then..if·!
 0003b790:·2072·706d·202d·7120·2d2d·7175·6965·7420···rpm·-q·--quiet·
 0003b7a0:·2261·6964·6522·203b·2074·6865·6e0a·2020··"aide"·;·then.··
 0003b7b0:·2020·646e·6620·696e·7374·616c·6c20·2d79····dnf·install·-y
 0003b7c0:·2022·6169·6465·220a·6669·0a0a·656c·7365···"aide".fi..else
 0003b7d0:·0a20·2020·2026·6774·3b26·616d·703b·3220··.····&gt;&amp;2·
 0003b7e0:·6563·686f·2027·5265·6d65·6469·6174·696f··echo·'Remediatio
 0003b7f0:·6e20·6973·206e·6f74·2061·7070·6c69·6361··n·is·not·applica
 0003b800:·626c·652c·206e·6f74·6869·6e67·2077·6173··ble,·nothing·was
 0003b810:·2064·6f6e·6527·0a66·690a·3c2f·636f·6465···done'.fi.</code
 0003b820:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a·
 0003b830:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s
 0003b840:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog
 0003b850:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d
 0003b860:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
 0003b870:·3531·3031·2220·7461·6269·6e64·6578·3d22··5101"·tabindex="
 0003b880:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
 0003b890:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
 0003b8a0:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
 0003b8b0:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
 0003b8c0:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
0003b220:·6469·6174·696f·6e20·416e·6163·6f6e·6461··diation·Anaconda0003b8d0:·6469·6174·696f·6e20·416e·6163·6f6e·6461··diation·Anaconda
0003b230:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>0003b8e0:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>
0003b240:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="0003b8f0:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="
0003b250:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c0003b900:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c
0003b260:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm0003b910:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm
0003b270:·3530·3938·223e·3c74·6162·6c65·2063·6c61··5098"><table·cla0003b920:·3531·3031·223e·3c74·6162·6c65·2063·6c61··5101"><table·cla
0003b280:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-0003b930:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-
0003b290:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo0003b940:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo
0003b2a0:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con0003b950:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con
0003b2b0:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th> 
0003b2c0:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th> 
0003b2d0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
0003b2e0:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt 
Max diff block lines reached; 664362/682882 bytes (97.29%) of diff not shown.
54.6 KB
html2text {}
    
Offset 153, 21 lines modifiedOffset 153, 14 lines modified
153 ··-·PCI-DSSv4-11.5.2153 ··-·PCI-DSSv4-11.5.2
154 ··-·enable_strategy154 ··-·enable_strategy
155 ··-·low_complexity155 ··-·low_complexity
156 ··-·low_disruption156 ··-·low_disruption
157 ··-·medium_severity157 ··-·medium_severity
158 ··-·no_reboot_needed158 ··-·no_reboot_needed
159 ··-·package_aide_installed159 ··-·package_aide_installed
160 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
161 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
162 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
163 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
164 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
165 package·--add=aide 
166 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8160 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
167 [[packages]]161 [[packages]]
168 name·=·"aide"162 name·=·"aide"
169 version·=·"*"163 version·=·"*"
170 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8164 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
171 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low165 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 192, 14 lines modifiedOffset 185, 21 lines modified
192 if·!·rpm·-q·--quiet·"aide"·;·then185 if·!·rpm·-q·--quiet·"aide"·;·then
193 ····dnf·install·-y·"aide"186 ····dnf·install·-y·"aide"
194 fi187 fi
  
195 else188 else
196 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'189 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
197 fi190 fi
 191 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 192 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 193 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 194 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 195 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 196 package·--add=aide
198 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*197 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
199 Run·the·following·command·to·generate·a·new·database:198 Run·the·following·command·to·generate·a·new·database:
200 $·sudo·/usr/sbin/aide·--init199 $·sudo·/usr/sbin/aide·--init
201 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the200 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the
202 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these201 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these
203 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their202 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their
204 integrity.·The·newly-generated·database·can·be·installed·as·follows:203 integrity.·The·newly-generated·database·can·be·installed·as·follows:
Offset 1121, 21 lines modifiedOffset 1121, 14 lines modified
1121 ··tags:1121 ··tags:
1122 ··-·enable_strategy1122 ··-·enable_strategy
1123 ··-·low_complexity1123 ··-·low_complexity
1124 ··-·low_disruption1124 ··-·low_disruption
1125 ··-·low_severity1125 ··-·low_severity
1126 ··-·no_reboot_needed1126 ··-·no_reboot_needed
1127 ··-·systemd_tmp_mount_enabled1127 ··-·systemd_tmp_mount_enabled
1128 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
1129 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
1130 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
1131 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
1132 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
1133 services·--enabled=tmp.mount 
1134 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81128 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1135 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1129 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1136 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1130 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1137 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1131 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1138 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1132 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1139 #·Remediation·is·applicable·only·in·certain·platforms1133 #·Remediation·is·applicable·only·in·certain·platforms
1140 if·(·!·(·{·rpm·--quiet·-q·kernel·;}·&&·{·rpm·--quiet·-q·rpm-ostree·;}·&&·{·rpm·--quiet·-q·bootc·;}·&&1134 if·(·!·(·{·rpm·--quiet·-q·kernel·;}·&&·{·rpm·--quiet·-q·rpm-ostree·;}·&&·{·rpm·--quiet·-q·bootc·;}·&&
Offset 1148, 14 lines modifiedOffset 1141, 21 lines modified
1148 ··"$SYSTEMCTL_EXEC"·start·'tmp.mount'1141 ··"$SYSTEMCTL_EXEC"·start·'tmp.mount'
1149 fi1142 fi
1150 "$SYSTEMCTL_EXEC"·enable·'tmp.mount'1143 "$SYSTEMCTL_EXEC"·enable·'tmp.mount'
  
1151 else1144 else
1152 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'1145 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
1153 fi1146 fi
 1147 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 1148 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1149 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1150 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1151 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 1152 services·--enabled=tmp.mount
1154 Group  ·Sudo·  Group·contains·17·rules1153 Group  ·Sudo·  Group·contains·17·rules
1155 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Sudo,·which·stands·for·"su·'do'",·provides·the·ability·to·delegate·authority·to·certain1154 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Sudo,·which·stands·for·"su·'do'",·provides·the·ability·to·delegate·authority·to·certain
1156 users,·groups·of·users,·or·system·administrators.·When·configured·for·system·users·and/or·groups,1155 users,·groups·of·users,·or·system·administrators.·When·configured·for·system·users·and/or·groups,
1157 Sudo·can·allow·a·user·or·group·to·execute·privileged·commands·that·normally·only·root·is·allowed·to1156 Sudo·can·allow·a·user·or·group·to·execute·privileged·commands·that·normally·only·root·is·allowed·to
1158 execute.1157 execute.
  
1159 For·more·information·on·Sudo·and·addition·Sudo·configuration·options,·see·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8w\x8w_\x8w\x8w_\x8w\x8w_\x8.\x8._\x8s\x8s_\x8u\x8u_\x8d\x8d_\x8o\x8o_\x8.\x8._\x8w\x8w_\x8s\x8s.1158 For·more·information·on·Sudo·and·addition·Sudo·configuration·options,·see·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8w\x8w_\x8w\x8w_\x8w\x8w_\x8.\x8._\x8s\x8s_\x8u\x8u_\x8d\x8d_\x8o\x8o_\x8.\x8._\x8w\x8w_\x8s\x8s.
Offset 1204, 21 lines modifiedOffset 1204, 14 lines modified
1204 ··-·PCI-DSSv4-2.2.61204 ··-·PCI-DSSv4-2.2.6
1205 ··-·enable_strategy1205 ··-·enable_strategy
1206 ··-·low_complexity1206 ··-·low_complexity
1207 ··-·low_disruption1207 ··-·low_disruption
1208 ··-·medium_severity1208 ··-·medium_severity
1209 ··-·no_reboot_needed1209 ··-·no_reboot_needed
1210 ··-·package_sudo_installed1210 ··-·package_sudo_installed
1211 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
1212 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
1213 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
1214 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
1215 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
1216 package·--add=sudo 
1217 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81211 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
1218 [[packages]]1212 [[packages]]
1219 name·=·"sudo"1213 name·=·"sudo"
1220 version·=·"*"1214 version·=·"*"
1221 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81215 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1222 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1216 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 1243, 14 lines modifiedOffset 1236, 21 lines modified
1243 if·!·rpm·-q·--quiet·"sudo"·;·then1236 if·!·rpm·-q·--quiet·"sudo"·;·then
1244 ····dnf·install·-y·"sudo"1237 ····dnf·install·-y·"sudo"
1245 fi1238 fi
  
1246 else1239 else
1247 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'1240 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
1248 fi1241 fi
 1242 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 1243 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1244 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1245 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1246 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 1247 package·--add=sudo
1249 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·G\x8Gr\x8ro\x8ou\x8up\x8p·W\x8Wh\x8ho\x8o·O\x8Ow\x8wn\x8ns\x8s·/\x8/e\x8et\x8tc\x8c/\x8/s\x8su\x8ud\x8do\x8oe\x8er\x8rs\x8s.\x8.d\x8d·D\x8Di\x8ir\x8re\x8ec\x8ct\x8to\x8or\x8ry\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*1248 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·G\x8Gr\x8ro\x8ou\x8up\x8p·W\x8Wh\x8ho\x8o·O\x8Ow\x8wn\x8ns\x8s·/\x8/e\x8et\x8tc\x8c/\x8/s\x8su\x8ud\x8do\x8oe\x8er\x8rs\x8s.\x8.d\x8d·D\x8Di\x8ir\x8re\x8ec\x8ct\x8to\x8or\x8ry\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
1250 To·properly·set·the·group·owner·of·/etc/sudoers.d,·run·the·command:1249 To·properly·set·the·group·owner·of·/etc/sudoers.d,·run·the·command:
1251 $·sudo·chgrp·root·/etc/sudoers.d1250 $·sudo·chgrp·root·/etc/sudoers.d
Max diff block lines reached; 50799/55932 bytes (90.82%) of diff not shown.
599 KB
./usr/share/doc/ssg-nondebian/ssg-ol10-guide-anssi_bp28_intermediary.html
    
Offset 15123, 143 lines modifiedOffset 15123, 143 lines modified
0003b120:·7267·6574·3d22·2369·646d·3530·3938·2220··rget="#idm5098"·0003b120:·7267·6574·3d22·2369·646d·3530·3938·2220··rget="#idm5098"·
0003b130:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol0003b130:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol
0003b140:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-0003b140:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-
0003b150:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"0003b150:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"
0003b160:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate0003b160:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate
0003b170:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href0003b170:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href
0003b180:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio0003b180:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio
 0003b190:·6e20·4f53·4275·696c·6420·426c·7565·7072··n·OSBuild·Bluepr
 0003b1a0:·696e·7420·736e·6970·7065·7420·e287·b23c··int·snippet·...<
 0003b1b0:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas
 0003b1c0:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps
 0003b1d0:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="
 0003b1e0:·6964·6d35·3039·3822·3e3c·7072·653e·3c63··idm5098"><pre><c
 0003b1f0:·6f64·653e·0a5b·5b70·6163·6b61·6765·735d··ode>.[[packages]
 0003b200:·5d0a·6e61·6d65·203d·2022·6169·6465·220a··].name·=·"aide".
 0003b210:·7665·7273·696f·6e20·3d20·222a·220a·3c2f··version·=·"*".</
 0003b220:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div
 0003b230:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b
 0003b240:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data
 0003b250:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps
 0003b260:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
 0003b270:·2369·646d·3530·3939·2220·7461·6269·6e64··#idm5099"·tabind
 0003b280:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
 0003b290:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
 0003b2a0:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
 0003b2b0:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
 0003b2c0:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
 0003b2d0:·5265·6d65·6469·6174·696f·6e20·5075·7070··Remediation·Pupp
 0003b2e0:·6574·2073·6e69·7070·6574·20e2·87b2·3c2f··et·snippet·...</
 0003b2f0:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
 0003b300:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
 0003b310:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
 0003b320:·646d·3530·3939·223e·3c74·6162·6c65·2063··dm5099"><table·c
 0003b330:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl
 0003b340:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-
 0003b350:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c
 0003b360:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t
 0003b370:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t
 0003b380:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
 0003b390:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru
 0003b3a0:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l
 0003b3b0:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
 0003b3c0:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th>
 0003b3d0:·3c74·643e·6661·6c73·653c·2f74·643e·3c2f··<td>false</td></
 0003b3e0:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat
 0003b3f0:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena
 0003b400:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t
 0003b410:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>
 0003b420:·696e·636c·7564·6520·696e·7374·616c·6c5f··include·install_
 0003b430:·6169·6465·0a0a·636c·6173·7320·696e·7374··aide..class·inst
 0003b440:·616c·6c5f·6169·6465·207b·0a20·2070·6163··all_aide·{.··pac
 0003b450:·6b61·6765·207b·2027·6169·6465·273a·0a20··kage·{·'aide':.·
 0003b460:·2020·2065·6e73·7572·6520·3d26·6774·3b20·····ensure·=&gt;·
 0003b470:·2769·6e73·7461·6c6c·6564·272c·0a20·207d··'installed',.··}
 0003b480:·0a7d·0a3c·2f63·6f64·653e·3c2f·7072·653e··.}.</code></pre>
 0003b490:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class="
 0003b4a0:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success"
 0003b4b0:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co
 0003b4c0:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar
 0003b4d0:·6765·743d·2223·6964·6d35·3130·3022·2074··get="#idm5100"·t
 0003b4e0:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
 0003b4f0:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
 0003b500:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
 0003b510:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
 0003b520:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
 0003b530:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
 0003b540:·2053·6865·6c6c·2073·6372·6970·7420·e287···Shell·script·..
 0003b550:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl
 0003b560:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla
 0003b570:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id
 0003b580:·3d22·6964·6d35·3130·3022·3e3c·7461·626c··="idm5100"><tabl
 0003b590:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t
 0003b5a0:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab
 0003b5b0:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl
 0003b5c0:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr
 0003b5d0:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:
 0003b5e0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
 0003b5f0:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di
 0003b600:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t
 0003b610:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
 0003b620:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</
 0003b630:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td
 0003b640:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St
 0003b650:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>
 0003b660:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr>
 0003b670:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co
 0003b680:·6465·3e23·2052·656d·6564·6961·7469·6f6e··de>#·Remediation
 0003b690:·2069·7320·6170·706c·6963·6162·6c65·206f···is·applicable·o
 0003b6a0:·6e6c·7920·696e·2063·6572·7461·696e·2070··nly·in·certain·p
 0003b6b0:·6c61·7466·6f72·6d73·0a69·6620·7270·6d20··latforms.if·rpm·
 0003b6c0:·2d2d·7175·6965·7420·2d71·206b·6572·6e65··--quiet·-q·kerne
 0003b6d0:·6c20·7c7c·2072·706d·202d·2d71·7569·6574··l·||·rpm·--quiet
 0003b6e0:·202d·7120·6b65·726e·656c·2d75·656b·3b20···-q·kernel-uek;·
 0003b6f0:·7468·656e·0a0a·6966·2021·2072·706d·202d··then..if·!·rpm·-
 0003b700:·7120·2d2d·7175·6965·7420·2261·6964·6522··q·--quiet·"aide"
 0003b710:·203b·2074·6865·6e0a·2020·2020·646e·6620···;·then.····dnf·
 0003b720:·696e·7374·616c·6c20·2d79·2022·6169·6465··install·-y·"aide
 0003b730:·220a·6669·0a0a·656c·7365·0a20·2020·2026··".fi..else.····&
 0003b740:·6774·3b26·616d·703b·3220·6563·686f·2027··gt;&amp;2·echo·'
 0003b750:·5265·6d65·6469·6174·696f·6e20·6973·206e··Remediation·is·n
 0003b760:·6f74·2061·7070·6c69·6361·626c·652c·206e··ot·applicable,·n
 0003b770:·6f74·6869·6e67·2077·6173·2064·6f6e·6527··othing·was·done'
 0003b780:·0a66·690a·3c2f·636f·6465·3e3c·2f70·7265··.fi.</code></pre
 0003b790:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class=
 0003b7a0:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success
 0003b7b0:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c
 0003b7c0:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta
 0003b7d0:·7267·6574·3d22·2369·646d·3531·3031·2220··rget="#idm5101"·
 0003b7e0:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol
 0003b7f0:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-
 0003b800:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"
 0003b810:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate
 0003b820:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href
 0003b830:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio
0003b190:·6e20·416e·6163·6f6e·6461·2073·6e69·7070··n·Anaconda·snipp0003b840:·6e20·416e·6163·6f6e·6461·2073·6e69·7070··n·Anaconda·snipp
0003b1a0:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d 
0003b1b0:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel- 
0003b1c0:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps 
0003b1d0:·6522·2069·643d·2269·646d·3530·3938·223e··e"·id="idm5098"> 
0003b1e0:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta 
0003b1f0:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe 
0003b200:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered 
0003b210:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed 
0003b220:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple 
0003b230:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo 
0003b240:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr>< 
0003b250:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</ 
Max diff block lines reached; 550129/568511 bytes (96.77%) of diff not shown.
43.9 KB
html2text {}
    
Offset 151, 21 lines modifiedOffset 151, 14 lines modified
151 ··-·PCI-DSSv4-11.5.2151 ··-·PCI-DSSv4-11.5.2
152 ··-·enable_strategy152 ··-·enable_strategy
153 ··-·low_complexity153 ··-·low_complexity
154 ··-·low_disruption154 ··-·low_disruption
155 ··-·medium_severity155 ··-·medium_severity
156 ··-·no_reboot_needed156 ··-·no_reboot_needed
157 ··-·package_aide_installed157 ··-·package_aide_installed
158 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
159 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
160 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
161 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
162 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
163 package·--add=aide 
164 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8158 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
165 [[packages]]159 [[packages]]
166 name·=·"aide"160 name·=·"aide"
167 version·=·"*"161 version·=·"*"
168 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8162 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
169 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low163 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 190, 14 lines modifiedOffset 183, 21 lines modified
190 if·!·rpm·-q·--quiet·"aide"·;·then183 if·!·rpm·-q·--quiet·"aide"·;·then
191 ····dnf·install·-y·"aide"184 ····dnf·install·-y·"aide"
192 fi185 fi
  
193 else186 else
194 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'187 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
195 fi188 fi
 189 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 190 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 191 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 192 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 193 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 194 package·--add=aide
196 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*195 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
197 Run·the·following·command·to·generate·a·new·database:196 Run·the·following·command·to·generate·a·new·database:
198 $·sudo·/usr/sbin/aide·--init197 $·sudo·/usr/sbin/aide·--init
199 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the198 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the
200 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these199 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these
201 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their200 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their
202 integrity.·The·newly-generated·database·can·be·installed·as·follows:201 integrity.·The·newly-generated·database·can·be·installed·as·follows:
Offset 549, 21 lines modifiedOffset 549, 14 lines modified
549 ··tags:549 ··tags:
550 ··-·enable_strategy550 ··-·enable_strategy
551 ··-·low_complexity551 ··-·low_complexity
552 ··-·low_disruption552 ··-·low_disruption
553 ··-·low_severity553 ··-·low_severity
554 ··-·no_reboot_needed554 ··-·no_reboot_needed
555 ··-·systemd_tmp_mount_enabled555 ··-·systemd_tmp_mount_enabled
556 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
557 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
558 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
559 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
560 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
561 services·--enabled=tmp.mount 
562 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8556 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
563 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low557 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
564 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low558 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
565 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false559 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
566 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable560 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
567 #·Remediation·is·applicable·only·in·certain·platforms561 #·Remediation·is·applicable·only·in·certain·platforms
568 if·(·!·(·{·rpm·--quiet·-q·kernel·;}·&&·{·rpm·--quiet·-q·rpm-ostree·;}·&&·{·rpm·--quiet·-q·bootc·;}·&&562 if·(·!·(·{·rpm·--quiet·-q·kernel·;}·&&·{·rpm·--quiet·-q·rpm-ostree·;}·&&·{·rpm·--quiet·-q·bootc·;}·&&
Offset 576, 14 lines modifiedOffset 569, 21 lines modified
576 ··"$SYSTEMCTL_EXEC"·start·'tmp.mount'569 ··"$SYSTEMCTL_EXEC"·start·'tmp.mount'
577 fi570 fi
578 "$SYSTEMCTL_EXEC"·enable·'tmp.mount'571 "$SYSTEMCTL_EXEC"·enable·'tmp.mount'
  
579 else572 else
580 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'573 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
581 fi574 fi
 575 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 576 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 577 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 578 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 579 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 580 services·--enabled=tmp.mount
582 Group  ·Sudo·  Group·contains·15·rules581 Group  ·Sudo·  Group·contains·15·rules
583 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Sudo,·which·stands·for·"su·'do'",·provides·the·ability·to·delegate·authority·to·certain582 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Sudo,·which·stands·for·"su·'do'",·provides·the·ability·to·delegate·authority·to·certain
584 users,·groups·of·users,·or·system·administrators.·When·configured·for·system·users·and/or·groups,583 users,·groups·of·users,·or·system·administrators.·When·configured·for·system·users·and/or·groups,
585 Sudo·can·allow·a·user·or·group·to·execute·privileged·commands·that·normally·only·root·is·allowed·to584 Sudo·can·allow·a·user·or·group·to·execute·privileged·commands·that·normally·only·root·is·allowed·to
586 execute.585 execute.
  
587 For·more·information·on·Sudo·and·addition·Sudo·configuration·options,·see·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8w\x8w_\x8w\x8w_\x8w\x8w_\x8.\x8._\x8s\x8s_\x8u\x8u_\x8d\x8d_\x8o\x8o_\x8.\x8._\x8w\x8w_\x8s\x8s.586 For·more·information·on·Sudo·and·addition·Sudo·configuration·options,·see·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8w\x8w_\x8w\x8w_\x8w\x8w_\x8.\x8._\x8s\x8s_\x8u\x8u_\x8d\x8d_\x8o\x8o_\x8.\x8._\x8w\x8w_\x8s\x8s.
Offset 632, 21 lines modifiedOffset 632, 14 lines modified
632 ··-·PCI-DSSv4-2.2.6632 ··-·PCI-DSSv4-2.2.6
633 ··-·enable_strategy633 ··-·enable_strategy
634 ··-·low_complexity634 ··-·low_complexity
635 ··-·low_disruption635 ··-·low_disruption
636 ··-·medium_severity636 ··-·medium_severity
637 ··-·no_reboot_needed637 ··-·no_reboot_needed
638 ··-·package_sudo_installed638 ··-·package_sudo_installed
639 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
640 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
641 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
642 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
643 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
644 package·--add=sudo 
645 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8639 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
646 [[packages]]640 [[packages]]
647 name·=·"sudo"641 name·=·"sudo"
648 version·=·"*"642 version·=·"*"
649 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8643 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
650 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low644 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 671, 14 lines modifiedOffset 664, 21 lines modified
671 if·!·rpm·-q·--quiet·"sudo"·;·then664 if·!·rpm·-q·--quiet·"sudo"·;·then
672 ····dnf·install·-y·"sudo"665 ····dnf·install·-y·"sudo"
673 fi666 fi
  
674 else667 else
675 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'668 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
676 fi669 fi
 670 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 671 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 672 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 673 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 674 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 675 package·--add=sudo
677 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·G\x8Gr\x8ro\x8ou\x8up\x8p·W\x8Wh\x8ho\x8o·O\x8Ow\x8wn\x8ns\x8s·/\x8/e\x8et\x8tc\x8c/\x8/s\x8su\x8ud\x8do\x8oe\x8er\x8rs\x8s.\x8.d\x8d·D\x8Di\x8ir\x8re\x8ec\x8ct\x8to\x8or\x8ry\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*676 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·G\x8Gr\x8ro\x8ou\x8up\x8p·W\x8Wh\x8ho\x8o·O\x8Ow\x8wn\x8ns\x8s·/\x8/e\x8et\x8tc\x8c/\x8/s\x8su\x8ud\x8do\x8oe\x8er\x8rs\x8s.\x8.d\x8d·D\x8Di\x8ir\x8re\x8ec\x8ct\x8to\x8or\x8ry\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
678 To·properly·set·the·group·owner·of·/etc/sudoers.d,·run·the·command:677 To·properly·set·the·group·owner·of·/etc/sudoers.d,·run·the·command:
679 $·sudo·chgrp·root·/etc/sudoers.d678 $·sudo·chgrp·root·/etc/sudoers.d
Max diff block lines reached; 39839/44964 bytes (88.60%) of diff not shown.
111 KB
./usr/share/doc/ssg-nondebian/ssg-ol10-guide-anssi_bp28_minimal.html
    
Offset 14808, 154 lines modifiedOffset 14808, 154 lines modified
00039d70:·7267·6574·3d22·2369·646d·3831·3237·2220··rget="#idm8127"·00039d70:·7267·6574·3d22·2369·646d·3831·3237·2220··rget="#idm8127"·
00039d80:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol00039d80:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol
00039d90:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-00039d90:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-
00039da0:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"00039da0:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"
00039db0:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate00039db0:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate
00039dc0:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href00039dc0:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href
00039dd0:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio00039dd0:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio
 00039de0:·6e20·4f53·4275·696c·6420·426c·7565·7072··n·OSBuild·Bluepr
 00039df0:·696e·7420·736e·6970·7065·7420·e287·b23c··int·snippet·...<
 00039e00:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas
 00039e10:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps
 00039e20:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="
 00039e30:·6964·6d38·3132·3722·3e3c·7072·653e·3c63··idm8127"><pre><c
00039de0:·6e20·416e·6163·6f6e·6461·2073·6e69·7070··n·Anaconda·snipp 
00039df0:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d 
00039e00:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel- 
00039e10:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps 
00039e20:·6522·2069·643d·2269·646d·3831·3237·223e··e"·id="idm8127"> 
00039e30:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta 
00039e40:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe 
00039e50:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered 
00039e60:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed 
00039e70:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple 
00039e80:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo 
00039e90:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr>< 
00039ea0:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</ 
00039eb0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td>< 
00039ec0:·2f74·723e·3c74·723e·3c74·683e·5265·626f··/tr><tr><th>Rebo 
00039ed0:·6f74·3a3c·2f74·683e·3c74·643e·6661·6c73··ot:</th><td>fals 
00039ee0:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr>< 
00039ef0:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th 
00039f00:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td> 
00039f10:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr 
00039f20:·653e·3c63·6f64·653e·0a70·6163·6b61·6765··e><code>.package00039e40:·6f64·653e·0a5b·5b70·6163·6b61·6765·735d··ode>.[[packages]
00039f30:·202d·2d61·6464·3d64·6e66·2d61·7574·6f6d···--add=dnf-autom 
00039f40:·6174·6963·0a3c·2f63·6f64·653e·3c2f·7072··atic.</code></pr00039e50:·5d0a·6e61·6d65·203d·2022·646e·662d·6175··].name·=·"dnf-au
 00039e60:·746f·6d61·7469·6322·0a76·6572·7369·6f6e··tomatic".version
 00039e70:·203d·2022·2a22·0a3c·2f63·6f64·653e·3c2f···=·"*".</code></
00039f50:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class00039e80:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla
00039f60:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes00039e90:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ
00039f70:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle="00039ea0:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle
00039f80:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t00039eb0:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data
00039f90:·6172·6765·743d·2223·6964·6d38·3132·3822··arget="#idm8128"00039ec0:·2d74·6172·6765·743d·2223·6964·6d38·3132··-target="#idm812
00039fa0:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro00039ed0:·3822·2074·6162·696e·6465·783d·2230·2220··8"·tabindex="0"·
00039fb0:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria00039ee0:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar
00039fc0:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false00039ef0:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal
00039fd0:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat00039f00:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ
00039fe0:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre00039f10:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h
00039ff0:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati00039f20:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia
 00039f30:·7469·6f6e·2050·7570·7065·7420·736e·6970··tion·Puppet·snip
 00039f40:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br><
 00039f50:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
 00039f60:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap
 00039f70:·7365·2220·6964·3d22·6964·6d38·3132·3822··se"·id="idm8128"
 00039f80:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t
 00039f90:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip
0003a000:·6f6e·204f·5342·7569·6c64·2042·6c75·6570··on·OSBuild·Bluep 
0003a010:·7269·6e74·2073·6e69·7070·6574·20e2·87b2··rint·snippet·... 
0003a020:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla 
0003a030:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap 
0003a040:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id= 
0003a050:·2269·646d·3831·3238·223e·3c70·7265·3e3c··"idm8128"><pre>< 
0003a060:·636f·6465·3e0a·5b5b·7061·636b·6167·6573··code>.[[packages 
0003a070:·5d5d·0a6e·616d·6520·3d20·2264·6e66·2d61··]].name·=·"dnf-a 
0003a080:·7574·6f6d·6174·6963·220a·7665·7273·696f··utomatic".versio 
0003a090:·6e20·3d20·222a·220a·3c2f·636f·6465·3e3c··n·=·"*".</code>< 
0003a0a0:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl 
0003a0b0:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc 
0003a0c0:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl 
0003a0d0:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat 
0003a0e0:·612d·7461·7267·6574·3d22·2369·646d·3831··a-target="#idm81 
0003a0f0:·3239·2220·7461·6269·6e64·6578·3d22·3022··29"·tabindex="0" 
0003a100:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a 
0003a110:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa 
0003a120:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti 
0003a130:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"· 
0003a140:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi 
0003a150:·6174·696f·6e20·5075·7070·6574·2073·6e69··ation·Puppet·sni 
0003a160:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br> 
0003a170:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane 
0003a180:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla 
0003a190:·7073·6522·2069·643d·2269·646d·3831·3239··pse"·id="idm8129 
0003a1a0:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class=" 
0003a1b0:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri 
0003a1c0:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border 
0003a1d0:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens00039fa0:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere
 00039fb0:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense
 00039fc0:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl
 00039fd0:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l
 00039fe0:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
 00039ff0:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:<
 0003a000:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
 0003a010:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb
 0003a020:·6f6f·743a·3c2f·7468·3e3c·7464·3e66·616c··oot:</th><td>fal
 0003a030:·7365·3c2f·7464·3e3c·2f74·723e·3c74·723e··se</td></tr><tr>
 0003a040:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t
 0003a050:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td
 0003a060:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p
 0003a070:·7265·3e3c·636f·6465·3e69·6e63·6c75·6465··re><code>include
0003a1e0:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp 
0003a1f0:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td> 
0003a200:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr 
0003a210:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption: 
0003a220:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td 
0003a230:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re 
0003a240:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa 
0003a250:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr 
0003a260:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</ 
0003a270:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t 
0003a280:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table>< 
0003a290:·7072·653e·3c63·6f64·653e·696e·636c·7564··pre><code>includ 
0003a2a0:·6520·696e·7374·616c·6c5f·646e·662d·6175··e·install_dnf-au 
0003a2b0:·746f·6d61·7469·630a·0a63·6c61·7373·2069··tomatic..class·i 
0003a2c0:·6e73·7461·6c6c·5f64·6e66·2d61·7574·6f6d··nstall_dnf-autom0003a080:·2069·6e73·7461·6c6c·5f64·6e66·2d61·7574···install_dnf-aut
0003a2d0:·6174·6963·207b·0a20·2070·6163·6b61·6765··atic·{.··package 
0003a2e0:·207b·2027·646e·662d·6175·746f·6d61·7469···{·'dnf-automati 
0003a2f0:·6327·3a0a·2020·2020·656e·7375·7265·203d··c':.····ensure·= 
0003a300:·2667·743b·2027·696e·7374·616c·6c65·6427··&gt;·'installed' 
0003a310:·2c0a·2020·7d0a·7d0a·3c2f·636f·6465·3e3c··,.··}.}.</code>< 
0003a320:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl 
0003a330:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc 
0003a340:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl 
0003a350:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat 
0003a360:·612d·7461·7267·6574·3d22·2369·646d·3831··a-target="#idm81 
0003a370:·3330·2220·7461·6269·6e64·6578·3d22·3022··30"·tabindex="0" 
0003a380:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a 
0003a390:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa 
Max diff block lines reached; 82940/102840 bytes (80.65%) of diff not shown.
10.3 KB
html2text {}
    
Offset 114, 21 lines modifiedOffset 114, 14 lines modified
114 ··tags:114 ··tags:
115 ··-·enable_strategy115 ··-·enable_strategy
116 ··-·low_complexity116 ··-·low_complexity
117 ··-·low_disruption117 ··-·low_disruption
118 ··-·medium_severity118 ··-·medium_severity
119 ··-·no_reboot_needed119 ··-·no_reboot_needed
120 ··-·package_dnf-automatic_installed120 ··-·package_dnf-automatic_installed
121 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
122 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
123 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
124 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
125 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
126 package·--add=dnf-automatic 
127 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8121 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
128 [[packages]]122 [[packages]]
129 name·=·"dnf-automatic"123 name·=·"dnf-automatic"
130 version·=·"*"124 version·=·"*"
131 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8125 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
132 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low126 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 154, 14 lines modifiedOffset 147, 21 lines modified
154 if·!·rpm·-q·--quiet·"dnf-automatic"·;·then147 if·!·rpm·-q·--quiet·"dnf-automatic"·;·then
155 ····dnf·install·-y·"dnf-automatic"148 ····dnf·install·-y·"dnf-automatic"
156 fi149 fi
  
157 else150 else
158 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'151 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
159 fi152 fi
 153 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 154 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 155 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 156 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 157 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 158 package·--add=dnf-automatic
160 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·d\x8dn\x8nf\x8f-\x8-a\x8au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8c·t\x8to\x8o·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·A\x8Av\x8va\x8ai\x8il\x8la\x8ab\x8bl\x8le\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8es\x8s·A\x8Au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8ca\x8al\x8ll\x8ly\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*159 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·d\x8dn\x8nf\x8f-\x8-a\x8au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8c·t\x8to\x8o·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·A\x8Av\x8va\x8ai\x8il\x8la\x8ab\x8bl\x8le\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8es\x8s·A\x8Au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8ca\x8al\x8ll\x8ly\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
161 To·ensure·that·the·packages·comprising·the·available·updates·will·be·automatically·installed160 To·ensure·that·the·packages·comprising·the·available·updates·will·be·automatically·installed
162 by·dnf-automatic,·set·apply_updates·to·yes·under·[commands]·section·in·/etc/dnf/161 by·dnf-automatic,·set·apply_updates·to·yes·under·[commands]·section·in·/etc/dnf/
163 automatic.conf.162 automatic.conf.
164 ············Installing·software·updates·is·a·fundamental·mitigation·against·the·exploitation163 ············Installing·software·updates·is·a·fundamental·mitigation·against·the·exploitation
165 ············of·publicly-known·vulnerabilities.·If·the·most·recent·security·patches·and164 ············of·publicly-known·vulnerabilities.·If·the·most·recent·security·patches·and
166 Rationale:··updates·are·not·installed,·unauthorized·users·may·take·advantage·of·weaknesses·in165 Rationale:··updates·are·not·installed,·unauthorized·users·may·take·advantage·of·weaknesses·in
Offset 10883, 21 lines modifiedOffset 10883, 14 lines modified
10883 ··tags:10883 ··tags:
10884 ··-·disable_strategy10884 ··-·disable_strategy
10885 ··-·low_complexity10885 ··-·low_complexity
10886 ··-·low_disruption10886 ··-·low_disruption
10887 ··-·medium_severity10887 ··-·medium_severity
10888 ··-·no_reboot_needed10888 ··-·no_reboot_needed
10889 ··-·package_kea_removed10889 ··-·package_kea_removed
10890 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
10891 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
10892 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
10893 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
10894 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable 
  
10895 package·--remove=kea 
10896 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x810890 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
10897 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low10891 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
10898 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low10892 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
10899 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false10893 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
10900 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable10894 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
10901 include·remove_kea10895 include·remove_kea
  
Offset 10917, 14 lines modifiedOffset 10910, 21 lines modified
10917 #»      ···that·depend·on·kea.·Execute·this10910 #»      ···that·depend·on·kea.·Execute·this
10918 #»      ···remediation·AFTER·testing·on·a·non-production10911 #»      ···remediation·AFTER·testing·on·a·non-production
10919 #»      ···system!10912 #»      ···system!
  
10920 if·rpm·-q·--quiet·"kea"·;·then10913 if·rpm·-q·--quiet·"kea"·;·then
10921 dnf·remove·-y·--noautoremove·"kea"10914 dnf·remove·-y·--noautoremove·"kea"
10922 fi10915 fi
 10916 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 10917 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 10918 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 10919 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 10920 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
  
 10921 package·--remove=kea
10923 Group  ·Obsolete·Services·  Group·contains·2·groups·and·4·rules10922 Group  ·Obsolete·Services·  Group·contains·2·groups·and·4·rules
10924 _\x8[_\x8r_\x8e_\x8f_\x8]  ·This·section·discusses·a·number·of·network-visible·services·which·have·historically10923 _\x8[_\x8r_\x8e_\x8f_\x8]  ·This·section·discusses·a·number·of·network-visible·services·which·have·historically
10925 caused·problems·for·system·security,·and·for·which·disabling·or·severely·limiting·the·service10924 caused·problems·for·system·security,·and·for·which·disabling·or·severely·limiting·the·service
10926 has·been·the·best·available·guidance·for·some·time.·As·a·result·of·this,·many·of·these10925 has·been·the·best·available·guidance·for·some·time.·As·a·result·of·this,·many·of·these
10927 services·are·not·installed·as·part·of·Oracle·Linux·10·by·default.10926 services·are·not·installed·as·part·of·Oracle·Linux·10·by·default.
  
10928 Organizations·which·are·running·these·services·should·switch·to·more·secure·equivalents·as10927 Organizations·which·are·running·these·services·should·switch·to·more·secure·equivalents·as
Offset 10992, 21 lines modifiedOffset 10992, 14 lines modified
10992 ··-·PCI-DSSv4-2.2.410992 ··-·PCI-DSSv4-2.2.4
10993 ··-·disable_strategy10993 ··-·disable_strategy
10994 ··-·high_severity10994 ··-·high_severity
10995 ··-·low_complexity10995 ··-·low_complexity
10996 ··-·low_disruption10996 ··-·low_disruption
10997 ··-·no_reboot_needed10997 ··-·no_reboot_needed
10998 ··-·package_telnet-server_removed10998 ··-·package_telnet-server_removed
10999 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
11000 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
11001 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
11002 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
11003 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable 
  
11004 package·--remove=telnet-server 
11005 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x810999 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
11006 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low11000 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
11007 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low11001 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
11008 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false11002 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
11009 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable11003 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
11010 include·remove_telnet-server11004 include·remove_telnet-server
  
Offset 11026, 14 lines modifiedOffset 11019, 21 lines modified
11026 #»      ···that·depend·on·telnet-server.·Execute·this11019 #»      ···that·depend·on·telnet-server.·Execute·this
11027 #»      ···remediation·AFTER·testing·on·a·non-production11020 #»      ···remediation·AFTER·testing·on·a·non-production
11028 #»      ···system!11021 #»      ···system!
  
11029 if·rpm·-q·--quiet·"telnet-server"·;·then11022 if·rpm·-q·--quiet·"telnet-server"·;·then
11030 dnf·remove·-y·--noautoremove·"telnet-server"11023 dnf·remove·-y·--noautoremove·"telnet-server"
11031 fi11024 fi
 11025 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 11026 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 11027 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 11028 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 11029 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
  
 11030 package·--remove=telnet-server
11032 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·R\x8Re\x8em\x8mo\x8ov\x8ve\x8e·t\x8te\x8el\x8ln\x8ne\x8et\x8t·C\x8Cl\x8li\x8ie\x8en\x8nt\x8ts\x8s·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*11031 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·R\x8Re\x8em\x8mo\x8ov\x8ve\x8e·t\x8te\x8el\x8ln\x8ne\x8et\x8t·C\x8Cl\x8li\x8ie\x8en\x8nt\x8ts\x8s·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
11033 The·telnet·client·allows·users·to·start·connections·to·other·systems·via·the·telnet·protocol.11032 The·telnet·client·allows·users·to·start·connections·to·other·systems·via·the·telnet·protocol.
11034 ············The·telnet·protocol·is·insecure·and·unencrypted.·The·use·of·an·unencrypted11033 ············The·telnet·protocol·is·insecure·and·unencrypted.·The·use·of·an·unencrypted
Max diff block lines reached; 5250/10495 bytes (50.02%) of diff not shown.
126 KB
./usr/share/doc/ssg-nondebian/ssg-ol10-guide-e8.html
    
Offset 24444, 145 lines modifiedOffset 24444, 145 lines modified
0005f7b0:·7267·6574·3d22·2369·646d·3137·3030·3922··rget="#idm17009"0005f7b0:·7267·6574·3d22·2369·646d·3137·3030·3922··rget="#idm17009"
0005f7c0:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro0005f7c0:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro
0005f7d0:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria0005f7d0:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria
0005f7e0:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false0005f7e0:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false
0005f7f0:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat0005f7f0:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat
0005f800:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre0005f800:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre
0005f810:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati0005f810:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati
 0005f820:·6f6e·204f·5342·7569·6c64·2042·6c75·6570··on·OSBuild·Bluep
 0005f830:·7269·6e74·2073·6e69·7070·6574·20e2·87b2··rint·snippet·...
 0005f840:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
 0005f850:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
 0005f860:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
 0005f870:·2269·646d·3137·3030·3922·3e3c·7072·653e··"idm17009"><pre>
0005f820:·6f6e·2041·6e61·636f·6e64·6120·736e·6970··on·Anaconda·snip 
0005f830:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br>< 
0005f840:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel 
0005f850:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap 
0005f860:·7365·2220·6964·3d22·6964·6d31·3730·3039··se"·id="idm17009 
0005f870:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class=" 
0005f880:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri 
0005f890:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border 
0005f8a0:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens 
0005f8b0:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp 
0005f8c0:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td> 
0005f8d0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr 
0005f8e0:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption: 
0005f8f0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td 
0005f900:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re 
0005f910:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa 
0005f920:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr 
0005f930:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</ 
0005f940:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t 
0005f950:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table>< 
0005f960:·7072·653e·3c63·6f64·653e·0a70·6163·6b61··pre><code>.packa0005f880:·3c63·6f64·653e·0a5b·5b70·6163·6b61·6765··<code>.[[package
0005f970:·6765·202d·2d61·6464·3d72·7379·736c·6f67··ge·--add=rsyslog0005f890:·735d·5d0a·6e61·6d65·203d·2022·7273·7973··s]].name·=·"rsys
 0005f8a0:·6c6f·6722·0a76·6572·7369·6f6e·203d·2022··log".version·=·"
0005f980:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></0005f8b0:·2a22·0a3c·2f63·6f64·653e·3c2f·7072·653e··*".</code></pre>
0005f990:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt0005f8c0:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class="
0005f9a0:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d0005f8d0:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success"
 0005f8e0:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co
 0005f8f0:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar
 0005f900:·6765·743d·2223·6964·6d31·3730·3130·2220··get="#idm17010"·
 0005f910:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol
 0005f920:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-
 0005f930:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"
 0005f940:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate
 0005f950:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href
 0005f960:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio
 0005f970:·6e20·5075·7070·6574·2073·6e69·7070·6574··n·Puppet·snippet
 0005f980:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
 0005f990:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
 0005f9a0:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
 0005f9b0:·2069·643d·2269·646d·3137·3031·3022·3e3c···id="idm17010"><
 0005f9c0:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab
 0005f9d0:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped
 0005f9e0:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·
 0005f9f0:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"
 0005fa00:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex
 0005fa10:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low
 0005fa20:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
 0005fa30:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t
 0005fa40:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
 0005fa50:·7472·3e3c·7472·3e3c·7468·3e52·6562·6f6f··tr><tr><th>Reboo
 0005fa60:·743a·3c2f·7468·3e3c·7464·3e66·616c·7365··t:</th><td>false
 0005fa70:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
 0005fa80:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th>
 0005fa90:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td><
 0005faa0:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre
 0005fab0:·3e3c·636f·6465·3e69·6e63·6c75·6465·2069··><code>include·i
 0005fac0:·6e73·7461·6c6c·5f72·7379·736c·6f67·0a0a··nstall_rsyslog..
 0005fad0:·636c·6173·7320·696e·7374·616c·6c5f·7273··class·install_rs
 0005fae0:·7973·6c6f·6720·7b0a·2020·7061·636b·6167··yslog·{.··packag
 0005faf0:·6520·7b20·2772·7379·736c·6f67·273a·0a20··e·{·'rsyslog':.·
 0005fb00:·2020·2065·6e73·7572·6520·3d26·6774·3b20·····ensure·=&gt;·
 0005fb10:·2769·6e73·7461·6c6c·6564·272c·0a20·207d··'installed',.··}
 0005fb20:·0a7d·0a3c·2f63·6f64·653e·3c2f·7072·653e··.}.</code></pre>
 0005fb30:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class="
 0005fb40:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success"
0005f9b0:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll0005fb50:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co
0005f9c0:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe0005fb60:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar
0005f9d0:·743d·2223·6964·6d31·3730·3130·2220·7461··t="#idm17010"·ta0005fb70:·6765·743d·2223·6964·6d31·3730·3131·2220··get="#idm17011"·
0005f9e0:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=0005fb80:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol
0005f9f0:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex0005fb90:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-
0005fa00:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t0005fba0:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"
0005fa10:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t0005fbb0:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate
0005fa20:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="0005fbc0:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href
0005fa30:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·0005fbd0:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio
0005fa40:·4f53·4275·696c·6420·426c·7565·7072·696e··OSBuild·Blueprin0005fbe0:·6e20·5368·656c·6c20·7363·7269·7074·20e2··n·Shell·script·.
 0005fbf0:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c
 0005fc00:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
 0005fc10:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
 0005fc20:·643d·2269·646d·3137·3031·3122·3e3c·7461··d="idm17011"><ta
 0005fc30:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table
 0005fc40:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t
 0005fc50:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta
 0005fc60:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><
 0005fc70:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit
 0005fc80:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</
 0005fc90:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 0005fca0:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th>
 0005fcb0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
 0005fcc0:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot:
 0005fcd0:·3c2f·7468·3e3c·7464·3e66·616c·7365·3c2f··</th><td>false</
 0005fce0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 0005fcf0:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t
 0005fd00:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t
 0005fd10:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><
 0005fd20:·636f·6465·3e23·2052·656d·6564·6961·7469··code>#·Remediati
 0005fd30:·6f6e·2069·7320·6170·706c·6963·6162·6c65··on·is·applicable
 0005fd40:·206f·6e6c·7920·696e·2063·6572·7461·696e···only·in·certain
 0005fd50:·2070·6c61·7466·6f72·6d73·0a69·6620·7270···platforms.if·rp
 0005fd60:·6d20·2d2d·7175·6965·7420·2d71·206b·6572··m·--quiet·-q·ker
 0005fd70:·6e65·6c20·7c7c·2072·706d·202d·2d71·7569··nel·||·rpm·--qui
 0005fd80:·6574·202d·7120·6b65·726e·656c·2d75·656b··et·-q·kernel-uek
 0005fd90:·3b20·7468·656e·0a0a·6966·2021·2072·706d··;·then..if·!·rpm
 0005fda0:·202d·7120·2d2d·7175·6965·7420·2272·7379···-q·--quiet·"rsy
 0005fdb0:·736c·6f67·2220·3b20·7468·656e·0a20·2020··slog"·;·then.···
 0005fdc0:·2064·6e66·2069·6e73·7461·6c6c·202d·7920···dnf·install·-y·
 0005fdd0:·2272·7379·736c·6f67·220a·6669·0a0a·656c··"rsyslog".fi..el
 0005fde0:·7365·0a20·2020·2026·6774·3b26·616d·703b··se.····&gt;&amp;
 0005fdf0:·3220·6563·686f·2027·5265·6d65·6469·6174··2·echo·'Remediat
 0005fe00:·696f·6e20·6973·206e·6f74·2061·7070·6c69··ion·is·not·appli
 0005fe10:·6361·626c·652c·206e·6f74·6869·6e67·2077··cable,·nothing·w
 0005fe20:·6173·2064·6f6e·6527·0a66·690a·3c2f·636f··as·done'.fi.</co
 0005fe30:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div><
 0005fe40:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn
 0005fe50:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t
Max diff block lines reached; 97594/116252 bytes (83.95%) of diff not shown.
12.6 KB
html2text {}
    
Offset 2098, 21 lines modifiedOffset 2098, 14 lines modified
2098 ··-·NIST-800-53-CM-6(a)2098 ··-·NIST-800-53-CM-6(a)
2099 ··-·enable_strategy2099 ··-·enable_strategy
2100 ··-·low_complexity2100 ··-·low_complexity
2101 ··-·low_disruption2101 ··-·low_disruption
2102 ··-·medium_severity2102 ··-·medium_severity
2103 ··-·no_reboot_needed2103 ··-·no_reboot_needed
2104 ··-·package_rsyslog_installed2104 ··-·package_rsyslog_installed
2105 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
2106 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
2107 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
2108 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
2109 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
2110 package·--add=rsyslog 
2111 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x82105 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
2112 [[packages]]2106 [[packages]]
2113 name·=·"rsyslog"2107 name·=·"rsyslog"
2114 version·=·"*"2108 version·=·"*"
2115 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x82109 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
2116 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low2110 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 2137, 14 lines modifiedOffset 2130, 21 lines modified
2137 if·!·rpm·-q·--quiet·"rsyslog"·;·then2130 if·!·rpm·-q·--quiet·"rsyslog"·;·then
2138 ····dnf·install·-y·"rsyslog"2131 ····dnf·install·-y·"rsyslog"
2139 fi2132 fi
  
2140 else2133 else
2141 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'2134 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
2142 fi2135 fi
 2136 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 2137 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 2138 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 2139 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 2140 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 2141 package·--add=rsyslog
2143 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·r\x8rs\x8sy\x8ys\x8sl\x8lo\x8og\x8g·S\x8Se\x8er\x8rv\x8vi\x8ic\x8ce\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*2142 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·r\x8rs\x8sy\x8ys\x8sl\x8lo\x8og\x8g·S\x8Se\x8er\x8rv\x8vi\x8ic\x8ce\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
2144 The·rsyslog·service·provides·syslog-style·logging·by·default·on·Oracle·Linux·10.·The·rsyslog·service·can·be·enabled·with·the·following·command:2143 The·rsyslog·service·provides·syslog-style·logging·by·default·on·Oracle·Linux·10.·The·rsyslog·service·can·be·enabled·with·the·following·command:
2145 $·sudo·systemctl·enable·rsyslog.service2144 $·sudo·systemctl·enable·rsyslog.service
2146 Rationale:··The·rsyslog·service·must·be·running·in·order·to·provide·logging·services,·which·are·essential·to·system·administration.2145 Rationale:··The·rsyslog·service·must·be·running·in·order·to·provide·logging·services,·which·are·essential·to·system·administration.
2147 Severity: ··medium2146 Severity: ··medium
2148 Rule·ID:····xccdf_org.ssgproject.content_rule_service_rsyslog_enabled2147 Rule·ID:····xccdf_org.ssgproject.content_rule_service_rsyslog_enabled
2149 ············_\x8c_\x8i_\x8s_\x8-_\x8c_\x8s_\x8c········1,·12,·13,·14,·15,·16,·2,·3,·5,·6,·7,·8,·92148 ············_\x8c_\x8i_\x8s_\x8-_\x8c_\x8s_\x8c········1,·12,·13,·14,·15,·16,·2,·3,·5,·6,·7,·8,·9
Offset 2329, 21 lines modifiedOffset 2329, 14 lines modified
2329 ··-·PCI-DSSv4-1.2.12329 ··-·PCI-DSSv4-1.2.1
2330 ··-·enable_strategy2330 ··-·enable_strategy
2331 ··-·low_complexity2331 ··-·low_complexity
2332 ··-·low_disruption2332 ··-·low_disruption
2333 ··-·medium_severity2333 ··-·medium_severity
2334 ··-·no_reboot_needed2334 ··-·no_reboot_needed
2335 ··-·package_firewalld_installed2335 ··-·package_firewalld_installed
2336 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
2337 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
2338 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
2339 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
2340 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
2341 package·--add=firewalld 
2342 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x82336 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
2343 [[packages]]2337 [[packages]]
2344 name·=·"firewalld"2338 name·=·"firewalld"
2345 version·=·"*"2339 version·=·"*"
2346 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x82340 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
2347 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low2341 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 2368, 14 lines modifiedOffset 2361, 21 lines modified
2368 if·!·rpm·-q·--quiet·"firewalld"·;·then2361 if·!·rpm·-q·--quiet·"firewalld"·;·then
2369 ····dnf·install·-y·"firewalld"2362 ····dnf·install·-y·"firewalld"
2370 fi2363 fi
  
2371 else2364 else
2372 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'2365 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
2373 fi2366 fi
 2367 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 2368 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 2369 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 2370 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 2371 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 2372 package·--add=firewalld
2374 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·f\x8fi\x8ir\x8re\x8ew\x8wa\x8al\x8ll\x8ld\x8d·E\x8En\x8na\x8ab\x8bl\x8le\x8ed\x8d·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*2373 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·f\x8fi\x8ir\x8re\x8ew\x8wa\x8al\x8ll\x8ld\x8d·E\x8En\x8na\x8ab\x8bl\x8le\x8ed\x8d·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
2375 The·firewalld·service·can·be·enabled·with·the·following·command:2374 The·firewalld·service·can·be·enabled·with·the·following·command:
2376 $·sudo·systemctl·enable·firewalld.service2375 $·sudo·systemctl·enable·firewalld.service
2377 Rationale:··Access·control·methods·provide·the·ability·to·enhance·system·security·posture·by·restricting·services·and·known·good·IP·addresses·and·address·ranges.·This·prevents·connections·from·unknown·hosts·and·protocols.2376 Rationale:··Access·control·methods·provide·the·ability·to·enhance·system·security·posture·by·restricting·services·and·known·good·IP·addresses·and·address·ranges.·This·prevents·connections·from·unknown·hosts·and·protocols.
2378 Severity: ··medium2377 Severity: ··medium
2379 Rule·ID:····xccdf_org.ssgproject.content_rule_service_firewalld_enabled2378 Rule·ID:····xccdf_org.ssgproject.content_rule_service_firewalld_enabled
2380 ············_\x8c_\x8i_\x8s_\x8-_\x8c_\x8s_\x8c········11,·3,·92379 ············_\x8c_\x8i_\x8s_\x8-_\x8c_\x8s_\x8c········11,·3,·9
Offset 5714, 21 lines modifiedOffset 5714, 14 lines modified
5714 ··-·NIST-800-53-SI-4(22)5714 ··-·NIST-800-53-SI-4(22)
5715 ··-·enable_strategy5715 ··-·enable_strategy
5716 ··-·low_complexity5716 ··-·low_complexity
5717 ··-·low_disruption5717 ··-·low_disruption
5718 ··-·medium_severity5718 ··-·medium_severity
5719 ··-·no_reboot_needed5719 ··-·no_reboot_needed
5720 ··-·package_fapolicyd_installed5720 ··-·package_fapolicyd_installed
5721 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
5722 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
5723 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
5724 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
5725 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
5726 package·--add=fapolicyd 
5727 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x85721 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
5728 [[packages]]5722 [[packages]]
5729 name·=·"fapolicyd"5723 name·=·"fapolicyd"
5730 version·=·"*"5724 version·=·"*"
5731 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x85725 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
5732 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low5726 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 5753, 14 lines modifiedOffset 5746, 21 lines modified
5753 if·!·rpm·-q·--quiet·"fapolicyd"·;·then5746 if·!·rpm·-q·--quiet·"fapolicyd"·;·then
5754 ····dnf·install·-y·"fapolicyd"5747 ····dnf·install·-y·"fapolicyd"
5755 fi5748 fi
  
5756 else5749 else
5757 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'5750 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
5758 fi5751 fi
 5752 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 5753 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 5754 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 5755 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 5756 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 5757 package·--add=fapolicyd
5759 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·t\x8th\x8he\x8e·F\x8Fi\x8il\x8le\x8e·A\x8Ac\x8cc\x8ce\x8es\x8ss\x8s·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·S\x8Se\x8er\x8rv\x8vi\x8ic\x8ce\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*5758 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·t\x8th\x8he\x8e·F\x8Fi\x8il\x8le\x8e·A\x8Ac\x8cc\x8ce\x8es\x8ss\x8s·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·S\x8Se\x8er\x8rv\x8vi\x8ic\x8ce\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
5760 The·File·Access·Policy·service·should·be·enabled.·The·fapolicyd·service·can·be·enabled·with·the·following·command:5759 The·File·Access·Policy·service·should·be·enabled.·The·fapolicyd·service·can·be·enabled·with·the·following·command:
5761 $·sudo·systemctl·enable·fapolicyd.service5760 $·sudo·systemctl·enable·fapolicyd.service
Max diff block lines reached; 7598/12871 bytes (59.03%) of diff not shown.
133 KB
./usr/share/doc/ssg-nondebian/ssg-ol10-guide-hipaa.html
    
Offset 32112, 146 lines modifiedOffset 32112, 146 lines modified
0007d6f0:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#0007d6f0:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
0007d700:·6964·6d31·3730·3039·2220·7461·6269·6e64··idm17009"·tabind0007d700:·6964·6d31·3730·3039·2220·7461·6269·6e64··idm17009"·tabind
0007d710:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but0007d710:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
0007d720:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand0007d720:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
0007d730:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title0007d730:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
0007d740:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re0007d740:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
0007d750:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">0007d750:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
0007d760:·5265·6d65·6469·6174·696f·6e20·416e·6163··Remediation·Anac0007d760:·5265·6d65·6469·6174·696f·6e20·4f53·4275··Remediation·OSBu
0007d770:·6f6e·6461·2073·6e69·7070·6574·20e2·87b2··onda·snippet·... 
0007d780:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla 
0007d790:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap0007d770:·696c·6420·426c·7565·7072·696e·7420·736e··ild·Blueprint·sn
 0007d780:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br
 0007d790:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
0007d7a0:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=0007d7a0:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
 0007d7b0:·6170·7365·2220·6964·3d22·6964·6d31·3730··apse"·id="idm170
 0007d7c0:·3039·223e·3c70·7265·3e3c·636f·6465·3e0a··09"><pre><code>.
 0007d7d0:·5b5b·7061·636b·6167·6573·5d5d·0a6e·616d··[[packages]].nam
 0007d7e0:·6520·3d20·2272·7379·736c·6f67·220a·7665··e·=·"rsyslog".ve
 0007d7f0:·7273·696f·6e20·3d20·222a·220a·3c2f·636f··rsion·=·"*".</co
0007d7b0:·2269·646d·3137·3030·3922·3e3c·7461·626c··"idm17009"><tabl 
0007d7c0:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t 
0007d7d0:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab 
0007d7e0:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl 
0007d7f0:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr 
0007d800:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity: 
0007d810:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td 
0007d820:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di 
0007d830:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t 
0007d840:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr>< 
0007d850:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</ 
0007d860:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td 
0007d870:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St 
0007d880:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td> 
0007d890:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr> 
0007d8a0:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co 
0007d8b0:·6465·3e0a·7061·636b·6167·6520·2d2d·6164··de>.package·--ad 
0007d8c0:·643d·7273·7973·6c6f·670a·3c2f·636f·6465··d=rsyslog.</code 
0007d8d0:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a·0007d800:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div><
0007d8e0:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s0007d810:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn
0007d8f0:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog0007d820:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t
0007d900:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d0007d830:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse"
0007d910:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm0007d840:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i
0007d920:·3137·3031·3022·2074·6162·696e·6465·783d··17010"·tabindex=0007d850:·646d·3137·3031·3022·2074·6162·696e·6465··dm17010"·tabinde
0007d930:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button0007d860:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt
0007d940:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=0007d870:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande
0007d950:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A0007d880:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=
0007d960:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea0007d890:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev
0007d970:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem0007d8a0:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R
0007d980:·6564·6961·7469·6f6e·204f·5342·7569·6c64··ediation·OSBuild 
0007d990:·2042·6c75·6570·7269·6e74·2073·6e69·7070···Blueprint·snipp 
0007d9a0:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d 
0007d9b0:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel- 
0007d9c0:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps 
0007d9d0:·6522·2069·643d·2269·646d·3137·3031·3022··e"·id="idm17010"0007d8b0:·656d·6564·6961·7469·6f6e·2050·7570·7065··emediation·Puppe
 0007d8c0:·7420·736e·6970·7065·7420·e287·b23c·2f61··t·snippet·...</a
 0007d8d0:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
 0007d8e0:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
 0007d8f0:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
 0007d900:·6d31·3730·3130·223e·3c74·6162·6c65·2063··m17010"><table·c
 0007d910:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl
 0007d920:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-
 0007d930:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c
 0007d940:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t
 0007d950:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t
 0007d960:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
 0007d970:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru
 0007d980:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l
 0007d990:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
 0007d9a0:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th>
 0007d9b0:·3c74·643e·6661·6c73·653c·2f74·643e·3c2f··<td>false</td></
 0007d9c0:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat
 0007d9d0:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena
 0007d9e0:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t
0007d9e0:·3e3c·7072·653e·3c63·6f64·653e·0a5b·5b70··><pre><code>.[[p0007d9f0:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>
0007d9f0:·6163·6b61·6765·735d·5d0a·6e61·6d65·203d··ackages]].name·= 
0007da00:·2022·7273·7973·6c6f·6722·0a76·6572·7369···"rsyslog".versi 
0007da10:·6f6e·203d·2022·2a22·0a3c·2f63·6f64·653e··on·=·"*".</code>0007da00:·696e·636c·7564·6520·696e·7374·616c·6c5f··include·install_
 0007da10:·7273·7973·6c6f·670a·0a63·6c61·7373·2069··rsyslog..class·i
 0007da20:·6e73·7461·6c6c·5f72·7379·736c·6f67·207b··nstall_rsyslog·{
 0007da30:·0a20·2070·6163·6b61·6765·207b·2027·7273··.··package·{·'rs
 0007da40:·7973·6c6f·6727·3a0a·2020·2020·656e·7375··yslog':.····ensu
 0007da50:·7265·203d·2667·743b·2027·696e·7374·616c··re·=&gt;·'instal
 0007da60:·6c65·6427·2c0a·2020·7d0a·7d0a·3c2f·636f··led',.··}.}.</co
 0007da70:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div><
 0007da80:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn
 0007da90:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t
 0007daa0:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse"
 0007dab0:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i
 0007dac0:·646d·3137·3031·3122·2074·6162·696e·6465··dm17011"·tabinde
 0007dad0:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt
 0007dae0:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande
 0007daf0:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=
 0007db00:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev
 0007db10:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R
 0007db20:·656d·6564·6961·7469·6f6e·2053·6865·6c6c··emediation·Shell
 0007db30:·2073·6372·6970·7420·e287·b23c·2f61·3e3c···script·...</a><
 0007db40:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
 0007db50:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
 0007db60:·6c6c·6170·7365·2220·6964·3d22·6964·6d31··llapse"·id="idm1
 0007db70:·3730·3131·223e·3c74·6162·6c65·2063·6c61··7011"><table·cla
 0007db80:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-
 0007db90:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo
 0007dba0:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con
 0007dbb0:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>
 0007dbc0:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>
 0007dbd0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
 0007dbe0:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt
 0007dbf0:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low
 0007dc00:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
 0007dc10:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t
 0007dc20:·643e·6661·6c73·653c·2f74·643e·3c2f·7472··d>false</td></tr
 0007dc30:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg
 0007dc40:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl
 0007dc50:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab
 0007dc60:·6c65·3e3c·7072·653e·3c63·6f64·653e·2320··le><pre><code>#·
 0007dc70:·5265·6d65·6469·6174·696f·6e20·6973·2061··Remediation·is·a
 0007dc80:·7070·6c69·6361·626c·6520·6f6e·6c79·2069··pplicable·only·i
 0007dc90:·6e20·6365·7274·6169·6e20·706c·6174·666f··n·certain·platfo
 0007dca0:·726d·730a·6966·2072·706d·202d·2d71·7569··rms.if·rpm·--qui
 0007dcb0:·6574·202d·7120·6b65·726e·656c·207c·7c20··et·-q·kernel·||·
 0007dcc0:·7270·6d20·2d2d·7175·6965·7420·2d71·206b··rpm·--quiet·-q·k
 0007dcd0:·6572·6e65·6c2d·7565·6b3b·2074·6865·6e0a··ernel-uek;·then.
 0007dce0:·0a69·6620·2120·7270·6d20·2d71·202d·2d71··.if·!·rpm·-q·--q
 0007dcf0:·7569·6574·2022·7273·7973·6c6f·6722·203b··uiet·"rsyslog"·;
 0007dd00:·2074·6865·6e0a·2020·2020·646e·6620·696e···then.····dnf·in
 0007dd10:·7374·616c·6c20·2d79·2022·7273·7973·6c6f··stall·-y·"rsyslo
 0007dd20:·6722·0a66·690a·0a65·6c73·650a·2020·2020··g".fi..else.····
Max diff block lines reached; 104084/122880 bytes (84.70%) of diff not shown.
13.1 KB
html2text {}
    
Offset 3304, 21 lines modifiedOffset 3304, 14 lines modified
3304 ··-·NIST-800-53-CM-6(a)3304 ··-·NIST-800-53-CM-6(a)
3305 ··-·enable_strategy3305 ··-·enable_strategy
3306 ··-·low_complexity3306 ··-·low_complexity
3307 ··-·low_disruption3307 ··-·low_disruption
3308 ··-·medium_severity3308 ··-·medium_severity
3309 ··-·no_reboot_needed3309 ··-·no_reboot_needed
3310 ··-·package_rsyslog_installed3310 ··-·package_rsyslog_installed
3311 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
3312 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
3313 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
3314 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
3315 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
3316 package·--add=rsyslog 
3317 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x83311 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
3318 [[packages]]3312 [[packages]]
3319 name·=·"rsyslog"3313 name·=·"rsyslog"
3320 version·=·"*"3314 version·=·"*"
3321 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x83315 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
3322 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low3316 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 3343, 14 lines modifiedOffset 3336, 21 lines modified
3343 if·!·rpm·-q·--quiet·"rsyslog"·;·then3336 if·!·rpm·-q·--quiet·"rsyslog"·;·then
3344 ····dnf·install·-y·"rsyslog"3337 ····dnf·install·-y·"rsyslog"
3345 fi3338 fi
  
3346 else3339 else
3347 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'3340 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
3348 fi3341 fi
 3342 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 3343 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 3344 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 3345 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 3346 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 3347 package·--add=rsyslog
3349 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·r\x8rs\x8sy\x8ys\x8sl\x8lo\x8og\x8g·S\x8Se\x8er\x8rv\x8vi\x8ic\x8ce\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*3348 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·r\x8rs\x8sy\x8ys\x8sl\x8lo\x8og\x8g·S\x8Se\x8er\x8rv\x8vi\x8ic\x8ce\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
3350 The·rsyslog·service·provides·syslog-style·logging·by·default·on·Oracle·Linux·10.·The·rsyslog·service·can·be·enabled·with·the·following·command:3349 The·rsyslog·service·provides·syslog-style·logging·by·default·on·Oracle·Linux·10.·The·rsyslog·service·can·be·enabled·with·the·following·command:
3351 $·sudo·systemctl·enable·rsyslog.service3350 $·sudo·systemctl·enable·rsyslog.service
3352 Rationale:··The·rsyslog·service·must·be·running·in·order·to·provide·logging·services,·which·are·essential·to·system·administration.3351 Rationale:··The·rsyslog·service·must·be·running·in·order·to·provide·logging·services,·which·are·essential·to·system·administration.
3353 Severity: ··medium3352 Severity: ··medium
3354 Rule·ID:····xccdf_org.ssgproject.content_rule_service_rsyslog_enabled3353 Rule·ID:····xccdf_org.ssgproject.content_rule_service_rsyslog_enabled
3355 ············_\x8c_\x8i_\x8s_\x8-_\x8c_\x8s_\x8c········1,·12,·13,·14,·15,·16,·2,·3,·5,·6,·7,·8,·93354 ············_\x8c_\x8i_\x8s_\x8-_\x8c_\x8s_\x8c········1,·12,·13,·14,·15,·16,·2,·3,·5,·6,·7,·8,·9
Offset 5201, 17 lines modifiedOffset 5201, 14 lines modified
5201 ··-·NIST-800-53-CM-7(b)5201 ··-·NIST-800-53-CM-7(b)
5202 ··-·disable_strategy5202 ··-·disable_strategy
5203 ··-·low_complexity5203 ··-·low_complexity
5204 ··-·low_disruption5204 ··-·low_disruption
5205 ··-·medium_severity5205 ··-·medium_severity
5206 ··-·no_reboot_needed5206 ··-·no_reboot_needed
5207 ··-·service_kdump_disabled5207 ··-·service_kdump_disabled
5208 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
5209 kdump·--disable 
5210 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x85208 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
5211 [customizations.services]5209 [customizations.services]
5212 masked·=·["kdump"]5210 masked·=·["kdump"]
5213 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x85211 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
5214 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low5212 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
5215 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low5213 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
Offset 5250, 14 lines modifiedOffset 5247, 17 lines modified
5250 #·so·let's·reset·the·state·so·OVAL·checks·pass.5247 #·so·let's·reset·the·state·so·OVAL·checks·pass.
5251 #·Service·should·be·'inactive',·not·'failed'·after·reboot·though.5248 #·Service·should·be·'inactive',·not·'failed'·after·reboot·though.
5252 "$SYSTEMCTL_EXEC"·reset-failed·'kdump.service'·||·true5249 "$SYSTEMCTL_EXEC"·reset-failed·'kdump.service'·||·true
  
5253 else5250 else
5254 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'5251 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
5255 fi5252 fi
 5253 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 5254 kdump·--disable
5256 Group  ·Cron·and·At·Daemons·  Group·contains·3·rules5255 Group  ·Cron·and·At·Daemons·  Group·contains·3·rules
5257 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·cron·and·at·services·are·used·to·allow·commands·to·be·executed·at·a·later·time.·The·cron·service·is·required·by·almost·all·systems·to·perform·necessary·maintenance·tasks,·while·at·may·or·may·not·be·required·on·a·given·system.·Both·daemons·should·be·configured·defensively.5256 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·cron·and·at·services·are·used·to·allow·commands·to·be·executed·at·a·later·time.·The·cron·service·is·required·by·almost·all·systems·to·perform·necessary·maintenance·tasks,·while·at·may·or·may·not·be·required·on·a·given·system.·Both·daemons·should·be·configured·defensively.
5258 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·t\x8th\x8he\x8e·c\x8cr\x8ro\x8on\x8n·s\x8se\x8er\x8rv\x8vi\x8ic\x8ce\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*5257 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·t\x8th\x8he\x8e·c\x8cr\x8ro\x8on\x8n·s\x8se\x8er\x8rv\x8vi\x8ic\x8ce\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
5259 The·Cron·service·should·be·installed.5258 The·Cron·service·should·be·installed.
5260 Rationale:··The·cron·service·allow·periodic·job·execution,·needed·for·almost·all·administrative·tasks·and·services·(software·update,·log·rotating,·etc.).·Access·to·cron·service·should·be·restricted·to·administrative·accounts·only.5259 Rationale:··The·cron·service·allow·periodic·job·execution,·needed·for·almost·all·administrative·tasks·and·services·(software·update,·log·rotating,·etc.).·Access·to·cron·service·should·be·restricted·to·administrative·accounts·only.
5261 Severity: ··medium5260 Severity: ··medium
5262 Rule·ID:····xccdf_org.ssgproject.content_rule_package_cron_installed5261 Rule·ID:····xccdf_org.ssgproject.content_rule_package_cron_installed
Offset 5302, 21 lines modifiedOffset 5302, 14 lines modified
5302 ··-·PCI-DSSv4-2.2.65302 ··-·PCI-DSSv4-2.2.6
5303 ··-·enable_strategy5303 ··-·enable_strategy
5304 ··-·low_complexity5304 ··-·low_complexity
5305 ··-·low_disruption5305 ··-·low_disruption
5306 ··-·medium_severity5306 ··-·medium_severity
5307 ··-·no_reboot_needed5307 ··-·no_reboot_needed
5308 ··-·package_cron_installed5308 ··-·package_cron_installed
5309 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
5310 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
5311 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
5312 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
5313 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
5314 package·--add=cronie 
5315 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x85309 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
5316 [[packages]]5310 [[packages]]
5317 name·=·"cronie"5311 name·=·"cronie"
5318 version·=·"*"5312 version·=·"*"
5319 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x85313 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
5320 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low5314 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 5341, 14 lines modifiedOffset 5334, 21 lines modified
5341 if·!·rpm·-q·--quiet·"cronie"·;·then5334 if·!·rpm·-q·--quiet·"cronie"·;·then
5342 ····dnf·install·-y·"cronie"5335 ····dnf·install·-y·"cronie"
5343 fi5336 fi
  
5344 else5337 else
5345 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'5338 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
5346 fi5339 fi
 5340 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 5341 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 5342 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 5343 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 5344 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 5345 package·--add=cronie
5347 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·c\x8cr\x8ro\x8on\x8n·S\x8Se\x8er\x8rv\x8vi\x8ic\x8ce\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*5346 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·c\x8cr\x8ro\x8on\x8n·S\x8Se\x8er\x8rv\x8vi\x8ic\x8ce\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
5348 The·crond·service·is·used·to·execute·commands·at·preconfigured·times.·It·is·required·by·almost·all·systems·to·perform·necessary·maintenance·tasks,·such·as·notifying·root·of·system·activity.·The·cron·service·can·be·enabled·with·the·following·command:5347 The·crond·service·is·used·to·execute·commands·at·preconfigured·times.·It·is·required·by·almost·all·systems·to·perform·necessary·maintenance·tasks,·such·as·notifying·root·of·system·activity.·The·cron·service·can·be·enabled·with·the·following·command:
5349 $·sudo·systemctl·enable·cron.service5348 $·sudo·systemctl·enable·cron.service
5350 Rationale:··Due·to·its·usage·for·maintenance·and·security-supporting·tasks,·enabling·the·cron·daemon·is·essential.5349 Rationale:··Due·to·its·usage·for·maintenance·and·security-supporting·tasks,·enabling·the·cron·daemon·is·essential.
5351 Severity: ··medium5350 Severity: ··medium
5352 Rule·ID:····xccdf_org.ssgproject.content_rule_service_cron_enabled5351 Rule·ID:····xccdf_org.ssgproject.content_rule_service_cron_enabled
5353 ············_\x8c_\x8i_\x8s_\x8-_\x8c_\x8s_\x8c········11,·14,·3,·95352 ············_\x8c_\x8i_\x8s_\x8-_\x8c_\x8s_\x8c········11,·14,·3,·9
Offset 5825, 21 lines modifiedOffset 5825, 14 lines modified
5825 ··-·PCI-DSSv4-2.2.45825 ··-·PCI-DSSv4-2.2.4
5826 ··-·disable_strategy5826 ··-·disable_strategy
5827 ··-·high_severity5827 ··-·high_severity
Max diff block lines reached; 7726/13344 bytes (57.90%) of diff not shown.
308 KB
./usr/share/doc/ssg-nondebian/ssg-ol10-guide-ism_o.html
    
Offset 17394, 143 lines modifiedOffset 17394, 143 lines modified
00043f10:·2d74·6172·6765·743d·2223·6964·6d35·3039··-target="#idm50900043f10:·2d74·6172·6765·743d·2223·6964·6d35·3039··-target="#idm509
00043f20:·3822·2074·6162·696e·6465·783d·2230·2220··8"·tabindex="0"·00043f20:·3822·2074·6162·696e·6465·783d·2230·2220··8"·tabindex="0"·
00043f30:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar00043f30:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar
00043f40:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal00043f40:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal
00043f50:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ00043f50:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ
00043f60:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h00043f60:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h
00043f70:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia00043f70:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia
 00043f80:·7469·6f6e·204f·5342·7569·6c64·2042·6c75··tion·OSBuild·Blu
 00043f90:·6570·7269·6e74·2073·6e69·7070·6574·20e2··eprint·snippet·.
 00043fa0:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c
 00043fb0:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
 00043fc0:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
 00043fd0:·643d·2269·646d·3530·3938·223e·3c70·7265··d="idm5098"><pre
 00043fe0:·3e3c·636f·6465·3e0a·5b5b·7061·636b·6167··><code>.[[packag
 00043ff0:·6573·5d5d·0a6e·616d·6520·3d20·2261·6964··es]].name·=·"aid
 00044000:·6522·0a76·6572·7369·6f6e·203d·2022·2a22··e".version·=·"*"
 00044010:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></
 00044020:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt
 00044030:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d
 00044040:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll
 00044050:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
 00044060:·743d·2223·6964·6d35·3039·3922·2074·6162··t="#idm5099"·tab
 00044070:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
 00044080:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
 00044090:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
 000440a0:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
 000440b0:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
 000440c0:·2122·3e52·656d·6564·6961·7469·6f6e·2050··!">Remediation·P
 000440d0:·7570·7065·7420·736e·6970·7065·7420·e287··uppet·snippet·..
 000440e0:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl
 000440f0:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla
 00044100:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id
 00044110:·3d22·6964·6d35·3039·3922·3e3c·7461·626c··="idm5099"><tabl
 00044120:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t
 00044130:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab
 00044140:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl
 00044150:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr
 00044160:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:
 00044170:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
 00044180:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di
 00044190:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t
 000441a0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
 000441b0:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</
 000441c0:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td
 000441d0:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St
 000441e0:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>
 000441f0:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr>
 00044200:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co
 00044210:·6465·3e69·6e63·6c75·6465·2069·6e73·7461··de>include·insta
 00044220:·6c6c·5f61·6964·650a·0a63·6c61·7373·2069··ll_aide..class·i
 00044230:·6e73·7461·6c6c·5f61·6964·6520·7b0a·2020··nstall_aide·{.··
 00044240:·7061·636b·6167·6520·7b20·2761·6964·6527··package·{·'aide'
 00044250:·3a0a·2020·2020·656e·7375·7265·203d·2667··:.····ensure·=&g
 00044260:·743b·2027·696e·7374·616c·6c65·6427·2c0a··t;·'installed',.
 00044270:·2020·7d0a·7d0a·3c2f·636f·6465·3e3c·2f70····}.}.</code></p
 00044280:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas
 00044290:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe
 000442a0:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle=
 000442b0:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data-
 000442c0:·7461·7267·6574·3d22·2369·646d·3531·3030··target="#idm5100
 000442d0:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r
 000442e0:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari
 000442f0:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals
 00044300:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa
 00044310:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr
 00044320:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat
 00044330:·696f·6e20·5368·656c·6c20·7363·7269·7074··ion·Shell·script
 00044340:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
 00044350:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
 00044360:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
 00044370:·2069·643d·2269·646d·3531·3030·223e·3c74···id="idm5100"><t
 00044380:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl
 00044390:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·
 000443a0:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t
 000443b0:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">
 000443c0:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi
 000443d0:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<
 000443e0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 000443f0:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th
 00044400:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
 00044410:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot
 00044420:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false<
 00044430:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 00044440:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><
 00044450:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></
 00044460:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>
 00044470:·3c63·6f64·653e·2320·5265·6d65·6469·6174··<code>#·Remediat
 00044480:·696f·6e20·6973·2061·7070·6c69·6361·626c··ion·is·applicabl
 00044490:·6520·6f6e·6c79·2069·6e20·6365·7274·6169··e·only·in·certai
 000444a0:·6e20·706c·6174·666f·726d·730a·6966·2072··n·platforms.if·r
 000444b0:·706d·202d·2d71·7569·6574·202d·7120·6b65··pm·--quiet·-q·ke
 000444c0:·726e·656c·207c·7c20·7270·6d20·2d2d·7175··rnel·||·rpm·--qu
 000444d0:·6965·7420·2d71·206b·6572·6e65·6c2d·7565··iet·-q·kernel-ue
 000444e0:·6b3b·2074·6865·6e0a·0a69·6620·2120·7270··k;·then..if·!·rp
 000444f0:·6d20·2d71·202d·2d71·7569·6574·2022·6169··m·-q·--quiet·"ai
 00044500:·6465·2220·3b20·7468·656e·0a20·2020·2064··de"·;·then.····d
 00044510:·6e66·2069·6e73·7461·6c6c·202d·7920·2261··nf·install·-y·"a
 00044520:·6964·6522·0a66·690a·0a65·6c73·650a·2020··ide".fi..else.··
 00044530:·2020·2667·743b·2661·6d70·3b32·2065·6368····&gt;&amp;2·ech
 00044540:·6f20·2752·656d·6564·6961·7469·6f6e·2069··o·'Remediation·i
 00044550:·7320·6e6f·7420·6170·706c·6963·6162·6c65··s·not·applicable
 00044560:·2c20·6e6f·7468·696e·6720·7761·7320·646f··,·nothing·was·do
 00044570:·6e65·270a·6669·0a3c·2f63·6f64·653e·3c2f··ne'.fi.</code></
 00044580:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla
 00044590:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ
 000445a0:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle
 000445b0:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data
 000445c0:·2d74·6172·6765·743d·2223·6964·6d35·3130··-target="#idm510
 000445d0:·3122·2074·6162·696e·6465·783d·2230·2220··1"·tabindex="0"·
 000445e0:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar
 000445f0:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal
 00044600:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ
 00044610:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h
 00044620:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia
00043f80:·7469·6f6e·2041·6e61·636f·6e64·6120·736e··tion·Anaconda·sn00044630:·7469·6f6e·2041·6e61·636f·6e64·6120·736e··tion·Anaconda·sn
00043f90:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br 
00043fa0:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan 
00043fb0:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll 
00043fc0:·6170·7365·2220·6964·3d22·6964·6d35·3039··apse"·id="idm509 
00043fd0:·3822·3e3c·7461·626c·6520·636c·6173·733d··8"><table·class= 
00043fe0:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str 
00043ff0:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde 
00044000:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden 
00044010:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com 
00044020:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td 
00044030:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t 
00044040:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption 
Max diff block lines reached; 265518/283900 bytes (93.53%) of diff not shown.
31.1 KB
html2text {}
    
Offset 718, 21 lines modifiedOffset 718, 14 lines modified
718 ··-·PCI-DSSv4-11.5.2718 ··-·PCI-DSSv4-11.5.2
719 ··-·enable_strategy719 ··-·enable_strategy
720 ··-·low_complexity720 ··-·low_complexity
721 ··-·low_disruption721 ··-·low_disruption
722 ··-·medium_severity722 ··-·medium_severity
723 ··-·no_reboot_needed723 ··-·no_reboot_needed
724 ··-·package_aide_installed724 ··-·package_aide_installed
725 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
726 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
727 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
728 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
729 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
730 package·--add=aide 
731 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8725 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
732 [[packages]]726 [[packages]]
733 name·=·"aide"727 name·=·"aide"
734 version·=·"*"728 version·=·"*"
735 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8729 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
736 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low730 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 757, 14 lines modifiedOffset 750, 21 lines modified
757 if·!·rpm·-q·--quiet·"aide"·;·then750 if·!·rpm·-q·--quiet·"aide"·;·then
758 ····dnf·install·-y·"aide"751 ····dnf·install·-y·"aide"
759 fi752 fi
  
760 else753 else
761 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'754 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
762 fi755 fi
 756 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 757 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 758 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 759 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 760 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 761 package·--add=aide
763 Group  ·Federal·Information·Processing·Standard·(FIPS)·  Group·contains·2·rules762 Group  ·Federal·Information·Processing·Standard·(FIPS)·  Group·contains·2·rules
764 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·Federal·Information·Processing·Standard·(FIPS)·is·a·computer·security·standard·which·is·developed·by·the·U.S.·Government·and·industry·working·groups·to·validate·the·quality·of·cryptographic·modules.·The·FIPS·standard·provides·four·security·levels·to·ensure·adequate·coverage·of·different·industries,·implementation·of·cryptographic·modules,·and·organizational·sizes·and·requirements.763 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·Federal·Information·Processing·Standard·(FIPS)·is·a·computer·security·standard·which·is·developed·by·the·U.S.·Government·and·industry·working·groups·to·validate·the·quality·of·cryptographic·modules.·The·FIPS·standard·provides·four·security·levels·to·ensure·adequate·coverage·of·different·industries,·implementation·of·cryptographic·modules,·and·organizational·sizes·and·requirements.
  
765 FIPS·140-2·is·the·current·standard·for·validating·that·mechanisms·used·to·access·cryptographic·modules·utilize·authentication·that·meets·industry·and·government·requirements.·For·government·systems,·this·allows·Security·Levels·1,·2,·3,·or·4·for·use·on·Oracle·Linux·10.764 FIPS·140-2·is·the·current·standard·for·validating·that·mechanisms·used·to·access·cryptographic·modules·utilize·authentication·that·meets·industry·and·government·requirements.·For·government·systems,·this·allows·Security·Levels·1,·2,·3,·or·4·for·use·on·Oracle·Linux·10.
  
766 See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8c\x8c_\x8s\x8s_\x8r\x8r_\x8c\x8c_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8l\x8l_\x8i\x8i_\x8c\x8c_\x8a\x8a_\x8t\x8t_\x8i\x8i_\x8o\x8o_\x8n\x8n_\x8s\x8s_\x8/\x8/_\x8P\x8P_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x8h\x8h_\x8t\x8t_\x8m\x8m_\x8l\x8l·for·more·information.765 See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8c\x8c_\x8s\x8s_\x8r\x8r_\x8c\x8c_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8l\x8l_\x8i\x8i_\x8c\x8c_\x8a\x8a_\x8t\x8t_\x8i\x8i_\x8o\x8o_\x8n\x8n_\x8s\x8s_\x8/\x8/_\x8P\x8P_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x8h\x8h_\x8t\x8t_\x8m\x8m_\x8l\x8l·for·more·information.
767 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8de\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*766 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8de\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
Offset 1042, 21 lines modifiedOffset 1042, 14 lines modified
1042 ··-·PCI-DSSv4-2.2.61042 ··-·PCI-DSSv4-2.2.6
1043 ··-·enable_strategy1043 ··-·enable_strategy
1044 ··-·low_complexity1044 ··-·low_complexity
1045 ··-·low_disruption1045 ··-·low_disruption
1046 ··-·medium_severity1046 ··-·medium_severity
1047 ··-·no_reboot_needed1047 ··-·no_reboot_needed
1048 ··-·package_sudo_installed1048 ··-·package_sudo_installed
1049 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
1050 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
1051 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
1052 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
1053 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
1054 package·--add=sudo 
1055 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81049 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
1056 [[packages]]1050 [[packages]]
1057 name·=·"sudo"1051 name·=·"sudo"
1058 version·=·"*"1052 version·=·"*"
1059 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81053 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1060 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1054 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 1081, 14 lines modifiedOffset 1074, 21 lines modified
1081 if·!·rpm·-q·--quiet·"sudo"·;·then1074 if·!·rpm·-q·--quiet·"sudo"·;·then
1082 ····dnf·install·-y·"sudo"1075 ····dnf·install·-y·"sudo"
1083 fi1076 fi
  
1084 else1077 else
1085 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'1078 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
1086 fi1079 fi
 1080 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 1081 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1082 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1083 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1084 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 1085 package·--add=sudo
1087 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·U\x8Us\x8se\x8er\x8rs\x8s·R\x8Re\x8e-\x8-A\x8Au\x8ut\x8th\x8he\x8en\x8nt\x8ti\x8ic\x8ca\x8at\x8te\x8e·f\x8fo\x8or\x8r·P\x8Pr\x8ri\x8iv\x8vi\x8il\x8le\x8eg\x8ge\x8e·E\x8Es\x8sc\x8ca\x8al\x8la\x8at\x8ti\x8io\x8on\x8n·-\x8-·s\x8su\x8ud\x8do\x8o·!\x8!a\x8au\x8ut\x8th\x8he\x8en\x8nt\x8ti\x8ic\x8ca\x8at\x8te\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*1086 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·U\x8Us\x8se\x8er\x8rs\x8s·R\x8Re\x8e-\x8-A\x8Au\x8ut\x8th\x8he\x8en\x8nt\x8ti\x8ic\x8ca\x8at\x8te\x8e·f\x8fo\x8or\x8r·P\x8Pr\x8ri\x8iv\x8vi\x8il\x8le\x8eg\x8ge\x8e·E\x8Es\x8sc\x8ca\x8al\x8la\x8at\x8ti\x8io\x8on\x8n·-\x8-·s\x8su\x8ud\x8do\x8o·!\x8!a\x8au\x8ut\x8th\x8he\x8en\x8nt\x8ti\x8ic\x8ca\x8at\x8te\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
1088 The·sudo·!authenticate·option,·when·specified,·allows·a·user·to·execute·commands·using·sudo·without·having·to·authenticate.·This·should·be·disabled·by·making·sure·that·the·!authenticate·option·does·not·exist·in·/etc/sudoers·configuration·file·or·any·sudo·configuration·snippets·in·/etc/sudoers.d/.1087 The·sudo·!authenticate·option,·when·specified,·allows·a·user·to·execute·commands·using·sudo·without·having·to·authenticate.·This·should·be·disabled·by·making·sure·that·the·!authenticate·option·does·not·exist·in·/etc/sudoers·configuration·file·or·any·sudo·configuration·snippets·in·/etc/sudoers.d/.
1089 ············Without·re-authentication,·users·may·access·resources·or·perform·tasks·for·which·they·do·not·have·authorization.1088 ············Without·re-authentication,·users·may·access·resources·or·perform·tasks·for·which·they·do·not·have·authorization.
1090 Rationale:1089 Rationale:
1091 ············When·operating·systems·provide·the·capability·to·escalate·a·functional·capability,·it·is·critical·that·the·user·re-authenticate.1090 ············When·operating·systems·provide·the·capability·to·escalate·a·functional·capability,·it·is·critical·that·the·user·re-authenticate.
1092 Severity: ··medium1091 Severity: ··medium
1093 Rule·ID:····xccdf_org.ssgproject.content_rule_sudo_remove_no_authenticate1092 Rule·ID:····xccdf_org.ssgproject.content_rule_sudo_remove_no_authenticate
Offset 9161, 21 lines modifiedOffset 9161, 14 lines modified
9161 ··-·NIST-800-53-CM-6(a)9161 ··-·NIST-800-53-CM-6(a)
9162 ··-·enable_strategy9162 ··-·enable_strategy
9163 ··-·low_complexity9163 ··-·low_complexity
9164 ··-·low_disruption9164 ··-·low_disruption
9165 ··-·medium_severity9165 ··-·medium_severity
9166 ··-·no_reboot_needed9166 ··-·no_reboot_needed
9167 ··-·package_opensc_installed9167 ··-·package_opensc_installed
9168 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
9169 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
9170 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
9171 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
9172 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
9173 package·--add=opensc 
9174 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x89168 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
9175 [[packages]]9169 [[packages]]
9176 name·=·"opensc"9170 name·=·"opensc"
9177 version·=·"*"9171 version·=·"*"
9178 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x89172 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
9179 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low9173 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 9200, 14 lines modifiedOffset 9193, 21 lines modified
9200 if·!·rpm·-q·--quiet·"opensc"·;·then9193 if·!·rpm·-q·--quiet·"opensc"·;·then
9201 ····dnf·install·-y·"opensc"9194 ····dnf·install·-y·"opensc"
9202 fi9195 fi
  
9203 else9196 else
9204 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'9197 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
9205 fi9198 fi
 9199 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 9200 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 9201 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 9202 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 9203 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 9204 package·--add=opensc
9206 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·t\x8th\x8he\x8e·p\x8pc\x8cs\x8sc\x8c-\x8-l\x8li\x8it\x8te\x8e-\x8-c\x8cc\x8ci\x8id\x8d·p\x8pa\x8ac\x8ck\x8ka\x8ag\x8ge\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*9205 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·t\x8th\x8he\x8e·p\x8pc\x8cs\x8sc\x8c-\x8-l\x8li\x8it\x8te\x8e-\x8-c\x8cc\x8ci\x8id\x8d·p\x8pa\x8ac\x8ck\x8ka\x8ag\x8ge\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
9207 The·pcsc-lite-ccid·package·can·be·installed·with·the·following·command:9206 The·pcsc-lite-ccid·package·can·be·installed·with·the·following·command:
9208 $·sudo·dnf·install·pcsc-lite-ccid9207 $·sudo·dnf·install·pcsc-lite-ccid
Max diff block lines reached; 25875/31869 bytes (81.19%) of diff not shown.
309 KB
./usr/share/doc/ssg-nondebian/ssg-ol10-guide-ism_o_secret.html
    
Offset 17395, 143 lines modifiedOffset 17395, 143 lines modified
00043f20:·6574·3d22·2369·646d·3530·3938·2220·7461··et="#idm5098"·ta00043f20:·6574·3d22·2369·646d·3530·3938·2220·7461··et="#idm5098"·ta
00043f30:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=00043f30:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
00043f40:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex00043f40:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
00043f50:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t00043f50:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
00043f60:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t00043f60:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
00043f70:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="00043f70:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
00043f80:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·00043f80:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
 00043f90:·4f53·4275·696c·6420·426c·7565·7072·696e··OSBuild·Blueprin
 00043fa0:·7420·736e·6970·7065·7420·e287·b23c·2f61··t·snippet·...</a
 00043fb0:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
 00043fc0:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
 00043fd0:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
 00043fe0:·6d35·3039·3822·3e3c·7072·653e·3c63·6f64··m5098"><pre><cod
 00043ff0:·653e·0a5b·5b70·6163·6b61·6765·735d·5d0a··e>.[[packages]].
 00044000:·6e61·6d65·203d·2022·6169·6465·220a·7665··name·=·"aide".ve
 00044010:·7273·696f·6e20·3d20·222a·220a·3c2f·636f··rsion·=·"*".</co
 00044020:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div><
 00044030:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn
 00044040:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t
 00044050:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse"
 00044060:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i
 00044070:·646d·3530·3939·2220·7461·6269·6e64·6578··dm5099"·tabindex
 00044080:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto
 00044090:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded
 000440a0:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="
 000440b0:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve
 000440c0:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re
 000440d0:·6d65·6469·6174·696f·6e20·5075·7070·6574··mediation·Puppet
 000440e0:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>
 000440f0:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="
 00044100:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c
 00044110:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm
 00044120:·3530·3939·223e·3c74·6162·6c65·2063·6c61··5099"><table·cla
 00044130:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-
 00044140:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo
 00044150:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con
 00044160:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>
 00044170:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>
 00044180:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
 00044190:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt
 000441a0:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low
 000441b0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
 000441c0:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t
 000441d0:·643e·6661·6c73·653c·2f74·643e·3c2f·7472··d>false</td></tr
 000441e0:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg
 000441f0:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl
 00044200:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab
 00044210:·6c65·3e3c·7072·653e·3c63·6f64·653e·696e··le><pre><code>in
 00044220:·636c·7564·6520·696e·7374·616c·6c5f·6169··clude·install_ai
 00044230:·6465·0a0a·636c·6173·7320·696e·7374·616c··de..class·instal
 00044240:·6c5f·6169·6465·207b·0a20·2070·6163·6b61··l_aide·{.··packa
 00044250:·6765·207b·2027·6169·6465·273a·0a20·2020··ge·{·'aide':.···
 00044260:·2065·6e73·7572·6520·3d26·6774·3b20·2769···ensure·=&gt;·'i
 00044270:·6e73·7461·6c6c·6564·272c·0a20·207d·0a7d··nstalled',.··}.}
 00044280:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></
 00044290:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt
 000442a0:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d
 000442b0:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll
 000442c0:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
 000442d0:·743d·2223·6964·6d35·3130·3022·2074·6162··t="#idm5100"·tab
 000442e0:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
 000442f0:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
 00044300:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
 00044310:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
 00044320:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
 00044330:·2122·3e52·656d·6564·6961·7469·6f6e·2053··!">Remediation·S
 00044340:·6865·6c6c·2073·6372·6970·7420·e287·b23c··hell·script·...<
 00044350:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas
 00044360:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps
 00044370:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="
 00044380:·6964·6d35·3130·3022·3e3c·7461·626c·6520··idm5100"><table·
 00044390:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab
 000443a0:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table
 000443b0:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-
 000443c0:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><
 000443d0:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</
 000443e0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
 000443f0:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr
 00044400:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>
 00044410:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
 00044420:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th
 00044430:·3e3c·7464·3e66·616c·7365·3c2f·7464·3e3c··><td>false</td><
 00044440:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra
 00044450:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en
 00044460:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></
 00044470:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code
 00044480:·3e23·2052·656d·6564·6961·7469·6f6e·2069··>#·Remediation·i
 00044490:·7320·6170·706c·6963·6162·6c65·206f·6e6c··s·applicable·onl
 000444a0:·7920·696e·2063·6572·7461·696e·2070·6c61··y·in·certain·pla
 000444b0:·7466·6f72·6d73·0a69·6620·7270·6d20·2d2d··tforms.if·rpm·--
 000444c0:·7175·6965·7420·2d71·206b·6572·6e65·6c20··quiet·-q·kernel·
 000444d0:·7c7c·2072·706d·202d·2d71·7569·6574·202d··||·rpm·--quiet·-
 000444e0:·7120·6b65·726e·656c·2d75·656b·3b20·7468··q·kernel-uek;·th
 000444f0:·656e·0a0a·6966·2021·2072·706d·202d·7120··en..if·!·rpm·-q·
 00044500:·2d2d·7175·6965·7420·2261·6964·6522·203b··--quiet·"aide"·;
 00044510:·2074·6865·6e0a·2020·2020·646e·6620·696e···then.····dnf·in
 00044520:·7374·616c·6c20·2d79·2022·6169·6465·220a··stall·-y·"aide".
 00044530:·6669·0a0a·656c·7365·0a20·2020·2026·6774··fi..else.····&gt
 00044540:·3b26·616d·703b·3220·6563·686f·2027·5265··;&amp;2·echo·'Re
 00044550:·6d65·6469·6174·696f·6e20·6973·206e·6f74··mediation·is·not
 00044560:·2061·7070·6c69·6361·626c·652c·206e·6f74···applicable,·not
 00044570:·6869·6e67·2077·6173·2064·6f6e·6527·0a66··hing·was·done'.f
 00044580:·690a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··i.</code></pre><
 00044590:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b
 000445a0:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"·
 000445b0:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col
 000445c0:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ
 000445d0:·6574·3d22·2369·646d·3531·3031·2220·7461··et="#idm5101"·ta
 000445e0:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
 000445f0:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
 00044600:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
 00044610:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
 00044620:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
 00044630:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
00043f90:·416e·6163·6f6e·6461·2073·6e69·7070·6574··Anaconda·snippet00044640:·416e·6163·6f6e·6461·2073·6e69·7070·6574··Anaconda·snippet
00043fa0:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div 
00043fb0:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co 
00043fc0:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse" 
00043fd0:·2069·643d·2269·646d·3530·3938·223e·3c74···id="idm5098"><t 
00043fe0:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl 
00043ff0:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped· 
00044000:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t 
00044010:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed"> 
00044020:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi 
00044030:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low< 
00044040:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
00044050:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th 
Max diff block lines reached; 265932/284314 bytes (93.53%) of diff not shown.
31.1 KB
html2text {}
    
Offset 718, 21 lines modifiedOffset 718, 14 lines modified
718 ··-·PCI-DSSv4-11.5.2718 ··-·PCI-DSSv4-11.5.2
719 ··-·enable_strategy719 ··-·enable_strategy
720 ··-·low_complexity720 ··-·low_complexity
721 ··-·low_disruption721 ··-·low_disruption
722 ··-·medium_severity722 ··-·medium_severity
723 ··-·no_reboot_needed723 ··-·no_reboot_needed
724 ··-·package_aide_installed724 ··-·package_aide_installed
725 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
726 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
727 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
728 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
729 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
730 package·--add=aide 
731 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8725 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
732 [[packages]]726 [[packages]]
733 name·=·"aide"727 name·=·"aide"
734 version·=·"*"728 version·=·"*"
735 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8729 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
736 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low730 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 757, 14 lines modifiedOffset 750, 21 lines modified
757 if·!·rpm·-q·--quiet·"aide"·;·then750 if·!·rpm·-q·--quiet·"aide"·;·then
758 ····dnf·install·-y·"aide"751 ····dnf·install·-y·"aide"
759 fi752 fi
  
760 else753 else
761 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'754 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
762 fi755 fi
 756 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 757 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 758 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 759 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 760 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 761 package·--add=aide
763 Group  ·Federal·Information·Processing·Standard·(FIPS)·  Group·contains·2·rules762 Group  ·Federal·Information·Processing·Standard·(FIPS)·  Group·contains·2·rules
764 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·Federal·Information·Processing·Standard·(FIPS)·is·a·computer·security·standard·which·is·developed·by·the·U.S.·Government·and·industry·working·groups·to·validate·the·quality·of·cryptographic·modules.·The·FIPS·standard·provides·four·security·levels·to·ensure·adequate·coverage·of·different·industries,·implementation·of·cryptographic·modules,·and·organizational·sizes·and·requirements.763 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·Federal·Information·Processing·Standard·(FIPS)·is·a·computer·security·standard·which·is·developed·by·the·U.S.·Government·and·industry·working·groups·to·validate·the·quality·of·cryptographic·modules.·The·FIPS·standard·provides·four·security·levels·to·ensure·adequate·coverage·of·different·industries,·implementation·of·cryptographic·modules,·and·organizational·sizes·and·requirements.
  
765 FIPS·140-2·is·the·current·standard·for·validating·that·mechanisms·used·to·access·cryptographic·modules·utilize·authentication·that·meets·industry·and·government·requirements.·For·government·systems,·this·allows·Security·Levels·1,·2,·3,·or·4·for·use·on·Oracle·Linux·10.764 FIPS·140-2·is·the·current·standard·for·validating·that·mechanisms·used·to·access·cryptographic·modules·utilize·authentication·that·meets·industry·and·government·requirements.·For·government·systems,·this·allows·Security·Levels·1,·2,·3,·or·4·for·use·on·Oracle·Linux·10.
  
766 See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8c\x8c_\x8s\x8s_\x8r\x8r_\x8c\x8c_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8l\x8l_\x8i\x8i_\x8c\x8c_\x8a\x8a_\x8t\x8t_\x8i\x8i_\x8o\x8o_\x8n\x8n_\x8s\x8s_\x8/\x8/_\x8P\x8P_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x8h\x8h_\x8t\x8t_\x8m\x8m_\x8l\x8l·for·more·information.765 See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8c\x8c_\x8s\x8s_\x8r\x8r_\x8c\x8c_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8l\x8l_\x8i\x8i_\x8c\x8c_\x8a\x8a_\x8t\x8t_\x8i\x8i_\x8o\x8o_\x8n\x8n_\x8s\x8s_\x8/\x8/_\x8P\x8P_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x8h\x8h_\x8t\x8t_\x8m\x8m_\x8l\x8l·for·more·information.
767 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8de\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*766 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8de\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
Offset 1042, 21 lines modifiedOffset 1042, 14 lines modified
1042 ··-·PCI-DSSv4-2.2.61042 ··-·PCI-DSSv4-2.2.6
1043 ··-·enable_strategy1043 ··-·enable_strategy
1044 ··-·low_complexity1044 ··-·low_complexity
1045 ··-·low_disruption1045 ··-·low_disruption
1046 ··-·medium_severity1046 ··-·medium_severity
1047 ··-·no_reboot_needed1047 ··-·no_reboot_needed
1048 ··-·package_sudo_installed1048 ··-·package_sudo_installed
1049 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
1050 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
1051 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
1052 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
1053 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
1054 package·--add=sudo 
1055 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81049 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
1056 [[packages]]1050 [[packages]]
1057 name·=·"sudo"1051 name·=·"sudo"
1058 version·=·"*"1052 version·=·"*"
1059 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81053 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1060 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1054 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 1081, 14 lines modifiedOffset 1074, 21 lines modified
1081 if·!·rpm·-q·--quiet·"sudo"·;·then1074 if·!·rpm·-q·--quiet·"sudo"·;·then
1082 ····dnf·install·-y·"sudo"1075 ····dnf·install·-y·"sudo"
1083 fi1076 fi
  
1084 else1077 else
1085 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'1078 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
1086 fi1079 fi
 1080 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 1081 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1082 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1083 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1084 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 1085 package·--add=sudo
1087 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·U\x8Us\x8se\x8er\x8rs\x8s·R\x8Re\x8e-\x8-A\x8Au\x8ut\x8th\x8he\x8en\x8nt\x8ti\x8ic\x8ca\x8at\x8te\x8e·f\x8fo\x8or\x8r·P\x8Pr\x8ri\x8iv\x8vi\x8il\x8le\x8eg\x8ge\x8e·E\x8Es\x8sc\x8ca\x8al\x8la\x8at\x8ti\x8io\x8on\x8n·-\x8-·s\x8su\x8ud\x8do\x8o·!\x8!a\x8au\x8ut\x8th\x8he\x8en\x8nt\x8ti\x8ic\x8ca\x8at\x8te\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*1086 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·U\x8Us\x8se\x8er\x8rs\x8s·R\x8Re\x8e-\x8-A\x8Au\x8ut\x8th\x8he\x8en\x8nt\x8ti\x8ic\x8ca\x8at\x8te\x8e·f\x8fo\x8or\x8r·P\x8Pr\x8ri\x8iv\x8vi\x8il\x8le\x8eg\x8ge\x8e·E\x8Es\x8sc\x8ca\x8al\x8la\x8at\x8ti\x8io\x8on\x8n·-\x8-·s\x8su\x8ud\x8do\x8o·!\x8!a\x8au\x8ut\x8th\x8he\x8en\x8nt\x8ti\x8ic\x8ca\x8at\x8te\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
1088 The·sudo·!authenticate·option,·when·specified,·allows·a·user·to·execute·commands·using·sudo·without·having·to·authenticate.·This·should·be·disabled·by·making·sure·that·the·!authenticate·option·does·not·exist·in·/etc/sudoers·configuration·file·or·any·sudo·configuration·snippets·in·/etc/sudoers.d/.1087 The·sudo·!authenticate·option,·when·specified,·allows·a·user·to·execute·commands·using·sudo·without·having·to·authenticate.·This·should·be·disabled·by·making·sure·that·the·!authenticate·option·does·not·exist·in·/etc/sudoers·configuration·file·or·any·sudo·configuration·snippets·in·/etc/sudoers.d/.
1089 ············Without·re-authentication,·users·may·access·resources·or·perform·tasks·for·which·they·do·not·have·authorization.1088 ············Without·re-authentication,·users·may·access·resources·or·perform·tasks·for·which·they·do·not·have·authorization.
1090 Rationale:1089 Rationale:
1091 ············When·operating·systems·provide·the·capability·to·escalate·a·functional·capability,·it·is·critical·that·the·user·re-authenticate.1090 ············When·operating·systems·provide·the·capability·to·escalate·a·functional·capability,·it·is·critical·that·the·user·re-authenticate.
1092 Severity: ··medium1091 Severity: ··medium
1093 Rule·ID:····xccdf_org.ssgproject.content_rule_sudo_remove_no_authenticate1092 Rule·ID:····xccdf_org.ssgproject.content_rule_sudo_remove_no_authenticate
Offset 9161, 21 lines modifiedOffset 9161, 14 lines modified
9161 ··-·NIST-800-53-CM-6(a)9161 ··-·NIST-800-53-CM-6(a)
9162 ··-·enable_strategy9162 ··-·enable_strategy
9163 ··-·low_complexity9163 ··-·low_complexity
9164 ··-·low_disruption9164 ··-·low_disruption
9165 ··-·medium_severity9165 ··-·medium_severity
9166 ··-·no_reboot_needed9166 ··-·no_reboot_needed
9167 ··-·package_opensc_installed9167 ··-·package_opensc_installed
9168 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
9169 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
9170 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
9171 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
9172 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
9173 package·--add=opensc 
9174 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x89168 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
9175 [[packages]]9169 [[packages]]
9176 name·=·"opensc"9170 name·=·"opensc"
9177 version·=·"*"9171 version·=·"*"
9178 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x89172 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
9179 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low9173 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 9200, 14 lines modifiedOffset 9193, 21 lines modified
9200 if·!·rpm·-q·--quiet·"opensc"·;·then9193 if·!·rpm·-q·--quiet·"opensc"·;·then
9201 ····dnf·install·-y·"opensc"9194 ····dnf·install·-y·"opensc"
9202 fi9195 fi
  
9203 else9196 else
9204 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'9197 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
9205 fi9198 fi
 9199 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 9200 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 9201 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 9202 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 9203 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 9204 package·--add=opensc
9206 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·t\x8th\x8he\x8e·p\x8pc\x8cs\x8sc\x8c-\x8-l\x8li\x8it\x8te\x8e-\x8-c\x8cc\x8ci\x8id\x8d·p\x8pa\x8ac\x8ck\x8ka\x8ag\x8ge\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*9205 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·t\x8th\x8he\x8e·p\x8pc\x8cs\x8sc\x8c-\x8-l\x8li\x8it\x8te\x8e-\x8-c\x8cc\x8ci\x8id\x8d·p\x8pa\x8ac\x8ck\x8ka\x8ag\x8ge\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
9207 The·pcsc-lite-ccid·package·can·be·installed·with·the·following·command:9206 The·pcsc-lite-ccid·package·can·be·installed·with·the·following·command:
9208 $·sudo·dnf·install·pcsc-lite-ccid9207 $·sudo·dnf·install·pcsc-lite-ccid
Max diff block lines reached; 25875/31869 bytes (81.19%) of diff not shown.
309 KB
./usr/share/doc/ssg-nondebian/ssg-ol10-guide-ism_o_top_secret.html
    
Offset 17395, 144 lines modifiedOffset 17395, 144 lines modified
00043f20:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="00043f20:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
00043f30:·2369·646d·3530·3938·2220·7461·6269·6e64··#idm5098"·tabind00043f30:·2369·646d·3530·3938·2220·7461·6269·6e64··#idm5098"·tabind
00043f40:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but00043f40:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
00043f50:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand00043f50:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
00043f60:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title00043f60:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
00043f70:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re00043f70:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
00043f80:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">00043f80:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
 00043f90:·5265·6d65·6469·6174·696f·6e20·4f53·4275··Remediation·OSBu
 00043fa0:·696c·6420·426c·7565·7072·696e·7420·736e··ild·Blueprint·sn
 00043fb0:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br
 00043fc0:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
 00043fd0:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
 00043fe0:·6170·7365·2220·6964·3d22·6964·6d35·3039··apse"·id="idm509
 00043ff0:·3822·3e3c·7072·653e·3c63·6f64·653e·0a5b··8"><pre><code>.[
 00044000:·5b70·6163·6b61·6765·735d·5d0a·6e61·6d65··[packages]].name
 00044010:·203d·2022·6169·6465·220a·7665·7273·696f···=·"aide".versio
 00044020:·6e20·3d20·222a·220a·3c2f·636f·6465·3e3c··n·=·"*".</code><
 00044030:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl
 00044040:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc
 00044050:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl
 00044060:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat
 00044070:·612d·7461·7267·6574·3d22·2369·646d·3530··a-target="#idm50
 00044080:·3939·2220·7461·6269·6e64·6578·3d22·3022··99"·tabindex="0"
 00044090:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
 000440a0:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
 000440b0:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
 000440c0:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
 000440d0:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
 000440e0:·6174·696f·6e20·5075·7070·6574·2073·6e69··ation·Puppet·sni
 000440f0:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>
 00044100:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
 00044110:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
 00044120:·7073·6522·2069·643d·2269·646d·3530·3939··pse"·id="idm5099
 00044130:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="
 00044140:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri
 00044150:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border
 00044160:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens
 00044170:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp
 00044180:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>
 00044190:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
 000441a0:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:
 000441b0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
 000441c0:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re
 000441d0:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa
 000441e0:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr
 000441f0:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</
 00044200:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t
 00044210:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><
 00044220:·7072·653e·3c63·6f64·653e·696e·636c·7564··pre><code>includ
 00044230:·6520·696e·7374·616c·6c5f·6169·6465·0a0a··e·install_aide..
 00044240:·636c·6173·7320·696e·7374·616c·6c5f·6169··class·install_ai
 00044250:·6465·207b·0a20·2070·6163·6b61·6765·207b··de·{.··package·{
 00044260:·2027·6169·6465·273a·0a20·2020·2065·6e73···'aide':.····ens
 00044270:·7572·6520·3d26·6774·3b20·2769·6e73·7461··ure·=&gt;·'insta
 00044280:·6c6c·6564·272c·0a20·207d·0a7d·0a3c·2f63··lled',.··}.}.</c
 00044290:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div>
 000442a0:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt
 000442b0:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data-
 000442c0:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse
 000442d0:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
 000442e0:·6964·6d35·3130·3022·2074·6162·696e·6465··idm5100"·tabinde
 000442f0:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt
 00044300:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande
 00044310:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=
 00044320:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev
 00044330:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R
 00044340:·656d·6564·6961·7469·6f6e·2053·6865·6c6c··emediation·Shell
 00044350:·2073·6372·6970·7420·e287·b23c·2f61·3e3c···script·...</a><
 00044360:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
 00044370:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
 00044380:·6c6c·6170·7365·2220·6964·3d22·6964·6d35··llapse"·id="idm5
 00044390:·3130·3022·3e3c·7461·626c·6520·636c·6173··100"><table·clas
 000443a0:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s
 000443b0:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor
 000443c0:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond
 000443d0:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C
 000443e0:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><
 000443f0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
 00044400:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti
 00044410:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<
 00044420:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 00044430:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td
 00044440:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr>
 00044450:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy
 00044460:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable
 00044470:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl
 00044480:·653e·3c70·7265·3e3c·636f·6465·3e23·2052··e><pre><code>#·R
 00044490:·656d·6564·6961·7469·6f6e·2069·7320·6170··emediation·is·ap
 000444a0:·706c·6963·6162·6c65·206f·6e6c·7920·696e··plicable·only·in
 000444b0:·2063·6572·7461·696e·2070·6c61·7466·6f72···certain·platfor
 000444c0:·6d73·0a69·6620·7270·6d20·2d2d·7175·6965··ms.if·rpm·--quie
 000444d0:·7420·2d71·206b·6572·6e65·6c20·7c7c·2072··t·-q·kernel·||·r
 000444e0:·706d·202d·2d71·7569·6574·202d·7120·6b65··pm·--quiet·-q·ke
 000444f0:·726e·656c·2d75·656b·3b20·7468·656e·0a0a··rnel-uek;·then..
 00044500:·6966·2021·2072·706d·202d·7120·2d2d·7175··if·!·rpm·-q·--qu
 00044510:·6965·7420·2261·6964·6522·203b·2074·6865··iet·"aide"·;·the
 00044520:·6e0a·2020·2020·646e·6620·696e·7374·616c··n.····dnf·instal
 00044530:·6c20·2d79·2022·6169·6465·220a·6669·0a0a··l·-y·"aide".fi..
 00044540:·656c·7365·0a20·2020·2026·6774·3b26·616d··else.····&gt;&am
 00044550:·703b·3220·6563·686f·2027·5265·6d65·6469··p;2·echo·'Remedi
 00044560:·6174·696f·6e20·6973·206e·6f74·2061·7070··ation·is·not·app
 00044570:·6c69·6361·626c·652c·206e·6f74·6869·6e67··licable,·nothing
 00044580:·2077·6173·2064·6f6e·6527·0a66·690a·3c2f···was·done'.fi.</
 00044590:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div
 000445a0:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b
 000445b0:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data
 000445c0:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps
 000445d0:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
 000445e0:·2369·646d·3531·3031·2220·7461·6269·6e64··#idm5101"·tabind
 000445f0:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
 00044600:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
 00044610:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
 00044620:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
 00044630:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
00043f90:·5265·6d65·6469·6174·696f·6e20·416e·6163··Remediation·Anac00044640:·5265·6d65·6469·6174·696f·6e20·416e·6163··Remediation·Anac
00043fa0:·6f6e·6461·2073·6e69·7070·6574·20e2·87b2··onda·snippet·...00044650:·6f6e·6461·2073·6e69·7070·6574·20e2·87b2··onda·snippet·...
00043fb0:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla 
00043fc0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap 
00043fd0:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id= 
00043fe0:·2269·646d·3530·3938·223e·3c74·6162·6c65··"idm5098"><table 
00043ff0:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta 
00044000:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl 
00044010:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table 
00044020:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr> 
00044030:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:< 
00044040:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td> 
00044050:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis 
Max diff block lines reached; 265380/283900 bytes (93.48%) of diff not shown.
31.1 KB
html2text {}
    
Offset 718, 21 lines modifiedOffset 718, 14 lines modified
718 ··-·PCI-DSSv4-11.5.2718 ··-·PCI-DSSv4-11.5.2
719 ··-·enable_strategy719 ··-·enable_strategy
720 ··-·low_complexity720 ··-·low_complexity
721 ··-·low_disruption721 ··-·low_disruption
722 ··-·medium_severity722 ··-·medium_severity
723 ··-·no_reboot_needed723 ··-·no_reboot_needed
724 ··-·package_aide_installed724 ··-·package_aide_installed
725 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
726 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
727 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
728 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
729 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
730 package·--add=aide 
731 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8725 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
732 [[packages]]726 [[packages]]
733 name·=·"aide"727 name·=·"aide"
734 version·=·"*"728 version·=·"*"
735 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8729 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
736 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low730 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 757, 14 lines modifiedOffset 750, 21 lines modified
757 if·!·rpm·-q·--quiet·"aide"·;·then750 if·!·rpm·-q·--quiet·"aide"·;·then
758 ····dnf·install·-y·"aide"751 ····dnf·install·-y·"aide"
759 fi752 fi
  
760 else753 else
761 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'754 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
762 fi755 fi
 756 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 757 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 758 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 759 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 760 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 761 package·--add=aide
763 Group  ·Federal·Information·Processing·Standard·(FIPS)·  Group·contains·2·rules762 Group  ·Federal·Information·Processing·Standard·(FIPS)·  Group·contains·2·rules
764 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·Federal·Information·Processing·Standard·(FIPS)·is·a·computer·security·standard·which·is·developed·by·the·U.S.·Government·and·industry·working·groups·to·validate·the·quality·of·cryptographic·modules.·The·FIPS·standard·provides·four·security·levels·to·ensure·adequate·coverage·of·different·industries,·implementation·of·cryptographic·modules,·and·organizational·sizes·and·requirements.763 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·Federal·Information·Processing·Standard·(FIPS)·is·a·computer·security·standard·which·is·developed·by·the·U.S.·Government·and·industry·working·groups·to·validate·the·quality·of·cryptographic·modules.·The·FIPS·standard·provides·four·security·levels·to·ensure·adequate·coverage·of·different·industries,·implementation·of·cryptographic·modules,·and·organizational·sizes·and·requirements.
  
765 FIPS·140-2·is·the·current·standard·for·validating·that·mechanisms·used·to·access·cryptographic·modules·utilize·authentication·that·meets·industry·and·government·requirements.·For·government·systems,·this·allows·Security·Levels·1,·2,·3,·or·4·for·use·on·Oracle·Linux·10.764 FIPS·140-2·is·the·current·standard·for·validating·that·mechanisms·used·to·access·cryptographic·modules·utilize·authentication·that·meets·industry·and·government·requirements.·For·government·systems,·this·allows·Security·Levels·1,·2,·3,·or·4·for·use·on·Oracle·Linux·10.
  
766 See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8c\x8c_\x8s\x8s_\x8r\x8r_\x8c\x8c_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8l\x8l_\x8i\x8i_\x8c\x8c_\x8a\x8a_\x8t\x8t_\x8i\x8i_\x8o\x8o_\x8n\x8n_\x8s\x8s_\x8/\x8/_\x8P\x8P_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x8h\x8h_\x8t\x8t_\x8m\x8m_\x8l\x8l·for·more·information.765 See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8c\x8c_\x8s\x8s_\x8r\x8r_\x8c\x8c_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8l\x8l_\x8i\x8i_\x8c\x8c_\x8a\x8a_\x8t\x8t_\x8i\x8i_\x8o\x8o_\x8n\x8n_\x8s\x8s_\x8/\x8/_\x8P\x8P_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x8h\x8h_\x8t\x8t_\x8m\x8m_\x8l\x8l·for·more·information.
767 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8de\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*766 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8de\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
Offset 1042, 21 lines modifiedOffset 1042, 14 lines modified
1042 ··-·PCI-DSSv4-2.2.61042 ··-·PCI-DSSv4-2.2.6
1043 ··-·enable_strategy1043 ··-·enable_strategy
1044 ··-·low_complexity1044 ··-·low_complexity
1045 ··-·low_disruption1045 ··-·low_disruption
1046 ··-·medium_severity1046 ··-·medium_severity
1047 ··-·no_reboot_needed1047 ··-·no_reboot_needed
1048 ··-·package_sudo_installed1048 ··-·package_sudo_installed
1049 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
1050 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
1051 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
1052 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
1053 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
1054 package·--add=sudo 
1055 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81049 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
1056 [[packages]]1050 [[packages]]
1057 name·=·"sudo"1051 name·=·"sudo"
1058 version·=·"*"1052 version·=·"*"
1059 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81053 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1060 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1054 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 1081, 14 lines modifiedOffset 1074, 21 lines modified
1081 if·!·rpm·-q·--quiet·"sudo"·;·then1074 if·!·rpm·-q·--quiet·"sudo"·;·then
1082 ····dnf·install·-y·"sudo"1075 ····dnf·install·-y·"sudo"
1083 fi1076 fi
  
1084 else1077 else
1085 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'1078 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
1086 fi1079 fi
 1080 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 1081 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1082 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1083 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1084 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 1085 package·--add=sudo
1087 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·U\x8Us\x8se\x8er\x8rs\x8s·R\x8Re\x8e-\x8-A\x8Au\x8ut\x8th\x8he\x8en\x8nt\x8ti\x8ic\x8ca\x8at\x8te\x8e·f\x8fo\x8or\x8r·P\x8Pr\x8ri\x8iv\x8vi\x8il\x8le\x8eg\x8ge\x8e·E\x8Es\x8sc\x8ca\x8al\x8la\x8at\x8ti\x8io\x8on\x8n·-\x8-·s\x8su\x8ud\x8do\x8o·!\x8!a\x8au\x8ut\x8th\x8he\x8en\x8nt\x8ti\x8ic\x8ca\x8at\x8te\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*1086 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·U\x8Us\x8se\x8er\x8rs\x8s·R\x8Re\x8e-\x8-A\x8Au\x8ut\x8th\x8he\x8en\x8nt\x8ti\x8ic\x8ca\x8at\x8te\x8e·f\x8fo\x8or\x8r·P\x8Pr\x8ri\x8iv\x8vi\x8il\x8le\x8eg\x8ge\x8e·E\x8Es\x8sc\x8ca\x8al\x8la\x8at\x8ti\x8io\x8on\x8n·-\x8-·s\x8su\x8ud\x8do\x8o·!\x8!a\x8au\x8ut\x8th\x8he\x8en\x8nt\x8ti\x8ic\x8ca\x8at\x8te\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
1088 The·sudo·!authenticate·option,·when·specified,·allows·a·user·to·execute·commands·using·sudo·without·having·to·authenticate.·This·should·be·disabled·by·making·sure·that·the·!authenticate·option·does·not·exist·in·/etc/sudoers·configuration·file·or·any·sudo·configuration·snippets·in·/etc/sudoers.d/.1087 The·sudo·!authenticate·option,·when·specified,·allows·a·user·to·execute·commands·using·sudo·without·having·to·authenticate.·This·should·be·disabled·by·making·sure·that·the·!authenticate·option·does·not·exist·in·/etc/sudoers·configuration·file·or·any·sudo·configuration·snippets·in·/etc/sudoers.d/.
1089 ············Without·re-authentication,·users·may·access·resources·or·perform·tasks·for·which·they·do·not·have·authorization.1088 ············Without·re-authentication,·users·may·access·resources·or·perform·tasks·for·which·they·do·not·have·authorization.
1090 Rationale:1089 Rationale:
1091 ············When·operating·systems·provide·the·capability·to·escalate·a·functional·capability,·it·is·critical·that·the·user·re-authenticate.1090 ············When·operating·systems·provide·the·capability·to·escalate·a·functional·capability,·it·is·critical·that·the·user·re-authenticate.
1092 Severity: ··medium1091 Severity: ··medium
1093 Rule·ID:····xccdf_org.ssgproject.content_rule_sudo_remove_no_authenticate1092 Rule·ID:····xccdf_org.ssgproject.content_rule_sudo_remove_no_authenticate
Offset 9161, 21 lines modifiedOffset 9161, 14 lines modified
9161 ··-·NIST-800-53-CM-6(a)9161 ··-·NIST-800-53-CM-6(a)
9162 ··-·enable_strategy9162 ··-·enable_strategy
9163 ··-·low_complexity9163 ··-·low_complexity
9164 ··-·low_disruption9164 ··-·low_disruption
9165 ··-·medium_severity9165 ··-·medium_severity
9166 ··-·no_reboot_needed9166 ··-·no_reboot_needed
9167 ··-·package_opensc_installed9167 ··-·package_opensc_installed
9168 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
9169 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
9170 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
9171 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
9172 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
9173 package·--add=opensc 
9174 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x89168 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
9175 [[packages]]9169 [[packages]]
9176 name·=·"opensc"9170 name·=·"opensc"
9177 version·=·"*"9171 version·=·"*"
9178 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x89172 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
9179 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low9173 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 9200, 14 lines modifiedOffset 9193, 21 lines modified
9200 if·!·rpm·-q·--quiet·"opensc"·;·then9193 if·!·rpm·-q·--quiet·"opensc"·;·then
9201 ····dnf·install·-y·"opensc"9194 ····dnf·install·-y·"opensc"
9202 fi9195 fi
  
9203 else9196 else
9204 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'9197 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
9205 fi9198 fi
 9199 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 9200 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 9201 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 9202 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 9203 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 9204 package·--add=opensc
9206 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·t\x8th\x8he\x8e·p\x8pc\x8cs\x8sc\x8c-\x8-l\x8li\x8it\x8te\x8e-\x8-c\x8cc\x8ci\x8id\x8d·p\x8pa\x8ac\x8ck\x8ka\x8ag\x8ge\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*9205 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·t\x8th\x8he\x8e·p\x8pc\x8cs\x8sc\x8c-\x8-l\x8li\x8it\x8te\x8e-\x8-c\x8cc\x8ci\x8id\x8d·p\x8pa\x8ac\x8ck\x8ka\x8ag\x8ge\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
9207 The·pcsc-lite-ccid·package·can·be·installed·with·the·following·command:9206 The·pcsc-lite-ccid·package·can·be·installed·with·the·following·command:
9208 $·sudo·dnf·install·pcsc-lite-ccid9207 $·sudo·dnf·install·pcsc-lite-ccid
Max diff block lines reached; 25875/31869 bytes (81.19%) of diff not shown.
346 KB
./usr/share/doc/ssg-nondebian/ssg-ol10-guide-pci-dss.html
    
Offset 17383, 143 lines modifiedOffset 17383, 143 lines modified
00043e60:·6172·6765·743d·2223·6964·6d35·3039·3822··arget="#idm5098"00043e60:·6172·6765·743d·2223·6964·6d35·3039·3822··arget="#idm5098"
00043e70:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro00043e70:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro
00043e80:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria00043e80:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria
00043e90:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false00043e90:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false
00043ea0:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat00043ea0:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat
00043eb0:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre00043eb0:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre
00043ec0:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati00043ec0:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati
 00043ed0:·6f6e·204f·5342·7569·6c64·2042·6c75·6570··on·OSBuild·Bluep
 00043ee0:·7269·6e74·2073·6e69·7070·6574·20e2·87b2··rint·snippet·...
 00043ef0:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
 00043f00:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
 00043f10:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
 00043f20:·2269·646d·3530·3938·223e·3c70·7265·3e3c··"idm5098"><pre><
 00043f30:·636f·6465·3e0a·5b5b·7061·636b·6167·6573··code>.[[packages
 00043f40:·5d5d·0a6e·616d·6520·3d20·2261·6964·6522··]].name·=·"aide"
 00043f50:·0a76·6572·7369·6f6e·203d·2022·2a22·0a3c··.version·=·"*".<
 00043f60:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di
 00043f70:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn·
 00043f80:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat
 00043f90:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap
 00043fa0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
 00043fb0:·2223·6964·6d35·3039·3922·2074·6162·696e··"#idm5099"·tabin
 00043fc0:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
 00043fd0:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
 00043fe0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
 00043ff0:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
 00044000:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
 00044010:·3e52·656d·6564·6961·7469·6f6e·2050·7570··>Remediation·Pup
 00044020:·7065·7420·736e·6970·7065·7420·e287·b23c··pet·snippet·...<
 00044030:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas
 00044040:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps
 00044050:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="
 00044060:·6964·6d35·3039·3922·3e3c·7461·626c·6520··idm5099"><table·
 00044070:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab
 00044080:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table
 00044090:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-
 000440a0:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><
 000440b0:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</
 000440c0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
 000440d0:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr
 000440e0:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>
 000440f0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
 00044100:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th
 00044110:·3e3c·7464·3e66·616c·7365·3c2f·7464·3e3c··><td>false</td><
 00044120:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra
 00044130:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en
 00044140:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></
 00044150:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code
 00044160:·3e69·6e63·6c75·6465·2069·6e73·7461·6c6c··>include·install
 00044170:·5f61·6964·650a·0a63·6c61·7373·2069·6e73··_aide..class·ins
 00044180:·7461·6c6c·5f61·6964·6520·7b0a·2020·7061··tall_aide·{.··pa
 00044190:·636b·6167·6520·7b20·2761·6964·6527·3a0a··ckage·{·'aide':.
 000441a0:·2020·2020·656e·7375·7265·203d·2667·743b······ensure·=&gt;
 000441b0:·2027·696e·7374·616c·6c65·6427·2c0a·2020···'installed',.··
 000441c0:·7d0a·7d0a·3c2f·636f·6465·3e3c·2f70·7265··}.}.</code></pre
 000441d0:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class=
 000441e0:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success
 000441f0:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c
 00044200:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta
 00044210:·7267·6574·3d22·2369·646d·3531·3030·2220··rget="#idm5100"·
 00044220:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol
 00044230:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-
 00044240:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"
 00044250:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate
 00044260:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href
 00044270:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio
 00044280:·6e20·5368·656c·6c20·7363·7269·7074·20e2··n·Shell·script·.
 00044290:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c
 000442a0:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
 000442b0:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
 000442c0:·643d·2269·646d·3531·3030·223e·3c74·6162··d="idm5100"><tab
 000442d0:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·
 000442e0:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta
 000442f0:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab
 00044300:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t
 00044310:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity
 00044320:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
 00044330:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D
 00044340:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><
 00044350:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
 00044360:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:<
 00044370:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t
 00044380:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S
 00044390:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td
 000443a0:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr
 000443b0:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c
 000443c0:·6f64·653e·2320·5265·6d65·6469·6174·696f··ode>#·Remediatio
 000443d0:·6e20·6973·2061·7070·6c69·6361·626c·6520··n·is·applicable·
 000443e0:·6f6e·6c79·2069·6e20·6365·7274·6169·6e20··only·in·certain·
 000443f0:·706c·6174·666f·726d·730a·6966·2072·706d··platforms.if·rpm
 00044400:·202d·2d71·7569·6574·202d·7120·6b65·726e···--quiet·-q·kern
 00044410:·656c·207c·7c20·7270·6d20·2d2d·7175·6965··el·||·rpm·--quie
 00044420:·7420·2d71·206b·6572·6e65·6c2d·7565·6b3b··t·-q·kernel-uek;
 00044430:·2074·6865·6e0a·0a69·6620·2120·7270·6d20···then..if·!·rpm·
 00044440:·2d71·202d·2d71·7569·6574·2022·6169·6465··-q·--quiet·"aide
 00044450:·2220·3b20·7468·656e·0a20·2020·2064·6e66··"·;·then.····dnf
 00044460:·2069·6e73·7461·6c6c·202d·7920·2261·6964···install·-y·"aid
 00044470:·6522·0a66·690a·0a65·6c73·650a·2020·2020··e".fi..else.····
 00044480:·2667·743b·2661·6d70·3b32·2065·6368·6f20··&gt;&amp;2·echo·
 00044490:·2752·656d·6564·6961·7469·6f6e·2069·7320··'Remediation·is·
 000444a0:·6e6f·7420·6170·706c·6963·6162·6c65·2c20··not·applicable,·
 000444b0:·6e6f·7468·696e·6720·7761·7320·646f·6e65··nothing·was·done
 000444c0:·270a·6669·0a3c·2f63·6f64·653e·3c2f·7072··'.fi.</code></pr
 000444d0:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class
 000444e0:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes
 000444f0:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle="
 00044500:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t
 00044510:·6172·6765·743d·2223·6964·6d35·3130·3122··arget="#idm5101"
 00044520:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro
 00044530:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria
 00044540:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false
 00044550:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat
 00044560:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre
 00044570:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati
00043ed0:·6f6e·2041·6e61·636f·6e64·6120·736e·6970··on·Anaconda·snip00044580:·6f6e·2041·6e61·636f·6e64·6120·736e·6970··on·Anaconda·snip
00043ee0:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br>< 
00043ef0:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel 
00043f00:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap 
00043f10:·7365·2220·6964·3d22·6964·6d35·3039·3822··se"·id="idm5098" 
00043f20:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t 
00043f30:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip 
00043f40:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere 
00043f50:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense 
00043f60:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl 
00043f70:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l 
00043f80:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr> 
00043f90:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:< 
Max diff block lines reached; 298852/317234 bytes (94.21%) of diff not shown.
36.6 KB
html2text {}
    
Offset 715, 21 lines modifiedOffset 715, 14 lines modified
715 ··-·PCI-DSSv4-11.5.2715 ··-·PCI-DSSv4-11.5.2
716 ··-·enable_strategy716 ··-·enable_strategy
717 ··-·low_complexity717 ··-·low_complexity
718 ··-·low_disruption718 ··-·low_disruption
719 ··-·medium_severity719 ··-·medium_severity
720 ··-·no_reboot_needed720 ··-·no_reboot_needed
721 ··-·package_aide_installed721 ··-·package_aide_installed
722 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
723 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
724 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
725 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
726 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
727 package·--add=aide 
728 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8722 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
729 [[packages]]723 [[packages]]
730 name·=·"aide"724 name·=·"aide"
731 version·=·"*"725 version·=·"*"
732 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8726 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
733 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low727 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 754, 14 lines modifiedOffset 747, 21 lines modified
754 if·!·rpm·-q·--quiet·"aide"·;·then747 if·!·rpm·-q·--quiet·"aide"·;·then
755 ····dnf·install·-y·"aide"748 ····dnf·install·-y·"aide"
756 fi749 fi
  
757 else750 else
758 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'751 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
759 fi752 fi
 753 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 754 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 755 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 756 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 757 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 758 package·--add=aide
760 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*759 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
761 Run·the·following·command·to·generate·a·new·database:760 Run·the·following·command·to·generate·a·new·database:
762 $·sudo·/usr/sbin/aide·--init761 $·sudo·/usr/sbin/aide·--init
763 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:762 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
764 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz763 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
765 To·initiate·a·manual·check,·run·the·following·command:764 To·initiate·a·manual·check,·run·the·following·command:
766 $·sudo·/usr/sbin/aide·--check765 $·sudo·/usr/sbin/aide·--check
Offset 2848, 21 lines modifiedOffset 2848, 14 lines modified
2848 ··-·PCI-DSSv4-2.2.62848 ··-·PCI-DSSv4-2.2.6
2849 ··-·enable_strategy2849 ··-·enable_strategy
2850 ··-·low_complexity2850 ··-·low_complexity
2851 ··-·low_disruption2851 ··-·low_disruption
2852 ··-·medium_severity2852 ··-·medium_severity
2853 ··-·no_reboot_needed2853 ··-·no_reboot_needed
2854 ··-·package_sudo_installed2854 ··-·package_sudo_installed
2855 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
2856 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
2857 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
2858 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
2859 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
2860 package·--add=sudo 
2861 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x82855 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
2862 [[packages]]2856 [[packages]]
2863 name·=·"sudo"2857 name·=·"sudo"
2864 version·=·"*"2858 version·=·"*"
2865 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x82859 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
2866 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low2860 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 2887, 14 lines modifiedOffset 2880, 21 lines modified
2887 if·!·rpm·-q·--quiet·"sudo"·;·then2880 if·!·rpm·-q·--quiet·"sudo"·;·then
2888 ····dnf·install·-y·"sudo"2881 ····dnf·install·-y·"sudo"
2889 fi2882 fi
  
2890 else2883 else
2891 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'2884 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
2892 fi2885 fi
 2886 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 2887 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 2888 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 2889 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 2890 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 2891 package·--add=sudo
2893 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·O\x8On\x8nl\x8ly\x8y·U\x8Us\x8se\x8er\x8rs\x8s·L\x8Lo\x8og\x8gg\x8ge\x8ed\x8d·I\x8In\x8n·T\x8To\x8o·R\x8Re\x8ea\x8al\x8l·t\x8tt\x8ty\x8y·C\x8Ca\x8an\x8n·E\x8Ex\x8xe\x8ec\x8cu\x8ut\x8te\x8e·S\x8Su\x8ud\x8do\x8o·-\x8-·s\x8su\x8ud\x8do\x8o·u\x8us\x8se\x8e_\x8_p\x8pt\x8ty\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*2892 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·O\x8On\x8nl\x8ly\x8y·U\x8Us\x8se\x8er\x8rs\x8s·L\x8Lo\x8og\x8gg\x8ge\x8ed\x8d·I\x8In\x8n·T\x8To\x8o·R\x8Re\x8ea\x8al\x8l·t\x8tt\x8ty\x8y·C\x8Ca\x8an\x8n·E\x8Ex\x8xe\x8ec\x8cu\x8ut\x8te\x8e·S\x8Su\x8ud\x8do\x8o·-\x8-·s\x8su\x8ud\x8do\x8o·u\x8us\x8se\x8e_\x8_p\x8pt\x8ty\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
2894 The·sudo·use_pty·tag,·when·specified,·will·only·execute·sudo·commands·from·users·logged·in·to·a·real·tty.·This·should·be·enabled·by·making·sure·that·the·use_pty·tag·exists·in·/etc/sudoers·configuration·file·or·any·sudo·configuration·snippets·in·/etc/sudoers.d/.2893 The·sudo·use_pty·tag,·when·specified,·will·only·execute·sudo·commands·from·users·logged·in·to·a·real·tty.·This·should·be·enabled·by·making·sure·that·the·use_pty·tag·exists·in·/etc/sudoers·configuration·file·or·any·sudo·configuration·snippets·in·/etc/sudoers.d/.
2895 Rationale:··Requiring·that·sudo·commands·be·run·in·a·pseudo-terminal·can·prevent·an·attacker·from·retaining·access·to·the·user's·terminal·after·the·main·program·has·finished·executing.2894 Rationale:··Requiring·that·sudo·commands·be·run·in·a·pseudo-terminal·can·prevent·an·attacker·from·retaining·access·to·the·user's·terminal·after·the·main·program·has·finished·executing.
2896 Severity: ··medium2895 Severity: ··medium
2897 Rule·ID:····xccdf_org.ssgproject.content_rule_sudo_add_use_pty2896 Rule·ID:····xccdf_org.ssgproject.content_rule_sudo_add_use_pty
2898 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s··Req-10.2.52897 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s··Req-10.2.5
2899 References:·_\x8a_\x8n_\x8s_\x8s_\x8i···R392898 References:·_\x8a_\x8n_\x8s_\x8s_\x8i···R39
Offset 3409, 21 lines modifiedOffset 3409, 14 lines modified
3409 ··-·PCI-DSSv4-3.5.1.23409 ··-·PCI-DSSv4-3.5.1.2
3410 ··-·enable_strategy3410 ··-·enable_strategy
3411 ··-·low_complexity3411 ··-·low_complexity
3412 ··-·low_disruption3412 ··-·low_disruption
3413 ··-·medium_severity3413 ··-·medium_severity
3414 ··-·no_reboot_needed3414 ··-·no_reboot_needed
3415 ··-·package_cryptsetup-luks_installed3415 ··-·package_cryptsetup-luks_installed
3416 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
3417 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
3418 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
3419 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
3420 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
3421 package·--add=cryptsetup 
3422 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x83416 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
3423 [[packages]]3417 [[packages]]
3424 name·=·"cryptsetup"3418 name·=·"cryptsetup"
3425 version·=·"*"3419 version·=·"*"
3426 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x83420 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
3427 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low3421 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 3442, 14 lines modifiedOffset 3435, 21 lines modified
3442 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low3435 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
3443 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false3436 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
3444 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable3437 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
3445 if·!·rpm·-q·--quiet·"cryptsetup"·;·then3438 if·!·rpm·-q·--quiet·"cryptsetup"·;·then
3446 ····dnf·install·-y·"cryptsetup"3439 ····dnf·install·-y·"cryptsetup"
3447 fi3440 fi
 3441 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 3442 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 3443 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 3444 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 3445 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 3446 package·--add=cryptsetup
3448 Group  ·Updating·Software·  Group·contains·3·rules3447 Group  ·Updating·Software·  Group·contains·3·rules
3449 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·dnf·command·line·tool·is·used·to·install·and·update·software·packages.·The·system·also·provides·a·graphical·software·update·tool·in·the·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·menu,·in·the·A\x8Ad\x8dm\x8mi\x8in\x8ni\x8is\x8st\x8tr\x8ra\x8at\x8ti\x8io\x8on\x8n·submenu,·called·S\x8So\x8of\x8ft\x8tw\x8wa\x8ar\x8re\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8e.3448 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·dnf·command·line·tool·is·used·to·install·and·update·software·packages.·The·system·also·provides·a·graphical·software·update·tool·in·the·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·menu,·in·the·A\x8Ad\x8dm\x8mi\x8in\x8ni\x8is\x8st\x8tr\x8ra\x8at\x8ti\x8io\x8on\x8n·submenu,·called·S\x8So\x8of\x8ft\x8tw\x8wa\x8ar\x8re\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8e.
  
Max diff block lines reached; 31562/37417 bytes (84.35%) of diff not shown.
1.23 MB
./usr/share/doc/ssg-nondebian/ssg-ol10-guide-stig.html
    
Offset 15144, 144 lines modifiedOffset 15144, 144 lines modified
0003b270:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target0003b270:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
0003b280:·3d22·2369·646d·3530·3938·2220·7461·6269··="#idm5098"·tabi0003b280:·3d22·2369·646d·3530·3938·2220·7461·6269··="#idm5098"·tabi
0003b290:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b0003b290:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
0003b2a0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa0003b2a0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
0003b2b0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit0003b2b0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
0003b2c0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·0003b2c0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
0003b2d0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!0003b2d0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
 0003b2e0:·223e·5265·6d65·6469·6174·696f·6e20·4f53··">Remediation·OS
 0003b2f0:·4275·696c·6420·426c·7565·7072·696e·7420··Build·Blueprint·
 0003b300:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><
 0003b310:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
 0003b320:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
 0003b330:·6c6c·6170·7365·2220·6964·3d22·6964·6d35··llapse"·id="idm5
 0003b340:·3039·3822·3e3c·7072·653e·3c63·6f64·653e··098"><pre><code>
 0003b350:·0a5b·5b70·6163·6b61·6765·735d·5d0a·6e61··.[[packages]].na
 0003b360:·6d65·203d·2022·6169·6465·220a·7665·7273··me·=·"aide".vers
 0003b370:·696f·6e20·3d20·222a·220a·3c2f·636f·6465··ion·=·"*".</code
 0003b380:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a·
 0003b390:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s
 0003b3a0:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog
 0003b3b0:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d
 0003b3c0:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
 0003b3d0:·3530·3939·2220·7461·6269·6e64·6578·3d22··5099"·tabindex="
 0003b3e0:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
 0003b3f0:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
 0003b400:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
 0003b410:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
 0003b420:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
 0003b430:·6469·6174·696f·6e20·5075·7070·6574·2073··diation·Puppet·s
 0003b440:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b
 0003b450:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
 0003b460:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
 0003b470:·6c61·7073·6522·2069·643d·2269·646d·3530··lapse"·id="idm50
 0003b480:·3939·223e·3c74·6162·6c65·2063·6c61·7373··99"><table·class
 0003b490:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st
 0003b4a0:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord
 0003b4b0:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde
 0003b4c0:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co
 0003b4d0:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t
 0003b4e0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
 0003b4f0:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio
 0003b500:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</
 0003b510:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 0003b520:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td>
 0003b530:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr><
 0003b540:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:
 0003b550:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<
 0003b560:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table
 0003b570:·3e3c·7072·653e·3c63·6f64·653e·696e·636c··><pre><code>incl
 0003b580:·7564·6520·696e·7374·616c·6c5f·6169·6465··ude·install_aide
 0003b590:·0a0a·636c·6173·7320·696e·7374·616c·6c5f··..class·install_
 0003b5a0:·6169·6465·207b·0a20·2070·6163·6b61·6765··aide·{.··package
 0003b5b0:·207b·2027·6169·6465·273a·0a20·2020·2065···{·'aide':.····e
 0003b5c0:·6e73·7572·6520·3d26·6774·3b20·2769·6e73··nsure·=&gt;·'ins
 0003b5d0:·7461·6c6c·6564·272c·0a20·207d·0a7d·0a3c··talled',.··}.}.<
 0003b5e0:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di
 0003b5f0:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn·
 0003b600:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat
 0003b610:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap
 0003b620:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
 0003b630:·2223·6964·6d35·3130·3022·2074·6162·696e··"#idm5100"·tabin
 0003b640:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
 0003b650:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
 0003b660:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
 0003b670:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
 0003b680:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
 0003b690:·3e52·656d·6564·6961·7469·6f6e·2053·6865··>Remediation·She
 0003b6a0:·6c6c·2073·6372·6970·7420·e287·b23c·2f61··ll·script·...</a
 0003b6b0:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
 0003b6c0:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
 0003b6d0:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
 0003b6e0:·6d35·3130·3022·3e3c·7461·626c·6520·636c··m5100"><table·cl
 0003b6f0:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table
 0003b700:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b
 0003b710:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co
 0003b720:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th
 0003b730:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th
 0003b740:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
 0003b750:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup
 0003b760:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo
 0003b770:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
 0003b780:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th><
 0003b790:·7464·3e66·616c·7365·3c2f·7464·3e3c·2f74··td>false</td></t
 0003b7a0:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate
 0003b7b0:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab
 0003b7c0:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta
 0003b7d0:·626c·653e·3c70·7265·3e3c·636f·6465·3e23··ble><pre><code>#
 0003b7e0:·2052·656d·6564·6961·7469·6f6e·2069·7320···Remediation·is·
 0003b7f0:·6170·706c·6963·6162·6c65·206f·6e6c·7920··applicable·only·
 0003b800:·696e·2063·6572·7461·696e·2070·6c61·7466··in·certain·platf
 0003b810:·6f72·6d73·0a69·6620·7270·6d20·2d2d·7175··orms.if·rpm·--qu
 0003b820:·6965·7420·2d71·206b·6572·6e65·6c20·7c7c··iet·-q·kernel·||
 0003b830:·2072·706d·202d·2d71·7569·6574·202d·7120···rpm·--quiet·-q·
 0003b840:·6b65·726e·656c·2d75·656b·3b20·7468·656e··kernel-uek;·then
 0003b850:·0a0a·6966·2021·2072·706d·202d·7120·2d2d··..if·!·rpm·-q·--
 0003b860:·7175·6965·7420·2261·6964·6522·203b·2074··quiet·"aide"·;·t
 0003b870:·6865·6e0a·2020·2020·646e·6620·696e·7374··hen.····dnf·inst
 0003b880:·616c·6c20·2d79·2022·6169·6465·220a·6669··all·-y·"aide".fi
 0003b890:·0a0a·656c·7365·0a20·2020·2026·6774·3b26··..else.····&gt;&
 0003b8a0:·616d·703b·3220·6563·686f·2027·5265·6d65··amp;2·echo·'Reme
 0003b8b0:·6469·6174·696f·6e20·6973·206e·6f74·2061··diation·is·not·a
 0003b8c0:·7070·6c69·6361·626c·652c·206e·6f74·6869··pplicable,·nothi
 0003b8d0:·6e67·2077·6173·2064·6f6e·6527·0a66·690a··ng·was·done'.fi.
 0003b8e0:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d
 0003b8f0:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn
 0003b900:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da
 0003b910:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla
 0003b920:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
 0003b930:·3d22·2369·646d·3531·3031·2220·7461·6269··="#idm5101"·tabi
 0003b940:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
 0003b950:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
 0003b960:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
 0003b970:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
 0003b980:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
0003b2e0:·223e·5265·6d65·6469·6174·696f·6e20·416e··">Remediation·An0003b990:·223e·5265·6d65·6469·6174·696f·6e20·416e··">Remediation·An
0003b2f0:·6163·6f6e·6461·2073·6e69·7070·6574·20e2··aconda·snippet·.0003b9a0:·6163·6f6e·6461·2073·6e69·7070·6574·20e2··aconda·snippet·.
0003b300:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c0003b9b0:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c
0003b310:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll0003b9c0:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
0003b320:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i0003b9d0:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
0003b330:·643d·2269·646d·3530·3938·223e·3c74·6162··d="idm5098"><tab0003b9e0:·643d·2269·646d·3531·3031·223e·3c74·6162··d="idm5101"><tab
0003b340:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·0003b9f0:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·
0003b350:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta0003ba00:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta
0003b360:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab0003ba10:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab
0003b370:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t0003ba20:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t
0003b380:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity0003ba30:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity
0003b390:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t0003ba40:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
0003b3a0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D0003ba50:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D
Max diff block lines reached; 1151702/1170222 bytes (98.42%) of diff not shown.
113 KB
html2text {}
    
Offset 136, 21 lines modifiedOffset 136, 14 lines modified
136 ··-·PCI-DSSv4-11.5.2136 ··-·PCI-DSSv4-11.5.2
137 ··-·enable_strategy137 ··-·enable_strategy
138 ··-·low_complexity138 ··-·low_complexity
139 ··-·low_disruption139 ··-·low_disruption
140 ··-·medium_severity140 ··-·medium_severity
141 ··-·no_reboot_needed141 ··-·no_reboot_needed
142 ··-·package_aide_installed142 ··-·package_aide_installed
143 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
144 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
145 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
146 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
147 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
148 package·--add=aide 
149 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8143 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
150 [[packages]]144 [[packages]]
151 name·=·"aide"145 name·=·"aide"
152 version·=·"*"146 version·=·"*"
153 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8147 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
154 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low148 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 175, 14 lines modifiedOffset 168, 21 lines modified
175 if·!·rpm·-q·--quiet·"aide"·;·then168 if·!·rpm·-q·--quiet·"aide"·;·then
176 ····dnf·install·-y·"aide"169 ····dnf·install·-y·"aide"
177 fi170 fi
  
178 else171 else
179 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'172 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
180 fi173 fi
 174 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 175 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 176 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 177 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 178 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 179 package·--add=aide
181 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*180 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
182 Run·the·following·command·to·generate·a·new·database:181 Run·the·following·command·to·generate·a·new·database:
183 $·sudo·/usr/sbin/aide·--init182 $·sudo·/usr/sbin/aide·--init
184 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:183 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
185 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz184 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
186 To·initiate·a·manual·check,·run·the·following·command:185 To·initiate·a·manual·check,·run·the·following·command:
187 $·sudo·/usr/sbin/aide·--check186 $·sudo·/usr/sbin/aide·--check
Offset 1997, 21 lines modifiedOffset 1997, 14 lines modified
1997 ··tags:1997 ··tags:
1998 ··-·enable_strategy1998 ··-·enable_strategy
1999 ··-·low_complexity1999 ··-·low_complexity
2000 ··-·low_disruption2000 ··-·low_disruption
2001 ··-·medium_severity2001 ··-·medium_severity
2002 ··-·no_reboot_needed2002 ··-·no_reboot_needed
2003 ··-·package_crypto-policies_installed2003 ··-·package_crypto-policies_installed
2004 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
2005 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
2006 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
2007 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
2008 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
2009 package·--add=crypto-policies 
2010 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x82004 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
2011 [[packages]]2005 [[packages]]
2012 name·=·"crypto-policies"2006 name·=·"crypto-policies"
2013 version·=·"*"2007 version·=·"*"
2014 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x82008 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
2015 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low2009 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 2030, 14 lines modifiedOffset 2023, 21 lines modified
2030 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low2023 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
2031 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false2024 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
2032 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable2025 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
2033 if·!·rpm·-q·--quiet·"crypto-policies"·;·then2026 if·!·rpm·-q·--quiet·"crypto-policies"·;·then
2034 ····dnf·install·-y·"crypto-policies"2027 ····dnf·install·-y·"crypto-policies"
2035 fi2028 fi
 2029 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 2030 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 2031 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 2032 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 2033 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 2034 package·--add=crypto-policies
2036 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·B\x8BI\x8IN\x8ND\x8D·t\x8to\x8o·u\x8us\x8se\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8o·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*2035 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·B\x8BI\x8IN\x8ND\x8D·t\x8to\x8o·u\x8us\x8se\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8o·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
2037 Crypto·Policies·provide·a·centralized·control·over·crypto·algorithms·usage·of·many·packages.·BIND·is·supported·by·crypto·policy,·but·the·BIND·configuration·may·be·set·up·to·ignore·it.·To·check·that·Crypto·Policies·settings·are·configured·correctly,·ensure·that·the·/etc/named.conf·includes·the·appropriate·configuration:·In·the·options·section·of·/etc/named.conf,·make·sure·that·the·following·line·is·not·commented·out·or·superseded·by·later·includes:·include·"/etc/crypto-policies/back-ends/bind.config";2036 Crypto·Policies·provide·a·centralized·control·over·crypto·algorithms·usage·of·many·packages.·BIND·is·supported·by·crypto·policy,·but·the·BIND·configuration·may·be·set·up·to·ignore·it.·To·check·that·Crypto·Policies·settings·are·configured·correctly,·ensure·that·the·/etc/named.conf·includes·the·appropriate·configuration:·In·the·options·section·of·/etc/named.conf,·make·sure·that·the·following·line·is·not·commented·out·or·superseded·by·later·includes:·include·"/etc/crypto-policies/back-ends/bind.config";
2038 Rationale:··Overriding·the·system·crypto·policy·makes·the·behavior·of·the·BIND·service·violate·expectations,·and·makes·system·configuration·more·fragmented.2037 Rationale:··Overriding·the·system·crypto·policy·makes·the·behavior·of·the·BIND·service·violate·expectations,·and·makes·system·configuration·more·fragmented.
2039 Severity: ··high2038 Severity: ··high
2040 Rule·ID:····xccdf_org.ssgproject.content_rule_configure_bind_crypto_policy2039 Rule·ID:····xccdf_org.ssgproject.content_rule_configure_bind_crypto_policy
2041 ············_\x8d_\x8i_\x8s_\x8a·····CCI-002418,·CCI-0024222040 ············_\x8d_\x8i_\x8s_\x8a·····CCI-002418,·CCI-002422
2042 References:·_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.12041 References:·_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1
Offset 4883, 21 lines modifiedOffset 4883, 14 lines modified
4883 ··-·NIST-800-53-CM-7(b)4883 ··-·NIST-800-53-CM-7(b)
4884 ··-·disable_strategy4884 ··-·disable_strategy
4885 ··-·low_complexity4885 ··-·low_complexity
4886 ··-·low_disruption4886 ··-·low_disruption
4887 ··-·medium_severity4887 ··-·medium_severity
4888 ··-·no_reboot_needed4888 ··-·no_reboot_needed
4889 ··-·package_gdm_removed4889 ··-·package_gdm_removed
4890 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
4891 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
4892 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
4893 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
4894 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable 
  
4895 package·--remove=gdm 
4896 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x84890 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
4897 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low4891 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
4898 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low4892 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
4899 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false4893 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
4900 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable4894 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
4901 include·remove_gdm4895 include·remove_gdm
  
Offset 4923, 14 lines modifiedOffset 4916, 21 lines modified
4923 if·rpm·-q·--quiet·"gdm"·;·then4916 if·rpm·-q·--quiet·"gdm"·;·then
4924 dnf·remove·-y·--noautoremove·"gdm"4917 dnf·remove·-y·--noautoremove·"gdm"
4925 fi4918 fi
  
4926 else4919 else
4927 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'4920 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
4928 fi4921 fi
 4922 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 4923 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 4924 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 4925 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 4926 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
  
 4927 package·--remove=gdm
4929 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·M\x8Ma\x8ak\x8ke\x8e·s\x8su\x8ur\x8re\x8e·t\x8th\x8ha\x8at\x8t·t\x8th\x8he\x8e·d\x8dc\x8co\x8on\x8nf\x8f·d\x8da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8es\x8s·a\x8ar\x8re\x8e·u\x8up\x8p-\x8-t\x8to\x8o-\x8-d\x8da\x8at\x8te\x8e·w\x8wi\x8it\x8th\x8h·r\x8re\x8eg\x8ga\x8ar\x8rd\x8ds\x8s·t\x8to\x8o·r\x8re\x8es\x8sp\x8pe\x8ec\x8ct\x8ti\x8iv\x8ve\x8e·k\x8ke\x8ey\x8yf\x8fi\x8il\x8le\x8es\x8s·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*4928 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·M\x8Ma\x8ak\x8ke\x8e·s\x8su\x8ur\x8re\x8e·t\x8th\x8ha\x8at\x8t·t\x8th\x8he\x8e·d\x8dc\x8co\x8on\x8nf\x8f·d\x8da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8es\x8s·a\x8ar\x8re\x8e·u\x8up\x8p-\x8-t\x8to\x8o-\x8-d\x8da\x8at\x8te\x8e·w\x8wi\x8it\x8th\x8h·r\x8re\x8eg\x8ga\x8ar\x8rd\x8ds\x8s·t\x8to\x8o·r\x8re\x8es\x8sp\x8pe\x8ec\x8ct\x8ti\x8iv\x8ve\x8e·k\x8ke\x8ey\x8yf\x8fi\x8il\x8le\x8es\x8s·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
4930 By·default,·DConf·uses·a·binary·database·as·a·data·backend.·The·system-level·database·is·compiled·from·keyfiles·in·the·/etc/dconf/db/·directory·by·the4929 By·default,·DConf·uses·a·binary·database·as·a·data·backend.·The·system-level·database·is·compiled·from·keyfiles·in·the·/etc/dconf/db/·directory·by·the
4931 dconf·update4930 dconf·update
Max diff block lines reached; 110286/116195 bytes (94.91%) of diff not shown.
1.21 MB
./usr/share/doc/ssg-nondebian/ssg-ol10-guide-stig_gui.html
    
Offset 15139, 144 lines modifiedOffset 15139, 144 lines modified
0003b220:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe0003b220:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
0003b230:·743d·2223·6964·6d35·3039·3822·2074·6162··t="#idm5098"·tab0003b230:·743d·2223·6964·6d35·3039·3822·2074·6162··t="#idm5098"·tab
0003b240:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="0003b240:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
0003b250:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp0003b250:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
0003b260:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti0003b260:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
0003b270:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to0003b270:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
0003b280:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#0003b280:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
 0003b290:·2122·3e52·656d·6564·6961·7469·6f6e·204f··!">Remediation·O
 0003b2a0:·5342·7569·6c64·2042·6c75·6570·7269·6e74··SBuild·Blueprint
 0003b2b0:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>
 0003b2c0:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="
 0003b2d0:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c
 0003b2e0:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm
 0003b2f0:·3530·3938·223e·3c70·7265·3e3c·636f·6465··5098"><pre><code
 0003b300:·3e0a·5b5b·7061·636b·6167·6573·5d5d·0a6e··>.[[packages]].n
 0003b310:·616d·6520·3d20·2261·6964·6522·0a76·6572··ame·=·"aide".ver
 0003b320:·7369·6f6e·203d·2022·2a22·0a3c·2f63·6f64··sion·=·"*".</cod
 0003b330:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a
 0003b340:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn-
 0003b350:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to
 0003b360:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"·
 0003b370:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
 0003b380:·6d35·3039·3922·2074·6162·696e·6465·783d··m5099"·tabindex=
 0003b390:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button
 0003b3a0:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=
 0003b3b0:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A
 0003b3c0:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea
 0003b3d0:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem
 0003b3e0:·6564·6961·7469·6f6e·2050·7570·7065·7420··ediation·Puppet·
 0003b3f0:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><
 0003b400:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
 0003b410:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
 0003b420:·6c6c·6170·7365·2220·6964·3d22·6964·6d35··llapse"·id="idm5
 0003b430:·3039·3922·3e3c·7461·626c·6520·636c·6173··099"><table·clas
 0003b440:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s
 0003b450:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor
 0003b460:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond
 0003b470:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C
 0003b480:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><
 0003b490:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
 0003b4a0:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti
 0003b4b0:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<
 0003b4c0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 0003b4d0:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td
 0003b4e0:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr>
 0003b4f0:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy
 0003b500:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable
 0003b510:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl
 0003b520:·653e·3c70·7265·3e3c·636f·6465·3e69·6e63··e><pre><code>inc
 0003b530:·6c75·6465·2069·6e73·7461·6c6c·5f61·6964··lude·install_aid
 0003b540:·650a·0a63·6c61·7373·2069·6e73·7461·6c6c··e..class·install
 0003b550:·5f61·6964·6520·7b0a·2020·7061·636b·6167··_aide·{.··packag
 0003b560:·6520·7b20·2761·6964·6527·3a0a·2020·2020··e·{·'aide':.····
 0003b570:·656e·7375·7265·203d·2667·743b·2027·696e··ensure·=&gt;·'in
 0003b580:·7374·616c·6c65·6427·2c0a·2020·7d0a·7d0a··stalled',.··}.}.
 0003b590:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d
 0003b5a0:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn
 0003b5b0:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da
 0003b5c0:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla
 0003b5d0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
 0003b5e0:·3d22·2369·646d·3531·3030·2220·7461·6269··="#idm5100"·tabi
 0003b5f0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
 0003b600:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
 0003b610:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
 0003b620:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
 0003b630:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
 0003b640:·223e·5265·6d65·6469·6174·696f·6e20·5368··">Remediation·Sh
 0003b650:·656c·6c20·7363·7269·7074·20e2·87b2·3c2f··ell·script·...</
 0003b660:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
 0003b670:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
 0003b680:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
 0003b690:·646d·3531·3030·223e·3c74·6162·6c65·2063··dm5100"><table·c
 0003b6a0:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl
 0003b6b0:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-
 0003b6c0:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c
 0003b6d0:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t
 0003b6e0:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t
 0003b6f0:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
 0003b700:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru
 0003b710:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l
 0003b720:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
 0003b730:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th>
 0003b740:·3c74·643e·6661·6c73·653c·2f74·643e·3c2f··<td>false</td></
 0003b750:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat
 0003b760:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena
 0003b770:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t
 0003b780:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>
 0003b790:·2320·5265·6d65·6469·6174·696f·6e20·6973··#·Remediation·is
 0003b7a0:·2061·7070·6c69·6361·626c·6520·6f6e·6c79···applicable·only
 0003b7b0:·2069·6e20·6365·7274·6169·6e20·706c·6174···in·certain·plat
 0003b7c0:·666f·726d·730a·6966·2072·706d·202d·2d71··forms.if·rpm·--q
 0003b7d0:·7569·6574·202d·7120·6b65·726e·656c·207c··uiet·-q·kernel·|
 0003b7e0:·7c20·7270·6d20·2d2d·7175·6965·7420·2d71··|·rpm·--quiet·-q
 0003b7f0:·206b·6572·6e65·6c2d·7565·6b3b·2074·6865···kernel-uek;·the
 0003b800:·6e0a·0a69·6620·2120·7270·6d20·2d71·202d··n..if·!·rpm·-q·-
 0003b810:·2d71·7569·6574·2022·6169·6465·2220·3b20··-quiet·"aide"·;·
 0003b820:·7468·656e·0a20·2020·2064·6e66·2069·6e73··then.····dnf·ins
 0003b830:·7461·6c6c·202d·7920·2261·6964·6522·0a66··tall·-y·"aide".f
 0003b840:·690a·0a65·6c73·650a·2020·2020·2667·743b··i..else.····&gt;
 0003b850:·2661·6d70·3b32·2065·6368·6f20·2752·656d··&amp;2·echo·'Rem
 0003b860:·6564·6961·7469·6f6e·2069·7320·6e6f·7420··ediation·is·not·
 0003b870:·6170·706c·6963·6162·6c65·2c20·6e6f·7468··applicable,·noth
 0003b880:·696e·6720·7761·7320·646f·6e65·270a·6669··ing·was·done'.fi
 0003b890:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></
 0003b8a0:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt
 0003b8b0:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d
 0003b8c0:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll
 0003b8d0:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
 0003b8e0:·743d·2223·6964·6d35·3130·3122·2074·6162··t="#idm5101"·tab
 0003b8f0:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
 0003b900:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
 0003b910:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
 0003b920:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
 0003b930:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
0003b290:·2122·3e52·656d·6564·6961·7469·6f6e·2041··!">Remediation·A0003b940:·2122·3e52·656d·6564·6961·7469·6f6e·2041··!">Remediation·A
0003b2a0:·6e61·636f·6e64·6120·736e·6970·7065·7420··naconda·snippet·0003b950:·6e61·636f·6e64·6120·736e·6970·7065·7420··naconda·snippet·
0003b2b0:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div· 
0003b2c0:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col 
0003b2d0:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"· 
0003b2e0:·6964·3d22·6964·6d35·3039·3822·3e3c·7461··id="idm5098"><ta 
0003b2f0:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table 
0003b300:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t 
0003b310:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta 
0003b320:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed">< 
0003b330:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit 
0003b340:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</ 
0003b350:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
Max diff block lines reached; 1135319/1153839 bytes (98.39%) of diff not shown.
111 KB
html2text {}
    
Offset 135, 21 lines modifiedOffset 135, 14 lines modified
135 ··-·PCI-DSSv4-11.5.2135 ··-·PCI-DSSv4-11.5.2
136 ··-·enable_strategy136 ··-·enable_strategy
137 ··-·low_complexity137 ··-·low_complexity
138 ··-·low_disruption138 ··-·low_disruption
139 ··-·medium_severity139 ··-·medium_severity
140 ··-·no_reboot_needed140 ··-·no_reboot_needed
141 ··-·package_aide_installed141 ··-·package_aide_installed
142 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
143 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
144 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
145 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
146 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
147 package·--add=aide 
148 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8142 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
149 [[packages]]143 [[packages]]
150 name·=·"aide"144 name·=·"aide"
151 version·=·"*"145 version·=·"*"
152 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8146 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
153 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low147 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 174, 14 lines modifiedOffset 167, 21 lines modified
174 if·!·rpm·-q·--quiet·"aide"·;·then167 if·!·rpm·-q·--quiet·"aide"·;·then
175 ····dnf·install·-y·"aide"168 ····dnf·install·-y·"aide"
176 fi169 fi
  
177 else170 else
178 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'171 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
179 fi172 fi
 173 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 174 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 175 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 176 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 177 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 178 package·--add=aide
180 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*179 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
181 Run·the·following·command·to·generate·a·new·database:180 Run·the·following·command·to·generate·a·new·database:
182 $·sudo·/usr/sbin/aide·--init181 $·sudo·/usr/sbin/aide·--init
183 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:182 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
184 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz183 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
185 To·initiate·a·manual·check,·run·the·following·command:184 To·initiate·a·manual·check,·run·the·following·command:
186 $·sudo·/usr/sbin/aide·--check185 $·sudo·/usr/sbin/aide·--check
Offset 1996, 21 lines modifiedOffset 1996, 14 lines modified
1996 ··tags:1996 ··tags:
1997 ··-·enable_strategy1997 ··-·enable_strategy
1998 ··-·low_complexity1998 ··-·low_complexity
1999 ··-·low_disruption1999 ··-·low_disruption
2000 ··-·medium_severity2000 ··-·medium_severity
2001 ··-·no_reboot_needed2001 ··-·no_reboot_needed
2002 ··-·package_crypto-policies_installed2002 ··-·package_crypto-policies_installed
2003 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
2004 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
2005 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
2006 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
2007 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
2008 package·--add=crypto-policies 
2009 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x82003 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
2010 [[packages]]2004 [[packages]]
2011 name·=·"crypto-policies"2005 name·=·"crypto-policies"
2012 version·=·"*"2006 version·=·"*"
2013 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x82007 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
2014 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low2008 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 2029, 14 lines modifiedOffset 2022, 21 lines modified
2029 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low2022 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
2030 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false2023 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
2031 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable2024 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
2032 if·!·rpm·-q·--quiet·"crypto-policies"·;·then2025 if·!·rpm·-q·--quiet·"crypto-policies"·;·then
2033 ····dnf·install·-y·"crypto-policies"2026 ····dnf·install·-y·"crypto-policies"
2034 fi2027 fi
 2028 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 2029 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 2030 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 2031 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 2032 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 2033 package·--add=crypto-policies
2035 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·B\x8BI\x8IN\x8ND\x8D·t\x8to\x8o·u\x8us\x8se\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8o·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*2034 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·B\x8BI\x8IN\x8ND\x8D·t\x8to\x8o·u\x8us\x8se\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8o·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
2036 Crypto·Policies·provide·a·centralized·control·over·crypto·algorithms·usage·of·many·packages.·BIND·is·supported·by·crypto·policy,·but·the·BIND·configuration·may·be·set·up·to·ignore·it.·To·check·that·Crypto·Policies·settings·are·configured·correctly,·ensure·that·the·/etc/named.conf·includes·the·appropriate·configuration:·In·the·options·section·of·/etc/named.conf,·make·sure·that·the·following·line·is·not·commented·out·or·superseded·by·later·includes:·include·"/etc/crypto-policies/back-ends/bind.config";2035 Crypto·Policies·provide·a·centralized·control·over·crypto·algorithms·usage·of·many·packages.·BIND·is·supported·by·crypto·policy,·but·the·BIND·configuration·may·be·set·up·to·ignore·it.·To·check·that·Crypto·Policies·settings·are·configured·correctly,·ensure·that·the·/etc/named.conf·includes·the·appropriate·configuration:·In·the·options·section·of·/etc/named.conf,·make·sure·that·the·following·line·is·not·commented·out·or·superseded·by·later·includes:·include·"/etc/crypto-policies/back-ends/bind.config";
2037 Rationale:··Overriding·the·system·crypto·policy·makes·the·behavior·of·the·BIND·service·violate·expectations,·and·makes·system·configuration·more·fragmented.2036 Rationale:··Overriding·the·system·crypto·policy·makes·the·behavior·of·the·BIND·service·violate·expectations,·and·makes·system·configuration·more·fragmented.
2038 Severity: ··high2037 Severity: ··high
2039 Rule·ID:····xccdf_org.ssgproject.content_rule_configure_bind_crypto_policy2038 Rule·ID:····xccdf_org.ssgproject.content_rule_configure_bind_crypto_policy
2040 ············_\x8d_\x8i_\x8s_\x8a·····CCI-002418,·CCI-0024222039 ············_\x8d_\x8i_\x8s_\x8a·····CCI-002418,·CCI-002422
2041 References:·_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.12040 References:·_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1
Offset 4882, 21 lines modifiedOffset 4882, 14 lines modified
4882 ··-·NIST-800-53-CM-7(b)4882 ··-·NIST-800-53-CM-7(b)
4883 ··-·disable_strategy4883 ··-·disable_strategy
4884 ··-·low_complexity4884 ··-·low_complexity
4885 ··-·low_disruption4885 ··-·low_disruption
4886 ··-·medium_severity4886 ··-·medium_severity
4887 ··-·no_reboot_needed4887 ··-·no_reboot_needed
4888 ··-·package_gdm_removed4888 ··-·package_gdm_removed
4889 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
4890 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
4891 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
4892 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
4893 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable 
  
4894 package·--remove=gdm 
4895 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x84889 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
4896 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low4890 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
4897 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low4891 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
4898 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false4892 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
4899 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable4893 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
4900 include·remove_gdm4894 include·remove_gdm
  
Offset 4922, 14 lines modifiedOffset 4915, 21 lines modified
4922 if·rpm·-q·--quiet·"gdm"·;·then4915 if·rpm·-q·--quiet·"gdm"·;·then
4923 dnf·remove·-y·--noautoremove·"gdm"4916 dnf·remove·-y·--noautoremove·"gdm"
4924 fi4917 fi
  
4925 else4918 else
4926 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'4919 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
4927 fi4920 fi
 4921 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 4922 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 4923 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 4924 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 4925 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
  
 4926 package·--remove=gdm
4928 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·M\x8Ma\x8ak\x8ke\x8e·s\x8su\x8ur\x8re\x8e·t\x8th\x8ha\x8at\x8t·t\x8th\x8he\x8e·d\x8dc\x8co\x8on\x8nf\x8f·d\x8da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8es\x8s·a\x8ar\x8re\x8e·u\x8up\x8p-\x8-t\x8to\x8o-\x8-d\x8da\x8at\x8te\x8e·w\x8wi\x8it\x8th\x8h·r\x8re\x8eg\x8ga\x8ar\x8rd\x8ds\x8s·t\x8to\x8o·r\x8re\x8es\x8sp\x8pe\x8ec\x8ct\x8ti\x8iv\x8ve\x8e·k\x8ke\x8ey\x8yf\x8fi\x8il\x8le\x8es\x8s·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*4927 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·M\x8Ma\x8ak\x8ke\x8e·s\x8su\x8ur\x8re\x8e·t\x8th\x8ha\x8at\x8t·t\x8th\x8he\x8e·d\x8dc\x8co\x8on\x8nf\x8f·d\x8da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8es\x8s·a\x8ar\x8re\x8e·u\x8up\x8p-\x8-t\x8to\x8o-\x8-d\x8da\x8at\x8te\x8e·w\x8wi\x8it\x8th\x8h·r\x8re\x8eg\x8ga\x8ar\x8rd\x8ds\x8s·t\x8to\x8o·r\x8re\x8es\x8sp\x8pe\x8ec\x8ct\x8ti\x8iv\x8ve\x8e·k\x8ke\x8ey\x8yf\x8fi\x8il\x8le\x8es\x8s·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
4929 By·default,·DConf·uses·a·binary·database·as·a·data·backend.·The·system-level·database·is·compiled·from·keyfiles·in·the·/etc/dconf/db/·directory·by·the4928 By·default,·DConf·uses·a·binary·database·as·a·data·backend.·The·system-level·database·is·compiled·from·keyfiles·in·the·/etc/dconf/db/·directory·by·the
4930 dconf·update4929 dconf·update
Max diff block lines reached; 107919/113828 bytes (94.81%) of diff not shown.
812 KB
./usr/share/doc/ssg-nondebian/ssg-ol7-guide-anssi_nt28_enhanced.html
    
Offset 15136, 144 lines modifiedOffset 15136, 144 lines modified
0003b1f0:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="0003b1f0:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
0003b200:·2369·646d·3536·3532·2220·7461·6269·6e64··#idm5652"·tabind0003b200:·2369·646d·3536·3532·2220·7461·6269·6e64··#idm5652"·tabind
0003b210:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but0003b210:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
0003b220:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand0003b220:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
0003b230:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title0003b230:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
0003b240:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re0003b240:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
0003b250:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">0003b250:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
 0003b260:·5265·6d65·6469·6174·696f·6e20·4f53·4275··Remediation·OSBu
 0003b270:·696c·6420·426c·7565·7072·696e·7420·736e··ild·Blueprint·sn
 0003b280:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br
 0003b290:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
 0003b2a0:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
 0003b2b0:·6170·7365·2220·6964·3d22·6964·6d35·3635··apse"·id="idm565
 0003b2c0:·3222·3e3c·7072·653e·3c63·6f64·653e·0a5b··2"><pre><code>.[
 0003b2d0:·5b70·6163·6b61·6765·735d·5d0a·6e61·6d65··[packages]].name
 0003b2e0:·203d·2022·6169·6465·220a·7665·7273·696f···=·"aide".versio
 0003b2f0:·6e20·3d20·222a·220a·3c2f·636f·6465·3e3c··n·=·"*".</code><
 0003b300:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl
 0003b310:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc
 0003b320:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl
 0003b330:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat
 0003b340:·612d·7461·7267·6574·3d22·2369·646d·3536··a-target="#idm56
 0003b350:·3533·2220·7461·6269·6e64·6578·3d22·3022··53"·tabindex="0"
 0003b360:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
 0003b370:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
 0003b380:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
 0003b390:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
 0003b3a0:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
 0003b3b0:·6174·696f·6e20·5075·7070·6574·2073·6e69··ation·Puppet·sni
 0003b3c0:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>
 0003b3d0:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
 0003b3e0:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
 0003b3f0:·7073·6522·2069·643d·2269·646d·3536·3533··pse"·id="idm5653
 0003b400:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="
 0003b410:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri
 0003b420:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border
 0003b430:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens
 0003b440:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp
 0003b450:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>
 0003b460:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
 0003b470:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:
 0003b480:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
 0003b490:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re
 0003b4a0:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa
 0003b4b0:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr
 0003b4c0:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</
 0003b4d0:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t
 0003b4e0:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><
 0003b4f0:·7072·653e·3c63·6f64·653e·696e·636c·7564··pre><code>includ
 0003b500:·6520·696e·7374·616c·6c5f·6169·6465·0a0a··e·install_aide..
 0003b510:·636c·6173·7320·696e·7374·616c·6c5f·6169··class·install_ai
 0003b520:·6465·207b·0a20·2070·6163·6b61·6765·207b··de·{.··package·{
 0003b530:·2027·6169·6465·273a·0a20·2020·2065·6e73···'aide':.····ens
 0003b540:·7572·6520·3d26·6774·3b20·2769·6e73·7461··ure·=&gt;·'insta
 0003b550:·6c6c·6564·272c·0a20·207d·0a7d·0a3c·2f63··lled',.··}.}.</c
 0003b560:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div>
 0003b570:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt
 0003b580:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data-
 0003b590:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse
 0003b5a0:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
 0003b5b0:·6964·6d35·3635·3422·2074·6162·696e·6465··idm5654"·tabinde
 0003b5c0:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt
 0003b5d0:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande
 0003b5e0:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=
 0003b5f0:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev
 0003b600:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R
 0003b610:·656d·6564·6961·7469·6f6e·2053·6865·6c6c··emediation·Shell
 0003b620:·2073·6372·6970·7420·e287·b23c·2f61·3e3c···script·...</a><
 0003b630:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
 0003b640:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
 0003b650:·6c6c·6170·7365·2220·6964·3d22·6964·6d35··llapse"·id="idm5
 0003b660:·3635·3422·3e3c·7461·626c·6520·636c·6173··654"><table·clas
 0003b670:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s
 0003b680:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor
 0003b690:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond
 0003b6a0:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C
 0003b6b0:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><
 0003b6c0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
 0003b6d0:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti
 0003b6e0:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<
 0003b6f0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 0003b700:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td
 0003b710:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr>
 0003b720:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy
 0003b730:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable
 0003b740:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl
 0003b750:·653e·3c70·7265·3e3c·636f·6465·3e23·2052··e><pre><code>#·R
 0003b760:·656d·6564·6961·7469·6f6e·2069·7320·6170··emediation·is·ap
 0003b770:·706c·6963·6162·6c65·206f·6e6c·7920·696e··plicable·only·in
 0003b780:·2063·6572·7461·696e·2070·6c61·7466·6f72···certain·platfor
 0003b790:·6d73·0a69·6620·7270·6d20·2d2d·7175·6965··ms.if·rpm·--quie
 0003b7a0:·7420·2d71·206b·6572·6e65·6c20·7c7c·2072··t·-q·kernel·||·r
 0003b7b0:·706d·202d·2d71·7569·6574·202d·7120·6b65··pm·--quiet·-q·ke
 0003b7c0:·726e·656c·2d75·656b·3b20·7468·656e·0a0a··rnel-uek;·then..
 0003b7d0:·6966·2021·2072·706d·202d·7120·2d2d·7175··if·!·rpm·-q·--qu
 0003b7e0:·6965·7420·2261·6964·6522·203b·2074·6865··iet·"aide"·;·the
 0003b7f0:·6e0a·2020·2020·7975·6d20·696e·7374·616c··n.····yum·instal
 0003b800:·6c20·2d79·2022·6169·6465·220a·6669·0a0a··l·-y·"aide".fi..
 0003b810:·656c·7365·0a20·2020·2026·6774·3b26·616d··else.····&gt;&am
 0003b820:·703b·3220·6563·686f·2027·5265·6d65·6469··p;2·echo·'Remedi
 0003b830:·6174·696f·6e20·6973·206e·6f74·2061·7070··ation·is·not·app
 0003b840:·6c69·6361·626c·652c·206e·6f74·6869·6e67··licable,·nothing
 0003b850:·2077·6173·2064·6f6e·6527·0a66·690a·3c2f···was·done'.fi.</
 0003b860:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div
 0003b870:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b
 0003b880:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data
 0003b890:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps
 0003b8a0:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
 0003b8b0:·2369·646d·3536·3535·2220·7461·6269·6e64··#idm5655"·tabind
 0003b8c0:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
 0003b8d0:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
 0003b8e0:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
 0003b8f0:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
 0003b900:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
0003b260:·5265·6d65·6469·6174·696f·6e20·416e·6163··Remediation·Anac0003b910:·5265·6d65·6469·6174·696f·6e20·416e·6163··Remediation·Anac
0003b270:·6f6e·6461·2073·6e69·7070·6574·20e2·87b2··onda·snippet·...0003b920:·6f6e·6461·2073·6e69·7070·6574·20e2·87b2··onda·snippet·...
0003b280:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla0003b930:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
0003b290:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap0003b940:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
0003b2a0:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=0003b950:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
0003b2b0:·2269·646d·3536·3532·223e·3c74·6162·6c65··"idm5652"><table0003b960:·2269·646d·3536·3535·223e·3c74·6162·6c65··"idm5655"><table
0003b2c0:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta0003b970:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta
0003b2d0:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl0003b980:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl
0003b2e0:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table0003b990:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table
0003b2f0:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>0003b9a0:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>
0003b300:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<0003b9b0:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<
0003b310:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>0003b9c0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
0003b320:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis0003b9d0:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis
Max diff block lines reached; 747407/765927 bytes (97.58%) of diff not shown.
63.7 KB
html2text {}
    
Offset 154, 21 lines modifiedOffset 154, 14 lines modified
154 ··-·PCI-DSSv4-11.5.2154 ··-·PCI-DSSv4-11.5.2
155 ··-·enable_strategy155 ··-·enable_strategy
156 ··-·low_complexity156 ··-·low_complexity
157 ··-·low_disruption157 ··-·low_disruption
158 ··-·medium_severity158 ··-·medium_severity
159 ··-·no_reboot_needed159 ··-·no_reboot_needed
160 ··-·package_aide_installed160 ··-·package_aide_installed
161 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
162 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
163 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
164 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
165 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
166 package·--add=aide 
167 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8161 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
168 [[packages]]162 [[packages]]
169 name·=·"aide"163 name·=·"aide"
170 version·=·"*"164 version·=·"*"
171 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8165 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
172 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low166 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 193, 14 lines modifiedOffset 186, 21 lines modified
193 if·!·rpm·-q·--quiet·"aide"·;·then186 if·!·rpm·-q·--quiet·"aide"·;·then
194 ····yum·install·-y·"aide"187 ····yum·install·-y·"aide"
195 fi188 fi
  
196 else189 else
197 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'190 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
198 fi191 fi
 192 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 193 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 194 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 195 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 196 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 197 package·--add=aide
199 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*198 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
200 Run·the·following·command·to·generate·a·new·database:199 Run·the·following·command·to·generate·a·new·database:
201 $·sudo·/usr/sbin/aide·--init200 $·sudo·/usr/sbin/aide·--init
202 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the201 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the
203 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these202 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these
204 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their203 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their
205 integrity.·The·newly-generated·database·can·be·installed·as·follows:204 integrity.·The·newly-generated·database·can·be·installed·as·follows:
Offset 460, 31 lines modifiedOffset 460, 31 lines modified
460 ··-·NIST-800-53-SC-13460 ··-·NIST-800-53-SC-13
461 ··-·enable_strategy461 ··-·enable_strategy
462 ··-·low_complexity462 ··-·low_complexity
463 ··-·low_disruption463 ··-·low_disruption
464 ··-·medium_severity464 ··-·medium_severity
465 ··-·no_reboot_needed465 ··-·no_reboot_needed
466 ··-·package_dracut-fips-aesni_installed466 ··-·package_dracut-fips-aesni_installed
467 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
468 package·--add=dracut-fips-aesni 
469 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8467 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
470 #·Remediation·is·applicable·only·in·certain·platforms468 #·Remediation·is·applicable·only·in·certain·platforms
471 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·||·rpm·--quiet·-469 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·||·rpm·--quiet·-
472 q·kernel-uek·);·then470 q·kernel-uek·);·then
  
473 if·grep·-q·-m1·-o·aes·/proc/cpuinfo;·then471 if·grep·-q·-m1·-o·aes·/proc/cpuinfo;·then
474 ····if·!·rpm·-q·--quiet·"dracut-fips-aesni"·;·then472 ····if·!·rpm·-q·--quiet·"dracut-fips-aesni"·;·then
475 ········yum·install·-y·"dracut-fips-aesni"473 ········yum·install·-y·"dracut-fips-aesni"
476 ····fi474 ····fi
477 fi475 fi
  
478 else476 else
479 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'477 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
480 fi478 fi
 479 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 480 package·--add=dracut-fips-aesni
481 Group  ·Disk·Partitioning·  Group·contains·10·rules481 Group  ·Disk·Partitioning·  Group·contains·10·rules
482 _\x8[_\x8r_\x8e_\x8f_\x8]  ·To·ensure·separation·and·protection·of·data,·there·are·top-level·system·directories·which482 _\x8[_\x8r_\x8e_\x8f_\x8]  ·To·ensure·separation·and·protection·of·data,·there·are·top-level·system·directories·which
483 should·be·placed·on·their·own·physical·partition·or·logical·volume.·The·installer's·default483 should·be·placed·on·their·own·physical·partition·or·logical·volume.·The·installer's·default
484 partitioning·scheme·creates·separate·logical·volumes·for·/,·/boot,·and·swap.484 partitioning·scheme·creates·separate·logical·volumes·for·/,·/boot,·and·swap.
485 ····*·If·starting·with·any·of·the·default·layouts,·check·the·box·to·\"Review·and·modify485 ····*·If·starting·with·any·of·the·default·layouts,·check·the·box·to·\"Review·and·modify
486 ······partitioning.\"·This·allows·for·the·easy·creation·of·additional·logical·volumes·inside·the486 ······partitioning.\"·This·allows·for·the·easy·creation·of·additional·logical·volumes·inside·the
487 ······volume·group·already·created,·though·it·may·require·making·/'s·logical·volume·smaller·to·create487 ······volume·group·already·created,·though·it·may·require·making·/'s·logical·volume·smaller·to·create
Offset 738, 21 lines modifiedOffset 738, 14 lines modified
738 ··tags:738 ··tags:
739 ··-·enable_strategy739 ··-·enable_strategy
740 ··-·low_complexity740 ··-·low_complexity
741 ··-·low_disruption741 ··-·low_disruption
742 ··-·low_severity742 ··-·low_severity
743 ··-·no_reboot_needed743 ··-·no_reboot_needed
744 ··-·systemd_tmp_mount_enabled744 ··-·systemd_tmp_mount_enabled
745 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
746 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
747 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
748 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
749 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
750 services·--enabled=tmp.mount 
751 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8745 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
752 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low746 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
753 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low747 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
754 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false748 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
755 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable749 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
756 #·Remediation·is·applicable·only·in·certain·platforms750 #·Remediation·is·applicable·only·in·certain·platforms
757 if·(·!·(·{·rpm·--quiet·-q·kernel·;}·&&·{·rpm·--quiet·-q·rpm-ostree·;}·&&·{·rpm·--quiet·-q·bootc·;}·&&751 if·(·!·(·{·rpm·--quiet·-q·kernel·;}·&&·{·rpm·--quiet·-q·rpm-ostree·;}·&&·{·rpm·--quiet·-q·bootc·;}·&&
Offset 765, 14 lines modifiedOffset 758, 21 lines modified
765 ··"$SYSTEMCTL_EXEC"·start·'tmp.mount'758 ··"$SYSTEMCTL_EXEC"·start·'tmp.mount'
766 fi759 fi
767 "$SYSTEMCTL_EXEC"·enable·'tmp.mount'760 "$SYSTEMCTL_EXEC"·enable·'tmp.mount'
  
768 else761 else
769 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'762 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
770 fi763 fi
 764 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 765 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 766 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 767 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 768 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 769 services·--enabled=tmp.mount
771 Group  ·Sudo·  Group·contains·18·rules770 Group  ·Sudo·  Group·contains·18·rules
772 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Sudo,·which·stands·for·"su·'do'",·provides·the·ability·to·delegate·authority·to·certain771 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Sudo,·which·stands·for·"su·'do'",·provides·the·ability·to·delegate·authority·to·certain
773 users,·groups·of·users,·or·system·administrators.·When·configured·for·system·users·and/or·groups,772 users,·groups·of·users,·or·system·administrators.·When·configured·for·system·users·and/or·groups,
774 Sudo·can·allow·a·user·or·group·to·execute·privileged·commands·that·normally·only·root·is·allowed·to773 Sudo·can·allow·a·user·or·group·to·execute·privileged·commands·that·normally·only·root·is·allowed·to
775 execute.774 execute.
  
776 For·more·information·on·Sudo·and·addition·Sudo·configuration·options,·see·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8w\x8w_\x8w\x8w_\x8w\x8w_\x8.\x8._\x8s\x8s_\x8u\x8u_\x8d\x8d_\x8o\x8o_\x8.\x8._\x8w\x8w_\x8s\x8s.775 For·more·information·on·Sudo·and·addition·Sudo·configuration·options,·see·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8w\x8w_\x8w\x8w_\x8w\x8w_\x8.\x8._\x8s\x8s_\x8u\x8u_\x8d\x8d_\x8o\x8o_\x8.\x8._\x8w\x8w_\x8s\x8s.
Offset 821, 21 lines modifiedOffset 821, 14 lines modified
821 ··-·PCI-DSSv4-2.2.6821 ··-·PCI-DSSv4-2.2.6
822 ··-·enable_strategy822 ··-·enable_strategy
823 ··-·low_complexity823 ··-·low_complexity
824 ··-·low_disruption824 ··-·low_disruption
Max diff block lines reached; 59930/65165 bytes (91.97%) of diff not shown.
872 KB
./usr/share/doc/ssg-nondebian/ssg-ol7-guide-anssi_nt28_high.html
    
Offset 15142, 144 lines modifiedOffset 15142, 144 lines modified
0003b250:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe0003b250:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
0003b260:·743d·2223·6964·6d35·3635·3222·2074·6162··t="#idm5652"·tab0003b260:·743d·2223·6964·6d35·3635·3222·2074·6162··t="#idm5652"·tab
0003b270:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="0003b270:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
0003b280:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp0003b280:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
0003b290:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti0003b290:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
0003b2a0:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to0003b2a0:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
0003b2b0:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#0003b2b0:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
0003b2c0:·2122·3e52·656d·6564·6961·7469·6f6e·2041··!">Remediation·A0003b2c0:·2122·3e52·656d·6564·6961·7469·6f6e·204f··!">Remediation·O
 0003b2d0:·5342·7569·6c64·2042·6c75·6570·7269·6e74··SBuild·Blueprint
 0003b2e0:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>
 0003b2f0:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="
 0003b300:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c
 0003b310:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm
 0003b320:·3536·3532·223e·3c70·7265·3e3c·636f·6465··5652"><pre><code
 0003b330:·3e0a·5b5b·7061·636b·6167·6573·5d5d·0a6e··>.[[packages]].n
 0003b340:·616d·6520·3d20·2261·6964·6522·0a76·6572··ame·=·"aide".ver
 0003b350:·7369·6f6e·203d·2022·2a22·0a3c·2f63·6f64··sion·=·"*".</cod
 0003b360:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a
 0003b370:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn-
 0003b380:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to
 0003b390:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"·
 0003b3a0:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
 0003b3b0:·6d35·3635·3322·2074·6162·696e·6465·783d··m5653"·tabindex=
 0003b3c0:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button
 0003b3d0:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=
 0003b3e0:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A
 0003b3f0:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea
 0003b400:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem
 0003b410:·6564·6961·7469·6f6e·2050·7570·7065·7420··ediation·Puppet·
 0003b420:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><
 0003b430:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
 0003b440:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
 0003b450:·6c6c·6170·7365·2220·6964·3d22·6964·6d35··llapse"·id="idm5
 0003b460:·3635·3322·3e3c·7461·626c·6520·636c·6173··653"><table·clas
 0003b470:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s
 0003b480:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor
 0003b490:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond
 0003b4a0:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C
 0003b4b0:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><
 0003b4c0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
 0003b4d0:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti
 0003b4e0:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<
 0003b4f0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 0003b500:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td
 0003b510:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr>
 0003b520:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy
 0003b530:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable
 0003b540:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl
 0003b550:·653e·3c70·7265·3e3c·636f·6465·3e69·6e63··e><pre><code>inc
 0003b560:·6c75·6465·2069·6e73·7461·6c6c·5f61·6964··lude·install_aid
 0003b570:·650a·0a63·6c61·7373·2069·6e73·7461·6c6c··e..class·install
 0003b580:·5f61·6964·6520·7b0a·2020·7061·636b·6167··_aide·{.··packag
 0003b590:·6520·7b20·2761·6964·6527·3a0a·2020·2020··e·{·'aide':.····
 0003b5a0:·656e·7375·7265·203d·2667·743b·2027·696e··ensure·=&gt;·'in
 0003b5b0:·7374·616c·6c65·6427·2c0a·2020·7d0a·7d0a··stalled',.··}.}.
 0003b5c0:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d
 0003b5d0:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn
 0003b5e0:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da
 0003b5f0:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla
 0003b600:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
 0003b610:·3d22·2369·646d·3536·3534·2220·7461·6269··="#idm5654"·tabi
 0003b620:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
 0003b630:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
 0003b640:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
 0003b650:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
 0003b660:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
 0003b670:·223e·5265·6d65·6469·6174·696f·6e20·5368··">Remediation·Sh
 0003b680:·656c·6c20·7363·7269·7074·20e2·87b2·3c2f··ell·script·...</
 0003b690:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
 0003b6a0:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
 0003b6b0:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
 0003b6c0:·646d·3536·3534·223e·3c74·6162·6c65·2063··dm5654"><table·c
 0003b6d0:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl
 0003b6e0:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-
 0003b6f0:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c
 0003b700:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t
 0003b710:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t
 0003b720:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
 0003b730:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru
 0003b740:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l
 0003b750:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
 0003b760:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th>
 0003b770:·3c74·643e·6661·6c73·653c·2f74·643e·3c2f··<td>false</td></
 0003b780:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat
 0003b790:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena
 0003b7a0:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t
 0003b7b0:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>
 0003b7c0:·2320·5265·6d65·6469·6174·696f·6e20·6973··#·Remediation·is
 0003b7d0:·2061·7070·6c69·6361·626c·6520·6f6e·6c79···applicable·only
 0003b7e0:·2069·6e20·6365·7274·6169·6e20·706c·6174···in·certain·plat
 0003b7f0:·666f·726d·730a·6966·2072·706d·202d·2d71··forms.if·rpm·--q
 0003b800:·7569·6574·202d·7120·6b65·726e·656c·207c··uiet·-q·kernel·|
 0003b810:·7c20·7270·6d20·2d2d·7175·6965·7420·2d71··|·rpm·--quiet·-q
 0003b820:·206b·6572·6e65·6c2d·7565·6b3b·2074·6865···kernel-uek;·the
 0003b830:·6e0a·0a69·6620·2120·7270·6d20·2d71·202d··n..if·!·rpm·-q·-
 0003b840:·2d71·7569·6574·2022·6169·6465·2220·3b20··-quiet·"aide"·;·
 0003b850:·7468·656e·0a20·2020·2079·756d·2069·6e73··then.····yum·ins
 0003b860:·7461·6c6c·202d·7920·2261·6964·6522·0a66··tall·-y·"aide".f
 0003b870:·690a·0a65·6c73·650a·2020·2020·2667·743b··i..else.····&gt;
 0003b880:·2661·6d70·3b32·2065·6368·6f20·2752·656d··&amp;2·echo·'Rem
 0003b890:·6564·6961·7469·6f6e·2069·7320·6e6f·7420··ediation·is·not·
 0003b8a0:·6170·706c·6963·6162·6c65·2c20·6e6f·7468··applicable,·noth
 0003b8b0:·696e·6720·7761·7320·646f·6e65·270a·6669··ing·was·done'.fi
 0003b8c0:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></
 0003b8d0:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt
 0003b8e0:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d
 0003b8f0:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll
 0003b900:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
 0003b910:·743d·2223·6964·6d35·3635·3522·2074·6162··t="#idm5655"·tab
 0003b920:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
 0003b930:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
 0003b940:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
 0003b950:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
 0003b960:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
 0003b970:·2122·3e52·656d·6564·6961·7469·6f6e·2041··!">Remediation·A
0003b2d0:·6e61·636f·6e64·6120·736e·6970·7065·7420··naconda·snippet·0003b980:·6e61·636f·6e64·6120·736e·6970·7065·7420··naconda·snippet·
0003b2e0:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·0003b990:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·
0003b2f0:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col0003b9a0:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col
0003b300:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·0003b9b0:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·
0003b310:·6964·3d22·6964·6d35·3635·3222·3e3c·7461··id="idm5652"><ta0003b9c0:·6964·3d22·6964·6d35·3635·3522·3e3c·7461··id="idm5655"><ta
0003b320:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table0003b9d0:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table
0003b330:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t 
0003b340:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta 
0003b350:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed">< 
0003b360:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit 
0003b370:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</ 
0003b380:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
Max diff block lines reached; 803732/822252 bytes (97.75%) of diff not shown.
69.0 KB
html2text {}
    
Offset 155, 21 lines modifiedOffset 155, 14 lines modified
155 ··-·PCI-DSSv4-11.5.2155 ··-·PCI-DSSv4-11.5.2
156 ··-·enable_strategy156 ··-·enable_strategy
157 ··-·low_complexity157 ··-·low_complexity
158 ··-·low_disruption158 ··-·low_disruption
159 ··-·medium_severity159 ··-·medium_severity
160 ··-·no_reboot_needed160 ··-·no_reboot_needed
161 ··-·package_aide_installed161 ··-·package_aide_installed
162 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
163 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
164 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
165 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
166 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
167 package·--add=aide 
168 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8162 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
169 [[packages]]163 [[packages]]
170 name·=·"aide"164 name·=·"aide"
171 version·=·"*"165 version·=·"*"
172 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8166 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
173 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low167 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 194, 14 lines modifiedOffset 187, 21 lines modified
194 if·!·rpm·-q·--quiet·"aide"·;·then187 if·!·rpm·-q·--quiet·"aide"·;·then
195 ····yum·install·-y·"aide"188 ····yum·install·-y·"aide"
196 fi189 fi
  
197 else190 else
198 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'191 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
199 fi192 fi
 193 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 194 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 195 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 196 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 197 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 198 package·--add=aide
200 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*199 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
201 Run·the·following·command·to·generate·a·new·database:200 Run·the·following·command·to·generate·a·new·database:
202 $·sudo·/usr/sbin/aide·--init201 $·sudo·/usr/sbin/aide·--init
203 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the202 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the
204 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these203 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these
205 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their204 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their
206 integrity.·The·newly-generated·database·can·be·installed·as·follows:205 integrity.·The·newly-generated·database·can·be·installed·as·follows:
Offset 1021, 31 lines modifiedOffset 1021, 31 lines modified
1021 ··-·NIST-800-53-SC-131021 ··-·NIST-800-53-SC-13
1022 ··-·enable_strategy1022 ··-·enable_strategy
1023 ··-·low_complexity1023 ··-·low_complexity
1024 ··-·low_disruption1024 ··-·low_disruption
1025 ··-·medium_severity1025 ··-·medium_severity
1026 ··-·no_reboot_needed1026 ··-·no_reboot_needed
1027 ··-·package_dracut-fips-aesni_installed1027 ··-·package_dracut-fips-aesni_installed
1028 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
1029 package·--add=dracut-fips-aesni 
1030 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81028 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1031 #·Remediation·is·applicable·only·in·certain·platforms1029 #·Remediation·is·applicable·only·in·certain·platforms
1032 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·||·rpm·--quiet·-1030 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·||·rpm·--quiet·-
1033 q·kernel-uek·);·then1031 q·kernel-uek·);·then
  
1034 if·grep·-q·-m1·-o·aes·/proc/cpuinfo;·then1032 if·grep·-q·-m1·-o·aes·/proc/cpuinfo;·then
1035 ····if·!·rpm·-q·--quiet·"dracut-fips-aesni"·;·then1033 ····if·!·rpm·-q·--quiet·"dracut-fips-aesni"·;·then
1036 ········yum·install·-y·"dracut-fips-aesni"1034 ········yum·install·-y·"dracut-fips-aesni"
1037 ····fi1035 ····fi
1038 fi1036 fi
  
1039 else1037 else
1040 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'1038 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
1041 fi1039 fi
 1040 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 1041 package·--add=dracut-fips-aesni
1042 Group  ·Disk·Partitioning·  Group·contains·10·rules1042 Group  ·Disk·Partitioning·  Group·contains·10·rules
1043 _\x8[_\x8r_\x8e_\x8f_\x8]  ·To·ensure·separation·and·protection·of·data,·there·are·top-level·system·directories·which1043 _\x8[_\x8r_\x8e_\x8f_\x8]  ·To·ensure·separation·and·protection·of·data,·there·are·top-level·system·directories·which
1044 should·be·placed·on·their·own·physical·partition·or·logical·volume.·The·installer's·default1044 should·be·placed·on·their·own·physical·partition·or·logical·volume.·The·installer's·default
1045 partitioning·scheme·creates·separate·logical·volumes·for·/,·/boot,·and·swap.1045 partitioning·scheme·creates·separate·logical·volumes·for·/,·/boot,·and·swap.
1046 ····*·If·starting·with·any·of·the·default·layouts,·check·the·box·to·\"Review·and·modify1046 ····*·If·starting·with·any·of·the·default·layouts,·check·the·box·to·\"Review·and·modify
1047 ······partitioning.\"·This·allows·for·the·easy·creation·of·additional·logical·volumes·inside·the1047 ······partitioning.\"·This·allows·for·the·easy·creation·of·additional·logical·volumes·inside·the
1048 ······volume·group·already·created,·though·it·may·require·making·/'s·logical·volume·smaller·to·create1048 ······volume·group·already·created,·though·it·may·require·making·/'s·logical·volume·smaller·to·create
Offset 1299, 21 lines modifiedOffset 1299, 14 lines modified
1299 ··tags:1299 ··tags:
1300 ··-·enable_strategy1300 ··-·enable_strategy
1301 ··-·low_complexity1301 ··-·low_complexity
1302 ··-·low_disruption1302 ··-·low_disruption
1303 ··-·low_severity1303 ··-·low_severity
1304 ··-·no_reboot_needed1304 ··-·no_reboot_needed
1305 ··-·systemd_tmp_mount_enabled1305 ··-·systemd_tmp_mount_enabled
1306 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
1307 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
1308 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
1309 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
1310 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
1311 services·--enabled=tmp.mount 
1312 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81306 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1313 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1307 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1314 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1308 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1315 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1309 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1316 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1310 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1317 #·Remediation·is·applicable·only·in·certain·platforms1311 #·Remediation·is·applicable·only·in·certain·platforms
1318 if·(·!·(·{·rpm·--quiet·-q·kernel·;}·&&·{·rpm·--quiet·-q·rpm-ostree·;}·&&·{·rpm·--quiet·-q·bootc·;}·&&1312 if·(·!·(·{·rpm·--quiet·-q·kernel·;}·&&·{·rpm·--quiet·-q·rpm-ostree·;}·&&·{·rpm·--quiet·-q·bootc·;}·&&
Offset 1326, 14 lines modifiedOffset 1319, 21 lines modified
1326 ··"$SYSTEMCTL_EXEC"·start·'tmp.mount'1319 ··"$SYSTEMCTL_EXEC"·start·'tmp.mount'
1327 fi1320 fi
1328 "$SYSTEMCTL_EXEC"·enable·'tmp.mount'1321 "$SYSTEMCTL_EXEC"·enable·'tmp.mount'
  
1329 else1322 else
1330 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'1323 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
1331 fi1324 fi
 1325 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 1326 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1327 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1328 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1329 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 1330 services·--enabled=tmp.mount
1332 Group  ·Sudo·  Group·contains·18·rules1331 Group  ·Sudo·  Group·contains·18·rules
1333 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Sudo,·which·stands·for·"su·'do'",·provides·the·ability·to·delegate·authority·to·certain1332 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Sudo,·which·stands·for·"su·'do'",·provides·the·ability·to·delegate·authority·to·certain
1334 users,·groups·of·users,·or·system·administrators.·When·configured·for·system·users·and/or·groups,1333 users,·groups·of·users,·or·system·administrators.·When·configured·for·system·users·and/or·groups,
1335 Sudo·can·allow·a·user·or·group·to·execute·privileged·commands·that·normally·only·root·is·allowed·to1334 Sudo·can·allow·a·user·or·group·to·execute·privileged·commands·that·normally·only·root·is·allowed·to
1336 execute.1335 execute.
  
1337 For·more·information·on·Sudo·and·addition·Sudo·configuration·options,·see·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8w\x8w_\x8w\x8w_\x8w\x8w_\x8.\x8._\x8s\x8s_\x8u\x8u_\x8d\x8d_\x8o\x8o_\x8.\x8._\x8w\x8w_\x8s\x8s.1336 For·more·information·on·Sudo·and·addition·Sudo·configuration·options,·see·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8w\x8w_\x8w\x8w_\x8w\x8w_\x8.\x8._\x8s\x8s_\x8u\x8u_\x8d\x8d_\x8o\x8o_\x8.\x8._\x8w\x8w_\x8s\x8s.
Offset 1382, 21 lines modifiedOffset 1382, 14 lines modified
1382 ··-·PCI-DSSv4-2.2.61382 ··-·PCI-DSSv4-2.2.6
1383 ··-·enable_strategy1383 ··-·enable_strategy
1384 ··-·low_complexity1384 ··-·low_complexity
1385 ··-·low_disruption1385 ··-·low_disruption
Max diff block lines reached; 65389/70632 bytes (92.58%) of diff not shown.
720 KB
./usr/share/doc/ssg-nondebian/ssg-ol7-guide-anssi_nt28_intermediary.html
    
Offset 15127, 144 lines modifiedOffset 15127, 144 lines modified
0003b160:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=0003b160:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
0003b170:·2223·6964·6d35·3635·3222·2074·6162·696e··"#idm5652"·tabin0003b170:·2223·6964·6d35·3635·3222·2074·6162·696e··"#idm5652"·tabin
0003b180:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu0003b180:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
0003b190:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan0003b190:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
0003b1a0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl0003b1a0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
0003b1b0:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r0003b1b0:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
0003b1c0:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"0003b1c0:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
 0003b1d0:·3e52·656d·6564·6961·7469·6f6e·204f·5342··>Remediation·OSB
 0003b1e0:·7569·6c64·2042·6c75·6570·7269·6e74·2073··uild·Blueprint·s
 0003b1f0:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b
 0003b200:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
 0003b210:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
 0003b220:·6c61·7073·6522·2069·643d·2269·646d·3536··lapse"·id="idm56
 0003b230:·3532·223e·3c70·7265·3e3c·636f·6465·3e0a··52"><pre><code>.
 0003b240:·5b5b·7061·636b·6167·6573·5d5d·0a6e·616d··[[packages]].nam
 0003b250:·6520·3d20·2261·6964·6522·0a76·6572·7369··e·=·"aide".versi
 0003b260:·6f6e·203d·2022·2a22·0a3c·2f63·6f64·653e··on·=·"*".</code>
 0003b270:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c
 0003b280:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su
 0003b290:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg
 0003b2a0:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da
 0003b2b0:·7461·2d74·6172·6765·743d·2223·6964·6d35··ta-target="#idm5
 0003b2c0:·3635·3322·2074·6162·696e·6465·783d·2230··653"·tabindex="0
 0003b2d0:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
 0003b2e0:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
 0003b2f0:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
 0003b300:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
 0003b310:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
 0003b320:·6961·7469·6f6e·2050·7570·7065·7420·736e··iation·Puppet·sn
 0003b330:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br
 0003b340:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
 0003b350:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
 0003b360:·6170·7365·2220·6964·3d22·6964·6d35·3635··apse"·id="idm565
 0003b370:·3322·3e3c·7461·626c·6520·636c·6173·733d··3"><table·class=
 0003b380:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str
 0003b390:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde
 0003b3a0:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden
 0003b3b0:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com
 0003b3c0:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td
 0003b3d0:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
 0003b3e0:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption
 0003b3f0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
 0003b400:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e52··d></tr><tr><th>R
 0003b410:·6562·6f6f·743a·3c2f·7468·3e3c·7464·3e66··eboot:</th><td>f
 0003b420:·616c·7365·3c2f·7464·3e3c·2f74·723e·3c74··alse</td></tr><t
 0003b430:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<
 0003b440:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</
 0003b450:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table>
 0003b460:·3c70·7265·3e3c·636f·6465·3e69·6e63·6c75··<pre><code>inclu
 0003b470:·6465·2069·6e73·7461·6c6c·5f61·6964·650a··de·install_aide.
 0003b480:·0a63·6c61·7373·2069·6e73·7461·6c6c·5f61··.class·install_a
 0003b490:·6964·6520·7b0a·2020·7061·636b·6167·6520··ide·{.··package·
 0003b4a0:·7b20·2761·6964·6527·3a0a·2020·2020·656e··{·'aide':.····en
 0003b4b0:·7375·7265·203d·2667·743b·2027·696e·7374··sure·=&gt;·'inst
 0003b4c0:·616c·6c65·6427·2c0a·2020·7d0a·7d0a·3c2f··alled',.··}.}.</
 0003b4d0:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div
 0003b4e0:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b
 0003b4f0:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data
 0003b500:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps
 0003b510:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
 0003b520:·2369·646d·3536·3534·2220·7461·6269·6e64··#idm5654"·tabind
 0003b530:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
 0003b540:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
 0003b550:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
 0003b560:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
 0003b570:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
 0003b580:·5265·6d65·6469·6174·696f·6e20·5368·656c··Remediation·Shel
 0003b590:·6c20·7363·7269·7074·20e2·87b2·3c2f·613e··l·script·...</a>
 0003b5a0:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="
 0003b5b0:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c
 0003b5c0:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm
 0003b5d0:·3536·3534·223e·3c74·6162·6c65·2063·6c61··5654"><table·cla
 0003b5e0:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-
 0003b5f0:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo
 0003b600:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con
 0003b610:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>
 0003b620:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>
 0003b630:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
 0003b640:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt
 0003b650:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low
 0003b660:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
 0003b670:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t
 0003b680:·643e·6661·6c73·653c·2f74·643e·3c2f·7472··d>false</td></tr
 0003b690:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg
 0003b6a0:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl
 0003b6b0:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab
 0003b6c0:·6c65·3e3c·7072·653e·3c63·6f64·653e·2320··le><pre><code>#·
 0003b6d0:·5265·6d65·6469·6174·696f·6e20·6973·2061··Remediation·is·a
 0003b6e0:·7070·6c69·6361·626c·6520·6f6e·6c79·2069··pplicable·only·i
 0003b6f0:·6e20·6365·7274·6169·6e20·706c·6174·666f··n·certain·platfo
 0003b700:·726d·730a·6966·2072·706d·202d·2d71·7569··rms.if·rpm·--qui
 0003b710:·6574·202d·7120·6b65·726e·656c·207c·7c20··et·-q·kernel·||·
 0003b720:·7270·6d20·2d2d·7175·6965·7420·2d71·206b··rpm·--quiet·-q·k
 0003b730:·6572·6e65·6c2d·7565·6b3b·2074·6865·6e0a··ernel-uek;·then.
 0003b740:·0a69·6620·2120·7270·6d20·2d71·202d·2d71··.if·!·rpm·-q·--q
 0003b750:·7569·6574·2022·6169·6465·2220·3b20·7468··uiet·"aide"·;·th
 0003b760:·656e·0a20·2020·2079·756d·2069·6e73·7461··en.····yum·insta
 0003b770:·6c6c·202d·7920·2261·6964·6522·0a66·690a··ll·-y·"aide".fi.
 0003b780:·0a65·6c73·650a·2020·2020·2667·743b·2661··.else.····&gt;&a
 0003b790:·6d70·3b32·2065·6368·6f20·2752·656d·6564··mp;2·echo·'Remed
 0003b7a0:·6961·7469·6f6e·2069·7320·6e6f·7420·6170··iation·is·not·ap
 0003b7b0:·706c·6963·6162·6c65·2c20·6e6f·7468·696e··plicable,·nothin
 0003b7c0:·6720·7761·7320·646f·6e65·270a·6669·0a3c··g·was·done'.fi.<
 0003b7d0:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di
 0003b7e0:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn·
 0003b7f0:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat
 0003b800:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap
 0003b810:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
 0003b820:·2223·6964·6d35·3635·3522·2074·6162·696e··"#idm5655"·tabin
 0003b830:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
 0003b840:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
 0003b850:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
 0003b860:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
 0003b870:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
0003b1d0:·3e52·656d·6564·6961·7469·6f6e·2041·6e61··>Remediation·Ana0003b880:·3e52·656d·6564·6961·7469·6f6e·2041·6e61··>Remediation·Ana
0003b1e0:·636f·6e64·6120·736e·6970·7065·7420·e287··conda·snippet·..0003b890:·636f·6e64·6120·736e·6970·7065·7420·e287··conda·snippet·..
0003b1f0:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl0003b8a0:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl
0003b200:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla0003b8b0:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla
0003b210:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id0003b8c0:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id
0003b220:·3d22·6964·6d35·3635·3222·3e3c·7461·626c··="idm5652"><tabl0003b8d0:·3d22·6964·6d35·3635·3522·3e3c·7461·626c··="idm5655"><tabl
0003b230:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t0003b8e0:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t
0003b240:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab0003b8f0:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab
0003b250:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl0003b900:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl
0003b260:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr0003b910:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr
0003b270:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:0003b920:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:
0003b280:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td0003b930:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
0003b290:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di0003b940:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di
Max diff block lines reached; 662190/680710 bytes (97.28%) of diff not shown.
55.5 KB
html2text {}
    
Offset 152, 21 lines modifiedOffset 152, 14 lines modified
152 ··-·PCI-DSSv4-11.5.2152 ··-·PCI-DSSv4-11.5.2
153 ··-·enable_strategy153 ··-·enable_strategy
154 ··-·low_complexity154 ··-·low_complexity
155 ··-·low_disruption155 ··-·low_disruption
156 ··-·medium_severity156 ··-·medium_severity
157 ··-·no_reboot_needed157 ··-·no_reboot_needed
158 ··-·package_aide_installed158 ··-·package_aide_installed
159 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
160 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
161 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
162 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
163 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
164 package·--add=aide 
165 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8159 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
166 [[packages]]160 [[packages]]
167 name·=·"aide"161 name·=·"aide"
168 version·=·"*"162 version·=·"*"
169 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8163 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
170 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low164 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 191, 14 lines modifiedOffset 184, 21 lines modified
191 if·!·rpm·-q·--quiet·"aide"·;·then184 if·!·rpm·-q·--quiet·"aide"·;·then
192 ····yum·install·-y·"aide"185 ····yum·install·-y·"aide"
193 fi186 fi
  
194 else187 else
195 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'188 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
196 fi189 fi
 190 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 191 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 192 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 193 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 194 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 195 package·--add=aide
197 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*196 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
198 Run·the·following·command·to·generate·a·new·database:197 Run·the·following·command·to·generate·a·new·database:
199 $·sudo·/usr/sbin/aide·--init198 $·sudo·/usr/sbin/aide·--init
200 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the199 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the
201 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these200 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these
202 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their201 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their
203 integrity.·The·newly-generated·database·can·be·installed·as·follows:202 integrity.·The·newly-generated·database·can·be·installed·as·follows:
Offset 561, 21 lines modifiedOffset 561, 14 lines modified
561 ··tags:561 ··tags:
562 ··-·enable_strategy562 ··-·enable_strategy
563 ··-·low_complexity563 ··-·low_complexity
564 ··-·low_disruption564 ··-·low_disruption
565 ··-·low_severity565 ··-·low_severity
566 ··-·no_reboot_needed566 ··-·no_reboot_needed
567 ··-·systemd_tmp_mount_enabled567 ··-·systemd_tmp_mount_enabled
568 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
569 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
570 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
571 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
572 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
573 services·--enabled=tmp.mount 
574 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8568 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
575 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low569 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
576 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low570 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
577 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false571 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
578 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable572 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
579 #·Remediation·is·applicable·only·in·certain·platforms573 #·Remediation·is·applicable·only·in·certain·platforms
580 if·(·!·(·{·rpm·--quiet·-q·kernel·;}·&&·{·rpm·--quiet·-q·rpm-ostree·;}·&&·{·rpm·--quiet·-q·bootc·;}·&&574 if·(·!·(·{·rpm·--quiet·-q·kernel·;}·&&·{·rpm·--quiet·-q·rpm-ostree·;}·&&·{·rpm·--quiet·-q·bootc·;}·&&
Offset 588, 14 lines modifiedOffset 581, 21 lines modified
588 ··"$SYSTEMCTL_EXEC"·start·'tmp.mount'581 ··"$SYSTEMCTL_EXEC"·start·'tmp.mount'
589 fi582 fi
590 "$SYSTEMCTL_EXEC"·enable·'tmp.mount'583 "$SYSTEMCTL_EXEC"·enable·'tmp.mount'
  
591 else584 else
592 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'585 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
593 fi586 fi
 587 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 588 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 589 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 590 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 591 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 592 services·--enabled=tmp.mount
594 Group  ·Sudo·  Group·contains·16·rules593 Group  ·Sudo·  Group·contains·16·rules
595 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Sudo,·which·stands·for·"su·'do'",·provides·the·ability·to·delegate·authority·to·certain594 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Sudo,·which·stands·for·"su·'do'",·provides·the·ability·to·delegate·authority·to·certain
596 users,·groups·of·users,·or·system·administrators.·When·configured·for·system·users·and/or·groups,595 users,·groups·of·users,·or·system·administrators.·When·configured·for·system·users·and/or·groups,
597 Sudo·can·allow·a·user·or·group·to·execute·privileged·commands·that·normally·only·root·is·allowed·to596 Sudo·can·allow·a·user·or·group·to·execute·privileged·commands·that·normally·only·root·is·allowed·to
598 execute.597 execute.
  
599 For·more·information·on·Sudo·and·addition·Sudo·configuration·options,·see·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8w\x8w_\x8w\x8w_\x8w\x8w_\x8.\x8._\x8s\x8s_\x8u\x8u_\x8d\x8d_\x8o\x8o_\x8.\x8._\x8w\x8w_\x8s\x8s.598 For·more·information·on·Sudo·and·addition·Sudo·configuration·options,·see·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8w\x8w_\x8w\x8w_\x8w\x8w_\x8.\x8._\x8s\x8s_\x8u\x8u_\x8d\x8d_\x8o\x8o_\x8.\x8._\x8w\x8w_\x8s\x8s.
Offset 644, 21 lines modifiedOffset 644, 14 lines modified
644 ··-·PCI-DSSv4-2.2.6644 ··-·PCI-DSSv4-2.2.6
645 ··-·enable_strategy645 ··-·enable_strategy
646 ··-·low_complexity646 ··-·low_complexity
647 ··-·low_disruption647 ··-·low_disruption
648 ··-·medium_severity648 ··-·medium_severity
649 ··-·no_reboot_needed649 ··-·no_reboot_needed
650 ··-·package_sudo_installed650 ··-·package_sudo_installed
651 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
652 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
653 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
654 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
655 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
656 package·--add=sudo 
657 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8651 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
658 [[packages]]652 [[packages]]
659 name·=·"sudo"653 name·=·"sudo"
660 version·=·"*"654 version·=·"*"
661 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8655 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
662 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low656 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 683, 14 lines modifiedOffset 676, 21 lines modified
683 if·!·rpm·-q·--quiet·"sudo"·;·then676 if·!·rpm·-q·--quiet·"sudo"·;·then
684 ····yum·install·-y·"sudo"677 ····yum·install·-y·"sudo"
685 fi678 fi
  
686 else679 else
687 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'680 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
688 fi681 fi
 682 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 683 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 684 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 685 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 686 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 687 package·--add=sudo
689 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·G\x8Gr\x8ro\x8ou\x8up\x8p·W\x8Wh\x8ho\x8o·O\x8Ow\x8wn\x8ns\x8s·/\x8/e\x8et\x8tc\x8c/\x8/s\x8su\x8ud\x8do\x8oe\x8er\x8rs\x8s.\x8.d\x8d·D\x8Di\x8ir\x8re\x8ec\x8ct\x8to\x8or\x8ry\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*688 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·G\x8Gr\x8ro\x8ou\x8up\x8p·W\x8Wh\x8ho\x8o·O\x8Ow\x8wn\x8ns\x8s·/\x8/e\x8et\x8tc\x8c/\x8/s\x8su\x8ud\x8do\x8oe\x8er\x8rs\x8s.\x8.d\x8d·D\x8Di\x8ir\x8re\x8ec\x8ct\x8to\x8or\x8ry\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
690 To·properly·set·the·group·owner·of·/etc/sudoers.d,·run·the·command:689 To·properly·set·the·group·owner·of·/etc/sudoers.d,·run·the·command:
691 $·sudo·chgrp·root·/etc/sudoers.d690 $·sudo·chgrp·root·/etc/sudoers.d
Max diff block lines reached; 51732/56857 bytes (90.99%) of diff not shown.
233 KB
./usr/share/doc/ssg-nondebian/ssg-ol7-guide-anssi_nt28_minimal.html
    
Offset 48290, 124 lines modifiedOffset 48290, 124 lines modified
000bca10:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=000bca10:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
000bca20:·2223·6964·6d33·3734·3630·2220·7461·6269··"#idm37460"·tabi000bca20:·2223·6964·6d33·3734·3630·2220·7461·6269··"#idm37460"·tabi
000bca30:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b000bca30:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
000bca40:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa000bca40:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
000bca50:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit000bca50:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
000bca60:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·000bca60:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
000bca70:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!000bca70:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
000bca80:·223e·5265·6d65·6469·6174·696f·6e20·416e··">Remediation·An000bca80:·223e·5265·6d65·6469·6174·696f·6e20·5075··">Remediation·Pu
000bca90:·6163·6f6e·6461·2073·6e69·7070·6574·20e2··aconda·snippet·.000bca90:·7070·6574·2073·6e69·7070·6574·20e2·87b2··ppet·snippet·...
000bcaa0:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c000bcaa0:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
000bcab0:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll000bcab0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
000bcac0:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i000bcac0:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
000bcad0:·643d·2269·646d·3337·3436·3022·3e3c·7461··d="idm37460"><ta000bcad0:·2269·646d·3337·3436·3022·3e3c·7461·626c··"idm37460"><tabl
000bcae0:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table000bcae0:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t
000bcaf0:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t000bcaf0:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab
000bcb00:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta000bcb00:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl
000bcb10:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><000bcb10:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr
000bcb20:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit000bcb20:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:
000bcb30:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</000bcb30:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
000bcb40:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>000bcb40:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di
000bcb50:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th>000bcb50:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t
000bcb60:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr000bcb60:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
000bcb70:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot:000bcb70:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</
000bcb80:·3c2f·7468·3e3c·7464·3e66·616c·7365·3c2f··</th><td>false</000bcb80:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td
000bcb90:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>000bcb90:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St
000bcba0:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t000bcba0:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>
000bcbb0:·643e·6469·7361·626c·653c·2f74·643e·3c2f··d>disable</td></000bcbb0:·6469·7361·626c·653c·2f74·643e·3c2f·7472··disable</td></tr
000bcbc0:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>000bcbc0:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c
000bcbd0:·3c63·6f64·653e·0a70·6163·6b61·6765·202d··<code>.package·- 
000bcbe0:·2d72·656d·6f76·653d·6468·6370·0a3c·2f63··-remove=dhcp.</c 
000bcbf0:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div> 
000bcc00:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt 
000bcc10:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data- 
000bcc20:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse 
000bcc30:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="# 
000bcc40:·6964·6d33·3734·3631·2220·7461·6269·6e64··idm37461"·tabind 
000bcc50:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but 
000bcc60:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand 
000bcc70:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title 
000bcc80:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re 
000bcc90:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!"> 
000bcca0:·5265·6d65·6469·6174·696f·6e20·5075·7070··Remediation·Pupp 
000bccb0:·6574·2073·6e69·7070·6574·20e2·87b2·3c2f··et·snippet·...</ 
000bccc0:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class 
000bccd0:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse 
000bcce0:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i 
000bccf0:·646d·3337·3436·3122·3e3c·7461·626c·6520··dm37461"><table· 
000bcd00:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab 
000bcd10:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table 
000bcd20:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table- 
000bcd30:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr>< 
000bcd40:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</ 
000bcd50:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td>< 
000bcd60:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr 
000bcd70:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td> 
000bcd80:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr 
000bcd90:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th 
000bcda0:·3e3c·7464·3e66·616c·7365·3c2f·7464·3e3c··><td>false</td>< 
000bcdb0:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra 
000bcdc0:·7465·6779·3a3c·2f74·683e·3c74·643e·6469··tegy:</th><td>di 
000bcdd0:·7361·626c·653c·2f74·643e·3c2f·7472·3e3c··sable</td></tr>< 
000bcde0:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod 
000bcdf0:·653e·696e·636c·7564·6520·7265·6d6f·7665··e>include·remove000bcbd0:·6f64·653e·696e·636c·7564·6520·7265·6d6f··ode>include·remo
000bce00:·5f64·6863·700a·0a63·6c61·7373·2072·656d··_dhcp..class·rem000bcbe0:·7665·5f64·6863·700a·0a63·6c61·7373·2072··ve_dhcp..class·r
000bce10:·6f76·655f·6468·6370·207b·0a20·2070·6163··ove_dhcp·{.··pac000bcbf0:·656d·6f76·655f·6468·6370·207b·0a20·2070··emove_dhcp·{.··p
000bce20:·6b61·6765·207b·2027·6468·6370·273a·0a20··kage·{·'dhcp':.·000bcc00:·6163·6b61·6765·207b·2027·6468·6370·273a··ackage·{·'dhcp':
000bce30:·2020·2065·6e73·7572·6520·3d26·6774·3b20·····ensure·=&gt;·000bcc10:·0a20·2020·2065·6e73·7572·6520·3d26·6774··.····ensure·=&gt
000bce40:·2770·7572·6765·6427·2c0a·2020·7d0a·7d0a··'purged',.··}.}.000bcc20:·3b20·2770·7572·6765·6427·2c0a·2020·7d0a··;·'purged',.··}.
000bce50:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d000bcc30:·7d0a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··}.</code></pre><
000bce60:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn000bcc40:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b
000bce70:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da000bcc50:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"·
000bce80:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla000bcc60:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col
000bce90:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target000bcc70:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ
000bcea0:·3d22·2369·646d·3337·3436·3222·2074·6162··="#idm37462"·tab000bcc80:·6574·3d22·2369·646d·3337·3436·3122·2074··et="#idm37461"·t
000bceb0:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="000bcc90:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
000bcec0:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp000bcca0:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
000bced0:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti000bccb0:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
000bcee0:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to000bccc0:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
000bcef0:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#000bccd0:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
000bcf00:·2122·3e52·656d·6564·6961·7469·6f6e·2053··!">Remediation·S000bcce0:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
000bcf10:·6865·6c6c·2073·6372·6970·7420·e287·b23c··hell·script·...<000bccf0:·2053·6865·6c6c·2073·6372·6970·7420·e287···Shell·script·..
 000bcd00:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl
 000bcd10:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla
 000bcd20:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id
 000bcd30:·3d22·6964·6d33·3734·3631·223e·3c74·6162··="idm37461"><tab
 000bcd40:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·
 000bcd50:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta
 000bcd60:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab
 000bcd70:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t
 000bcd80:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity
 000bcd90:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
 000bcda0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D
 000bcdb0:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><
 000bcdc0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
 000bcdd0:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:<
 000bcde0:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t
 000bcdf0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S
 000bce00:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td
 000bce10:·3e64·6973·6162·6c65·3c2f·7464·3e3c·2f74··>disable</td></t
 000bce20:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><
 000bce30:·636f·6465·3e0a·2320·4341·5554·494f·4e3a··code>.#·CAUTION:
 000bce40:·2054·6869·7320·7265·6d65·6469·6174·696f···This·remediatio
 000bce50:·6e20·7363·7269·7074·2077·696c·6c20·7265··n·script·will·re
 000bce60:·6d6f·7665·2064·6863·700a·2309·2020·2066··move·dhcp.#.···f
 000bce70:·726f·6d20·7468·6520·7379·7374·656d·2c20··rom·the·system,·
 000bce80:·616e·6420·6d61·7920·7265·6d6f·7665·2061··and·may·remove·a
 000bce90:·6e79·2070·6163·6b61·6765·730a·2309·2020··ny·packages.#.··
 000bcea0:·2074·6861·7420·6465·7065·6e64·206f·6e20···that·depend·on·
 000bceb0:·6468·6370·2e20·4578·6563·7574·6520·7468··dhcp.·Execute·th
 000bcec0:·6973·0a23·0920·2020·7265·6d65·6469·6174··is.#.···remediat
 000bced0:·696f·6e20·4146·5445·5220·7465·7374·696e··ion·AFTER·testin
 000bcee0:·6720·6f6e·2061·206e·6f6e·2d70·726f·6475··g·on·a·non-produ
 000bcef0:·6374·696f·6e0a·2309·2020·2073·7973·7465··ction.#.···syste
 000bcf00:·6d21·0a0a·6966·2072·706d·202d·7120·2d2d··m!..if·rpm·-q·--
 000bcf10:·7175·6965·7420·2264·6863·7022·203b·2074··quiet·"dhcp"·;·t
 000bcf20:·6865·6e0a·7975·6d20·7265·6d6f·7665·202d··hen.yum·remove·-
 000bcf30:·7920·2264·6863·7022·0a66·690a·3c2f·636f··y·"dhcp".fi.</co
 000bcf40:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div><
 000bcf50:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn
 000bcf60:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t
 000bcf70:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse"
 000bcf80:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i
 000bcf90:·646d·3337·3436·3222·2074·6162·696e·6465··dm37462"·tabinde
 000bcfa0:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt
 000bcfb0:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande
 000bcfc0:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=
 000bcfd0:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev
Max diff block lines reached; 200022/215782 bytes (92.70%) of diff not shown.
21.8 KB
html2text {}
    
Offset 10663, 21 lines modifiedOffset 10663, 14 lines modified
10663 ··-·PCI-DSSv4-2.2.410663 ··-·PCI-DSSv4-2.2.4
10664 ··-·disable_strategy10664 ··-·disable_strategy
10665 ··-·low_complexity10665 ··-·low_complexity
10666 ··-·low_disruption10666 ··-·low_disruption
10667 ··-·medium_severity10667 ··-·medium_severity
10668 ··-·no_reboot_needed10668 ··-·no_reboot_needed
10669 ··-·package_dhcp_removed10669 ··-·package_dhcp_removed
10670 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
10671 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
10672 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
10673 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
10674 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable 
  
10675 package·--remove=dhcp 
10676 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x810670 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
10677 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low10671 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
10678 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low10672 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
10679 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false10673 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
10680 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable10674 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
10681 include·remove_dhcp10675 include·remove_dhcp
  
Offset 10697, 14 lines modifiedOffset 10690, 21 lines modified
10697 #»      ···that·depend·on·dhcp.·Execute·this10690 #»      ···that·depend·on·dhcp.·Execute·this
10698 #»      ···remediation·AFTER·testing·on·a·non-production10691 #»      ···remediation·AFTER·testing·on·a·non-production
10699 #»      ···system!10692 #»      ···system!
  
10700 if·rpm·-q·--quiet·"dhcp"·;·then10693 if·rpm·-q·--quiet·"dhcp"·;·then
10701 yum·remove·-y·"dhcp"10694 yum·remove·-y·"dhcp"
10702 fi10695 fi
 10696 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 10697 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 10698 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 10699 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 10700 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
  
 10701 package·--remove=dhcp
10703 Group  ·Mail·Server·Software·  Group·contains·1·rule10702 Group  ·Mail·Server·Software·  Group·contains·1·rule
10704 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Mail·servers·are·used·to·send·and·receive·email·over·the·network.·Mail·is·a·very10703 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Mail·servers·are·used·to·send·and·receive·email·over·the·network.·Mail·is·a·very
10705 common·service,·and·Mail·Transfer·Agents·(MTAs)·are·obvious·targets·of·network·attack.·Ensure10704 common·service,·and·Mail·Transfer·Agents·(MTAs)·are·obvious·targets·of·network·attack.·Ensure
10706 that·systems·are·not·running·MTAs·unnecessarily,·and·configure·needed·MTAs·as·defensively·as10705 that·systems·are·not·running·MTAs·unnecessarily,·and·configure·needed·MTAs·as·defensively·as
10707 possible.10706 possible.
  
10708 Very·few·systems·at·any·site·should·be·configured·to·directly·receive·email·over·the·network.10707 Very·few·systems·at·any·site·should·be·configured·to·directly·receive·email·over·the·network.
Offset 10776, 21 lines modifiedOffset 10776, 14 lines modified
10776 ··-·NIST-800-53-CM-7(b)10776 ··-·NIST-800-53-CM-7(b)
10777 ··-·disable_strategy10777 ··-·disable_strategy
10778 ··-·low_complexity10778 ··-·low_complexity
10779 ··-·low_disruption10779 ··-·low_disruption
10780 ··-·medium_severity10780 ··-·medium_severity
10781 ··-·no_reboot_needed10781 ··-·no_reboot_needed
10782 ··-·package_sendmail_removed10782 ··-·package_sendmail_removed
10783 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
10784 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
10785 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
10786 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
10787 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable 
  
10788 package·--remove=sendmail 
10789 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x810783 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
10790 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low10784 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
10791 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low10785 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
10792 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false10786 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
10793 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable10787 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
10794 include·remove_sendmail10788 include·remove_sendmail
  
Offset 10816, 14 lines modifiedOffset 10809, 21 lines modified
10816 if·rpm·-q·--quiet·"sendmail"·;·then10809 if·rpm·-q·--quiet·"sendmail"·;·then
10817 yum·remove·-y·"sendmail"10810 yum·remove·-y·"sendmail"
10818 fi10811 fi
  
10819 else10812 else
10820 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'10813 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
10821 fi10814 fi
 10815 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 10816 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 10817 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 10818 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 10819 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
  
 10820 package·--remove=sendmail
10822 Group  ·Obsolete·Services·  Group·contains·6·groups·and·11·rules10821 Group  ·Obsolete·Services·  Group·contains·6·groups·and·11·rules
10823 _\x8[_\x8r_\x8e_\x8f_\x8]  ·This·section·discusses·a·number·of·network-visible·services·which·have·historically10822 _\x8[_\x8r_\x8e_\x8f_\x8]  ·This·section·discusses·a·number·of·network-visible·services·which·have·historically
10824 caused·problems·for·system·security,·and·for·which·disabling·or·severely·limiting·the·service10823 caused·problems·for·system·security,·and·for·which·disabling·or·severely·limiting·the·service
10825 has·been·the·best·available·guidance·for·some·time.·As·a·result·of·this,·many·of·these10824 has·been·the·best·available·guidance·for·some·time.·As·a·result·of·this,·many·of·these
10826 services·are·not·installed·as·part·of·Oracle·Linux·7·by·default.10825 services·are·not·installed·as·part·of·Oracle·Linux·7·by·default.
  
10827 Organizations·which·are·running·these·services·should·switch·to·more·secure·equivalents·as10826 Organizations·which·are·running·these·services·should·switch·to·more·secure·equivalents·as
Offset 10897, 21 lines modifiedOffset 10897, 14 lines modified
10897 ··-·PCI-DSSv4-2.2.410897 ··-·PCI-DSSv4-2.2.4
10898 ··-·disable_strategy10898 ··-·disable_strategy
10899 ··-·low_complexity10899 ··-·low_complexity
10900 ··-·low_disruption10900 ··-·low_disruption
10901 ··-·low_severity10901 ··-·low_severity
10902 ··-·no_reboot_needed10902 ··-·no_reboot_needed
10903 ··-·package_xinetd_removed10903 ··-·package_xinetd_removed
10904 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
10905 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
10906 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
10907 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
10908 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable 
  
10909 package·--remove=xinetd 
10910 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x810904 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
10911 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low10905 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
10912 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low10906 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
10913 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false10907 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
10914 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable10908 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
10915 include·remove_xinetd10909 include·remove_xinetd
  
Offset 10937, 14 lines modifiedOffset 10930, 21 lines modified
10937 if·rpm·-q·--quiet·"xinetd"·;·then10930 if·rpm·-q·--quiet·"xinetd"·;·then
10938 yum·remove·-y·"xinetd"10931 yum·remove·-y·"xinetd"
10939 fi10932 fi
  
10940 else10933 else
10941 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'10934 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
10942 fi10935 fi
 10936 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 10937 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 10938 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 10939 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 10940 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
  
 10941 package·--remove=xinetd
10943 Group  ·NIS·  Group·contains·2·rules10942 Group  ·NIS·  Group·contains·2·rules
10944 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·Network·Information·Service·(NIS),·also·known·as·'Yellow·Pages'·(YP),·and·its10943 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·Network·Information·Service·(NIS),·also·known·as·'Yellow·Pages'·(YP),·and·its
10945 successor·NIS+·have·been·made·obsolete·by·Kerberos,·LDAP,·and·other·modern·centralized10944 successor·NIS+·have·been·made·obsolete·by·Kerberos,·LDAP,·and·other·modern·centralized
Max diff block lines reached; 17563/22309 bytes (78.73%) of diff not shown.
30.8 KB
./usr/share/doc/ssg-nondebian/ssg-ol7-guide-cjis.html
    
Offset 16705, 143 lines modifiedOffset 16705, 143 lines modified
00041400:·7461·2d74·6172·6765·743d·2223·6964·6d35··ta-target="#idm500041400:·7461·2d74·6172·6765·743d·2223·6964·6d35··ta-target="#idm5
00041410:·3635·3222·2074·6162·696e·6465·783d·2230··652"·tabindex="000041410:·3635·3222·2074·6162·696e·6465·783d·2230··652"·tabindex="0
00041420:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·00041420:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
00041430:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f00041430:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
00041440:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act00041440:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
00041450:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"00041450:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
00041460:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed00041460:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
 00041470:·6961·7469·6f6e·204f·5342·7569·6c64·2042··iation·OSBuild·B
 00041480:·6c75·6570·7269·6e74·2073·6e69·7070·6574··lueprint·snippet
 00041490:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
 000414a0:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
 000414b0:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
 000414c0:·2069·643d·2269·646d·3536·3532·223e·3c70···id="idm5652"><p
 000414d0:·7265·3e3c·636f·6465·3e0a·5b5b·7061·636b··re><code>.[[pack
 000414e0:·6167·6573·5d5d·0a6e·616d·6520·3d20·2261··ages]].name·=·"a
 000414f0:·6964·6522·0a76·6572·7369·6f6e·203d·2022··ide".version·=·"
 00041500:·2a22·0a3c·2f63·6f64·653e·3c2f·7072·653e··*".</code></pre>
 00041510:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class="
 00041520:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success"
 00041530:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co
 00041540:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar
 00041550:·6765·743d·2223·6964·6d35·3635·3322·2074··get="#idm5653"·t
 00041560:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
 00041570:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
 00041580:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
 00041590:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
 000415a0:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
 000415b0:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
 000415c0:·2050·7570·7065·7420·736e·6970·7065·7420···Puppet·snippet·
 000415d0:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·
 000415e0:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col
 000415f0:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·
 00041600:·6964·3d22·6964·6d35·3635·3322·3e3c·7461··id="idm5653"><ta
 00041610:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table
 00041620:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t
 00041630:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta
 00041640:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><
 00041650:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit
 00041660:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</
 00041670:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 00041680:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th>
 00041690:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
 000416a0:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot:
 000416b0:·3c2f·7468·3e3c·7464·3e66·616c·7365·3c2f··</th><td>false</
 000416c0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 000416d0:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t
 000416e0:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t
 000416f0:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><
 00041700:·636f·6465·3e69·6e63·6c75·6465·2069·6e73··code>include·ins
 00041710:·7461·6c6c·5f61·6964·650a·0a63·6c61·7373··tall_aide..class
 00041720:·2069·6e73·7461·6c6c·5f61·6964·6520·7b0a···install_aide·{.
 00041730:·2020·7061·636b·6167·6520·7b20·2761·6964····package·{·'aid
 00041740:·6527·3a0a·2020·2020·656e·7375·7265·203d··e':.····ensure·=
 00041750:·2667·743b·2027·696e·7374·616c·6c65·6427··&gt;·'installed'
 00041760:·2c0a·2020·7d0a·7d0a·3c2f·636f·6465·3e3c··,.··}.}.</code><
 00041770:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl
 00041780:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc
 00041790:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl
 000417a0:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat
 000417b0:·612d·7461·7267·6574·3d22·2369·646d·3536··a-target="#idm56
 000417c0:·3534·2220·7461·6269·6e64·6578·3d22·3022··54"·tabindex="0"
 000417d0:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
 000417e0:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
 000417f0:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
 00041800:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
 00041810:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
 00041820:·6174·696f·6e20·5368·656c·6c20·7363·7269··ation·Shell·scri
 00041830:·7074·20e2·87b2·3c2f·613e·3c62·723e·3c64··pt·...</a><br><d
 00041840:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-
 00041850:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps
 00041860:·6522·2069·643d·2269·646d·3536·3534·223e··e"·id="idm5654">
 00041870:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta
 00041880:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe
 00041890:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered
 000418a0:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed
 000418b0:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple
 000418c0:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo
 000418d0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
 000418e0:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</
 000418f0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
 00041900:·2f74·723e·3c74·723e·3c74·683e·5265·626f··/tr><tr><th>Rebo
 00041910:·6f74·3a3c·2f74·683e·3c74·643e·6661·6c73··ot:</th><td>fals
 00041920:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr><
 00041930:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th
 00041940:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td>
 00041950:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr
 00041960:·653e·3c63·6f64·653e·2320·5265·6d65·6469··e><code>#·Remedi
 00041970:·6174·696f·6e20·6973·2061·7070·6c69·6361··ation·is·applica
 00041980:·626c·6520·6f6e·6c79·2069·6e20·6365·7274··ble·only·in·cert
 00041990:·6169·6e20·706c·6174·666f·726d·730a·6966··ain·platforms.if
 000419a0:·2072·706d·202d·2d71·7569·6574·202d·7120···rpm·--quiet·-q·
 000419b0:·6b65·726e·656c·207c·7c20·7270·6d20·2d2d··kernel·||·rpm·--
 000419c0:·7175·6965·7420·2d71·206b·6572·6e65·6c2d··quiet·-q·kernel-
 000419d0:·7565·6b3b·2074·6865·6e0a·0a69·6620·2120··uek;·then..if·!·
 000419e0:·7270·6d20·2d71·202d·2d71·7569·6574·2022··rpm·-q·--quiet·"
 000419f0:·6169·6465·2220·3b20·7468·656e·0a20·2020··aide"·;·then.···
 00041a00:·2079·756d·2069·6e73·7461·6c6c·202d·7920···yum·install·-y·
 00041a10:·2261·6964·6522·0a66·690a·0a65·6c73·650a··"aide".fi..else.
 00041a20:·2020·2020·2667·743b·2661·6d70·3b32·2065······&gt;&amp;2·e
 00041a30:·6368·6f20·2752·656d·6564·6961·7469·6f6e··cho·'Remediation
 00041a40:·2069·7320·6e6f·7420·6170·706c·6963·6162···is·not·applicab
 00041a50:·6c65·2c20·6e6f·7468·696e·6720·7761·7320··le,·nothing·was·
 00041a60:·646f·6e65·270a·6669·0a3c·2f63·6f64·653e··done'.fi.</code>
 00041a70:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c
 00041a80:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su
 00041a90:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg
 00041aa0:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da
 00041ab0:·7461·2d74·6172·6765·743d·2223·6964·6d35··ta-target="#idm5
 00041ac0:·3635·3522·2074·6162·696e·6465·783d·2230··655"·tabindex="0
 00041ad0:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
 00041ae0:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
 00041af0:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
 00041b00:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
 00041b10:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
00041470:·6961·7469·6f6e·2041·6e61·636f·6e64·6120··iation·Anaconda·00041b20:·6961·7469·6f6e·2041·6e61·636f·6e64·6120··iation·Anaconda·
00041480:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><00041b30:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><
00041490:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p00041b40:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
000414a0:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co00041b50:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
000414b0:·6c6c·6170·7365·2220·6964·3d22·6964·6d35··llapse"·id="idm500041b60:·6c6c·6170·7365·2220·6964·3d22·6964·6d35··llapse"·id="idm5
000414c0:·3635·3222·3e3c·7461·626c·6520·636c·6173··652"><table·clas00041b70:·3635·3522·3e3c·7461·626c·6520·636c·6173··655"><table·clas
000414d0:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s 
000414e0:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor 
000414f0:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond 
00041500:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C 
00041510:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th>< 
00041520:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
00041530:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti 
Max diff block lines reached; 9550/27932 bytes (34.19%) of diff not shown.
3.47 KB
html2text {}
    
Offset 548, 21 lines modifiedOffset 548, 14 lines modified
548 ··-·PCI-DSSv4-11.5.2548 ··-·PCI-DSSv4-11.5.2
549 ··-·enable_strategy549 ··-·enable_strategy
550 ··-·low_complexity550 ··-·low_complexity
551 ··-·low_disruption551 ··-·low_disruption
552 ··-·medium_severity552 ··-·medium_severity
553 ··-·no_reboot_needed553 ··-·no_reboot_needed
554 ··-·package_aide_installed554 ··-·package_aide_installed
555 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
556 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
557 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
558 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
559 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
560 package·--add=aide 
561 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8555 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
562 [[packages]]556 [[packages]]
563 name·=·"aide"557 name·=·"aide"
564 version·=·"*"558 version·=·"*"
565 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8559 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
566 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low560 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 587, 14 lines modifiedOffset 580, 21 lines modified
587 if·!·rpm·-q·--quiet·"aide"·;·then580 if·!·rpm·-q·--quiet·"aide"·;·then
588 ····yum·install·-y·"aide"581 ····yum·install·-y·"aide"
589 fi582 fi
  
590 else583 else
591 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'584 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
592 fi585 fi
 586 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 587 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 588 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 589 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 590 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 591 package·--add=aide
593 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*592 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
594 Run·the·following·command·to·generate·a·new·database:593 Run·the·following·command·to·generate·a·new·database:
595 $·sudo·/usr/sbin/aide·--init594 $·sudo·/usr/sbin/aide·--init
596 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:595 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
597 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz596 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
598 To·initiate·a·manual·check,·run·the·following·command:597 To·initiate·a·manual·check,·run·the·following·command:
599 $·sudo·/usr/sbin/aide·--check598 $·sudo·/usr/sbin/aide·--check
Offset 31603, 39 lines modifiedOffset 31603, 39 lines modified
31603 ··-·medium_severity31603 ··-·medium_severity
31604 ··-·no_reboot_needed31604 ··-·no_reboot_needed
31605 ··-·service_auditd_enabled31605 ··-·service_auditd_enabled
31606 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x831606 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
31607 [customizations.services]31607 [customizations.services]
31608 enabled·=·["auditd"]31608 enabled·=·["auditd"]
31609 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
31610 --- 
31611 apiVersion:·machineconfiguration.openshift.io/v1 
31612 kind:·MachineConfig 
31613 spec: 
31614 ··config: 
31615 ····ignition: 
31616 ······version:·3.1.0 
31617 ····systemd: 
31618 ······units: 
31619 ······-·name:·auditd.service 
31620 ········enabled:·true 
31621 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x831609 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
31622 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low31610 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
31623 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low31611 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
31624 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false31612 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
31625 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable31613 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
31626 include·enable_auditd31614 include·enable_auditd
  
31627 class·enable_auditd·{31615 class·enable_auditd·{
31628 ··service·{'auditd':31616 ··service·{'auditd':
31629 ····enable·=>·true,31617 ····enable·=>·true,
31630 ····ensure·=>·'running',31618 ····ensure·=>·'running',
31631 ··}31619 ··}
31632 }31620 }
 31621 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 31622 ---
 31623 apiVersion:·machineconfiguration.openshift.io/v1
 31624 kind:·MachineConfig
 31625 spec:
 31626 ··config:
 31627 ····ignition:
 31628 ······version:·3.1.0
 31629 ····systemd:
 31630 ······units:
 31631 ······-·name:·auditd.service
 31632 ········enabled:·true
31633 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x831633 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
31634 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low31634 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
31635 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low31635 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
31636 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false31636 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
31637 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable31637 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
31638 #·Remediation·is·applicable·only·in·certain·platforms31638 #·Remediation·is·applicable·only·in·certain·platforms
31639 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek·&&·{·rpm·--quiet·-q·audit;·};·then31639 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek·&&·{·rpm·--quiet·-q·audit;·};·then
351 KB
./usr/share/doc/ssg-nondebian/ssg-ol7-guide-cui.html
    
Offset 15166, 151 lines modifiedOffset 15166, 151 lines modified
0003b3d0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target0003b3d0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
0003b3e0:·3d22·2369·646d·3631·3834·2220·7461·6269··="#idm6184"·tabi0003b3e0:·3d22·2369·646d·3631·3834·2220·7461·6269··="#idm6184"·tabi
0003b3f0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b0003b3f0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
0003b400:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa0003b400:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
0003b410:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit0003b410:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
0003b420:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·0003b420:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
0003b430:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!0003b430:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
0003b440:·223e·5265·6d65·6469·6174·696f·6e20·416e··">Remediation·An0003b440:·223e·5265·6d65·6469·6174·696f·6e20·4f53··">Remediation·OS
0003b450:·6163·6f6e·6461·2073·6e69·7070·6574·20e2··aconda·snippet·. 
0003b460:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c 
0003b470:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll0003b450:·4275·696c·6420·426c·7565·7072·696e·7420··Build·Blueprint·
 0003b460:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><
 0003b470:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
0003b480:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i0003b480:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
 0003b490:·6c6c·6170·7365·2220·6964·3d22·6964·6d36··llapse"·id="idm6
 0003b4a0:·3138·3422·3e3c·7072·653e·3c63·6f64·653e··184"><pre><code>
 0003b4b0:·0a5b·5b70·6163·6b61·6765·735d·5d0a·6e61··.[[packages]].na
 0003b4c0:·6d65·203d·2022·6472·6163·7574·2d66·6970··me·=·"dracut-fip
 0003b4d0:·7322·0a76·6572·7369·6f6e·203d·2022·2a22··s".version·=·"*"
0003b490:·643d·2269·646d·3631·3834·223e·3c74·6162··d="idm6184"><tab 
0003b4a0:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table· 
0003b4b0:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta 
0003b4c0:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab 
0003b4d0:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t 
0003b4e0:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity 
0003b4f0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t 
0003b500:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D 
0003b510:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th>< 
0003b520:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
0003b530:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:< 
0003b540:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t 
0003b550:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S 
0003b560:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td 
0003b570:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr 
0003b580:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c 
0003b590:·6f64·653e·0a70·6163·6b61·6765·202d·2d61··ode>.package·--a 
0003b5a0:·6464·3d64·7261·6375·742d·6669·7073·0a3c··dd=dracut-fips.< 
0003b5b0:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di0003b4e0:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></
0003b5c0:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn·0003b4f0:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt
0003b5d0:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat0003b500:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d
0003b5e0:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap0003b510:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll
0003b5f0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=0003b520:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
0003b600:·2223·6964·6d36·3138·3522·2074·6162·696e··"#idm6185"·tabin0003b530:·743d·2223·6964·6d36·3138·3522·2074·6162··t="#idm6185"·tab
0003b610:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu0003b540:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
0003b620:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan0003b550:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
0003b630:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl0003b560:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
0003b640:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r0003b570:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
0003b650:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"0003b580:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
0003b660:·3e52·656d·6564·6961·7469·6f6e·204f·5342··>Remediation·OSB0003b590:·2122·3e52·656d·6564·6961·7469·6f6e·2050··!">Remediation·P
0003b670:·7569·6c64·2042·6c75·6570·7269·6e74·2073··uild·Blueprint·s 
0003b680:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b 
0003b690:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa 
0003b6a0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col 
0003b6b0:·6c61·7073·6522·2069·643d·2269·646d·3631··lapse"·id="idm61 
0003b6c0:·3835·223e·3c70·7265·3e3c·636f·6465·3e0a··85"><pre><code>. 
0003b6d0:·5b5b·7061·636b·6167·6573·5d5d·0a6e·616d··[[packages]].nam0003b5a0:·7570·7065·7420·736e·6970·7065·7420·e287··uppet·snippet·..
 0003b5b0:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl
 0003b5c0:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla
 0003b5d0:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id
 0003b5e0:·3d22·6964·6d36·3138·3522·3e3c·7461·626c··="idm6185"><tabl
 0003b5f0:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t
 0003b600:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab
 0003b610:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl
 0003b620:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr
 0003b630:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:
 0003b640:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
 0003b650:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di
 0003b660:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t
 0003b670:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
 0003b680:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</
 0003b690:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td
 0003b6a0:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St
 0003b6b0:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>
 0003b6c0:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr>
 0003b6d0:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co
 0003b6e0:·6465·3e69·6e63·6c75·6465·2069·6e73·7461··de>include·insta
0003b6e0:·6520·3d20·2264·7261·6375·742d·6669·7073··e·=·"dracut-fips0003b6f0:·6c6c·5f64·7261·6375·742d·6669·7073·0a0a··ll_dracut-fips..
0003b6f0:·220a·7665·7273·696f·6e20·3d20·222a·220a··".version·=·"*". 
0003b700:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d 
0003b710:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn 
0003b720:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da 
0003b730:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla 
0003b740:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target 
0003b750:·3d22·2369·646d·3631·3836·2220·7461·6269··="#idm6186"·tabi 
0003b760:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b 
0003b770:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa 
0003b780:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit 
0003b790:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to· 
0003b7a0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#! 
0003b7b0:·223e·5265·6d65·6469·6174·696f·6e20·5075··">Remediation·Pu 
0003b7c0:·7070·6574·2073·6e69·7070·6574·20e2·87b2··ppet·snippet·... 
0003b7d0:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla 
0003b7e0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap 
0003b7f0:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id= 
0003b800:·2269·646d·3631·3836·223e·3c74·6162·6c65··"idm6186"><table 
0003b810:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta 
0003b820:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl 
0003b830:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table 
0003b840:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr> 
0003b850:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:< 
0003b860:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td> 
0003b870:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis0003b700:·636c·6173·7320·696e·7374·616c·6c5f·6472··class·install_dr
 0003b710:·6163·7574·2d66·6970·7320·7b0a·2020·7061··acut-fips·{.··pa
 0003b720:·636b·6167·6520·7b20·2764·7261·6375·742d··ckage·{·'dracut-
 0003b730:·6669·7073·273a·0a20·2020·2065·6e73·7572··fips':.····ensur
 0003b740:·6520·3d26·6774·3b20·2769·6e73·7461·6c6c··e·=&gt;·'install
 0003b750:·6564·272c·0a20·207d·0a7d·0a3c·2f63·6f64··ed',.··}.}.</cod
 0003b760:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a
 0003b770:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn-
 0003b780:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to
 0003b790:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"·
 0003b7a0:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
 0003b7b0:·6d36·3138·3622·2074·6162·696e·6465·783d··m6186"·tabindex=
 0003b7c0:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button
 0003b7d0:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=
 0003b7e0:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A
 0003b7f0:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea
 0003b800:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem
 0003b810:·6564·6961·7469·6f6e·2053·6865·6c6c·2073··ediation·Shell·s
 0003b820:·6372·6970·7420·e287·b23c·2f61·3e3c·6272··cript·...</a><br
 0003b830:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
 0003b840:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
 0003b850:·6170·7365·2220·6964·3d22·6964·6d36·3138··apse"·id="idm618
 0003b860:·3622·3e3c·7461·626c·6520·636c·6173·733d··6"><table·class=
 0003b870:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str
 0003b880:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde
 0003b890:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden
Max diff block lines reached; 311248/330734 bytes (94.11%) of diff not shown.
27.6 KB
html2text {}
    
Offset 146, 21 lines modifiedOffset 146, 14 lines modified
146 ··-·NIST-800-53-SC-13146 ··-·NIST-800-53-SC-13
147 ··-·enable_strategy147 ··-·enable_strategy
148 ··-·low_complexity148 ··-·low_complexity
149 ··-·low_disruption149 ··-·low_disruption
150 ··-·medium_severity150 ··-·medium_severity
151 ··-·no_reboot_needed151 ··-·no_reboot_needed
152 ··-·package_dracut-fips_installed152 ··-·package_dracut-fips_installed
153 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
154 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
155 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
156 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
157 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
158 package·--add=dracut-fips 
159 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8153 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
160 [[packages]]154 [[packages]]
161 name·=·"dracut-fips"155 name·=·"dracut-fips"
162 version·=·"*"156 version·=·"*"
163 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8157 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
164 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low158 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 185, 14 lines modifiedOffset 178, 21 lines modified
185 if·!·rpm·-q·--quiet·"dracut-fips"·;·then178 if·!·rpm·-q·--quiet·"dracut-fips"·;·then
186 ····yum·install·-y·"dracut-fips"179 ····yum·install·-y·"dracut-fips"
187 fi180 fi
  
188 else181 else
189 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'182 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
190 fi183 fi
 184 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 185 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 186 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 187 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 188 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 189 package·--add=dracut-fips
191 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8de\x8e·i\x8in\x8n·G\x8GR\x8RU\x8UB\x8B2\x82·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*190 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8de\x8e·i\x8in\x8n·G\x8GR\x8RU\x8UB\x8B2\x82·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
192 To·ensure·FIPS·mode·is·enabled,·install·package·dracut-fips,·and·rebuild·initramfs·by·running·the·following·commands:191 To·ensure·FIPS·mode·is·enabled,·install·package·dracut-fips,·and·rebuild·initramfs·by·running·the·following·commands:
193 $·sudo·yum·install·dracut-fips192 $·sudo·yum·install·dracut-fips
194 dracut·-f193 dracut·-f
195 After·the·dracut·command·has·been·run,·add·the·argument·fips=1·to·the·default·GRUB·2·command·line·for·the·Linux·operating·system·in·/etc/default/grub,·in·the·manner·below:194 After·the·dracut·command·has·been·run,·add·the·argument·fips=1·to·the·default·GRUB·2·command·line·for·the·Linux·operating·system·in·/etc/default/grub,·in·the·manner·below:
196 GRUB_CMDLINE_LINUX="crashkernel=auto·rd.lvm.lv=VolGroup/LogVol06·rd.lvm.lv=VolGroup/lv_swap·rhgb·quiet·rd.shell=0·fips=1"195 GRUB_CMDLINE_LINUX="crashkernel=auto·rd.lvm.lv=VolGroup/LogVol06·rd.lvm.lv=VolGroup/lv_swap·rhgb·quiet·rd.shell=0·fips=1"
197 Finally,·rebuild·the·grub.cfg·file·by·using·the196 Finally,·rebuild·the·grub.cfg·file·by·using·the
Offset 648, 17 lines modifiedOffset 648, 14 lines modified
648 ··-·NIST-800-53-SC-13648 ··-·NIST-800-53-SC-13
649 ··-·grub2_enable_fips_mode649 ··-·grub2_enable_fips_mode
650 ··-·high_complexity650 ··-·high_complexity
651 ··-·high_severity651 ··-·high_severity
652 ··-·medium_disruption652 ··-·medium_disruption
653 ··-·reboot_required653 ··-·reboot_required
654 ··-·restrict_strategy654 ··-·restrict_strategy
655 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
656 package·--add=dracut-fips·--add=dracut-fips-aesni 
657 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8655 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
658 #·Remediation·is·applicable·only·in·certain·platforms656 #·Remediation·is·applicable·only·in·certain·platforms
659 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek·)·&&·{·rpm·--quiet·-q·grub2-common;·};·then657 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek·)·&&·{·rpm·--quiet·-q·grub2-common;·};·then
  
660 #·prelink·not·installed658 #·prelink·not·installed
661 if·test·-e·/etc/sysconfig/prelink·-o·-e·/usr/sbin/prelink;·then659 if·test·-e·/etc/sysconfig/prelink·-o·-e·/usr/sbin/prelink;·then
662 ····if·grep·-q·^PRELINKING·/etc/sysconfig/prelink660 ····if·grep·-q·^PRELINKING·/etc/sysconfig/prelink
Offset 717, 14 lines modifiedOffset 714, 17 lines modified
717 »       #·Correct·the·form·of·kernel·command·line·for·each·installed·kernel·in·the·bootloader714 »       #·Correct·the·form·of·kernel·command·line·for·each·installed·kernel·in·the·bootloader
718 »       /sbin/grubby·--update-kernel=ALL·--args="fips=1·boot=UUID=${BOOT_UUID}"715 »       /sbin/grubby·--update-kernel=ALL·--args="fips=1·boot=UUID=${BOOT_UUID}"
719 fi716 fi
  
720 else717 else
721 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'718 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
722 fi719 fi
 720 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 721 package·--add=dracut-fips·--add=dracut-fips-aesni
723 Group  ·Updating·Software·  Group·contains·4·rules722 Group  ·Updating·Software·  Group·contains·4·rules
724 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·yum·command·line·tool·is·used·to·install·and·update·software·packages.·The·system·also·provides·a·graphical·software·update·tool·in·the·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·menu,·in·the·A\x8Ad\x8dm\x8mi\x8in\x8ni\x8is\x8st\x8tr\x8ra\x8at\x8ti\x8io\x8on\x8n·submenu,·called·S\x8So\x8of\x8ft\x8tw\x8wa\x8ar\x8re\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8e.723 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·yum·command·line·tool·is·used·to·install·and·update·software·packages.·The·system·also·provides·a·graphical·software·update·tool·in·the·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·menu,·in·the·A\x8Ad\x8dm\x8mi\x8in\x8ni\x8is\x8st\x8tr\x8ra\x8at\x8ti\x8io\x8on\x8n·submenu,·called·S\x8So\x8of\x8ft\x8tw\x8wa\x8ar\x8re\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8e.
  
725 Oracle·Linux·7·systems·contain·an·installed·software·catalog·called·the·RPM·database,·which·records·metadata·of·installed·packages.·Consistently·using·yum·or·the·graphical·S\x8So\x8of\x8ft\x8tw\x8wa\x8ar\x8re\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8e·for·all·software·installation·allows·for·insight·into·the·current·inventory·of·installed·software·on·the·system.724 Oracle·Linux·7·systems·contain·an·installed·software·catalog·called·the·RPM·database,·which·records·metadata·of·installed·packages.·Consistently·using·yum·or·the·graphical·S\x8So\x8of\x8ft\x8tw\x8wa\x8ar\x8re\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8e·for·all·software·installation·allows·for·insight·into·the·current·inventory·of·installed·software·on·the·system.
  
726 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·g\x8gp\x8pg\x8gc\x8ch\x8he\x8ec\x8ck\x8k·E\x8En\x8na\x8ab\x8bl\x8le\x8ed\x8d·I\x8In\x8n·M\x8Ma\x8ai\x8in\x8n·y\x8yu\x8um\x8m·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8ra\x8at\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*725 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·g\x8gp\x8pg\x8gc\x8ch\x8he\x8ec\x8ck\x8k·E\x8En\x8na\x8ab\x8bl\x8le\x8ed\x8d·I\x8In\x8n·M\x8Ma\x8ai\x8in\x8n·y\x8yu\x8um\x8m·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8ra\x8at\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
727 The·gpgcheck·option·controls·whether·RPM·packages'·signatures·are·always·checked·prior·to·installation.·To·configure·yum·to·check·package·signatures·before·installing·them,·ensure·the·following·line·appears·in·/etc/yum.conf·in·the·[main]·section:726 The·gpgcheck·option·controls·whether·RPM·packages'·signatures·are·always·checked·prior·to·installation.·To·configure·yum·to·check·package·signatures·before·installing·them,·ensure·the·following·line·appears·in·/etc/yum.conf·in·the·[main]·section:
Offset 7997, 21 lines modifiedOffset 7997, 14 lines modified
7997 ··-·NIST-800-53-CM-6(a)7997 ··-·NIST-800-53-CM-6(a)
7998 ··-·enable_strategy7998 ··-·enable_strategy
7999 ··-·low_complexity7999 ··-·low_complexity
8000 ··-·low_disruption8000 ··-·low_disruption
8001 ··-·medium_severity8001 ··-·medium_severity
8002 ··-·no_reboot_needed8002 ··-·no_reboot_needed
8003 ··-·package_screen_installed8003 ··-·package_screen_installed
8004 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
8005 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
8006 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
8007 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
8008 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
8009 package·--add=screen 
8010 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x88004 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
8011 [[packages]]8005 [[packages]]
8012 name·=·"screen"8006 name·=·"screen"
8013 version·=·"*"8007 version·=·"*"
8014 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x88008 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
8015 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low8009 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 8036, 14 lines modifiedOffset 8029, 21 lines modified
8036 if·!·rpm·-q·--quiet·"screen"·;·then8029 if·!·rpm·-q·--quiet·"screen"·;·then
8037 ····yum·install·-y·"screen"8030 ····yum·install·-y·"screen"
8038 fi8031 fi
  
8039 else8032 else
8040 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'8033 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
8041 fi8034 fi
 8035 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 8036 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 8037 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 8038 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 8039 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 8040 package·--add=screen
8042 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·D\x8Di\x8is\x8sa\x8ab\x8bl\x8le\x8e·d\x8de\x8eb\x8bu\x8ug\x8g-\x8-s\x8sh\x8he\x8el\x8ll\x8l·S\x8Sy\x8ys\x8st\x8te\x8em\x8mD\x8D·S\x8Se\x8er\x8rv\x8vi\x8ic\x8ce\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*8041 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·D\x8Di\x8is\x8sa\x8ab\x8bl\x8le\x8e·d\x8de\x8eb\x8bu\x8ug\x8g-\x8-s\x8sh\x8he\x8el\x8ll\x8l·S\x8Sy\x8ys\x8st\x8te\x8em\x8mD\x8D·S\x8Se\x8er\x8rv\x8vi\x8ic\x8ce\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
8043 SystemD's·debug-shell·service·is·intended·to·diagnose·SystemD·related·boot·issues·with·various·systemctl·commands.·Once·enabled·and·following·a·system·reboot,·the·root·shell·will·be·available·on·tty9·which·is·access·by·pressing·CTRL-ALT-F9.·The·debug-shell·service·should·only·be·used·for·SystemD·related·issues·and·should·otherwise·be·disabled.8042 SystemD's·debug-shell·service·is·intended·to·diagnose·SystemD·related·boot·issues·with·various·systemctl·commands.·Once·enabled·and·following·a·system·reboot,·the·root·shell·will·be·available·on·tty9·which·is·access·by·pressing·CTRL-ALT-F9.·The·debug-shell·service·should·only·be·used·for·SystemD·related·issues·and·should·otherwise·be·disabled.
  
8044 By·default,·the·debug-shell·SystemD·service·is·already·disabled.·The·debug-shell·service·can·be·disabled·with·the·following·command:8043 By·default,·the·debug-shell·SystemD·service·is·already·disabled.·The·debug-shell·service·can·be·disabled·with·the·following·command:
8045 $·sudo·systemctl·mask·--now·debug-shell.service8044 $·sudo·systemctl·mask·--now·debug-shell.service
8046 Rationale:··This·prevents·attackers·with·physical·access·from·trivially·bypassing·security·on·the·machine·through·valid·troubleshooting·configurations·and·gaining·root·access·when·the·system·is·rebooted.8045 Rationale:··This·prevents·attackers·with·physical·access·from·trivially·bypassing·security·on·the·machine·through·valid·troubleshooting·configurations·and·gaining·root·access·when·the·system·is·rebooted.
8047 Severity: ··medium8046 Severity: ··medium
Offset 15922, 21 lines modifiedOffset 15922, 14 lines modified
15922 ··tags:15922 ··tags:
15923 ··-·configure_strategy15923 ··-·configure_strategy
15924 ··-·high_disruption15924 ··-·high_disruption
Max diff block lines reached; 21887/28236 bytes (77.51%) of diff not shown.
262 KB
./usr/share/doc/ssg-nondebian/ssg-ol7-guide-e8.html
    
Offset 18576, 211 lines modifiedOffset 18576, 211 lines modified
000488f0:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i000488f0:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i
00048900:·646d·3938·3532·2220·7461·6269·6e64·6578··dm9852"·tabindex00048900:·646d·3938·3532·2220·7461·6269·6e64·6578··dm9852"·tabindex
00048910:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto00048910:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto
00048920:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded00048920:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded
00048930:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="00048930:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="
00048940:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve00048940:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve
00048950:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re00048950:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re
00048960:·6d65·6469·6174·696f·6e20·416e·6163·6f6e··mediation·Anacon00048960:·6d65·6469·6174·696f·6e20·4f53·4275·696c··mediation·OSBuil
 00048970:·6420·426c·7565·7072·696e·7420·736e·6970··d·Blueprint·snip
 00048980:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br><
 00048990:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
 000489a0:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap
 000489b0:·7365·2220·6964·3d22·6964·6d39·3835·3222··se"·id="idm9852"
00048970:·6461·2073·6e69·7070·6574·20e2·87b2·3c2f··da·snippet·...</ 
00048980:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class 
00048990:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse 
000489a0:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i 
000489b0:·646d·3938·3532·223e·3c74·6162·6c65·2063··dm9852"><table·c 
000489c0:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl 
000489d0:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table- 
000489e0:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c 
000489f0:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t 
00048a00:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t 
00048a10:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></ 
00048a20:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru 
00048a30:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l 
00048a40:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr> 
00048a50:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th> 
00048a60:·3c74·643e·6661·6c73·653c·2f74·643e·3c2f··<td>false</td></ 
00048a70:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat 
00048a80:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena 
00048a90:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t 
00048aa0:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>000489c0:·3e3c·7072·653e·3c63·6f64·653e·0a5b·5b70··><pre><code>.[[p
00048ab0:·0a70·6163·6b61·6765·202d·2d61·6464·3d72··.package·--add=r000489d0:·6163·6b61·6765·735d·5d0a·6e61·6d65·203d··ackages]].name·=
 000489e0:·2022·7265·6172·220a·7665·7273·696f·6e20···"rear".version·
00048ac0:·6561·720a·3c2f·636f·6465·3e3c·2f70·7265··ear.</code></pre000489f0:·3d20·222a·220a·3c2f·636f·6465·3e3c·2f70··=·"*".</code></p
00048ad0:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class=00048a00:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas
00048ae0:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success00048a10:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe
00048af0:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c00048a20:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle=
00048b00:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta00048a30:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data-
00048b10:·7267·6574·3d22·2369·646d·3938·3533·2220··rget="#idm9853"·00048a40:·7461·7267·6574·3d22·2369·646d·3938·3533··target="#idm9853
00048b20:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol00048a50:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r
00048b30:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-00048a60:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari
00048b40:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"00048a70:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals
00048b50:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate00048a80:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa
00048b60:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href00048a90:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr
00048b70:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio00048aa0:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat
00048b80:·6e20·4f53·4275·696c·6420·426c·7565·7072··n·OSBuild·Bluepr 
00048b90:·696e·7420·736e·6970·7065·7420·e287·b23c··int·snippet·...< 
00048ba0:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas 
00048bb0:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps 
00048bc0:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id=" 
00048bd0:·6964·6d39·3835·3322·3e3c·7072·653e·3c63··idm9853"><pre><c 
00048be0:·6f64·653e·0a5b·5b70·6163·6b61·6765·735d··ode>.[[packages] 
00048bf0:·5d0a·6e61·6d65·203d·2022·7265·6172·220a··].name·=·"rear". 
00048c00:·7665·7273·696f·6e20·3d20·222a·220a·3c2f··version·=·"*".</ 
00048c10:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div 
00048c20:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b 
00048c30:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data 
00048c40:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps 
00048c50:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target=" 
00048c60:·2369·646d·3938·3534·2220·7461·6269·6e64··#idm9854"·tabind 
00048c70:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but 
00048c80:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand 
00048c90:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title 
00048ca0:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re 
00048cb0:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!"> 
00048cc0:·5265·6d65·6469·6174·696f·6e20·5075·7070··Remediation·Pupp 
00048cd0:·6574·2073·6e69·7070·6574·20e2·87b2·3c2f··et·snippet·...</ 
00048ce0:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class 
00048cf0:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse 
00048d00:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i 
00048d10:·646d·3938·3534·223e·3c74·6162·6c65·2063··dm9854"><table·c 
00048d20:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl 
00048d30:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table- 
00048d40:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c 
00048d50:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t 
00048d60:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t 
00048d70:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></ 
00048d80:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru 
00048d90:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l00048ab0:·696f·6e20·5075·7070·6574·2073·6e69·7070··ion·Puppet·snipp
 00048ac0:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d
 00048ad0:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-
 00048ae0:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps
 00048af0:·6522·2069·643d·2269·646d·3938·3533·223e··e"·id="idm9853">
 00048b00:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta
 00048b10:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe
 00048b20:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered
 00048b30:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed
 00048b40:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple
 00048b50:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo
 00048b60:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
 00048b70:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</
 00048b80:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
 00048b90:·2f74·723e·3c74·723e·3c74·683e·5265·626f··/tr><tr><th>Rebo
 00048ba0:·6f74·3a3c·2f74·683e·3c74·643e·6661·6c73··ot:</th><td>fals
 00048bb0:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr><
 00048bc0:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th
 00048bd0:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td>
 00048be0:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr
 00048bf0:·653e·3c63·6f64·653e·696e·636c·7564·6520··e><code>include·
 00048c00:·696e·7374·616c·6c5f·7265·6172·0a0a·636c··install_rear..cl
 00048c10:·6173·7320·696e·7374·616c·6c5f·7265·6172··ass·install_rear
 00048c20:·207b·0a20·2070·6163·6b61·6765·207b·2027···{.··package·{·'
 00048c30:·7265·6172·273a·0a20·2020·2065·6e73·7572··rear':.····ensur
 00048c40:·6520·3d26·6774·3b20·2769·6e73·7461·6c6c··e·=&gt;·'install
 00048c50:·6564·272c·0a20·207d·0a7d·0a3c·2f63·6f64··ed',.··}.}.</cod
 00048c60:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a
 00048c70:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn-
 00048c80:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to
 00048c90:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"·
 00048ca0:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
 00048cb0:·6d39·3835·3422·2074·6162·696e·6465·783d··m9854"·tabindex=
 00048cc0:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button
 00048cd0:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=
 00048ce0:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A
 00048cf0:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea
 00048d00:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem
 00048d10:·6564·6961·7469·6f6e·2053·6865·6c6c·2073··ediation·Shell·s
 00048d20:·6372·6970·7420·e287·b23c·2f61·3e3c·6272··cript·...</a><br
 00048d30:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
 00048d40:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
 00048d50:·6170·7365·2220·6964·3d22·6964·6d39·3835··apse"·id="idm985
 00048d60:·3422·3e3c·7461·626c·6520·636c·6173·733d··4"><table·class=
 00048d70:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str
 00048d80:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde
 00048d90:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden
Max diff block lines reached; 212744/240510 bytes (88.46%) of diff not shown.
26.8 KB
html2text {}
    
Offset 992, 21 lines modifiedOffset 992, 14 lines modified
992 ··tags:992 ··tags:
993 ··-·enable_strategy993 ··-·enable_strategy
994 ··-·low_complexity994 ··-·low_complexity
995 ··-·low_disruption995 ··-·low_disruption
996 ··-·medium_severity996 ··-·medium_severity
997 ··-·no_reboot_needed997 ··-·no_reboot_needed
998 ··-·package_rear_installed998 ··-·package_rear_installed
999 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
1000 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
1001 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
1002 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
1003 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
1004 package·--add=rear 
1005 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8999 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
1006 [[packages]]1000 [[packages]]
1007 name·=·"rear"1001 name·=·"rear"
1008 version·=·"*"1002 version·=·"*"
1009 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81003 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1010 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1004 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 1031, 14 lines modifiedOffset 1024, 21 lines modified
1031 if·!·rpm·-q·--quiet·"rear"·;·then1024 if·!·rpm·-q·--quiet·"rear"·;·then
1032 ····yum·install·-y·"rear"1025 ····yum·install·-y·"rear"
1033 fi1026 fi
  
1034 else1027 else
1035 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'1028 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
1036 fi1029 fi
 1030 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 1031 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1032 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1033 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1034 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 1035 package·--add=rear
1037 Group  ·Updating·Software·  Group·contains·5·rules1036 Group  ·Updating·Software·  Group·contains·5·rules
1038 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·yum·command·line·tool·is·used·to·install·and·update·software·packages.·The·system·also·provides·a·graphical·software·update·tool·in·the·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·menu,·in·the·A\x8Ad\x8dm\x8mi\x8in\x8ni\x8is\x8st\x8tr\x8ra\x8at\x8ti\x8io\x8on\x8n·submenu,·called·S\x8So\x8of\x8ft\x8tw\x8wa\x8ar\x8re\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8e.1037 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·yum·command·line·tool·is·used·to·install·and·update·software·packages.·The·system·also·provides·a·graphical·software·update·tool·in·the·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·menu,·in·the·A\x8Ad\x8dm\x8mi\x8in\x8ni\x8is\x8st\x8tr\x8ra\x8at\x8ti\x8io\x8on\x8n·submenu,·called·S\x8So\x8of\x8ft\x8tw\x8wa\x8ar\x8re\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8e.
  
1039 Oracle·Linux·7·systems·contain·an·installed·software·catalog·called·the·RPM·database,·which·records·metadata·of·installed·packages.·Consistently·using·yum·or·the·graphical·S\x8So\x8of\x8ft\x8tw\x8wa\x8ar\x8re\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8e·for·all·software·installation·allows·for·insight·into·the·current·inventory·of·installed·software·on·the·system.1038 Oracle·Linux·7·systems·contain·an·installed·software·catalog·called·the·RPM·database,·which·records·metadata·of·installed·packages.·Consistently·using·yum·or·the·graphical·S\x8So\x8of\x8ft\x8tw\x8wa\x8ar\x8re\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8e·for·all·software·installation·allows·for·insight·into·the·current·inventory·of·installed·software·on·the·system.
  
1040 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·g\x8gp\x8pg\x8gc\x8ch\x8he\x8ec\x8ck\x8k·E\x8En\x8na\x8ab\x8bl\x8le\x8ed\x8d·I\x8In\x8n·M\x8Ma\x8ai\x8in\x8n·y\x8yu\x8um\x8m·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8ra\x8at\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*1039 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·g\x8gp\x8pg\x8gc\x8ch\x8he\x8ec\x8ck\x8k·E\x8En\x8na\x8ab\x8bl\x8le\x8ed\x8d·I\x8In\x8n·M\x8Ma\x8ai\x8in\x8n·y\x8yu\x8um\x8m·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8ra\x8at\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
1041 The·gpgcheck·option·controls·whether·RPM·packages'·signatures·are·always·checked·prior·to·installation.·To·configure·yum·to·check·package·signatures·before·installing·them,·ensure·the·following·line·appears·in·/etc/yum.conf·in·the·[main]·section:1040 The·gpgcheck·option·controls·whether·RPM·packages'·signatures·are·always·checked·prior·to·installation.·To·configure·yum·to·check·package·signatures·before·installing·them,·ensure·the·following·line·appears·in·/etc/yum.conf·in·the·[main]·section:
Offset 1955, 21 lines modifiedOffset 1955, 14 lines modified
1955 ··-·NIST-800-53-CM-6(a)1955 ··-·NIST-800-53-CM-6(a)
1956 ··-·enable_strategy1956 ··-·enable_strategy
1957 ··-·low_complexity1957 ··-·low_complexity
1958 ··-·low_disruption1958 ··-·low_disruption
1959 ··-·medium_severity1959 ··-·medium_severity
1960 ··-·no_reboot_needed1960 ··-·no_reboot_needed
1961 ··-·package_rsyslog_installed1961 ··-·package_rsyslog_installed
1962 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
1963 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
1964 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
1965 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
1966 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
1967 package·--add=rsyslog 
1968 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81962 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
1969 [[packages]]1963 [[packages]]
1970 name·=·"rsyslog"1964 name·=·"rsyslog"
1971 version·=·"*"1965 version·=·"*"
1972 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81966 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1973 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1967 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 1994, 14 lines modifiedOffset 1987, 21 lines modified
1994 if·!·rpm·-q·--quiet·"rsyslog"·;·then1987 if·!·rpm·-q·--quiet·"rsyslog"·;·then
1995 ····yum·install·-y·"rsyslog"1988 ····yum·install·-y·"rsyslog"
1996 fi1989 fi
  
1997 else1990 else
1998 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'1991 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
1999 fi1992 fi
 1993 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 1994 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1995 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1996 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1997 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 1998 package·--add=rsyslog
2000 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·r\x8rs\x8sy\x8ys\x8sl\x8lo\x8og\x8g·S\x8Se\x8er\x8rv\x8vi\x8ic\x8ce\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*1999 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·r\x8rs\x8sy\x8ys\x8sl\x8lo\x8og\x8g·S\x8Se\x8er\x8rv\x8vi\x8ic\x8ce\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
2001 The·rsyslog·service·provides·syslog-style·logging·by·default·on·Oracle·Linux·7.·The·rsyslog·service·can·be·enabled·with·the·following·command:2000 The·rsyslog·service·provides·syslog-style·logging·by·default·on·Oracle·Linux·7.·The·rsyslog·service·can·be·enabled·with·the·following·command:
2002 $·sudo·systemctl·enable·rsyslog.service2001 $·sudo·systemctl·enable·rsyslog.service
2003 Rationale:··The·rsyslog·service·must·be·running·in·order·to·provide·logging·services,·which·are·essential·to·system·administration.2002 Rationale:··The·rsyslog·service·must·be·running·in·order·to·provide·logging·services,·which·are·essential·to·system·administration.
2004 Severity: ··medium2003 Severity: ··medium
2005 Rule·ID:····xccdf_org.ssgproject.content_rule_service_rsyslog_enabled2004 Rule·ID:····xccdf_org.ssgproject.content_rule_service_rsyslog_enabled
2006 ············_\x8c_\x8i_\x8s_\x8-_\x8c_\x8s_\x8c········1,·12,·13,·14,·15,·16,·2,·3,·5,·6,·7,·8,·92005 ············_\x8c_\x8i_\x8s_\x8-_\x8c_\x8s_\x8c········1,·12,·13,·14,·15,·16,·2,·3,·5,·6,·7,·8,·9
Offset 2190, 21 lines modifiedOffset 2190, 14 lines modified
2190 ··-·PCI-DSSv4-1.2.12190 ··-·PCI-DSSv4-1.2.1
2191 ··-·enable_strategy2191 ··-·enable_strategy
2192 ··-·low_complexity2192 ··-·low_complexity
2193 ··-·low_disruption2193 ··-·low_disruption
2194 ··-·medium_severity2194 ··-·medium_severity
2195 ··-·no_reboot_needed2195 ··-·no_reboot_needed
2196 ··-·package_firewalld_installed2196 ··-·package_firewalld_installed
2197 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
2198 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
2199 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
2200 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
2201 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
2202 package·--add=firewalld 
2203 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x82197 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
2204 [[packages]]2198 [[packages]]
2205 name·=·"firewalld"2199 name·=·"firewalld"
2206 version·=·"*"2200 version·=·"*"
2207 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x82201 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
2208 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low2202 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 2229, 14 lines modifiedOffset 2222, 21 lines modified
2229 if·!·rpm·-q·--quiet·"firewalld"·;·then2222 if·!·rpm·-q·--quiet·"firewalld"·;·then
2230 ····yum·install·-y·"firewalld"2223 ····yum·install·-y·"firewalld"
2231 fi2224 fi
  
2232 else2225 else
2233 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'2226 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
2234 fi2227 fi
 2228 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 2229 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 2230 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 2231 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 2232 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 2233 package·--add=firewalld
2235 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·f\x8fi\x8ir\x8re\x8ew\x8wa\x8al\x8ll\x8ld\x8d·E\x8En\x8na\x8ab\x8bl\x8le\x8ed\x8d·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*2234 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·f\x8fi\x8ir\x8re\x8ew\x8wa\x8al\x8ll\x8ld\x8d·E\x8En\x8na\x8ab\x8bl\x8le\x8ed\x8d·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
2236 The·firewalld·service·can·be·enabled·with·the·following·command:2235 The·firewalld·service·can·be·enabled·with·the·following·command:
2237 $·sudo·systemctl·enable·firewalld.service2236 $·sudo·systemctl·enable·firewalld.service
Max diff block lines reached; 21662/27416 bytes (79.01%) of diff not shown.
198 KB
./usr/share/doc/ssg-nondebian/ssg-ol7-guide-hipaa.html
    
Offset 36869, 174 lines modifiedOffset 36869, 174 lines modified
00090040:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm00090040:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
00090050:·3335·3938·3222·2074·6162·696e·6465·783d··35982"·tabindex=00090050:·3335·3938·3222·2074·6162·696e·6465·783d··35982"·tabindex=
00090060:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button00090060:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button
00090070:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=00090070:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=
00090080:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A00090080:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A
00090090:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea00090090:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea
000900a0:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem000900a0:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem
000900b0:·6564·6961·7469·6f6e·2041·6e61·636f·6e64··ediation·Anacond000900b0:·6564·6961·7469·6f6e·204f·5342·7569·6c64··ediation·OSBuild
 000900c0:·2042·6c75·6570·7269·6e74·2073·6e69·7070···Blueprint·snipp
 000900d0:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d
 000900e0:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-
 000900f0:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps
 00090100:·6522·2069·643d·2269·646d·3335·3938·3222··e"·id="idm35982"
 00090110:·3e3c·7072·653e·3c63·6f64·653e·0a5b·6375··><pre><code>.[cu
 00090120:·7374·6f6d·697a·6174·696f·6e73·2e73·6572··stomizations.ser
 00090130:·7669·6365·735d·0a6d·6173·6b65·6420·3d20··vices].masked·=·
 00090140:·5b22·6b64·756d·7022·5d0a·3c2f·636f·6465··["kdump"].</code
 00090150:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a·
 00090160:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s
 00090170:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog
 00090180:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d
 00090190:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
 000901a0:·3335·3938·3322·2074·6162·696e·6465·783d··35983"·tabindex=
 000901b0:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button
 000901c0:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=
 000901d0:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A
 000901e0:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea
 000901f0:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem
 00090200:·6564·6961·7469·6f6e·2050·7570·7065·7420··ediation·Puppet·
000900c0:·6120·736e·6970·7065·7420·e287·b23c·2f61··a·snippet·...</a00090210:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><
000900d0:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=00090220:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
000900e0:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·00090230:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
000900f0:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id00090240:·6c6c·6170·7365·2220·6964·3d22·6964·6d33··llapse"·id="idm3
 00090250:·3539·3833·223e·3c74·6162·6c65·2063·6c61··5983"><table·cla
 00090260:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-
 00090270:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo
 00090280:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con
 00090290:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>
 000902a0:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>
00090100:·6d33·3539·3832·223e·3c70·7265·3e3c·636f··m35982"><pre><co 
00090110:·6465·3e0a·6b64·756d·7020·2d2d·6469·7361··de>.kdump·--disa 
00090120:·626c·650a·3c2f·636f·6465·3e3c·2f70·7265··ble.</code></pre 
00090130:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class= 
00090140:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success 
00090150:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c 
00090160:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta 
00090170:·7267·6574·3d22·2369·646d·3335·3938·3322··rget="#idm35983" 
00090180:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro 
00090190:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria 
000901a0:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false 
000901b0:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat 
000901c0:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre 
000901d0:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati 
000901e0:·6f6e·204f·5342·7569·6c64·2042·6c75·6570··on·OSBuild·Bluep 
000901f0:·7269·6e74·2073·6e69·7070·6574·20e2·87b2··rint·snippet·... 
00090200:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla 
00090210:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap 
00090220:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id= 
00090230:·2269·646d·3335·3938·3322·3e3c·7072·653e··"idm35983"><pre> 
00090240:·3c63·6f64·653e·0a5b·6375·7374·6f6d·697a··<code>.[customiz 
00090250:·6174·696f·6e73·2e73·6572·7669·6365·735d··ations.services] 
00090260:·0a6d·6173·6b65·6420·3d20·5b22·6b64·756d··.masked·=·["kdum 
00090270:·7022·5d0a·3c2f·636f·6465·3e3c·2f70·7265··p"].</code></pre 
00090280:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class= 
00090290:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success 
000902a0:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c 
000902b0:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta 
000902c0:·7267·6574·3d22·2369·646d·3335·3938·3422··rget="#idm35984" 
000902d0:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro 
000902e0:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria 
000902f0:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false 
00090300:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat 
00090310:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre 
00090320:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati 
00090330:·6f6e·2050·7570·7065·7420·736e·6970·7065··on·Puppet·snippe 
00090340:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di 
00090350:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c 
00090360:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse 
00090370:·2220·6964·3d22·6964·6d33·3539·3834·223e··"·id="idm35984"> 
00090380:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta 
00090390:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe 
000903a0:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered 
000903b0:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed 
000903c0:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple 
000903d0:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo 
000903e0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr>< 
000903f0:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</ 
00090400:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td>< 
00090410:·2f74·723e·3c74·723e·3c74·683e·5265·626f··/tr><tr><th>Rebo 
00090420:·6f74·3a3c·2f74·683e·3c74·643e·6661·6c73··ot:</th><td>fals 
00090430:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr>< 
00090440:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th 
00090450:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td> 
00090460:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr 
00090470:·653e·3c63·6f64·653e·696e·636c·7564·6520··e><code>include· 
00090480:·6469·7361·626c·655f·6b64·756d·700a·0a63··disable_kdump..c 
00090490:·6c61·7373·2064·6973·6162·6c65·5f6b·6475··lass·disable_kdu 
000904a0:·6d70·207b·0a20·2073·6572·7669·6365·207b··mp·{.··service·{ 
000904b0:·276b·6475·6d70·273a·0a20·2020·2065·6e61··'kdump':.····ena 
000904c0:·626c·6520·3d26·6774·3b20·6661·6c73·652c··ble·=&gt;·false, 
000904d0:·0a20·2020·2065·6e73·7572·6520·3d26·6774··.····ensure·=&gt 
000904e0:·3b20·2773·746f·7070·6564·272c·0a20·207d··;·'stopped',.··} 
000904f0:·0a7d·0a3c·2f63·6f64·653e·3c2f·7072·653e··.}.</code></pre> 
00090500:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class=" 
00090510:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success" 
00090520:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co 
00090530:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar 
00090540:·6765·743d·2223·6964·6d33·3539·3835·2220··get="#idm35985"· 
00090550:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol 
00090560:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria- 
00090570:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false" 
00090580:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate 
00090590:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href 
000905a0:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio 
000905b0:·6e20·5368·656c·6c20·7363·7269·7074·20e2··n·Shell·script·. 
000905c0:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c 
000905d0:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll 
000905e0:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i 
000905f0:·643d·2269·646d·3335·3938·3522·3e3c·7461··d="idm35985"><ta 
00090600:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table 
00090610:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t 
00090620:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta 
00090630:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed">< 
00090640:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit 
00090650:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</ 
00090660:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
00090670:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th> 
Max diff block lines reached; 158290/180950 bytes (87.48%) of diff not shown.
21.2 KB
html2text {}
    
Offset 4599, 17 lines modifiedOffset 4599, 14 lines modified
4599 ··-·NIST-800-53-CM-7(b)4599 ··-·NIST-800-53-CM-7(b)
4600 ··-·disable_strategy4600 ··-·disable_strategy
4601 ··-·low_complexity4601 ··-·low_complexity
4602 ··-·low_disruption4602 ··-·low_disruption
4603 ··-·medium_severity4603 ··-·medium_severity
4604 ··-·no_reboot_needed4604 ··-·no_reboot_needed
4605 ··-·service_kdump_disabled4605 ··-·service_kdump_disabled
4606 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
4607 kdump·--disable 
4608 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x84606 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
4609 [customizations.services]4607 [customizations.services]
4610 masked·=·["kdump"]4608 masked·=·["kdump"]
4611 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x84609 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
4612 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low4610 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
4613 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low4611 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
Offset 4648, 14 lines modifiedOffset 4645, 17 lines modified
4648 #·so·let's·reset·the·state·so·OVAL·checks·pass.4645 #·so·let's·reset·the·state·so·OVAL·checks·pass.
4649 #·Service·should·be·'inactive',·not·'failed'·after·reboot·though.4646 #·Service·should·be·'inactive',·not·'failed'·after·reboot·though.
4650 "$SYSTEMCTL_EXEC"·reset-failed·'kdump.service'·||·true4647 "$SYSTEMCTL_EXEC"·reset-failed·'kdump.service'·||·true
  
4651 else4648 else
4652 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'4649 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
4653 fi4650 fi
 4651 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 4652 kdump·--disable
4654 Group  ·Cron·and·At·Daemons·  Group·contains·1·rule4653 Group  ·Cron·and·At·Daemons·  Group·contains·1·rule
4655 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·cron·and·at·services·are·used·to·allow·commands·to·be·executed·at·a·later·time.·The·cron·service·is·required·by·almost·all·systems·to·perform·necessary·maintenance·tasks,·while·at·may·or·may·not·be·required·on·a·given·system.·Both·daemons·should·be·configured·defensively.4654 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·cron·and·at·services·are·used·to·allow·commands·to·be·executed·at·a·later·time.·The·cron·service·is·required·by·almost·all·systems·to·perform·necessary·maintenance·tasks,·while·at·may·or·may·not·be·required·on·a·given·system.·Both·daemons·should·be·configured·defensively.
4656 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·c\x8cr\x8ro\x8on\x8n·S\x8Se\x8er\x8rv\x8vi\x8ic\x8ce\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*4655 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·c\x8cr\x8ro\x8on\x8n·S\x8Se\x8er\x8rv\x8vi\x8ic\x8ce\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
4657 The·crond·service·is·used·to·execute·commands·at·preconfigured·times.·It·is·required·by·almost·all·systems·to·perform·necessary·maintenance·tasks,·such·as·notifying·root·of·system·activity.·The·crond·service·can·be·enabled·with·the·following·command:4656 The·crond·service·is·used·to·execute·commands·at·preconfigured·times.·It·is·required·by·almost·all·systems·to·perform·necessary·maintenance·tasks,·such·as·notifying·root·of·system·activity.·The·crond·service·can·be·enabled·with·the·following·command:
4658 $·sudo·systemctl·enable·crond.service4657 $·sudo·systemctl·enable·crond.service
4659 Rationale:··Due·to·its·usage·for·maintenance·and·security-supporting·tasks,·enabling·the·cron·daemon·is·essential.4658 Rationale:··Due·to·its·usage·for·maintenance·and·security-supporting·tasks,·enabling·the·cron·daemon·is·essential.
4660 Severity: ··medium4659 Severity: ··medium
Offset 4883, 21 lines modifiedOffset 4883, 14 lines modified
4883 ··-·PCI-DSSv4-2.2.44883 ··-·PCI-DSSv4-2.2.4
4884 ··-·disable_strategy4884 ··-·disable_strategy
4885 ··-·low_complexity4885 ··-·low_complexity
4886 ··-·low_disruption4886 ··-·low_disruption
4887 ··-·low_severity4887 ··-·low_severity
4888 ··-·no_reboot_needed4888 ··-·no_reboot_needed
4889 ··-·package_xinetd_removed4889 ··-·package_xinetd_removed
4890 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
4891 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
4892 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
4893 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
4894 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable 
  
4895 package·--remove=xinetd 
4896 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x84890 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
4897 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low4891 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
4898 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low4892 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
4899 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false4893 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
4900 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable4894 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
4901 include·remove_xinetd4895 include·remove_xinetd
  
Offset 4923, 14 lines modifiedOffset 4916, 21 lines modified
4923 if·rpm·-q·--quiet·"xinetd"·;·then4916 if·rpm·-q·--quiet·"xinetd"·;·then
4924 yum·remove·-y·"xinetd"4917 yum·remove·-y·"xinetd"
4925 fi4918 fi
  
4926 else4919 else
4927 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'4920 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
4928 fi4921 fi
 4922 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 4923 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 4924 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 4925 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 4926 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
  
 4927 package·--remove=xinetd
4929 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·D\x8Di\x8is\x8sa\x8ab\x8bl\x8le\x8e·x\x8xi\x8in\x8ne\x8et\x8td\x8d·S\x8Se\x8er\x8rv\x8vi\x8ic\x8ce\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*4928 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·D\x8Di\x8is\x8sa\x8ab\x8bl\x8le\x8e·x\x8xi\x8in\x8ne\x8et\x8td\x8d·S\x8Se\x8er\x8rv\x8vi\x8ic\x8ce\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
4930 The·xinetd·service·can·be·disabled·with·the·following·command:4929 The·xinetd·service·can·be·disabled·with·the·following·command:
4931 $·sudo·systemctl·mask·--now·xinetd.service4930 $·sudo·systemctl·mask·--now·xinetd.service
4932 Rationale:··The·xinetd·service·provides·a·dedicated·listener·service·for·some·programs,·which·is·no·longer·necessary·for·commonly-used·network·services.·Disabling·it·ensures·that·these·uncommon·services·are·not·running,·and·also·prevents·attacks·against·xinetd·itself.4931 Rationale:··The·xinetd·service·provides·a·dedicated·listener·service·for·some·programs,·which·is·no·longer·necessary·for·commonly-used·network·services.·Disabling·it·ensures·that·these·uncommon·services·are·not·running,·and·also·prevents·attacks·against·xinetd·itself.
4933 Severity: ··medium4932 Severity: ··medium
4934 Rule·ID:····xccdf_org.ssgproject.content_rule_service_xinetd_disabled4933 Rule·ID:····xccdf_org.ssgproject.content_rule_service_xinetd_disabled
4935 ············_\x8c_\x8i_\x8s_\x8-_\x8c_\x8s_\x8c········11,·12,·14,·15,·3,·8,·94934 ············_\x8c_\x8i_\x8s_\x8-_\x8c_\x8s_\x8c········11,·12,·14,·15,·3,·8,·9
Offset 5112, 21 lines modifiedOffset 5112, 14 lines modified
5112 ··-·PCI-DSSv4-2.2.45112 ··-·PCI-DSSv4-2.2.4
5113 ··-·disable_strategy5113 ··-·disable_strategy
5114 ··-·low_complexity5114 ··-·low_complexity
5115 ··-·low_disruption5115 ··-·low_disruption
5116 ··-·no_reboot_needed5116 ··-·no_reboot_needed
5117 ··-·package_ypbind_removed5117 ··-·package_ypbind_removed
5118 ··-·unknown_severity5118 ··-·unknown_severity
5119 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
5120 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
5121 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
5122 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
5123 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable 
  
5124 package·--remove=ypbind 
5125 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x85119 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
5126 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low5120 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
5127 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low5121 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
5128 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false5122 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
5129 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable5123 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
5130 include·remove_ypbind5124 include·remove_ypbind
  
Offset 5146, 14 lines modifiedOffset 5139, 21 lines modified
5146 #»      ···that·depend·on·ypbind.·Execute·this5139 #»      ···that·depend·on·ypbind.·Execute·this
5147 #»      ···remediation·AFTER·testing·on·a·non-production5140 #»      ···remediation·AFTER·testing·on·a·non-production
5148 #»      ···system!5141 #»      ···system!
  
5149 if·rpm·-q·--quiet·"ypbind"·;·then5142 if·rpm·-q·--quiet·"ypbind"·;·then
5150 yum·remove·-y·"ypbind"5143 yum·remove·-y·"ypbind"
5151 fi5144 fi
 5145 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 5146 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 5147 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 5148 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 5149 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
  
 5150 package·--remove=ypbind
5152 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·U\x8Un\x8ni\x8in\x8ns\x8st\x8ta\x8al\x8ll\x8l·y\x8yp\x8ps\x8se\x8er\x8rv\x8v·P\x8Pa\x8ac\x8ck\x8ka\x8ag\x8ge\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*5151 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·U\x8Un\x8ni\x8in\x8ns\x8st\x8ta\x8al\x8ll\x8l·y\x8yp\x8ps\x8se\x8er\x8rv\x8v·P\x8Pa\x8ac\x8ck\x8ka\x8ag\x8ge\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
5153 The·ypserv·package·can·be·removed·with·the·following·command:5152 The·ypserv·package·can·be·removed·with·the·following·command:
5154 $·sudo·yum·erase·ypserv5153 $·sudo·yum·erase·ypserv
5155 Rationale:··The·NIS·service·provides·an·unencrypted·authentication·service·which·does·not·provide·for·the·confidentiality·and·integrity·of·user·passwords·or·the·remote·session.·Removing·the·ypserv·package·decreases·the·risk·of·the·accidental·(or·intentional)·activation·of·NIS·or·NIS+·services.5154 Rationale:··The·NIS·service·provides·an·unencrypted·authentication·service·which·does·not·provide·for·the·confidentiality·and·integrity·of·user·passwords·or·the·remote·session.·Removing·the·ypserv·package·decreases·the·risk·of·the·accidental·(or·intentional)·activation·of·NIS·or·NIS+·services.
5156 Severity: ··high5155 Severity: ··high
5157 Rule·ID:····xccdf_org.ssgproject.content_rule_package_ypserv_removed5156 Rule·ID:····xccdf_org.ssgproject.content_rule_package_ypserv_removed
5158 ············_\x8c_\x8i_\x8s_\x8-_\x8c_\x8s_\x8c········11,·12,·14,·15,·3,·8,·95157 ············_\x8c_\x8i_\x8s_\x8-_\x8c_\x8s_\x8c········11,·12,·14,·15,·3,·8,·9
Offset 5191, 21 lines modifiedOffset 5191, 14 lines modified
5191 ··-·PCI-DSSv4-2.2.45191 ··-·PCI-DSSv4-2.2.4
5192 ··-·disable_strategy5192 ··-·disable_strategy
5193 ··-·high_severity5193 ··-·high_severity
Max diff block lines reached; 15992/21669 bytes (73.80%) of diff not shown.
575 KB
./usr/share/doc/ssg-nondebian/ssg-ol7-guide-ncp.html
    
Offset 16841, 144 lines modifiedOffset 16841, 144 lines modified
00041c80:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id00041c80:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
00041c90:·6d35·3635·3222·2074·6162·696e·6465·783d··m5652"·tabindex=00041c90:·6d35·3635·3222·2074·6162·696e·6465·783d··m5652"·tabindex=
00041ca0:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button00041ca0:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button
00041cb0:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=00041cb0:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=
00041cc0:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A00041cc0:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A
00041cd0:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea00041cd0:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea
00041ce0:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem00041ce0:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem
 00041cf0:·6564·6961·7469·6f6e·204f·5342·7569·6c64··ediation·OSBuild
 00041d00:·2042·6c75·6570·7269·6e74·2073·6e69·7070···Blueprint·snipp
 00041d10:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d
 00041d20:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-
 00041d30:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps
 00041d40:·6522·2069·643d·2269·646d·3536·3532·223e··e"·id="idm5652">
 00041d50:·3c70·7265·3e3c·636f·6465·3e0a·5b5b·7061··<pre><code>.[[pa
 00041d60:·636b·6167·6573·5d5d·0a6e·616d·6520·3d20··ckages]].name·=·
 00041d70:·2261·6964·6522·0a76·6572·7369·6f6e·203d··"aide".version·=
 00041d80:·2022·2a22·0a3c·2f63·6f64·653e·3c2f·7072···"*".</code></pr
 00041d90:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class
 00041da0:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes
 00041db0:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle="
 00041dc0:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t
 00041dd0:·6172·6765·743d·2223·6964·6d35·3635·3322··arget="#idm5653"
 00041de0:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro
 00041df0:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria
 00041e00:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false
 00041e10:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat
 00041e20:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre
 00041e30:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati
 00041e40:·6f6e·2050·7570·7065·7420·736e·6970·7065··on·Puppet·snippe
 00041e50:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di
 00041e60:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c
 00041e70:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse
 00041e80:·2220·6964·3d22·6964·6d35·3635·3322·3e3c··"·id="idm5653"><
 00041e90:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab
 00041ea0:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped
 00041eb0:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·
 00041ec0:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"
 00041ed0:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex
 00041ee0:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low
 00041ef0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
 00041f00:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t
 00041f10:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
 00041f20:·7472·3e3c·7472·3e3c·7468·3e52·6562·6f6f··tr><tr><th>Reboo
 00041f30:·743a·3c2f·7468·3e3c·7464·3e66·616c·7365··t:</th><td>false
 00041f40:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
 00041f50:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th>
 00041f60:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td><
 00041f70:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre
 00041f80:·3e3c·636f·6465·3e69·6e63·6c75·6465·2069··><code>include·i
 00041f90:·6e73·7461·6c6c·5f61·6964·650a·0a63·6c61··nstall_aide..cla
 00041fa0:·7373·2069·6e73·7461·6c6c·5f61·6964·6520··ss·install_aide·
 00041fb0:·7b0a·2020·7061·636b·6167·6520·7b20·2761··{.··package·{·'a
 00041fc0:·6964·6527·3a0a·2020·2020·656e·7375·7265··ide':.····ensure
 00041fd0:·203d·2667·743b·2027·696e·7374·616c·6c65···=&gt;·'installe
 00041fe0:·6427·2c0a·2020·7d0a·7d0a·3c2f·636f·6465··d',.··}.}.</code
 00041ff0:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a·
 00042000:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s
 00042010:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog
 00042020:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d
 00042030:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
 00042040:·3536·3534·2220·7461·6269·6e64·6578·3d22··5654"·tabindex="
 00042050:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
 00042060:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
 00042070:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
 00042080:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
 00042090:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
 000420a0:·6469·6174·696f·6e20·5368·656c·6c20·7363··diation·Shell·sc
 000420b0:·7269·7074·20e2·87b2·3c2f·613e·3c62·723e··ript·...</a><br>
 000420c0:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
 000420d0:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
 000420e0:·7073·6522·2069·643d·2269·646d·3536·3534··pse"·id="idm5654
 000420f0:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="
 00042100:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri
 00042110:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border
 00042120:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens
 00042130:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp
 00042140:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>
 00042150:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
 00042160:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:
 00042170:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
 00042180:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re
 00042190:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa
 000421a0:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr
 000421b0:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</
 000421c0:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t
 000421d0:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><
 000421e0:·7072·653e·3c63·6f64·653e·2320·5265·6d65··pre><code>#·Reme
 000421f0:·6469·6174·696f·6e20·6973·2061·7070·6c69··diation·is·appli
 00042200:·6361·626c·6520·6f6e·6c79·2069·6e20·6365··cable·only·in·ce
 00042210:·7274·6169·6e20·706c·6174·666f·726d·730a··rtain·platforms.
 00042220:·6966·2072·706d·202d·2d71·7569·6574·202d··if·rpm·--quiet·-
 00042230:·7120·6b65·726e·656c·207c·7c20·7270·6d20··q·kernel·||·rpm·
 00042240:·2d2d·7175·6965·7420·2d71·206b·6572·6e65··--quiet·-q·kerne
 00042250:·6c2d·7565·6b3b·2074·6865·6e0a·0a69·6620··l-uek;·then..if·
 00042260:·2120·7270·6d20·2d71·202d·2d71·7569·6574··!·rpm·-q·--quiet
 00042270:·2022·6169·6465·2220·3b20·7468·656e·0a20···"aide"·;·then.·
 00042280:·2020·2079·756d·2069·6e73·7461·6c6c·202d·····yum·install·-
 00042290:·7920·2261·6964·6522·0a66·690a·0a65·6c73··y·"aide".fi..els
 000422a0:·650a·2020·2020·2667·743b·2661·6d70·3b32··e.····&gt;&amp;2
 000422b0:·2065·6368·6f20·2752·656d·6564·6961·7469···echo·'Remediati
 000422c0:·6f6e·2069·7320·6e6f·7420·6170·706c·6963··on·is·not·applic
 000422d0:·6162·6c65·2c20·6e6f·7468·696e·6720·7761··able,·nothing·wa
 000422e0:·7320·646f·6e65·270a·6669·0a3c·2f63·6f64··s·done'.fi.</cod
 000422f0:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a
 00042300:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn-
 00042310:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to
 00042320:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"·
 00042330:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
 00042340:·6d35·3635·3522·2074·6162·696e·6465·783d··m5655"·tabindex=
 00042350:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button
 00042360:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=
 00042370:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A
 00042380:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea
 00042390:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem
00041cf0:·6564·6961·7469·6f6e·2041·6e61·636f·6e64··ediation·Anacond000423a0:·6564·6961·7469·6f6e·2041·6e61·636f·6e64··ediation·Anacond
00041d00:·6120·736e·6970·7065·7420·e287·b23c·2f61··a·snippet·...</a000423b0:·6120·736e·6970·7065·7420·e287·b23c·2f61··a·snippet·...</a
00041d10:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class= 
00041d20:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse· 
00041d30:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id 
00041d40:·6d35·3635·3222·3e3c·7461·626c·6520·636c··m5652"><table·cl 
00041d50:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table 
00041d60:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b 
00041d70:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co 
00041d80:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th 
00041d90:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th 
00041da0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t 
00041db0:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup 
Max diff block lines reached; 517587/536107 bytes (96.55%) of diff not shown.
51.2 KB
html2text {}
    
Offset 577, 21 lines modifiedOffset 577, 14 lines modified
577 ··-·PCI-DSSv4-11.5.2577 ··-·PCI-DSSv4-11.5.2
578 ··-·enable_strategy578 ··-·enable_strategy
579 ··-·low_complexity579 ··-·low_complexity
580 ··-·low_disruption580 ··-·low_disruption
581 ··-·medium_severity581 ··-·medium_severity
582 ··-·no_reboot_needed582 ··-·no_reboot_needed
583 ··-·package_aide_installed583 ··-·package_aide_installed
584 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
585 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
586 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
587 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
588 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
589 package·--add=aide 
590 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8584 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
591 [[packages]]585 [[packages]]
592 name·=·"aide"586 name·=·"aide"
593 version·=·"*"587 version·=·"*"
594 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8588 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
595 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low589 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 616, 14 lines modifiedOffset 609, 21 lines modified
616 if·!·rpm·-q·--quiet·"aide"·;·then609 if·!·rpm·-q·--quiet·"aide"·;·then
617 ····yum·install·-y·"aide"610 ····yum·install·-y·"aide"
618 fi611 fi
  
619 else612 else
620 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'613 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
621 fi614 fi
 615 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 616 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 617 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 618 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 619 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 620 package·--add=aide
622 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*621 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
623 Run·the·following·command·to·generate·a·new·database:622 Run·the·following·command·to·generate·a·new·database:
624 $·sudo·/usr/sbin/aide·--init623 $·sudo·/usr/sbin/aide·--init
625 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:624 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
626 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz625 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
627 To·initiate·a·manual·check,·run·the·following·command:626 To·initiate·a·manual·check,·run·the·following·command:
628 $·sudo·/usr/sbin/aide·--check627 $·sudo·/usr/sbin/aide·--check
Offset 1502, 21 lines modifiedOffset 1502, 14 lines modified
1502 ··-·NIST-800-53-SC-131502 ··-·NIST-800-53-SC-13
1503 ··-·enable_strategy1503 ··-·enable_strategy
1504 ··-·low_complexity1504 ··-·low_complexity
1505 ··-·low_disruption1505 ··-·low_disruption
1506 ··-·medium_severity1506 ··-·medium_severity
1507 ··-·no_reboot_needed1507 ··-·no_reboot_needed
1508 ··-·package_dracut-fips_installed1508 ··-·package_dracut-fips_installed
1509 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
1510 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
1511 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
1512 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
1513 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
1514 package·--add=dracut-fips 
1515 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81509 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
1516 [[packages]]1510 [[packages]]
1517 name·=·"dracut-fips"1511 name·=·"dracut-fips"
1518 version·=·"*"1512 version·=·"*"
1519 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81513 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1520 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1514 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 1541, 14 lines modifiedOffset 1534, 21 lines modified
1541 if·!·rpm·-q·--quiet·"dracut-fips"·;·then1534 if·!·rpm·-q·--quiet·"dracut-fips"·;·then
1542 ····yum·install·-y·"dracut-fips"1535 ····yum·install·-y·"dracut-fips"
1543 fi1536 fi
  
1544 else1537 else
1545 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'1538 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
1546 fi1539 fi
 1540 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 1541 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1542 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1543 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1544 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 1545 package·--add=dracut-fips
1547 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8de\x8e·i\x8in\x8n·G\x8GR\x8RU\x8UB\x8B2\x82·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*1546 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8de\x8e·i\x8in\x8n·G\x8GR\x8RU\x8UB\x8B2\x82·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
1548 To·ensure·FIPS·mode·is·enabled,·install·package·dracut-fips,·and·rebuild·initramfs·by·running·the·following·commands:1547 To·ensure·FIPS·mode·is·enabled,·install·package·dracut-fips,·and·rebuild·initramfs·by·running·the·following·commands:
1549 $·sudo·yum·install·dracut-fips1548 $·sudo·yum·install·dracut-fips
1550 dracut·-f1549 dracut·-f
1551 After·the·dracut·command·has·been·run,·add·the·argument·fips=1·to·the·default·GRUB·2·command·line·for·the·Linux·operating·system·in·/etc/default/grub,·in·the·manner·below:1550 After·the·dracut·command·has·been·run,·add·the·argument·fips=1·to·the·default·GRUB·2·command·line·for·the·Linux·operating·system·in·/etc/default/grub,·in·the·manner·below:
1552 GRUB_CMDLINE_LINUX="crashkernel=auto·rd.lvm.lv=VolGroup/LogVol06·rd.lvm.lv=VolGroup/lv_swap·rhgb·quiet·rd.shell=0·fips=1"1551 GRUB_CMDLINE_LINUX="crashkernel=auto·rd.lvm.lv=VolGroup/LogVol06·rd.lvm.lv=VolGroup/lv_swap·rhgb·quiet·rd.shell=0·fips=1"
1553 Finally,·rebuild·the·grub.cfg·file·by·using·the1552 Finally,·rebuild·the·grub.cfg·file·by·using·the
Offset 2004, 17 lines modifiedOffset 2004, 14 lines modified
2004 ··-·NIST-800-53-SC-132004 ··-·NIST-800-53-SC-13
2005 ··-·grub2_enable_fips_mode2005 ··-·grub2_enable_fips_mode
2006 ··-·high_complexity2006 ··-·high_complexity
2007 ··-·high_severity2007 ··-·high_severity
2008 ··-·medium_disruption2008 ··-·medium_disruption
2009 ··-·reboot_required2009 ··-·reboot_required
2010 ··-·restrict_strategy2010 ··-·restrict_strategy
2011 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
2012 package·--add=dracut-fips·--add=dracut-fips-aesni 
2013 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x82011 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
2014 #·Remediation·is·applicable·only·in·certain·platforms2012 #·Remediation·is·applicable·only·in·certain·platforms
2015 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek·)·&&·{·rpm·--quiet·-q·grub2-common;·};·then2013 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek·)·&&·{·rpm·--quiet·-q·grub2-common;·};·then
  
2016 #·prelink·not·installed2014 #·prelink·not·installed
2017 if·test·-e·/etc/sysconfig/prelink·-o·-e·/usr/sbin/prelink;·then2015 if·test·-e·/etc/sysconfig/prelink·-o·-e·/usr/sbin/prelink;·then
2018 ····if·grep·-q·^PRELINKING·/etc/sysconfig/prelink2016 ····if·grep·-q·^PRELINKING·/etc/sysconfig/prelink
Offset 2073, 14 lines modifiedOffset 2070, 17 lines modified
2073 »       #·Correct·the·form·of·kernel·command·line·for·each·installed·kernel·in·the·bootloader2070 »       #·Correct·the·form·of·kernel·command·line·for·each·installed·kernel·in·the·bootloader
2074 »       /sbin/grubby·--update-kernel=ALL·--args="fips=1·boot=UUID=${BOOT_UUID}"2071 »       /sbin/grubby·--update-kernel=ALL·--args="fips=1·boot=UUID=${BOOT_UUID}"
2075 fi2072 fi
  
2076 else2073 else
2077 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'2074 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
2078 fi2075 fi
 2076 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 2077 package·--add=dracut-fips·--add=dracut-fips-aesni
2079 Group  ·Operating·System·Vendor·Support·and·Certification·  Group·contains·1·rule2078 Group  ·Operating·System·Vendor·Support·and·Certification·  Group·contains·1·rule
2080 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·assurance·of·a·vendor·to·provide·operating·system·support·and·maintenance·for·their·product·is·an·important·criterion·to·ensure·product·stability·and·security·over·the·life·of·the·product.·A·certified·product·that·follows·the·necessary·standards·and·government·certification·requirements·guarantees·that·known·software·vulnerabilities·will·be·remediated,·and·proper·guidance·for·protecting·and·securing·the·operating·system·will·be·given.2079 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·assurance·of·a·vendor·to·provide·operating·system·support·and·maintenance·for·their·product·is·an·important·criterion·to·ensure·product·stability·and·security·over·the·life·of·the·product.·A·certified·product·that·follows·the·necessary·standards·and·government·certification·requirements·guarantees·that·known·software·vulnerabilities·will·be·remediated,·and·proper·guidance·for·protecting·and·securing·the·operating·system·will·be·given.
2081 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·T\x8Th\x8he\x8e·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8le\x8ed\x8d·O\x8Op\x8pe\x8er\x8ra\x8at\x8ti\x8in\x8ng\x8g·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·I\x8Is\x8s·V\x8Ve\x8en\x8nd\x8do\x8or\x8r·S\x8Su\x8up\x8pp\x8po\x8or\x8rt\x8te\x8ed\x8d·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*2080 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·T\x8Th\x8he\x8e·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8le\x8ed\x8d·O\x8Op\x8pe\x8er\x8ra\x8at\x8ti\x8in\x8ng\x8g·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·I\x8Is\x8s·V\x8Ve\x8en\x8nd\x8do\x8or\x8r·S\x8Su\x8up\x8pp\x8po\x8or\x8rt\x8te\x8ed\x8d·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
2082 The·installed·operating·system·must·be·maintained·by·a·vendor.·Oracle·Linux·is·supported·by·Oracle·Corporation.·As·the·Oracle·Linux·vendor,·Oracle·Corporation·is·responsible·for·providing·security·patches.2081 The·installed·operating·system·must·be·maintained·by·a·vendor.·Oracle·Linux·is·supported·by·Oracle·Corporation.·As·the·Oracle·Linux·vendor,·Oracle·Corporation·is·responsible·for·providing·security·patches.
2083 Warning: ·There·is·no·remediation·besides·switching·to·a·different·operating·system.2082 Warning: ·There·is·no·remediation·besides·switching·to·a·different·operating·system.
2084 Rationale:··An·operating·system·is·considered·"supported"·if·the·vendor·continues·to·provide·security·patches·for·the·product.·With·an·unsupported·release,·it·will·not·be·possible·to·resolve·any·security·issue·discovered·in·the·system·software.2083 Rationale:··An·operating·system·is·considered·"supported"·if·the·vendor·continues·to·provide·security·patches·for·the·product.·With·an·unsupported·release,·it·will·not·be·possible·to·resolve·any·security·issue·discovered·in·the·system·software.
2085 Severity: ··high2084 Severity: ··high
Offset 17325, 21 lines modifiedOffset 17325, 14 lines modified
17325 ··-·NIST-800-53-CM-6(a)17325 ··-·NIST-800-53-CM-6(a)
17326 ··-·enable_strategy17326 ··-·enable_strategy
17327 ··-·low_complexity17327 ··-·low_complexity
Max diff block lines reached; 46020/52367 bytes (87.88%) of diff not shown.
351 KB
./usr/share/doc/ssg-nondebian/ssg-ol7-guide-ospp.html
    
Offset 15141, 151 lines modifiedOffset 15141, 151 lines modified
0003b240:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target0003b240:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
0003b250:·3d22·2369·646d·3631·3834·2220·7461·6269··="#idm6184"·tabi0003b250:·3d22·2369·646d·3631·3834·2220·7461·6269··="#idm6184"·tabi
0003b260:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b0003b260:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
0003b270:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa0003b270:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
0003b280:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit0003b280:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
0003b290:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·0003b290:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
0003b2a0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!0003b2a0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
0003b2b0:·223e·5265·6d65·6469·6174·696f·6e20·416e··">Remediation·An0003b2b0:·223e·5265·6d65·6469·6174·696f·6e20·4f53··">Remediation·OS
0003b2c0:·6163·6f6e·6461·2073·6e69·7070·6574·20e2··aconda·snippet·. 
0003b2d0:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c 
0003b2e0:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll0003b2c0:·4275·696c·6420·426c·7565·7072·696e·7420··Build·Blueprint·
 0003b2d0:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><
 0003b2e0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
0003b2f0:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i0003b2f0:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
 0003b300:·6c6c·6170·7365·2220·6964·3d22·6964·6d36··llapse"·id="idm6
 0003b310:·3138·3422·3e3c·7072·653e·3c63·6f64·653e··184"><pre><code>
 0003b320:·0a5b·5b70·6163·6b61·6765·735d·5d0a·6e61··.[[packages]].na
 0003b330:·6d65·203d·2022·6472·6163·7574·2d66·6970··me·=·"dracut-fip
 0003b340:·7322·0a76·6572·7369·6f6e·203d·2022·2a22··s".version·=·"*"
0003b300:·643d·2269·646d·3631·3834·223e·3c74·6162··d="idm6184"><tab 
0003b310:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table· 
0003b320:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta 
0003b330:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab 
0003b340:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t 
0003b350:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity 
0003b360:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t 
0003b370:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D 
0003b380:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th>< 
0003b390:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
0003b3a0:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:< 
0003b3b0:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t 
0003b3c0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S 
0003b3d0:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td 
0003b3e0:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr 
0003b3f0:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c 
0003b400:·6f64·653e·0a70·6163·6b61·6765·202d·2d61··ode>.package·--a 
0003b410:·6464·3d64·7261·6375·742d·6669·7073·0a3c··dd=dracut-fips.< 
0003b420:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di0003b350:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></
0003b430:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn·0003b360:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt
0003b440:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat0003b370:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d
0003b450:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap0003b380:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll
0003b460:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=0003b390:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
0003b470:·2223·6964·6d36·3138·3522·2074·6162·696e··"#idm6185"·tabin0003b3a0:·743d·2223·6964·6d36·3138·3522·2074·6162··t="#idm6185"·tab
0003b480:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu0003b3b0:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
0003b490:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan0003b3c0:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
0003b4a0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl0003b3d0:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
0003b4b0:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r0003b3e0:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
0003b4c0:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"0003b3f0:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
0003b4d0:·3e52·656d·6564·6961·7469·6f6e·204f·5342··>Remediation·OSB0003b400:·2122·3e52·656d·6564·6961·7469·6f6e·2050··!">Remediation·P
0003b4e0:·7569·6c64·2042·6c75·6570·7269·6e74·2073··uild·Blueprint·s 
0003b4f0:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b 
0003b500:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa 
0003b510:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col 
0003b520:·6c61·7073·6522·2069·643d·2269·646d·3631··lapse"·id="idm61 
0003b530:·3835·223e·3c70·7265·3e3c·636f·6465·3e0a··85"><pre><code>. 
0003b540:·5b5b·7061·636b·6167·6573·5d5d·0a6e·616d··[[packages]].nam0003b410:·7570·7065·7420·736e·6970·7065·7420·e287··uppet·snippet·..
 0003b420:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl
 0003b430:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla
 0003b440:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id
 0003b450:·3d22·6964·6d36·3138·3522·3e3c·7461·626c··="idm6185"><tabl
 0003b460:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t
 0003b470:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab
 0003b480:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl
 0003b490:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr
 0003b4a0:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:
 0003b4b0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
 0003b4c0:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di
 0003b4d0:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t
 0003b4e0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
 0003b4f0:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</
 0003b500:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td
 0003b510:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St
 0003b520:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>
 0003b530:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr>
 0003b540:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co
 0003b550:·6465·3e69·6e63·6c75·6465·2069·6e73·7461··de>include·insta
0003b550:·6520·3d20·2264·7261·6375·742d·6669·7073··e·=·"dracut-fips0003b560:·6c6c·5f64·7261·6375·742d·6669·7073·0a0a··ll_dracut-fips..
0003b560:·220a·7665·7273·696f·6e20·3d20·222a·220a··".version·=·"*". 
0003b570:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d 
0003b580:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn 
0003b590:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da 
0003b5a0:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla 
0003b5b0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target 
0003b5c0:·3d22·2369·646d·3631·3836·2220·7461·6269··="#idm6186"·tabi 
0003b5d0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b 
0003b5e0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa 
0003b5f0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit 
0003b600:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to· 
0003b610:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#! 
0003b620:·223e·5265·6d65·6469·6174·696f·6e20·5075··">Remediation·Pu 
0003b630:·7070·6574·2073·6e69·7070·6574·20e2·87b2··ppet·snippet·... 
0003b640:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla 
0003b650:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap 
0003b660:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id= 
0003b670:·2269·646d·3631·3836·223e·3c74·6162·6c65··"idm6186"><table 
0003b680:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta 
0003b690:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl 
0003b6a0:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table 
0003b6b0:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr> 
0003b6c0:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:< 
0003b6d0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td> 
0003b6e0:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis 
0003b6f0:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td0003b570:·636c·6173·7320·696e·7374·616c·6c5f·6472··class·install_dr
 0003b580:·6163·7574·2d66·6970·7320·7b0a·2020·7061··acut-fips·{.··pa
 0003b590:·636b·6167·6520·7b20·2764·7261·6375·742d··ckage·{·'dracut-
 0003b5a0:·6669·7073·273a·0a20·2020·2065·6e73·7572··fips':.····ensur
 0003b5b0:·6520·3d26·6774·3b20·2769·6e73·7461·6c6c··e·=&gt;·'install
 0003b5c0:·6564·272c·0a20·207d·0a7d·0a3c·2f63·6f64··ed',.··}.}.</cod
 0003b5d0:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a
 0003b5e0:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn-
 0003b5f0:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to
 0003b600:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"·
 0003b610:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
 0003b620:·6d36·3138·3622·2074·6162·696e·6465·783d··m6186"·tabindex=
 0003b630:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button
 0003b640:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=
 0003b650:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A
 0003b660:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea
 0003b670:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem
 0003b680:·6564·6961·7469·6f6e·2053·6865·6c6c·2073··ediation·Shell·s
 0003b690:·6372·6970·7420·e287·b23c·2f61·3e3c·6272··cript·...</a><br
 0003b6a0:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
 0003b6b0:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
 0003b6c0:·6170·7365·2220·6964·3d22·6964·6d36·3138··apse"·id="idm618
 0003b6d0:·3622·3e3c·7461·626c·6520·636c·6173·733d··6"><table·class=
 0003b6e0:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str
 0003b6f0:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde
Max diff block lines reached; 311248/330734 bytes (94.11%) of diff not shown.
27.6 KB
html2text {}
    
Offset 139, 21 lines modifiedOffset 139, 14 lines modified
139 ··-·NIST-800-53-SC-13139 ··-·NIST-800-53-SC-13
140 ··-·enable_strategy140 ··-·enable_strategy
141 ··-·low_complexity141 ··-·low_complexity
142 ··-·low_disruption142 ··-·low_disruption
143 ··-·medium_severity143 ··-·medium_severity
144 ··-·no_reboot_needed144 ··-·no_reboot_needed
145 ··-·package_dracut-fips_installed145 ··-·package_dracut-fips_installed
146 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
147 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
148 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
149 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
150 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
151 package·--add=dracut-fips 
152 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8146 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
153 [[packages]]147 [[packages]]
154 name·=·"dracut-fips"148 name·=·"dracut-fips"
155 version·=·"*"149 version·=·"*"
156 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8150 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
157 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low151 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 178, 14 lines modifiedOffset 171, 21 lines modified
178 if·!·rpm·-q·--quiet·"dracut-fips"·;·then171 if·!·rpm·-q·--quiet·"dracut-fips"·;·then
179 ····yum·install·-y·"dracut-fips"172 ····yum·install·-y·"dracut-fips"
180 fi173 fi
  
181 else174 else
182 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'175 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
183 fi176 fi
 177 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 178 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 179 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 180 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 181 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 182 package·--add=dracut-fips
184 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8de\x8e·i\x8in\x8n·G\x8GR\x8RU\x8UB\x8B2\x82·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*183 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8de\x8e·i\x8in\x8n·G\x8GR\x8RU\x8UB\x8B2\x82·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
185 To·ensure·FIPS·mode·is·enabled,·install·package·dracut-fips,·and·rebuild·initramfs·by·running·the·following·commands:184 To·ensure·FIPS·mode·is·enabled,·install·package·dracut-fips,·and·rebuild·initramfs·by·running·the·following·commands:
186 $·sudo·yum·install·dracut-fips185 $·sudo·yum·install·dracut-fips
187 dracut·-f186 dracut·-f
188 After·the·dracut·command·has·been·run,·add·the·argument·fips=1·to·the·default·GRUB·2·command·line·for·the·Linux·operating·system·in·/etc/default/grub,·in·the·manner·below:187 After·the·dracut·command·has·been·run,·add·the·argument·fips=1·to·the·default·GRUB·2·command·line·for·the·Linux·operating·system·in·/etc/default/grub,·in·the·manner·below:
189 GRUB_CMDLINE_LINUX="crashkernel=auto·rd.lvm.lv=VolGroup/LogVol06·rd.lvm.lv=VolGroup/lv_swap·rhgb·quiet·rd.shell=0·fips=1"188 GRUB_CMDLINE_LINUX="crashkernel=auto·rd.lvm.lv=VolGroup/LogVol06·rd.lvm.lv=VolGroup/lv_swap·rhgb·quiet·rd.shell=0·fips=1"
190 Finally,·rebuild·the·grub.cfg·file·by·using·the189 Finally,·rebuild·the·grub.cfg·file·by·using·the
Offset 641, 17 lines modifiedOffset 641, 14 lines modified
641 ··-·NIST-800-53-SC-13641 ··-·NIST-800-53-SC-13
642 ··-·grub2_enable_fips_mode642 ··-·grub2_enable_fips_mode
643 ··-·high_complexity643 ··-·high_complexity
644 ··-·high_severity644 ··-·high_severity
645 ··-·medium_disruption645 ··-·medium_disruption
646 ··-·reboot_required646 ··-·reboot_required
647 ··-·restrict_strategy647 ··-·restrict_strategy
648 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
649 package·--add=dracut-fips·--add=dracut-fips-aesni 
650 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8648 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
651 #·Remediation·is·applicable·only·in·certain·platforms649 #·Remediation·is·applicable·only·in·certain·platforms
652 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek·)·&&·{·rpm·--quiet·-q·grub2-common;·};·then650 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek·)·&&·{·rpm·--quiet·-q·grub2-common;·};·then
  
653 #·prelink·not·installed651 #·prelink·not·installed
654 if·test·-e·/etc/sysconfig/prelink·-o·-e·/usr/sbin/prelink;·then652 if·test·-e·/etc/sysconfig/prelink·-o·-e·/usr/sbin/prelink;·then
655 ····if·grep·-q·^PRELINKING·/etc/sysconfig/prelink653 ····if·grep·-q·^PRELINKING·/etc/sysconfig/prelink
Offset 710, 14 lines modifiedOffset 707, 17 lines modified
710 »       #·Correct·the·form·of·kernel·command·line·for·each·installed·kernel·in·the·bootloader707 »       #·Correct·the·form·of·kernel·command·line·for·each·installed·kernel·in·the·bootloader
711 »       /sbin/grubby·--update-kernel=ALL·--args="fips=1·boot=UUID=${BOOT_UUID}"708 »       /sbin/grubby·--update-kernel=ALL·--args="fips=1·boot=UUID=${BOOT_UUID}"
712 fi709 fi
  
713 else710 else
714 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'711 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
715 fi712 fi
 713 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 714 package·--add=dracut-fips·--add=dracut-fips-aesni
716 Group  ·Updating·Software·  Group·contains·4·rules715 Group  ·Updating·Software·  Group·contains·4·rules
717 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·yum·command·line·tool·is·used·to·install·and·update·software·packages.·The·system·also·provides·a·graphical·software·update·tool·in·the·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·menu,·in·the·A\x8Ad\x8dm\x8mi\x8in\x8ni\x8is\x8st\x8tr\x8ra\x8at\x8ti\x8io\x8on\x8n·submenu,·called·S\x8So\x8of\x8ft\x8tw\x8wa\x8ar\x8re\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8e.716 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·yum·command·line·tool·is·used·to·install·and·update·software·packages.·The·system·also·provides·a·graphical·software·update·tool·in·the·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·menu,·in·the·A\x8Ad\x8dm\x8mi\x8in\x8ni\x8is\x8st\x8tr\x8ra\x8at\x8ti\x8io\x8on\x8n·submenu,·called·S\x8So\x8of\x8ft\x8tw\x8wa\x8ar\x8re\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8e.
  
718 Oracle·Linux·7·systems·contain·an·installed·software·catalog·called·the·RPM·database,·which·records·metadata·of·installed·packages.·Consistently·using·yum·or·the·graphical·S\x8So\x8of\x8ft\x8tw\x8wa\x8ar\x8re\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8e·for·all·software·installation·allows·for·insight·into·the·current·inventory·of·installed·software·on·the·system.717 Oracle·Linux·7·systems·contain·an·installed·software·catalog·called·the·RPM·database,·which·records·metadata·of·installed·packages.·Consistently·using·yum·or·the·graphical·S\x8So\x8of\x8ft\x8tw\x8wa\x8ar\x8re\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8e·for·all·software·installation·allows·for·insight·into·the·current·inventory·of·installed·software·on·the·system.
  
719 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·g\x8gp\x8pg\x8gc\x8ch\x8he\x8ec\x8ck\x8k·E\x8En\x8na\x8ab\x8bl\x8le\x8ed\x8d·I\x8In\x8n·M\x8Ma\x8ai\x8in\x8n·y\x8yu\x8um\x8m·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8ra\x8at\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*718 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·g\x8gp\x8pg\x8gc\x8ch\x8he\x8ec\x8ck\x8k·E\x8En\x8na\x8ab\x8bl\x8le\x8ed\x8d·I\x8In\x8n·M\x8Ma\x8ai\x8in\x8n·y\x8yu\x8um\x8m·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8ra\x8at\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
720 The·gpgcheck·option·controls·whether·RPM·packages'·signatures·are·always·checked·prior·to·installation.·To·configure·yum·to·check·package·signatures·before·installing·them,·ensure·the·following·line·appears·in·/etc/yum.conf·in·the·[main]·section:719 The·gpgcheck·option·controls·whether·RPM·packages'·signatures·are·always·checked·prior·to·installation.·To·configure·yum·to·check·package·signatures·before·installing·them,·ensure·the·following·line·appears·in·/etc/yum.conf·in·the·[main]·section:
Offset 7990, 21 lines modifiedOffset 7990, 14 lines modified
7990 ··-·NIST-800-53-CM-6(a)7990 ··-·NIST-800-53-CM-6(a)
7991 ··-·enable_strategy7991 ··-·enable_strategy
7992 ··-·low_complexity7992 ··-·low_complexity
7993 ··-·low_disruption7993 ··-·low_disruption
7994 ··-·medium_severity7994 ··-·medium_severity
7995 ··-·no_reboot_needed7995 ··-·no_reboot_needed
7996 ··-·package_screen_installed7996 ··-·package_screen_installed
7997 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
7998 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
7999 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
8000 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
8001 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
8002 package·--add=screen 
8003 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x87997 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
8004 [[packages]]7998 [[packages]]
8005 name·=·"screen"7999 name·=·"screen"
8006 version·=·"*"8000 version·=·"*"
8007 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x88001 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
8008 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low8002 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 8029, 14 lines modifiedOffset 8022, 21 lines modified
8029 if·!·rpm·-q·--quiet·"screen"·;·then8022 if·!·rpm·-q·--quiet·"screen"·;·then
8030 ····yum·install·-y·"screen"8023 ····yum·install·-y·"screen"
8031 fi8024 fi
  
8032 else8025 else
8033 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'8026 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
8034 fi8027 fi
 8028 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 8029 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 8030 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 8031 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 8032 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 8033 package·--add=screen
8035 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·D\x8Di\x8is\x8sa\x8ab\x8bl\x8le\x8e·d\x8de\x8eb\x8bu\x8ug\x8g-\x8-s\x8sh\x8he\x8el\x8ll\x8l·S\x8Sy\x8ys\x8st\x8te\x8em\x8mD\x8D·S\x8Se\x8er\x8rv\x8vi\x8ic\x8ce\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*8034 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·D\x8Di\x8is\x8sa\x8ab\x8bl\x8le\x8e·d\x8de\x8eb\x8bu\x8ug\x8g-\x8-s\x8sh\x8he\x8el\x8ll\x8l·S\x8Sy\x8ys\x8st\x8te\x8em\x8mD\x8D·S\x8Se\x8er\x8rv\x8vi\x8ic\x8ce\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
8036 SystemD's·debug-shell·service·is·intended·to·diagnose·SystemD·related·boot·issues·with·various·systemctl·commands.·Once·enabled·and·following·a·system·reboot,·the·root·shell·will·be·available·on·tty9·which·is·access·by·pressing·CTRL-ALT-F9.·The·debug-shell·service·should·only·be·used·for·SystemD·related·issues·and·should·otherwise·be·disabled.8035 SystemD's·debug-shell·service·is·intended·to·diagnose·SystemD·related·boot·issues·with·various·systemctl·commands.·Once·enabled·and·following·a·system·reboot,·the·root·shell·will·be·available·on·tty9·which·is·access·by·pressing·CTRL-ALT-F9.·The·debug-shell·service·should·only·be·used·for·SystemD·related·issues·and·should·otherwise·be·disabled.
  
8037 By·default,·the·debug-shell·SystemD·service·is·already·disabled.·The·debug-shell·service·can·be·disabled·with·the·following·command:8036 By·default,·the·debug-shell·SystemD·service·is·already·disabled.·The·debug-shell·service·can·be·disabled·with·the·following·command:
8038 $·sudo·systemctl·mask·--now·debug-shell.service8037 $·sudo·systemctl·mask·--now·debug-shell.service
8039 Rationale:··This·prevents·attackers·with·physical·access·from·trivially·bypassing·security·on·the·machine·through·valid·troubleshooting·configurations·and·gaining·root·access·when·the·system·is·rebooted.8038 Rationale:··This·prevents·attackers·with·physical·access·from·trivially·bypassing·security·on·the·machine·through·valid·troubleshooting·configurations·and·gaining·root·access·when·the·system·is·rebooted.
8040 Severity: ··medium8039 Severity: ··medium
Offset 15915, 21 lines modifiedOffset 15915, 14 lines modified
15915 ··tags:15915 ··tags:
15916 ··-·configure_strategy15916 ··-·configure_strategy
15917 ··-·high_disruption15917 ··-·high_disruption
Max diff block lines reached; 21887/28236 bytes (77.51%) of diff not shown.
103 KB
./usr/share/doc/ssg-nondebian/ssg-ol7-guide-pci-dss.html
    
Offset 16706, 144 lines modifiedOffset 16706, 144 lines modified
00041410:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target00041410:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
00041420:·3d22·2369·646d·3536·3532·2220·7461·6269··="#idm5652"·tabi00041420:·3d22·2369·646d·3536·3532·2220·7461·6269··="#idm5652"·tabi
00041430:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b00041430:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
00041440:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa00041440:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
00041450:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit00041450:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
00041460:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·00041460:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
00041470:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!00041470:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
 00041480:·223e·5265·6d65·6469·6174·696f·6e20·4f53··">Remediation·OS
 00041490:·4275·696c·6420·426c·7565·7072·696e·7420··Build·Blueprint·
 000414a0:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><
 000414b0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
 000414c0:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
 000414d0:·6c6c·6170·7365·2220·6964·3d22·6964·6d35··llapse"·id="idm5
 000414e0:·3635·3222·3e3c·7072·653e·3c63·6f64·653e··652"><pre><code>
 000414f0:·0a5b·5b70·6163·6b61·6765·735d·5d0a·6e61··.[[packages]].na
 00041500:·6d65·203d·2022·6169·6465·220a·7665·7273··me·=·"aide".vers
 00041510:·696f·6e20·3d20·222a·220a·3c2f·636f·6465··ion·=·"*".</code
 00041520:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a·
 00041530:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s
 00041540:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog
 00041550:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d
 00041560:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
 00041570:·3536·3533·2220·7461·6269·6e64·6578·3d22··5653"·tabindex="
 00041580:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
 00041590:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
 000415a0:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
 000415b0:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
 000415c0:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
 000415d0:·6469·6174·696f·6e20·5075·7070·6574·2073··diation·Puppet·s
 000415e0:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b
 000415f0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
 00041600:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
 00041610:·6c61·7073·6522·2069·643d·2269·646d·3536··lapse"·id="idm56
 00041620:·3533·223e·3c74·6162·6c65·2063·6c61·7373··53"><table·class
 00041630:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st
 00041640:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord
 00041650:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde
 00041660:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co
 00041670:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t
 00041680:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
 00041690:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio
 000416a0:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</
 000416b0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 000416c0:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td>
 000416d0:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr><
 000416e0:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:
 000416f0:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<
 00041700:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table
 00041710:·3e3c·7072·653e·3c63·6f64·653e·696e·636c··><pre><code>incl
 00041720:·7564·6520·696e·7374·616c·6c5f·6169·6465··ude·install_aide
 00041730:·0a0a·636c·6173·7320·696e·7374·616c·6c5f··..class·install_
 00041740:·6169·6465·207b·0a20·2070·6163·6b61·6765··aide·{.··package
 00041750:·207b·2027·6169·6465·273a·0a20·2020·2065···{·'aide':.····e
 00041760:·6e73·7572·6520·3d26·6774·3b20·2769·6e73··nsure·=&gt;·'ins
 00041770:·7461·6c6c·6564·272c·0a20·207d·0a7d·0a3c··talled',.··}.}.<
 00041780:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di
 00041790:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn·
 000417a0:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat
 000417b0:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap
 000417c0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
 000417d0:·2223·6964·6d35·3635·3422·2074·6162·696e··"#idm5654"·tabin
 000417e0:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
 000417f0:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
 00041800:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
 00041810:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
 00041820:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
 00041830:·3e52·656d·6564·6961·7469·6f6e·2053·6865··>Remediation·She
 00041840:·6c6c·2073·6372·6970·7420·e287·b23c·2f61··ll·script·...</a
 00041850:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
 00041860:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
 00041870:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
 00041880:·6d35·3635·3422·3e3c·7461·626c·6520·636c··m5654"><table·cl
 00041890:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table
 000418a0:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b
 000418b0:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co
 000418c0:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th
 000418d0:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th
 000418e0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
 000418f0:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup
 00041900:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo
 00041910:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
 00041920:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th><
 00041930:·7464·3e66·616c·7365·3c2f·7464·3e3c·2f74··td>false</td></t
 00041940:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate
 00041950:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab
 00041960:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta
 00041970:·626c·653e·3c70·7265·3e3c·636f·6465·3e23··ble><pre><code>#
 00041980:·2052·656d·6564·6961·7469·6f6e·2069·7320···Remediation·is·
 00041990:·6170·706c·6963·6162·6c65·206f·6e6c·7920··applicable·only·
 000419a0:·696e·2063·6572·7461·696e·2070·6c61·7466··in·certain·platf
 000419b0:·6f72·6d73·0a69·6620·7270·6d20·2d2d·7175··orms.if·rpm·--qu
 000419c0:·6965·7420·2d71·206b·6572·6e65·6c20·7c7c··iet·-q·kernel·||
 000419d0:·2072·706d·202d·2d71·7569·6574·202d·7120···rpm·--quiet·-q·
 000419e0:·6b65·726e·656c·2d75·656b·3b20·7468·656e··kernel-uek;·then
 000419f0:·0a0a·6966·2021·2072·706d·202d·7120·2d2d··..if·!·rpm·-q·--
 00041a00:·7175·6965·7420·2261·6964·6522·203b·2074··quiet·"aide"·;·t
 00041a10:·6865·6e0a·2020·2020·7975·6d20·696e·7374··hen.····yum·inst
 00041a20:·616c·6c20·2d79·2022·6169·6465·220a·6669··all·-y·"aide".fi
 00041a30:·0a0a·656c·7365·0a20·2020·2026·6774·3b26··..else.····&gt;&
 00041a40:·616d·703b·3220·6563·686f·2027·5265·6d65··amp;2·echo·'Reme
 00041a50:·6469·6174·696f·6e20·6973·206e·6f74·2061··diation·is·not·a
 00041a60:·7070·6c69·6361·626c·652c·206e·6f74·6869··pplicable,·nothi
 00041a70:·6e67·2077·6173·2064·6f6e·6527·0a66·690a··ng·was·done'.fi.
 00041a80:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d
 00041a90:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn
 00041aa0:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da
 00041ab0:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla
 00041ac0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
 00041ad0:·3d22·2369·646d·3536·3535·2220·7461·6269··="#idm5655"·tabi
 00041ae0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
 00041af0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
 00041b00:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
 00041b10:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
 00041b20:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
00041480:·223e·5265·6d65·6469·6174·696f·6e20·416e··">Remediation·An00041b30:·223e·5265·6d65·6469·6174·696f·6e20·416e··">Remediation·An
00041490:·6163·6f6e·6461·2073·6e69·7070·6574·20e2··aconda·snippet·.00041b40:·6163·6f6e·6461·2073·6e69·7070·6574·20e2··aconda·snippet·.
000414a0:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c00041b50:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c
000414b0:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll00041b60:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
000414c0:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i00041b70:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
000414d0:·643d·2269·646d·3536·3532·223e·3c74·6162··d="idm5652"><tab00041b80:·643d·2269·646d·3536·3535·223e·3c74·6162··d="idm5655"><tab
000414e0:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·00041b90:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·
000414f0:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta00041ba0:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta
00041500:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab00041bb0:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab
00041510:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t00041bc0:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t
00041520:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity00041bd0:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity
00041530:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t00041be0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
00041540:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D00041bf0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D
Max diff block lines reached; 77916/96436 bytes (80.80%) of diff not shown.
8.83 KB
html2text {}
    
Offset 547, 21 lines modifiedOffset 547, 14 lines modified
547 ··-·PCI-DSSv4-11.5.2547 ··-·PCI-DSSv4-11.5.2
548 ··-·enable_strategy548 ··-·enable_strategy
549 ··-·low_complexity549 ··-·low_complexity
550 ··-·low_disruption550 ··-·low_disruption
551 ··-·medium_severity551 ··-·medium_severity
552 ··-·no_reboot_needed552 ··-·no_reboot_needed
553 ··-·package_aide_installed553 ··-·package_aide_installed
554 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
555 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
556 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
557 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
558 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
559 package·--add=aide 
560 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8554 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
561 [[packages]]555 [[packages]]
562 name·=·"aide"556 name·=·"aide"
563 version·=·"*"557 version·=·"*"
564 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8558 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
565 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low559 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 586, 14 lines modifiedOffset 579, 21 lines modified
586 if·!·rpm·-q·--quiet·"aide"·;·then579 if·!·rpm·-q·--quiet·"aide"·;·then
587 ····yum·install·-y·"aide"580 ····yum·install·-y·"aide"
588 fi581 fi
  
589 else582 else
590 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'583 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
591 fi584 fi
 585 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 586 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 587 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 588 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 589 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 590 package·--add=aide
592 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*591 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
593 Run·the·following·command·to·generate·a·new·database:592 Run·the·following·command·to·generate·a·new·database:
594 $·sudo·/usr/sbin/aide·--init593 $·sudo·/usr/sbin/aide·--init
595 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:594 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
596 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz595 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
597 To·initiate·a·manual·check,·run·the·following·command:596 To·initiate·a·manual·check,·run·the·following·command:
598 $·sudo·/usr/sbin/aide·--check597 $·sudo·/usr/sbin/aide·--check
Offset 8504, 17 lines modifiedOffset 8504, 14 lines modified
8504 References:·_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.18.1.4,·A.7.1.1,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,·A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.38504 References:·_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.18.1.4,·A.7.1.1,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,·A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.3
8505 ············_\x8n_\x8i_\x8s_\x8t···········IA-2(1),·IA-2(2),·IA-2(3),·IA-2(4),·IA-2(6),·IA-2(7),·IA-2(11),·CM-6(a)8505 ············_\x8n_\x8i_\x8s_\x8t···········IA-2(1),·IA-2(2),·IA-2(3),·IA-2(4),·IA-2(6),·IA-2(7),·IA-2(11),·CM-6(a)
8506 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-1,·PR.AC-6,·PR.AC-78506 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-1,·PR.AC-6,·PR.AC-7
8507 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-8.38507 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-8.3
8508 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000104-GPOS-00051,·SRG-OS-000106-GPOS-00053,·SRG-OS-000107-GPOS-00054,·SRG-OS-000108-GPOS-00055,·SRG-OS-000108-GPOS-00057,·SRG-OS-000108-GPOS-00058,·SRG-OS-000109-GPOS-00056,·SRG-OS-000376-GPOS-00161,·SRG-OS-000377-GPOS-001628508 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000104-GPOS-00051,·SRG-OS-000106-GPOS-00053,·SRG-OS-000107-GPOS-00054,·SRG-OS-000108-GPOS-00055,·SRG-OS-000108-GPOS-00057,·SRG-OS-000108-GPOS-00058,·SRG-OS-000109-GPOS-00056,·SRG-OS-000376-GPOS-00161,·SRG-OS-000377-GPOS-00162
8509 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL07-00-0105008509 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL07-00-010500
8510 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-221703r1015186_rule8510 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-221703r1015186_rule
8511 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
8512 package·--add=pam_pkcs11·--add=esc 
8513 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x88511 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
8514 #·Remediation·is·applicable·only·in·certain·platforms8512 #·Remediation·is·applicable·only·in·certain·platforms
8515 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek·&&·{·!·(·grep·-sqE·"^.*\.s390x$"·/proc/sys/kernel/osrelease·||·grep·-sqE·"^s390x$"·/proc/sys/kernel/arch;·);·};·then8513 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek·&&·{·!·(·grep·-sqE·"^.*\.s390x$"·/proc/sys/kernel/osrelease·||·grep·-sqE·"^s390x$"·/proc/sys/kernel/arch;·);·};·then
  
8516 #·Install·required·packages8514 #·Install·required·packages
8517 if·!·rpm·-q·--quiet·"esc"·;·then8515 if·!·rpm·-q·--quiet·"esc"·;·then
8518 ····yum·install·-y·"esc"8516 ····yum·install·-y·"esc"
Offset 8623, 14 lines modifiedOffset 8620, 17 lines modified
8623 #·2)·Then·append·'ocsp_on'·value·setting·to·each·'cert_policy'·key·in·$PAM_PKCS11_CONF·configuration·line,8620 #·2)·Then·append·'ocsp_on'·value·setting·to·each·'cert_policy'·key·in·$PAM_PKCS11_CONF·configuration·line,
8624 #·which·does·not·contain·it·yet8621 #·which·does·not·contain·it·yet
8625 sed·-i·"/ocsp_on/!·s/^[$SP]*cert_policy[$SP]\+=[$SP]\+\(.*\);/\t\tcert_policy·=·\1,·ocsp_on;/"·"$PAM_PKCS11_CONF"8622 sed·-i·"/ocsp_on/!·s/^[$SP]*cert_policy[$SP]\+=[$SP]\+\(.*\);/\t\tcert_policy·=·\1,·ocsp_on;/"·"$PAM_PKCS11_CONF"
  
8626 else8623 else
8627 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'8624 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
8628 fi8625 fi
 8626 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 8627 package·--add=pam_pkcs11·--add=esc
8629 Group  ·Protect·Accounts·by·Restricting·Password-Based·Login·  Group·contains·3·groups·and·6·rules8628 Group  ·Protect·Accounts·by·Restricting·Password-Based·Login·  Group·contains·3·groups·and·6·rules
8630 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Conventionally,·Unix·shell·accounts·are·accessed·by·providing·a·username·and·password·to·a·login·program,·which·tests·these·values·for·correctness·using·the·/etc/passwd·and·/etc/shadow·files.·Password-based·login·is·vulnerable·to·guessing·of·weak·passwords,·and·to·sniffing·and·man-in-the-middle·attacks·against·passwords·entered·over·a·network·or·at·an·insecure·console.·Therefore,·mechanisms·for·accessing·accounts·by·entering·usernames·and·passwords·should·be·restricted·to·those·which·are·operationally·necessary.8629 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Conventionally,·Unix·shell·accounts·are·accessed·by·providing·a·username·and·password·to·a·login·program,·which·tests·these·values·for·correctness·using·the·/etc/passwd·and·/etc/shadow·files.·Password-based·login·is·vulnerable·to·guessing·of·weak·passwords,·and·to·sniffing·and·man-in-the-middle·attacks·against·passwords·entered·over·a·network·or·at·an·insecure·console.·Therefore,·mechanisms·for·accessing·accounts·by·entering·usernames·and·passwords·should·be·restricted·to·those·which·are·operationally·necessary.
8631 Group  ·Set·Account·Expiration·Parameters·  Group·contains·2·rules8630 Group  ·Set·Account·Expiration·Parameters·  Group·contains·2·rules
8632 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Accounts·can·be·configured·to·be·automatically·disabled·after·a·certain·time·period,·meaning·that·they·will·require·administrator·interaction·to·become·usable·again.·Expiration·of·accounts·after·inactivity·can·be·set·for·all·accounts·by·default·and·also·on·a·per-account·basis,·such·as·for·accounts·that·are·known·to·be·temporary.·To·configure·automatic·expiration·of·an·account·following·the·expiration·of·its·password·(that·is,·after·the·password·has·expired·and·not·been·changed),·run·the·following·command,·substituting·NUM_DAYS·and·USER·appropriately:8631 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Accounts·can·be·configured·to·be·automatically·disabled·after·a·certain·time·period,·meaning·that·they·will·require·administrator·interaction·to·become·usable·again.·Expiration·of·accounts·after·inactivity·can·be·set·for·all·accounts·by·default·and·also·on·a·per-account·basis,·such·as·for·accounts·that·are·known·to·be·temporary.·To·configure·automatic·expiration·of·an·account·following·the·expiration·of·its·password·(that·is,·after·the·password·has·expired·and·not·been·changed),·run·the·following·command,·substituting·NUM_DAYS·and·USER·appropriately:
8633 $·sudo·chage·-I·NUM_DAYS·USER8632 $·sudo·chage·-I·NUM_DAYS·USER
8634 Accounts,·such·as·temporary·accounts,·can·also·be·configured·to·expire·on·an·explicitly-set·date·with·the·-E·option.·The·file·/etc/default/useradd·controls·default·settings·for·all·newly-created·accounts·created·with·the·system's·normal·command·line·utilities.8633 Accounts,·such·as·temporary·accounts,·can·also·be·configured·to·expire·on·an·explicitly-set·date·with·the·-E·option.·The·file·/etc/default/useradd·controls·default·settings·for·all·newly-created·accounts·created·with·the·system's·normal·command·line·utilities.
8635 Warning: ·This·will·only·apply·to·newly·created·accounts8634 Warning: ·This·will·only·apply·to·newly·created·accounts
Offset 10830, 21 lines modifiedOffset 10830, 14 lines modified
10830 ··-·PCI-DSS-Req-4.110830 ··-·PCI-DSS-Req-4.1
10831 ··-·enable_strategy10831 ··-·enable_strategy
10832 ··-·low_complexity10832 ··-·low_complexity
10833 ··-·low_disruption10833 ··-·low_disruption
10834 ··-·medium_severity10834 ··-·medium_severity
10835 ··-·no_reboot_needed10835 ··-·no_reboot_needed
10836 ··-·package_libreswan_installed10836 ··-·package_libreswan_installed
10837 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
10838 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
10839 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
10840 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
10841 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
10842 package·--add=libreswan 
10843 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x810837 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
10844 [[packages]]10838 [[packages]]
10845 name·=·"libreswan"10839 name·=·"libreswan"
10846 version·=·"*"10840 version·=·"*"
10847 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x810841 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
10848 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low10842 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 10863, 14 lines modifiedOffset 10856, 21 lines modified
10863 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low10856 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
10864 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false10857 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
10865 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable10858 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
10866 if·!·rpm·-q·--quiet·"libreswan"·;·then10859 if·!·rpm·-q·--quiet·"libreswan"·;·then
10867 ····yum·install·-y·"libreswan"10860 ····yum·install·-y·"libreswan"
10868 fi10861 fi
 10862 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 10863 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 10864 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 10865 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 10866 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 10867 package·--add=libreswan
10869 Group  ·File·Permissions·and·Masks·  Group·contains·2·groups·and·9·rules10868 Group  ·File·Permissions·and·Masks·  Group·contains·2·groups·and·9·rules
10870 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Traditional·Unix·security·relies·heavily·on·file·and·directory·permissions·to·prevent·unauthorized·users·from·reading·or·modifying·files·to·which·they·should·not·have·access.10869 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Traditional·Unix·security·relies·heavily·on·file·and·directory·permissions·to·prevent·unauthorized·users·from·reading·or·modifying·files·to·which·they·should·not·have·access.
  
10871 Several·of·the·commands·in·this·section·search·filesystems·for·files·or·directories·with·certain·characteristics,·and·are·intended·to·be·run·on·every·local·partition·on·a·given·system.·When·the·variable·PART·appears·in·one·of·the·commands·below,·it·means·that·the·command·is·intended·to·be·run·repeatedly,·with·the·name·of·each·local·partition·substituted·for·PART·in·turn.10870 Several·of·the·commands·in·this·section·search·filesystems·for·files·or·directories·with·certain·characteristics,·and·are·intended·to·be·run·on·every·local·partition·on·a·given·system.·When·the·variable·PART·appears·in·one·of·the·commands·below,·it·means·that·the·command·is·intended·to·be·run·repeatedly,·with·the·name·of·each·local·partition·substituted·for·PART·in·turn.
  
10872 The·following·command·prints·a·list·of·all·xfs·partitions·on·the·local·system,·which·is·the·default·filesystem·for·Oracle·Linux·7·installations:10871 The·following·command·prints·a·list·of·all·xfs·partitions·on·the·local·system,·which·is·the·default·filesystem·for·Oracle·Linux·7·installations:
10873 $·mount·-t·xfs·|·awk·'{print·$3}'10872 $·mount·-t·xfs·|·awk·'{print·$3}'
Offset 34061, 39 lines modifiedOffset 34061, 39 lines modified
34061 ··-·medium_severity34061 ··-·medium_severity
34062 ··-·no_reboot_needed34062 ··-·no_reboot_needed
34063 ··-·service_auditd_enabled34063 ··-·service_auditd_enabled
Max diff block lines reached; 1405/9017 bytes (15.58%) of diff not shown.
73.4 KB
./usr/share/doc/ssg-nondebian/ssg-ol7-guide-sap.html
    
Offset 14695, 132 lines modifiedOffset 14695, 132 lines modified
00039660:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target00039660:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
00039670:·3d22·2369·646d·3839·3932·2220·7461·6269··="#idm8992"·tabi00039670:·3d22·2369·646d·3839·3932·2220·7461·6269··="#idm8992"·tabi
00039680:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b00039680:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
00039690:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa00039690:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
000396a0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit000396a0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
000396b0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·000396b0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
000396c0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!000396c0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
000396d0:·223e·5265·6d65·6469·6174·696f·6e20·416e··">Remediation·An000396d0:·223e·5265·6d65·6469·6174·696f·6e20·4f53··">Remediation·OS
000396e0:·6163·6f6e·6461·2073·6e69·7070·6574·20e2··aconda·snippet·. 
000396f0:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c 
00039700:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll000396e0:·4275·696c·6420·426c·7565·7072·696e·7420··Build·Blueprint·
 000396f0:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><
 00039700:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
00039710:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i00039710:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
00039720:·643d·2269·646d·3839·3932·223e·3c74·6162··d="idm8992"><tab 
00039730:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table· 
00039740:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta 
00039750:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab 
00039760:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t 
00039770:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity 
00039780:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t 
00039790:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D 
000397a0:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><00039720:·6c6c·6170·7365·2220·6964·3d22·6964·6d38··llapse"·id="idm8
 00039730:·3939·3222·3e3c·7072·653e·3c63·6f64·653e··992"><pre><code>
 00039740:·0a5b·5b70·6163·6b61·6765·735d·5d0a·6e61··.[[packages]].na
 00039750:·6d65·203d·2022·676c·6962·6322·0a76·6572··me·=·"glibc".ver
 00039760:·7369·6f6e·203d·2022·2a22·0a3c·2f63·6f64··sion·=·"*".</cod
 00039770:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a
 00039780:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn-
 00039790:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to
 000397a0:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"·
 000397b0:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
 000397c0:·6d38·3939·3322·2074·6162·696e·6465·783d··m8993"·tabindex=
 000397d0:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button
 000397e0:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=
 000397f0:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A
 00039800:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea
 00039810:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem
 00039820:·6564·6961·7469·6f6e·2050·7570·7065·7420··ediation·Puppet·
 00039830:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><
 00039840:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
 00039850:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
 00039860:·6c6c·6170·7365·2220·6964·3d22·6964·6d38··llapse"·id="idm8
 00039870:·3939·3322·3e3c·7461·626c·6520·636c·6173··993"><table·clas
 00039880:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s
 00039890:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor
 000398a0:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond
 000398b0:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C
 000398c0:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><
000397b0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>000398d0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
 000398e0:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti
000397c0:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:< 
000397d0:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t 
000397e0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S 
000397f0:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td 
00039800:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr 
00039810:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c 
00039820:·6f64·653e·0a70·6163·6b61·6765·202d·2d61··ode>.package·--a 
00039830:·6464·3d67·6c69·6263·0a3c·2f63·6f64·653e··dd=glibc.</code> 
00039840:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c 
00039850:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su 
00039860:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg 
00039870:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da 
00039880:·7461·2d74·6172·6765·743d·2223·6964·6d38··ta-target="#idm8 
00039890:·3939·3322·2074·6162·696e·6465·783d·2230··993"·tabindex="0 
000398a0:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"· 
000398b0:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f 
000398c0:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act 
000398d0:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal" 
000398e0:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed 
000398f0:·6961·7469·6f6e·204f·5342·7569·6c64·2042··iation·OSBuild·B 
00039900:·6c75·6570·7269·6e74·2073·6e69·7070·6574··lueprint·snippet 
00039910:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div 
00039920:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co 
00039930:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse" 
00039940:·2069·643d·2269·646d·3839·3933·223e·3c70···id="idm8993"><p 
00039950:·7265·3e3c·636f·6465·3e0a·5b5b·7061·636b··re><code>.[[pack 
00039960:·6167·6573·5d5d·0a6e·616d·6520·3d20·2267··ages]].name·=·"g 
00039970:·6c69·6263·220a·7665·7273·696f·6e20·3d20··libc".version·=· 
00039980:·222a·220a·3c2f·636f·6465·3e3c·2f70·7265··"*".</code></pre 
00039990:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class= 
000399a0:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success 
000399b0:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c 
000399c0:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta 
000399d0:·7267·6574·3d22·2369·646d·3839·3934·2220··rget="#idm8994"· 
000399e0:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol 
000399f0:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria- 
00039a00:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false" 
00039a10:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate 
00039a20:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href 
00039a30:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio 
00039a40:·6e20·5075·7070·6574·2073·6e69·7070·6574··n·Puppet·snippet 
00039a50:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div 
00039a60:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co 
00039a70:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse" 
00039a80:·2069·643d·2269·646d·3839·3934·223e·3c74···id="idm8994"><t 
00039a90:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl 
00039aa0:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped· 
00039ab0:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t 
00039ac0:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed"> 
00039ad0:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi 
00039ae0:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<000398f0:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<
00039af0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th00039900:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
00039b00:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th 
00039b10:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t 
00039b20:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot00039910:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td
 00039920:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr>
 00039930:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy
00039b30:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false<00039940:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable
 00039950:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl
 00039960:·653e·3c70·7265·3e3c·636f·6465·3e69·6e63··e><pre><code>inc
00039b40:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
00039b50:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th>< 
00039b60:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></ 
00039b70:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre> 
00039b80:·3c63·6f64·653e·696e·636c·7564·6520·696e··<code>include·in 
00039b90:·7374·616c·6c5f·676c·6962·630a·0a63·6c61··stall_glibc..cla 
00039ba0:·7373·2069·6e73·7461·6c6c·5f67·6c69·6263··ss·install_glibc00039970:·6c75·6465·2069·6e73·7461·6c6c·5f67·6c69··lude·install_gli
00039bb0:·207b·0a20·2070·6163·6b61·6765·207b·2027···{.··package·{·' 
00039bc0:·676c·6962·6327·3a0a·2020·2020·656e·7375··glibc':.····ensu 
00039bd0:·7265·203d·2667·743b·2027·696e·7374·616c··re·=&gt;·'instal 
00039be0:·6c65·6427·2c0a·2020·7d0a·7d0a·3c2f·636f··led',.··}.}.</co 
00039bf0:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div>< 
00039c00:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn 
00039c10:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t 
00039c20:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse"00039980:·6263·0a0a·636c·6173·7320·696e·7374·616c··bc..class·instal
 00039990:·6c5f·676c·6962·6320·7b0a·2020·7061·636b··l_glibc·{.··pack
Max diff block lines reached; 50316/67180 bytes (74.90%) of diff not shown.
7.66 KB
html2text {}
    
Offset 80, 21 lines modifiedOffset 80, 14 lines modified
80 ··tags:80 ··tags:
81 ··-·enable_strategy81 ··-·enable_strategy
82 ··-·low_complexity82 ··-·low_complexity
83 ··-·low_disruption83 ··-·low_disruption
84 ··-·medium_severity84 ··-·medium_severity
85 ··-·no_reboot_needed85 ··-·no_reboot_needed
86 ··-·package_glibc_installed86 ··-·package_glibc_installed
87 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
88 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
89 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
90 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
91 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
92 package·--add=glibc 
93 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x887 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
94 [[packages]]88 [[packages]]
95 name·=·"glibc"89 name·=·"glibc"
96 version·=·"*"90 version·=·"*"
97 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x891 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
98 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low92 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 113, 14 lines modifiedOffset 106, 21 lines modified
113 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low106 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
114 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false107 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
115 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable108 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
116 if·!·rpm·-q·--quiet·"glibc"·;·then109 if·!·rpm·-q·--quiet·"glibc"·;·then
117 ····yum·install·-y·"glibc"110 ····yum·install·-y·"glibc"
118 fi111 fi
 112 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 113 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 114 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 115 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 116 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 117 package·--add=glibc
119 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·P\x8Pa\x8ac\x8ck\x8ka\x8ag\x8ge\x8e·u\x8uu\x8ui\x8id\x8dd\x8d·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8le\x8ed\x8d·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*118 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·P\x8Pa\x8ac\x8ck\x8ka\x8ag\x8ge\x8e·u\x8uu\x8ui\x8id\x8dd\x8d·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8le\x8ed\x8d·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
120 The·package·uuidd·is·not·installed·on·normal·Linux·distribution·by·default.·Applications·require·this·package·to·avoid·database·inconsistences·caused·by·duplicated119 The·package·uuidd·is·not·installed·on·normal·Linux·distribution·by·default.·Applications·require·this·package·to·avoid·database·inconsistences·caused·by·duplicated
121 UUIDs.·Especially·in·banking·services·with·SAP·where·massive·UUIDs·are·created·in·a·short·time·period,·it·is·important·to·install·the·package·uuidd.·More·information120 UUIDs.·Especially·in·banking·services·with·SAP·where·massive·UUIDs·are·created·in·a·short·time·period,·it·is·important·to·install·the·package·uuidd.·More·information
122 can·be·found·in·SAP·note·1391070.·The·uuidd·package·can·be·installed·with·the·following·command:121 can·be·found·in·SAP·note·1391070.·The·uuidd·package·can·be·installed·with·the·following·command:
123 $·sudo·yum·install·uuidd122 $·sudo·yum·install·uuidd
124 Rationale:·The·uuidd·package·contains·a·userspace·daemon·(uuidd)·which·is·used·to·generate·unique·identifiers·even·at·very·high·rates·on·SMP·systems.123 Rationale:·The·uuidd·package·contains·a·userspace·daemon·(uuidd)·which·is·used·to·generate·unique·identifiers·even·at·very·high·rates·on·SMP·systems.
125 Severity: ·medium124 Severity: ·medium
Offset 137, 21 lines modifiedOffset 137, 14 lines modified
137 ··tags:137 ··tags:
138 ··-·enable_strategy138 ··-·enable_strategy
139 ··-·low_complexity139 ··-·low_complexity
140 ··-·low_disruption140 ··-·low_disruption
141 ··-·medium_severity141 ··-·medium_severity
142 ··-·no_reboot_needed142 ··-·no_reboot_needed
143 ··-·package_uuidd_installed143 ··-·package_uuidd_installed
144 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
145 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
146 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
147 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
148 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
149 package·--add=uuidd 
150 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8144 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
151 [[packages]]145 [[packages]]
152 name·=·"uuidd"146 name·=·"uuidd"
153 version·=·"*"147 version·=·"*"
154 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8148 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
155 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low149 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 170, 14 lines modifiedOffset 163, 21 lines modified
170 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low163 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
171 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false164 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
172 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable165 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
173 if·!·rpm·-q·--quiet·"uuidd"·;·then166 if·!·rpm·-q·--quiet·"uuidd"·;·then
174 ····yum·install·-y·"uuidd"167 ····yum·install·-y·"uuidd"
175 fi168 fi
 169 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 170 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 171 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 172 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 173 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 174 package·--add=uuidd
176 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·O\x8On\x8nl\x8ly\x8y·s\x8si\x8id\x8da\x8ad\x8dm\x8m·a\x8an\x8nd\x8d·o\x8or\x8ra\x8as\x8si\x8id\x8d/\x8/o\x8or\x8ra\x8ac\x8cl\x8le\x8e·U\x8Us\x8se\x8er\x8r·A\x8Ac\x8cc\x8co\x8ou\x8un\x8nt\x8ts\x8s·E\x8Ex\x8xi\x8is\x8st\x8t·o\x8on\x8n·O\x8Op\x8pe\x8er\x8ra\x8at\x8ti\x8in\x8ng\x8g·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*175 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·O\x8On\x8nl\x8ly\x8y·s\x8si\x8id\x8da\x8ad\x8dm\x8m·a\x8an\x8nd\x8d·o\x8or\x8ra\x8as\x8si\x8id\x8d/\x8/o\x8or\x8ra\x8ac\x8cl\x8le\x8e·U\x8Us\x8se\x8er\x8r·A\x8Ac\x8cc\x8co\x8ou\x8un\x8nt\x8ts\x8s·E\x8Ex\x8xi\x8is\x8st\x8t·o\x8on\x8n·O\x8Op\x8pe\x8er\x8ra\x8at\x8ti\x8in\x8ng\x8g·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
177 SAP·tends·to·use·the·server·or·virtual·machine·exclusively.·There·should·be·only·SAP·system·users·sidadm·and·orasid·that·exist·on·the·operating·system·(or·virtual176 SAP·tends·to·use·the·server·or·virtual·machine·exclusively.·There·should·be·only·SAP·system·users·sidadm·and·orasid·that·exist·on·the·operating·system·(or·virtual
178 machine).·If·SAP·Host·Agent·is·installed,·the·user·sapadm·must·exist·too.·With·Oracle·Database·using·oracle·user,·the·user·oracle·should·exist·as·well.·While·SID·is177 machine).·If·SAP·Host·Agent·is·installed,·the·user·sapadm·must·exist·too.·With·Oracle·Database·using·oracle·user,·the·user·oracle·should·exist·as·well.·While·SID·is
179 the·SAP·System·ID,·which·is·always·three·alphanumeric·characters·in·upper·case,·beginning·with·an·alphabetic·character,·the·user·names·sidadm·and·orasid·are·in·lower178 the·SAP·System·ID,·which·is·always·three·alphanumeric·characters·in·upper·case,·beginning·with·an·alphabetic·character,·the·user·names·sidadm·and·orasid·are·in·lower
180 case.179 case.
  
181 Besides·the·above·SAP·users·that·are·automatically·detected,·other·operating·system·users·can·be·customized·in·the·refine·value·variable180 Besides·the·above·SAP·users·that·are·automatically·detected,·other·operating·system·users·can·be·customized·in·the·refine·value·variable
Offset 411, 21 lines modifiedOffset 411, 14 lines modified
411 ··-·PCI-DSSv4-2.2.4411 ··-·PCI-DSSv4-2.2.4
412 ··-·disable_strategy412 ··-·disable_strategy
413 ··-·low_complexity413 ··-·low_complexity
414 ··-·low_disruption414 ··-·low_disruption
415 ··-·no_reboot_needed415 ··-·no_reboot_needed
416 ··-·package_ypbind_removed416 ··-·package_ypbind_removed
417 ··-·unknown_severity417 ··-·unknown_severity
418 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
419 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
420 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
421 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
422 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable 
  
423 package·--remove=ypbind 
424 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8418 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
425 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low419 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
426 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low420 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
427 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false421 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
428 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable422 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
429 include·remove_ypbind423 include·remove_ypbind
  
Offset 445, 14 lines modifiedOffset 438, 21 lines modified
445 #»      ···that·depend·on·ypbind.·Execute·this438 #»      ···that·depend·on·ypbind.·Execute·this
446 #»      ···remediation·AFTER·testing·on·a·non-production439 #»      ···remediation·AFTER·testing·on·a·non-production
447 #»      ···system!440 #»      ···system!
  
448 if·rpm·-q·--quiet·"ypbind"·;·then441 if·rpm·-q·--quiet·"ypbind"·;·then
449 yum·remove·-y·"ypbind"442 yum·remove·-y·"ypbind"
450 fi443 fi
 444 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 445 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 446 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 447 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 448 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
  
 449 package·--remove=ypbind
451 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·U\x8Un\x8ni\x8in\x8ns\x8st\x8ta\x8al\x8ll\x8l·y\x8yp\x8ps\x8se\x8er\x8rv\x8v·P\x8Pa\x8ac\x8ck\x8ka\x8ag\x8ge\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*450 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·U\x8Un\x8ni\x8in\x8ns\x8st\x8ta\x8al\x8ll\x8l·y\x8yp\x8ps\x8se\x8er\x8rv\x8v·P\x8Pa\x8ac\x8ck\x8ka\x8ag\x8ge\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
452 The·ypserv·package·can·be·removed·with·the·following·command:451 The·ypserv·package·can·be·removed·with·the·following·command:
453 $·sudo·yum·erase·ypserv452 $·sudo·yum·erase·ypserv
Max diff block lines reached; 2213/7820 bytes (28.30%) of diff not shown.
20.5 KB
./usr/share/doc/ssg-nondebian/ssg-ol7-guide-standard.html
    
Offset 21463, 145 lines modifiedOffset 21463, 145 lines modified
00053d60:·6172·6765·743d·2223·6964·6d31·3936·3836··arget="#idm1968600053d60:·6172·6765·743d·2223·6964·6d31·3936·3836··arget="#idm19686
00053d70:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r00053d70:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r
00053d80:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari00053d80:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari
00053d90:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals00053d90:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals
00053da0:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa00053da0:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa
00053db0:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr00053db0:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr
00053dc0:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat00053dc0:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat
 00053dd0:·696f·6e20·4f53·4275·696c·6420·426c·7565··ion·OSBuild·Blue
 00053de0:·7072·696e·7420·736e·6970·7065·7420·e287··print·snippet·..
 00053df0:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl
 00053e00:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla
 00053e10:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id
 00053e20:·3d22·6964·6d31·3936·3836·223e·3c70·7265··="idm19686"><pre
00053dd0:·696f·6e20·416e·6163·6f6e·6461·2073·6e69··ion·Anaconda·sni 
00053de0:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br> 
00053df0:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane 
00053e00:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla 
00053e10:·7073·6522·2069·643d·2269·646d·3139·3638··pse"·id="idm1968 
00053e20:·3622·3e3c·7461·626c·6520·636c·6173·733d··6"><table·class= 
00053e30:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str 
00053e40:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde 
00053e50:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden 
00053e60:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com 
00053e70:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td 
00053e80:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t 
00053e90:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption 
00053ea0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t 
00053eb0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e52··d></tr><tr><th>R 
00053ec0:·6562·6f6f·743a·3c2f·7468·3e3c·7464·3e66··eboot:</th><td>f 
00053ed0:·616c·7365·3c2f·7464·3e3c·2f74·723e·3c74··alse</td></tr><t 
00053ee0:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:< 
00053ef0:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</ 
00053f00:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table> 
00053f10:·3c70·7265·3e3c·636f·6465·3e0a·7061·636b··<pre><code>.pack00053e30:·3e3c·636f·6465·3e0a·5b5b·7061·636b·6167··><code>.[[packag
00053f20:·6167·6520·2d2d·6164·643d·7273·7973·6c6f··age·--add=rsyslo00053e40:·6573·5d5d·0a6e·616d·6520·3d20·2272·7379··es]].name·=·"rsy
 00053e50:·736c·6f67·220a·7665·7273·696f·6e20·3d20··slog".version·=·
00053f30:·670a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··g.</code></pre><00053e60:·222a·220a·3c2f·636f·6465·3e3c·2f70·7265··"*".</code></pre
00053f40:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b00053e70:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class=
00053f50:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"·00053e80:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success
00053f60:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col00053e90:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c
00053f70:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ00053ea0:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta
00053f80:·6574·3d22·2369·646d·3139·3638·3722·2074··et="#idm19687"·t00053eb0:·7267·6574·3d22·2369·646d·3139·3638·3722··rget="#idm19687"
00053f90:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role00053ec0:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro
00053fa0:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e00053ed0:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria
00053fb0:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·00053ee0:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false
00053fc0:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·00053ef0:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat
00053fd0:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=00053f00:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre
00053fe0:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation00053f10:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati
00053ff0:·204f·5342·7569·6c64·2042·6c75·6570·7269···OSBuild·Bluepri00053f20:·6f6e·2050·7570·7065·7420·736e·6970·7065··on·Puppet·snippe
 00053f30:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di
 00053f40:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c
 00053f50:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse
 00053f60:·2220·6964·3d22·6964·6d31·3936·3837·223e··"·id="idm19687">
 00053f70:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta
 00053f80:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe
 00053f90:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered
 00053fa0:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed
 00053fb0:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple
 00053fc0:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo
 00053fd0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
 00053fe0:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</
 00053ff0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
 00054000:·2f74·723e·3c74·723e·3c74·683e·5265·626f··/tr><tr><th>Rebo
 00054010:·6f74·3a3c·2f74·683e·3c74·643e·6661·6c73··ot:</th><td>fals
 00054020:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr><
 00054030:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th
 00054040:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td>
 00054050:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr
 00054060:·653e·3c63·6f64·653e·696e·636c·7564·6520··e><code>include·
 00054070:·696e·7374·616c·6c5f·7273·7973·6c6f·670a··install_rsyslog.
 00054080:·0a63·6c61·7373·2069·6e73·7461·6c6c·5f72··.class·install_r
 00054090:·7379·736c·6f67·207b·0a20·2070·6163·6b61··syslog·{.··packa
 000540a0:·6765·207b·2027·7273·7973·6c6f·6727·3a0a··ge·{·'rsyslog':.
 000540b0:·2020·2020·656e·7375·7265·203d·2667·743b······ensure·=&gt;
 000540c0:·2027·696e·7374·616c·6c65·6427·2c0a·2020···'installed',.··
 000540d0:·7d0a·7d0a·3c2f·636f·6465·3e3c·2f70·7265··}.}.</code></pre
 000540e0:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class=
 000540f0:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success
 00054100:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c
 00054110:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta
 00054120:·7267·6574·3d22·2369·646d·3139·3638·3822··rget="#idm19688"
 00054130:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro
 00054140:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria
 00054150:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false
 00054160:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat
 00054170:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre
 00054180:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati
 00054190:·6f6e·2053·6865·6c6c·2073·6372·6970·7420··on·Shell·script·
 000541a0:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·
 000541b0:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col
 000541c0:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·
 000541d0:·6964·3d22·6964·6d31·3936·3838·223e·3c74··id="idm19688"><t
 000541e0:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl
 000541f0:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·
 00054200:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t
 00054210:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">
 00054220:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi
 00054230:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<
 00054240:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 00054250:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th
 00054260:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
 00054270:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot
 00054280:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false<
 00054290:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 000542a0:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><
 000542b0:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></
 000542c0:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>
 000542d0:·3c63·6f64·653e·2320·5265·6d65·6469·6174··<code>#·Remediat
 000542e0:·696f·6e20·6973·2061·7070·6c69·6361·626c··ion·is·applicabl
 000542f0:·6520·6f6e·6c79·2069·6e20·6365·7274·6169··e·only·in·certai
 00054300:·6e20·706c·6174·666f·726d·730a·6966·2072··n·platforms.if·r
 00054310:·706d·202d·2d71·7569·6574·202d·7120·6b65··pm·--quiet·-q·ke
 00054320:·726e·656c·207c·7c20·7270·6d20·2d2d·7175··rnel·||·rpm·--qu
 00054330:·6965·7420·2d71·206b·6572·6e65·6c2d·7565··iet·-q·kernel-ue
 00054340:·6b3b·2074·6865·6e0a·0a69·6620·2120·7270··k;·then..if·!·rp
 00054350:·6d20·2d71·202d·2d71·7569·6574·2022·7273··m·-q·--quiet·"rs
 00054360:·7973·6c6f·6722·203b·2074·6865·6e0a·2020··yslog"·;·then.··
 00054370:·2020·7975·6d20·696e·7374·616c·6c20·2d79····yum·install·-y
 00054380:·2022·7273·7973·6c6f·6722·0a66·690a·0a65···"rsyslog".fi..e
 00054390:·6c73·650a·2020·2020·2667·743b·2661·6d70··lse.····&gt;&amp
 000543a0:·3b32·2065·6368·6f20·2752·656d·6564·6961··;2·echo·'Remedia
 000543b0:·7469·6f6e·2069·7320·6e6f·7420·6170·706c··tion·is·not·appl
 000543c0:·6963·6162·6c65·2c20·6e6f·7468·696e·6720··icable,·nothing·
 000543d0:·7761·7320·646f·6e65·270a·6669·0a3c·2f63··was·done'.fi.</c
 000543e0:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div>
 000543f0:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt
 00054400:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data-
Max diff block lines reached; 414/19072 bytes (2.17%) of diff not shown.
1.79 KB
html2text {}
    
Offset 1289, 21 lines modifiedOffset 1289, 14 lines modified
1289 ··-·NIST-800-53-CM-6(a)1289 ··-·NIST-800-53-CM-6(a)
1290 ··-·enable_strategy1290 ··-·enable_strategy
1291 ··-·low_complexity1291 ··-·low_complexity
1292 ··-·low_disruption1292 ··-·low_disruption
1293 ··-·medium_severity1293 ··-·medium_severity
1294 ··-·no_reboot_needed1294 ··-·no_reboot_needed
1295 ··-·package_rsyslog_installed1295 ··-·package_rsyslog_installed
1296 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
1297 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
1298 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
1299 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
1300 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
1301 package·--add=rsyslog 
1302 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81296 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
1303 [[packages]]1297 [[packages]]
1304 name·=·"rsyslog"1298 name·=·"rsyslog"
1305 version·=·"*"1299 version·=·"*"
1306 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81300 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1307 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1301 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 1328, 14 lines modifiedOffset 1321, 21 lines modified
1328 if·!·rpm·-q·--quiet·"rsyslog"·;·then1321 if·!·rpm·-q·--quiet·"rsyslog"·;·then
1329 ····yum·install·-y·"rsyslog"1322 ····yum·install·-y·"rsyslog"
1330 fi1323 fi
  
1331 else1324 else
1332 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'1325 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
1333 fi1326 fi
 1327 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 1328 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1329 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1330 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1331 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 1332 package·--add=rsyslog
1334 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·r\x8rs\x8sy\x8ys\x8sl\x8lo\x8og\x8g·S\x8Se\x8er\x8rv\x8vi\x8ic\x8ce\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*1333 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·r\x8rs\x8sy\x8ys\x8sl\x8lo\x8og\x8g·S\x8Se\x8er\x8rv\x8vi\x8ic\x8ce\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
1335 The·rsyslog·service·provides·syslog-style·logging·by·default·on·Oracle·Linux·7.·The·rsyslog·service·can·be·enabled·with·the·following·command:1334 The·rsyslog·service·provides·syslog-style·logging·by·default·on·Oracle·Linux·7.·The·rsyslog·service·can·be·enabled·with·the·following·command:
1336 $·sudo·systemctl·enable·rsyslog.service1335 $·sudo·systemctl·enable·rsyslog.service
1337 Rationale:··The·rsyslog·service·must·be·running·in·order·to·provide·logging·services,·which·are·essential·to·system·administration.1336 Rationale:··The·rsyslog·service·must·be·running·in·order·to·provide·logging·services,·which·are·essential·to·system·administration.
1338 Severity: ··medium1337 Severity: ··medium
1339 Rule·ID:····xccdf_org.ssgproject.content_rule_service_rsyslog_enabled1338 Rule·ID:····xccdf_org.ssgproject.content_rule_service_rsyslog_enabled
1340 ············_\x8c_\x8i_\x8s_\x8-_\x8c_\x8s_\x8c········1,·12,·13,·14,·15,·16,·2,·3,·5,·6,·7,·8,·91339 ············_\x8c_\x8i_\x8s_\x8-_\x8c_\x8s_\x8c········1,·12,·13,·14,·15,·16,·2,·3,·5,·6,·7,·8,·9
346 KB
./usr/share/doc/ssg-nondebian/ssg-ol7-guide-stig.html
    
Offset 17466, 144 lines modifiedOffset 17466, 144 lines modified
00044390:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm00044390:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
000443a0:·3536·3532·2220·7461·6269·6e64·6578·3d22··5652"·tabindex="000443a0:·3536·3532·2220·7461·6269·6e64·6578·3d22··5652"·tabindex="
000443b0:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"000443b0:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
000443c0:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="000443c0:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
000443d0:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac000443d0:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
000443e0:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal000443e0:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
000443f0:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme000443f0:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
 00044400:·6469·6174·696f·6e20·4f53·4275·696c·6420··diation·OSBuild·
 00044410:·426c·7565·7072·696e·7420·736e·6970·7065··Blueprint·snippe
 00044420:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di
 00044430:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c
 00044440:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse
 00044450:·2220·6964·3d22·6964·6d35·3635·3222·3e3c··"·id="idm5652"><
 00044460:·7072·653e·3c63·6f64·653e·0a5b·5b70·6163··pre><code>.[[pac
 00044470:·6b61·6765·735d·5d0a·6e61·6d65·203d·2022··kages]].name·=·"
 00044480:·6169·6465·220a·7665·7273·696f·6e20·3d20··aide".version·=·
 00044490:·222a·220a·3c2f·636f·6465·3e3c·2f70·7265··"*".</code></pre
 000444a0:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class=
 000444b0:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success
 000444c0:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c
 000444d0:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta
 000444e0:·7267·6574·3d22·2369·646d·3536·3533·2220··rget="#idm5653"·
 000444f0:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol
 00044500:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-
 00044510:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"
 00044520:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate
 00044530:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href
 00044540:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio
 00044550:·6e20·5075·7070·6574·2073·6e69·7070·6574··n·Puppet·snippet
 00044560:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
 00044570:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
 00044580:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
 00044590:·2069·643d·2269·646d·3536·3533·223e·3c74···id="idm5653"><t
 000445a0:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl
 000445b0:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·
 000445c0:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t
 000445d0:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">
 000445e0:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi
 000445f0:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<
 00044600:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 00044610:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th
 00044620:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
 00044630:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot
 00044640:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false<
 00044650:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 00044660:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><
 00044670:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></
 00044680:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>
 00044690:·3c63·6f64·653e·696e·636c·7564·6520·696e··<code>include·in
 000446a0:·7374·616c·6c5f·6169·6465·0a0a·636c·6173··stall_aide..clas
 000446b0:·7320·696e·7374·616c·6c5f·6169·6465·207b··s·install_aide·{
 000446c0:·0a20·2070·6163·6b61·6765·207b·2027·6169··.··package·{·'ai
 000446d0:·6465·273a·0a20·2020·2065·6e73·7572·6520··de':.····ensure·
 000446e0:·3d26·6774·3b20·2769·6e73·7461·6c6c·6564··=&gt;·'installed
 000446f0:·272c·0a20·207d·0a7d·0a3c·2f63·6f64·653e··',.··}.}.</code>
 00044700:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c
 00044710:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su
 00044720:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg
 00044730:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da
 00044740:·7461·2d74·6172·6765·743d·2223·6964·6d35··ta-target="#idm5
 00044750:·3635·3422·2074·6162·696e·6465·783d·2230··654"·tabindex="0
 00044760:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
 00044770:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
 00044780:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
 00044790:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
 000447a0:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
 000447b0:·6961·7469·6f6e·2053·6865·6c6c·2073·6372··iation·Shell·scr
 000447c0:·6970·7420·e287·b23c·2f61·3e3c·6272·3e3c··ipt·...</a><br><
 000447d0:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
 000447e0:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap
 000447f0:·7365·2220·6964·3d22·6964·6d35·3635·3422··se"·id="idm5654"
 00044800:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t
 00044810:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip
 00044820:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere
 00044830:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense
 00044840:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl
 00044850:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l
 00044860:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
 00044870:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:<
 00044880:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
 00044890:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb
 000448a0:·6f6f·743a·3c2f·7468·3e3c·7464·3e66·616c··oot:</th><td>fal
 000448b0:·7365·3c2f·7464·3e3c·2f74·723e·3c74·723e··se</td></tr><tr>
 000448c0:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t
 000448d0:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td
 000448e0:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p
 000448f0:·7265·3e3c·636f·6465·3e23·2052·656d·6564··re><code>#·Remed
 00044900:·6961·7469·6f6e·2069·7320·6170·706c·6963··iation·is·applic
 00044910:·6162·6c65·206f·6e6c·7920·696e·2063·6572··able·only·in·cer
 00044920:·7461·696e·2070·6c61·7466·6f72·6d73·0a69··tain·platforms.i
 00044930:·6620·7270·6d20·2d2d·7175·6965·7420·2d71··f·rpm·--quiet·-q
 00044940:·206b·6572·6e65·6c20·7c7c·2072·706d·202d···kernel·||·rpm·-
 00044950:·2d71·7569·6574·202d·7120·6b65·726e·656c··-quiet·-q·kernel
 00044960:·2d75·656b·3b20·7468·656e·0a0a·6966·2021··-uek;·then..if·!
 00044970:·2072·706d·202d·7120·2d2d·7175·6965·7420···rpm·-q·--quiet·
 00044980:·2261·6964·6522·203b·2074·6865·6e0a·2020··"aide"·;·then.··
 00044990:·2020·7975·6d20·696e·7374·616c·6c20·2d79····yum·install·-y
 000449a0:·2022·6169·6465·220a·6669·0a0a·656c·7365···"aide".fi..else
 000449b0:·0a20·2020·2026·6774·3b26·616d·703b·3220··.····&gt;&amp;2·
 000449c0:·6563·686f·2027·5265·6d65·6469·6174·696f··echo·'Remediatio
 000449d0:·6e20·6973·206e·6f74·2061·7070·6c69·6361··n·is·not·applica
 000449e0:·626c·652c·206e·6f74·6869·6e67·2077·6173··ble,·nothing·was
 000449f0:·2064·6f6e·6527·0a66·690a·3c2f·636f·6465···done'.fi.</code
 00044a00:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a·
 00044a10:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s
 00044a20:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog
 00044a30:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d
 00044a40:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
 00044a50:·3536·3535·2220·7461·6269·6e64·6578·3d22··5655"·tabindex="
 00044a60:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
 00044a70:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
 00044a80:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
 00044a90:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
 00044aa0:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
00044400:·6469·6174·696f·6e20·416e·6163·6f6e·6461··diation·Anaconda00044ab0:·6469·6174·696f·6e20·416e·6163·6f6e·6461··diation·Anaconda
00044410:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>00044ac0:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>
00044420:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="00044ad0:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="
00044430:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c00044ae0:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c
00044440:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm 
00044450:·3536·3532·223e·3c74·6162·6c65·2063·6c61··5652"><table·cla 
00044460:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table- 
00044470:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo 
00044480:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con 
00044490:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th> 
000444a0:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th> 
000444b0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
000444c0:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt 
Max diff block lines reached; 300310/318830 bytes (94.19%) of diff not shown.
34.7 KB
html2text {}
    
Offset 736, 21 lines modifiedOffset 736, 14 lines modified
736 ··-·PCI-DSSv4-11.5.2736 ··-·PCI-DSSv4-11.5.2
737 ··-·enable_strategy737 ··-·enable_strategy
738 ··-·low_complexity738 ··-·low_complexity
739 ··-·low_disruption739 ··-·low_disruption
740 ··-·medium_severity740 ··-·medium_severity
741 ··-·no_reboot_needed741 ··-·no_reboot_needed
742 ··-·package_aide_installed742 ··-·package_aide_installed
743 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
744 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
745 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
746 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
747 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
748 package·--add=aide 
749 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8743 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
750 [[packages]]744 [[packages]]
751 name·=·"aide"745 name·=·"aide"
752 version·=·"*"746 version·=·"*"
753 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8747 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
754 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low748 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 775, 14 lines modifiedOffset 768, 21 lines modified
775 if·!·rpm·-q·--quiet·"aide"·;·then768 if·!·rpm·-q·--quiet·"aide"·;·then
776 ····yum·install·-y·"aide"769 ····yum·install·-y·"aide"
777 fi770 fi
  
778 else771 else
779 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'772 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
780 fi773 fi
 774 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 775 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 776 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 777 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 778 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 779 package·--add=aide
781 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*780 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
782 Run·the·following·command·to·generate·a·new·database:781 Run·the·following·command·to·generate·a·new·database:
783 $·sudo·/usr/sbin/aide·--init782 $·sudo·/usr/sbin/aide·--init
784 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:783 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
785 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz784 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
786 To·initiate·a·manual·check,·run·the·following·command:785 To·initiate·a·manual·check,·run·the·following·command:
787 $·sudo·/usr/sbin/aide·--check786 $·sudo·/usr/sbin/aide·--check
Offset 2058, 17 lines modifiedOffset 2058, 14 lines modified
2058 ··-·NIST-800-53-SC-132058 ··-·NIST-800-53-SC-13
2059 ··-·grub2_enable_fips_mode2059 ··-·grub2_enable_fips_mode
2060 ··-·high_complexity2060 ··-·high_complexity
2061 ··-·high_severity2061 ··-·high_severity
2062 ··-·medium_disruption2062 ··-·medium_disruption
2063 ··-·reboot_required2063 ··-·reboot_required
2064 ··-·restrict_strategy2064 ··-·restrict_strategy
2065 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
2066 package·--add=dracut-fips·--add=dracut-fips-aesni 
2067 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x82065 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
2068 #·Remediation·is·applicable·only·in·certain·platforms2066 #·Remediation·is·applicable·only·in·certain·platforms
2069 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek·)·&&·{·rpm·--quiet·-q·grub2-common;·};·then2067 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek·)·&&·{·rpm·--quiet·-q·grub2-common;·};·then
  
2070 #·prelink·not·installed2068 #·prelink·not·installed
2071 if·test·-e·/etc/sysconfig/prelink·-o·-e·/usr/sbin/prelink;·then2069 if·test·-e·/etc/sysconfig/prelink·-o·-e·/usr/sbin/prelink;·then
2072 ····if·grep·-q·^PRELINKING·/etc/sysconfig/prelink2070 ····if·grep·-q·^PRELINKING·/etc/sysconfig/prelink
Offset 2127, 14 lines modifiedOffset 2124, 17 lines modified
2127 »       #·Correct·the·form·of·kernel·command·line·for·each·installed·kernel·in·the·bootloader2124 »       #·Correct·the·form·of·kernel·command·line·for·each·installed·kernel·in·the·bootloader
2128 »       /sbin/grubby·--update-kernel=ALL·--args="fips=1·boot=UUID=${BOOT_UUID}"2125 »       /sbin/grubby·--update-kernel=ALL·--args="fips=1·boot=UUID=${BOOT_UUID}"
2129 fi2126 fi
  
2130 else2127 else
2131 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'2128 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
2132 fi2129 fi
 2130 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 2131 package·--add=dracut-fips·--add=dracut-fips-aesni
2133 Group  ·Operating·System·Vendor·Support·and·Certification·  Group·contains·1·rule2132 Group  ·Operating·System·Vendor·Support·and·Certification·  Group·contains·1·rule
2134 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·assurance·of·a·vendor·to·provide·operating·system·support·and·maintenance·for·their·product·is·an·important·criterion·to·ensure·product·stability·and·security·over·the·life·of·the·product.·A·certified·product·that·follows·the·necessary·standards·and·government·certification·requirements·guarantees·that·known·software·vulnerabilities·will·be·remediated,·and·proper·guidance·for·protecting·and·securing·the·operating·system·will·be·given.2133 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·assurance·of·a·vendor·to·provide·operating·system·support·and·maintenance·for·their·product·is·an·important·criterion·to·ensure·product·stability·and·security·over·the·life·of·the·product.·A·certified·product·that·follows·the·necessary·standards·and·government·certification·requirements·guarantees·that·known·software·vulnerabilities·will·be·remediated,·and·proper·guidance·for·protecting·and·securing·the·operating·system·will·be·given.
2135 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·T\x8Th\x8he\x8e·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8le\x8ed\x8d·O\x8Op\x8pe\x8er\x8ra\x8at\x8ti\x8in\x8ng\x8g·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·I\x8Is\x8s·V\x8Ve\x8en\x8nd\x8do\x8or\x8r·S\x8Su\x8up\x8pp\x8po\x8or\x8rt\x8te\x8ed\x8d·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*2134 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·T\x8Th\x8he\x8e·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8le\x8ed\x8d·O\x8Op\x8pe\x8er\x8ra\x8at\x8ti\x8in\x8ng\x8g·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·I\x8Is\x8s·V\x8Ve\x8en\x8nd\x8do\x8or\x8r·S\x8Su\x8up\x8pp\x8po\x8or\x8rt\x8te\x8ed\x8d·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
2136 The·installed·operating·system·must·be·maintained·by·a·vendor.·Oracle·Linux·is·supported·by·Oracle·Corporation.·As·the·Oracle·Linux·vendor,·Oracle·Corporation·is·responsible·for·providing·security·patches.2135 The·installed·operating·system·must·be·maintained·by·a·vendor.·Oracle·Linux·is·supported·by·Oracle·Corporation.·As·the·Oracle·Linux·vendor,·Oracle·Corporation·is·responsible·for·providing·security·patches.
2137 Warning: ·There·is·no·remediation·besides·switching·to·a·different·operating·system.2136 Warning: ·There·is·no·remediation·besides·switching·to·a·different·operating·system.
2138 Rationale:··An·operating·system·is·considered·"supported"·if·the·vendor·continues·to·provide·security·patches·for·the·product.·With·an·unsupported·release,·it·will·not·be·possible·to·resolve·any·security·issue·discovered·in·the·system·software.2137 Rationale:··An·operating·system·is·considered·"supported"·if·the·vendor·continues·to·provide·security·patches·for·the·product.·With·an·unsupported·release,·it·will·not·be·possible·to·resolve·any·security·issue·discovered·in·the·system·software.
2139 Severity: ··high2138 Severity: ··high
Offset 16307, 21 lines modifiedOffset 16307, 14 lines modified
16307 ··-·NIST-800-53-CM-6(a)16307 ··-·NIST-800-53-CM-6(a)
16308 ··-·enable_strategy16308 ··-·enable_strategy
16309 ··-·low_complexity16309 ··-·low_complexity
16310 ··-·low_disruption16310 ··-·low_disruption
16311 ··-·medium_severity16311 ··-·medium_severity
16312 ··-·no_reboot_needed16312 ··-·no_reboot_needed
16313 ··-·package_screen_installed16313 ··-·package_screen_installed
16314 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
16315 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
16316 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
16317 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
16318 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
16319 package·--add=screen 
16320 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x816314 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
16321 [[packages]]16315 [[packages]]
16322 name·=·"screen"16316 name·=·"screen"
16323 version·=·"*"16317 version·=·"*"
16324 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x816318 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
16325 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low16319 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 16346, 14 lines modifiedOffset 16339, 21 lines modified
16346 if·!·rpm·-q·--quiet·"screen"·;·then16339 if·!·rpm·-q·--quiet·"screen"·;·then
16347 ····yum·install·-y·"screen"16340 ····yum·install·-y·"screen"
16348 fi16341 fi
  
16349 else16342 else
16350 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'16343 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
16351 fi16344 fi
 16345 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 16346 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 16347 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 16348 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 16349 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 16350 package·--add=screen
16352 Group  ·Hardware·Tokens·for·Authentication·  Group·contains·3·rules16351 Group  ·Hardware·Tokens·for·Authentication·  Group·contains·3·rules
16353 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·use·of·hardware·tokens·such·as·smart·cards·for·system·login·provides·stronger,·two-factor·authentication·than·using·a·username·and·password.·In·Oracle·Linux·7·servers,·hardware·token·login·is·not·enabled·by·default·and·must·be·enabled·in·the·system·settings.16352 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·use·of·hardware·tokens·such·as·smart·cards·for·system·login·provides·stronger,·two-factor·authentication·than·using·a·username·and·password.·In·Oracle·Linux·7·servers,·hardware·token·login·is·not·enabled·by·default·and·must·be·enabled·in·the·system·settings.
16354 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·S\x8Sm\x8ma\x8ar\x8rt\x8t·C\x8Ca\x8ar\x8rd\x8d·P\x8Pa\x8ac\x8ck\x8ka\x8ag\x8ge\x8es\x8s·F\x8Fo\x8or\x8r·M\x8Mu\x8ul\x8lt\x8ti\x8if\x8fa\x8ac\x8ct\x8to\x8or\x8r·A\x8Au\x8ut\x8th\x8he\x8en\x8nt\x8ti\x8ic\x8ca\x8at\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*16353 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·S\x8Sm\x8ma\x8ar\x8rt\x8t·C\x8Ca\x8ar\x8rd\x8d·P\x8Pa\x8ac\x8ck\x8ka\x8ag\x8ge\x8es\x8s·F\x8Fo\x8or\x8r·M\x8Mu\x8ul\x8lt\x8ti\x8if\x8fa\x8ac\x8ct\x8to\x8or\x8r·A\x8Au\x8ut\x8th\x8he\x8en\x8nt\x8ti\x8ic\x8ca\x8at\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
16355 Configure·the·operating·system·to·implement·multifactor·authentication·by·installing·the·required·package·with·the·following·command:·The·pam_pkcs11·package·can·be·installed·with·the·following·command:16354 Configure·the·operating·system·to·implement·multifactor·authentication·by·installing·the·required·package·with·the·following·command:·The·pam_pkcs11·package·can·be·installed·with·the·following·command:
16356 $·sudo·yum·install·pam_pkcs1116355 $·sudo·yum·install·pam_pkcs11
16357 ············Using·an·authentication·device,·such·as·a·CAC·or·token·that·is·separate·from·the·information·system,·ensures·that·even·if·the·information·system·is·compromised,·that·compromise·will·not·affect·credentials·stored·on·the·authentication·device.16356 ············Using·an·authentication·device,·such·as·a·CAC·or·token·that·is·separate·from·the·information·system,·ensures·that·even·if·the·information·system·is·compromised,·that·compromise·will·not·affect·credentials·stored·on·the·authentication·device.
16358 Rationale:16357 Rationale:
Offset 16398, 21 lines modifiedOffset 16398, 14 lines modified
16398 ··-·PCI-DSS-Req-8.316398 ··-·PCI-DSS-Req-8.3
16399 ··-·enable_strategy16399 ··-·enable_strategy
16400 ··-·install_smartcard_packages16400 ··-·install_smartcard_packages
Max diff block lines reached; 28708/35479 bytes (80.92%) of diff not shown.
335 KB
./usr/share/doc/ssg-nondebian/ssg-ol7-guide-stig_gui.html
    
Offset 17484, 144 lines modifiedOffset 17484, 144 lines modified
000444b0:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="000444b0:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
000444c0:·2369·646d·3536·3532·2220·7461·6269·6e64··#idm5652"·tabind000444c0:·2369·646d·3536·3532·2220·7461·6269·6e64··#idm5652"·tabind
000444d0:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but000444d0:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
000444e0:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand000444e0:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
000444f0:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title000444f0:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
00044500:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re00044500:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
00044510:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">00044510:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
 00044520:·5265·6d65·6469·6174·696f·6e20·4f53·4275··Remediation·OSBu
 00044530:·696c·6420·426c·7565·7072·696e·7420·736e··ild·Blueprint·sn
 00044540:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br
 00044550:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
 00044560:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
 00044570:·6170·7365·2220·6964·3d22·6964·6d35·3635··apse"·id="idm565
 00044580:·3222·3e3c·7072·653e·3c63·6f64·653e·0a5b··2"><pre><code>.[
 00044590:·5b70·6163·6b61·6765·735d·5d0a·6e61·6d65··[packages]].name
 000445a0:·203d·2022·6169·6465·220a·7665·7273·696f···=·"aide".versio
 000445b0:·6e20·3d20·222a·220a·3c2f·636f·6465·3e3c··n·=·"*".</code><
 000445c0:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl
 000445d0:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc
 000445e0:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl
 000445f0:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat
 00044600:·612d·7461·7267·6574·3d22·2369·646d·3536··a-target="#idm56
 00044610:·3533·2220·7461·6269·6e64·6578·3d22·3022··53"·tabindex="0"
 00044620:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
 00044630:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
 00044640:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
 00044650:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
 00044660:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
 00044670:·6174·696f·6e20·5075·7070·6574·2073·6e69··ation·Puppet·sni
 00044680:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>
 00044690:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
 000446a0:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
 000446b0:·7073·6522·2069·643d·2269·646d·3536·3533··pse"·id="idm5653
 000446c0:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="
 000446d0:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri
 000446e0:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border
 000446f0:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens
 00044700:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp
 00044710:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>
 00044720:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
 00044730:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:
 00044740:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
 00044750:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re
 00044760:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa
 00044770:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr
 00044780:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</
 00044790:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t
 000447a0:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><
 000447b0:·7072·653e·3c63·6f64·653e·696e·636c·7564··pre><code>includ
 000447c0:·6520·696e·7374·616c·6c5f·6169·6465·0a0a··e·install_aide..
 000447d0:·636c·6173·7320·696e·7374·616c·6c5f·6169··class·install_ai
 000447e0:·6465·207b·0a20·2070·6163·6b61·6765·207b··de·{.··package·{
 000447f0:·2027·6169·6465·273a·0a20·2020·2065·6e73···'aide':.····ens
 00044800:·7572·6520·3d26·6774·3b20·2769·6e73·7461··ure·=&gt;·'insta
 00044810:·6c6c·6564·272c·0a20·207d·0a7d·0a3c·2f63··lled',.··}.}.</c
 00044820:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div>
 00044830:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt
 00044840:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data-
 00044850:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse
 00044860:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
 00044870:·6964·6d35·3635·3422·2074·6162·696e·6465··idm5654"·tabinde
 00044880:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt
 00044890:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande
 000448a0:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=
 000448b0:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev
 000448c0:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R
 000448d0:·656d·6564·6961·7469·6f6e·2053·6865·6c6c··emediation·Shell
 000448e0:·2073·6372·6970·7420·e287·b23c·2f61·3e3c···script·...</a><
 000448f0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
 00044900:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
 00044910:·6c6c·6170·7365·2220·6964·3d22·6964·6d35··llapse"·id="idm5
 00044920:·3635·3422·3e3c·7461·626c·6520·636c·6173··654"><table·clas
 00044930:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s
 00044940:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor
 00044950:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond
 00044960:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C
 00044970:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><
 00044980:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
 00044990:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti
 000449a0:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<
 000449b0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 000449c0:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td
 000449d0:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr>
 000449e0:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy
 000449f0:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable
 00044a00:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl
 00044a10:·653e·3c70·7265·3e3c·636f·6465·3e23·2052··e><pre><code>#·R
 00044a20:·656d·6564·6961·7469·6f6e·2069·7320·6170··emediation·is·ap
 00044a30:·706c·6963·6162·6c65·206f·6e6c·7920·696e··plicable·only·in
 00044a40:·2063·6572·7461·696e·2070·6c61·7466·6f72···certain·platfor
 00044a50:·6d73·0a69·6620·7270·6d20·2d2d·7175·6965··ms.if·rpm·--quie
 00044a60:·7420·2d71·206b·6572·6e65·6c20·7c7c·2072··t·-q·kernel·||·r
 00044a70:·706d·202d·2d71·7569·6574·202d·7120·6b65··pm·--quiet·-q·ke
 00044a80:·726e·656c·2d75·656b·3b20·7468·656e·0a0a··rnel-uek;·then..
 00044a90:·6966·2021·2072·706d·202d·7120·2d2d·7175··if·!·rpm·-q·--qu
 00044aa0:·6965·7420·2261·6964·6522·203b·2074·6865··iet·"aide"·;·the
 00044ab0:·6e0a·2020·2020·7975·6d20·696e·7374·616c··n.····yum·instal
 00044ac0:·6c20·2d79·2022·6169·6465·220a·6669·0a0a··l·-y·"aide".fi..
 00044ad0:·656c·7365·0a20·2020·2026·6774·3b26·616d··else.····&gt;&am
 00044ae0:·703b·3220·6563·686f·2027·5265·6d65·6469··p;2·echo·'Remedi
 00044af0:·6174·696f·6e20·6973·206e·6f74·2061·7070··ation·is·not·app
 00044b00:·6c69·6361·626c·652c·206e·6f74·6869·6e67··licable,·nothing
 00044b10:·2077·6173·2064·6f6e·6527·0a66·690a·3c2f···was·done'.fi.</
 00044b20:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div
 00044b30:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b
 00044b40:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data
 00044b50:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps
 00044b60:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
 00044b70:·2369·646d·3536·3535·2220·7461·6269·6e64··#idm5655"·tabind
 00044b80:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
 00044b90:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
 00044ba0:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
 00044bb0:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
 00044bc0:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
00044520:·5265·6d65·6469·6174·696f·6e20·416e·6163··Remediation·Anac00044bd0:·5265·6d65·6469·6174·696f·6e20·416e·6163··Remediation·Anac
00044530:·6f6e·6461·2073·6e69·7070·6574·20e2·87b2··onda·snippet·...00044be0:·6f6e·6461·2073·6e69·7070·6574·20e2·87b2··onda·snippet·...
00044540:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla00044bf0:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
00044550:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap00044c00:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
00044560:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id= 
00044570:·2269·646d·3536·3532·223e·3c74·6162·6c65··"idm5652"><table 
00044580:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta 
00044590:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl 
000445a0:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table 
000445b0:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr> 
000445c0:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:< 
000445d0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td> 
000445e0:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis 
Max diff block lines reached; 291036/309556 bytes (94.02%) of diff not shown.
32.1 KB
html2text {}
    
Offset 740, 21 lines modifiedOffset 740, 14 lines modified
740 ··-·PCI-DSSv4-11.5.2740 ··-·PCI-DSSv4-11.5.2
741 ··-·enable_strategy741 ··-·enable_strategy
742 ··-·low_complexity742 ··-·low_complexity
743 ··-·low_disruption743 ··-·low_disruption
744 ··-·medium_severity744 ··-·medium_severity
745 ··-·no_reboot_needed745 ··-·no_reboot_needed
746 ··-·package_aide_installed746 ··-·package_aide_installed
747 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
748 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
749 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
750 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
751 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
752 package·--add=aide 
753 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8747 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
754 [[packages]]748 [[packages]]
755 name·=·"aide"749 name·=·"aide"
756 version·=·"*"750 version·=·"*"
757 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8751 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
758 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low752 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 779, 14 lines modifiedOffset 772, 21 lines modified
779 if·!·rpm·-q·--quiet·"aide"·;·then772 if·!·rpm·-q·--quiet·"aide"·;·then
780 ····yum·install·-y·"aide"773 ····yum·install·-y·"aide"
781 fi774 fi
  
782 else775 else
783 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'776 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
784 fi777 fi
 778 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 779 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 780 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 781 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 782 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 783 package·--add=aide
785 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*784 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
786 Run·the·following·command·to·generate·a·new·database:785 Run·the·following·command·to·generate·a·new·database:
787 $·sudo·/usr/sbin/aide·--init786 $·sudo·/usr/sbin/aide·--init
788 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:787 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
789 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz788 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
790 To·initiate·a·manual·check,·run·the·following·command:789 To·initiate·a·manual·check,·run·the·following·command:
791 $·sudo·/usr/sbin/aide·--check790 $·sudo·/usr/sbin/aide·--check
Offset 2062, 17 lines modifiedOffset 2062, 14 lines modified
2062 ··-·NIST-800-53-SC-132062 ··-·NIST-800-53-SC-13
2063 ··-·grub2_enable_fips_mode2063 ··-·grub2_enable_fips_mode
2064 ··-·high_complexity2064 ··-·high_complexity
2065 ··-·high_severity2065 ··-·high_severity
2066 ··-·medium_disruption2066 ··-·medium_disruption
2067 ··-·reboot_required2067 ··-·reboot_required
2068 ··-·restrict_strategy2068 ··-·restrict_strategy
2069 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
2070 package·--add=dracut-fips·--add=dracut-fips-aesni 
2071 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x82069 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
2072 #·Remediation·is·applicable·only·in·certain·platforms2070 #·Remediation·is·applicable·only·in·certain·platforms
2073 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek·)·&&·{·rpm·--quiet·-q·grub2-common;·};·then2071 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek·)·&&·{·rpm·--quiet·-q·grub2-common;·};·then
  
2074 #·prelink·not·installed2072 #·prelink·not·installed
2075 if·test·-e·/etc/sysconfig/prelink·-o·-e·/usr/sbin/prelink;·then2073 if·test·-e·/etc/sysconfig/prelink·-o·-e·/usr/sbin/prelink;·then
2076 ····if·grep·-q·^PRELINKING·/etc/sysconfig/prelink2074 ····if·grep·-q·^PRELINKING·/etc/sysconfig/prelink
Offset 2131, 14 lines modifiedOffset 2128, 17 lines modified
2131 »       #·Correct·the·form·of·kernel·command·line·for·each·installed·kernel·in·the·bootloader2128 »       #·Correct·the·form·of·kernel·command·line·for·each·installed·kernel·in·the·bootloader
2132 »       /sbin/grubby·--update-kernel=ALL·--args="fips=1·boot=UUID=${BOOT_UUID}"2129 »       /sbin/grubby·--update-kernel=ALL·--args="fips=1·boot=UUID=${BOOT_UUID}"
2133 fi2130 fi
  
2134 else2131 else
2135 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'2132 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
2136 fi2133 fi
 2134 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 2135 package·--add=dracut-fips·--add=dracut-fips-aesni
2137 Group  ·Operating·System·Vendor·Support·and·Certification·  Group·contains·1·rule2136 Group  ·Operating·System·Vendor·Support·and·Certification·  Group·contains·1·rule
2138 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·assurance·of·a·vendor·to·provide·operating·system·support·and·maintenance·for·their·product·is·an·important·criterion·to·ensure·product·stability·and·security·over·the·life·of·the·product.·A·certified·product·that·follows·the·necessary·standards·and·government·certification·requirements·guarantees·that·known·software·vulnerabilities·will·be·remediated,·and·proper·guidance·for·protecting·and·securing·the·operating·system·will·be·given.2137 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·assurance·of·a·vendor·to·provide·operating·system·support·and·maintenance·for·their·product·is·an·important·criterion·to·ensure·product·stability·and·security·over·the·life·of·the·product.·A·certified·product·that·follows·the·necessary·standards·and·government·certification·requirements·guarantees·that·known·software·vulnerabilities·will·be·remediated,·and·proper·guidance·for·protecting·and·securing·the·operating·system·will·be·given.
2139 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·T\x8Th\x8he\x8e·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8le\x8ed\x8d·O\x8Op\x8pe\x8er\x8ra\x8at\x8ti\x8in\x8ng\x8g·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·I\x8Is\x8s·V\x8Ve\x8en\x8nd\x8do\x8or\x8r·S\x8Su\x8up\x8pp\x8po\x8or\x8rt\x8te\x8ed\x8d·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*2138 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·T\x8Th\x8he\x8e·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8le\x8ed\x8d·O\x8Op\x8pe\x8er\x8ra\x8at\x8ti\x8in\x8ng\x8g·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·I\x8Is\x8s·V\x8Ve\x8en\x8nd\x8do\x8or\x8r·S\x8Su\x8up\x8pp\x8po\x8or\x8rt\x8te\x8ed\x8d·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
2140 The·installed·operating·system·must·be·maintained·by·a·vendor.·Oracle·Linux·is·supported·by·Oracle·Corporation.·As·the·Oracle·Linux·vendor,·Oracle·Corporation·is·responsible·for·providing·security·patches.2139 The·installed·operating·system·must·be·maintained·by·a·vendor.·Oracle·Linux·is·supported·by·Oracle·Corporation.·As·the·Oracle·Linux·vendor,·Oracle·Corporation·is·responsible·for·providing·security·patches.
2141 Warning: ·There·is·no·remediation·besides·switching·to·a·different·operating·system.2140 Warning: ·There·is·no·remediation·besides·switching·to·a·different·operating·system.
2142 Rationale:··An·operating·system·is·considered·"supported"·if·the·vendor·continues·to·provide·security·patches·for·the·product.·With·an·unsupported·release,·it·will·not·be·possible·to·resolve·any·security·issue·discovered·in·the·system·software.2141 Rationale:··An·operating·system·is·considered·"supported"·if·the·vendor·continues·to·provide·security·patches·for·the·product.·With·an·unsupported·release,·it·will·not·be·possible·to·resolve·any·security·issue·discovered·in·the·system·software.
2143 Severity: ··high2142 Severity: ··high
Offset 16311, 21 lines modifiedOffset 16311, 14 lines modified
16311 ··-·NIST-800-53-CM-6(a)16311 ··-·NIST-800-53-CM-6(a)
16312 ··-·enable_strategy16312 ··-·enable_strategy
16313 ··-·low_complexity16313 ··-·low_complexity
16314 ··-·low_disruption16314 ··-·low_disruption
16315 ··-·medium_severity16315 ··-·medium_severity
16316 ··-·no_reboot_needed16316 ··-·no_reboot_needed
16317 ··-·package_screen_installed16317 ··-·package_screen_installed
16318 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
16319 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
16320 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
16321 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
16322 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
16323 package·--add=screen 
16324 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x816318 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
16325 [[packages]]16319 [[packages]]
16326 name·=·"screen"16320 name·=·"screen"
16327 version·=·"*"16321 version·=·"*"
16328 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x816322 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
16329 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low16323 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 16350, 14 lines modifiedOffset 16343, 21 lines modified
16350 if·!·rpm·-q·--quiet·"screen"·;·then16343 if·!·rpm·-q·--quiet·"screen"·;·then
16351 ····yum·install·-y·"screen"16344 ····yum·install·-y·"screen"
16352 fi16345 fi
  
16353 else16346 else
16354 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'16347 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
16355 fi16348 fi
 16349 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 16350 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 16351 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 16352 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 16353 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 16354 package·--add=screen
16356 Group  ·Hardware·Tokens·for·Authentication·  Group·contains·3·rules16355 Group  ·Hardware·Tokens·for·Authentication·  Group·contains·3·rules
16357 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·use·of·hardware·tokens·such·as·smart·cards·for·system·login·provides·stronger,·two-factor·authentication·than·using·a·username·and·password.·In·Oracle·Linux·7·servers,·hardware·token·login·is·not·enabled·by·default·and·must·be·enabled·in·the·system·settings.16356 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·use·of·hardware·tokens·such·as·smart·cards·for·system·login·provides·stronger,·two-factor·authentication·than·using·a·username·and·password.·In·Oracle·Linux·7·servers,·hardware·token·login·is·not·enabled·by·default·and·must·be·enabled·in·the·system·settings.
16358 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·S\x8Sm\x8ma\x8ar\x8rt\x8t·C\x8Ca\x8ar\x8rd\x8d·P\x8Pa\x8ac\x8ck\x8ka\x8ag\x8ge\x8es\x8s·F\x8Fo\x8or\x8r·M\x8Mu\x8ul\x8lt\x8ti\x8if\x8fa\x8ac\x8ct\x8to\x8or\x8r·A\x8Au\x8ut\x8th\x8he\x8en\x8nt\x8ti\x8ic\x8ca\x8at\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*16357 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·S\x8Sm\x8ma\x8ar\x8rt\x8t·C\x8Ca\x8ar\x8rd\x8d·P\x8Pa\x8ac\x8ck\x8ka\x8ag\x8ge\x8es\x8s·F\x8Fo\x8or\x8r·M\x8Mu\x8ul\x8lt\x8ti\x8if\x8fa\x8ac\x8ct\x8to\x8or\x8r·A\x8Au\x8ut\x8th\x8he\x8en\x8nt\x8ti\x8ic\x8ca\x8at\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
16359 Configure·the·operating·system·to·implement·multifactor·authentication·by·installing·the·required·package·with·the·following·command:·The·pam_pkcs11·package·can·be·installed·with·the·following·command:16358 Configure·the·operating·system·to·implement·multifactor·authentication·by·installing·the·required·package·with·the·following·command:·The·pam_pkcs11·package·can·be·installed·with·the·following·command:
16360 $·sudo·yum·install·pam_pkcs1116359 $·sudo·yum·install·pam_pkcs11
16361 ············Using·an·authentication·device,·such·as·a·CAC·or·token·that·is·separate·from·the·information·system,·ensures·that·even·if·the·information·system·is·compromised,·that·compromise·will·not·affect·credentials·stored·on·the·authentication·device.16360 ············Using·an·authentication·device,·such·as·a·CAC·or·token·that·is·separate·from·the·information·system,·ensures·that·even·if·the·information·system·is·compromised,·that·compromise·will·not·affect·credentials·stored·on·the·authentication·device.
16362 Rationale:16361 Rationale:
Offset 16402, 21 lines modifiedOffset 16402, 14 lines modified
16402 ··-·PCI-DSS-Req-8.316402 ··-·PCI-DSS-Req-8.3
16403 ··-·enable_strategy16403 ··-·enable_strategy
16404 ··-·install_smartcard_packages16404 ··-·install_smartcard_packages
Max diff block lines reached; 26096/32867 bytes (79.40%) of diff not shown.
804 KB
./usr/share/doc/ssg-nondebian/ssg-ol8-guide-anssi_bp28_enhanced.html
    
Offset 15136, 144 lines modifiedOffset 15136, 144 lines modified
0003b1f0:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id0003b1f0:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
0003b200:·6d35·3639·3722·2074·6162·696e·6465·783d··m5697"·tabindex=0003b200:·6d35·3639·3722·2074·6162·696e·6465·783d··m5697"·tabindex=
0003b210:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button0003b210:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button
0003b220:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=0003b220:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=
0003b230:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A0003b230:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A
0003b240:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea0003b240:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea
0003b250:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem0003b250:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem
 0003b260:·6564·6961·7469·6f6e·204f·5342·7569·6c64··ediation·OSBuild
 0003b270:·2042·6c75·6570·7269·6e74·2073·6e69·7070···Blueprint·snipp
 0003b280:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d
 0003b290:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-
 0003b2a0:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps
 0003b2b0:·6522·2069·643d·2269·646d·3536·3937·223e··e"·id="idm5697">
 0003b2c0:·3c70·7265·3e3c·636f·6465·3e0a·5b5b·7061··<pre><code>.[[pa
 0003b2d0:·636b·6167·6573·5d5d·0a6e·616d·6520·3d20··ckages]].name·=·
 0003b2e0:·2261·6964·6522·0a76·6572·7369·6f6e·203d··"aide".version·=
 0003b2f0:·2022·2a22·0a3c·2f63·6f64·653e·3c2f·7072···"*".</code></pr
 0003b300:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class
 0003b310:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes
 0003b320:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle="
 0003b330:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t
 0003b340:·6172·6765·743d·2223·6964·6d35·3639·3822··arget="#idm5698"
 0003b350:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro
 0003b360:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria
 0003b370:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false
 0003b380:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat
 0003b390:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre
 0003b3a0:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati
 0003b3b0:·6f6e·2050·7570·7065·7420·736e·6970·7065··on·Puppet·snippe
 0003b3c0:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di
 0003b3d0:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c
 0003b3e0:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse
 0003b3f0:·2220·6964·3d22·6964·6d35·3639·3822·3e3c··"·id="idm5698"><
 0003b400:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab
 0003b410:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped
 0003b420:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·
 0003b430:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"
 0003b440:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex
 0003b450:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low
 0003b460:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
 0003b470:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t
 0003b480:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
 0003b490:·7472·3e3c·7472·3e3c·7468·3e52·6562·6f6f··tr><tr><th>Reboo
 0003b4a0:·743a·3c2f·7468·3e3c·7464·3e66·616c·7365··t:</th><td>false
 0003b4b0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
 0003b4c0:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th>
 0003b4d0:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td><
 0003b4e0:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre
 0003b4f0:·3e3c·636f·6465·3e69·6e63·6c75·6465·2069··><code>include·i
 0003b500:·6e73·7461·6c6c·5f61·6964·650a·0a63·6c61··nstall_aide..cla
 0003b510:·7373·2069·6e73·7461·6c6c·5f61·6964·6520··ss·install_aide·
 0003b520:·7b0a·2020·7061·636b·6167·6520·7b20·2761··{.··package·{·'a
 0003b530:·6964·6527·3a0a·2020·2020·656e·7375·7265··ide':.····ensure
 0003b540:·203d·2667·743b·2027·696e·7374·616c·6c65···=&gt;·'installe
 0003b550:·6427·2c0a·2020·7d0a·7d0a·3c2f·636f·6465··d',.··}.}.</code
 0003b560:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a·
 0003b570:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s
 0003b580:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog
 0003b590:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d
 0003b5a0:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
 0003b5b0:·3536·3939·2220·7461·6269·6e64·6578·3d22··5699"·tabindex="
 0003b5c0:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
 0003b5d0:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
 0003b5e0:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
 0003b5f0:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
 0003b600:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
 0003b610:·6469·6174·696f·6e20·5368·656c·6c20·7363··diation·Shell·sc
 0003b620:·7269·7074·20e2·87b2·3c2f·613e·3c62·723e··ript·...</a><br>
 0003b630:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
 0003b640:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
 0003b650:·7073·6522·2069·643d·2269·646d·3536·3939··pse"·id="idm5699
 0003b660:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="
 0003b670:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri
 0003b680:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border
 0003b690:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens
 0003b6a0:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp
 0003b6b0:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>
 0003b6c0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
 0003b6d0:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:
 0003b6e0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
 0003b6f0:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re
 0003b700:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa
 0003b710:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr
 0003b720:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</
 0003b730:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t
 0003b740:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><
 0003b750:·7072·653e·3c63·6f64·653e·2320·5265·6d65··pre><code>#·Reme
 0003b760:·6469·6174·696f·6e20·6973·2061·7070·6c69··diation·is·appli
 0003b770:·6361·626c·6520·6f6e·6c79·2069·6e20·6365··cable·only·in·ce
 0003b780:·7274·6169·6e20·706c·6174·666f·726d·730a··rtain·platforms.
 0003b790:·6966·2072·706d·202d·2d71·7569·6574·202d··if·rpm·--quiet·-
 0003b7a0:·7120·6b65·726e·656c·207c·7c20·7270·6d20··q·kernel·||·rpm·
 0003b7b0:·2d2d·7175·6965·7420·2d71·206b·6572·6e65··--quiet·-q·kerne
 0003b7c0:·6c2d·7565·6b3b·2074·6865·6e0a·0a69·6620··l-uek;·then..if·
 0003b7d0:·2120·7270·6d20·2d71·202d·2d71·7569·6574··!·rpm·-q·--quiet
 0003b7e0:·2022·6169·6465·2220·3b20·7468·656e·0a20···"aide"·;·then.·
 0003b7f0:·2020·2079·756d·2069·6e73·7461·6c6c·202d·····yum·install·-
 0003b800:·7920·2261·6964·6522·0a66·690a·0a65·6c73··y·"aide".fi..els
 0003b810:·650a·2020·2020·2667·743b·2661·6d70·3b32··e.····&gt;&amp;2
 0003b820:·2065·6368·6f20·2752·656d·6564·6961·7469···echo·'Remediati
 0003b830:·6f6e·2069·7320·6e6f·7420·6170·706c·6963··on·is·not·applic
 0003b840:·6162·6c65·2c20·6e6f·7468·696e·6720·7761··able,·nothing·wa
 0003b850:·7320·646f·6e65·270a·6669·0a3c·2f63·6f64··s·done'.fi.</cod
 0003b860:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a
 0003b870:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn-
 0003b880:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to
 0003b890:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"·
 0003b8a0:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
 0003b8b0:·6d35·3730·3022·2074·6162·696e·6465·783d··m5700"·tabindex=
 0003b8c0:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button
 0003b8d0:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=
 0003b8e0:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A
 0003b8f0:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea
 0003b900:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem
0003b260:·6564·6961·7469·6f6e·2041·6e61·636f·6e64··ediation·Anacond0003b910:·6564·6961·7469·6f6e·2041·6e61·636f·6e64··ediation·Anacond
0003b270:·6120·736e·6970·7065·7420·e287·b23c·2f61··a·snippet·...</a0003b920:·6120·736e·6970·7065·7420·e287·b23c·2f61··a·snippet·...</a
0003b280:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=0003b930:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
0003b290:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·0003b940:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
0003b2a0:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id0003b950:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
0003b2b0:·6d35·3639·3722·3e3c·7461·626c·6520·636c··m5697"><table·cl0003b960:·6d35·3730·3022·3e3c·7461·626c·6520·636c··m5700"><table·cl
0003b2c0:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table0003b970:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table
0003b2d0:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b0003b980:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b
0003b2e0:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co0003b990:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co
0003b2f0:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th0003b9a0:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th
0003b300:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th0003b9b0:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th
0003b310:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t0003b9c0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
0003b320:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup0003b9d0:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup
Max diff block lines reached; 740136/758656 bytes (97.56%) of diff not shown.
62.7 KB
html2text {}
    
Offset 154, 21 lines modifiedOffset 154, 14 lines modified
154 ··-·PCI-DSSv4-11.5.2154 ··-·PCI-DSSv4-11.5.2
155 ··-·enable_strategy155 ··-·enable_strategy
156 ··-·low_complexity156 ··-·low_complexity
157 ··-·low_disruption157 ··-·low_disruption
158 ··-·medium_severity158 ··-·medium_severity
159 ··-·no_reboot_needed159 ··-·no_reboot_needed
160 ··-·package_aide_installed160 ··-·package_aide_installed
161 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
162 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
163 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
164 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
165 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
166 package·--add=aide 
167 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8161 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
168 [[packages]]162 [[packages]]
169 name·=·"aide"163 name·=·"aide"
170 version·=·"*"164 version·=·"*"
171 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8165 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
172 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low166 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 193, 14 lines modifiedOffset 186, 21 lines modified
193 if·!·rpm·-q·--quiet·"aide"·;·then186 if·!·rpm·-q·--quiet·"aide"·;·then
194 ····yum·install·-y·"aide"187 ····yum·install·-y·"aide"
195 fi188 fi
  
196 else189 else
197 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'190 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
198 fi191 fi
 192 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 193 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 194 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 195 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 196 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 197 package·--add=aide
199 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*198 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
200 Run·the·following·command·to·generate·a·new·database:199 Run·the·following·command·to·generate·a·new·database:
201 $·sudo·/usr/sbin/aide·--init200 $·sudo·/usr/sbin/aide·--init
202 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the201 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the
203 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these202 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these
204 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their203 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their
205 integrity.·The·newly-generated·database·can·be·installed·as·follows:204 integrity.·The·newly-generated·database·can·be·installed·as·follows:
Offset 602, 21 lines modifiedOffset 602, 14 lines modified
602 ··tags:602 ··tags:
603 ··-·enable_strategy603 ··-·enable_strategy
604 ··-·low_complexity604 ··-·low_complexity
605 ··-·low_disruption605 ··-·low_disruption
606 ··-·low_severity606 ··-·low_severity
607 ··-·no_reboot_needed607 ··-·no_reboot_needed
608 ··-·systemd_tmp_mount_enabled608 ··-·systemd_tmp_mount_enabled
609 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
610 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
611 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
612 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
613 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
614 services·--enabled=tmp.mount 
615 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8609 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
616 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low610 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
617 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low611 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
618 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false612 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
619 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable613 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
620 #·Remediation·is·applicable·only·in·certain·platforms614 #·Remediation·is·applicable·only·in·certain·platforms
621 if·(·!·(·{·rpm·--quiet·-q·kernel·;}·&&·{·rpm·--quiet·-q·rpm-ostree·;}·&&·{·rpm·--quiet·-q·bootc·;}·&&615 if·(·!·(·{·rpm·--quiet·-q·kernel·;}·&&·{·rpm·--quiet·-q·rpm-ostree·;}·&&·{·rpm·--quiet·-q·bootc·;}·&&
Offset 629, 14 lines modifiedOffset 622, 21 lines modified
629 ··"$SYSTEMCTL_EXEC"·start·'tmp.mount'622 ··"$SYSTEMCTL_EXEC"·start·'tmp.mount'
630 fi623 fi
631 "$SYSTEMCTL_EXEC"·enable·'tmp.mount'624 "$SYSTEMCTL_EXEC"·enable·'tmp.mount'
  
632 else625 else
633 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'626 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
634 fi627 fi
 628 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 629 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 630 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 631 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 632 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 633 services·--enabled=tmp.mount
635 Group  ·Sudo·  Group·contains·18·rules634 Group  ·Sudo·  Group·contains·18·rules
636 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Sudo,·which·stands·for·"su·'do'",·provides·the·ability·to·delegate·authority·to·certain635 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Sudo,·which·stands·for·"su·'do'",·provides·the·ability·to·delegate·authority·to·certain
637 users,·groups·of·users,·or·system·administrators.·When·configured·for·system·users·and/or·groups,636 users,·groups·of·users,·or·system·administrators.·When·configured·for·system·users·and/or·groups,
638 Sudo·can·allow·a·user·or·group·to·execute·privileged·commands·that·normally·only·root·is·allowed·to637 Sudo·can·allow·a·user·or·group·to·execute·privileged·commands·that·normally·only·root·is·allowed·to
639 execute.638 execute.
  
640 For·more·information·on·Sudo·and·addition·Sudo·configuration·options,·see·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8w\x8w_\x8w\x8w_\x8w\x8w_\x8.\x8._\x8s\x8s_\x8u\x8u_\x8d\x8d_\x8o\x8o_\x8.\x8._\x8w\x8w_\x8s\x8s.639 For·more·information·on·Sudo·and·addition·Sudo·configuration·options,·see·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8w\x8w_\x8w\x8w_\x8w\x8w_\x8.\x8._\x8s\x8s_\x8u\x8u_\x8d\x8d_\x8o\x8o_\x8.\x8._\x8w\x8w_\x8s\x8s.
Offset 685, 21 lines modifiedOffset 685, 14 lines modified
685 ··-·PCI-DSSv4-2.2.6685 ··-·PCI-DSSv4-2.2.6
686 ··-·enable_strategy686 ··-·enable_strategy
687 ··-·low_complexity687 ··-·low_complexity
688 ··-·low_disruption688 ··-·low_disruption
689 ··-·medium_severity689 ··-·medium_severity
690 ··-·no_reboot_needed690 ··-·no_reboot_needed
691 ··-·package_sudo_installed691 ··-·package_sudo_installed
692 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
693 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
694 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
695 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
696 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
697 package·--add=sudo 
698 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8692 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
699 [[packages]]693 [[packages]]
700 name·=·"sudo"694 name·=·"sudo"
701 version·=·"*"695 version·=·"*"
702 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8696 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
703 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low697 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 724, 14 lines modifiedOffset 717, 21 lines modified
724 if·!·rpm·-q·--quiet·"sudo"·;·then717 if·!·rpm·-q·--quiet·"sudo"·;·then
725 ····yum·install·-y·"sudo"718 ····yum·install·-y·"sudo"
726 fi719 fi
  
727 else720 else
728 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'721 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
729 fi722 fi
 723 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 724 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 725 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 726 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 727 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 728 package·--add=sudo
730 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·G\x8Gr\x8ro\x8ou\x8up\x8p·W\x8Wh\x8ho\x8o·O\x8Ow\x8wn\x8ns\x8s·/\x8/e\x8et\x8tc\x8c/\x8/s\x8su\x8ud\x8do\x8oe\x8er\x8rs\x8s.\x8.d\x8d·D\x8Di\x8ir\x8re\x8ec\x8ct\x8to\x8or\x8ry\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*729 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·G\x8Gr\x8ro\x8ou\x8up\x8p·W\x8Wh\x8ho\x8o·O\x8Ow\x8wn\x8ns\x8s·/\x8/e\x8et\x8tc\x8c/\x8/s\x8su\x8ud\x8do\x8oe\x8er\x8rs\x8s.\x8.d\x8d·D\x8Di\x8ir\x8re\x8ec\x8ct\x8to\x8or\x8ry\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
731 To·properly·set·the·group·owner·of·/etc/sudoers.d,·run·the·command:730 To·properly·set·the·group·owner·of·/etc/sudoers.d,·run·the·command:
732 $·sudo·chgrp·root·/etc/sudoers.d731 $·sudo·chgrp·root·/etc/sudoers.d
Max diff block lines reached; 59050/64175 bytes (92.01%) of diff not shown.
865 KB
./usr/share/doc/ssg-nondebian/ssg-ol8-guide-anssi_bp28_high.html
    
Offset 15141, 144 lines modifiedOffset 15141, 144 lines modified
0003b240:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="0003b240:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
0003b250:·2369·646d·3536·3937·2220·7461·6269·6e64··#idm5697"·tabind0003b250:·2369·646d·3536·3937·2220·7461·6269·6e64··#idm5697"·tabind
0003b260:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but0003b260:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
0003b270:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand0003b270:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
0003b280:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title0003b280:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
0003b290:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re0003b290:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
0003b2a0:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">0003b2a0:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
 0003b2b0:·5265·6d65·6469·6174·696f·6e20·4f53·4275··Remediation·OSBu
 0003b2c0:·696c·6420·426c·7565·7072·696e·7420·736e··ild·Blueprint·sn
 0003b2d0:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br
 0003b2e0:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
 0003b2f0:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
 0003b300:·6170·7365·2220·6964·3d22·6964·6d35·3639··apse"·id="idm569
 0003b310:·3722·3e3c·7072·653e·3c63·6f64·653e·0a5b··7"><pre><code>.[
 0003b320:·5b70·6163·6b61·6765·735d·5d0a·6e61·6d65··[packages]].name
 0003b330:·203d·2022·6169·6465·220a·7665·7273·696f···=·"aide".versio
 0003b340:·6e20·3d20·222a·220a·3c2f·636f·6465·3e3c··n·=·"*".</code><
 0003b350:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl
 0003b360:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc
 0003b370:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl
 0003b380:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat
 0003b390:·612d·7461·7267·6574·3d22·2369·646d·3536··a-target="#idm56
 0003b3a0:·3938·2220·7461·6269·6e64·6578·3d22·3022··98"·tabindex="0"
 0003b3b0:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
 0003b3c0:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
 0003b3d0:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
 0003b3e0:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
 0003b3f0:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
 0003b400:·6174·696f·6e20·5075·7070·6574·2073·6e69··ation·Puppet·sni
 0003b410:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>
 0003b420:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
 0003b430:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
 0003b440:·7073·6522·2069·643d·2269·646d·3536·3938··pse"·id="idm5698
 0003b450:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="
 0003b460:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri
 0003b470:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border
 0003b480:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens
 0003b490:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp
 0003b4a0:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>
 0003b4b0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
 0003b4c0:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:
 0003b4d0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
 0003b4e0:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re
 0003b4f0:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa
 0003b500:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr
 0003b510:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</
 0003b520:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t
 0003b530:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><
 0003b540:·7072·653e·3c63·6f64·653e·696e·636c·7564··pre><code>includ
 0003b550:·6520·696e·7374·616c·6c5f·6169·6465·0a0a··e·install_aide..
 0003b560:·636c·6173·7320·696e·7374·616c·6c5f·6169··class·install_ai
 0003b570:·6465·207b·0a20·2070·6163·6b61·6765·207b··de·{.··package·{
 0003b580:·2027·6169·6465·273a·0a20·2020·2065·6e73···'aide':.····ens
 0003b590:·7572·6520·3d26·6774·3b20·2769·6e73·7461··ure·=&gt;·'insta
 0003b5a0:·6c6c·6564·272c·0a20·207d·0a7d·0a3c·2f63··lled',.··}.}.</c
 0003b5b0:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div>
 0003b5c0:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt
 0003b5d0:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data-
 0003b5e0:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse
 0003b5f0:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
 0003b600:·6964·6d35·3639·3922·2074·6162·696e·6465··idm5699"·tabinde
 0003b610:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt
 0003b620:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande
 0003b630:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=
 0003b640:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev
 0003b650:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R
 0003b660:·656d·6564·6961·7469·6f6e·2053·6865·6c6c··emediation·Shell
 0003b670:·2073·6372·6970·7420·e287·b23c·2f61·3e3c···script·...</a><
 0003b680:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
 0003b690:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
 0003b6a0:·6c6c·6170·7365·2220·6964·3d22·6964·6d35··llapse"·id="idm5
 0003b6b0:·3639·3922·3e3c·7461·626c·6520·636c·6173··699"><table·clas
 0003b6c0:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s
 0003b6d0:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor
 0003b6e0:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond
 0003b6f0:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C
 0003b700:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><
 0003b710:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
 0003b720:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti
 0003b730:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<
 0003b740:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 0003b750:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td
 0003b760:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr>
 0003b770:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy
 0003b780:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable
 0003b790:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl
 0003b7a0:·653e·3c70·7265·3e3c·636f·6465·3e23·2052··e><pre><code>#·R
 0003b7b0:·656d·6564·6961·7469·6f6e·2069·7320·6170··emediation·is·ap
 0003b7c0:·706c·6963·6162·6c65·206f·6e6c·7920·696e··plicable·only·in
 0003b7d0:·2063·6572·7461·696e·2070·6c61·7466·6f72···certain·platfor
 0003b7e0:·6d73·0a69·6620·7270·6d20·2d2d·7175·6965··ms.if·rpm·--quie
 0003b7f0:·7420·2d71·206b·6572·6e65·6c20·7c7c·2072··t·-q·kernel·||·r
 0003b800:·706d·202d·2d71·7569·6574·202d·7120·6b65··pm·--quiet·-q·ke
 0003b810:·726e·656c·2d75·656b·3b20·7468·656e·0a0a··rnel-uek;·then..
 0003b820:·6966·2021·2072·706d·202d·7120·2d2d·7175··if·!·rpm·-q·--qu
 0003b830:·6965·7420·2261·6964·6522·203b·2074·6865··iet·"aide"·;·the
 0003b840:·6e0a·2020·2020·7975·6d20·696e·7374·616c··n.····yum·instal
 0003b850:·6c20·2d79·2022·6169·6465·220a·6669·0a0a··l·-y·"aide".fi..
 0003b860:·656c·7365·0a20·2020·2026·6774·3b26·616d··else.····&gt;&am
 0003b870:·703b·3220·6563·686f·2027·5265·6d65·6469··p;2·echo·'Remedi
 0003b880:·6174·696f·6e20·6973·206e·6f74·2061·7070··ation·is·not·app
 0003b890:·6c69·6361·626c·652c·206e·6f74·6869·6e67··licable,·nothing
 0003b8a0:·2077·6173·2064·6f6e·6527·0a66·690a·3c2f···was·done'.fi.</
 0003b8b0:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div
 0003b8c0:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b
 0003b8d0:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data
 0003b8e0:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps
 0003b8f0:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
 0003b900:·2369·646d·3537·3030·2220·7461·6269·6e64··#idm5700"·tabind
 0003b910:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
 0003b920:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
 0003b930:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
 0003b940:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
 0003b950:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
0003b2b0:·5265·6d65·6469·6174·696f·6e20·416e·6163··Remediation·Anac0003b960:·5265·6d65·6469·6174·696f·6e20·416e·6163··Remediation·Anac
0003b2c0:·6f6e·6461·2073·6e69·7070·6574·20e2·87b2··onda·snippet·...0003b970:·6f6e·6461·2073·6e69·7070·6574·20e2·87b2··onda·snippet·...
0003b2d0:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla0003b980:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
0003b2e0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap0003b990:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
0003b2f0:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=0003b9a0:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
0003b300:·2269·646d·3536·3937·223e·3c74·6162·6c65··"idm5697"><table0003b9b0:·2269·646d·3537·3030·223e·3c74·6162·6c65··"idm5700"><table
0003b310:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta0003b9c0:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta
0003b320:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl0003b9d0:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl
0003b330:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table 
0003b340:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr> 
0003b350:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:< 
0003b360:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td> 
0003b370:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis 
Max diff block lines reached; 796944/815464 bytes (97.73%) of diff not shown.
68.0 KB
html2text {}
    
Offset 155, 21 lines modifiedOffset 155, 14 lines modified
155 ··-·PCI-DSSv4-11.5.2155 ··-·PCI-DSSv4-11.5.2
156 ··-·enable_strategy156 ··-·enable_strategy
157 ··-·low_complexity157 ··-·low_complexity
158 ··-·low_disruption158 ··-·low_disruption
159 ··-·medium_severity159 ··-·medium_severity
160 ··-·no_reboot_needed160 ··-·no_reboot_needed
161 ··-·package_aide_installed161 ··-·package_aide_installed
162 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
163 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
164 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
165 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
166 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
167 package·--add=aide 
168 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8162 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
169 [[packages]]163 [[packages]]
170 name·=·"aide"164 name·=·"aide"
171 version·=·"*"165 version·=·"*"
172 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8166 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
173 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low167 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 194, 14 lines modifiedOffset 187, 21 lines modified
194 if·!·rpm·-q·--quiet·"aide"·;·then187 if·!·rpm·-q·--quiet·"aide"·;·then
195 ····yum·install·-y·"aide"188 ····yum·install·-y·"aide"
196 fi189 fi
  
197 else190 else
198 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'191 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
199 fi192 fi
 193 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 194 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 195 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 196 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 197 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 198 package·--add=aide
200 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*199 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
201 Run·the·following·command·to·generate·a·new·database:200 Run·the·following·command·to·generate·a·new·database:
202 $·sudo·/usr/sbin/aide·--init201 $·sudo·/usr/sbin/aide·--init
203 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the202 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the
204 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these203 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these
205 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their204 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their
206 integrity.·The·newly-generated·database·can·be·installed·as·follows:205 integrity.·The·newly-generated·database·can·be·installed·as·follows:
Offset 1155, 21 lines modifiedOffset 1155, 14 lines modified
1155 ··tags:1155 ··tags:
1156 ··-·enable_strategy1156 ··-·enable_strategy
1157 ··-·low_complexity1157 ··-·low_complexity
1158 ··-·low_disruption1158 ··-·low_disruption
1159 ··-·low_severity1159 ··-·low_severity
1160 ··-·no_reboot_needed1160 ··-·no_reboot_needed
1161 ··-·systemd_tmp_mount_enabled1161 ··-·systemd_tmp_mount_enabled
1162 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
1163 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
1164 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
1165 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
1166 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
1167 services·--enabled=tmp.mount 
1168 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81162 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1169 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1163 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1170 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1164 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1171 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1165 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1172 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1166 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1173 #·Remediation·is·applicable·only·in·certain·platforms1167 #·Remediation·is·applicable·only·in·certain·platforms
1174 if·(·!·(·{·rpm·--quiet·-q·kernel·;}·&&·{·rpm·--quiet·-q·rpm-ostree·;}·&&·{·rpm·--quiet·-q·bootc·;}·&&1168 if·(·!·(·{·rpm·--quiet·-q·kernel·;}·&&·{·rpm·--quiet·-q·rpm-ostree·;}·&&·{·rpm·--quiet·-q·bootc·;}·&&
Offset 1182, 14 lines modifiedOffset 1175, 21 lines modified
1182 ··"$SYSTEMCTL_EXEC"·start·'tmp.mount'1175 ··"$SYSTEMCTL_EXEC"·start·'tmp.mount'
1183 fi1176 fi
1184 "$SYSTEMCTL_EXEC"·enable·'tmp.mount'1177 "$SYSTEMCTL_EXEC"·enable·'tmp.mount'
  
1185 else1178 else
1186 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'1179 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
1187 fi1180 fi
 1181 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 1182 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1183 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1184 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1185 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 1186 services·--enabled=tmp.mount
1188 Group  ·Sudo·  Group·contains·18·rules1187 Group  ·Sudo·  Group·contains·18·rules
1189 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Sudo,·which·stands·for·"su·'do'",·provides·the·ability·to·delegate·authority·to·certain1188 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Sudo,·which·stands·for·"su·'do'",·provides·the·ability·to·delegate·authority·to·certain
1190 users,·groups·of·users,·or·system·administrators.·When·configured·for·system·users·and/or·groups,1189 users,·groups·of·users,·or·system·administrators.·When·configured·for·system·users·and/or·groups,
1191 Sudo·can·allow·a·user·or·group·to·execute·privileged·commands·that·normally·only·root·is·allowed·to1190 Sudo·can·allow·a·user·or·group·to·execute·privileged·commands·that·normally·only·root·is·allowed·to
1192 execute.1191 execute.
  
1193 For·more·information·on·Sudo·and·addition·Sudo·configuration·options,·see·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8w\x8w_\x8w\x8w_\x8w\x8w_\x8.\x8._\x8s\x8s_\x8u\x8u_\x8d\x8d_\x8o\x8o_\x8.\x8._\x8w\x8w_\x8s\x8s.1192 For·more·information·on·Sudo·and·addition·Sudo·configuration·options,·see·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8w\x8w_\x8w\x8w_\x8w\x8w_\x8.\x8._\x8s\x8s_\x8u\x8u_\x8d\x8d_\x8o\x8o_\x8.\x8._\x8w\x8w_\x8s\x8s.
Offset 1238, 21 lines modifiedOffset 1238, 14 lines modified
1238 ··-·PCI-DSSv4-2.2.61238 ··-·PCI-DSSv4-2.2.6
1239 ··-·enable_strategy1239 ··-·enable_strategy
1240 ··-·low_complexity1240 ··-·low_complexity
1241 ··-·low_disruption1241 ··-·low_disruption
1242 ··-·medium_severity1242 ··-·medium_severity
1243 ··-·no_reboot_needed1243 ··-·no_reboot_needed
1244 ··-·package_sudo_installed1244 ··-·package_sudo_installed
1245 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
1246 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
1247 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
1248 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
1249 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
1250 package·--add=sudo 
1251 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81245 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
1252 [[packages]]1246 [[packages]]
1253 name·=·"sudo"1247 name·=·"sudo"
1254 version·=·"*"1248 version·=·"*"
1255 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81249 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1256 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1250 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 1277, 14 lines modifiedOffset 1270, 21 lines modified
1277 if·!·rpm·-q·--quiet·"sudo"·;·then1270 if·!·rpm·-q·--quiet·"sudo"·;·then
1278 ····yum·install·-y·"sudo"1271 ····yum·install·-y·"sudo"
1279 fi1272 fi
  
1280 else1273 else
1281 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'1274 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
1282 fi1275 fi
 1276 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 1277 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1278 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1279 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1280 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 1281 package·--add=sudo
1283 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·G\x8Gr\x8ro\x8ou\x8up\x8p·W\x8Wh\x8ho\x8o·O\x8Ow\x8wn\x8ns\x8s·/\x8/e\x8et\x8tc\x8c/\x8/s\x8su\x8ud\x8do\x8oe\x8er\x8rs\x8s.\x8.d\x8d·D\x8Di\x8ir\x8re\x8ec\x8ct\x8to\x8or\x8ry\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*1282 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·G\x8Gr\x8ro\x8ou\x8up\x8p·W\x8Wh\x8ho\x8o·O\x8Ow\x8wn\x8ns\x8s·/\x8/e\x8et\x8tc\x8c/\x8/s\x8su\x8ud\x8do\x8oe\x8er\x8rs\x8s.\x8.d\x8d·D\x8Di\x8ir\x8re\x8ec\x8ct\x8to\x8or\x8ry\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
1284 To·properly·set·the·group·owner·of·/etc/sudoers.d,·run·the·command:1283 To·properly·set·the·group·owner·of·/etc/sudoers.d,·run·the·command:
1285 $·sudo·chgrp·root·/etc/sudoers.d1284 $·sudo·chgrp·root·/etc/sudoers.d
Max diff block lines reached; 64507/69640 bytes (92.63%) of diff not shown.
742 KB
./usr/share/doc/ssg-nondebian/ssg-ol8-guide-anssi_bp28_intermediary.html
    
Offset 15132, 143 lines modifiedOffset 15132, 143 lines modified
0003b1b0:·612d·7461·7267·6574·3d22·2369·646d·3536··a-target="#idm560003b1b0:·612d·7461·7267·6574·3d22·2369·646d·3536··a-target="#idm56
0003b1c0:·3937·2220·7461·6269·6e64·6578·3d22·3022··97"·tabindex="0"0003b1c0:·3937·2220·7461·6269·6e64·6578·3d22·3022··97"·tabindex="0"
0003b1d0:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a0003b1d0:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
0003b1e0:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa0003b1e0:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
0003b1f0:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti0003b1f0:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
0003b200:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·0003b200:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
0003b210:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi0003b210:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
 0003b220:·6174·696f·6e20·4f53·4275·696c·6420·426c··ation·OSBuild·Bl
 0003b230:·7565·7072·696e·7420·736e·6970·7065·7420··ueprint·snippet·
 0003b240:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·
 0003b250:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col
 0003b260:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·
 0003b270:·6964·3d22·6964·6d35·3639·3722·3e3c·7072··id="idm5697"><pr
 0003b280:·653e·3c63·6f64·653e·0a5b·5b70·6163·6b61··e><code>.[[packa
 0003b290:·6765·735d·5d0a·6e61·6d65·203d·2022·6169··ges]].name·=·"ai
 0003b2a0:·6465·220a·7665·7273·696f·6e20·3d20·222a··de".version·=·"*
 0003b2b0:·220a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··".</code></pre><
 0003b2c0:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b
 0003b2d0:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"·
 0003b2e0:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col
 0003b2f0:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ
 0003b300:·6574·3d22·2369·646d·3536·3938·2220·7461··et="#idm5698"·ta
 0003b310:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
 0003b320:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
 0003b330:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
 0003b340:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
 0003b350:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
 0003b360:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
 0003b370:·5075·7070·6574·2073·6e69·7070·6574·20e2··Puppet·snippet·.
 0003b380:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c
 0003b390:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
 0003b3a0:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
 0003b3b0:·643d·2269·646d·3536·3938·223e·3c74·6162··d="idm5698"><tab
 0003b3c0:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·
 0003b3d0:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta
 0003b3e0:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab
 0003b3f0:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t
 0003b400:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity
 0003b410:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
 0003b420:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D
 0003b430:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><
 0003b440:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
 0003b450:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:<
 0003b460:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t
 0003b470:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S
 0003b480:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td
 0003b490:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr
 0003b4a0:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c
 0003b4b0:·6f64·653e·696e·636c·7564·6520·696e·7374··ode>include·inst
 0003b4c0:·616c·6c5f·6169·6465·0a0a·636c·6173·7320··all_aide..class·
 0003b4d0:·696e·7374·616c·6c5f·6169·6465·207b·0a20··install_aide·{.·
 0003b4e0:·2070·6163·6b61·6765·207b·2027·6169·6465···package·{·'aide
 0003b4f0:·273a·0a20·2020·2065·6e73·7572·6520·3d26··':.····ensure·=&
 0003b500:·6774·3b20·2769·6e73·7461·6c6c·6564·272c··gt;·'installed',
 0003b510:·0a20·207d·0a7d·0a3c·2f63·6f64·653e·3c2f··.··}.}.</code></
 0003b520:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla
 0003b530:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ
 0003b540:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle
 0003b550:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data
 0003b560:·2d74·6172·6765·743d·2223·6964·6d35·3639··-target="#idm569
 0003b570:·3922·2074·6162·696e·6465·783d·2230·2220··9"·tabindex="0"·
 0003b580:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar
 0003b590:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal
 0003b5a0:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ
 0003b5b0:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h
 0003b5c0:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia
 0003b5d0:·7469·6f6e·2053·6865·6c6c·2073·6372·6970··tion·Shell·scrip
 0003b5e0:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di
 0003b5f0:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c
 0003b600:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse
 0003b610:·2220·6964·3d22·6964·6d35·3639·3922·3e3c··"·id="idm5699"><
 0003b620:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab
 0003b630:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped
 0003b640:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·
 0003b650:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"
 0003b660:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex
 0003b670:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low
 0003b680:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
 0003b690:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t
 0003b6a0:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
 0003b6b0:·7472·3e3c·7472·3e3c·7468·3e52·6562·6f6f··tr><tr><th>Reboo
 0003b6c0:·743a·3c2f·7468·3e3c·7464·3e66·616c·7365··t:</th><td>false
 0003b6d0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
 0003b6e0:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th>
 0003b6f0:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td><
 0003b700:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre
 0003b710:·3e3c·636f·6465·3e23·2052·656d·6564·6961··><code>#·Remedia
 0003b720:·7469·6f6e·2069·7320·6170·706c·6963·6162··tion·is·applicab
 0003b730:·6c65·206f·6e6c·7920·696e·2063·6572·7461··le·only·in·certa
 0003b740:·696e·2070·6c61·7466·6f72·6d73·0a69·6620··in·platforms.if·
 0003b750:·7270·6d20·2d2d·7175·6965·7420·2d71·206b··rpm·--quiet·-q·k
 0003b760:·6572·6e65·6c20·7c7c·2072·706d·202d·2d71··ernel·||·rpm·--q
 0003b770:·7569·6574·202d·7120·6b65·726e·656c·2d75··uiet·-q·kernel-u
 0003b780:·656b·3b20·7468·656e·0a0a·6966·2021·2072··ek;·then..if·!·r
 0003b790:·706d·202d·7120·2d2d·7175·6965·7420·2261··pm·-q·--quiet·"a
 0003b7a0:·6964·6522·203b·2074·6865·6e0a·2020·2020··ide"·;·then.····
 0003b7b0:·7975·6d20·696e·7374·616c·6c20·2d79·2022··yum·install·-y·"
 0003b7c0:·6169·6465·220a·6669·0a0a·656c·7365·0a20··aide".fi..else.·
 0003b7d0:·2020·2026·6774·3b26·616d·703b·3220·6563·····&gt;&amp;2·ec
 0003b7e0:·686f·2027·5265·6d65·6469·6174·696f·6e20··ho·'Remediation·
 0003b7f0:·6973·206e·6f74·2061·7070·6c69·6361·626c··is·not·applicabl
 0003b800:·652c·206e·6f74·6869·6e67·2077·6173·2064··e,·nothing·was·d
 0003b810:·6f6e·6527·0a66·690a·3c2f·636f·6465·3e3c··one'.fi.</code><
 0003b820:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl
 0003b830:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc
 0003b840:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl
 0003b850:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat
 0003b860:·612d·7461·7267·6574·3d22·2369·646d·3537··a-target="#idm57
 0003b870:·3030·2220·7461·6269·6e64·6578·3d22·3022··00"·tabindex="0"
 0003b880:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
 0003b890:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
 0003b8a0:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
 0003b8b0:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
 0003b8c0:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
0003b220:·6174·696f·6e20·416e·6163·6f6e·6461·2073··ation·Anaconda·s0003b8d0:·6174·696f·6e20·416e·6163·6f6e·6461·2073··ation·Anaconda·s
0003b230:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b0003b8e0:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b
0003b240:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa0003b8f0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
0003b250:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col0003b900:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
0003b260:·6c61·7073·6522·2069·643d·2269·646d·3536··lapse"·id="idm560003b910:·6c61·7073·6522·2069·643d·2269·646d·3537··lapse"·id="idm57
0003b270:·3937·223e·3c74·6162·6c65·2063·6c61·7373··97"><table·class0003b920:·3030·223e·3c74·6162·6c65·2063·6c61·7373··00"><table·class
0003b280:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st0003b930:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st
0003b290:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord0003b940:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord
0003b2a0:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde0003b950:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde
0003b2b0:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co 
0003b2c0:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t 
0003b2d0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr>< 
0003b2e0:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio 
Max diff block lines reached; 682642/701024 bytes (97.38%) of diff not shown.
57.7 KB
html2text {}
    
Offset 153, 21 lines modifiedOffset 153, 14 lines modified
153 ··-·PCI-DSSv4-11.5.2153 ··-·PCI-DSSv4-11.5.2
154 ··-·enable_strategy154 ··-·enable_strategy
155 ··-·low_complexity155 ··-·low_complexity
156 ··-·low_disruption156 ··-·low_disruption
157 ··-·medium_severity157 ··-·medium_severity
158 ··-·no_reboot_needed158 ··-·no_reboot_needed
159 ··-·package_aide_installed159 ··-·package_aide_installed
160 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
161 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
162 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
163 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
164 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
165 package·--add=aide 
166 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8160 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
167 [[packages]]161 [[packages]]
168 name·=·"aide"162 name·=·"aide"
169 version·=·"*"163 version·=·"*"
170 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8164 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
171 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low165 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 192, 14 lines modifiedOffset 185, 21 lines modified
192 if·!·rpm·-q·--quiet·"aide"·;·then185 if·!·rpm·-q·--quiet·"aide"·;·then
193 ····yum·install·-y·"aide"186 ····yum·install·-y·"aide"
194 fi187 fi
  
195 else188 else
196 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'189 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
197 fi190 fi
 191 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 192 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 193 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 194 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 195 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 196 package·--add=aide
198 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*197 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
199 Run·the·following·command·to·generate·a·new·database:198 Run·the·following·command·to·generate·a·new·database:
200 $·sudo·/usr/sbin/aide·--init199 $·sudo·/usr/sbin/aide·--init
201 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the200 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the
202 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these201 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these
203 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their202 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their
204 integrity.·The·newly-generated·database·can·be·installed·as·follows:203 integrity.·The·newly-generated·database·can·be·installed·as·follows:
Offset 566, 21 lines modifiedOffset 566, 14 lines modified
566 ··tags:566 ··tags:
567 ··-·enable_strategy567 ··-·enable_strategy
568 ··-·low_complexity568 ··-·low_complexity
569 ··-·low_disruption569 ··-·low_disruption
570 ··-·low_severity570 ··-·low_severity
571 ··-·no_reboot_needed571 ··-·no_reboot_needed
572 ··-·systemd_tmp_mount_enabled572 ··-·systemd_tmp_mount_enabled
573 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
574 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
575 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
576 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
577 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
578 services·--enabled=tmp.mount 
579 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8573 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
580 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low574 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
581 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low575 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
582 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false576 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
583 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable577 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
584 #·Remediation·is·applicable·only·in·certain·platforms578 #·Remediation·is·applicable·only·in·certain·platforms
585 if·(·!·(·{·rpm·--quiet·-q·kernel·;}·&&·{·rpm·--quiet·-q·rpm-ostree·;}·&&·{·rpm·--quiet·-q·bootc·;}·&&579 if·(·!·(·{·rpm·--quiet·-q·kernel·;}·&&·{·rpm·--quiet·-q·rpm-ostree·;}·&&·{·rpm·--quiet·-q·bootc·;}·&&
Offset 593, 14 lines modifiedOffset 586, 21 lines modified
593 ··"$SYSTEMCTL_EXEC"·start·'tmp.mount'586 ··"$SYSTEMCTL_EXEC"·start·'tmp.mount'
594 fi587 fi
595 "$SYSTEMCTL_EXEC"·enable·'tmp.mount'588 "$SYSTEMCTL_EXEC"·enable·'tmp.mount'
  
596 else589 else
597 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'590 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
598 fi591 fi
 592 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 593 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 594 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 595 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 596 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 597 services·--enabled=tmp.mount
599 Group  ·Sudo·  Group·contains·16·rules598 Group  ·Sudo·  Group·contains·16·rules
600 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Sudo,·which·stands·for·"su·'do'",·provides·the·ability·to·delegate·authority·to·certain599 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Sudo,·which·stands·for·"su·'do'",·provides·the·ability·to·delegate·authority·to·certain
601 users,·groups·of·users,·or·system·administrators.·When·configured·for·system·users·and/or·groups,600 users,·groups·of·users,·or·system·administrators.·When·configured·for·system·users·and/or·groups,
602 Sudo·can·allow·a·user·or·group·to·execute·privileged·commands·that·normally·only·root·is·allowed·to601 Sudo·can·allow·a·user·or·group·to·execute·privileged·commands·that·normally·only·root·is·allowed·to
603 execute.602 execute.
  
604 For·more·information·on·Sudo·and·addition·Sudo·configuration·options,·see·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8w\x8w_\x8w\x8w_\x8w\x8w_\x8.\x8._\x8s\x8s_\x8u\x8u_\x8d\x8d_\x8o\x8o_\x8.\x8._\x8w\x8w_\x8s\x8s.603 For·more·information·on·Sudo·and·addition·Sudo·configuration·options,·see·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8w\x8w_\x8w\x8w_\x8w\x8w_\x8.\x8._\x8s\x8s_\x8u\x8u_\x8d\x8d_\x8o\x8o_\x8.\x8._\x8w\x8w_\x8s\x8s.
Offset 649, 21 lines modifiedOffset 649, 14 lines modified
649 ··-·PCI-DSSv4-2.2.6649 ··-·PCI-DSSv4-2.2.6
650 ··-·enable_strategy650 ··-·enable_strategy
651 ··-·low_complexity651 ··-·low_complexity
652 ··-·low_disruption652 ··-·low_disruption
653 ··-·medium_severity653 ··-·medium_severity
654 ··-·no_reboot_needed654 ··-·no_reboot_needed
655 ··-·package_sudo_installed655 ··-·package_sudo_installed
656 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
657 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
658 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
659 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
660 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
661 package·--add=sudo 
662 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8656 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
663 [[packages]]657 [[packages]]
664 name·=·"sudo"658 name·=·"sudo"
665 version·=·"*"659 version·=·"*"
666 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8660 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
667 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low661 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 688, 14 lines modifiedOffset 681, 21 lines modified
688 if·!·rpm·-q·--quiet·"sudo"·;·then681 if·!·rpm·-q·--quiet·"sudo"·;·then
689 ····yum·install·-y·"sudo"682 ····yum·install·-y·"sudo"
690 fi683 fi
  
691 else684 else
692 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'685 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
693 fi686 fi
 687 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 688 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 689 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 690 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 691 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 692 package·--add=sudo
694 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·G\x8Gr\x8ro\x8ou\x8up\x8p·W\x8Wh\x8ho\x8o·O\x8Ow\x8wn\x8ns\x8s·/\x8/e\x8et\x8tc\x8c/\x8/s\x8su\x8ud\x8do\x8oe\x8er\x8rs\x8s.\x8.d\x8d·D\x8Di\x8ir\x8re\x8ec\x8ct\x8to\x8or\x8ry\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*693 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·G\x8Gr\x8ro\x8ou\x8up\x8p·W\x8Wh\x8ho\x8o·O\x8Ow\x8wn\x8ns\x8s·/\x8/e\x8et\x8tc\x8c/\x8/s\x8su\x8ud\x8do\x8oe\x8er\x8rs\x8s.\x8.d\x8d·D\x8Di\x8ir\x8re\x8ec\x8ct\x8to\x8or\x8ry\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
695 To·properly·set·the·group·owner·of·/etc/sudoers.d,·run·the·command:694 To·properly·set·the·group·owner·of·/etc/sudoers.d,·run·the·command:
696 $·sudo·chgrp·root·/etc/sudoers.d695 $·sudo·chgrp·root·/etc/sudoers.d
Max diff block lines reached; 53965/59090 bytes (91.33%) of diff not shown.
255 KB
./usr/share/doc/ssg-nondebian/ssg-ol8-guide-anssi_bp28_minimal.html
    
Offset 14798, 155 lines modifiedOffset 14798, 155 lines modified
00039cd0:·7461·7267·6574·3d22·2369·646d·3130·3539··target="#idm105900039cd0:·7461·7267·6574·3d22·2369·646d·3130·3539··target="#idm1059
00039ce0:·3822·2074·6162·696e·6465·783d·2230·2220··8"·tabindex="0"·00039ce0:·3822·2074·6162·696e·6465·783d·2230·2220··8"·tabindex="0"·
00039cf0:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar00039cf0:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar
00039d00:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal00039d00:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal
00039d10:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ00039d10:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ
00039d20:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h00039d20:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h
00039d30:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia00039d30:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia
 00039d40:·7469·6f6e·204f·5342·7569·6c64·2042·6c75··tion·OSBuild·Blu
 00039d50:·6570·7269·6e74·2073·6e69·7070·6574·20e2··eprint·snippet·.
 00039d60:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c
 00039d70:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
 00039d80:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
 00039d90:·643d·2269·646d·3130·3539·3822·3e3c·7072··d="idm10598"><pr
00039d40:·7469·6f6e·2041·6e61·636f·6e64·6120·736e··tion·Anaconda·sn 
00039d50:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br 
00039d60:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan 
00039d70:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll 
00039d80:·6170·7365·2220·6964·3d22·6964·6d31·3035··apse"·id="idm105 
00039d90:·3938·223e·3c74·6162·6c65·2063·6c61·7373··98"><table·class 
00039da0:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st 
00039db0:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord 
00039dc0:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde 
00039dd0:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co 
00039de0:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t 
00039df0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr>< 
00039e00:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio 
00039e10:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</ 
00039e20:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
00039e30:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td> 
00039e40:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr>< 
00039e50:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy: 
00039e60:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable< 
00039e70:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table 
00039e80:·3e3c·7072·653e·3c63·6f64·653e·0a70·6163··><pre><code>.pac00039da0:·653e·3c63·6f64·653e·0a5b·5b70·6163·6b61··e><code>.[[packa
00039e90:·6b61·6765·202d·2d61·6464·3d64·6e66·2d61··kage·--add=dnf-a 
00039ea0:·7574·6f6d·6174·6963·0a3c·2f63·6f64·653e··utomatic.</code>00039db0:·6765·735d·5d0a·6e61·6d65·203d·2022·646e··ges]].name·=·"dn
 00039dc0:·662d·6175·746f·6d61·7469·6322·0a76·6572··f-automatic".ver
 00039dd0:·7369·6f6e·203d·2022·2a22·0a3c·2f63·6f64··sion·=·"*".</cod
00039eb0:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c00039de0:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a
00039ec0:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su00039df0:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn-
00039ed0:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg00039e00:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to
00039ee0:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da00039e10:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"·
00039ef0:·7461·2d74·6172·6765·743d·2223·6964·6d31··ta-target="#idm100039e20:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
00039f00:·3035·3939·2220·7461·6269·6e64·6578·3d22··0599"·tabindex="00039e30:·6d31·3035·3939·2220·7461·6269·6e64·6578··m10599"·tabindex
00039f10:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"00039e40:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto
00039f20:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="00039e50:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded
00039f30:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac00039e60:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="
00039f40:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal00039e70:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve
00039f50:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme00039e80:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re
00039f60:·6469·6174·696f·6e20·4f53·4275·696c·6420··diation·OSBuild· 
00039f70:·426c·7565·7072·696e·7420·736e·6970·7065··Blueprint·snippe00039e90:·6d65·6469·6174·696f·6e20·5075·7070·6574··mediation·Puppet
 00039ea0:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>
 00039eb0:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="
 00039ec0:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c
 00039ed0:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm
 00039ee0:·3130·3539·3922·3e3c·7461·626c·6520·636c··10599"><table·cl
 00039ef0:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table
 00039f00:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b
 00039f10:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co
 00039f20:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th
 00039f30:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th
 00039f40:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
 00039f50:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup
 00039f60:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo
 00039f70:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
 00039f80:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th><
 00039f90:·7464·3e66·616c·7365·3c2f·7464·3e3c·2f74··td>false</td></t
 00039fa0:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate
 00039fb0:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab
 00039fc0:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta
 00039fd0:·626c·653e·3c70·7265·3e3c·636f·6465·3e69··ble><pre><code>i
 00039fe0:·6e63·6c75·6465·2069·6e73·7461·6c6c·5f64··nclude·install_d
 00039ff0:·6e66·2d61·7574·6f6d·6174·6963·0a0a·636c··nf-automatic..cl
 0003a000:·6173·7320·696e·7374·616c·6c5f·646e·662d··ass·install_dnf-
 0003a010:·6175·746f·6d61·7469·6320·7b0a·2020·7061··automatic·{.··pa
 0003a020:·636b·6167·6520·7b20·2764·6e66·2d61·7574··ckage·{·'dnf-aut
 0003a030:·6f6d·6174·6963·273a·0a20·2020·2065·6e73··omatic':.····ens
 0003a040:·7572·6520·3d26·6774·3b20·2769·6e73·7461··ure·=&gt;·'insta
 0003a050:·6c6c·6564·272c·0a20·207d·0a7d·0a3c·2f63··lled',.··}.}.</c
 0003a060:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div>
 0003a070:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt
 0003a080:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data-
 0003a090:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse
 0003a0a0:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
 0003a0b0:·6964·6d31·3036·3030·2220·7461·6269·6e64··idm10600"·tabind
 0003a0c0:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
 0003a0d0:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
 0003a0e0:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
 0003a0f0:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
 0003a100:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
 0003a110:·5265·6d65·6469·6174·696f·6e20·5368·656c··Remediation·Shel
 0003a120:·6c20·7363·7269·7074·20e2·87b2·3c2f·613e··l·script·...</a>
 0003a130:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="
 0003a140:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c
 0003a150:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm
 0003a160:·3130·3630·3022·3e3c·7461·626c·6520·636c··10600"><table·cl
 0003a170:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table
 0003a180:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b
 0003a190:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co
 0003a1a0:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th
 0003a1b0:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th
 0003a1c0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
 0003a1d0:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup
 0003a1e0:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo
 0003a1f0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
 0003a200:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th><
 0003a210:·7464·3e66·616c·7365·3c2f·7464·3e3c·2f74··td>false</td></t
 0003a220:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate
 0003a230:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab
 0003a240:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta
 0003a250:·626c·653e·3c70·7265·3e3c·636f·6465·3e23··ble><pre><code>#
 0003a260:·2052·656d·6564·6961·7469·6f6e·2069·7320···Remediation·is·
 0003a270:·6170·706c·6963·6162·6c65·206f·6e6c·7920··applicable·only·
 0003a280:·696e·2063·6572·7461·696e·2070·6c61·7466··in·certain·platf
 0003a290:·6f72·6d73·0a69·6620·2120·2820·7b20·7270··orms.if·!·(·{·rp
 0003a2a0:·6d20·2d2d·7175·6965·7420·2d71·206b·6572··m·--quiet·-q·ker
 0003a2b0:·6e65·6c20·3b7d·2026·616d·703b·2661·6d70··nel·;}·&amp;&amp
 0003a2c0:·3b20·7b20·7270·6d20·2d2d·7175·6965·7420··;·{·rpm·--quiet·
 0003a2d0:·2d71·2072·706d·2d6f·7374·7265·6520·3b7d··-q·rpm-ostree·;}
 0003a2e0:·2026·616d·703b·2661·6d70·3b20·7b20·7270···&amp;&amp;·{·rp
 0003a2f0:·6d20·2d2d·7175·6965·7420·2d71·2062·6f6f··m·--quiet·-q·boo
 0003a300:·7463·203b·7d20·2661·6d70·3b26·616d·703b··tc·;}·&amp;&amp;
 0003a310:·207b·2021·2072·706d·202d·2d71·7569·6574···{·!·rpm·--quiet
 0003a320:·202d·7120·6f70·656e·7368·6966·742d·6b75···-q·openshift-ku
 0003a330:·6265·6c65·7420·3b7d·2029·3b20·7468·656e··belet·;}·);·then
 0003a340:·0a0a·6966·2021·2072·706d·202d·7120·2d2d··..if·!·rpm·-q·--
 0003a350:·7175·6965·7420·2264·6e66·2d61·7574·6f6d··quiet·"dnf-autom
Max diff block lines reached; 216334/236372 bytes (91.52%) of diff not shown.
23.7 KB
html2text {}
    
Offset 112, 21 lines modifiedOffset 112, 14 lines modified
112 ··tags:112 ··tags:
113 ··-·enable_strategy113 ··-·enable_strategy
114 ··-·low_complexity114 ··-·low_complexity
115 ··-·low_disruption115 ··-·low_disruption
116 ··-·medium_severity116 ··-·medium_severity
117 ··-·no_reboot_needed117 ··-·no_reboot_needed
118 ··-·package_dnf-automatic_installed118 ··-·package_dnf-automatic_installed
119 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
120 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
121 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
122 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
123 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
124 package·--add=dnf-automatic 
125 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8119 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
126 [[packages]]120 [[packages]]
127 name·=·"dnf-automatic"121 name·=·"dnf-automatic"
128 version·=·"*"122 version·=·"*"
129 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8123 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
130 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low124 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 152, 14 lines modifiedOffset 145, 21 lines modified
152 if·!·rpm·-q·--quiet·"dnf-automatic"·;·then145 if·!·rpm·-q·--quiet·"dnf-automatic"·;·then
153 ····yum·install·-y·"dnf-automatic"146 ····yum·install·-y·"dnf-automatic"
154 fi147 fi
  
155 else148 else
156 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'149 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
157 fi150 fi
 151 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 152 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 153 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 154 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 155 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 156 package·--add=dnf-automatic
158 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·d\x8dn\x8nf\x8f-\x8-a\x8au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8c·t\x8to\x8o·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·A\x8Av\x8va\x8ai\x8il\x8la\x8ab\x8bl\x8le\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8es\x8s·A\x8Au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8ca\x8al\x8ll\x8ly\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*157 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·d\x8dn\x8nf\x8f-\x8-a\x8au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8c·t\x8to\x8o·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·A\x8Av\x8va\x8ai\x8il\x8la\x8ab\x8bl\x8le\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8es\x8s·A\x8Au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8ca\x8al\x8ll\x8ly\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
159 To·ensure·that·the·packages·comprising·the·available·updates·will·be·automatically·installed158 To·ensure·that·the·packages·comprising·the·available·updates·will·be·automatically·installed
160 by·dnf-automatic,·set·apply_updates·to·yes·under·[commands]·section·in·/etc/dnf/159 by·dnf-automatic,·set·apply_updates·to·yes·under·[commands]·section·in·/etc/dnf/
161 automatic.conf.160 automatic.conf.
162 ············Installing·software·updates·is·a·fundamental·mitigation·against·the·exploitation161 ············Installing·software·updates·is·a·fundamental·mitigation·against·the·exploitation
163 ············of·publicly-known·vulnerabilities.·If·the·most·recent·security·patches·and162 ············of·publicly-known·vulnerabilities.·If·the·most·recent·security·patches·and
164 Rationale:··updates·are·not·installed,·unauthorized·users·may·take·advantage·of·weaknesses·in163 Rationale:··updates·are·not·installed,·unauthorized·users·may·take·advantage·of·weaknesses·in
Offset 11830, 21 lines modifiedOffset 11830, 14 lines modified
11830 ··-·PCI-DSSv4-2.2.411830 ··-·PCI-DSSv4-2.2.4
11831 ··-·disable_strategy11831 ··-·disable_strategy
11832 ··-·low_complexity11832 ··-·low_complexity
11833 ··-·low_disruption11833 ··-·low_disruption
11834 ··-·medium_severity11834 ··-·medium_severity
11835 ··-·no_reboot_needed11835 ··-·no_reboot_needed
11836 ··-·package_dhcp_removed11836 ··-·package_dhcp_removed
11837 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
11838 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
11839 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
11840 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
11841 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable 
  
11842 package·--remove=dhcp 
11843 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x811837 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
11844 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low11838 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
11845 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low11839 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
11846 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false11840 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
11847 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable11841 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
11848 include·remove_dhcp11842 include·remove_dhcp
  
Offset 11864, 14 lines modifiedOffset 11857, 21 lines modified
11864 #»      ···that·depend·on·dhcp.·Execute·this11857 #»      ···that·depend·on·dhcp.·Execute·this
11865 #»      ···remediation·AFTER·testing·on·a·non-production11858 #»      ···remediation·AFTER·testing·on·a·non-production
11866 #»      ···system!11859 #»      ···system!
  
11867 if·rpm·-q·--quiet·"dhcp"·;·then11860 if·rpm·-q·--quiet·"dhcp"·;·then
11868 yum·remove·-y·"dhcp"11861 yum·remove·-y·"dhcp"
11869 fi11862 fi
 11863 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 11864 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 11865 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 11866 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 11867 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
  
 11868 package·--remove=dhcp
11870 Group  ·Mail·Server·Software·  Group·contains·1·rule11869 Group  ·Mail·Server·Software·  Group·contains·1·rule
11871 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Mail·servers·are·used·to·send·and·receive·email·over·the·network.·Mail·is·a·very11870 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Mail·servers·are·used·to·send·and·receive·email·over·the·network.·Mail·is·a·very
11872 common·service,·and·Mail·Transfer·Agents·(MTAs)·are·obvious·targets·of·network·attack.·Ensure11871 common·service,·and·Mail·Transfer·Agents·(MTAs)·are·obvious·targets·of·network·attack.·Ensure
11873 that·systems·are·not·running·MTAs·unnecessarily,·and·configure·needed·MTAs·as·defensively·as11872 that·systems·are·not·running·MTAs·unnecessarily,·and·configure·needed·MTAs·as·defensively·as
11874 possible.11873 possible.
  
11875 Very·few·systems·at·any·site·should·be·configured·to·directly·receive·email·over·the·network.11874 Very·few·systems·at·any·site·should·be·configured·to·directly·receive·email·over·the·network.
Offset 11947, 21 lines modifiedOffset 11947, 14 lines modified
11947 ··-·NIST-800-53-CM-7(b)11947 ··-·NIST-800-53-CM-7(b)
11948 ··-·disable_strategy11948 ··-·disable_strategy
11949 ··-·low_complexity11949 ··-·low_complexity
11950 ··-·low_disruption11950 ··-·low_disruption
11951 ··-·medium_severity11951 ··-·medium_severity
11952 ··-·no_reboot_needed11952 ··-·no_reboot_needed
11953 ··-·package_sendmail_removed11953 ··-·package_sendmail_removed
11954 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
11955 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
11956 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
11957 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
11958 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable 
  
11959 package·--remove=sendmail 
11960 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x811954 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
11961 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low11955 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
11962 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low11956 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
11963 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false11957 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
11964 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable11958 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
11965 include·remove_sendmail11959 include·remove_sendmail
  
Offset 11987, 14 lines modifiedOffset 11980, 21 lines modified
11987 if·rpm·-q·--quiet·"sendmail"·;·then11980 if·rpm·-q·--quiet·"sendmail"·;·then
11988 yum·remove·-y·"sendmail"11981 yum·remove·-y·"sendmail"
11989 fi11982 fi
  
11990 else11983 else
11991 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'11984 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
11992 fi11985 fi
 11986 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 11987 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 11988 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 11989 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 11990 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
  
 11991 package·--remove=sendmail
11993 Group  ·Obsolete·Services·  Group·contains·6·groups·and·11·rules11992 Group  ·Obsolete·Services·  Group·contains·6·groups·and·11·rules
11994 _\x8[_\x8r_\x8e_\x8f_\x8]  ·This·section·discusses·a·number·of·network-visible·services·which·have·historically11993 _\x8[_\x8r_\x8e_\x8f_\x8]  ·This·section·discusses·a·number·of·network-visible·services·which·have·historically
11995 caused·problems·for·system·security,·and·for·which·disabling·or·severely·limiting·the·service11994 caused·problems·for·system·security,·and·for·which·disabling·or·severely·limiting·the·service
Max diff block lines reached; 19182/24235 bytes (79.15%) of diff not shown.
1.14 MB
./usr/share/doc/ssg-nondebian/ssg-ol8-guide-cui.html
    
Offset 15175, 144 lines modifiedOffset 15175, 144 lines modified
0003b460:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target0003b460:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
0003b470:·3d22·2369·646d·3536·3937·2220·7461·6269··="#idm5697"·tabi0003b470:·3d22·2369·646d·3536·3937·2220·7461·6269··="#idm5697"·tabi
0003b480:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b0003b480:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
0003b490:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa0003b490:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
0003b4a0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit0003b4a0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
0003b4b0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·0003b4b0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
0003b4c0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!0003b4c0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
 0003b4d0:·223e·5265·6d65·6469·6174·696f·6e20·4f53··">Remediation·OS
 0003b4e0:·4275·696c·6420·426c·7565·7072·696e·7420··Build·Blueprint·
 0003b4f0:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><
 0003b500:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
 0003b510:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
 0003b520:·6c6c·6170·7365·2220·6964·3d22·6964·6d35··llapse"·id="idm5
 0003b530:·3639·3722·3e3c·7072·653e·3c63·6f64·653e··697"><pre><code>
 0003b540:·0a5b·5b70·6163·6b61·6765·735d·5d0a·6e61··.[[packages]].na
 0003b550:·6d65·203d·2022·6169·6465·220a·7665·7273··me·=·"aide".vers
 0003b560:·696f·6e20·3d20·222a·220a·3c2f·636f·6465··ion·=·"*".</code
 0003b570:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a·
 0003b580:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s
 0003b590:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog
 0003b5a0:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d
 0003b5b0:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
 0003b5c0:·3536·3938·2220·7461·6269·6e64·6578·3d22··5698"·tabindex="
 0003b5d0:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
 0003b5e0:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
 0003b5f0:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
 0003b600:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
 0003b610:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
 0003b620:·6469·6174·696f·6e20·5075·7070·6574·2073··diation·Puppet·s
 0003b630:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b
 0003b640:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
 0003b650:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
 0003b660:·6c61·7073·6522·2069·643d·2269·646d·3536··lapse"·id="idm56
 0003b670:·3938·223e·3c74·6162·6c65·2063·6c61·7373··98"><table·class
 0003b680:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st
 0003b690:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord
 0003b6a0:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde
 0003b6b0:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co
 0003b6c0:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t
 0003b6d0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
 0003b6e0:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio
 0003b6f0:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</
 0003b700:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 0003b710:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td>
 0003b720:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr><
 0003b730:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:
 0003b740:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<
 0003b750:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table
 0003b760:·3e3c·7072·653e·3c63·6f64·653e·696e·636c··><pre><code>incl
 0003b770:·7564·6520·696e·7374·616c·6c5f·6169·6465··ude·install_aide
 0003b780:·0a0a·636c·6173·7320·696e·7374·616c·6c5f··..class·install_
 0003b790:·6169·6465·207b·0a20·2070·6163·6b61·6765··aide·{.··package
 0003b7a0:·207b·2027·6169·6465·273a·0a20·2020·2065···{·'aide':.····e
 0003b7b0:·6e73·7572·6520·3d26·6774·3b20·2769·6e73··nsure·=&gt;·'ins
 0003b7c0:·7461·6c6c·6564·272c·0a20·207d·0a7d·0a3c··talled',.··}.}.<
 0003b7d0:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di
 0003b7e0:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn·
 0003b7f0:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat
 0003b800:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap
 0003b810:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
 0003b820:·2223·6964·6d35·3639·3922·2074·6162·696e··"#idm5699"·tabin
 0003b830:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
 0003b840:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
 0003b850:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
 0003b860:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
 0003b870:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
 0003b880:·3e52·656d·6564·6961·7469·6f6e·2053·6865··>Remediation·She
 0003b890:·6c6c·2073·6372·6970·7420·e287·b23c·2f61··ll·script·...</a
 0003b8a0:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
 0003b8b0:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
 0003b8c0:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
 0003b8d0:·6d35·3639·3922·3e3c·7461·626c·6520·636c··m5699"><table·cl
 0003b8e0:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table
 0003b8f0:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b
 0003b900:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co
 0003b910:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th
 0003b920:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th
 0003b930:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
 0003b940:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup
 0003b950:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo
 0003b960:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
 0003b970:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th><
 0003b980:·7464·3e66·616c·7365·3c2f·7464·3e3c·2f74··td>false</td></t
 0003b990:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate
 0003b9a0:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab
 0003b9b0:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta
 0003b9c0:·626c·653e·3c70·7265·3e3c·636f·6465·3e23··ble><pre><code>#
 0003b9d0:·2052·656d·6564·6961·7469·6f6e·2069·7320···Remediation·is·
 0003b9e0:·6170·706c·6963·6162·6c65·206f·6e6c·7920··applicable·only·
 0003b9f0:·696e·2063·6572·7461·696e·2070·6c61·7466··in·certain·platf
 0003ba00:·6f72·6d73·0a69·6620·7270·6d20·2d2d·7175··orms.if·rpm·--qu
 0003ba10:·6965·7420·2d71·206b·6572·6e65·6c20·7c7c··iet·-q·kernel·||
 0003ba20:·2072·706d·202d·2d71·7569·6574·202d·7120···rpm·--quiet·-q·
 0003ba30:·6b65·726e·656c·2d75·656b·3b20·7468·656e··kernel-uek;·then
 0003ba40:·0a0a·6966·2021·2072·706d·202d·7120·2d2d··..if·!·rpm·-q·--
 0003ba50:·7175·6965·7420·2261·6964·6522·203b·2074··quiet·"aide"·;·t
 0003ba60:·6865·6e0a·2020·2020·7975·6d20·696e·7374··hen.····yum·inst
 0003ba70:·616c·6c20·2d79·2022·6169·6465·220a·6669··all·-y·"aide".fi
 0003ba80:·0a0a·656c·7365·0a20·2020·2026·6774·3b26··..else.····&gt;&
 0003ba90:·616d·703b·3220·6563·686f·2027·5265·6d65··amp;2·echo·'Reme
 0003baa0:·6469·6174·696f·6e20·6973·206e·6f74·2061··diation·is·not·a
 0003bab0:·7070·6c69·6361·626c·652c·206e·6f74·6869··pplicable,·nothi
 0003bac0:·6e67·2077·6173·2064·6f6e·6527·0a66·690a··ng·was·done'.fi.
 0003bad0:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d
 0003bae0:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn
 0003baf0:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da
 0003bb00:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla
 0003bb10:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
 0003bb20:·3d22·2369·646d·3537·3030·2220·7461·6269··="#idm5700"·tabi
 0003bb30:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
 0003bb40:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
 0003bb50:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
 0003bb60:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
 0003bb70:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
0003b4d0:·223e·5265·6d65·6469·6174·696f·6e20·416e··">Remediation·An0003bb80:·223e·5265·6d65·6469·6174·696f·6e20·416e··">Remediation·An
0003b4e0:·6163·6f6e·6461·2073·6e69·7070·6574·20e2··aconda·snippet·.0003bb90:·6163·6f6e·6461·2073·6e69·7070·6574·20e2··aconda·snippet·.
0003b4f0:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c0003bba0:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c
0003b500:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll0003bbb0:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
0003b510:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i0003bbc0:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
0003b520:·643d·2269·646d·3536·3937·223e·3c74·6162··d="idm5697"><tab0003bbd0:·643d·2269·646d·3537·3030·223e·3c74·6162··d="idm5700"><tab
0003b530:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·0003bbe0:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·
0003b540:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta0003bbf0:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta
0003b550:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab0003bc00:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab
0003b560:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t 
0003b570:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity 
0003b580:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t 
0003b590:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D 
Max diff block lines reached; 1068250/1086770 bytes (98.30%) of diff not shown.
103 KB
html2text {}
    
Offset 146, 21 lines modifiedOffset 146, 14 lines modified
146 ··-·PCI-DSSv4-11.5.2146 ··-·PCI-DSSv4-11.5.2
147 ··-·enable_strategy147 ··-·enable_strategy
148 ··-·low_complexity148 ··-·low_complexity
149 ··-·low_disruption149 ··-·low_disruption
150 ··-·medium_severity150 ··-·medium_severity
151 ··-·no_reboot_needed151 ··-·no_reboot_needed
152 ··-·package_aide_installed152 ··-·package_aide_installed
153 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
154 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
155 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
156 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
157 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
158 package·--add=aide 
159 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8153 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
160 [[packages]]154 [[packages]]
161 name·=·"aide"155 name·=·"aide"
162 version·=·"*"156 version·=·"*"
163 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8157 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
164 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low158 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 185, 14 lines modifiedOffset 178, 21 lines modified
185 if·!·rpm·-q·--quiet·"aide"·;·then178 if·!·rpm·-q·--quiet·"aide"·;·then
186 ····yum·install·-y·"aide"179 ····yum·install·-y·"aide"
187 fi180 fi
  
188 else181 else
189 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'182 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
190 fi183 fi
 184 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 185 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 186 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 187 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 188 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 189 package·--add=aide
191 Group  ·Federal·Information·Processing·Standard·(FIPS)·  Group·contains·2·rules190 Group  ·Federal·Information·Processing·Standard·(FIPS)·  Group·contains·2·rules
192 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·Federal·Information·Processing·Standard·(FIPS)·is·a·computer·security·standard·which·is·developed·by·the·U.S.·Government·and·industry·working·groups·to·validate·the·quality·of·cryptographic·modules.·The·FIPS·standard·provides·four·security·levels·to·ensure·adequate·coverage·of·different·industries,·implementation·of·cryptographic·modules,·and·organizational·sizes·and·requirements.191 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·Federal·Information·Processing·Standard·(FIPS)·is·a·computer·security·standard·which·is·developed·by·the·U.S.·Government·and·industry·working·groups·to·validate·the·quality·of·cryptographic·modules.·The·FIPS·standard·provides·four·security·levels·to·ensure·adequate·coverage·of·different·industries,·implementation·of·cryptographic·modules,·and·organizational·sizes·and·requirements.
  
193 FIPS·140-2·is·the·current·standard·for·validating·that·mechanisms·used·to·access·cryptographic·modules·utilize·authentication·that·meets·industry·and·government·requirements.·For·government·systems,·this·allows·Security·Levels·1,·2,·3,·or·4·for·use·on·Oracle·Linux·8.192 FIPS·140-2·is·the·current·standard·for·validating·that·mechanisms·used·to·access·cryptographic·modules·utilize·authentication·that·meets·industry·and·government·requirements.·For·government·systems,·this·allows·Security·Levels·1,·2,·3,·or·4·for·use·on·Oracle·Linux·8.
  
194 See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8c\x8c_\x8s\x8s_\x8r\x8r_\x8c\x8c_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8l\x8l_\x8i\x8i_\x8c\x8c_\x8a\x8a_\x8t\x8t_\x8i\x8i_\x8o\x8o_\x8n\x8n_\x8s\x8s_\x8/\x8/_\x8P\x8P_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x8h\x8h_\x8t\x8t_\x8m\x8m_\x8l\x8l·for·more·information.193 See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8c\x8c_\x8s\x8s_\x8r\x8r_\x8c\x8c_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8l\x8l_\x8i\x8i_\x8c\x8c_\x8a\x8a_\x8t\x8t_\x8i\x8i_\x8o\x8o_\x8n\x8n_\x8s\x8s_\x8/\x8/_\x8P\x8P_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x8h\x8h_\x8t\x8t_\x8m\x8m_\x8l\x8l·for·more·information.
195 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·D\x8Dr\x8ra\x8ac\x8cu\x8ut\x8t·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8du\x8ul\x8le\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*194 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·D\x8Dr\x8ra\x8ac\x8cu\x8ut\x8t·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8du\x8ul\x8le\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
Offset 392, 21 lines modifiedOffset 392, 14 lines modified
392 ··tags:392 ··tags:
393 ··-·enable_strategy393 ··-·enable_strategy
394 ··-·low_complexity394 ··-·low_complexity
395 ··-·low_disruption395 ··-·low_disruption
396 ··-·medium_severity396 ··-·medium_severity
397 ··-·no_reboot_needed397 ··-·no_reboot_needed
398 ··-·package_crypto-policies_installed398 ··-·package_crypto-policies_installed
399 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
400 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
401 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
402 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
403 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
404 package·--add=crypto-policies 
405 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8399 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
406 [[packages]]400 [[packages]]
407 name·=·"crypto-policies"401 name·=·"crypto-policies"
408 version·=·"*"402 version·=·"*"
409 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8403 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
410 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low404 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 425, 14 lines modifiedOffset 418, 21 lines modified
425 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low418 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
426 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false419 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
427 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable420 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
428 if·!·rpm·-q·--quiet·"crypto-policies"·;·then421 if·!·rpm·-q·--quiet·"crypto-policies"·;·then
429 ····yum·install·-y·"crypto-policies"422 ····yum·install·-y·"crypto-policies"
430 fi423 fi
 424 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 425 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 426 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 427 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 428 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 429 package·--add=crypto-policies
431 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·B\x8BI\x8IN\x8ND\x8D·t\x8to\x8o·u\x8us\x8se\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8o·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*430 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·B\x8BI\x8IN\x8ND\x8D·t\x8to\x8o·u\x8us\x8se\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8o·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
432 Crypto·Policies·provide·a·centralized·control·over·crypto·algorithms·usage·of·many·packages.·BIND·is·supported·by·crypto·policy,·but·the·BIND·configuration·may·be·set·up·to·ignore·it.·To·check·that·Crypto·Policies·settings·are·configured·correctly,·ensure·that·the·/etc/named.conf·includes·the·appropriate·configuration:·In·the·options·section·of·/etc/named.conf,·make·sure·that·the·following·line·is·not·commented·out·or·superseded·by·later·includes:·include·"/etc/crypto-policies/back-ends/bind.config";431 Crypto·Policies·provide·a·centralized·control·over·crypto·algorithms·usage·of·many·packages.·BIND·is·supported·by·crypto·policy,·but·the·BIND·configuration·may·be·set·up·to·ignore·it.·To·check·that·Crypto·Policies·settings·are·configured·correctly,·ensure·that·the·/etc/named.conf·includes·the·appropriate·configuration:·In·the·options·section·of·/etc/named.conf,·make·sure·that·the·following·line·is·not·commented·out·or·superseded·by·later·includes:·include·"/etc/crypto-policies/back-ends/bind.config";
433 Rationale:··Overriding·the·system·crypto·policy·makes·the·behavior·of·the·BIND·service·violate·expectations,·and·makes·system·configuration·more·fragmented.432 Rationale:··Overriding·the·system·crypto·policy·makes·the·behavior·of·the·BIND·service·violate·expectations,·and·makes·system·configuration·more·fragmented.
434 Severity: ··high433 Severity: ··high
435 Rule·ID:····xccdf_org.ssgproject.content_rule_configure_bind_crypto_policy434 Rule·ID:····xccdf_org.ssgproject.content_rule_configure_bind_crypto_policy
436 ············_\x8d_\x8i_\x8s_\x8a·····CCI-002418,·CCI-002422435 ············_\x8d_\x8i_\x8s_\x8a·····CCI-002418,·CCI-002422
437 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1436 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1
Offset 1194, 21 lines modifiedOffset 1194, 14 lines modified
1194 ··-·PCI-DSSv4-2.2.61194 ··-·PCI-DSSv4-2.2.6
1195 ··-·enable_strategy1195 ··-·enable_strategy
1196 ··-·low_complexity1196 ··-·low_complexity
1197 ··-·low_disruption1197 ··-·low_disruption
1198 ··-·medium_severity1198 ··-·medium_severity
1199 ··-·no_reboot_needed1199 ··-·no_reboot_needed
1200 ··-·package_sudo_installed1200 ··-·package_sudo_installed
1201 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
1202 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
1203 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
1204 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
1205 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
1206 package·--add=sudo 
1207 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81201 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
1208 [[packages]]1202 [[packages]]
1209 name·=·"sudo"1203 name·=·"sudo"
1210 version·=·"*"1204 version·=·"*"
1211 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81205 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1212 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1206 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 1233, 14 lines modifiedOffset 1226, 21 lines modified
1233 if·!·rpm·-q·--quiet·"sudo"·;·then1226 if·!·rpm·-q·--quiet·"sudo"·;·then
1234 ····yum·install·-y·"sudo"1227 ····yum·install·-y·"sudo"
1235 fi1228 fi
  
1236 else1229 else
1237 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'1230 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
1238 fi1231 fi
 1232 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 1233 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1234 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1235 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1236 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 1237 package·--add=sudo
1239 Group  ·System·Tooling·/·Utilities·  Group·contains·13·rules1238 Group  ·System·Tooling·/·Utilities·  Group·contains·13·rules
1240 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·following·checks·evaluate·the·system·for·recommended·base·packages·--·both·for·installation·and·removal.1239 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·following·checks·evaluate·the·system·for·recommended·base·packages·--·both·for·installation·and·removal.
1241 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·g\x8gn\x8nu\x8ut\x8tl\x8ls\x8s-\x8-u\x8ut\x8ti\x8il\x8ls\x8s·i\x8is\x8s·i\x8in\x8ns\x8st\x8ta\x8al\x8ll\x8le\x8ed\x8d·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*1240 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·g\x8gn\x8nu\x8ut\x8tl\x8ls\x8s-\x8-u\x8ut\x8ti\x8il\x8ls\x8s·i\x8is\x8s·i\x8in\x8ns\x8st\x8ta\x8al\x8ll\x8le\x8ed\x8d·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
Max diff block lines reached; 99239/105457 bytes (94.10%) of diff not shown.
265 KB
./usr/share/doc/ssg-nondebian/ssg-ol8-guide-e8.html
    
Offset 19448, 211 lines modifiedOffset 19448, 211 lines modified
0004bf70:·612d·7461·7267·6574·3d22·2369·646d·3130··a-target="#idm100004bf70:·612d·7461·7267·6574·3d22·2369·646d·3130··a-target="#idm10
0004bf80:·3134·3322·2074·6162·696e·6465·783d·2230··143"·tabindex="00004bf80:·3134·3322·2074·6162·696e·6465·783d·2230··143"·tabindex="0
0004bf90:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·0004bf90:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
0004bfa0:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f0004bfa0:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
0004bfb0:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act0004bfb0:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
0004bfc0:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"0004bfc0:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
0004bfd0:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed0004bfd0:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
 0004bfe0:·6961·7469·6f6e·204f·5342·7569·6c64·2042··iation·OSBuild·B
 0004bff0:·6c75·6570·7269·6e74·2073·6e69·7070·6574··lueprint·snippet
0004bfe0:·6961·7469·6f6e·2041·6e61·636f·6e64·6120··iation·Anaconda· 
0004bff0:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a>< 
0004c000:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p 
0004c010:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co 
0004c020:·6c6c·6170·7365·2220·6964·3d22·6964·6d31··llapse"·id="idm1 
0004c030:·3031·3433·223e·3c74·6162·6c65·2063·6c61··0143"><table·cla 
0004c040:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table- 
0004c050:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo 
0004c060:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con 
0004c070:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th> 
0004c080:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th> 
0004c090:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
0004c0a0:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt 
0004c0b0:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low 
0004c0c0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
0004c0d0:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t 
0004c0e0:·643e·6661·6c73·653c·2f74·643e·3c2f·7472··d>false</td></tr 
0004c0f0:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg 
0004c100:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl 
0004c110:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab 
0004c120:·6c65·3e3c·7072·653e·3c63·6f64·653e·0a70··le><pre><code>.p 
0004c130:·6163·6b61·6765·202d·2d61·6464·3d72·6561··ackage·--add=rea 
0004c140:·720a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··r.</code></pre>< 
0004c150:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b 
0004c160:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"· 
0004c170:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col 
0004c180:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ 
0004c190:·6574·3d22·2369·646d·3130·3134·3422·2074··et="#idm10144"·t 
0004c1a0:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role 
0004c1b0:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e 
0004c1c0:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"· 
0004c1d0:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate· 
0004c1e0:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href= 
0004c1f0:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation 
0004c200:·204f·5342·7569·6c64·2042·6c75·6570·7269···OSBuild·Bluepri 
0004c210:·6e74·2073·6e69·7070·6574·20e2·87b2·3c2f··nt·snippet·...</ 
0004c220:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class 
0004c230:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse 
0004c240:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i 
0004c250:·646d·3130·3134·3422·3e3c·7072·653e·3c63··dm10144"><pre><c 
0004c260:·6f64·653e·0a5b·5b70·6163·6b61·6765·735d··ode>.[[packages] 
0004c270:·5d0a·6e61·6d65·203d·2022·7265·6172·220a··].name·=·"rear". 
0004c280:·7665·7273·696f·6e20·3d20·222a·220a·3c2f··version·=·"*".</ 
0004c290:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div 
0004c2a0:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b 
0004c2b0:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data 
0004c2c0:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps 
0004c2d0:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target=" 
0004c2e0:·2369·646d·3130·3134·3522·2074·6162·696e··#idm10145"·tabin 
0004c2f0:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu 
0004c300:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan 
0004c310:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl 
0004c320:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r 
0004c330:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!" 
0004c340:·3e52·656d·6564·6961·7469·6f6e·2050·7570··>Remediation·Pup 
0004c350:·7065·7420·736e·6970·7065·7420·e287·b23c··pet·snippet·...< 
0004c360:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas 
0004c370:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps 
0004c380:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id=" 
0004c390:·6964·6d31·3031·3435·223e·3c74·6162·6c65··idm10145"><table 
0004c3a0:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta 
0004c3b0:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl 
0004c3c0:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table 
0004c3d0:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr> 
0004c3e0:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:< 
0004c3f0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td> 
0004c400:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis 
0004c410:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td 
0004c420:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t 
0004c430:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t 
0004c440:·683e·3c74·643e·6661·6c73·653c·2f74·643e··h><td>false</td> 
0004c450:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str 
0004c460:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e 
0004c470:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr>< 
0004c480:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod 
0004c490:·653e·696e·636c·7564·6520·696e·7374·616c··e>include·instal 
0004c4a0:·6c5f·7265·6172·0a0a·636c·6173·7320·696e··l_rear..class·in 
0004c4b0:·7374·616c·6c5f·7265·6172·207b·0a20·2070··stall_rear·{.··p 
0004c4c0:·6163·6b61·6765·207b·2027·7265·6172·273a··ackage·{·'rear': 
0004c4d0:·0a20·2020·2065·6e73·7572·6520·3d26·6774··.····ensure·=&gt 
0004c4e0:·3b20·2769·6e73·7461·6c6c·6564·272c·0a20··;·'installed',.· 
0004c4f0:·207d·0a7d·0a3c·2f63·6f64·653e·3c2f·7072···}.}.</code></pr 
0004c500:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class 
0004c510:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes 
0004c520:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle=" 
0004c530:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t 
0004c540:·6172·6765·743d·2223·6964·6d31·3031·3436··arget="#idm10146 
0004c550:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r 
0004c560:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari 
0004c570:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals 
0004c580:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa 
0004c590:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr 
0004c5a0:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat 
0004c5b0:·696f·6e20·5368·656c·6c20·7363·7269·7074··ion·Shell·script 
0004c5c0:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div0004c000:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
0004c5d0:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co0004c010:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
0004c5e0:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"0004c020:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
0004c5f0:·2069·643d·2269·646d·3130·3134·3622·3e3c···id="idm10146"><0004c030:·2069·643d·2269·646d·3130·3134·3322·3e3c···id="idm10143"><
0004c600:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab 
0004c610:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped0004c040:·7072·653e·3c63·6f64·653e·0a5b·5b70·6163··pre><code>.[[pac
 0004c050:·6b61·6765·735d·5d0a·6e61·6d65·203d·2022··kages]].name·=·"
 0004c060:·7265·6172·220a·7665·7273·696f·6e20·3d20··rear".version·=·
 0004c070:·222a·220a·3c2f·636f·6465·3e3c·2f70·7265··"*".</code></pre
 0004c080:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class=
 0004c090:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success
 0004c0a0:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c
 0004c0b0:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta
 0004c0c0:·7267·6574·3d22·2369·646d·3130·3134·3422··rget="#idm10144"
 0004c0d0:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro
 0004c0e0:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria
 0004c0f0:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false
 0004c100:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat
 0004c110:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre
 0004c120:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati
 0004c130:·6f6e·2050·7570·7065·7420·736e·6970·7065··on·Puppet·snippe
 0004c140:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di
 0004c150:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c
 0004c160:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse
Max diff block lines reached; 215918/243684 bytes (88.61%) of diff not shown.
26.7 KB
html2text {}
    
Offset 1120, 21 lines modifiedOffset 1120, 14 lines modified
1120 ··tags:1120 ··tags:
1121 ··-·enable_strategy1121 ··-·enable_strategy
1122 ··-·low_complexity1122 ··-·low_complexity
1123 ··-·low_disruption1123 ··-·low_disruption
1124 ··-·medium_severity1124 ··-·medium_severity
1125 ··-·no_reboot_needed1125 ··-·no_reboot_needed
1126 ··-·package_rear_installed1126 ··-·package_rear_installed
1127 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
1128 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
1129 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
1130 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
1131 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
1132 package·--add=rear 
1133 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81127 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
1134 [[packages]]1128 [[packages]]
1135 name·=·"rear"1129 name·=·"rear"
1136 version·=·"*"1130 version·=·"*"
1137 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81131 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1138 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1132 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 1159, 14 lines modifiedOffset 1152, 21 lines modified
1159 if·!·rpm·-q·--quiet·"rear"·;·then1152 if·!·rpm·-q·--quiet·"rear"·;·then
1160 ····yum·install·-y·"rear"1153 ····yum·install·-y·"rear"
1161 fi1154 fi
  
1162 else1155 else
1163 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'1156 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
1164 fi1157 fi
 1158 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 1159 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1160 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1161 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1162 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 1163 package·--add=rear
1165 Group  ·Updating·Software·  Group·contains·6·rules1164 Group  ·Updating·Software·  Group·contains·6·rules
1166 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·yum·command·line·tool·is·used·to·install·and·update·software·packages.·The·system·also·provides·a·graphical·software·update·tool·in·the·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·menu,·in·the·A\x8Ad\x8dm\x8mi\x8in\x8ni\x8is\x8st\x8tr\x8ra\x8at\x8ti\x8io\x8on\x8n·submenu,·called·S\x8So\x8of\x8ft\x8tw\x8wa\x8ar\x8re\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8e.1165 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·yum·command·line·tool·is·used·to·install·and·update·software·packages.·The·system·also·provides·a·graphical·software·update·tool·in·the·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·menu,·in·the·A\x8Ad\x8dm\x8mi\x8in\x8ni\x8is\x8st\x8tr\x8ra\x8at\x8ti\x8io\x8on\x8n·submenu,·called·S\x8So\x8of\x8ft\x8tw\x8wa\x8ar\x8re\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8e.
  
1167 Oracle·Linux·8·systems·contain·an·installed·software·catalog·called·the·RPM·database,·which·records·metadata·of·installed·packages.·Consistently·using·yum·or·the·graphical·S\x8So\x8of\x8ft\x8tw\x8wa\x8ar\x8re\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8e·for·all·software·installation·allows·for·insight·into·the·current·inventory·of·installed·software·on·the·system.1166 Oracle·Linux·8·systems·contain·an·installed·software·catalog·called·the·RPM·database,·which·records·metadata·of·installed·packages.·Consistently·using·yum·or·the·graphical·S\x8So\x8of\x8ft\x8tw\x8wa\x8ar\x8re\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8e·for·all·software·installation·allows·for·insight·into·the·current·inventory·of·installed·software·on·the·system.
  
1168 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·d\x8dn\x8nf\x8f-\x8-a\x8au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8c·t\x8to\x8o·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·O\x8On\x8nl\x8ly\x8y·S\x8Se\x8ec\x8cu\x8ur\x8ri\x8it\x8ty\x8y·U\x8Up\x8pd\x8da\x8at\x8te\x8es\x8s·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*1167 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·d\x8dn\x8nf\x8f-\x8-a\x8au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8c·t\x8to\x8o·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·O\x8On\x8nl\x8ly\x8y·S\x8Se\x8ec\x8cu\x8ur\x8ri\x8it\x8ty\x8y·U\x8Up\x8pd\x8da\x8at\x8te\x8es\x8s·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
1169 To·configure·dnf-automatic·to·install·only·security·updates·automatically,·set·upgrade_type·to·security·under·[commands]·section·in·/etc/dnf/automatic.conf.1168 To·configure·dnf-automatic·to·install·only·security·updates·automatically,·set·upgrade_type·to·security·under·[commands]·section·in·/etc/dnf/automatic.conf.
Offset 2315, 21 lines modifiedOffset 2315, 14 lines modified
2315 ··-·NIST-800-53-CM-6(a)2315 ··-·NIST-800-53-CM-6(a)
2316 ··-·enable_strategy2316 ··-·enable_strategy
2317 ··-·low_complexity2317 ··-·low_complexity
2318 ··-·low_disruption2318 ··-·low_disruption
2319 ··-·medium_severity2319 ··-·medium_severity
2320 ··-·no_reboot_needed2320 ··-·no_reboot_needed
2321 ··-·package_rsyslog_installed2321 ··-·package_rsyslog_installed
2322 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
2323 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
2324 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
2325 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
2326 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
2327 package·--add=rsyslog 
2328 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x82322 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
2329 [[packages]]2323 [[packages]]
2330 name·=·"rsyslog"2324 name·=·"rsyslog"
2331 version·=·"*"2325 version·=·"*"
2332 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x82326 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
2333 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low2327 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 2354, 14 lines modifiedOffset 2347, 21 lines modified
2354 if·!·rpm·-q·--quiet·"rsyslog"·;·then2347 if·!·rpm·-q·--quiet·"rsyslog"·;·then
2355 ····yum·install·-y·"rsyslog"2348 ····yum·install·-y·"rsyslog"
2356 fi2349 fi
  
2357 else2350 else
2358 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'2351 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
2359 fi2352 fi
 2353 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 2354 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 2355 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 2356 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 2357 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 2358 package·--add=rsyslog
2360 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·r\x8rs\x8sy\x8ys\x8sl\x8lo\x8og\x8g·S\x8Se\x8er\x8rv\x8vi\x8ic\x8ce\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*2359 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·r\x8rs\x8sy\x8ys\x8sl\x8lo\x8og\x8g·S\x8Se\x8er\x8rv\x8vi\x8ic\x8ce\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
2361 The·rsyslog·service·provides·syslog-style·logging·by·default·on·Oracle·Linux·8.·The·rsyslog·service·can·be·enabled·with·the·following·command:2360 The·rsyslog·service·provides·syslog-style·logging·by·default·on·Oracle·Linux·8.·The·rsyslog·service·can·be·enabled·with·the·following·command:
2362 $·sudo·systemctl·enable·rsyslog.service2361 $·sudo·systemctl·enable·rsyslog.service
2363 Rationale:··The·rsyslog·service·must·be·running·in·order·to·provide·logging·services,·which·are·essential·to·system·administration.2362 Rationale:··The·rsyslog·service·must·be·running·in·order·to·provide·logging·services,·which·are·essential·to·system·administration.
2364 Severity: ··medium2363 Severity: ··medium
2365 Rule·ID:····xccdf_org.ssgproject.content_rule_service_rsyslog_enabled2364 Rule·ID:····xccdf_org.ssgproject.content_rule_service_rsyslog_enabled
2366 ············_\x8c_\x8i_\x8s_\x8-_\x8c_\x8s_\x8c········1,·12,·13,·14,·15,·16,·2,·3,·5,·6,·7,·8,·92365 ············_\x8c_\x8i_\x8s_\x8-_\x8c_\x8s_\x8c········1,·12,·13,·14,·15,·16,·2,·3,·5,·6,·7,·8,·9
Offset 2554, 21 lines modifiedOffset 2554, 14 lines modified
2554 ··-·PCI-DSSv4-1.2.12554 ··-·PCI-DSSv4-1.2.1
2555 ··-·enable_strategy2555 ··-·enable_strategy
2556 ··-·low_complexity2556 ··-·low_complexity
2557 ··-·low_disruption2557 ··-·low_disruption
2558 ··-·medium_severity2558 ··-·medium_severity
2559 ··-·no_reboot_needed2559 ··-·no_reboot_needed
2560 ··-·package_firewalld_installed2560 ··-·package_firewalld_installed
2561 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
2562 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
2563 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
2564 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
2565 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
2566 package·--add=firewalld 
2567 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x82561 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
2568 [[packages]]2562 [[packages]]
2569 name·=·"firewalld"2563 name·=·"firewalld"
2570 version·=·"*"2564 version·=·"*"
2571 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x82565 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
2572 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low2566 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 2593, 14 lines modifiedOffset 2586, 21 lines modified
2593 if·!·rpm·-q·--quiet·"firewalld"·;·then2586 if·!·rpm·-q·--quiet·"firewalld"·;·then
2594 ····yum·install·-y·"firewalld"2587 ····yum·install·-y·"firewalld"
2595 fi2588 fi
  
2596 else2589 else
2597 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'2590 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
2598 fi2591 fi
 2592 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 2593 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 2594 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 2595 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 2596 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 2597 package·--add=firewalld
2599 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·f\x8fi\x8ir\x8re\x8ew\x8wa\x8al\x8ll\x8ld\x8d·E\x8En\x8na\x8ab\x8bl\x8le\x8ed\x8d·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*2598 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·f\x8fi\x8ir\x8re\x8ew\x8wa\x8al\x8ll\x8ld\x8d·E\x8En\x8na\x8ab\x8bl\x8le\x8ed\x8d·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
2600 The·firewalld·service·can·be·enabled·with·the·following·command:2599 The·firewalld·service·can·be·enabled·with·the·following·command:
2601 $·sudo·systemctl·enable·firewalld.service2600 $·sudo·systemctl·enable·firewalld.service
Max diff block lines reached; 21649/27336 bytes (79.20%) of diff not shown.
145 KB
./usr/share/doc/ssg-nondebian/ssg-ol8-guide-hipaa.html
    
Offset 39528, 174 lines modifiedOffset 39528, 174 lines modified
0009a670:·7267·6574·3d22·2369·646d·3337·3830·3522··rget="#idm37805"0009a670:·7267·6574·3d22·2369·646d·3337·3830·3522··rget="#idm37805"
0009a680:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro0009a680:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro
0009a690:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria0009a690:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria
0009a6a0:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false0009a6a0:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false
0009a6b0:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat0009a6b0:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat
0009a6c0:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre0009a6c0:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre
0009a6d0:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati0009a6d0:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati
0009a6e0:·6f6e·2041·6e61·636f·6e64·6120·736e·6970··on·Anaconda·snip0009a6e0:·6f6e·204f·5342·7569·6c64·2042·6c75·6570··on·OSBuild·Bluep
 0009a6f0:·7269·6e74·2073·6e69·7070·6574·20e2·87b2··rint·snippet·...
 0009a700:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
 0009a710:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
 0009a720:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
 0009a730:·2269·646d·3337·3830·3522·3e3c·7072·653e··"idm37805"><pre>
 0009a740:·3c63·6f64·653e·0a5b·6375·7374·6f6d·697a··<code>.[customiz
 0009a750:·6174·696f·6e73·2e73·6572·7669·6365·735d··ations.services]
 0009a760:·0a6d·6173·6b65·6420·3d20·5b22·6b64·756d··.masked·=·["kdum
 0009a770:·7022·5d0a·3c2f·636f·6465·3e3c·2f70·7265··p"].</code></pre
 0009a780:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class=
 0009a790:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success
 0009a7a0:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c
 0009a7b0:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta
 0009a7c0:·7267·6574·3d22·2369·646d·3337·3830·3622··rget="#idm37806"
 0009a7d0:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro
 0009a7e0:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria
 0009a7f0:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false
 0009a800:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat
 0009a810:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre
 0009a820:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati
 0009a830:·6f6e·2050·7570·7065·7420·736e·6970·7065··on·Puppet·snippe
0009a6f0:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br><0009a840:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di
0009a700:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel0009a850:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c
0009a710:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap0009a860:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse
0009a720:·7365·2220·6964·3d22·6964·6d33·3738·3035··se"·id="idm378050009a870:·2220·6964·3d22·6964·6d33·3738·3036·223e··"·id="idm37806">
0009a730:·223e·3c70·7265·3e3c·636f·6465·3e0a·6b64··"><pre><code>.kd 
0009a740:·756d·7020·2d2d·6469·7361·626c·650a·3c2f··ump·--disable.</ 
0009a750:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div 
0009a760:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b 
0009a770:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data 
0009a780:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps 
0009a790:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target=" 
0009a7a0:·2369·646d·3337·3830·3622·2074·6162·696e··#idm37806"·tabin 
0009a7b0:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu 
0009a7c0:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan 
0009a7d0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl 
0009a7e0:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r 
0009a7f0:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!" 
0009a800:·3e52·656d·6564·6961·7469·6f6e·204f·5342··>Remediation·OSB 
0009a810:·7569·6c64·2042·6c75·6570·7269·6e74·2073··uild·Blueprint·s 
0009a820:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b 
0009a830:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa0009a880:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta
 0009a890:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe
 0009a8a0:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered
 0009a8b0:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed
 0009a8c0:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple
0009a840:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col 
0009a850:·6c61·7073·6522·2069·643d·2269·646d·3337··lapse"·id="idm37 
0009a860:·3830·3622·3e3c·7072·653e·3c63·6f64·653e··806"><pre><code> 
0009a870:·0a5b·6375·7374·6f6d·697a·6174·696f·6e73··.[customizations 
0009a880:·2e73·6572·7669·6365·735d·0a6d·6173·6b65··.services].maske 
0009a890:·6420·3d20·5b22·6b64·756d·7022·5d0a·3c2f··d·=·["kdump"].</ 
0009a8a0:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div 
0009a8b0:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b 
0009a8c0:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data 
0009a8d0:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps 
0009a8e0:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target=" 
0009a8f0:·2369·646d·3337·3830·3722·2074·6162·696e··#idm37807"·tabin 
0009a900:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu 
0009a910:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan 
0009a920:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl 
0009a930:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r 
0009a940:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!" 
0009a950:·3e52·656d·6564·6961·7469·6f6e·2050·7570··>Remediation·Pup 
0009a960:·7065·7420·736e·6970·7065·7420·e287·b23c··pet·snippet·...< 
0009a970:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas 
0009a980:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps 
0009a990:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id=" 
0009a9a0:·6964·6d33·3738·3037·223e·3c74·6162·6c65··idm37807"><table 
0009a9b0:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta 
0009a9c0:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl 
0009a9d0:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table 
0009a9e0:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr> 
0009a9f0:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:< 
0009aa00:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td> 
0009aa10:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis 
0009aa20:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td 
0009aa30:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t 
0009aa40:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t 
0009aa50:·683e·3c74·643e·6661·6c73·653c·2f74·643e··h><td>false</td> 
0009aa60:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str 
0009aa70:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e 
0009aa80:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr>< 
0009aa90:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod 
0009aaa0:·653e·696e·636c·7564·6520·6469·7361·626c··e>include·disabl 
0009aab0:·655f·6b64·756d·700a·0a63·6c61·7373·2064··e_kdump..class·d 
0009aac0:·6973·6162·6c65·5f6b·6475·6d70·207b·0a20··isable_kdump·{.· 
0009aad0:·2073·6572·7669·6365·207b·276b·6475·6d70···service·{'kdump 
0009aae0:·273a·0a20·2020·2065·6e61·626c·6520·3d26··':.····enable·=& 
0009aaf0:·6774·3b20·6661·6c73·652c·0a20·2020·2065··gt;·false,.····e 
0009ab00:·6e73·7572·6520·3d26·6774·3b20·2773·746f··nsure·=&gt;·'sto 
0009ab10:·7070·6564·272c·0a20·207d·0a7d·0a3c·2f63··pped',.··}.}.</c 
0009ab20:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div> 
0009ab30:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt 
0009ab40:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data- 
0009ab50:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse 
0009ab60:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="# 
0009ab70:·6964·6d33·3738·3038·2220·7461·6269·6e64··idm37808"·tabind 
0009ab80:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but 
0009ab90:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand 
0009aba0:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title 
0009abb0:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re 
0009abc0:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!"> 
0009abd0:·5265·6d65·6469·6174·696f·6e20·5368·656c··Remediation·Shel 
0009abe0:·6c20·7363·7269·7074·20e2·87b2·3c2f·613e··l·script·...</a> 
0009abf0:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class=" 
0009ac00:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c 
0009ac10:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm 
0009ac20:·3337·3830·3822·3e3c·7461·626c·6520·636c··37808"><table·cl 
0009ac30:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table 
0009ac40:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b 
0009ac50:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co 
0009ac60:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th 
0009ac70:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th 
0009ac80:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t 
0009ac90:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup 
0009aca0:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo0009a8d0:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo
0009acb0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><0009a8e0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
0009acc0:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th>< 
Max diff block lines reached; 109768/132428 bytes (82.89%) of diff not shown.
15.6 KB
html2text {}
    
Offset 5158, 17 lines modifiedOffset 5158, 14 lines modified
5158 ··-·NIST-800-53-CM-7(b)5158 ··-·NIST-800-53-CM-7(b)
5159 ··-·disable_strategy5159 ··-·disable_strategy
5160 ··-·low_complexity5160 ··-·low_complexity
5161 ··-·low_disruption5161 ··-·low_disruption
5162 ··-·medium_severity5162 ··-·medium_severity
5163 ··-·no_reboot_needed5163 ··-·no_reboot_needed
5164 ··-·service_kdump_disabled5164 ··-·service_kdump_disabled
5165 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
5166 kdump·--disable 
5167 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x85165 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
5168 [customizations.services]5166 [customizations.services]
5169 masked·=·["kdump"]5167 masked·=·["kdump"]
5170 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x85168 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
5171 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low5169 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
5172 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low5170 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
Offset 5207, 14 lines modifiedOffset 5204, 17 lines modified
5207 #·so·let's·reset·the·state·so·OVAL·checks·pass.5204 #·so·let's·reset·the·state·so·OVAL·checks·pass.
5208 #·Service·should·be·'inactive',·not·'failed'·after·reboot·though.5205 #·Service·should·be·'inactive',·not·'failed'·after·reboot·though.
5209 "$SYSTEMCTL_EXEC"·reset-failed·'kdump.service'·||·true5206 "$SYSTEMCTL_EXEC"·reset-failed·'kdump.service'·||·true
  
5210 else5207 else
5211 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'5208 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
5212 fi5209 fi
 5210 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 5211 kdump·--disable
5213 Group  ·Cron·and·At·Daemons·  Group·contains·1·rule5212 Group  ·Cron·and·At·Daemons·  Group·contains·1·rule
5214 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·cron·and·at·services·are·used·to·allow·commands·to·be·executed·at·a·later·time.·The·cron·service·is·required·by·almost·all·systems·to·perform·necessary·maintenance·tasks,·while·at·may·or·may·not·be·required·on·a·given·system.·Both·daemons·should·be·configured·defensively.5213 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·cron·and·at·services·are·used·to·allow·commands·to·be·executed·at·a·later·time.·The·cron·service·is·required·by·almost·all·systems·to·perform·necessary·maintenance·tasks,·while·at·may·or·may·not·be·required·on·a·given·system.·Both·daemons·should·be·configured·defensively.
5215 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·c\x8cr\x8ro\x8on\x8n·S\x8Se\x8er\x8rv\x8vi\x8ic\x8ce\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*5214 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·c\x8cr\x8ro\x8on\x8n·S\x8Se\x8er\x8rv\x8vi\x8ic\x8ce\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
5216 The·crond·service·is·used·to·execute·commands·at·preconfigured·times.·It·is·required·by·almost·all·systems·to·perform·necessary·maintenance·tasks,·such·as·notifying·root·of·system·activity.·The·crond·service·can·be·enabled·with·the·following·command:5215 The·crond·service·is·used·to·execute·commands·at·preconfigured·times.·It·is·required·by·almost·all·systems·to·perform·necessary·maintenance·tasks,·such·as·notifying·root·of·system·activity.·The·crond·service·can·be·enabled·with·the·following·command:
5217 $·sudo·systemctl·enable·crond.service5216 $·sudo·systemctl·enable·crond.service
5218 Rationale:··Due·to·its·usage·for·maintenance·and·security-supporting·tasks,·enabling·the·cron·daemon·is·essential.5217 Rationale:··Due·to·its·usage·for·maintenance·and·security-supporting·tasks,·enabling·the·cron·daemon·is·essential.
5219 Severity: ··medium5218 Severity: ··medium
Offset 5442, 21 lines modifiedOffset 5442, 14 lines modified
5442 ··-·PCI-DSSv4-2.2.45442 ··-·PCI-DSSv4-2.2.4
5443 ··-·disable_strategy5443 ··-·disable_strategy
5444 ··-·low_complexity5444 ··-·low_complexity
5445 ··-·low_disruption5445 ··-·low_disruption
5446 ··-·low_severity5446 ··-·low_severity
5447 ··-·no_reboot_needed5447 ··-·no_reboot_needed
5448 ··-·package_xinetd_removed5448 ··-·package_xinetd_removed
5449 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
5450 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
5451 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
5452 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
5453 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable 
  
5454 package·--remove=xinetd 
5455 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x85449 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
5456 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low5450 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
5457 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low5451 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
5458 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false5452 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
5459 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable5453 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
5460 include·remove_xinetd5454 include·remove_xinetd
  
Offset 5482, 14 lines modifiedOffset 5475, 21 lines modified
5482 if·rpm·-q·--quiet·"xinetd"·;·then5475 if·rpm·-q·--quiet·"xinetd"·;·then
5483 yum·remove·-y·"xinetd"5476 yum·remove·-y·"xinetd"
5484 fi5477 fi
  
5485 else5478 else
5486 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'5479 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
5487 fi5480 fi
 5481 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 5482 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 5483 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 5484 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 5485 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
  
 5486 package·--remove=xinetd
5488 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·D\x8Di\x8is\x8sa\x8ab\x8bl\x8le\x8e·x\x8xi\x8in\x8ne\x8et\x8td\x8d·S\x8Se\x8er\x8rv\x8vi\x8ic\x8ce\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*5487 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·D\x8Di\x8is\x8sa\x8ab\x8bl\x8le\x8e·x\x8xi\x8in\x8ne\x8et\x8td\x8d·S\x8Se\x8er\x8rv\x8vi\x8ic\x8ce\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
5489 The·xinetd·service·can·be·disabled·with·the·following·command:5488 The·xinetd·service·can·be·disabled·with·the·following·command:
5490 $·sudo·systemctl·mask·--now·xinetd.service5489 $·sudo·systemctl·mask·--now·xinetd.service
5491 Rationale:··The·xinetd·service·provides·a·dedicated·listener·service·for·some·programs,·which·is·no·longer·necessary·for·commonly-used·network·services.·Disabling·it·ensures·that·these·uncommon·services·are·not·running,·and·also·prevents·attacks·against·xinetd·itself.5490 Rationale:··The·xinetd·service·provides·a·dedicated·listener·service·for·some·programs,·which·is·no·longer·necessary·for·commonly-used·network·services.·Disabling·it·ensures·that·these·uncommon·services·are·not·running,·and·also·prevents·attacks·against·xinetd·itself.
5492 Severity: ··medium5491 Severity: ··medium
5493 Rule·ID:····xccdf_org.ssgproject.content_rule_service_xinetd_disabled5492 Rule·ID:····xccdf_org.ssgproject.content_rule_service_xinetd_disabled
5494 ············_\x8c_\x8i_\x8s_\x8-_\x8c_\x8s_\x8c········11,·12,·14,·15,·3,·8,·95493 ············_\x8c_\x8i_\x8s_\x8-_\x8c_\x8s_\x8c········11,·12,·14,·15,·3,·8,·9
Offset 5688, 21 lines modifiedOffset 5688, 14 lines modified
5688 ··-·PCI-DSSv4-2.2.45688 ··-·PCI-DSSv4-2.2.4
5689 ··-·disable_strategy5689 ··-·disable_strategy
5690 ··-·high_severity5690 ··-·high_severity
5691 ··-·low_complexity5691 ··-·low_complexity
5692 ··-·low_disruption5692 ··-·low_disruption
5693 ··-·no_reboot_needed5693 ··-·no_reboot_needed
5694 ··-·package_rsh-server_removed5694 ··-·package_rsh-server_removed
5695 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
5696 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
5697 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
5698 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
5699 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable 
  
5700 package·--remove=rsh-server 
5701 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x85695 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
5702 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low5696 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
5703 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low5697 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
5704 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false5698 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
5705 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable5699 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
5706 include·remove_rsh-server5700 include·remove_rsh-server
  
Offset 5722, 14 lines modifiedOffset 5715, 21 lines modified
5722 #»      ···that·depend·on·rsh-server.·Execute·this5715 #»      ···that·depend·on·rsh-server.·Execute·this
5723 #»      ···remediation·AFTER·testing·on·a·non-production5716 #»      ···remediation·AFTER·testing·on·a·non-production
5724 #»      ···system!5717 #»      ···system!
  
5725 if·rpm·-q·--quiet·"rsh-server"·;·then5718 if·rpm·-q·--quiet·"rsh-server"·;·then
5726 yum·remove·-y·"rsh-server"5719 yum·remove·-y·"rsh-server"
5727 fi5720 fi
 5721 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 5722 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 5723 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 5724 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 5725 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
  
 5726 package·--remove=rsh-server
5728 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·D\x8Di\x8is\x8sa\x8ab\x8bl\x8le\x8e·r\x8re\x8ex\x8xe\x8ec\x8c·S\x8Se\x8er\x8rv\x8vi\x8ic\x8ce\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*5727 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·D\x8Di\x8is\x8sa\x8ab\x8bl\x8le\x8e·r\x8re\x8ex\x8xe\x8ec\x8c·S\x8Se\x8er\x8rv\x8vi\x8ic\x8ce\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
5729 The·rexec·service,·which·is·available·with·the·rsh-server·package·and·runs·as·a·service·through·xinetd·or·separately·as·a·systemd·socket,·should·be·disabled.·If·using·xinetd,·set·disable·to·yes·in·/etc/xinetd.d/rexec.·The·rexec·socket·can·be·disabled·with·the·following·command:5728 The·rexec·service,·which·is·available·with·the·rsh-server·package·and·runs·as·a·service·through·xinetd·or·separately·as·a·systemd·socket,·should·be·disabled.·If·using·xinetd,·set·disable·to·yes·in·/etc/xinetd.d/rexec.·The·rexec·socket·can·be·disabled·with·the·following·command:
5730 $·sudo·systemctl·mask·--now·rexec.socket5729 $·sudo·systemctl·mask·--now·rexec.socket
5731 Rationale:··The·rexec·service·uses·unencrypted·network·communications,·which·means·that·data·from·the·login·session,·including·passwords·and·all·other·information·transmitted·during·the·session,·can·be·stolen·by·eavesdroppers·on·the·network.5730 Rationale:··The·rexec·service·uses·unencrypted·network·communications,·which·means·that·data·from·the·login·session,·including·passwords·and·all·other·information·transmitted·during·the·session,·can·be·stolen·by·eavesdroppers·on·the·network.
5732 Severity: ··high5731 Severity: ··high
5733 Rule·ID:····xccdf_org.ssgproject.content_rule_service_rexec_disabled5732 Rule·ID:····xccdf_org.ssgproject.content_rule_service_rexec_disabled
5734 ············_\x8c_\x8i_\x8s_\x8-_\x8c_\x8s_\x8c········11,·12,·14,·15,·3,·8,·95733 ············_\x8c_\x8i_\x8s_\x8-_\x8c_\x8s_\x8c········11,·12,·14,·15,·3,·8,·9
Offset 6196, 21 lines modifiedOffset 6196, 14 lines modified
6196 ··-·PCI-DSSv4-2.2.46196 ··-·PCI-DSSv4-2.2.4
6197 ··-·disable_strategy6197 ··-·disable_strategy
6198 ··-·low_complexity6198 ··-·low_complexity
Max diff block lines reached; 10091/15966 bytes (63.20%) of diff not shown.
426 KB
./usr/share/doc/ssg-nondebian/ssg-ol8-guide-ism_o.html
    
Offset 17413, 143 lines modifiedOffset 17413, 143 lines modified
00044040:·6172·6765·743d·2223·6964·6d35·3639·3722··arget="#idm5697"00044040:·6172·6765·743d·2223·6964·6d35·3639·3722··arget="#idm5697"
00044050:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro00044050:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro
00044060:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria00044060:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria
00044070:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false00044070:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false
00044080:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat00044080:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat
00044090:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre00044090:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre
000440a0:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati000440a0:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati
 000440b0:·6f6e·204f·5342·7569·6c64·2042·6c75·6570··on·OSBuild·Bluep
 000440c0:·7269·6e74·2073·6e69·7070·6574·20e2·87b2··rint·snippet·...
 000440d0:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
 000440e0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
 000440f0:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
 00044100:·2269·646d·3536·3937·223e·3c70·7265·3e3c··"idm5697"><pre><
 00044110:·636f·6465·3e0a·5b5b·7061·636b·6167·6573··code>.[[packages
 00044120:·5d5d·0a6e·616d·6520·3d20·2261·6964·6522··]].name·=·"aide"
 00044130:·0a76·6572·7369·6f6e·203d·2022·2a22·0a3c··.version·=·"*".<
 00044140:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di
 00044150:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn·
 00044160:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat
 00044170:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap
 00044180:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
 00044190:·2223·6964·6d35·3639·3822·2074·6162·696e··"#idm5698"·tabin
 000441a0:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
 000441b0:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
 000441c0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
 000441d0:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
 000441e0:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
 000441f0:·3e52·656d·6564·6961·7469·6f6e·2050·7570··>Remediation·Pup
 00044200:·7065·7420·736e·6970·7065·7420·e287·b23c··pet·snippet·...<
 00044210:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas
 00044220:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps
 00044230:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="
 00044240:·6964·6d35·3639·3822·3e3c·7461·626c·6520··idm5698"><table·
 00044250:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab
 00044260:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table
 00044270:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-
 00044280:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><
 00044290:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</
 000442a0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
 000442b0:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr
 000442c0:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>
 000442d0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
 000442e0:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th
 000442f0:·3e3c·7464·3e66·616c·7365·3c2f·7464·3e3c··><td>false</td><
 00044300:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra
 00044310:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en
 00044320:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></
 00044330:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code
 00044340:·3e69·6e63·6c75·6465·2069·6e73·7461·6c6c··>include·install
 00044350:·5f61·6964·650a·0a63·6c61·7373·2069·6e73··_aide..class·ins
 00044360:·7461·6c6c·5f61·6964·6520·7b0a·2020·7061··tall_aide·{.··pa
 00044370:·636b·6167·6520·7b20·2761·6964·6527·3a0a··ckage·{·'aide':.
 00044380:·2020·2020·656e·7375·7265·203d·2667·743b······ensure·=&gt;
 00044390:·2027·696e·7374·616c·6c65·6427·2c0a·2020···'installed',.··
 000443a0:·7d0a·7d0a·3c2f·636f·6465·3e3c·2f70·7265··}.}.</code></pre
 000443b0:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class=
 000443c0:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success
 000443d0:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c
 000443e0:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta
 000443f0:·7267·6574·3d22·2369·646d·3536·3939·2220··rget="#idm5699"·
 00044400:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol
 00044410:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-
 00044420:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"
 00044430:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate
 00044440:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href
 00044450:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio
 00044460:·6e20·5368·656c·6c20·7363·7269·7074·20e2··n·Shell·script·.
 00044470:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c
 00044480:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
 00044490:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
 000444a0:·643d·2269·646d·3536·3939·223e·3c74·6162··d="idm5699"><tab
 000444b0:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·
 000444c0:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta
 000444d0:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab
 000444e0:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t
 000444f0:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity
 00044500:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
 00044510:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D
 00044520:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><
 00044530:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
 00044540:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:<
 00044550:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t
 00044560:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S
 00044570:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td
 00044580:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr
 00044590:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c
 000445a0:·6f64·653e·2320·5265·6d65·6469·6174·696f··ode>#·Remediatio
 000445b0:·6e20·6973·2061·7070·6c69·6361·626c·6520··n·is·applicable·
 000445c0:·6f6e·6c79·2069·6e20·6365·7274·6169·6e20··only·in·certain·
 000445d0:·706c·6174·666f·726d·730a·6966·2072·706d··platforms.if·rpm
 000445e0:·202d·2d71·7569·6574·202d·7120·6b65·726e···--quiet·-q·kern
 000445f0:·656c·207c·7c20·7270·6d20·2d2d·7175·6965··el·||·rpm·--quie
 00044600:·7420·2d71·206b·6572·6e65·6c2d·7565·6b3b··t·-q·kernel-uek;
 00044610:·2074·6865·6e0a·0a69·6620·2120·7270·6d20···then..if·!·rpm·
 00044620:·2d71·202d·2d71·7569·6574·2022·6169·6465··-q·--quiet·"aide
 00044630:·2220·3b20·7468·656e·0a20·2020·2079·756d··"·;·then.····yum
 00044640:·2069·6e73·7461·6c6c·202d·7920·2261·6964···install·-y·"aid
 00044650:·6522·0a66·690a·0a65·6c73·650a·2020·2020··e".fi..else.····
 00044660:·2667·743b·2661·6d70·3b32·2065·6368·6f20··&gt;&amp;2·echo·
 00044670:·2752·656d·6564·6961·7469·6f6e·2069·7320··'Remediation·is·
 00044680:·6e6f·7420·6170·706c·6963·6162·6c65·2c20··not·applicable,·
 00044690:·6e6f·7468·696e·6720·7761·7320·646f·6e65··nothing·was·done
 000446a0:·270a·6669·0a3c·2f63·6f64·653e·3c2f·7072··'.fi.</code></pr
 000446b0:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class
 000446c0:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes
 000446d0:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle="
 000446e0:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t
 000446f0:·6172·6765·743d·2223·6964·6d35·3730·3022··arget="#idm5700"
 00044700:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro
 00044710:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria
 00044720:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false
 00044730:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat
 00044740:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre
 00044750:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati
000440b0:·6f6e·2041·6e61·636f·6e64·6120·736e·6970··on·Anaconda·snip00044760:·6f6e·2041·6e61·636f·6e64·6120·736e·6970··on·Anaconda·snip
000440c0:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br><00044770:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br><
000440d0:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel00044780:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
000440e0:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap00044790:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap
000440f0:·7365·2220·6964·3d22·6964·6d35·3639·3722··se"·id="idm5697"000447a0:·7365·2220·6964·3d22·6964·6d35·3730·3022··se"·id="idm5700"
00044100:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t000447b0:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t
00044110:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip 
00044120:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere 
00044130:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense 
00044140:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl 
00044150:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l 
00044160:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr> 
00044170:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:< 
Max diff block lines reached; 373468/391850 bytes (95.31%) of diff not shown.
43.7 KB
html2text {}
    
Offset 721, 21 lines modifiedOffset 721, 14 lines modified
721 ··-·PCI-DSSv4-11.5.2721 ··-·PCI-DSSv4-11.5.2
722 ··-·enable_strategy722 ··-·enable_strategy
723 ··-·low_complexity723 ··-·low_complexity
724 ··-·low_disruption724 ··-·low_disruption
725 ··-·medium_severity725 ··-·medium_severity
726 ··-·no_reboot_needed726 ··-·no_reboot_needed
727 ··-·package_aide_installed727 ··-·package_aide_installed
728 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
729 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
730 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
731 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
732 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
733 package·--add=aide 
734 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8728 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
735 [[packages]]729 [[packages]]
736 name·=·"aide"730 name·=·"aide"
737 version·=·"*"731 version·=·"*"
738 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8732 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
739 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low733 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 760, 14 lines modifiedOffset 753, 21 lines modified
760 if·!·rpm·-q·--quiet·"aide"·;·then753 if·!·rpm·-q·--quiet·"aide"·;·then
761 ····yum·install·-y·"aide"754 ····yum·install·-y·"aide"
762 fi755 fi
  
763 else756 else
764 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'757 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
765 fi758 fi
 759 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 760 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 761 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 762 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 763 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 764 package·--add=aide
766 Group  ·Federal·Information·Processing·Standard·(FIPS)·  Group·contains·2·rules765 Group  ·Federal·Information·Processing·Standard·(FIPS)·  Group·contains·2·rules
767 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·Federal·Information·Processing·Standard·(FIPS)·is·a·computer·security·standard·which·is·developed·by·the·U.S.·Government·and·industry·working·groups·to·validate·the·quality·of·cryptographic·modules.·The·FIPS·standard·provides·four·security·levels·to·ensure·adequate·coverage·of·different·industries,·implementation·of·cryptographic·modules,·and·organizational·sizes·and·requirements.766 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·Federal·Information·Processing·Standard·(FIPS)·is·a·computer·security·standard·which·is·developed·by·the·U.S.·Government·and·industry·working·groups·to·validate·the·quality·of·cryptographic·modules.·The·FIPS·standard·provides·four·security·levels·to·ensure·adequate·coverage·of·different·industries,·implementation·of·cryptographic·modules,·and·organizational·sizes·and·requirements.
  
768 FIPS·140-2·is·the·current·standard·for·validating·that·mechanisms·used·to·access·cryptographic·modules·utilize·authentication·that·meets·industry·and·government·requirements.·For·government·systems,·this·allows·Security·Levels·1,·2,·3,·or·4·for·use·on·Oracle·Linux·8.767 FIPS·140-2·is·the·current·standard·for·validating·that·mechanisms·used·to·access·cryptographic·modules·utilize·authentication·that·meets·industry·and·government·requirements.·For·government·systems,·this·allows·Security·Levels·1,·2,·3,·or·4·for·use·on·Oracle·Linux·8.
  
769 See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8c\x8c_\x8s\x8s_\x8r\x8r_\x8c\x8c_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8l\x8l_\x8i\x8i_\x8c\x8c_\x8a\x8a_\x8t\x8t_\x8i\x8i_\x8o\x8o_\x8n\x8n_\x8s\x8s_\x8/\x8/_\x8P\x8P_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x8h\x8h_\x8t\x8t_\x8m\x8m_\x8l\x8l·for·more·information.768 See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8c\x8c_\x8s\x8s_\x8r\x8r_\x8c\x8c_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8l\x8l_\x8i\x8i_\x8c\x8c_\x8a\x8a_\x8t\x8t_\x8i\x8i_\x8o\x8o_\x8n\x8n_\x8s\x8s_\x8/\x8/_\x8P\x8P_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x8h\x8h_\x8t\x8t_\x8m\x8m_\x8l\x8l·for·more·information.
770 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·D\x8Dr\x8ra\x8ac\x8cu\x8ut\x8t·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8du\x8ul\x8le\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*769 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·D\x8Dr\x8ra\x8ac\x8cu\x8ut\x8t·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8du\x8ul\x8le\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
Offset 1284, 21 lines modifiedOffset 1284, 14 lines modified
1284 ··-·PCI-DSSv4-2.2.61284 ··-·PCI-DSSv4-2.2.6
1285 ··-·enable_strategy1285 ··-·enable_strategy
1286 ··-·low_complexity1286 ··-·low_complexity
1287 ··-·low_disruption1287 ··-·low_disruption
1288 ··-·medium_severity1288 ··-·medium_severity
1289 ··-·no_reboot_needed1289 ··-·no_reboot_needed
1290 ··-·package_sudo_installed1290 ··-·package_sudo_installed
1291 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
1292 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
1293 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
1294 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
1295 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
1296 package·--add=sudo 
1297 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81291 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
1298 [[packages]]1292 [[packages]]
1299 name·=·"sudo"1293 name·=·"sudo"
1300 version·=·"*"1294 version·=·"*"
1301 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81295 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1302 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1296 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 1323, 14 lines modifiedOffset 1316, 21 lines modified
1323 if·!·rpm·-q·--quiet·"sudo"·;·then1316 if·!·rpm·-q·--quiet·"sudo"·;·then
1324 ····yum·install·-y·"sudo"1317 ····yum·install·-y·"sudo"
1325 fi1318 fi
  
1326 else1319 else
1327 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'1320 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
1328 fi1321 fi
 1322 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 1323 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1324 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1325 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1326 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 1327 package·--add=sudo
1329 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·U\x8Us\x8se\x8er\x8rs\x8s·R\x8Re\x8e-\x8-A\x8Au\x8ut\x8th\x8he\x8en\x8nt\x8ti\x8ic\x8ca\x8at\x8te\x8e·f\x8fo\x8or\x8r·P\x8Pr\x8ri\x8iv\x8vi\x8il\x8le\x8eg\x8ge\x8e·E\x8Es\x8sc\x8ca\x8al\x8la\x8at\x8ti\x8io\x8on\x8n·-\x8-·s\x8su\x8ud\x8do\x8o·!\x8!a\x8au\x8ut\x8th\x8he\x8en\x8nt\x8ti\x8ic\x8ca\x8at\x8te\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*1328 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·U\x8Us\x8se\x8er\x8rs\x8s·R\x8Re\x8e-\x8-A\x8Au\x8ut\x8th\x8he\x8en\x8nt\x8ti\x8ic\x8ca\x8at\x8te\x8e·f\x8fo\x8or\x8r·P\x8Pr\x8ri\x8iv\x8vi\x8il\x8le\x8eg\x8ge\x8e·E\x8Es\x8sc\x8ca\x8al\x8la\x8at\x8ti\x8io\x8on\x8n·-\x8-·s\x8su\x8ud\x8do\x8o·!\x8!a\x8au\x8ut\x8th\x8he\x8en\x8nt\x8ti\x8ic\x8ca\x8at\x8te\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
1330 The·sudo·!authenticate·option,·when·specified,·allows·a·user·to·execute·commands·using·sudo·without·having·to·authenticate.·This·should·be·disabled·by·making·sure·that·the·!authenticate·option·does·not·exist·in·/etc/sudoers·configuration·file·or·any·sudo·configuration·snippets·in·/etc/sudoers.d/.1329 The·sudo·!authenticate·option,·when·specified,·allows·a·user·to·execute·commands·using·sudo·without·having·to·authenticate.·This·should·be·disabled·by·making·sure·that·the·!authenticate·option·does·not·exist·in·/etc/sudoers·configuration·file·or·any·sudo·configuration·snippets·in·/etc/sudoers.d/.
1331 ············Without·re-authentication,·users·may·access·resources·or·perform·tasks·for·which·they·do·not·have·authorization.1330 ············Without·re-authentication,·users·may·access·resources·or·perform·tasks·for·which·they·do·not·have·authorization.
1332 Rationale:1331 Rationale:
1333 ············When·operating·systems·provide·the·capability·to·escalate·a·functional·capability,·it·is·critical·that·the·user·re-authenticate.1332 ············When·operating·systems·provide·the·capability·to·escalate·a·functional·capability,·it·is·critical·that·the·user·re-authenticate.
1334 Severity: ··medium1333 Severity: ··medium
1335 Rule·ID:····xccdf_org.ssgproject.content_rule_sudo_remove_no_authenticate1334 Rule·ID:····xccdf_org.ssgproject.content_rule_sudo_remove_no_authenticate
Offset 1640, 21 lines modifiedOffset 1640, 14 lines modified
1640 ··tags:1640 ··tags:
1641 ··-·enable_strategy1641 ··-·enable_strategy
1642 ··-·low_complexity1642 ··-·low_complexity
1643 ··-·low_disruption1643 ··-·low_disruption
1644 ··-·medium_severity1644 ··-·medium_severity
1645 ··-·no_reboot_needed1645 ··-·no_reboot_needed
1646 ··-·package_rear_installed1646 ··-·package_rear_installed
1647 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
1648 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
1649 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
1650 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
1651 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
1652 package·--add=rear 
1653 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81647 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
1654 [[packages]]1648 [[packages]]
1655 name·=·"rear"1649 name·=·"rear"
1656 version·=·"*"1650 version·=·"*"
1657 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81651 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1658 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1652 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 1679, 14 lines modifiedOffset 1672, 21 lines modified
1679 if·!·rpm·-q·--quiet·"rear"·;·then1672 if·!·rpm·-q·--quiet·"rear"·;·then
1680 ····yum·install·-y·"rear"1673 ····yum·install·-y·"rear"
1681 fi1674 fi
  
1682 else1675 else
1683 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'1676 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
1684 fi1677 fi
 1678 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 1679 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1680 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1681 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1682 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 1683 package·--add=rear
1685 Group  ·Updating·Software·  Group·contains·7·rules1684 Group  ·Updating·Software·  Group·contains·7·rules
1686 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·yum·command·line·tool·is·used·to·install·and·update·software·packages.·The·system·also·provides·a·graphical·software·update·tool·in·the·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·menu,·in·the·A\x8Ad\x8dm\x8mi\x8in\x8ni\x8is\x8st\x8tr\x8ra\x8at\x8ti\x8io\x8on\x8n·submenu,·called·S\x8So\x8of\x8ft\x8tw\x8wa\x8ar\x8re\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8e.1685 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·yum·command·line·tool·is·used·to·install·and·update·software·packages.·The·system·also·provides·a·graphical·software·update·tool·in·the·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·menu,·in·the·A\x8Ad\x8dm\x8mi\x8in\x8ni\x8is\x8st\x8tr\x8ra\x8at\x8ti\x8io\x8on\x8n·submenu,·called·S\x8So\x8of\x8ft\x8tw\x8wa\x8ar\x8re\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8e.
  
Max diff block lines reached; 38421/44681 bytes (85.99%) of diff not shown.
1.14 MB
./usr/share/doc/ssg-nondebian/ssg-ol8-guide-ospp.html
    
Offset 15150, 144 lines modifiedOffset 15150, 144 lines modified
0003b2d0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target0003b2d0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
0003b2e0:·3d22·2369·646d·3536·3937·2220·7461·6269··="#idm5697"·tabi0003b2e0:·3d22·2369·646d·3536·3937·2220·7461·6269··="#idm5697"·tabi
0003b2f0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b0003b2f0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
0003b300:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa0003b300:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
0003b310:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit0003b310:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
0003b320:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·0003b320:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
0003b330:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!0003b330:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
 0003b340:·223e·5265·6d65·6469·6174·696f·6e20·4f53··">Remediation·OS
 0003b350:·4275·696c·6420·426c·7565·7072·696e·7420··Build·Blueprint·
 0003b360:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><
 0003b370:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
 0003b380:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
 0003b390:·6c6c·6170·7365·2220·6964·3d22·6964·6d35··llapse"·id="idm5
 0003b3a0:·3639·3722·3e3c·7072·653e·3c63·6f64·653e··697"><pre><code>
 0003b3b0:·0a5b·5b70·6163·6b61·6765·735d·5d0a·6e61··.[[packages]].na
 0003b3c0:·6d65·203d·2022·6169·6465·220a·7665·7273··me·=·"aide".vers
 0003b3d0:·696f·6e20·3d20·222a·220a·3c2f·636f·6465··ion·=·"*".</code
 0003b3e0:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a·
 0003b3f0:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s
 0003b400:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog
 0003b410:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d
 0003b420:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
 0003b430:·3536·3938·2220·7461·6269·6e64·6578·3d22··5698"·tabindex="
 0003b440:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
 0003b450:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
 0003b460:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
 0003b470:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
 0003b480:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
 0003b490:·6469·6174·696f·6e20·5075·7070·6574·2073··diation·Puppet·s
 0003b4a0:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b
 0003b4b0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
 0003b4c0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
 0003b4d0:·6c61·7073·6522·2069·643d·2269·646d·3536··lapse"·id="idm56
 0003b4e0:·3938·223e·3c74·6162·6c65·2063·6c61·7373··98"><table·class
 0003b4f0:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st
 0003b500:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord
 0003b510:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde
 0003b520:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co
 0003b530:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t
 0003b540:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
 0003b550:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio
 0003b560:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</
 0003b570:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 0003b580:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td>
 0003b590:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr><
 0003b5a0:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:
 0003b5b0:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<
 0003b5c0:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table
 0003b5d0:·3e3c·7072·653e·3c63·6f64·653e·696e·636c··><pre><code>incl
 0003b5e0:·7564·6520·696e·7374·616c·6c5f·6169·6465··ude·install_aide
 0003b5f0:·0a0a·636c·6173·7320·696e·7374·616c·6c5f··..class·install_
 0003b600:·6169·6465·207b·0a20·2070·6163·6b61·6765··aide·{.··package
 0003b610:·207b·2027·6169·6465·273a·0a20·2020·2065···{·'aide':.····e
 0003b620:·6e73·7572·6520·3d26·6774·3b20·2769·6e73··nsure·=&gt;·'ins
 0003b630:·7461·6c6c·6564·272c·0a20·207d·0a7d·0a3c··talled',.··}.}.<
 0003b640:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di
 0003b650:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn·
 0003b660:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat
 0003b670:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap
 0003b680:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
 0003b690:·2223·6964·6d35·3639·3922·2074·6162·696e··"#idm5699"·tabin
 0003b6a0:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
 0003b6b0:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
 0003b6c0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
 0003b6d0:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
 0003b6e0:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
 0003b6f0:·3e52·656d·6564·6961·7469·6f6e·2053·6865··>Remediation·She
 0003b700:·6c6c·2073·6372·6970·7420·e287·b23c·2f61··ll·script·...</a
 0003b710:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
 0003b720:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
 0003b730:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
 0003b740:·6d35·3639·3922·3e3c·7461·626c·6520·636c··m5699"><table·cl
 0003b750:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table
 0003b760:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b
 0003b770:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co
 0003b780:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th
 0003b790:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th
 0003b7a0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
 0003b7b0:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup
 0003b7c0:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo
 0003b7d0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
 0003b7e0:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th><
 0003b7f0:·7464·3e66·616c·7365·3c2f·7464·3e3c·2f74··td>false</td></t
 0003b800:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate
 0003b810:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab
 0003b820:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta
 0003b830:·626c·653e·3c70·7265·3e3c·636f·6465·3e23··ble><pre><code>#
 0003b840:·2052·656d·6564·6961·7469·6f6e·2069·7320···Remediation·is·
 0003b850:·6170·706c·6963·6162·6c65·206f·6e6c·7920··applicable·only·
 0003b860:·696e·2063·6572·7461·696e·2070·6c61·7466··in·certain·platf
 0003b870:·6f72·6d73·0a69·6620·7270·6d20·2d2d·7175··orms.if·rpm·--qu
 0003b880:·6965·7420·2d71·206b·6572·6e65·6c20·7c7c··iet·-q·kernel·||
 0003b890:·2072·706d·202d·2d71·7569·6574·202d·7120···rpm·--quiet·-q·
 0003b8a0:·6b65·726e·656c·2d75·656b·3b20·7468·656e··kernel-uek;·then
 0003b8b0:·0a0a·6966·2021·2072·706d·202d·7120·2d2d··..if·!·rpm·-q·--
 0003b8c0:·7175·6965·7420·2261·6964·6522·203b·2074··quiet·"aide"·;·t
 0003b8d0:·6865·6e0a·2020·2020·7975·6d20·696e·7374··hen.····yum·inst
 0003b8e0:·616c·6c20·2d79·2022·6169·6465·220a·6669··all·-y·"aide".fi
 0003b8f0:·0a0a·656c·7365·0a20·2020·2026·6774·3b26··..else.····&gt;&
 0003b900:·616d·703b·3220·6563·686f·2027·5265·6d65··amp;2·echo·'Reme
 0003b910:·6469·6174·696f·6e20·6973·206e·6f74·2061··diation·is·not·a
 0003b920:·7070·6c69·6361·626c·652c·206e·6f74·6869··pplicable,·nothi
 0003b930:·6e67·2077·6173·2064·6f6e·6527·0a66·690a··ng·was·done'.fi.
 0003b940:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d
 0003b950:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn
 0003b960:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da
 0003b970:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla
 0003b980:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
 0003b990:·3d22·2369·646d·3537·3030·2220·7461·6269··="#idm5700"·tabi
 0003b9a0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
 0003b9b0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
 0003b9c0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
 0003b9d0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
 0003b9e0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
0003b340:·223e·5265·6d65·6469·6174·696f·6e20·416e··">Remediation·An0003b9f0:·223e·5265·6d65·6469·6174·696f·6e20·416e··">Remediation·An
0003b350:·6163·6f6e·6461·2073·6e69·7070·6574·20e2··aconda·snippet·.0003ba00:·6163·6f6e·6461·2073·6e69·7070·6574·20e2··aconda·snippet·.
0003b360:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c0003ba10:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c
0003b370:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll0003ba20:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
0003b380:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i0003ba30:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
0003b390:·643d·2269·646d·3536·3937·223e·3c74·6162··d="idm5697"><tab0003ba40:·643d·2269·646d·3537·3030·223e·3c74·6162··d="idm5700"><tab
0003b3a0:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·0003ba50:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·
0003b3b0:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta0003ba60:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta
0003b3c0:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab 
0003b3d0:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t 
0003b3e0:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity 
0003b3f0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t 
0003b400:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D 
Max diff block lines reached; 1068664/1087184 bytes (98.30%) of diff not shown.
103 KB
html2text {}
    
Offset 139, 21 lines modifiedOffset 139, 14 lines modified
139 ··-·PCI-DSSv4-11.5.2139 ··-·PCI-DSSv4-11.5.2
140 ··-·enable_strategy140 ··-·enable_strategy
141 ··-·low_complexity141 ··-·low_complexity
142 ··-·low_disruption142 ··-·low_disruption
143 ··-·medium_severity143 ··-·medium_severity
144 ··-·no_reboot_needed144 ··-·no_reboot_needed
145 ··-·package_aide_installed145 ··-·package_aide_installed
146 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
147 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
148 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
149 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
150 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
151 package·--add=aide 
152 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8146 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
153 [[packages]]147 [[packages]]
154 name·=·"aide"148 name·=·"aide"
155 version·=·"*"149 version·=·"*"
156 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8150 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
157 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low151 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 178, 14 lines modifiedOffset 171, 21 lines modified
178 if·!·rpm·-q·--quiet·"aide"·;·then171 if·!·rpm·-q·--quiet·"aide"·;·then
179 ····yum·install·-y·"aide"172 ····yum·install·-y·"aide"
180 fi173 fi
  
181 else174 else
182 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'175 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
183 fi176 fi
 177 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 178 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 179 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 180 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 181 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 182 package·--add=aide
184 Group  ·Federal·Information·Processing·Standard·(FIPS)·  Group·contains·2·rules183 Group  ·Federal·Information·Processing·Standard·(FIPS)·  Group·contains·2·rules
185 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·Federal·Information·Processing·Standard·(FIPS)·is·a·computer·security·standard·which·is·developed·by·the·U.S.·Government·and·industry·working·groups·to·validate·the·quality·of·cryptographic·modules.·The·FIPS·standard·provides·four·security·levels·to·ensure·adequate·coverage·of·different·industries,·implementation·of·cryptographic·modules,·and·organizational·sizes·and·requirements.184 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·Federal·Information·Processing·Standard·(FIPS)·is·a·computer·security·standard·which·is·developed·by·the·U.S.·Government·and·industry·working·groups·to·validate·the·quality·of·cryptographic·modules.·The·FIPS·standard·provides·four·security·levels·to·ensure·adequate·coverage·of·different·industries,·implementation·of·cryptographic·modules,·and·organizational·sizes·and·requirements.
  
186 FIPS·140-2·is·the·current·standard·for·validating·that·mechanisms·used·to·access·cryptographic·modules·utilize·authentication·that·meets·industry·and·government·requirements.·For·government·systems,·this·allows·Security·Levels·1,·2,·3,·or·4·for·use·on·Oracle·Linux·8.185 FIPS·140-2·is·the·current·standard·for·validating·that·mechanisms·used·to·access·cryptographic·modules·utilize·authentication·that·meets·industry·and·government·requirements.·For·government·systems,·this·allows·Security·Levels·1,·2,·3,·or·4·for·use·on·Oracle·Linux·8.
  
187 See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8c\x8c_\x8s\x8s_\x8r\x8r_\x8c\x8c_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8l\x8l_\x8i\x8i_\x8c\x8c_\x8a\x8a_\x8t\x8t_\x8i\x8i_\x8o\x8o_\x8n\x8n_\x8s\x8s_\x8/\x8/_\x8P\x8P_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x8h\x8h_\x8t\x8t_\x8m\x8m_\x8l\x8l·for·more·information.186 See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8c\x8c_\x8s\x8s_\x8r\x8r_\x8c\x8c_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8l\x8l_\x8i\x8i_\x8c\x8c_\x8a\x8a_\x8t\x8t_\x8i\x8i_\x8o\x8o_\x8n\x8n_\x8s\x8s_\x8/\x8/_\x8P\x8P_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x8h\x8h_\x8t\x8t_\x8m\x8m_\x8l\x8l·for·more·information.
188 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·D\x8Dr\x8ra\x8ac\x8cu\x8ut\x8t·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8du\x8ul\x8le\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*187 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·D\x8Dr\x8ra\x8ac\x8cu\x8ut\x8t·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8du\x8ul\x8le\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
Offset 385, 21 lines modifiedOffset 385, 14 lines modified
385 ··tags:385 ··tags:
386 ··-·enable_strategy386 ··-·enable_strategy
387 ··-·low_complexity387 ··-·low_complexity
388 ··-·low_disruption388 ··-·low_disruption
389 ··-·medium_severity389 ··-·medium_severity
390 ··-·no_reboot_needed390 ··-·no_reboot_needed
391 ··-·package_crypto-policies_installed391 ··-·package_crypto-policies_installed
392 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
393 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
394 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
395 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
396 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
397 package·--add=crypto-policies 
398 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8392 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
399 [[packages]]393 [[packages]]
400 name·=·"crypto-policies"394 name·=·"crypto-policies"
401 version·=·"*"395 version·=·"*"
402 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8396 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
403 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low397 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 418, 14 lines modifiedOffset 411, 21 lines modified
418 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low411 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
419 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false412 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
420 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable413 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
421 if·!·rpm·-q·--quiet·"crypto-policies"·;·then414 if·!·rpm·-q·--quiet·"crypto-policies"·;·then
422 ····yum·install·-y·"crypto-policies"415 ····yum·install·-y·"crypto-policies"
423 fi416 fi
 417 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 418 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 419 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 420 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 421 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 422 package·--add=crypto-policies
424 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·B\x8BI\x8IN\x8ND\x8D·t\x8to\x8o·u\x8us\x8se\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8o·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*423 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·B\x8BI\x8IN\x8ND\x8D·t\x8to\x8o·u\x8us\x8se\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8o·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
425 Crypto·Policies·provide·a·centralized·control·over·crypto·algorithms·usage·of·many·packages.·BIND·is·supported·by·crypto·policy,·but·the·BIND·configuration·may·be·set·up·to·ignore·it.·To·check·that·Crypto·Policies·settings·are·configured·correctly,·ensure·that·the·/etc/named.conf·includes·the·appropriate·configuration:·In·the·options·section·of·/etc/named.conf,·make·sure·that·the·following·line·is·not·commented·out·or·superseded·by·later·includes:·include·"/etc/crypto-policies/back-ends/bind.config";424 Crypto·Policies·provide·a·centralized·control·over·crypto·algorithms·usage·of·many·packages.·BIND·is·supported·by·crypto·policy,·but·the·BIND·configuration·may·be·set·up·to·ignore·it.·To·check·that·Crypto·Policies·settings·are·configured·correctly,·ensure·that·the·/etc/named.conf·includes·the·appropriate·configuration:·In·the·options·section·of·/etc/named.conf,·make·sure·that·the·following·line·is·not·commented·out·or·superseded·by·later·includes:·include·"/etc/crypto-policies/back-ends/bind.config";
426 Rationale:··Overriding·the·system·crypto·policy·makes·the·behavior·of·the·BIND·service·violate·expectations,·and·makes·system·configuration·more·fragmented.425 Rationale:··Overriding·the·system·crypto·policy·makes·the·behavior·of·the·BIND·service·violate·expectations,·and·makes·system·configuration·more·fragmented.
427 Severity: ··high426 Severity: ··high
428 Rule·ID:····xccdf_org.ssgproject.content_rule_configure_bind_crypto_policy427 Rule·ID:····xccdf_org.ssgproject.content_rule_configure_bind_crypto_policy
429 ············_\x8d_\x8i_\x8s_\x8a·····CCI-002418,·CCI-002422428 ············_\x8d_\x8i_\x8s_\x8a·····CCI-002418,·CCI-002422
430 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1429 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1
Offset 1187, 21 lines modifiedOffset 1187, 14 lines modified
1187 ··-·PCI-DSSv4-2.2.61187 ··-·PCI-DSSv4-2.2.6
1188 ··-·enable_strategy1188 ··-·enable_strategy
1189 ··-·low_complexity1189 ··-·low_complexity
1190 ··-·low_disruption1190 ··-·low_disruption
1191 ··-·medium_severity1191 ··-·medium_severity
1192 ··-·no_reboot_needed1192 ··-·no_reboot_needed
1193 ··-·package_sudo_installed1193 ··-·package_sudo_installed
1194 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
1195 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
1196 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
1197 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
1198 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
1199 package·--add=sudo 
1200 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81194 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
1201 [[packages]]1195 [[packages]]
1202 name·=·"sudo"1196 name·=·"sudo"
1203 version·=·"*"1197 version·=·"*"
1204 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81198 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1205 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1199 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 1226, 14 lines modifiedOffset 1219, 21 lines modified
1226 if·!·rpm·-q·--quiet·"sudo"·;·then1219 if·!·rpm·-q·--quiet·"sudo"·;·then
1227 ····yum·install·-y·"sudo"1220 ····yum·install·-y·"sudo"
1228 fi1221 fi
  
1229 else1222 else
1230 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'1223 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
1231 fi1224 fi
 1225 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 1226 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1227 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1228 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1229 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 1230 package·--add=sudo
1232 Group  ·System·Tooling·/·Utilities·  Group·contains·13·rules1231 Group  ·System·Tooling·/·Utilities·  Group·contains·13·rules
1233 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·following·checks·evaluate·the·system·for·recommended·base·packages·--·both·for·installation·and·removal.1232 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·following·checks·evaluate·the·system·for·recommended·base·packages·--·both·for·installation·and·removal.
1234 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·g\x8gn\x8nu\x8ut\x8tl\x8ls\x8s-\x8-u\x8ut\x8ti\x8il\x8ls\x8s·i\x8is\x8s·i\x8in\x8ns\x8st\x8ta\x8al\x8ll\x8le\x8ed\x8d·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*1233 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·g\x8gn\x8nu\x8ut\x8tl\x8ls\x8s-\x8-u\x8ut\x8ti\x8il\x8ls\x8s·i\x8is\x8s·i\x8in\x8ns\x8st\x8ta\x8al\x8ll\x8le\x8ed\x8d·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
Max diff block lines reached; 99239/105457 bytes (94.10%) of diff not shown.
400 KB
./usr/share/doc/ssg-nondebian/ssg-ol8-guide-pci-dss.html
    
Offset 16667, 144 lines modifiedOffset 16667, 144 lines modified
000411a0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target000411a0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
000411b0:·3d22·2369·646d·3536·3937·2220·7461·6269··="#idm5697"·tabi000411b0:·3d22·2369·646d·3536·3937·2220·7461·6269··="#idm5697"·tabi
000411c0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b000411c0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
000411d0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa000411d0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
000411e0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit000411e0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
000411f0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·000411f0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
00041200:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!00041200:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
 00041210:·223e·5265·6d65·6469·6174·696f·6e20·4f53··">Remediation·OS
 00041220:·4275·696c·6420·426c·7565·7072·696e·7420··Build·Blueprint·
 00041230:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><
 00041240:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
 00041250:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
 00041260:·6c6c·6170·7365·2220·6964·3d22·6964·6d35··llapse"·id="idm5
 00041270:·3639·3722·3e3c·7072·653e·3c63·6f64·653e··697"><pre><code>
 00041280:·0a5b·5b70·6163·6b61·6765·735d·5d0a·6e61··.[[packages]].na
 00041290:·6d65·203d·2022·6169·6465·220a·7665·7273··me·=·"aide".vers
 000412a0:·696f·6e20·3d20·222a·220a·3c2f·636f·6465··ion·=·"*".</code
 000412b0:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a·
 000412c0:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s
 000412d0:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog
 000412e0:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d
 000412f0:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
 00041300:·3536·3938·2220·7461·6269·6e64·6578·3d22··5698"·tabindex="
 00041310:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
 00041320:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
 00041330:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
 00041340:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
 00041350:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
 00041360:·6469·6174·696f·6e20·5075·7070·6574·2073··diation·Puppet·s
 00041370:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b
 00041380:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
 00041390:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
 000413a0:·6c61·7073·6522·2069·643d·2269·646d·3536··lapse"·id="idm56
 000413b0:·3938·223e·3c74·6162·6c65·2063·6c61·7373··98"><table·class
 000413c0:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st
 000413d0:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord
 000413e0:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde
 000413f0:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co
 00041400:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t
 00041410:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
 00041420:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio
 00041430:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</
 00041440:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 00041450:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td>
 00041460:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr><
 00041470:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:
 00041480:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<
 00041490:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table
 000414a0:·3e3c·7072·653e·3c63·6f64·653e·696e·636c··><pre><code>incl
 000414b0:·7564·6520·696e·7374·616c·6c5f·6169·6465··ude·install_aide
 000414c0:·0a0a·636c·6173·7320·696e·7374·616c·6c5f··..class·install_
 000414d0:·6169·6465·207b·0a20·2070·6163·6b61·6765··aide·{.··package
 000414e0:·207b·2027·6169·6465·273a·0a20·2020·2065···{·'aide':.····e
 000414f0:·6e73·7572·6520·3d26·6774·3b20·2769·6e73··nsure·=&gt;·'ins
 00041500:·7461·6c6c·6564·272c·0a20·207d·0a7d·0a3c··talled',.··}.}.<
 00041510:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di
 00041520:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn·
 00041530:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat
 00041540:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap
 00041550:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
 00041560:·2223·6964·6d35·3639·3922·2074·6162·696e··"#idm5699"·tabin
 00041570:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
 00041580:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
 00041590:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
 000415a0:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
 000415b0:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
 000415c0:·3e52·656d·6564·6961·7469·6f6e·2053·6865··>Remediation·She
 000415d0:·6c6c·2073·6372·6970·7420·e287·b23c·2f61··ll·script·...</a
 000415e0:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
 000415f0:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
 00041600:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
 00041610:·6d35·3639·3922·3e3c·7461·626c·6520·636c··m5699"><table·cl
 00041620:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table
 00041630:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b
 00041640:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co
 00041650:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th
 00041660:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th
 00041670:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
 00041680:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup
 00041690:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo
 000416a0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
 000416b0:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th><
 000416c0:·7464·3e66·616c·7365·3c2f·7464·3e3c·2f74··td>false</td></t
 000416d0:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate
 000416e0:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab
 000416f0:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta
 00041700:·626c·653e·3c70·7265·3e3c·636f·6465·3e23··ble><pre><code>#
 00041710:·2052·656d·6564·6961·7469·6f6e·2069·7320···Remediation·is·
 00041720:·6170·706c·6963·6162·6c65·206f·6e6c·7920··applicable·only·
 00041730:·696e·2063·6572·7461·696e·2070·6c61·7466··in·certain·platf
 00041740:·6f72·6d73·0a69·6620·7270·6d20·2d2d·7175··orms.if·rpm·--qu
 00041750:·6965·7420·2d71·206b·6572·6e65·6c20·7c7c··iet·-q·kernel·||
 00041760:·2072·706d·202d·2d71·7569·6574·202d·7120···rpm·--quiet·-q·
 00041770:·6b65·726e·656c·2d75·656b·3b20·7468·656e··kernel-uek;·then
 00041780:·0a0a·6966·2021·2072·706d·202d·7120·2d2d··..if·!·rpm·-q·--
 00041790:·7175·6965·7420·2261·6964·6522·203b·2074··quiet·"aide"·;·t
 000417a0:·6865·6e0a·2020·2020·7975·6d20·696e·7374··hen.····yum·inst
 000417b0:·616c·6c20·2d79·2022·6169·6465·220a·6669··all·-y·"aide".fi
 000417c0:·0a0a·656c·7365·0a20·2020·2026·6774·3b26··..else.····&gt;&
 000417d0:·616d·703b·3220·6563·686f·2027·5265·6d65··amp;2·echo·'Reme
 000417e0:·6469·6174·696f·6e20·6973·206e·6f74·2061··diation·is·not·a
 000417f0:·7070·6c69·6361·626c·652c·206e·6f74·6869··pplicable,·nothi
 00041800:·6e67·2077·6173·2064·6f6e·6527·0a66·690a··ng·was·done'.fi.
 00041810:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d
 00041820:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn
 00041830:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da
 00041840:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla
 00041850:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
 00041860:·3d22·2369·646d·3537·3030·2220·7461·6269··="#idm5700"·tabi
 00041870:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
 00041880:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
 00041890:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
 000418a0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
 000418b0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
00041210:·223e·5265·6d65·6469·6174·696f·6e20·416e··">Remediation·An000418c0:·223e·5265·6d65·6469·6174·696f·6e20·416e··">Remediation·An
00041220:·6163·6f6e·6461·2073·6e69·7070·6574·20e2··aconda·snippet·.000418d0:·6163·6f6e·6461·2073·6e69·7070·6574·20e2··aconda·snippet·.
00041230:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c000418e0:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c
00041240:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll000418f0:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
00041250:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i00041900:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
00041260:·643d·2269·646d·3536·3937·223e·3c74·6162··d="idm5697"><tab00041910:·643d·2269·646d·3537·3030·223e·3c74·6162··d="idm5700"><tab
00041270:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·00041920:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·
00041280:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta00041930:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta
00041290:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab00041940:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab
000412a0:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t00041950:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t
000412b0:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity 
000412c0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t 
000412d0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D 
Max diff block lines reached; 346968/365488 bytes (94.93%) of diff not shown.
43.0 KB
html2text {}
    
Offset 535, 21 lines modifiedOffset 535, 14 lines modified
535 ··-·PCI-DSSv4-11.5.2535 ··-·PCI-DSSv4-11.5.2
536 ··-·enable_strategy536 ··-·enable_strategy
537 ··-·low_complexity537 ··-·low_complexity
538 ··-·low_disruption538 ··-·low_disruption
539 ··-·medium_severity539 ··-·medium_severity
540 ··-·no_reboot_needed540 ··-·no_reboot_needed
541 ··-·package_aide_installed541 ··-·package_aide_installed
542 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
543 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
544 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
545 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
546 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
547 package·--add=aide 
548 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8542 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
549 [[packages]]543 [[packages]]
550 name·=·"aide"544 name·=·"aide"
551 version·=·"*"545 version·=·"*"
552 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8546 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
553 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low547 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 574, 14 lines modifiedOffset 567, 21 lines modified
574 if·!·rpm·-q·--quiet·"aide"·;·then567 if·!·rpm·-q·--quiet·"aide"·;·then
575 ····yum·install·-y·"aide"568 ····yum·install·-y·"aide"
576 fi569 fi
  
577 else570 else
578 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'571 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
579 fi572 fi
 573 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 574 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 575 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 576 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 577 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 578 package·--add=aide
580 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*579 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
581 Run·the·following·command·to·generate·a·new·database:580 Run·the·following·command·to·generate·a·new·database:
582 $·sudo·/usr/sbin/aide·--init581 $·sudo·/usr/sbin/aide·--init
583 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:582 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
584 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz583 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
585 To·initiate·a·manual·check,·run·the·following·command:584 To·initiate·a·manual·check,·run·the·following·command:
586 $·sudo·/usr/sbin/aide·--check585 $·sudo·/usr/sbin/aide·--check
Offset 2721, 21 lines modifiedOffset 2721, 14 lines modified
2721 ··-·PCI-DSSv4-2.2.62721 ··-·PCI-DSSv4-2.2.6
2722 ··-·enable_strategy2722 ··-·enable_strategy
2723 ··-·low_complexity2723 ··-·low_complexity
2724 ··-·low_disruption2724 ··-·low_disruption
2725 ··-·medium_severity2725 ··-·medium_severity
2726 ··-·no_reboot_needed2726 ··-·no_reboot_needed
2727 ··-·package_sudo_installed2727 ··-·package_sudo_installed
2728 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
2729 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
2730 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
2731 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
2732 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
2733 package·--add=sudo 
2734 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x82728 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
2735 [[packages]]2729 [[packages]]
2736 name·=·"sudo"2730 name·=·"sudo"
2737 version·=·"*"2731 version·=·"*"
2738 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x82732 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
2739 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low2733 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 2760, 14 lines modifiedOffset 2753, 21 lines modified
2760 if·!·rpm·-q·--quiet·"sudo"·;·then2753 if·!·rpm·-q·--quiet·"sudo"·;·then
2761 ····yum·install·-y·"sudo"2754 ····yum·install·-y·"sudo"
2762 fi2755 fi
  
2763 else2756 else
2764 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'2757 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
2765 fi2758 fi
 2759 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 2760 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 2761 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 2762 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 2763 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 2764 package·--add=sudo
2766 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·O\x8On\x8nl\x8ly\x8y·U\x8Us\x8se\x8er\x8rs\x8s·L\x8Lo\x8og\x8gg\x8ge\x8ed\x8d·I\x8In\x8n·T\x8To\x8o·R\x8Re\x8ea\x8al\x8l·t\x8tt\x8ty\x8y·C\x8Ca\x8an\x8n·E\x8Ex\x8xe\x8ec\x8cu\x8ut\x8te\x8e·S\x8Su\x8ud\x8do\x8o·-\x8-·s\x8su\x8ud\x8do\x8o·u\x8us\x8se\x8e_\x8_p\x8pt\x8ty\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*2765 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·O\x8On\x8nl\x8ly\x8y·U\x8Us\x8se\x8er\x8rs\x8s·L\x8Lo\x8og\x8gg\x8ge\x8ed\x8d·I\x8In\x8n·T\x8To\x8o·R\x8Re\x8ea\x8al\x8l·t\x8tt\x8ty\x8y·C\x8Ca\x8an\x8n·E\x8Ex\x8xe\x8ec\x8cu\x8ut\x8te\x8e·S\x8Su\x8ud\x8do\x8o·-\x8-·s\x8su\x8ud\x8do\x8o·u\x8us\x8se\x8e_\x8_p\x8pt\x8ty\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
2767 The·sudo·use_pty·tag,·when·specified,·will·only·execute·sudo·commands·from·users·logged·in·to·a·real·tty.·This·should·be·enabled·by·making·sure·that·the·use_pty·tag·exists·in·/etc/sudoers·configuration·file·or·any·sudo·configuration·snippets·in·/etc/sudoers.d/.2766 The·sudo·use_pty·tag,·when·specified,·will·only·execute·sudo·commands·from·users·logged·in·to·a·real·tty.·This·should·be·enabled·by·making·sure·that·the·use_pty·tag·exists·in·/etc/sudoers·configuration·file·or·any·sudo·configuration·snippets·in·/etc/sudoers.d/.
2768 Rationale:··Requiring·that·sudo·commands·be·run·in·a·pseudo-terminal·can·prevent·an·attacker·from·retaining·access·to·the·user's·terminal·after·the·main·program·has·finished·executing.2767 Rationale:··Requiring·that·sudo·commands·be·run·in·a·pseudo-terminal·can·prevent·an·attacker·from·retaining·access·to·the·user's·terminal·after·the·main·program·has·finished·executing.
2769 Severity: ··medium2768 Severity: ··medium
2770 Rule·ID:····xccdf_org.ssgproject.content_rule_sudo_add_use_pty2769 Rule·ID:····xccdf_org.ssgproject.content_rule_sudo_add_use_pty
2771 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s··Req-10.2.52770 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s··Req-10.2.5
2772 References:·_\x8a_\x8n_\x8s_\x8s_\x8i···R392771 References:·_\x8a_\x8n_\x8s_\x8s_\x8i···R39
Offset 15422, 21 lines modifiedOffset 15422, 14 lines modified
15422 ··-·PCI-DSSv4-10.5.115422 ··-·PCI-DSSv4-10.5.1
15423 ··-·enable_strategy15423 ··-·enable_strategy
15424 ··-·low_complexity15424 ··-·low_complexity
15425 ··-·low_disruption15425 ··-·low_disruption
15426 ··-·medium_severity15426 ··-·medium_severity
15427 ··-·no_reboot_needed15427 ··-·no_reboot_needed
15428 ··-·package_logrotate_installed15428 ··-·package_logrotate_installed
15429 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
15430 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
15431 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
15432 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
15433 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
15434 package·--add=logrotate 
15435 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x815429 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
15436 [[packages]]15430 [[packages]]
15437 name·=·"logrotate"15431 name·=·"logrotate"
15438 version·=·"*"15432 version·=·"*"
15439 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x815433 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
15440 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low15434 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 15461, 14 lines modifiedOffset 15454, 21 lines modified
15461 if·!·rpm·-q·--quiet·"logrotate"·;·then15454 if·!·rpm·-q·--quiet·"logrotate"·;·then
15462 ····yum·install·-y·"logrotate"15455 ····yum·install·-y·"logrotate"
15463 fi15456 fi
  
15464 else15457 else
15465 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'15458 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
15466 fi15459 fi
 15460 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 15461 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 15462 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 15463 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 15464 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 15465 package·--add=logrotate
15467 Group  ·Network·Configuration·and·Firewalls·  Group·contains·14·groups·and·24·rules15466 Group  ·Network·Configuration·and·Firewalls·  Group·contains·14·groups·and·24·rules
15468 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Most·systems·must·be·connected·to·a·network·of·some·sort,·and·this·brings·with·it·the·substantial·risk·of·network·attack.·This·section·discusses·the·security·impact·of·decisions·about·networking·which·must·be·made·when·configuring·a·system.15467 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Most·systems·must·be·connected·to·a·network·of·some·sort,·and·this·brings·with·it·the·substantial·risk·of·network·attack.·This·section·discusses·the·security·impact·of·decisions·about·networking·which·must·be·made·when·configuring·a·system.
  
Max diff block lines reached; 38114/44039 bytes (86.55%) of diff not shown.
20.5 KB
./usr/share/doc/ssg-nondebian/ssg-ol8-guide-standard.html
    
Offset 23904, 145 lines modifiedOffset 23904, 145 lines modified
0005d5f0:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm0005d5f0:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
0005d600:·3231·3037·3022·2074·6162·696e·6465·783d··21070"·tabindex=0005d600:·3231·3037·3022·2074·6162·696e·6465·783d··21070"·tabindex=
0005d610:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button0005d610:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button
0005d620:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=0005d620:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=
0005d630:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A0005d630:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A
0005d640:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea0005d640:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea
0005d650:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem0005d650:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem
 0005d660:·6564·6961·7469·6f6e·204f·5342·7569·6c64··ediation·OSBuild
 0005d670:·2042·6c75·6570·7269·6e74·2073·6e69·7070···Blueprint·snipp
 0005d680:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d
 0005d690:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-
 0005d6a0:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps
 0005d6b0:·6522·2069·643d·2269·646d·3231·3037·3022··e"·id="idm21070"
0005d660:·6564·6961·7469·6f6e·2041·6e61·636f·6e64··ediation·Anacond 
0005d670:·6120·736e·6970·7065·7420·e287·b23c·2f61··a·snippet·...</a 
0005d680:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class= 
0005d690:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse· 
0005d6a0:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id 
0005d6b0:·6d32·3130·3730·223e·3c74·6162·6c65·2063··m21070"><table·c 
0005d6c0:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl 
0005d6d0:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table- 
0005d6e0:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c 
0005d6f0:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t 
0005d700:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t 
0005d710:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></ 
0005d720:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru 
0005d730:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l 
0005d740:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr> 
0005d750:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th> 
0005d760:·3c74·643e·6661·6c73·653c·2f74·643e·3c2f··<td>false</td></ 
0005d770:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat 
0005d780:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena 
0005d790:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t 
0005d7a0:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>0005d6c0:·3e3c·7072·653e·3c63·6f64·653e·0a5b·5b70··><pre><code>.[[p
0005d7b0:·0a70·6163·6b61·6765·202d·2d61·6464·3d72··.package·--add=r 
0005d7c0:·7379·736c·6f67·0a3c·2f63·6f64·653e·3c2f··syslog.</code></0005d6d0:·6163·6b61·6765·735d·5d0a·6e61·6d65·203d··ackages]].name·=
 0005d6e0:·2022·7273·7973·6c6f·6722·0a76·6572·7369···"rsyslog".versi
 0005d6f0:·6f6e·203d·2022·2a22·0a3c·2f63·6f64·653e··on·=·"*".</code>
0005d7d0:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla0005d700:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c
0005d7e0:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ0005d710:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su
0005d7f0:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle0005d720:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg
0005d800:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data0005d730:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da
0005d810:·2d74·6172·6765·743d·2223·6964·6d32·3130··-target="#idm2100005d740:·7461·2d74·6172·6765·743d·2223·6964·6d32··ta-target="#idm2
0005d820:·3731·2220·7461·6269·6e64·6578·3d22·3022··71"·tabindex="0"0005d750:·3130·3731·2220·7461·6269·6e64·6578·3d22··1071"·tabindex="
0005d830:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a0005d760:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
0005d840:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa0005d770:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
0005d850:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti0005d780:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
0005d860:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·0005d790:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
0005d870:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi0005d7a0:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
0005d880:·6174·696f·6e20·4f53·4275·696c·6420·426c··ation·OSBuild·Bl 
0005d890:·7565·7072·696e·7420·736e·6970·7065·7420··ueprint·snippet· 
0005d8a0:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div· 
0005d8b0:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col0005d7b0:·6469·6174·696f·6e20·5075·7070·6574·2073··diation·Puppet·s
 0005d7c0:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b
 0005d7d0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
 0005d7e0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
 0005d7f0:·6c61·7073·6522·2069·643d·2269·646d·3231··lapse"·id="idm21
 0005d800:·3037·3122·3e3c·7461·626c·6520·636c·6173··071"><table·clas
 0005d810:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s
 0005d820:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor
 0005d830:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond
 0005d840:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C
 0005d850:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><
 0005d860:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
 0005d870:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti
 0005d880:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<
 0005d890:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 0005d8a0:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td
 0005d8b0:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr>
 0005d8c0:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy
 0005d8d0:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable
 0005d8e0:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl
 0005d8f0:·653e·3c70·7265·3e3c·636f·6465·3e69·6e63··e><pre><code>inc
 0005d900:·6c75·6465·2069·6e73·7461·6c6c·5f72·7379··lude·install_rsy
 0005d910:·736c·6f67·0a0a·636c·6173·7320·696e·7374··slog..class·inst
 0005d920:·616c·6c5f·7273·7973·6c6f·6720·7b0a·2020··all_rsyslog·{.··
 0005d930:·7061·636b·6167·6520·7b20·2772·7379·736c··package·{·'rsysl
 0005d940:·6f67·273a·0a20·2020·2065·6e73·7572·6520··og':.····ensure·
 0005d950:·3d26·6774·3b20·2769·6e73·7461·6c6c·6564··=&gt;·'installed
 0005d960:·272c·0a20·207d·0a7d·0a3c·2f63·6f64·653e··',.··}.}.</code>
 0005d970:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c
 0005d980:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su
 0005d990:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg
0005d8c0:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·0005d9a0:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da
 0005d9b0:·7461·2d74·6172·6765·743d·2223·6964·6d32··ta-target="#idm2
 0005d9c0:·3130·3732·2220·7461·6269·6e64·6578·3d22··1072"·tabindex="
 0005d9d0:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
 0005d9e0:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
 0005d9f0:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
 0005da00:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
 0005da10:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
 0005da20:·6469·6174·696f·6e20·5368·656c·6c20·7363··diation·Shell·sc
 0005da30:·7269·7074·20e2·87b2·3c2f·613e·3c62·723e··ript·...</a><br>
 0005da40:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
 0005da50:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
 0005da60:·7073·6522·2069·643d·2269·646d·3231·3037··pse"·id="idm2107
 0005da70:·3222·3e3c·7461·626c·6520·636c·6173·733d··2"><table·class=
 0005da80:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str
 0005da90:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde
0005d8d0:·6964·3d22·6964·6d32·3130·3731·223e·3c70··id="idm21071"><p 
0005d8e0:·7265·3e3c·636f·6465·3e0a·5b5b·7061·636b··re><code>.[[pack 
0005d8f0:·6167·6573·5d5d·0a6e·616d·6520·3d20·2272··ages]].name·=·"r 
0005d900:·7379·736c·6f67·220a·7665·7273·696f·6e20··syslog".version· 
0005d910:·3d20·222a·220a·3c2f·636f·6465·3e3c·2f70··=·"*".</code></p 
0005d920:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas 
0005d930:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe 
0005d940:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle= 
0005d950:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data- 
0005d960:·7461·7267·6574·3d22·2369·646d·3231·3037··target="#idm2107 
0005d970:·3222·2074·6162·696e·6465·783d·2230·2220··2"·tabindex="0"· 
0005d980:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar 
0005d990:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal 
0005d9a0:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ 
0005d9b0:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h 
0005d9c0:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia 
0005d9d0:·7469·6f6e·2050·7570·7065·7420·736e·6970··tion·Puppet·snip 
0005d9e0:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br>< 
0005d9f0:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel 
0005da00:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap 
0005da10:·7365·2220·6964·3d22·6964·6d32·3130·3732··se"·id="idm21072 
0005da20:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class=" 
0005da30:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri 
0005da40:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border0005daa0:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden
 0005dab0:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com
 0005dac0:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td
 0005dad0:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
 0005dae0:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption
Max diff block lines reached; 414/19072 bytes (2.17%) of diff not shown.
1.79 KB
html2text {}
    
Offset 1780, 21 lines modifiedOffset 1780, 14 lines modified
1780 ··-·NIST-800-53-CM-6(a)1780 ··-·NIST-800-53-CM-6(a)
1781 ··-·enable_strategy1781 ··-·enable_strategy
1782 ··-·low_complexity1782 ··-·low_complexity
1783 ··-·low_disruption1783 ··-·low_disruption
1784 ··-·medium_severity1784 ··-·medium_severity
1785 ··-·no_reboot_needed1785 ··-·no_reboot_needed
1786 ··-·package_rsyslog_installed1786 ··-·package_rsyslog_installed
1787 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
1788 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
1789 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
1790 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
1791 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
1792 package·--add=rsyslog 
1793 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81787 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
1794 [[packages]]1788 [[packages]]
1795 name·=·"rsyslog"1789 name·=·"rsyslog"
1796 version·=·"*"1790 version·=·"*"
1797 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81791 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1798 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1792 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 1819, 14 lines modifiedOffset 1812, 21 lines modified
1819 if·!·rpm·-q·--quiet·"rsyslog"·;·then1812 if·!·rpm·-q·--quiet·"rsyslog"·;·then
1820 ····yum·install·-y·"rsyslog"1813 ····yum·install·-y·"rsyslog"
1821 fi1814 fi
  
1822 else1815 else
1823 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'1816 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
1824 fi1817 fi
 1818 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 1819 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1820 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1821 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1822 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 1823 package·--add=rsyslog
1825 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·r\x8rs\x8sy\x8ys\x8sl\x8lo\x8og\x8g·S\x8Se\x8er\x8rv\x8vi\x8ic\x8ce\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*1824 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·r\x8rs\x8sy\x8ys\x8sl\x8lo\x8og\x8g·S\x8Se\x8er\x8rv\x8vi\x8ic\x8ce\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
1826 The·rsyslog·service·provides·syslog-style·logging·by·default·on·Oracle·Linux·8.·The·rsyslog·service·can·be·enabled·with·the·following·command:1825 The·rsyslog·service·provides·syslog-style·logging·by·default·on·Oracle·Linux·8.·The·rsyslog·service·can·be·enabled·with·the·following·command:
1827 $·sudo·systemctl·enable·rsyslog.service1826 $·sudo·systemctl·enable·rsyslog.service
1828 Rationale:··The·rsyslog·service·must·be·running·in·order·to·provide·logging·services,·which·are·essential·to·system·administration.1827 Rationale:··The·rsyslog·service·must·be·running·in·order·to·provide·logging·services,·which·are·essential·to·system·administration.
1829 Severity: ··medium1828 Severity: ··medium
1830 Rule·ID:····xccdf_org.ssgproject.content_rule_service_rsyslog_enabled1829 Rule·ID:····xccdf_org.ssgproject.content_rule_service_rsyslog_enabled
1831 ············_\x8c_\x8i_\x8s_\x8-_\x8c_\x8s_\x8c········1,·12,·13,·14,·15,·16,·2,·3,·5,·6,·7,·8,·91830 ············_\x8c_\x8i_\x8s_\x8-_\x8c_\x8s_\x8c········1,·12,·13,·14,·15,·16,·2,·3,·5,·6,·7,·8,·9
1.01 MB
./usr/share/doc/ssg-nondebian/ssg-ol8-guide-stig.html
    
Offset 15160, 144 lines modifiedOffset 15160, 144 lines modified
0003b370:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="0003b370:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
0003b380:·2369·646d·3536·3937·2220·7461·6269·6e64··#idm5697"·tabind0003b380:·2369·646d·3536·3937·2220·7461·6269·6e64··#idm5697"·tabind
0003b390:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but0003b390:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
0003b3a0:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand0003b3a0:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
0003b3b0:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title0003b3b0:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
0003b3c0:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re0003b3c0:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
0003b3d0:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">0003b3d0:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
 0003b3e0:·5265·6d65·6469·6174·696f·6e20·4f53·4275··Remediation·OSBu
 0003b3f0:·696c·6420·426c·7565·7072·696e·7420·736e··ild·Blueprint·sn
 0003b400:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br
 0003b410:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
 0003b420:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
 0003b430:·6170·7365·2220·6964·3d22·6964·6d35·3639··apse"·id="idm569
 0003b440:·3722·3e3c·7072·653e·3c63·6f64·653e·0a5b··7"><pre><code>.[
 0003b450:·5b70·6163·6b61·6765·735d·5d0a·6e61·6d65··[packages]].name
 0003b460:·203d·2022·6169·6465·220a·7665·7273·696f···=·"aide".versio
 0003b470:·6e20·3d20·222a·220a·3c2f·636f·6465·3e3c··n·=·"*".</code><
 0003b480:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl
 0003b490:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc
 0003b4a0:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl
 0003b4b0:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat
 0003b4c0:·612d·7461·7267·6574·3d22·2369·646d·3536··a-target="#idm56
 0003b4d0:·3938·2220·7461·6269·6e64·6578·3d22·3022··98"·tabindex="0"
 0003b4e0:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
 0003b4f0:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
 0003b500:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
 0003b510:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
 0003b520:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
 0003b530:·6174·696f·6e20·5075·7070·6574·2073·6e69··ation·Puppet·sni
 0003b540:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>
 0003b550:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
 0003b560:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
 0003b570:·7073·6522·2069·643d·2269·646d·3536·3938··pse"·id="idm5698
 0003b580:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="
 0003b590:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri
 0003b5a0:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border
 0003b5b0:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens
 0003b5c0:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp
 0003b5d0:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>
 0003b5e0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
 0003b5f0:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:
 0003b600:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
 0003b610:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re
 0003b620:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa
 0003b630:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr
 0003b640:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</
 0003b650:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t
 0003b660:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><
 0003b670:·7072·653e·3c63·6f64·653e·696e·636c·7564··pre><code>includ
 0003b680:·6520·696e·7374·616c·6c5f·6169·6465·0a0a··e·install_aide..
 0003b690:·636c·6173·7320·696e·7374·616c·6c5f·6169··class·install_ai
 0003b6a0:·6465·207b·0a20·2070·6163·6b61·6765·207b··de·{.··package·{
 0003b6b0:·2027·6169·6465·273a·0a20·2020·2065·6e73···'aide':.····ens
 0003b6c0:·7572·6520·3d26·6774·3b20·2769·6e73·7461··ure·=&gt;·'insta
 0003b6d0:·6c6c·6564·272c·0a20·207d·0a7d·0a3c·2f63··lled',.··}.}.</c
 0003b6e0:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div>
 0003b6f0:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt
 0003b700:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data-
 0003b710:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse
 0003b720:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
 0003b730:·6964·6d35·3639·3922·2074·6162·696e·6465··idm5699"·tabinde
 0003b740:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt
 0003b750:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande
 0003b760:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=
 0003b770:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev
 0003b780:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R
 0003b790:·656d·6564·6961·7469·6f6e·2053·6865·6c6c··emediation·Shell
 0003b7a0:·2073·6372·6970·7420·e287·b23c·2f61·3e3c···script·...</a><
 0003b7b0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
 0003b7c0:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
 0003b7d0:·6c6c·6170·7365·2220·6964·3d22·6964·6d35··llapse"·id="idm5
 0003b7e0:·3639·3922·3e3c·7461·626c·6520·636c·6173··699"><table·clas
 0003b7f0:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s
 0003b800:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor
 0003b810:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond
 0003b820:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C
 0003b830:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><
 0003b840:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
 0003b850:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti
 0003b860:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<
 0003b870:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 0003b880:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td
 0003b890:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr>
 0003b8a0:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy
 0003b8b0:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable
 0003b8c0:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl
 0003b8d0:·653e·3c70·7265·3e3c·636f·6465·3e23·2052··e><pre><code>#·R
 0003b8e0:·656d·6564·6961·7469·6f6e·2069·7320·6170··emediation·is·ap
 0003b8f0:·706c·6963·6162·6c65·206f·6e6c·7920·696e··plicable·only·in
 0003b900:·2063·6572·7461·696e·2070·6c61·7466·6f72···certain·platfor
 0003b910:·6d73·0a69·6620·7270·6d20·2d2d·7175·6965··ms.if·rpm·--quie
 0003b920:·7420·2d71·206b·6572·6e65·6c20·7c7c·2072··t·-q·kernel·||·r
 0003b930:·706d·202d·2d71·7569·6574·202d·7120·6b65··pm·--quiet·-q·ke
 0003b940:·726e·656c·2d75·656b·3b20·7468·656e·0a0a··rnel-uek;·then..
 0003b950:·6966·2021·2072·706d·202d·7120·2d2d·7175··if·!·rpm·-q·--qu
 0003b960:·6965·7420·2261·6964·6522·203b·2074·6865··iet·"aide"·;·the
 0003b970:·6e0a·2020·2020·7975·6d20·696e·7374·616c··n.····yum·instal
 0003b980:·6c20·2d79·2022·6169·6465·220a·6669·0a0a··l·-y·"aide".fi..
 0003b990:·656c·7365·0a20·2020·2026·6774·3b26·616d··else.····&gt;&am
 0003b9a0:·703b·3220·6563·686f·2027·5265·6d65·6469··p;2·echo·'Remedi
 0003b9b0:·6174·696f·6e20·6973·206e·6f74·2061·7070··ation·is·not·app
 0003b9c0:·6c69·6361·626c·652c·206e·6f74·6869·6e67··licable,·nothing
 0003b9d0:·2077·6173·2064·6f6e·6527·0a66·690a·3c2f···was·done'.fi.</
 0003b9e0:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div
 0003b9f0:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b
 0003ba00:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data
 0003ba10:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps
 0003ba20:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
 0003ba30:·2369·646d·3537·3030·2220·7461·6269·6e64··#idm5700"·tabind
 0003ba40:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
 0003ba50:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
 0003ba60:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
 0003ba70:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
 0003ba80:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
0003b3e0:·5265·6d65·6469·6174·696f·6e20·416e·6163··Remediation·Anac0003ba90:·5265·6d65·6469·6174·696f·6e20·416e·6163··Remediation·Anac
0003b3f0:·6f6e·6461·2073·6e69·7070·6574·20e2·87b2··onda·snippet·...0003baa0:·6f6e·6461·2073·6e69·7070·6574·20e2·87b2··onda·snippet·...
0003b400:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla0003bab0:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
0003b410:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap0003bac0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
0003b420:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=0003bad0:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
0003b430:·2269·646d·3536·3937·223e·3c74·6162·6c65··"idm5697"><table0003bae0:·2269·646d·3537·3030·223e·3c74·6162·6c65··"idm5700"><table
0003b440:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta 
0003b450:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl 
0003b460:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table 
0003b470:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr> 
0003b480:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:< 
0003b490:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td> 
0003b4a0:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis 
Max diff block lines reached; 951008/969528 bytes (98.09%) of diff not shown.
91.8 KB
html2text {}
    
Offset 139, 21 lines modifiedOffset 139, 14 lines modified
139 ··-·PCI-DSSv4-11.5.2139 ··-·PCI-DSSv4-11.5.2
140 ··-·enable_strategy140 ··-·enable_strategy
141 ··-·low_complexity141 ··-·low_complexity
142 ··-·low_disruption142 ··-·low_disruption
143 ··-·medium_severity143 ··-·medium_severity
144 ··-·no_reboot_needed144 ··-·no_reboot_needed
145 ··-·package_aide_installed145 ··-·package_aide_installed
146 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
147 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
148 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
149 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
150 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
151 package·--add=aide 
152 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8146 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
153 [[packages]]147 [[packages]]
154 name·=·"aide"148 name·=·"aide"
155 version·=·"*"149 version·=·"*"
156 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8150 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
157 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low151 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 178, 14 lines modifiedOffset 171, 21 lines modified
178 if·!·rpm·-q·--quiet·"aide"·;·then171 if·!·rpm·-q·--quiet·"aide"·;·then
179 ····yum·install·-y·"aide"172 ····yum·install·-y·"aide"
180 fi173 fi
  
181 else174 else
182 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'175 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
183 fi176 fi
 177 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 178 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 179 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 180 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 181 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 182 package·--add=aide
184 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*183 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
185 Run·the·following·command·to·generate·a·new·database:184 Run·the·following·command·to·generate·a·new·database:
186 $·sudo·/usr/sbin/aide·--init185 $·sudo·/usr/sbin/aide·--init
187 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:186 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
188 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz187 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
189 To·initiate·a·manual·check,·run·the·following·command:188 To·initiate·a·manual·check,·run·the·following·command:
190 $·sudo·/usr/sbin/aide·--check189 $·sudo·/usr/sbin/aide·--check
Offset 5532, 21 lines modifiedOffset 5532, 14 lines modified
5532 ··-·DISA-STIG-OL08-00-0104725532 ··-·DISA-STIG-OL08-00-010472
5533 ··-·enable_strategy5533 ··-·enable_strategy
5534 ··-·low_complexity5534 ··-·low_complexity
5535 ··-·low_disruption5535 ··-·low_disruption
5536 ··-·low_severity5536 ··-·low_severity
5537 ··-·no_reboot_needed5537 ··-·no_reboot_needed
5538 ··-·package_rng-tools_installed5538 ··-·package_rng-tools_installed
5539 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
5540 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
5541 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
5542 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
5543 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
5544 package·--add=rng-tools 
5545 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x85539 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
5546 [[packages]]5540 [[packages]]
5547 name·=·"rng-tools"5541 name·=·"rng-tools"
5548 version·=·"*"5542 version·=·"*"
5549 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x85543 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
5550 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low5544 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 5571, 14 lines modifiedOffset 5564, 21 lines modified
5571 if·!·rpm·-q·--quiet·"rng-tools"·;·then5564 if·!·rpm·-q·--quiet·"rng-tools"·;·then
5572 ····yum·install·-y·"rng-tools"5565 ····yum·install·-y·"rng-tools"
5573 fi5566 fi
  
5574 else5567 else
5575 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'5568 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
5576 fi5569 fi
 5570 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 5571 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 5572 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 5573 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 5574 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 5575 package·--add=rng-tools
5577 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·U\x8Un\x8ni\x8in\x8ns\x8st\x8ta\x8al\x8ll\x8l·a\x8ab\x8br\x8rt\x8t-\x8-l\x8li\x8ib\x8bs\x8s·P\x8Pa\x8ac\x8ck\x8ka\x8ag\x8ge\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*5576 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·U\x8Un\x8ni\x8in\x8ns\x8st\x8ta\x8al\x8ll\x8l·a\x8ab\x8br\x8rt\x8t-\x8-l\x8li\x8ib\x8bs\x8s·P\x8Pa\x8ac\x8ck\x8ka\x8ag\x8ge\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
5578 The·abrt-libs·package·can·be·removed·with·the·following·command:5577 The·abrt-libs·package·can·be·removed·with·the·following·command:
5579 $·sudo·yum·erase·abrt-libs5578 $·sudo·yum·erase·abrt-libs
5580 Rationale:··abrt-libs·provides·libraries·for·the·ABRT·package.5579 Rationale:··abrt-libs·provides·libraries·for·the·ABRT·package.
5581 Severity: ··medium5580 Severity: ··medium
5582 Rule·ID:····xccdf_org.ssgproject.content_rule_package_abrt-libs_removed5581 Rule·ID:····xccdf_org.ssgproject.content_rule_package_abrt-libs_removed
5583 ············_\x8d_\x8i_\x8s_\x8a····CCI-0003815582 ············_\x8d_\x8i_\x8s_\x8a····CCI-000381
Offset 5598, 21 lines modifiedOffset 5598, 14 lines modified
5598 ··-·DISA-STIG-OL08-00-0400015598 ··-·DISA-STIG-OL08-00-040001
5599 ··-·disable_strategy5599 ··-·disable_strategy
5600 ··-·low_complexity5600 ··-·low_complexity
5601 ··-·low_disruption5601 ··-·low_disruption
5602 ··-·medium_severity5602 ··-·medium_severity
5603 ··-·no_reboot_needed5603 ··-·no_reboot_needed
5604 ··-·package_abrt-libs_removed5604 ··-·package_abrt-libs_removed
5605 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
5606 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
5607 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
5608 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
5609 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable 
  
5610 package·--remove=abrt-libs 
5611 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x85605 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
5612 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low5606 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
5613 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low5607 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
5614 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false5608 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
5615 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable5609 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
5616 include·remove_abrt-libs5610 include·remove_abrt-libs
  
Offset 5632, 14 lines modifiedOffset 5625, 21 lines modified
5632 #»      ···that·depend·on·abrt-libs.·Execute·this5625 #»      ···that·depend·on·abrt-libs.·Execute·this
5633 #»      ···remediation·AFTER·testing·on·a·non-production5626 #»      ···remediation·AFTER·testing·on·a·non-production
5634 #»      ···system!5627 #»      ···system!
  
5635 if·rpm·-q·--quiet·"abrt-libs"·;·then5628 if·rpm·-q·--quiet·"abrt-libs"·;·then
5636 yum·remove·-y·"abrt-libs"5629 yum·remove·-y·"abrt-libs"
5637 fi5630 fi
 5631 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 5632 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 5633 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 5634 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 5635 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
  
 5636 package·--remove=abrt-libs
5638 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·U\x8Un\x8ni\x8in\x8ns\x8st\x8ta\x8al\x8ll\x8l·a\x8ab\x8br\x8rt\x8t-\x8-s\x8se\x8er\x8rv\x8ve\x8er\x8r-\x8-i\x8in\x8nf\x8fo\x8o-\x8-p\x8pa\x8ag\x8ge\x8e·P\x8Pa\x8ac\x8ck\x8ka\x8ag\x8ge\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*5637 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·U\x8Un\x8ni\x8in\x8ns\x8st\x8ta\x8al\x8ll\x8l·a\x8ab\x8br\x8rt\x8t-\x8-s\x8se\x8er\x8rv\x8ve\x8er\x8r-\x8-i\x8in\x8nf\x8fo\x8o-\x8-p\x8pa\x8ag\x8ge\x8e·P\x8Pa\x8ac\x8ck\x8ka\x8ag\x8ge\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
5639 The·abrt-server-info-page·package·can·be·removed·with·the·following·command:5638 The·abrt-server-info-page·package·can·be·removed·with·the·following·command:
5640 $·sudo·yum·erase·abrt-server-info-page5639 $·sudo·yum·erase·abrt-server-info-page
Max diff block lines reached; 88838/93974 bytes (94.53%) of diff not shown.
1.0 MB
./usr/share/doc/ssg-nondebian/ssg-ol8-guide-stig_gui.html
    
Offset 15178, 144 lines modifiedOffset 15178, 144 lines modified
0003b490:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe0003b490:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
0003b4a0:·743d·2223·6964·6d35·3639·3722·2074·6162··t="#idm5697"·tab0003b4a0:·743d·2223·6964·6d35·3639·3722·2074·6162··t="#idm5697"·tab
0003b4b0:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="0003b4b0:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
0003b4c0:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp0003b4c0:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
0003b4d0:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti0003b4d0:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
0003b4e0:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to0003b4e0:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
0003b4f0:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#0003b4f0:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
0003b500:·2122·3e52·656d·6564·6961·7469·6f6e·2041··!">Remediation·A0003b500:·2122·3e52·656d·6564·6961·7469·6f6e·204f··!">Remediation·O
 0003b510:·5342·7569·6c64·2042·6c75·6570·7269·6e74··SBuild·Blueprint
 0003b520:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>
 0003b530:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="
 0003b540:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c
 0003b550:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm
 0003b560:·3536·3937·223e·3c70·7265·3e3c·636f·6465··5697"><pre><code
 0003b570:·3e0a·5b5b·7061·636b·6167·6573·5d5d·0a6e··>.[[packages]].n
 0003b580:·616d·6520·3d20·2261·6964·6522·0a76·6572··ame·=·"aide".ver
 0003b590:·7369·6f6e·203d·2022·2a22·0a3c·2f63·6f64··sion·=·"*".</cod
 0003b5a0:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a
 0003b5b0:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn-
 0003b5c0:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to
 0003b5d0:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"·
 0003b5e0:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
 0003b5f0:·6d35·3639·3822·2074·6162·696e·6465·783d··m5698"·tabindex=
 0003b600:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button
 0003b610:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=
 0003b620:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A
 0003b630:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea
 0003b640:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem
 0003b650:·6564·6961·7469·6f6e·2050·7570·7065·7420··ediation·Puppet·
 0003b660:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><
 0003b670:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
 0003b680:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
 0003b690:·6c6c·6170·7365·2220·6964·3d22·6964·6d35··llapse"·id="idm5
 0003b6a0:·3639·3822·3e3c·7461·626c·6520·636c·6173··698"><table·clas
 0003b6b0:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s
 0003b6c0:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor
 0003b6d0:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond
 0003b6e0:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C
 0003b6f0:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><
 0003b700:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
 0003b710:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti
 0003b720:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<
 0003b730:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 0003b740:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td
 0003b750:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr>
 0003b760:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy
 0003b770:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable
 0003b780:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl
 0003b790:·653e·3c70·7265·3e3c·636f·6465·3e69·6e63··e><pre><code>inc
 0003b7a0:·6c75·6465·2069·6e73·7461·6c6c·5f61·6964··lude·install_aid
 0003b7b0:·650a·0a63·6c61·7373·2069·6e73·7461·6c6c··e..class·install
 0003b7c0:·5f61·6964·6520·7b0a·2020·7061·636b·6167··_aide·{.··packag
 0003b7d0:·6520·7b20·2761·6964·6527·3a0a·2020·2020··e·{·'aide':.····
 0003b7e0:·656e·7375·7265·203d·2667·743b·2027·696e··ensure·=&gt;·'in
 0003b7f0:·7374·616c·6c65·6427·2c0a·2020·7d0a·7d0a··stalled',.··}.}.
 0003b800:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d
 0003b810:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn
 0003b820:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da
 0003b830:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla
 0003b840:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
 0003b850:·3d22·2369·646d·3536·3939·2220·7461·6269··="#idm5699"·tabi
 0003b860:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
 0003b870:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
 0003b880:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
 0003b890:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
 0003b8a0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
 0003b8b0:·223e·5265·6d65·6469·6174·696f·6e20·5368··">Remediation·Sh
 0003b8c0:·656c·6c20·7363·7269·7074·20e2·87b2·3c2f··ell·script·...</
 0003b8d0:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
 0003b8e0:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
 0003b8f0:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
 0003b900:·646d·3536·3939·223e·3c74·6162·6c65·2063··dm5699"><table·c
 0003b910:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl
 0003b920:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-
 0003b930:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c
 0003b940:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t
 0003b950:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t
 0003b960:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
 0003b970:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru
 0003b980:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l
 0003b990:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
 0003b9a0:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th>
 0003b9b0:·3c74·643e·6661·6c73·653c·2f74·643e·3c2f··<td>false</td></
 0003b9c0:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat
 0003b9d0:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena
 0003b9e0:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t
 0003b9f0:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>
 0003ba00:·2320·5265·6d65·6469·6174·696f·6e20·6973··#·Remediation·is
 0003ba10:·2061·7070·6c69·6361·626c·6520·6f6e·6c79···applicable·only
 0003ba20:·2069·6e20·6365·7274·6169·6e20·706c·6174···in·certain·plat
 0003ba30:·666f·726d·730a·6966·2072·706d·202d·2d71··forms.if·rpm·--q
 0003ba40:·7569·6574·202d·7120·6b65·726e·656c·207c··uiet·-q·kernel·|
 0003ba50:·7c20·7270·6d20·2d2d·7175·6965·7420·2d71··|·rpm·--quiet·-q
 0003ba60:·206b·6572·6e65·6c2d·7565·6b3b·2074·6865···kernel-uek;·the
 0003ba70:·6e0a·0a69·6620·2120·7270·6d20·2d71·202d··n..if·!·rpm·-q·-
 0003ba80:·2d71·7569·6574·2022·6169·6465·2220·3b20··-quiet·"aide"·;·
 0003ba90:·7468·656e·0a20·2020·2079·756d·2069·6e73··then.····yum·ins
 0003baa0:·7461·6c6c·202d·7920·2261·6964·6522·0a66··tall·-y·"aide".f
 0003bab0:·690a·0a65·6c73·650a·2020·2020·2667·743b··i..else.····&gt;
 0003bac0:·2661·6d70·3b32·2065·6368·6f20·2752·656d··&amp;2·echo·'Rem
 0003bad0:·6564·6961·7469·6f6e·2069·7320·6e6f·7420··ediation·is·not·
 0003bae0:·6170·706c·6963·6162·6c65·2c20·6e6f·7468··applicable,·noth
 0003baf0:·696e·6720·7761·7320·646f·6e65·270a·6669··ing·was·done'.fi
 0003bb00:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></
 0003bb10:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt
 0003bb20:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d
 0003bb30:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll
 0003bb40:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
 0003bb50:·743d·2223·6964·6d35·3730·3022·2074·6162··t="#idm5700"·tab
 0003bb60:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
 0003bb70:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
 0003bb80:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
 0003bb90:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
 0003bba0:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
 0003bbb0:·2122·3e52·656d·6564·6961·7469·6f6e·2041··!">Remediation·A
0003b510:·6e61·636f·6e64·6120·736e·6970·7065·7420··naconda·snippet·0003bbc0:·6e61·636f·6e64·6120·736e·6970·7065·7420··naconda·snippet·
0003b520:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·0003bbd0:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·
0003b530:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col0003bbe0:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col
0003b540:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·0003bbf0:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·
0003b550:·6964·3d22·6964·6d35·3639·3722·3e3c·7461··id="idm5697"><ta0003bc00:·6964·3d22·6964·6d35·3730·3022·3e3c·7461··id="idm5700"><ta
0003b560:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table 
0003b570:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t 
0003b580:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta 
0003b590:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed">< 
0003b5a0:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit 
0003b5b0:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</ 
0003b5c0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
Max diff block lines reached; 939388/957908 bytes (98.07%) of diff not shown.
89.8 KB
html2text {}
    
Offset 143, 21 lines modifiedOffset 143, 14 lines modified
143 ··-·PCI-DSSv4-11.5.2143 ··-·PCI-DSSv4-11.5.2
144 ··-·enable_strategy144 ··-·enable_strategy
145 ··-·low_complexity145 ··-·low_complexity
146 ··-·low_disruption146 ··-·low_disruption
147 ··-·medium_severity147 ··-·medium_severity
148 ··-·no_reboot_needed148 ··-·no_reboot_needed
149 ··-·package_aide_installed149 ··-·package_aide_installed
150 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
151 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
152 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
153 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
154 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
155 package·--add=aide 
156 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8150 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
157 [[packages]]151 [[packages]]
158 name·=·"aide"152 name·=·"aide"
159 version·=·"*"153 version·=·"*"
160 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8154 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
161 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low155 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 182, 14 lines modifiedOffset 175, 21 lines modified
182 if·!·rpm·-q·--quiet·"aide"·;·then175 if·!·rpm·-q·--quiet·"aide"·;·then
183 ····yum·install·-y·"aide"176 ····yum·install·-y·"aide"
184 fi177 fi
  
185 else178 else
186 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'179 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
187 fi180 fi
 181 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 182 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 183 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 184 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 185 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 186 package·--add=aide
188 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*187 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
189 Run·the·following·command·to·generate·a·new·database:188 Run·the·following·command·to·generate·a·new·database:
190 $·sudo·/usr/sbin/aide·--init189 $·sudo·/usr/sbin/aide·--init
191 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:190 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
192 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz191 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
193 To·initiate·a·manual·check,·run·the·following·command:192 To·initiate·a·manual·check,·run·the·following·command:
194 $·sudo·/usr/sbin/aide·--check193 $·sudo·/usr/sbin/aide·--check
Offset 5536, 21 lines modifiedOffset 5536, 14 lines modified
5536 ··-·DISA-STIG-OL08-00-0104725536 ··-·DISA-STIG-OL08-00-010472
5537 ··-·enable_strategy5537 ··-·enable_strategy
5538 ··-·low_complexity5538 ··-·low_complexity
5539 ··-·low_disruption5539 ··-·low_disruption
5540 ··-·low_severity5540 ··-·low_severity
5541 ··-·no_reboot_needed5541 ··-·no_reboot_needed
5542 ··-·package_rng-tools_installed5542 ··-·package_rng-tools_installed
5543 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
5544 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
5545 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
5546 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
5547 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
5548 package·--add=rng-tools 
5549 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x85543 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
5550 [[packages]]5544 [[packages]]
5551 name·=·"rng-tools"5545 name·=·"rng-tools"
5552 version·=·"*"5546 version·=·"*"
5553 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x85547 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
5554 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low5548 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 5575, 14 lines modifiedOffset 5568, 21 lines modified
5575 if·!·rpm·-q·--quiet·"rng-tools"·;·then5568 if·!·rpm·-q·--quiet·"rng-tools"·;·then
5576 ····yum·install·-y·"rng-tools"5569 ····yum·install·-y·"rng-tools"
5577 fi5570 fi
  
5578 else5571 else
5579 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'5572 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
5580 fi5573 fi
 5574 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 5575 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 5576 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 5577 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 5578 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 5579 package·--add=rng-tools
5581 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·U\x8Un\x8ni\x8in\x8ns\x8st\x8ta\x8al\x8ll\x8l·a\x8ab\x8br\x8rt\x8t-\x8-l\x8li\x8ib\x8bs\x8s·P\x8Pa\x8ac\x8ck\x8ka\x8ag\x8ge\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*5580 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·U\x8Un\x8ni\x8in\x8ns\x8st\x8ta\x8al\x8ll\x8l·a\x8ab\x8br\x8rt\x8t-\x8-l\x8li\x8ib\x8bs\x8s·P\x8Pa\x8ac\x8ck\x8ka\x8ag\x8ge\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
5582 The·abrt-libs·package·can·be·removed·with·the·following·command:5581 The·abrt-libs·package·can·be·removed·with·the·following·command:
5583 $·sudo·yum·erase·abrt-libs5582 $·sudo·yum·erase·abrt-libs
5584 Rationale:··abrt-libs·provides·libraries·for·the·ABRT·package.5583 Rationale:··abrt-libs·provides·libraries·for·the·ABRT·package.
5585 Severity: ··medium5584 Severity: ··medium
5586 Rule·ID:····xccdf_org.ssgproject.content_rule_package_abrt-libs_removed5585 Rule·ID:····xccdf_org.ssgproject.content_rule_package_abrt-libs_removed
5587 ············_\x8d_\x8i_\x8s_\x8a····CCI-0003815586 ············_\x8d_\x8i_\x8s_\x8a····CCI-000381
Offset 5602, 21 lines modifiedOffset 5602, 14 lines modified
5602 ··-·DISA-STIG-OL08-00-0400015602 ··-·DISA-STIG-OL08-00-040001
5603 ··-·disable_strategy5603 ··-·disable_strategy
5604 ··-·low_complexity5604 ··-·low_complexity
5605 ··-·low_disruption5605 ··-·low_disruption
5606 ··-·medium_severity5606 ··-·medium_severity
5607 ··-·no_reboot_needed5607 ··-·no_reboot_needed
5608 ··-·package_abrt-libs_removed5608 ··-·package_abrt-libs_removed
5609 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
5610 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
5611 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
5612 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
5613 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable 
  
5614 package·--remove=abrt-libs 
5615 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x85609 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
5616 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low5610 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
5617 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low5611 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
5618 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false5612 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
5619 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable5613 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
5620 include·remove_abrt-libs5614 include·remove_abrt-libs
  
Offset 5636, 14 lines modifiedOffset 5629, 21 lines modified
5636 #»      ···that·depend·on·abrt-libs.·Execute·this5629 #»      ···that·depend·on·abrt-libs.·Execute·this
5637 #»      ···remediation·AFTER·testing·on·a·non-production5630 #»      ···remediation·AFTER·testing·on·a·non-production
5638 #»      ···system!5631 #»      ···system!
  
5639 if·rpm·-q·--quiet·"abrt-libs"·;·then5632 if·rpm·-q·--quiet·"abrt-libs"·;·then
5640 yum·remove·-y·"abrt-libs"5633 yum·remove·-y·"abrt-libs"
5641 fi5634 fi
 5635 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 5636 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 5637 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 5638 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 5639 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
  
 5640 package·--remove=abrt-libs
5642 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·U\x8Un\x8ni\x8in\x8ns\x8st\x8ta\x8al\x8ll\x8l·a\x8ab\x8br\x8rt\x8t-\x8-s\x8se\x8er\x8rv\x8ve\x8er\x8r-\x8-i\x8in\x8nf\x8fo\x8o-\x8-p\x8pa\x8ag\x8ge\x8e·P\x8Pa\x8ac\x8ck\x8ka\x8ag\x8ge\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*5641 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·U\x8Un\x8ni\x8in\x8ns\x8st\x8ta\x8al\x8ll\x8l·a\x8ab\x8br\x8rt\x8t-\x8-s\x8se\x8er\x8rv\x8ve\x8er\x8r-\x8-i\x8in\x8nf\x8fo\x8o-\x8-p\x8pa\x8ag\x8ge\x8e·P\x8Pa\x8ac\x8ck\x8ka\x8ag\x8ge\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
5643 The·abrt-server-info-page·package·can·be·removed·with·the·following·command:5642 The·abrt-server-info-page·package·can·be·removed·with·the·following·command:
5644 $·sudo·yum·erase·abrt-server-info-page5643 $·sudo·yum·erase·abrt-server-info-page
Max diff block lines reached; 86782/91918 bytes (94.41%) of diff not shown.
750 KB
./usr/share/doc/ssg-nondebian/ssg-ol9-guide-anssi_bp28_enhanced.html
    
Offset 15111, 144 lines modifiedOffset 15111, 144 lines modified
0003b060:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#0003b060:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
0003b070:·6964·6d36·3238·3022·2074·6162·696e·6465··idm6280"·tabinde0003b070:·6964·6d36·3238·3022·2074·6162·696e·6465··idm6280"·tabinde
0003b080:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt0003b080:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt
0003b090:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande0003b090:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande
0003b0a0:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=0003b0a0:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=
0003b0b0:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev0003b0b0:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev
0003b0c0:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R0003b0c0:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R
 0003b0d0:·656d·6564·6961·7469·6f6e·204f·5342·7569··emediation·OSBui
 0003b0e0:·6c64·2042·6c75·6570·7269·6e74·2073·6e69··ld·Blueprint·sni
 0003b0f0:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>
 0003b100:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
 0003b110:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
 0003b120:·7073·6522·2069·643d·2269·646d·3632·3830··pse"·id="idm6280
 0003b130:·223e·3c70·7265·3e3c·636f·6465·3e0a·5b5b··"><pre><code>.[[
 0003b140:·7061·636b·6167·6573·5d5d·0a6e·616d·6520··packages]].name·
 0003b150:·3d20·2261·6964·6522·0a76·6572·7369·6f6e··=·"aide".version
 0003b160:·203d·2022·2a22·0a3c·2f63·6f64·653e·3c2f···=·"*".</code></
 0003b170:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla
 0003b180:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ
 0003b190:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle
 0003b1a0:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data
 0003b1b0:·2d74·6172·6765·743d·2223·6964·6d36·3238··-target="#idm628
 0003b1c0:·3122·2074·6162·696e·6465·783d·2230·2220··1"·tabindex="0"·
 0003b1d0:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar
 0003b1e0:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal
 0003b1f0:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ
 0003b200:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h
 0003b210:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia
 0003b220:·7469·6f6e·2050·7570·7065·7420·736e·6970··tion·Puppet·snip
 0003b230:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br><
 0003b240:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
 0003b250:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap
 0003b260:·7365·2220·6964·3d22·6964·6d36·3238·3122··se"·id="idm6281"
 0003b270:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t
 0003b280:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip
 0003b290:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere
 0003b2a0:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense
 0003b2b0:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl
 0003b2c0:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l
 0003b2d0:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
 0003b2e0:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:<
 0003b2f0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
 0003b300:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb
 0003b310:·6f6f·743a·3c2f·7468·3e3c·7464·3e66·616c··oot:</th><td>fal
 0003b320:·7365·3c2f·7464·3e3c·2f74·723e·3c74·723e··se</td></tr><tr>
 0003b330:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t
 0003b340:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td
 0003b350:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p
 0003b360:·7265·3e3c·636f·6465·3e69·6e63·6c75·6465··re><code>include
 0003b370:·2069·6e73·7461·6c6c·5f61·6964·650a·0a63···install_aide..c
 0003b380:·6c61·7373·2069·6e73·7461·6c6c·5f61·6964··lass·install_aid
 0003b390:·6520·7b0a·2020·7061·636b·6167·6520·7b20··e·{.··package·{·
 0003b3a0:·2761·6964·6527·3a0a·2020·2020·656e·7375··'aide':.····ensu
 0003b3b0:·7265·203d·2667·743b·2027·696e·7374·616c··re·=&gt;·'instal
 0003b3c0:·6c65·6427·2c0a·2020·7d0a·7d0a·3c2f·636f··led',.··}.}.</co
 0003b3d0:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div><
 0003b3e0:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn
 0003b3f0:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t
 0003b400:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse"
 0003b410:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i
 0003b420:·646d·3632·3832·2220·7461·6269·6e64·6578··dm6282"·tabindex
 0003b430:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto
 0003b440:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded
 0003b450:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="
 0003b460:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve
 0003b470:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re
 0003b480:·6d65·6469·6174·696f·6e20·5368·656c·6c20··mediation·Shell·
 0003b490:·7363·7269·7074·20e2·87b2·3c2f·613e·3c62··script·...</a><b
 0003b4a0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
 0003b4b0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
 0003b4c0:·6c61·7073·6522·2069·643d·2269·646d·3632··lapse"·id="idm62
 0003b4d0:·3832·223e·3c74·6162·6c65·2063·6c61·7373··82"><table·class
 0003b4e0:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st
 0003b4f0:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord
 0003b500:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde
 0003b510:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co
 0003b520:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t
 0003b530:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
 0003b540:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio
 0003b550:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</
 0003b560:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 0003b570:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td>
 0003b580:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr><
 0003b590:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:
 0003b5a0:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<
 0003b5b0:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table
 0003b5c0:·3e3c·7072·653e·3c63·6f64·653e·2320·5265··><pre><code>#·Re
 0003b5d0:·6d65·6469·6174·696f·6e20·6973·2061·7070··mediation·is·app
 0003b5e0:·6c69·6361·626c·6520·6f6e·6c79·2069·6e20··licable·only·in·
 0003b5f0:·6365·7274·6169·6e20·706c·6174·666f·726d··certain·platform
 0003b600:·730a·6966·2072·706d·202d·2d71·7569·6574··s.if·rpm·--quiet
 0003b610:·202d·7120·6b65·726e·656c·207c·7c20·7270···-q·kernel·||·rp
 0003b620:·6d20·2d2d·7175·6965·7420·2d71·206b·6572··m·--quiet·-q·ker
 0003b630:·6e65·6c2d·7565·6b3b·2074·6865·6e0a·0a69··nel-uek;·then..i
 0003b640:·6620·2120·7270·6d20·2d71·202d·2d71·7569··f·!·rpm·-q·--qui
 0003b650:·6574·2022·6169·6465·2220·3b20·7468·656e··et·"aide"·;·then
 0003b660:·0a20·2020·2079·756d·2069·6e73·7461·6c6c··.····yum·install
 0003b670:·202d·7920·2261·6964·6522·0a66·690a·0a65···-y·"aide".fi..e
 0003b680:·6c73·650a·2020·2020·2667·743b·2661·6d70··lse.····&gt;&amp
 0003b690:·3b32·2065·6368·6f20·2752·656d·6564·6961··;2·echo·'Remedia
 0003b6a0:·7469·6f6e·2069·7320·6e6f·7420·6170·706c··tion·is·not·appl
 0003b6b0:·6963·6162·6c65·2c20·6e6f·7468·696e·6720··icable,·nothing·
 0003b6c0:·7761·7320·646f·6e65·270a·6669·0a3c·2f63··was·done'.fi.</c
 0003b6d0:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div>
 0003b6e0:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt
 0003b6f0:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data-
 0003b700:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse
 0003b710:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
 0003b720:·6964·6d36·3238·3322·2074·6162·696e·6465··idm6283"·tabinde
 0003b730:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt
 0003b740:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande
 0003b750:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=
 0003b760:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev
 0003b770:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R
0003b0d0:·656d·6564·6961·7469·6f6e·2041·6e61·636f··emediation·Anaco0003b780:·656d·6564·6961·7469·6f6e·2041·6e61·636f··emediation·Anaco
0003b0e0:·6e64·6120·736e·6970·7065·7420·e287·b23c··nda·snippet·...<0003b790:·6e64·6120·736e·6970·7065·7420·e287·b23c··nda·snippet·...<
0003b0f0:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas0003b7a0:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas
0003b100:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps0003b7b0:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps
0003b110:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id=" 
0003b120:·6964·6d36·3238·3022·3e3c·7461·626c·6520··idm6280"><table· 
0003b130:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab 
0003b140:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table 
0003b150:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table- 
0003b160:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr>< 
0003b170:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</ 
0003b180:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td>< 
0003b190:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr 
Max diff block lines reached; 690090/708610 bytes (97.39%) of diff not shown.
57.7 KB
html2text {}
    
Offset 149, 21 lines modifiedOffset 149, 14 lines modified
149 ··-·PCI-DSSv4-11.5.2149 ··-·PCI-DSSv4-11.5.2
150 ··-·enable_strategy150 ··-·enable_strategy
151 ··-·low_complexity151 ··-·low_complexity
152 ··-·low_disruption152 ··-·low_disruption
153 ··-·medium_severity153 ··-·medium_severity
154 ··-·no_reboot_needed154 ··-·no_reboot_needed
155 ··-·package_aide_installed155 ··-·package_aide_installed
156 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
157 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
158 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
159 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
160 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
161 package·--add=aide 
162 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8156 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
163 [[packages]]157 [[packages]]
164 name·=·"aide"158 name·=·"aide"
165 version·=·"*"159 version·=·"*"
166 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8160 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
167 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low161 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 188, 14 lines modifiedOffset 181, 21 lines modified
188 if·!·rpm·-q·--quiet·"aide"·;·then181 if·!·rpm·-q·--quiet·"aide"·;·then
189 ····yum·install·-y·"aide"182 ····yum·install·-y·"aide"
190 fi183 fi
  
191 else184 else
192 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'185 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
193 fi186 fi
 187 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 188 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 189 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 190 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 191 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 192 package·--add=aide
194 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*193 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
195 Run·the·following·command·to·generate·a·new·database:194 Run·the·following·command·to·generate·a·new·database:
196 $·sudo·/usr/sbin/aide·--init195 $·sudo·/usr/sbin/aide·--init
197 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the196 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the
198 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these197 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these
199 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their198 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their
200 integrity.·The·newly-generated·database·can·be·installed·as·follows:199 integrity.·The·newly-generated·database·can·be·installed·as·follows:
Offset 534, 21 lines modifiedOffset 534, 14 lines modified
534 ··tags:534 ··tags:
535 ··-·enable_strategy535 ··-·enable_strategy
536 ··-·low_complexity536 ··-·low_complexity
537 ··-·low_disruption537 ··-·low_disruption
538 ··-·low_severity538 ··-·low_severity
539 ··-·no_reboot_needed539 ··-·no_reboot_needed
540 ··-·systemd_tmp_mount_enabled540 ··-·systemd_tmp_mount_enabled
541 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
542 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
543 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
544 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
545 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
546 services·--enabled=tmp.mount 
547 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8541 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
548 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low542 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
549 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low543 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
550 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false544 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
551 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable545 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
552 #·Remediation·is·applicable·only·in·certain·platforms546 #·Remediation·is·applicable·only·in·certain·platforms
553 if·(·!·(·{·rpm·--quiet·-q·kernel·;}·&&·{·rpm·--quiet·-q·rpm-ostree·;}·&&·{·rpm·--quiet·-q·bootc·;}·&&547 if·(·!·(·{·rpm·--quiet·-q·kernel·;}·&&·{·rpm·--quiet·-q·rpm-ostree·;}·&&·{·rpm·--quiet·-q·bootc·;}·&&
Offset 561, 14 lines modifiedOffset 554, 21 lines modified
561 ··"$SYSTEMCTL_EXEC"·start·'tmp.mount'554 ··"$SYSTEMCTL_EXEC"·start·'tmp.mount'
562 fi555 fi
563 "$SYSTEMCTL_EXEC"·enable·'tmp.mount'556 "$SYSTEMCTL_EXEC"·enable·'tmp.mount'
  
564 else557 else
565 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'558 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
566 fi559 fi
 560 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 561 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 562 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 563 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 564 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 565 services·--enabled=tmp.mount
567 Group  ·Sudo·  Group·contains·14·rules566 Group  ·Sudo·  Group·contains·14·rules
568 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Sudo,·which·stands·for·"su·'do'",·provides·the·ability·to·delegate·authority·to·certain567 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Sudo,·which·stands·for·"su·'do'",·provides·the·ability·to·delegate·authority·to·certain
569 users,·groups·of·users,·or·system·administrators.·When·configured·for·system·users·and/or·groups,568 users,·groups·of·users,·or·system·administrators.·When·configured·for·system·users·and/or·groups,
570 Sudo·can·allow·a·user·or·group·to·execute·privileged·commands·that·normally·only·root·is·allowed·to569 Sudo·can·allow·a·user·or·group·to·execute·privileged·commands·that·normally·only·root·is·allowed·to
571 execute.570 execute.
  
572 For·more·information·on·Sudo·and·addition·Sudo·configuration·options,·see·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8w\x8w_\x8w\x8w_\x8w\x8w_\x8.\x8._\x8s\x8s_\x8u\x8u_\x8d\x8d_\x8o\x8o_\x8.\x8._\x8w\x8w_\x8s\x8s.571 For·more·information·on·Sudo·and·addition·Sudo·configuration·options,·see·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8w\x8w_\x8w\x8w_\x8w\x8w_\x8.\x8._\x8s\x8s_\x8u\x8u_\x8d\x8d_\x8o\x8o_\x8.\x8._\x8w\x8w_\x8s\x8s.
Offset 617, 21 lines modifiedOffset 617, 14 lines modified
617 ··-·PCI-DSSv4-2.2.6617 ··-·PCI-DSSv4-2.2.6
618 ··-·enable_strategy618 ··-·enable_strategy
619 ··-·low_complexity619 ··-·low_complexity
620 ··-·low_disruption620 ··-·low_disruption
621 ··-·medium_severity621 ··-·medium_severity
622 ··-·no_reboot_needed622 ··-·no_reboot_needed
623 ··-·package_sudo_installed623 ··-·package_sudo_installed
624 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
625 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
626 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
627 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
628 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
629 package·--add=sudo 
630 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8624 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
631 [[packages]]625 [[packages]]
632 name·=·"sudo"626 name·=·"sudo"
633 version·=·"*"627 version·=·"*"
634 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8628 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
635 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low629 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 656, 14 lines modifiedOffset 649, 21 lines modified
656 if·!·rpm·-q·--quiet·"sudo"·;·then649 if·!·rpm·-q·--quiet·"sudo"·;·then
657 ····yum·install·-y·"sudo"650 ····yum·install·-y·"sudo"
658 fi651 fi
  
659 else652 else
660 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'653 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
661 fi654 fi
 655 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 656 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 657 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 658 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 659 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 660 package·--add=sudo
662 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·G\x8Gr\x8ro\x8ou\x8up\x8p·W\x8Wh\x8ho\x8o·O\x8Ow\x8wn\x8ns\x8s·/\x8/e\x8et\x8tc\x8c/\x8/s\x8su\x8ud\x8do\x8oe\x8er\x8rs\x8s.\x8.d\x8d·D\x8Di\x8ir\x8re\x8ec\x8ct\x8to\x8or\x8ry\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*661 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·G\x8Gr\x8ro\x8ou\x8up\x8p·W\x8Wh\x8ho\x8o·O\x8Ow\x8wn\x8ns\x8s·/\x8/e\x8et\x8tc\x8c/\x8/s\x8su\x8ud\x8do\x8oe\x8er\x8rs\x8s.\x8.d\x8d·D\x8Di\x8ir\x8re\x8ec\x8ct\x8to\x8or\x8ry\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
663 To·properly·set·the·group·owner·of·/etc/sudoers.d,·run·the·command:662 To·properly·set·the·group·owner·of·/etc/sudoers.d,·run·the·command:
664 $·sudo·chgrp·root·/etc/sudoers.d663 $·sudo·chgrp·root·/etc/sudoers.d
Max diff block lines reached; 53934/59059 bytes (91.32%) of diff not shown.
810 KB
./usr/share/doc/ssg-nondebian/ssg-ol9-guide-anssi_bp28_high.html
    
Offset 15116, 144 lines modifiedOffset 15116, 144 lines modified
0003b0b0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target0003b0b0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
0003b0c0:·3d22·2369·646d·3632·3830·2220·7461·6269··="#idm6280"·tabi0003b0c0:·3d22·2369·646d·3632·3830·2220·7461·6269··="#idm6280"·tabi
0003b0d0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b0003b0d0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
0003b0e0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa0003b0e0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
0003b0f0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit0003b0f0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
0003b100:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·0003b100:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
0003b110:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!0003b110:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
 0003b120:·223e·5265·6d65·6469·6174·696f·6e20·4f53··">Remediation·OS
 0003b130:·4275·696c·6420·426c·7565·7072·696e·7420··Build·Blueprint·
 0003b140:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><
 0003b150:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
 0003b160:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
 0003b170:·6c6c·6170·7365·2220·6964·3d22·6964·6d36··llapse"·id="idm6
 0003b180:·3238·3022·3e3c·7072·653e·3c63·6f64·653e··280"><pre><code>
 0003b190:·0a5b·5b70·6163·6b61·6765·735d·5d0a·6e61··.[[packages]].na
 0003b1a0:·6d65·203d·2022·6169·6465·220a·7665·7273··me·=·"aide".vers
 0003b1b0:·696f·6e20·3d20·222a·220a·3c2f·636f·6465··ion·=·"*".</code
 0003b1c0:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a·
 0003b1d0:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s
 0003b1e0:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog
 0003b1f0:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d
 0003b200:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
 0003b210:·3632·3831·2220·7461·6269·6e64·6578·3d22··6281"·tabindex="
 0003b220:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
 0003b230:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
 0003b240:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
 0003b250:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
 0003b260:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
 0003b270:·6469·6174·696f·6e20·5075·7070·6574·2073··diation·Puppet·s
 0003b280:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b
 0003b290:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
 0003b2a0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
 0003b2b0:·6c61·7073·6522·2069·643d·2269·646d·3632··lapse"·id="idm62
 0003b2c0:·3831·223e·3c74·6162·6c65·2063·6c61·7373··81"><table·class
 0003b2d0:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st
 0003b2e0:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord
 0003b2f0:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde
 0003b300:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co
 0003b310:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t
 0003b320:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
 0003b330:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio
 0003b340:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</
 0003b350:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 0003b360:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td>
 0003b370:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr><
 0003b380:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:
 0003b390:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<
 0003b3a0:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table
 0003b3b0:·3e3c·7072·653e·3c63·6f64·653e·696e·636c··><pre><code>incl
 0003b3c0:·7564·6520·696e·7374·616c·6c5f·6169·6465··ude·install_aide
 0003b3d0:·0a0a·636c·6173·7320·696e·7374·616c·6c5f··..class·install_
 0003b3e0:·6169·6465·207b·0a20·2070·6163·6b61·6765··aide·{.··package
 0003b3f0:·207b·2027·6169·6465·273a·0a20·2020·2065···{·'aide':.····e
 0003b400:·6e73·7572·6520·3d26·6774·3b20·2769·6e73··nsure·=&gt;·'ins
 0003b410:·7461·6c6c·6564·272c·0a20·207d·0a7d·0a3c··talled',.··}.}.<
 0003b420:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di
 0003b430:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn·
 0003b440:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat
 0003b450:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap
 0003b460:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
 0003b470:·2223·6964·6d36·3238·3222·2074·6162·696e··"#idm6282"·tabin
 0003b480:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
 0003b490:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
 0003b4a0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
 0003b4b0:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
 0003b4c0:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
 0003b4d0:·3e52·656d·6564·6961·7469·6f6e·2053·6865··>Remediation·She
 0003b4e0:·6c6c·2073·6372·6970·7420·e287·b23c·2f61··ll·script·...</a
 0003b4f0:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
 0003b500:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
 0003b510:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
 0003b520:·6d36·3238·3222·3e3c·7461·626c·6520·636c··m6282"><table·cl
 0003b530:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table
 0003b540:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b
 0003b550:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co
 0003b560:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th
 0003b570:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th
 0003b580:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
 0003b590:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup
 0003b5a0:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo
 0003b5b0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
 0003b5c0:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th><
 0003b5d0:·7464·3e66·616c·7365·3c2f·7464·3e3c·2f74··td>false</td></t
 0003b5e0:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate
 0003b5f0:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab
 0003b600:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta
 0003b610:·626c·653e·3c70·7265·3e3c·636f·6465·3e23··ble><pre><code>#
 0003b620:·2052·656d·6564·6961·7469·6f6e·2069·7320···Remediation·is·
 0003b630:·6170·706c·6963·6162·6c65·206f·6e6c·7920··applicable·only·
 0003b640:·696e·2063·6572·7461·696e·2070·6c61·7466··in·certain·platf
 0003b650:·6f72·6d73·0a69·6620·7270·6d20·2d2d·7175··orms.if·rpm·--qu
 0003b660:·6965·7420·2d71·206b·6572·6e65·6c20·7c7c··iet·-q·kernel·||
 0003b670:·2072·706d·202d·2d71·7569·6574·202d·7120···rpm·--quiet·-q·
 0003b680:·6b65·726e·656c·2d75·656b·3b20·7468·656e··kernel-uek;·then
 0003b690:·0a0a·6966·2021·2072·706d·202d·7120·2d2d··..if·!·rpm·-q·--
 0003b6a0:·7175·6965·7420·2261·6964·6522·203b·2074··quiet·"aide"·;·t
 0003b6b0:·6865·6e0a·2020·2020·7975·6d20·696e·7374··hen.····yum·inst
 0003b6c0:·616c·6c20·2d79·2022·6169·6465·220a·6669··all·-y·"aide".fi
 0003b6d0:·0a0a·656c·7365·0a20·2020·2026·6774·3b26··..else.····&gt;&
 0003b6e0:·616d·703b·3220·6563·686f·2027·5265·6d65··amp;2·echo·'Reme
 0003b6f0:·6469·6174·696f·6e20·6973·206e·6f74·2061··diation·is·not·a
 0003b700:·7070·6c69·6361·626c·652c·206e·6f74·6869··pplicable,·nothi
 0003b710:·6e67·2077·6173·2064·6f6e·6527·0a66·690a··ng·was·done'.fi.
 0003b720:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d
 0003b730:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn
 0003b740:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da
 0003b750:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla
 0003b760:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
 0003b770:·3d22·2369·646d·3632·3833·2220·7461·6269··="#idm6283"·tabi
 0003b780:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
 0003b790:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
 0003b7a0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
 0003b7b0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
 0003b7c0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
0003b120:·223e·5265·6d65·6469·6174·696f·6e20·416e··">Remediation·An0003b7d0:·223e·5265·6d65·6469·6174·696f·6e20·416e··">Remediation·An
0003b130:·6163·6f6e·6461·2073·6e69·7070·6574·20e2··aconda·snippet·.0003b7e0:·6163·6f6e·6461·2073·6e69·7070·6574·20e2··aconda·snippet·.
0003b140:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c0003b7f0:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c
0003b150:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll0003b800:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
0003b160:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i0003b810:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
0003b170:·643d·2269·646d·3632·3830·223e·3c74·6162··d="idm6280"><tab0003b820:·643d·2269·646d·3632·3833·223e·3c74·6162··d="idm6283"><tab
0003b180:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·0003b830:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·
0003b190:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta 
0003b1a0:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab 
0003b1b0:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t 
0003b1c0:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity 
0003b1d0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t 
0003b1e0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D 
Max diff block lines reached; 746346/764866 bytes (97.58%) of diff not shown.
63.0 KB
html2text {}
    
Offset 150, 21 lines modifiedOffset 150, 14 lines modified
150 ··-·PCI-DSSv4-11.5.2150 ··-·PCI-DSSv4-11.5.2
151 ··-·enable_strategy151 ··-·enable_strategy
152 ··-·low_complexity152 ··-·low_complexity
153 ··-·low_disruption153 ··-·low_disruption
154 ··-·medium_severity154 ··-·medium_severity
155 ··-·no_reboot_needed155 ··-·no_reboot_needed
156 ··-·package_aide_installed156 ··-·package_aide_installed
157 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
158 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
159 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
160 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
161 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
162 package·--add=aide 
163 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8157 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
164 [[packages]]158 [[packages]]
165 name·=·"aide"159 name·=·"aide"
166 version·=·"*"160 version·=·"*"
167 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8161 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
168 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low162 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 189, 14 lines modifiedOffset 182, 21 lines modified
189 if·!·rpm·-q·--quiet·"aide"·;·then182 if·!·rpm·-q·--quiet·"aide"·;·then
190 ····yum·install·-y·"aide"183 ····yum·install·-y·"aide"
191 fi184 fi
  
192 else185 else
193 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'186 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
194 fi187 fi
 188 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 189 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 190 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 191 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 192 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 193 package·--add=aide
195 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*194 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
196 Run·the·following·command·to·generate·a·new·database:195 Run·the·following·command·to·generate·a·new·database:
197 $·sudo·/usr/sbin/aide·--init196 $·sudo·/usr/sbin/aide·--init
198 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the197 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the
199 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these198 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these
200 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their199 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their
201 integrity.·The·newly-generated·database·can·be·installed·as·follows:200 integrity.·The·newly-generated·database·can·be·installed·as·follows:
Offset 1072, 21 lines modifiedOffset 1072, 14 lines modified
1072 ··tags:1072 ··tags:
1073 ··-·enable_strategy1073 ··-·enable_strategy
1074 ··-·low_complexity1074 ··-·low_complexity
1075 ··-·low_disruption1075 ··-·low_disruption
1076 ··-·low_severity1076 ··-·low_severity
1077 ··-·no_reboot_needed1077 ··-·no_reboot_needed
1078 ··-·systemd_tmp_mount_enabled1078 ··-·systemd_tmp_mount_enabled
1079 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
1080 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
1081 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
1082 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
1083 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
1084 services·--enabled=tmp.mount 
1085 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81079 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1086 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1080 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1087 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1081 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1088 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1082 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1089 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1083 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1090 #·Remediation·is·applicable·only·in·certain·platforms1084 #·Remediation·is·applicable·only·in·certain·platforms
1091 if·(·!·(·{·rpm·--quiet·-q·kernel·;}·&&·{·rpm·--quiet·-q·rpm-ostree·;}·&&·{·rpm·--quiet·-q·bootc·;}·&&1085 if·(·!·(·{·rpm·--quiet·-q·kernel·;}·&&·{·rpm·--quiet·-q·rpm-ostree·;}·&&·{·rpm·--quiet·-q·bootc·;}·&&
Offset 1099, 14 lines modifiedOffset 1092, 21 lines modified
1099 ··"$SYSTEMCTL_EXEC"·start·'tmp.mount'1092 ··"$SYSTEMCTL_EXEC"·start·'tmp.mount'
1100 fi1093 fi
1101 "$SYSTEMCTL_EXEC"·enable·'tmp.mount'1094 "$SYSTEMCTL_EXEC"·enable·'tmp.mount'
  
1102 else1095 else
1103 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'1096 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
1104 fi1097 fi
 1098 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 1099 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1100 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1101 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1102 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 1103 services·--enabled=tmp.mount
1105 Group  ·Sudo·  Group·contains·14·rules1104 Group  ·Sudo·  Group·contains·14·rules
1106 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Sudo,·which·stands·for·"su·'do'",·provides·the·ability·to·delegate·authority·to·certain1105 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Sudo,·which·stands·for·"su·'do'",·provides·the·ability·to·delegate·authority·to·certain
1107 users,·groups·of·users,·or·system·administrators.·When·configured·for·system·users·and/or·groups,1106 users,·groups·of·users,·or·system·administrators.·When·configured·for·system·users·and/or·groups,
1108 Sudo·can·allow·a·user·or·group·to·execute·privileged·commands·that·normally·only·root·is·allowed·to1107 Sudo·can·allow·a·user·or·group·to·execute·privileged·commands·that·normally·only·root·is·allowed·to
1109 execute.1108 execute.
  
1110 For·more·information·on·Sudo·and·addition·Sudo·configuration·options,·see·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8w\x8w_\x8w\x8w_\x8w\x8w_\x8.\x8._\x8s\x8s_\x8u\x8u_\x8d\x8d_\x8o\x8o_\x8.\x8._\x8w\x8w_\x8s\x8s.1109 For·more·information·on·Sudo·and·addition·Sudo·configuration·options,·see·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8w\x8w_\x8w\x8w_\x8w\x8w_\x8.\x8._\x8s\x8s_\x8u\x8u_\x8d\x8d_\x8o\x8o_\x8.\x8._\x8w\x8w_\x8s\x8s.
Offset 1155, 21 lines modifiedOffset 1155, 14 lines modified
1155 ··-·PCI-DSSv4-2.2.61155 ··-·PCI-DSSv4-2.2.6
1156 ··-·enable_strategy1156 ··-·enable_strategy
1157 ··-·low_complexity1157 ··-·low_complexity
1158 ··-·low_disruption1158 ··-·low_disruption
1159 ··-·medium_severity1159 ··-·medium_severity
1160 ··-·no_reboot_needed1160 ··-·no_reboot_needed
1161 ··-·package_sudo_installed1161 ··-·package_sudo_installed
1162 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
1163 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
1164 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
1165 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
1166 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
1167 package·--add=sudo 
1168 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81162 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
1169 [[packages]]1163 [[packages]]
1170 name·=·"sudo"1164 name·=·"sudo"
1171 version·=·"*"1165 version·=·"*"
1172 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81166 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1173 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1167 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 1194, 14 lines modifiedOffset 1187, 21 lines modified
1194 if·!·rpm·-q·--quiet·"sudo"·;·then1187 if·!·rpm·-q·--quiet·"sudo"·;·then
1195 ····yum·install·-y·"sudo"1188 ····yum·install·-y·"sudo"
1196 fi1189 fi
  
1197 else1190 else
1198 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'1191 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
1199 fi1192 fi
 1193 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 1194 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1195 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1196 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1197 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 1198 package·--add=sudo
1200 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·G\x8Gr\x8ro\x8ou\x8up\x8p·W\x8Wh\x8ho\x8o·O\x8Ow\x8wn\x8ns\x8s·/\x8/e\x8et\x8tc\x8c/\x8/s\x8su\x8ud\x8do\x8oe\x8er\x8rs\x8s.\x8.d\x8d·D\x8Di\x8ir\x8re\x8ec\x8ct\x8to\x8or\x8ry\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*1199 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·G\x8Gr\x8ro\x8ou\x8up\x8p·W\x8Wh\x8ho\x8o·O\x8Ow\x8wn\x8ns\x8s·/\x8/e\x8et\x8tc\x8c/\x8/s\x8su\x8ud\x8do\x8oe\x8er\x8rs\x8s.\x8.d\x8d·D\x8Di\x8ir\x8re\x8ec\x8ct\x8to\x8or\x8ry\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
1201 To·properly·set·the·group·owner·of·/etc/sudoers.d,·run·the·command:1200 To·properly·set·the·group·owner·of·/etc/sudoers.d,·run·the·command:
1202 $·sudo·chgrp·root·/etc/sudoers.d1201 $·sudo·chgrp·root·/etc/sudoers.d
Max diff block lines reached; 59391/64524 bytes (92.04%) of diff not shown.
688 KB
./usr/share/doc/ssg-nondebian/ssg-ol9-guide-anssi_bp28_intermediary.html
    
Offset 15107, 144 lines modifiedOffset 15107, 144 lines modified
0003b020:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm0003b020:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
0003b030:·3632·3830·2220·7461·6269·6e64·6578·3d22··6280"·tabindex="0003b030:·3632·3830·2220·7461·6269·6e64·6578·3d22··6280"·tabindex="
0003b040:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"0003b040:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
0003b050:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="0003b050:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
0003b060:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac0003b060:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
0003b070:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal0003b070:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
0003b080:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme0003b080:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
 0003b090:·6469·6174·696f·6e20·4f53·4275·696c·6420··diation·OSBuild·
 0003b0a0:·426c·7565·7072·696e·7420·736e·6970·7065··Blueprint·snippe
 0003b0b0:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di
 0003b0c0:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c
 0003b0d0:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse
 0003b0e0:·2220·6964·3d22·6964·6d36·3238·3022·3e3c··"·id="idm6280"><
 0003b0f0:·7072·653e·3c63·6f64·653e·0a5b·5b70·6163··pre><code>.[[pac
 0003b100:·6b61·6765·735d·5d0a·6e61·6d65·203d·2022··kages]].name·=·"
 0003b110:·6169·6465·220a·7665·7273·696f·6e20·3d20··aide".version·=·
 0003b120:·222a·220a·3c2f·636f·6465·3e3c·2f70·7265··"*".</code></pre
 0003b130:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class=
 0003b140:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success
 0003b150:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c
 0003b160:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta
 0003b170:·7267·6574·3d22·2369·646d·3632·3831·2220··rget="#idm6281"·
 0003b180:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol
 0003b190:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-
 0003b1a0:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"
 0003b1b0:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate
 0003b1c0:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href
 0003b1d0:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio
 0003b1e0:·6e20·5075·7070·6574·2073·6e69·7070·6574··n·Puppet·snippet
 0003b1f0:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
 0003b200:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
 0003b210:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
 0003b220:·2069·643d·2269·646d·3632·3831·223e·3c74···id="idm6281"><t
 0003b230:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl
 0003b240:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·
 0003b250:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t
 0003b260:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">
 0003b270:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi
 0003b280:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<
 0003b290:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 0003b2a0:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th
 0003b2b0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
 0003b2c0:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot
 0003b2d0:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false<
 0003b2e0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 0003b2f0:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><
 0003b300:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></
 0003b310:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>
 0003b320:·3c63·6f64·653e·696e·636c·7564·6520·696e··<code>include·in
 0003b330:·7374·616c·6c5f·6169·6465·0a0a·636c·6173··stall_aide..clas
 0003b340:·7320·696e·7374·616c·6c5f·6169·6465·207b··s·install_aide·{
 0003b350:·0a20·2070·6163·6b61·6765·207b·2027·6169··.··package·{·'ai
 0003b360:·6465·273a·0a20·2020·2065·6e73·7572·6520··de':.····ensure·
 0003b370:·3d26·6774·3b20·2769·6e73·7461·6c6c·6564··=&gt;·'installed
 0003b380:·272c·0a20·207d·0a7d·0a3c·2f63·6f64·653e··',.··}.}.</code>
 0003b390:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c
 0003b3a0:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su
 0003b3b0:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg
 0003b3c0:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da
 0003b3d0:·7461·2d74·6172·6765·743d·2223·6964·6d36··ta-target="#idm6
 0003b3e0:·3238·3222·2074·6162·696e·6465·783d·2230··282"·tabindex="0
 0003b3f0:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
 0003b400:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
 0003b410:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
 0003b420:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
 0003b430:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
 0003b440:·6961·7469·6f6e·2053·6865·6c6c·2073·6372··iation·Shell·scr
 0003b450:·6970·7420·e287·b23c·2f61·3e3c·6272·3e3c··ipt·...</a><br><
 0003b460:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
 0003b470:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap
 0003b480:·7365·2220·6964·3d22·6964·6d36·3238·3222··se"·id="idm6282"
 0003b490:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t
 0003b4a0:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip
 0003b4b0:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere
 0003b4c0:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense
 0003b4d0:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl
 0003b4e0:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l
 0003b4f0:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
 0003b500:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:<
 0003b510:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
 0003b520:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb
 0003b530:·6f6f·743a·3c2f·7468·3e3c·7464·3e66·616c··oot:</th><td>fal
 0003b540:·7365·3c2f·7464·3e3c·2f74·723e·3c74·723e··se</td></tr><tr>
 0003b550:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t
 0003b560:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td
 0003b570:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p
 0003b580:·7265·3e3c·636f·6465·3e23·2052·656d·6564··re><code>#·Remed
 0003b590:·6961·7469·6f6e·2069·7320·6170·706c·6963··iation·is·applic
 0003b5a0:·6162·6c65·206f·6e6c·7920·696e·2063·6572··able·only·in·cer
 0003b5b0:·7461·696e·2070·6c61·7466·6f72·6d73·0a69··tain·platforms.i
 0003b5c0:·6620·7270·6d20·2d2d·7175·6965·7420·2d71··f·rpm·--quiet·-q
 0003b5d0:·206b·6572·6e65·6c20·7c7c·2072·706d·202d···kernel·||·rpm·-
 0003b5e0:·2d71·7569·6574·202d·7120·6b65·726e·656c··-quiet·-q·kernel
 0003b5f0:·2d75·656b·3b20·7468·656e·0a0a·6966·2021··-uek;·then..if·!
 0003b600:·2072·706d·202d·7120·2d2d·7175·6965·7420···rpm·-q·--quiet·
 0003b610:·2261·6964·6522·203b·2074·6865·6e0a·2020··"aide"·;·then.··
 0003b620:·2020·7975·6d20·696e·7374·616c·6c20·2d79····yum·install·-y
 0003b630:·2022·6169·6465·220a·6669·0a0a·656c·7365···"aide".fi..else
 0003b640:·0a20·2020·2026·6774·3b26·616d·703b·3220··.····&gt;&amp;2·
 0003b650:·6563·686f·2027·5265·6d65·6469·6174·696f··echo·'Remediatio
 0003b660:·6e20·6973·206e·6f74·2061·7070·6c69·6361··n·is·not·applica
 0003b670:·626c·652c·206e·6f74·6869·6e67·2077·6173··ble,·nothing·was
 0003b680:·2064·6f6e·6527·0a66·690a·3c2f·636f·6465···done'.fi.</code
 0003b690:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a·
 0003b6a0:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s
 0003b6b0:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog
 0003b6c0:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d
 0003b6d0:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
 0003b6e0:·3632·3833·2220·7461·6269·6e64·6578·3d22··6283"·tabindex="
 0003b6f0:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
 0003b700:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
 0003b710:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
 0003b720:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
 0003b730:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
0003b090:·6469·6174·696f·6e20·416e·6163·6f6e·6461··diation·Anaconda0003b740:·6469·6174·696f·6e20·416e·6163·6f6e·6461··diation·Anaconda
0003b0a0:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>0003b750:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>
0003b0b0:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="0003b760:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="
0003b0c0:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c0003b770:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c
0003b0d0:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm0003b780:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm
0003b0e0:·3632·3830·223e·3c74·6162·6c65·2063·6c61··6280"><table·cla0003b790:·3632·3833·223e·3c74·6162·6c65·2063·6c61··6283"><table·cla
0003b0f0:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-0003b7a0:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-
0003b100:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo0003b7b0:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo
0003b110:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con 
0003b120:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th> 
0003b130:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th> 
0003b140:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
0003b150:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt 
Max diff block lines reached; 632389/650909 bytes (97.15%) of diff not shown.
52.4 KB
html2text {}
    
Offset 148, 21 lines modifiedOffset 148, 14 lines modified
148 ··-·PCI-DSSv4-11.5.2148 ··-·PCI-DSSv4-11.5.2
149 ··-·enable_strategy149 ··-·enable_strategy
150 ··-·low_complexity150 ··-·low_complexity
151 ··-·low_disruption151 ··-·low_disruption
152 ··-·medium_severity152 ··-·medium_severity
153 ··-·no_reboot_needed153 ··-·no_reboot_needed
154 ··-·package_aide_installed154 ··-·package_aide_installed
155 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
156 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
157 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
158 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
159 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
160 package·--add=aide 
161 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8155 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
162 [[packages]]156 [[packages]]
163 name·=·"aide"157 name·=·"aide"
164 version·=·"*"158 version·=·"*"
165 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8159 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
166 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low160 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 187, 14 lines modifiedOffset 180, 21 lines modified
187 if·!·rpm·-q·--quiet·"aide"·;·then180 if·!·rpm·-q·--quiet·"aide"·;·then
188 ····yum·install·-y·"aide"181 ····yum·install·-y·"aide"
189 fi182 fi
  
190 else183 else
191 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'184 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
192 fi185 fi
 186 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 187 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 188 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 189 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 190 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 191 package·--add=aide
193 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*192 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
194 Run·the·following·command·to·generate·a·new·database:193 Run·the·following·command·to·generate·a·new·database:
195 $·sudo·/usr/sbin/aide·--init194 $·sudo·/usr/sbin/aide·--init
196 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the195 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the
197 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these196 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these
198 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their197 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their
199 integrity.·The·newly-generated·database·can·be·installed·as·follows:198 integrity.·The·newly-generated·database·can·be·installed·as·follows:
Offset 500, 21 lines modifiedOffset 500, 14 lines modified
500 ··tags:500 ··tags:
501 ··-·enable_strategy501 ··-·enable_strategy
502 ··-·low_complexity502 ··-·low_complexity
503 ··-·low_disruption503 ··-·low_disruption
504 ··-·low_severity504 ··-·low_severity
505 ··-·no_reboot_needed505 ··-·no_reboot_needed
506 ··-·systemd_tmp_mount_enabled506 ··-·systemd_tmp_mount_enabled
507 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
508 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
509 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
510 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
511 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
512 services·--enabled=tmp.mount 
513 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8507 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
514 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low508 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
515 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low509 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
516 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false510 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
517 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable511 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
518 #·Remediation·is·applicable·only·in·certain·platforms512 #·Remediation·is·applicable·only·in·certain·platforms
519 if·(·!·(·{·rpm·--quiet·-q·kernel·;}·&&·{·rpm·--quiet·-q·rpm-ostree·;}·&&·{·rpm·--quiet·-q·bootc·;}·&&513 if·(·!·(·{·rpm·--quiet·-q·kernel·;}·&&·{·rpm·--quiet·-q·rpm-ostree·;}·&&·{·rpm·--quiet·-q·bootc·;}·&&
Offset 527, 14 lines modifiedOffset 520, 21 lines modified
527 ··"$SYSTEMCTL_EXEC"·start·'tmp.mount'520 ··"$SYSTEMCTL_EXEC"·start·'tmp.mount'
528 fi521 fi
529 "$SYSTEMCTL_EXEC"·enable·'tmp.mount'522 "$SYSTEMCTL_EXEC"·enable·'tmp.mount'
  
530 else523 else
531 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'524 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
532 fi525 fi
 526 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 527 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 528 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 529 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 530 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 531 services·--enabled=tmp.mount
533 Group  ·Sudo·  Group·contains·13·rules532 Group  ·Sudo·  Group·contains·13·rules
534 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Sudo,·which·stands·for·"su·'do'",·provides·the·ability·to·delegate·authority·to·certain533 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Sudo,·which·stands·for·"su·'do'",·provides·the·ability·to·delegate·authority·to·certain
535 users,·groups·of·users,·or·system·administrators.·When·configured·for·system·users·and/or·groups,534 users,·groups·of·users,·or·system·administrators.·When·configured·for·system·users·and/or·groups,
536 Sudo·can·allow·a·user·or·group·to·execute·privileged·commands·that·normally·only·root·is·allowed·to535 Sudo·can·allow·a·user·or·group·to·execute·privileged·commands·that·normally·only·root·is·allowed·to
537 execute.536 execute.
  
538 For·more·information·on·Sudo·and·addition·Sudo·configuration·options,·see·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8w\x8w_\x8w\x8w_\x8w\x8w_\x8.\x8._\x8s\x8s_\x8u\x8u_\x8d\x8d_\x8o\x8o_\x8.\x8._\x8w\x8w_\x8s\x8s.537 For·more·information·on·Sudo·and·addition·Sudo·configuration·options,·see·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8w\x8w_\x8w\x8w_\x8w\x8w_\x8.\x8._\x8s\x8s_\x8u\x8u_\x8d\x8d_\x8o\x8o_\x8.\x8._\x8w\x8w_\x8s\x8s.
Offset 583, 21 lines modifiedOffset 583, 14 lines modified
583 ··-·PCI-DSSv4-2.2.6583 ··-·PCI-DSSv4-2.2.6
584 ··-·enable_strategy584 ··-·enable_strategy
585 ··-·low_complexity585 ··-·low_complexity
586 ··-·low_disruption586 ··-·low_disruption
587 ··-·medium_severity587 ··-·medium_severity
588 ··-·no_reboot_needed588 ··-·no_reboot_needed
589 ··-·package_sudo_installed589 ··-·package_sudo_installed
590 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
591 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
592 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
593 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
594 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
595 package·--add=sudo 
596 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8590 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
597 [[packages]]591 [[packages]]
598 name·=·"sudo"592 name·=·"sudo"
599 version·=·"*"593 version·=·"*"
600 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8594 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
601 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low595 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 622, 14 lines modifiedOffset 615, 21 lines modified
622 if·!·rpm·-q·--quiet·"sudo"·;·then615 if·!·rpm·-q·--quiet·"sudo"·;·then
623 ····yum·install·-y·"sudo"616 ····yum·install·-y·"sudo"
624 fi617 fi
  
625 else618 else
626 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'619 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
627 fi620 fi
 621 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 622 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 623 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 624 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 625 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 626 package·--add=sudo
628 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·G\x8Gr\x8ro\x8ou\x8up\x8p·W\x8Wh\x8ho\x8o·O\x8Ow\x8wn\x8ns\x8s·/\x8/e\x8et\x8tc\x8c/\x8/s\x8su\x8ud\x8do\x8oe\x8er\x8rs\x8s.\x8.d\x8d·D\x8Di\x8ir\x8re\x8ec\x8ct\x8to\x8or\x8ry\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*627 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·G\x8Gr\x8ro\x8ou\x8up\x8p·W\x8Wh\x8ho\x8o·O\x8Ow\x8wn\x8ns\x8s·/\x8/e\x8et\x8tc\x8c/\x8/s\x8su\x8ud\x8do\x8oe\x8er\x8rs\x8s.\x8.d\x8d·D\x8Di\x8ir\x8re\x8ec\x8ct\x8to\x8or\x8ry\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
629 To·properly·set·the·group·owner·of·/etc/sudoers.d,·run·the·command:628 To·properly·set·the·group·owner·of·/etc/sudoers.d,·run·the·command:
630 $·sudo·chgrp·root·/etc/sudoers.d629 $·sudo·chgrp·root·/etc/sudoers.d
Max diff block lines reached; 48543/53668 bytes (90.45%) of diff not shown.
200 KB
./usr/share/doc/ssg-nondebian/ssg-ol9-guide-anssi_bp28_minimal.html
    
Offset 14797, 155 lines modifiedOffset 14797, 155 lines modified
00039cc0:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#00039cc0:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
00039cd0:·6964·6d39·3537·3022·2074·6162·696e·6465··idm9570"·tabinde00039cd0:·6964·6d39·3537·3022·2074·6162·696e·6465··idm9570"·tabinde
00039ce0:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt00039ce0:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt
00039cf0:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande00039cf0:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande
00039d00:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=00039d00:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=
00039d10:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev00039d10:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev
00039d20:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R00039d20:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R
00039d30:·656d·6564·6961·7469·6f6e·2041·6e61·636f··emediation·Anaco00039d30:·656d·6564·6961·7469·6f6e·204f·5342·7569··emediation·OSBui
 00039d40:·6c64·2042·6c75·6570·7269·6e74·2073·6e69··ld·Blueprint·sni
 00039d50:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>
 00039d60:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
 00039d70:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
 00039d80:·7073·6522·2069·643d·2269·646d·3935·3730··pse"·id="idm9570
 00039d90:·223e·3c70·7265·3e3c·636f·6465·3e0a·5b5b··"><pre><code>.[[
 00039da0:·7061·636b·6167·6573·5d5d·0a6e·616d·6520··packages]].name·
00039d40:·6e64·6120·736e·6970·7065·7420·e287·b23c··nda·snippet·...< 
00039d50:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas 
00039d60:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps 
00039d70:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id=" 
00039d80:·6964·6d39·3537·3022·3e3c·7461·626c·6520··idm9570"><table· 
00039d90:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab 
00039da0:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table 
00039db0:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table- 
00039dc0:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr>< 
00039dd0:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</ 
00039de0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td>< 
00039df0:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr 
00039e00:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td> 
00039e10:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr 
00039e20:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th 
00039e30:·3e3c·7464·3e66·616c·7365·3c2f·7464·3e3c··><td>false</td>< 
00039e40:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra 
00039e50:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en 
00039e60:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></ 
00039e70:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code 
00039e80:·3e0a·7061·636b·6167·6520·2d2d·6164·643d··>.package·--add= 
00039e90:·646e·662d·6175·746f·6d61·7469·630a·3c2f··dnf-automatic.</ 
00039ea0:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div 
00039eb0:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b 
00039ec0:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data 
00039ed0:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps 
00039ee0:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target=" 
00039ef0:·2369·646d·3935·3731·2220·7461·6269·6e64··#idm9571"·tabind 
00039f00:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but 
00039f10:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand 
00039f20:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title 
00039f30:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re 
00039f40:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!"> 
00039f50:·5265·6d65·6469·6174·696f·6e20·4f53·4275··Remediation·OSBu 
00039f60:·696c·6420·426c·7565·7072·696e·7420·736e··ild·Blueprint·sn 
00039f70:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br 
00039f80:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan 
00039f90:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll 
00039fa0:·6170·7365·2220·6964·3d22·6964·6d39·3537··apse"·id="idm957 
00039fb0:·3122·3e3c·7072·653e·3c63·6f64·653e·0a5b··1"><pre><code>.[ 
00039fc0:·5b70·6163·6b61·6765·735d·5d0a·6e61·6d65··[packages]].name 
00039fd0:·203d·2022·646e·662d·6175·746f·6d61·7469···=·"dnf-automati 
00039fe0:·6322·0a76·6572·7369·6f6e·203d·2022·2a22··c".version·=·"*" 
00039ff0:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></ 
0003a000:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt 
0003a010:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d 
0003a020:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll 
0003a030:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe 
0003a040:·743d·2223·6964·6d39·3537·3222·2074·6162··t="#idm9572"·tab 
0003a050:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role=" 
0003a060:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp 
0003a070:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti 
0003a080:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to 
0003a090:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="# 
0003a0a0:·2122·3e52·656d·6564·6961·7469·6f6e·2050··!">Remediation·P 
0003a0b0:·7570·7065·7420·736e·6970·7065·7420·e287··uppet·snippet·.. 
0003a0c0:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl 
0003a0d0:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla 
0003a0e0:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id 
0003a0f0:·3d22·6964·6d39·3537·3222·3e3c·7461·626c··="idm9572"><tabl 
0003a100:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t 
0003a110:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab 
0003a120:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl 
0003a130:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr 
0003a140:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity: 
0003a150:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td 
0003a160:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di 
0003a170:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t 
0003a180:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr>< 
0003a190:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</ 
0003a1a0:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td 
0003a1b0:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St 
0003a1c0:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td> 
0003a1d0:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr> 
0003a1e0:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co 
0003a1f0:·6465·3e69·6e63·6c75·6465·2069·6e73·7461··de>include·insta 
0003a200:·6c6c·5f64·6e66·2d61·7574·6f6d·6174·6963··ll_dnf-automatic 
0003a210:·0a0a·636c·6173·7320·696e·7374·616c·6c5f··..class·install_ 
0003a220:·646e·662d·6175·746f·6d61·7469·6320·7b0a··dnf-automatic·{. 
0003a230:·2020·7061·636b·6167·6520·7b20·2764·6e66····package·{·'dnf 
0003a240:·2d61·7574·6f6d·6174·6963·273a·0a20·2020··-automatic':.··· 
0003a250:·2065·6e73·7572·6520·3d26·6774·3b20·2769···ensure·=&gt;·'i 
0003a260:·6e73·7461·6c6c·6564·272c·0a20·207d·0a7d··nstalled',.··}.} 
0003a270:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></ 
0003a280:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt 
0003a290:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d 
0003a2a0:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll 
0003a2b0:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe 
0003a2c0:·743d·2223·6964·6d39·3537·3322·2074·6162··t="#idm9573"·tab 
0003a2d0:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role=" 
0003a2e0:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp 
0003a2f0:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti 
0003a300:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to 
0003a310:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="# 
0003a320:·2122·3e52·656d·6564·6961·7469·6f6e·2053··!">Remediation·S 
0003a330:·6865·6c6c·2073·6372·6970·7420·e287·b23c··hell·script·...< 
0003a340:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas 
0003a350:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps 
0003a360:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id=" 
0003a370:·6964·6d39·3537·3322·3e3c·7461·626c·6520··idm9573"><table· 
0003a380:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab 
0003a390:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table 
0003a3a0:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table- 
0003a3b0:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr>< 
0003a3c0:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</ 
0003a3d0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td>< 
0003a3e0:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr 
0003a3f0:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td> 
0003a400:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr 
0003a410:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th 
0003a420:·3e3c·7464·3e66·616c·7365·3c2f·7464·3e3c··><td>false</td>< 
0003a430:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra 
Max diff block lines reached; 165466/185504 bytes (89.20%) of diff not shown.
18.7 KB
html2text {}
    
Offset 112, 21 lines modifiedOffset 112, 14 lines modified
112 ··tags:112 ··tags:
113 ··-·enable_strategy113 ··-·enable_strategy
114 ··-·low_complexity114 ··-·low_complexity
115 ··-·low_disruption115 ··-·low_disruption
116 ··-·medium_severity116 ··-·medium_severity
117 ··-·no_reboot_needed117 ··-·no_reboot_needed
118 ··-·package_dnf-automatic_installed118 ··-·package_dnf-automatic_installed
119 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
120 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
121 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
122 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
123 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
124 package·--add=dnf-automatic 
125 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8119 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
126 [[packages]]120 [[packages]]
127 name·=·"dnf-automatic"121 name·=·"dnf-automatic"
128 version·=·"*"122 version·=·"*"
129 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8123 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
130 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low124 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 152, 14 lines modifiedOffset 145, 21 lines modified
152 if·!·rpm·-q·--quiet·"dnf-automatic"·;·then145 if·!·rpm·-q·--quiet·"dnf-automatic"·;·then
153 ····yum·install·-y·"dnf-automatic"146 ····yum·install·-y·"dnf-automatic"
154 fi147 fi
  
155 else148 else
156 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'149 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
157 fi150 fi
 151 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 152 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 153 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 154 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 155 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 156 package·--add=dnf-automatic
158 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·d\x8dn\x8nf\x8f-\x8-a\x8au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8c·t\x8to\x8o·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·A\x8Av\x8va\x8ai\x8il\x8la\x8ab\x8bl\x8le\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8es\x8s·A\x8Au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8ca\x8al\x8ll\x8ly\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*157 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·d\x8dn\x8nf\x8f-\x8-a\x8au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8c·t\x8to\x8o·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·A\x8Av\x8va\x8ai\x8il\x8la\x8ab\x8bl\x8le\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8es\x8s·A\x8Au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8ca\x8al\x8ll\x8ly\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
159 To·ensure·that·the·packages·comprising·the·available·updates·will·be·automatically·installed158 To·ensure·that·the·packages·comprising·the·available·updates·will·be·automatically·installed
160 by·dnf-automatic,·set·apply_updates·to·yes·under·[commands]·section·in·/etc/dnf/159 by·dnf-automatic,·set·apply_updates·to·yes·under·[commands]·section·in·/etc/dnf/
161 automatic.conf.160 automatic.conf.
162 ············Installing·software·updates·is·a·fundamental·mitigation·against·the·exploitation161 ············Installing·software·updates·is·a·fundamental·mitigation·against·the·exploitation
163 ············of·publicly-known·vulnerabilities.·If·the·most·recent·security·patches·and162 ············of·publicly-known·vulnerabilities.·If·the·most·recent·security·patches·and
164 Rationale:··updates·are·not·installed,·unauthorized·users·may·take·advantage·of·weaknesses·in163 Rationale:··updates·are·not·installed,·unauthorized·users·may·take·advantage·of·weaknesses·in
Offset 11286, 21 lines modifiedOffset 11286, 14 lines modified
11286 ··-·PCI-DSSv4-2.2.411286 ··-·PCI-DSSv4-2.2.4
11287 ··-·disable_strategy11287 ··-·disable_strategy
11288 ··-·low_complexity11288 ··-·low_complexity
11289 ··-·low_disruption11289 ··-·low_disruption
11290 ··-·medium_severity11290 ··-·medium_severity
11291 ··-·no_reboot_needed11291 ··-·no_reboot_needed
11292 ··-·package_dhcp_removed11292 ··-·package_dhcp_removed
11293 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
11294 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
11295 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
11296 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
11297 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable 
  
11298 package·--remove=dhcp 
11299 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x811293 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
11300 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low11294 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
11301 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low11295 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
11302 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false11296 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
11303 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable11297 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
11304 include·remove_dhcp11298 include·remove_dhcp
  
Offset 11320, 14 lines modifiedOffset 11313, 21 lines modified
11320 #»      ···that·depend·on·dhcp.·Execute·this11313 #»      ···that·depend·on·dhcp.·Execute·this
11321 #»      ···remediation·AFTER·testing·on·a·non-production11314 #»      ···remediation·AFTER·testing·on·a·non-production
11322 #»      ···system!11315 #»      ···system!
  
11323 if·rpm·-q·--quiet·"dhcp"·;·then11316 if·rpm·-q·--quiet·"dhcp"·;·then
11324 yum·remove·-y·"dhcp"11317 yum·remove·-y·"dhcp"
11325 fi11318 fi
 11319 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 11320 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 11321 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 11322 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 11323 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
  
 11324 package·--remove=dhcp
11326 Group  ·Mail·Server·Software·  Group·contains·1·rule11325 Group  ·Mail·Server·Software·  Group·contains·1·rule
11327 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Mail·servers·are·used·to·send·and·receive·email·over·the·network.·Mail·is·a·very11326 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Mail·servers·are·used·to·send·and·receive·email·over·the·network.·Mail·is·a·very
11328 common·service,·and·Mail·Transfer·Agents·(MTAs)·are·obvious·targets·of·network·attack.·Ensure11327 common·service,·and·Mail·Transfer·Agents·(MTAs)·are·obvious·targets·of·network·attack.·Ensure
11329 that·systems·are·not·running·MTAs·unnecessarily,·and·configure·needed·MTAs·as·defensively·as11328 that·systems·are·not·running·MTAs·unnecessarily,·and·configure·needed·MTAs·as·defensively·as
11330 possible.11329 possible.
  
11331 Very·few·systems·at·any·site·should·be·configured·to·directly·receive·email·over·the·network.11330 Very·few·systems·at·any·site·should·be·configured·to·directly·receive·email·over·the·network.
Offset 11399, 21 lines modifiedOffset 11399, 14 lines modified
11399 ··-·NIST-800-53-CM-7(b)11399 ··-·NIST-800-53-CM-7(b)
11400 ··-·disable_strategy11400 ··-·disable_strategy
11401 ··-·low_complexity11401 ··-·low_complexity
11402 ··-·low_disruption11402 ··-·low_disruption
11403 ··-·medium_severity11403 ··-·medium_severity
11404 ··-·no_reboot_needed11404 ··-·no_reboot_needed
11405 ··-·package_sendmail_removed11405 ··-·package_sendmail_removed
11406 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
11407 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
11408 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
11409 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
11410 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable 
  
11411 package·--remove=sendmail 
11412 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x811406 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
11413 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low11407 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
11414 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low11408 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
11415 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false11409 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
11416 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable11410 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
11417 include·remove_sendmail11411 include·remove_sendmail
  
Offset 11439, 14 lines modifiedOffset 11432, 21 lines modified
11439 if·rpm·-q·--quiet·"sendmail"·;·then11432 if·rpm·-q·--quiet·"sendmail"·;·then
11440 yum·remove·-y·"sendmail"11433 yum·remove·-y·"sendmail"
11441 fi11434 fi
  
11442 else11435 else
11443 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'11436 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
11444 fi11437 fi
 11438 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 11439 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 11440 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 11441 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 11442 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
  
 11443 package·--remove=sendmail
11445 Group  ·Obsolete·Services·  Group·contains·4·groups·and·8·rules11444 Group  ·Obsolete·Services·  Group·contains·4·groups·and·8·rules
11446 _\x8[_\x8r_\x8e_\x8f_\x8]  ·This·section·discusses·a·number·of·network-visible·services·which·have·historically11445 _\x8[_\x8r_\x8e_\x8f_\x8]  ·This·section·discusses·a·number·of·network-visible·services·which·have·historically
11447 caused·problems·for·system·security,·and·for·which·disabling·or·severely·limiting·the·service11446 caused·problems·for·system·security,·and·for·which·disabling·or·severely·limiting·the·service
Max diff block lines reached; 14053/19105 bytes (73.56%) of diff not shown.
261 KB
./usr/share/doc/ssg-nondebian/ssg-ol9-guide-ccn_advanced.html
    
Offset 21809, 134 lines modifiedOffset 21809, 134 lines modified
00055300:·6574·3d22·2369·646d·3933·3631·2220·7461··et="#idm9361"·ta00055300:·6574·3d22·2369·646d·3933·3631·2220·7461··et="#idm9361"·ta
00055310:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=00055310:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
00055320:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex00055320:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
00055330:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t00055330:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
00055340:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t00055340:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
00055350:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="00055350:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
00055360:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·00055360:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
00055370:·416e·6163·6f6e·6461·2073·6e69·7070·6574··Anaconda·snippet00055370:·4f53·4275·696c·6420·426c·7565·7072·696e··OSBuild·Blueprin
 00055380:·7420·736e·6970·7065·7420·e287·b23c·2f61··t·snippet·...</a
 00055390:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
 000553a0:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
 000553b0:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
 000553c0:·6d39·3336·3122·3e3c·7072·653e·3c63·6f64··m9361"><pre><cod
 000553d0:·653e·0a5b·5b70·6163·6b61·6765·735d·5d0a··e>.[[packages]].
 000553e0:·6e61·6d65·203d·2022·6372·7970·7473·6574··name·=·"cryptset
 000553f0:·7570·220a·7665·7273·696f·6e20·3d20·222a··up".version·=·"*
 00055400:·220a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··".</code></pre><
 00055410:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b
 00055420:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"·
 00055430:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col
 00055440:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ
 00055450:·6574·3d22·2369·646d·3933·3632·2220·7461··et="#idm9362"·ta
 00055460:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
 00055470:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
 00055480:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
 00055490:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
 000554a0:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
 000554b0:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
 000554c0:·5075·7070·6574·2073·6e69·7070·6574·20e2··Puppet·snippet·.
00055380:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div000554d0:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c
00055390:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co000554e0:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
000553a0:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"000554f0:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
000553b0:·2069·643d·2269·646d·3933·3631·223e·3c74···id="idm9361"><t00055500:·643d·2269·646d·3933·3632·223e·3c74·6162··d="idm9362"><tab
000553c0:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl00055510:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·
000553d0:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·00055520:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta
000553e0:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t00055530:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab
000553f0:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">00055540:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t
00055400:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi00055550:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity
00055410:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<00055560:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
00055420:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
00055430:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th 
00055440:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t 
00055450:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot 
00055460:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false< 
00055470:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th00055570:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D
 00055580:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><
 00055590:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
 000555a0:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:<
 000555b0:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t
 000555c0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S
00055480:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><000555d0:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td
00055490:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></000555e0:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr
000554a0:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>000555f0:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c
 00055600:·6f64·653e·696e·636c·7564·6520·696e·7374··ode>include·inst
 00055610:·616c·6c5f·6372·7970·7473·6574·7570·0a0a··all_cryptsetup..
 00055620:·636c·6173·7320·696e·7374·616c·6c5f·6372··class·install_cr
 00055630:·7970·7473·6574·7570·207b·0a20·2070·6163··yptsetup·{.··pac
000554b0:·3c63·6f64·653e·0a70·6163·6b61·6765·202d··<code>.package·- 
000554c0:·2d61·6464·3d63·7279·7074·7365·7475·700a··-add=cryptsetup. 
000554d0:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d 
000554e0:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn 
000554f0:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da 
00055500:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla 
00055510:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target 
00055520:·3d22·2369·646d·3933·3632·2220·7461·6269··="#idm9362"·tabi 
00055530:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b 
00055540:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa 
00055550:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit 
00055560:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to· 
00055570:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#! 
00055580:·223e·5265·6d65·6469·6174·696f·6e20·4f53··">Remediation·OS 
00055590:·4275·696c·6420·426c·7565·7072·696e·7420··Build·Blueprint· 
000555a0:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a>< 
000555b0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p 
000555c0:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co 
000555d0:·6c6c·6170·7365·2220·6964·3d22·6964·6d39··llapse"·id="idm9 
000555e0:·3336·3222·3e3c·7072·653e·3c63·6f64·653e··362"><pre><code> 
000555f0:·0a5b·5b70·6163·6b61·6765·735d·5d0a·6e61··.[[packages]].na 
00055600:·6d65·203d·2022·6372·7970·7473·6574·7570··me·=·"cryptsetup00055640:·6b61·6765·207b·2027·6372·7970·7473·6574··kage·{·'cryptset
00055610:·220a·7665·7273·696f·6e20·3d20·222a·220a··".version·=·"*". 
00055620:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d00055650:·7570·273a·0a20·2020·2065·6e73·7572·6520··up':.····ensure·
 00055660:·3d26·6774·3b20·2769·6e73·7461·6c6c·6564··=&gt;·'installed
 00055670:·272c·0a20·207d·0a7d·0a3c·2f63·6f64·653e··',.··}.}.</code>
 00055680:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c
 00055690:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su
 000556a0:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg
 000556b0:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da
 000556c0:·7461·2d74·6172·6765·743d·2223·6964·6d39··ta-target="#idm9
 000556d0:·3336·3322·2074·6162·696e·6465·783d·2230··363"·tabindex="0
 000556e0:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
 000556f0:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
 00055700:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
 00055710:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
 00055720:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
 00055730:·6961·7469·6f6e·2053·6865·6c6c·2073·6372··iation·Shell·scr
 00055740:·6970·7420·e287·b23c·2f61·3e3c·6272·3e3c··ipt·...</a><br><
 00055750:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
 00055760:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap
 00055770:·7365·2220·6964·3d22·6964·6d39·3336·3322··se"·id="idm9363"
00055630:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn00055780:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t
 00055790:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip
 000557a0:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere
 000557b0:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense
 000557c0:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl
 000557d0:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l
 000557e0:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
 000557f0:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:<
00055640:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da 
00055650:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla 
00055660:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target 
00055670:·3d22·2369·646d·3933·3633·2220·7461·6269··="#idm9363"·tabi 
00055680:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b 
00055690:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa 
000556a0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit 
000556b0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to· 
000556c0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#! 
000556d0:·223e·5265·6d65·6469·6174·696f·6e20·5075··">Remediation·Pu 
000556e0:·7070·6574·2073·6e69·7070·6574·20e2·87b2··ppet·snippet·... 
000556f0:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla 
00055700:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap 
00055710:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id= 
00055720:·2269·646d·3933·3633·223e·3c74·6162·6c65··"idm9363"><table 
00055730:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta 
00055740:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl 
00055750:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table 
00055760:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr> 
00055770:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:< 
Max diff block lines reached; 223646/240786 bytes (92.88%) of diff not shown.
25.7 KB
html2text {}
    
Offset 1808, 21 lines modifiedOffset 1808, 14 lines modified
1808 ··-·PCI-DSSv4-3.5.1.21808 ··-·PCI-DSSv4-3.5.1.2
1809 ··-·enable_strategy1809 ··-·enable_strategy
1810 ··-·low_complexity1810 ··-·low_complexity
1811 ··-·low_disruption1811 ··-·low_disruption
1812 ··-·medium_severity1812 ··-·medium_severity
1813 ··-·no_reboot_needed1813 ··-·no_reboot_needed
1814 ··-·package_cryptsetup-luks_installed1814 ··-·package_cryptsetup-luks_installed
1815 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
1816 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
1817 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
1818 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
1819 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
1820 package·--add=cryptsetup 
1821 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81815 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
1822 [[packages]]1816 [[packages]]
1823 name·=·"cryptsetup"1817 name·=·"cryptsetup"
1824 version·=·"*"1818 version·=·"*"
1825 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81819 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1826 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1820 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 1841, 14 lines modifiedOffset 1834, 21 lines modified
1841 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1834 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1842 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1835 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1843 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1836 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
1844 if·!·rpm·-q·--quiet·"cryptsetup"·;·then1837 if·!·rpm·-q·--quiet·"cryptsetup"·;·then
1845 ····yum·install·-y·"cryptsetup"1838 ····yum·install·-y·"cryptsetup"
1846 fi1839 fi
 1840 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 1841 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1842 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1843 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1844 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 1845 package·--add=cryptsetup
1847 Group  ·Account·and·Access·Control·  Group·contains·13·groups·and·29·rules1846 Group  ·Account·and·Access·Control·  Group·contains·13·groups·and·29·rules
1848 _\x8[_\x8r_\x8e_\x8f_\x8]  ·In·traditional·Unix·security,·if·an·attacker·gains·shell·access·to·a·certain·login·account,·they1847 _\x8[_\x8r_\x8e_\x8f_\x8]  ·In·traditional·Unix·security,·if·an·attacker·gains·shell·access·to·a·certain·login·account,·they
1849 can·perform·any·action·or·access·any·file·to·which·that·account·has·access.·Therefore,·making·it·more1848 can·perform·any·action·or·access·any·file·to·which·that·account·has·access.·Therefore,·making·it·more
1850 difficult·for·unauthorized·people·to·gain·shell·access·to·accounts,·particularly·to·privileged·accounts,·is1849 difficult·for·unauthorized·people·to·gain·shell·access·to·accounts,·particularly·to·privileged·accounts,·is
1851 a·necessary·part·of·securing·a·system.·This·section·introduces·mechanisms·for·restricting·access·to1850 a·necessary·part·of·securing·a·system.·This·section·introduces·mechanisms·for·restricting·access·to
1852 accounts·under·Oracle·Linux·9.1851 accounts·under·Oracle·Linux·9.
1853 Group  ·Warning·Banners·for·System·Accesses·  Group·contains·1·group·and·5·rules1852 Group  ·Warning·Banners·for·System·Accesses·  Group·contains·1·group·and·5·rules
Offset 9908, 21 lines modifiedOffset 9908, 14 lines modified
9908 ··-·PCI-DSSv4-1.2.19908 ··-·PCI-DSSv4-1.2.1
9909 ··-·enable_strategy9909 ··-·enable_strategy
9910 ··-·low_complexity9910 ··-·low_complexity
9911 ··-·low_disruption9911 ··-·low_disruption
9912 ··-·medium_severity9912 ··-·medium_severity
9913 ··-·no_reboot_needed9913 ··-·no_reboot_needed
9914 ··-·package_firewalld_installed9914 ··-·package_firewalld_installed
9915 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
9916 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
9917 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
9918 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
9919 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
9920 package·--add=firewalld 
9921 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x89915 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
9922 [[packages]]9916 [[packages]]
9923 name·=·"firewalld"9917 name·=·"firewalld"
9924 version·=·"*"9918 version·=·"*"
9925 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x89919 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
9926 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low9920 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 9947, 14 lines modifiedOffset 9940, 21 lines modified
9947 if·!·rpm·-q·--quiet·"firewalld"·;·then9940 if·!·rpm·-q·--quiet·"firewalld"·;·then
9948 ····yum·install·-y·"firewalld"9941 ····yum·install·-y·"firewalld"
9949 fi9942 fi
  
9950 else9943 else
9951 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'9944 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
9952 fi9945 fi
 9946 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 9947 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 9948 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 9949 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 9950 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 9951 package·--add=firewalld
9953 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·f\x8fi\x8ir\x8re\x8ew\x8wa\x8al\x8ll\x8ld\x8d·E\x8En\x8na\x8ab\x8bl\x8le\x8ed\x8d·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*9952 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·f\x8fi\x8ir\x8re\x8ew\x8wa\x8al\x8ll\x8ld\x8d·E\x8En\x8na\x8ab\x8bl\x8le\x8ed\x8d·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
9954 The·firewalld·service·can·be·enabled·with·the·following·command:9953 The·firewalld·service·can·be·enabled·with·the·following·command:
9955 $·sudo·systemctl·enable·firewalld.service9954 $·sudo·systemctl·enable·firewalld.service
9956 ············Access·control·methods·provide·the·ability·to·enhance·system·security·posture·by·restricting9955 ············Access·control·methods·provide·the·ability·to·enhance·system·security·posture·by·restricting
9957 Rationale:··services·and·known·good·IP·addresses·and·address·ranges.·This·prevents·connections·from·unknown9956 Rationale:··services·and·known·good·IP·addresses·and·address·ranges.·This·prevents·connections·from·unknown
9958 ············hosts·and·protocols.9957 ············hosts·and·protocols.
9959 Severity: ··medium9958 Severity: ··medium
Offset 15674, 21 lines modifiedOffset 15674, 14 lines modified
15674 ··-·PCI-DSSv4-1.2.615674 ··-·PCI-DSSv4-1.2.6
15675 ··-·enable_strategy15675 ··-·enable_strategy
15676 ··-·high_severity15676 ··-·high_severity
15677 ··-·low_complexity15677 ··-·low_complexity
15678 ··-·low_disruption15678 ··-·low_disruption
15679 ··-·no_reboot_needed15679 ··-·no_reboot_needed
15680 ··-·package_libselinux_installed15680 ··-·package_libselinux_installed
15681 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
15682 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
15683 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
15684 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
15685 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
15686 package·--add=libselinux 
15687 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x815681 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
15688 [[packages]]15682 [[packages]]
15689 name·=·"libselinux"15683 name·=·"libselinux"
15690 version·=·"*"15684 version·=·"*"
15691 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x815685 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
15692 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low15686 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 15713, 14 lines modifiedOffset 15706, 21 lines modified
15713 if·!·rpm·-q·--quiet·"libselinux"·;·then15706 if·!·rpm·-q·--quiet·"libselinux"·;·then
15714 ····yum·install·-y·"libselinux"15707 ····yum·install·-y·"libselinux"
15715 fi15708 fi
  
15716 else15709 else
15717 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'15710 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
15718 fi15711 fi
 15712 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 15713 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 15714 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 15715 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 15716 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 15717 package·--add=libselinux
15719 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·S\x8SE\x8EL\x8Li\x8in\x8nu\x8ux\x8x·N\x8No\x8ot\x8t·D\x8Di\x8is\x8sa\x8ab\x8bl\x8le\x8ed\x8d·i\x8in\x8n·/\x8/e\x8et\x8tc\x8c/\x8/d\x8de\x8ef\x8fa\x8au\x8ul\x8lt\x8t/\x8/g\x8gr\x8ru\x8ub\x8b·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*15718 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·S\x8SE\x8EL\x8Li\x8in\x8nu\x8ux\x8x·N\x8No\x8ot\x8t·D\x8Di\x8is\x8sa\x8ab\x8bl\x8le\x8ed\x8d·i\x8in\x8n·/\x8/e\x8et\x8tc\x8c/\x8/d\x8de\x8ef\x8fa\x8au\x8ul\x8lt\x8t/\x8/g\x8gr\x8ru\x8ub\x8b·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
15720 SELinux·can·be·disabled·at·boot·time·by·an·argument·in·/etc/default/grub.·Remove·any·instances·of15719 SELinux·can·be·disabled·at·boot·time·by·an·argument·in·/etc/default/grub.·Remove·any·instances·of
15721 selinux=0·from·the·kernel·arguments·in·that·file·to·prevent·SELinux·from·being·disabled·at·boot.15720 selinux=0·from·the·kernel·arguments·in·that·file·to·prevent·SELinux·from·being·disabled·at·boot.
Max diff block lines reached; 21034/26303 bytes (79.97%) of diff not shown.
58.6 KB
./usr/share/doc/ssg-nondebian/ssg-ol9-guide-ccn_basic.html
    
Offset 37407, 146 lines modifiedOffset 37407, 146 lines modified
000921e0:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#000921e0:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
000921f0:·6964·6d32·3038·3237·2220·7461·6269·6e64··idm20827"·tabind000921f0:·6964·6d32·3038·3237·2220·7461·6269·6e64··idm20827"·tabind
00092200:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but00092200:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
00092210:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand00092210:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
00092220:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title00092220:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
00092230:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re00092230:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
00092240:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">00092240:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
00092250:·5265·6d65·6469·6174·696f·6e20·416e·6163··Remediation·Anac00092250:·5265·6d65·6469·6174·696f·6e20·4f53·4275··Remediation·OSBu
00092260:·6f6e·6461·2073·6e69·7070·6574·20e2·87b2··onda·snippet·... 
00092270:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla 
00092280:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap00092260:·696c·6420·426c·7565·7072·696e·7420·736e··ild·Blueprint·sn
 00092270:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br
 00092280:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
00092290:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=00092290:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
 000922a0:·6170·7365·2220·6964·3d22·6964·6d32·3038··apse"·id="idm208
 000922b0:·3237·223e·3c70·7265·3e3c·636f·6465·3e0a··27"><pre><code>.
 000922c0:·5b5b·7061·636b·6167·6573·5d5d·0a6e·616d··[[packages]].nam
 000922d0:·6520·3d20·2266·6972·6577·616c·6c64·220a··e·=·"firewalld".
 000922e0:·7665·7273·696f·6e20·3d20·222a·220a·3c2f··version·=·"*".</
000922a0:·2269·646d·3230·3832·3722·3e3c·7461·626c··"idm20827"><tabl 
000922b0:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t 
000922c0:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab 
000922d0:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl 
000922e0:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr 
000922f0:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity: 
00092300:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td 
00092310:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di 
00092320:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t 
00092330:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr>< 
00092340:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</ 
00092350:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td 
00092360:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St 
00092370:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td> 
00092380:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr> 
00092390:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co 
000923a0:·6465·3e0a·7061·636b·6167·6520·2d2d·6164··de>.package·--ad 
000923b0:·643d·6669·7265·7761·6c6c·640a·3c2f·636f··d=firewalld.</co 
000923c0:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div><000922f0:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div
000923d0:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn00092300:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b
000923e0:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t00092310:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data
000923f0:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse"00092320:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps
00092400:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i00092330:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
00092410:·646d·3230·3832·3822·2074·6162·696e·6465··dm20828"·tabinde00092340:·2369·646d·3230·3832·3822·2074·6162·696e··#idm20828"·tabin
00092420:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt00092350:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
00092430:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande00092360:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
00092440:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=00092370:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
00092450:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev00092380:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
00092460:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R00092390:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
00092470:·656d·6564·6961·7469·6f6e·204f·5342·7569··emediation·OSBui000923a0:·3e52·656d·6564·6961·7469·6f6e·2050·7570··>Remediation·Pup
00092480:·6c64·2042·6c75·6570·7269·6e74·2073·6e69··ld·Blueprint·sni 
00092490:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br> 
000924a0:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane 
000924b0:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla 
000924c0:·7073·6522·2069·643d·2269·646d·3230·3832··pse"·id="idm2082 
000924d0:·3822·3e3c·7072·653e·3c63·6f64·653e·0a5b··8"><pre><code>.[ 
000924e0:·5b70·6163·6b61·6765·735d·5d0a·6e61·6d65··[packages]].name000923b0:·7065·7420·736e·6970·7065·7420·e287·b23c··pet·snippet·...<
 000923c0:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas
 000923d0:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps
 000923e0:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="
 000923f0:·6964·6d32·3038·3238·223e·3c74·6162·6c65··idm20828"><table
 00092400:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta
 00092410:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl
 00092420:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table
 00092430:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>
 00092440:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<
 00092450:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
 00092460:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis
 00092470:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td
 00092480:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
 00092490:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t
 000924a0:·683e·3c74·643e·6661·6c73·653c·2f74·643e··h><td>false</td>
 000924b0:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str
 000924c0:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e
 000924d0:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr><
 000924e0:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod
 000924f0:·653e·696e·636c·7564·6520·696e·7374·616c··e>include·instal
 00092500:·6c5f·6669·7265·7761·6c6c·640a·0a63·6c61··l_firewalld..cla
 00092510:·7373·2069·6e73·7461·6c6c·5f66·6972·6577··ss·install_firew
 00092520:·616c·6c64·207b·0a20·2070·6163·6b61·6765··alld·{.··package
000924f0:·203d·2022·6669·7265·7761·6c6c·6422·0a76···=·"firewalld".v00092530:·207b·2027·6669·7265·7761·6c6c·6427·3a0a···{·'firewalld':.
00092500:·6572·7369·6f6e·203d·2022·2a22·0a3c·2f63··ersion·=·"*".</c 
00092510:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div> 
00092520:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt 
00092530:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data- 
00092540:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse00092540:·2020·2020·656e·7375·7265·203d·2667·743b······ensure·=&gt;
 00092550:·2027·696e·7374·616c·6c65·6427·2c0a·2020···'installed',.··
 00092560:·7d0a·7d0a·3c2f·636f·6465·3e3c·2f70·7265··}.}.</code></pre
 00092570:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class=
 00092580:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success
00092550:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#00092590:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c
00092560:·6964·6d32·3038·3239·2220·7461·6269·6e64··idm20829"·tabind 
00092570:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but 
00092580:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand 
00092590:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title 
000925a0:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re 
000925b0:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!"> 
000925c0:·5265·6d65·6469·6174·696f·6e20·5075·7070··Remediation·Pupp 
000925d0:·6574·2073·6e69·7070·6574·20e2·87b2·3c2f··et·snippet·...</ 
000925e0:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class 
000925f0:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse 
00092600:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i 
00092610:·646d·3230·3832·3922·3e3c·7461·626c·6520··dm20829"><table· 
00092620:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab 
00092630:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table 
00092640:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table- 
00092650:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr>< 
00092660:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</000925a0:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta
 000925b0:·7267·6574·3d22·2369·646d·3230·3832·3922··rget="#idm20829"
 000925c0:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro
 000925d0:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria
 000925e0:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false
 000925f0:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat
 00092600:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre
 00092610:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati
 00092620:·6f6e·2053·6865·6c6c·2073·6372·6970·7420··on·Shell·script·
 00092630:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·
 00092640:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col
 00092650:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·
 00092660:·6964·3d22·6964·6d32·3038·3239·223e·3c74··id="idm20829"><t
 00092670:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl
 00092680:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·
 00092690:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t
 000926a0:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">
 000926b0:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi
 000926c0:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<
 000926d0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 000926e0:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th
Max diff block lines reached; 34692/53488 bytes (64.86%) of diff not shown.
6.2 KB
html2text {}
    
Offset 6113, 21 lines modifiedOffset 6113, 14 lines modified
6113 ··-·PCI-DSSv4-1.2.16113 ··-·PCI-DSSv4-1.2.1
6114 ··-·enable_strategy6114 ··-·enable_strategy
6115 ··-·low_complexity6115 ··-·low_complexity
6116 ··-·low_disruption6116 ··-·low_disruption
6117 ··-·medium_severity6117 ··-·medium_severity
6118 ··-·no_reboot_needed6118 ··-·no_reboot_needed
6119 ··-·package_firewalld_installed6119 ··-·package_firewalld_installed
6120 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
6121 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
6122 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
6123 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
6124 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
6125 package·--add=firewalld 
6126 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x86120 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
6127 [[packages]]6121 [[packages]]
6128 name·=·"firewalld"6122 name·=·"firewalld"
6129 version·=·"*"6123 version·=·"*"
6130 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x86124 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
6131 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low6125 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 6152, 14 lines modifiedOffset 6145, 21 lines modified
6152 if·!·rpm·-q·--quiet·"firewalld"·;·then6145 if·!·rpm·-q·--quiet·"firewalld"·;·then
6153 ····yum·install·-y·"firewalld"6146 ····yum·install·-y·"firewalld"
6154 fi6147 fi
  
6155 else6148 else
6156 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'6149 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
6157 fi6150 fi
 6151 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 6152 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 6153 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 6154 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 6155 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 6156 package·--add=firewalld
6158 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·f\x8fi\x8ir\x8re\x8ew\x8wa\x8al\x8ll\x8ld\x8d·E\x8En\x8na\x8ab\x8bl\x8le\x8ed\x8d·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*6157 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·f\x8fi\x8ir\x8re\x8ew\x8wa\x8al\x8ll\x8ld\x8d·E\x8En\x8na\x8ab\x8bl\x8le\x8ed\x8d·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
6159 The·firewalld·service·can·be·enabled·with·the·following·command:6158 The·firewalld·service·can·be·enabled·with·the·following·command:
6160 $·sudo·systemctl·enable·firewalld.service6159 $·sudo·systemctl·enable·firewalld.service
6161 ············Access·control·methods·provide·the·ability·to·enhance·system·security·posture·by6160 ············Access·control·methods·provide·the·ability·to·enhance·system·security·posture·by
6162 Rationale:··restricting·services·and·known·good·IP·addresses·and·address·ranges.·This·prevents6161 Rationale:··restricting·services·and·known·good·IP·addresses·and·address·ranges.·This·prevents
6163 ············connections·from·unknown·hosts·and·protocols.6162 ············connections·from·unknown·hosts·and·protocols.
6164 Severity: ··medium6163 Severity: ··medium
Offset 12253, 48 lines modifiedOffset 12253, 41 lines modified
12253 ··-·NIST-800-53-IA-312253 ··-·NIST-800-53-IA-3
12254 ··-·enable_strategy12254 ··-·enable_strategy
12255 ··-·low_complexity12255 ··-·low_complexity
12256 ··-·low_disruption12256 ··-·low_disruption
12257 ··-·medium_severity12257 ··-·medium_severity
12258 ··-·no_reboot_needed12258 ··-·no_reboot_needed
12259 ··-·package_usbguard_installed12259 ··-·package_usbguard_installed
12260 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
12261 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
12262 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
12263 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
12264 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
12265 package·--add=usbguard 
12266 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x812260 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
12267 [[packages]]12261 [[packages]]
12268 name·=·"usbguard"12262 name·=·"usbguard"
12269 version·=·"*"12263 version·=·"*"
12270 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
12271 --- 
12272 apiVersion:·machineconfiguration.openshift.io/v1 
12273 kind:·MachineConfig 
12274 spec: 
12275 ··config: 
12276 ····ignition: 
12277 ······version:·3.1.0 
12278 ··extensions: 
12279 ····-·usbguard 
12280 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x812264 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
12281 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low12265 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
12282 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low12266 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
12283 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false12267 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
12284 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable12268 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
12285 include·install_usbguard12269 include·install_usbguard
  
12286 class·install_usbguard·{12270 class·install_usbguard·{
12287 ··package·{·'usbguard':12271 ··package·{·'usbguard':
12288 ····ensure·=>·'installed',12272 ····ensure·=>·'installed',
12289 ··}12273 ··}
12290 }12274 }
 12275 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 12276 ---
 12277 apiVersion:·machineconfiguration.openshift.io/v1
 12278 kind:·MachineConfig
 12279 spec:
 12280 ··config:
 12281 ····ignition:
 12282 ······version:·3.1.0
 12283 ··extensions:
 12284 ····-·usbguard
12291 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x812285 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
12292 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low12286 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
12293 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low12287 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
12294 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false12288 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
12295 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable12289 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
12296 #·Remediation·is·applicable·only·in·certain·platforms12290 #·Remediation·is·applicable·only·in·certain·platforms
12297 if·(·!·(·grep·-sqE·"^.*\.s390x$"·/proc/sys/kernel/osrelease·||·grep·-sqE·"^s390x$"·/proc/sys/kernel/12291 if·(·!·(·grep·-sqE·"^.*\.s390x$"·/proc/sys/kernel/osrelease·||·grep·-sqE·"^s390x$"·/proc/sys/kernel/
Offset 12303, 14 lines modifiedOffset 12296, 21 lines modified
12303 if·!·rpm·-q·--quiet·"usbguard"·;·then12296 if·!·rpm·-q·--quiet·"usbguard"·;·then
12304 ····yum·install·-y·"usbguard"12297 ····yum·install·-y·"usbguard"
12305 fi12298 fi
  
12306 else12299 else
12307 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'12300 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
12308 fi12301 fi
 12302 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 12303 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 12304 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 12305 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 12306 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 12307 package·--add=usbguard
12309 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·t\x8th\x8he\x8e·U\x8US\x8SB\x8BG\x8Gu\x8ua\x8ar\x8rd\x8d·S\x8Se\x8er\x8rv\x8vi\x8ic\x8ce\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*12308 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·t\x8th\x8he\x8e·U\x8US\x8SB\x8BG\x8Gu\x8ua\x8ar\x8rd\x8d·S\x8Se\x8er\x8rv\x8vi\x8ic\x8ce\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
12310 The·USBGuard·service·should·be·enabled.·The·usbguard·service·can·be·enabled·with·the·following12309 The·USBGuard·service·should·be·enabled.·The·usbguard·service·can·be·enabled·with·the·following
12311 command:12310 command:
12312 $·sudo·systemctl·enable·usbguard.service12311 $·sudo·systemctl·enable·usbguard.service
12313 Rationale:··The·usbguard·service·must·be·running·in·order·to·enforce·the·USB·device·authorization12312 Rationale:··The·usbguard·service·must·be·running·in·order·to·enforce·the·USB·device·authorization
12314 ············policy·for·all·USB·devices.12313 ············policy·for·all·USB·devices.
12315 Severity: ··medium12314 Severity: ··medium
Offset 12366, 14 lines modifiedOffset 12366, 27 lines modified
12366 ··-·medium_severity12366 ··-·medium_severity
12367 ··-·no_reboot_needed12367 ··-·no_reboot_needed
Max diff block lines reached; 1746/6328 bytes (27.59%) of diff not shown.
242 KB
./usr/share/doc/ssg-nondebian/ssg-ol9-guide-ccn_intermediate.html
    
Offset 43249, 146 lines modifiedOffset 43249, 146 lines modified
000a8f00:·7461·7267·6574·3d22·2369·646d·3230·3832··target="#idm2082000a8f00:·7461·7267·6574·3d22·2369·646d·3230·3832··target="#idm2082
000a8f10:·3722·2074·6162·696e·6465·783d·2230·2220··7"·tabindex="0"·000a8f10:·3722·2074·6162·696e·6465·783d·2230·2220··7"·tabindex="0"·
000a8f20:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar000a8f20:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar
000a8f30:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal000a8f30:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal
000a8f40:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ000a8f40:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ
000a8f50:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h000a8f50:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h
000a8f60:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia000a8f60:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia
 000a8f70:·7469·6f6e·204f·5342·7569·6c64·2042·6c75··tion·OSBuild·Blu
 000a8f80:·6570·7269·6e74·2073·6e69·7070·6574·20e2··eprint·snippet·.
 000a8f90:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c
 000a8fa0:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
 000a8fb0:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
 000a8fc0:·643d·2269·646d·3230·3832·3722·3e3c·7072··d="idm20827"><pr
 000a8fd0:·653e·3c63·6f64·653e·0a5b·5b70·6163·6b61··e><code>.[[packa
 000a8fe0:·6765·735d·5d0a·6e61·6d65·203d·2022·6669··ges]].name·=·"fi
 000a8ff0:·7265·7761·6c6c·6422·0a76·6572·7369·6f6e··rewalld".version
 000a9000:·203d·2022·2a22·0a3c·2f63·6f64·653e·3c2f···=·"*".</code></
000a8f70:·7469·6f6e·2041·6e61·636f·6e64·6120·736e··tion·Anaconda·sn 
000a8f80:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br 
000a8f90:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan 
000a8fa0:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll 
000a8fb0:·6170·7365·2220·6964·3d22·6964·6d32·3038··apse"·id="idm208 
000a8fc0:·3237·223e·3c74·6162·6c65·2063·6c61·7373··27"><table·class 
000a8fd0:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st 
000a8fe0:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord 
000a8ff0:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde 
000a9000:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co 
000a9010:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t 
000a9020:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr>< 
000a9030:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio 
000a9040:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</ 
000a9050:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
000a9060:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td> 
000a9070:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr>< 
000a9080:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy: 
000a9090:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable< 
000a90a0:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table 
000a90b0:·3e3c·7072·653e·3c63·6f64·653e·0a70·6163··><pre><code>.pac 
000a90c0:·6b61·6765·202d·2d61·6464·3d66·6972·6577··kage·--add=firew 
000a90d0:·616c·6c64·0a3c·2f63·6f64·653e·3c2f·7072··alld.</code></pr 
000a90e0:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class000a9010:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla
000a90f0:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes000a9020:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ
000a9100:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle="000a9030:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle
000a9110:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t000a9040:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data
000a9120:·6172·6765·743d·2223·6964·6d32·3038·3238··arget="#idm20828000a9050:·2d74·6172·6765·743d·2223·6964·6d32·3038··-target="#idm208
000a9130:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r000a9060:·3238·2220·7461·6269·6e64·6578·3d22·3022··28"·tabindex="0"
000a9140:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari000a9070:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
000a9150:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals000a9080:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
000a9160:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa000a9090:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
000a9170:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr000a90a0:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
000a9180:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat000a90b0:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
 000a90c0:·6174·696f·6e20·5075·7070·6574·2073·6e69··ation·Puppet·sni
 000a90d0:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>
 000a90e0:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
 000a90f0:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
 000a9100:·7073·6522·2069·643d·2269·646d·3230·3832··pse"·id="idm2082
 000a9110:·3822·3e3c·7461·626c·6520·636c·6173·733d··8"><table·class=
 000a9120:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str
 000a9130:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde
000a9190:·696f·6e20·4f53·4275·696c·6420·426c·7565··ion·OSBuild·Blue 
000a91a0:·7072·696e·7420·736e·6970·7065·7420·e287··print·snippet·.. 
000a91b0:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl 
000a91c0:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla 
000a91d0:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id 
000a91e0:·3d22·6964·6d32·3038·3238·223e·3c70·7265··="idm20828"><pre 
000a91f0:·3e3c·636f·6465·3e0a·5b5b·7061·636b·6167··><code>.[[packag 
000a9200:·6573·5d5d·0a6e·616d·6520·3d20·2266·6972··es]].name·=·"fir 
000a9210:·6577·616c·6c64·220a·7665·7273·696f·6e20··ewalld".version· 
000a9220:·3d20·222a·220a·3c2f·636f·6465·3e3c·2f70··=·"*".</code></p 
000a9230:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas 
000a9240:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe 
000a9250:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle= 
000a9260:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data- 
000a9270:·7461·7267·6574·3d22·2369·646d·3230·3832··target="#idm2082 
000a9280:·3922·2074·6162·696e·6465·783d·2230·2220··9"·tabindex="0"· 
000a9290:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar 
000a92a0:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal 
000a92b0:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ 
000a92c0:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h 
000a92d0:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia 
000a92e0:·7469·6f6e·2050·7570·7065·7420·736e·6970··tion·Puppet·snip 
000a92f0:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br>< 
000a9300:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel 
000a9310:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap 
000a9320:·7365·2220·6964·3d22·6964·6d32·3038·3239··se"·id="idm20829 
000a9330:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class=" 
000a9340:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri 
000a9350:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border000a9140:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden
000a9360:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens 
000a9370:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp 
000a9380:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>000a9150:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com
 000a9160:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td
 000a9170:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
 000a9180:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption
 000a9190:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
 000a91a0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e52··d></tr><tr><th>R
 000a91b0:·6562·6f6f·743a·3c2f·7468·3e3c·7464·3e66··eboot:</th><td>f
 000a91c0:·616c·7365·3c2f·7464·3e3c·2f74·723e·3c74··alse</td></tr><t
 000a91d0:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<
 000a91e0:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</
 000a91f0:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table>
 000a9200:·3c70·7265·3e3c·636f·6465·3e69·6e63·6c75··<pre><code>inclu
 000a9210:·6465·2069·6e73·7461·6c6c·5f66·6972·6577··de·install_firew
 000a9220:·616c·6c64·0a0a·636c·6173·7320·696e·7374··alld..class·inst
 000a9230:·616c·6c5f·6669·7265·7761·6c6c·6420·7b0a··all_firewalld·{.
 000a9240:·2020·7061·636b·6167·6520·7b20·2766·6972····package·{·'fir
 000a9250:·6577·616c·6c64·273a·0a20·2020·2065·6e73··ewalld':.····ens
 000a9260:·7572·6520·3d26·6774·3b20·2769·6e73·7461··ure·=&gt;·'insta
 000a9270:·6c6c·6564·272c·0a20·207d·0a7d·0a3c·2f63··lled',.··}.}.</c
 000a9280:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div>
 000a9290:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt
 000a92a0:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data-
 000a92b0:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse
 000a92c0:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
 000a92d0:·6964·6d32·3038·3239·2220·7461·6269·6e64··idm20829"·tabind
 000a92e0:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
 000a92f0:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
 000a9300:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
 000a9310:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
 000a9320:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
 000a9330:·5265·6d65·6469·6174·696f·6e20·5368·656c··Remediation·Shel
 000a9340:·6c20·7363·7269·7074·20e2·87b2·3c2f·613e··l·script·...</a>
 000a9350:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="
 000a9360:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c
 000a9370:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm
 000a9380:·3230·3832·3922·3e3c·7461·626c·6520·636c··20829"><table·cl
 000a9390:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table
Max diff block lines reached; 204298/223094 bytes (91.57%) of diff not shown.
23.9 KB
html2text {}
    
Offset 7484, 21 lines modifiedOffset 7484, 14 lines modified
7484 ··-·PCI-DSSv4-1.2.17484 ··-·PCI-DSSv4-1.2.1
7485 ··-·enable_strategy7485 ··-·enable_strategy
7486 ··-·low_complexity7486 ··-·low_complexity
7487 ··-·low_disruption7487 ··-·low_disruption
7488 ··-·medium_severity7488 ··-·medium_severity
7489 ··-·no_reboot_needed7489 ··-·no_reboot_needed
7490 ··-·package_firewalld_installed7490 ··-·package_firewalld_installed
7491 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
7492 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
7493 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
7494 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
7495 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
7496 package·--add=firewalld 
7497 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x87491 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
7498 [[packages]]7492 [[packages]]
7499 name·=·"firewalld"7493 name·=·"firewalld"
7500 version·=·"*"7494 version·=·"*"
7501 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x87495 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
7502 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low7496 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 7523, 14 lines modifiedOffset 7516, 21 lines modified
7523 if·!·rpm·-q·--quiet·"firewalld"·;·then7516 if·!·rpm·-q·--quiet·"firewalld"·;·then
7524 ····yum·install·-y·"firewalld"7517 ····yum·install·-y·"firewalld"
7525 fi7518 fi
  
7526 else7519 else
7527 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'7520 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
7528 fi7521 fi
 7522 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 7523 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 7524 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 7525 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 7526 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 7527 package·--add=firewalld
7529 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·f\x8fi\x8ir\x8re\x8ew\x8wa\x8al\x8ll\x8ld\x8d·E\x8En\x8na\x8ab\x8bl\x8le\x8ed\x8d·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*7528 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·f\x8fi\x8ir\x8re\x8ew\x8wa\x8al\x8ll\x8ld\x8d·E\x8En\x8na\x8ab\x8bl\x8le\x8ed\x8d·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
7530 The·firewalld·service·can·be·enabled·with·the·following·command:7529 The·firewalld·service·can·be·enabled·with·the·following·command:
7531 $·sudo·systemctl·enable·firewalld.service7530 $·sudo·systemctl·enable·firewalld.service
7532 ············Access·control·methods·provide·the·ability·to·enhance·system·security·posture·by·restricting7531 ············Access·control·methods·provide·the·ability·to·enhance·system·security·posture·by·restricting
7533 Rationale:··services·and·known·good·IP·addresses·and·address·ranges.·This·prevents·connections·from·unknown7532 Rationale:··services·and·known·good·IP·addresses·and·address·ranges.·This·prevents·connections·from·unknown
7534 ············hosts·and·protocols.7533 ············hosts·and·protocols.
7535 Severity: ··medium7534 Severity: ··medium
Offset 13250, 21 lines modifiedOffset 13250, 14 lines modified
13250 ··-·PCI-DSSv4-1.2.613250 ··-·PCI-DSSv4-1.2.6
13251 ··-·enable_strategy13251 ··-·enable_strategy
13252 ··-·high_severity13252 ··-·high_severity
13253 ··-·low_complexity13253 ··-·low_complexity
13254 ··-·low_disruption13254 ··-·low_disruption
13255 ··-·no_reboot_needed13255 ··-·no_reboot_needed
13256 ··-·package_libselinux_installed13256 ··-·package_libselinux_installed
13257 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
13258 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
13259 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
13260 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
13261 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
13262 package·--add=libselinux 
13263 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x813257 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
13264 [[packages]]13258 [[packages]]
13265 name·=·"libselinux"13259 name·=·"libselinux"
13266 version·=·"*"13260 version·=·"*"
13267 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x813261 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
13268 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low13262 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 13289, 14 lines modifiedOffset 13282, 21 lines modified
13289 if·!·rpm·-q·--quiet·"libselinux"·;·then13282 if·!·rpm·-q·--quiet·"libselinux"·;·then
13290 ····yum·install·-y·"libselinux"13283 ····yum·install·-y·"libselinux"
13291 fi13284 fi
  
13292 else13285 else
13293 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'13286 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
13294 fi13287 fi
 13288 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 13289 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 13290 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 13291 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 13292 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 13293 package·--add=libselinux
13295 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·S\x8SE\x8EL\x8Li\x8in\x8nu\x8ux\x8x·N\x8No\x8ot\x8t·D\x8Di\x8is\x8sa\x8ab\x8bl\x8le\x8ed\x8d·i\x8in\x8n·/\x8/e\x8et\x8tc\x8c/\x8/d\x8de\x8ef\x8fa\x8au\x8ul\x8lt\x8t/\x8/g\x8gr\x8ru\x8ub\x8b·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*13294 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·S\x8SE\x8EL\x8Li\x8in\x8nu\x8ux\x8x·N\x8No\x8ot\x8t·D\x8Di\x8is\x8sa\x8ab\x8bl\x8le\x8ed\x8d·i\x8in\x8n·/\x8/e\x8et\x8tc\x8c/\x8/d\x8de\x8ef\x8fa\x8au\x8ul\x8lt\x8t/\x8/g\x8gr\x8ru\x8ub\x8b·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
13296 SELinux·can·be·disabled·at·boot·time·by·an·argument·in·/etc/default/grub.·Remove·any·instances·of13295 SELinux·can·be·disabled·at·boot·time·by·an·argument·in·/etc/default/grub.·Remove·any·instances·of
13297 selinux=0·from·the·kernel·arguments·in·that·file·to·prevent·SELinux·from·being·disabled·at·boot.13296 selinux=0·from·the·kernel·arguments·in·that·file·to·prevent·SELinux·from·being·disabled·at·boot.
13298 ············Disabling·a·major·host·protection·feature,·such·as·SELinux,·at·boot·time·prevents·it·from13297 ············Disabling·a·major·host·protection·feature,·such·as·SELinux,·at·boot·time·prevents·it·from
13299 Rationale:··confining·system·services·at·boot·time.·Further,·it·increases·the·chances·that·it·will·remain13298 Rationale:··confining·system·services·at·boot·time.·Further,·it·increases·the·chances·that·it·will·remain
13300 ············off·during·system·operation.13299 ············off·during·system·operation.
13301 Severity: ··medium13300 Severity: ··medium
Offset 13845, 21 lines modifiedOffset 13845, 14 lines modified
13845 ··-·NIST-800-53-CM-7(b)13845 ··-·NIST-800-53-CM-7(b)
13846 ··-·disable_strategy13846 ··-·disable_strategy
13847 ··-·low_complexity13847 ··-·low_complexity
13848 ··-·low_disruption13848 ··-·low_disruption
13849 ··-·low_severity13849 ··-·low_severity
13850 ··-·no_reboot_needed13850 ··-·no_reboot_needed
13851 ··-·package_bind_removed13851 ··-·package_bind_removed
13852 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
13853 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
13854 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
13855 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
13856 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable 
  
13857 package·--remove=bind 
13858 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x813852 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
13859 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low13853 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
13860 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low13854 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
13861 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false13855 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
13862 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable13856 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
13863 include·remove_bind13857 include·remove_bind
  
Offset 13879, 14 lines modifiedOffset 13872, 21 lines modified
13879 #»      ···that·depend·on·bind.·Execute·this13872 #»      ···that·depend·on·bind.·Execute·this
13880 #»      ···remediation·AFTER·testing·on·a·non-production13873 #»      ···remediation·AFTER·testing·on·a·non-production
13881 #»      ···system!13874 #»      ···system!
  
13882 if·rpm·-q·--quiet·"bind"·;·then13875 if·rpm·-q·--quiet·"bind"·;·then
13883 yum·remove·-y·"bind"13876 yum·remove·-y·"bind"
13884 fi13877 fi
 13878 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 13879 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 13880 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 13881 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 13882 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
  
 13883 package·--remove=bind
13885 Group  ·FTP·Server·  Group·contains·1·group·and·1·rule13884 Group  ·FTP·Server·  Group·contains·1·group·and·1·rule
13886 _\x8[_\x8r_\x8e_\x8f_\x8]  ·FTP·is·a·common·method·for·allowing·remote·access·to·files.·Like·telnet,·the·FTP·protocol·is13885 _\x8[_\x8r_\x8e_\x8f_\x8]  ·FTP·is·a·common·method·for·allowing·remote·access·to·files.·Like·telnet,·the·FTP·protocol·is
13887 unencrypted,·which·means·that·passwords·and·other·data·transmitted·during·the·session·can·be·captured·and13886 unencrypted,·which·means·that·passwords·and·other·data·transmitted·during·the·session·can·be·captured·and
Max diff block lines reached; 19316/24446 bytes (79.01%) of diff not shown.
440 KB
./usr/share/doc/ssg-nondebian/ssg-ol9-guide-cui.html
    
Offset 15948, 137 lines modifiedOffset 15948, 137 lines modified
0003e4b0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=0003e4b0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
0003e4c0:·2223·6964·6d36·3936·3522·2074·6162·696e··"#idm6965"·tabin0003e4c0:·2223·6964·6d36·3936·3522·2074·6162·696e··"#idm6965"·tabin
0003e4d0:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu0003e4d0:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
0003e4e0:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan0003e4e0:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
0003e4f0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl0003e4f0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
0003e500:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r0003e500:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
0003e510:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"0003e510:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
0003e520:·3e52·656d·6564·6961·7469·6f6e·2041·6e61··>Remediation·Ana0003e520:·3e52·656d·6564·6961·7469·6f6e·204f·5342··>Remediation·OSB
0003e530:·636f·6e64·6120·736e·6970·7065·7420·e287··conda·snippet·.. 
0003e540:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl 
0003e550:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla0003e530:·7569·6c64·2042·6c75·6570·7269·6e74·2073··uild·Blueprint·s
 0003e540:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b
 0003e550:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
0003e560:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id0003e560:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
0003e570:·3d22·6964·6d36·3936·3522·3e3c·7461·626c··="idm6965"><tabl 
0003e580:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t 
0003e590:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab 
0003e5a0:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl 
0003e5b0:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr 
0003e5c0:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:0003e570:·6c61·7073·6522·2069·643d·2269·646d·3639··lapse"·id="idm69
 0003e580:·3635·223e·3c70·7265·3e3c·636f·6465·3e0a··65"><pre><code>.
 0003e590:·5b5b·7061·636b·6167·6573·5d5d·0a6e·616d··[[packages]].nam
 0003e5a0:·6520·3d20·2263·7279·7074·6f2d·706f·6c69··e·=·"crypto-poli
 0003e5b0:·6369·6573·220a·7665·7273·696f·6e20·3d20··cies".version·=·
 0003e5c0:·222a·220a·3c2f·636f·6465·3e3c·2f70·7265··"*".</code></pre
 0003e5d0:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class=
 0003e5e0:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success
 0003e5f0:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c
 0003e600:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta
 0003e610:·7267·6574·3d22·2369·646d·3639·3636·2220··rget="#idm6966"·
 0003e620:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol
 0003e630:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-
 0003e640:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"
 0003e650:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate
 0003e660:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href
 0003e670:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio
 0003e680:·6e20·5075·7070·6574·2073·6e69·7070·6574··n·Puppet·snippet
 0003e690:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
 0003e6a0:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
 0003e6b0:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
 0003e6c0:·2069·643d·2269·646d·3639·3636·223e·3c74···id="idm6966"><t
 0003e6d0:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl
 0003e6e0:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·
 0003e6f0:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t
 0003e700:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">
 0003e710:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi
 0003e720:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<
 0003e730:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 0003e740:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th
 0003e750:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
 0003e760:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot
 0003e770:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false<
 0003e780:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 0003e790:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><
 0003e7a0:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></
 0003e7b0:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>
 0003e7c0:·3c63·6f64·653e·696e·636c·7564·6520·696e··<code>include·in
 0003e7d0:·7374·616c·6c5f·6372·7970·746f·2d70·6f6c··stall_crypto-pol
 0003e7e0:·6963·6965·730a·0a63·6c61·7373·2069·6e73··icies..class·ins
 0003e7f0:·7461·6c6c·5f63·7279·7074·6f2d·706f·6c69··tall_crypto-poli
 0003e800:·6369·6573·207b·0a20·2070·6163·6b61·6765··cies·{.··package
 0003e810:·207b·2027·6372·7970·746f·2d70·6f6c·6963···{·'crypto-polic
 0003e820:·6965·7327·3a0a·2020·2020·656e·7375·7265··ies':.····ensure
 0003e830:·203d·2667·743b·2027·696e·7374·616c·6c65···=&gt;·'installe
 0003e840:·6427·2c0a·2020·7d0a·7d0a·3c2f·636f·6465··d',.··}.}.</code
 0003e850:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a·
 0003e860:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s
 0003e870:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog
 0003e880:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d
 0003e890:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
 0003e8a0:·3639·3637·2220·7461·6269·6e64·6578·3d22··6967"·tabindex="
 0003e8b0:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
 0003e8c0:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
 0003e8d0:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
 0003e8e0:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
 0003e8f0:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
 0003e900:·6469·6174·696f·6e20·5368·656c·6c20·7363··diation·Shell·sc
 0003e910:·7269·7074·20e2·87b2·3c2f·613e·3c62·723e··ript·...</a><br>
 0003e920:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
 0003e930:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
 0003e940:·7073·6522·2069·643d·2269·646d·3639·3637··pse"·id="idm6967
 0003e950:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="
 0003e960:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri
 0003e970:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border
 0003e980:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens
 0003e990:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp
 0003e9a0:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>
 0003e9b0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
 0003e9c0:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:
0003e5d0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td0003e9d0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
0003e5e0:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di0003e9e0:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re
0003e5f0:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t0003e9f0:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa
0003e600:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><0003ea00:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr
0003e610:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</0003ea10:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</
0003e620:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td0003ea20:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t
 0003ea30:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><
 0003ea40:·7072·653e·3c63·6f64·653e·0a69·6620·2120··pre><code>.if·!·
 0003ea50:·7270·6d20·2d71·202d·2d71·7569·6574·2022··rpm·-q·--quiet·"
0003e630:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St 
0003e640:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td> 
0003e650:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr> 
0003e660:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co 
0003e670:·6465·3e0a·7061·636b·6167·6520·2d2d·6164··de>.package·--ad 
0003e680:·643d·6372·7970·746f·2d70·6f6c·6963·6965··d=crypto-policie0003ea60:·6372·7970·746f·2d70·6f6c·6963·6965·7322··crypto-policies"
 0003ea70:·203b·2074·6865·6e0a·2020·2020·7975·6d20···;·then.····yum·
 0003ea80:·696e·7374·616c·6c20·2d79·2022·6372·7970··install·-y·"cryp
 0003ea90:·746f·2d70·6f6c·6963·6965·7322·0a66·690a··to-policies".fi.
0003e690:·730a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··s.</code></pre><0003eaa0:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d
0003e6a0:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b0003eab0:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn
0003e6b0:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"·0003eac0:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da
0003e6c0:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col0003ead0:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla
0003e6d0:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ0003eae0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
0003e6e0:·6574·3d22·2369·646d·3639·3636·2220·7461··et="#idm6966"·ta0003eaf0:·3d22·2369·646d·3639·3638·2220·7461·6269··="#idm6968"·tabi
0003e6f0:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=0003eb00:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
0003e700:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex0003eb10:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
0003e710:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t0003eb20:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
0003e720:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t0003eb30:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
0003e730:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="0003eb40:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
0003e740:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·0003eb50:·223e·5265·6d65·6469·6174·696f·6e20·416e··">Remediation·An
 0003eb60:·6163·6f6e·6461·2073·6e69·7070·6574·20e2··aconda·snippet·.
 0003eb70:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c
 0003eb80:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
 0003eb90:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
 0003eba0:·643d·2269·646d·3639·3638·223e·3c74·6162··d="idm6968"><tab
 0003ebb0:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·
 0003ebc0:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta
 0003ebd0:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab
Max diff block lines reached; 389136/406690 bytes (95.68%) of diff not shown.
43.2 KB
html2text {}
    
Offset 275, 21 lines modifiedOffset 275, 14 lines modified
275 ··tags:275 ··tags:
276 ··-·enable_strategy276 ··-·enable_strategy
277 ··-·low_complexity277 ··-·low_complexity
278 ··-·low_disruption278 ··-·low_disruption
279 ··-·medium_severity279 ··-·medium_severity
280 ··-·no_reboot_needed280 ··-·no_reboot_needed
281 ··-·package_crypto-policies_installed281 ··-·package_crypto-policies_installed
282 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
283 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
284 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
285 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
286 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
287 package·--add=crypto-policies 
288 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8282 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
289 [[packages]]283 [[packages]]
290 name·=·"crypto-policies"284 name·=·"crypto-policies"
291 version·=·"*"285 version·=·"*"
292 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8286 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
293 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low287 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 308, 14 lines modifiedOffset 301, 21 lines modified
308 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low301 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
309 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false302 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
310 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable303 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
311 if·!·rpm·-q·--quiet·"crypto-policies"·;·then304 if·!·rpm·-q·--quiet·"crypto-policies"·;·then
312 ····yum·install·-y·"crypto-policies"305 ····yum·install·-y·"crypto-policies"
313 fi306 fi
 307 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 308 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 309 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 310 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 311 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 312 package·--add=crypto-policies
314 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8og\x8gr\x8ra\x8ap\x8ph\x8hy\x8y·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*313 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8og\x8gr\x8ra\x8ap\x8ph\x8hy\x8y·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
315 To·configure·the·system·cryptography·policy·to·use·ciphers·only·from·the·FIPS:OSPP·policy,·run·the·following·command:314 To·configure·the·system·cryptography·policy·to·use·ciphers·only·from·the·FIPS:OSPP·policy,·run·the·following·command:
316 $·sudo·update-crypto-policies·--set·FIPS:OSPP315 $·sudo·update-crypto-policies·--set·FIPS:OSPP
317 The·rule·checks·if·settings·for·selected·crypto·policy·are·configured·as·expected.·Configuration·files·in·the·/etc/crypto-policies/back-ends·are·either·symlinks·to·correct·files·provided·by·Crypto-policies·package·or·they·are·regular·files·in·case·crypto·policy·customizations·are·applied.·Crypto·policies·may·be·customized·by·crypto·policy·modules,·in·which·case·it·is·delimited·from·the·base·policy·using·a·colon.316 The·rule·checks·if·settings·for·selected·crypto·policy·are·configured·as·expected.·Configuration·files·in·the·/etc/crypto-policies/back-ends·are·either·symlinks·to·correct·files·provided·by·Crypto-policies·package·or·they·are·regular·files·in·case·crypto·policy·customizations·are·applied.·Crypto·policies·may·be·customized·by·crypto·policy·modules,·in·which·case·it·is·delimited·from·the·base·policy·using·a·colon.
318 Warning: ·The·system·needs·to·be·rebooted·for·these·changes·to·take·effect.317 Warning: ·The·system·needs·to·be·rebooted·for·these·changes·to·take·effect.
319 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8n\x8n_\x8v\x8v_\x8l\x8l_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8/\x8/_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8/\x8/_\x8N\x8N_\x8I\x8I_\x8S\x8S_\x8T\x8T_\x8.\x8._\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x81\x81_\x84\x84_\x80\x80_\x8-\x8-_\x82\x82_\x8.\x8._\x8p\x8p_\x8d\x8d_\x8f\x8f·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.318 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8n\x8n_\x8v\x8v_\x8l\x8l_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8/\x8/_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8/\x8/_\x8N\x8N_\x8I\x8I_\x8S\x8S_\x8T\x8T_\x8.\x8._\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x81\x81_\x84\x84_\x80\x80_\x8-\x8-_\x82\x82_\x8.\x8._\x8p\x8p_\x8d\x8d_\x8f\x8f·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.
320 Rationale:··Centralized·cryptographic·policies·simplify·applying·secure·ciphers·across·an·operating·system·and·the·applications·that·run·on·that·operating·system.·Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.319 Rationale:··Centralized·cryptographic·policies·simplify·applying·secure·ciphers·across·an·operating·system·and·the·applications·that·run·on·that·operating·system.·Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.
Offset 666, 21 lines modifiedOffset 666, 14 lines modified
666 ··-·PCI-DSSv4-2.2.6666 ··-·PCI-DSSv4-2.2.6
667 ··-·enable_strategy667 ··-·enable_strategy
668 ··-·low_complexity668 ··-·low_complexity
669 ··-·low_disruption669 ··-·low_disruption
670 ··-·medium_severity670 ··-·medium_severity
671 ··-·no_reboot_needed671 ··-·no_reboot_needed
672 ··-·package_sudo_installed672 ··-·package_sudo_installed
673 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
674 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
675 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
676 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
677 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
678 package·--add=sudo 
679 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8673 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
680 [[packages]]674 [[packages]]
681 name·=·"sudo"675 name·=·"sudo"
682 version·=·"*"676 version·=·"*"
683 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8677 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
684 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low678 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 705, 14 lines modifiedOffset 698, 21 lines modified
705 if·!·rpm·-q·--quiet·"sudo"·;·then698 if·!·rpm·-q·--quiet·"sudo"·;·then
706 ····yum·install·-y·"sudo"699 ····yum·install·-y·"sudo"
707 fi700 fi
  
708 else701 else
709 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'702 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
710 fi703 fi
 704 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 705 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 706 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 707 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 708 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 709 package·--add=sudo
711 Group  ·System·Tooling·/·Utilities·  Group·contains·3·rules710 Group  ·System·Tooling·/·Utilities·  Group·contains·3·rules
712 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·following·checks·evaluate·the·system·for·recommended·base·packages·--·both·for·installation·and·removal.711 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·following·checks·evaluate·the·system·for·recommended·base·packages·--·both·for·installation·and·removal.
713 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·g\x8gn\x8nu\x8ut\x8tl\x8ls\x8s-\x8-u\x8ut\x8ti\x8il\x8ls\x8s·i\x8is\x8s·i\x8in\x8ns\x8st\x8ta\x8al\x8ll\x8le\x8ed\x8d·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*712 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·g\x8gn\x8nu\x8ut\x8tl\x8ls\x8s-\x8-u\x8ut\x8ti\x8il\x8ls\x8s·i\x8is\x8s·i\x8in\x8ns\x8st\x8ta\x8al\x8ll\x8le\x8ed\x8d·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
714 The·gnutls-utils·package·can·be·installed·with·the·following·command:713 The·gnutls-utils·package·can·be·installed·with·the·following·command:
715 $·sudo·yum·install·gnutls-utils714 $·sudo·yum·install·gnutls-utils
716 Rationale:··GnuTLS·is·a·secure·communications·library·implementing·the·SSL,·TLS·and·DTLS·protocols·and·technologies·around·them.·It·provides·a·simple·C·language·application·programming·interface·(API)·to·access·the·secure·communications·protocols·as·well·as·APIs·to·parse·and·write·X.509,·PKCS·#12,·OpenPGP·and·other·required·structures.·This·package·contains·command·line·TLS·client·and·server·and·certificate·manipulation·tools.715 Rationale:··GnuTLS·is·a·secure·communications·library·implementing·the·SSL,·TLS·and·DTLS·protocols·and·technologies·around·them.·It·provides·a·simple·C·language·application·programming·interface·(API)·to·access·the·secure·communications·protocols·as·well·as·APIs·to·parse·and·write·X.509,·PKCS·#12,·OpenPGP·and·other·required·structures.·This·package·contains·command·line·TLS·client·and·server·and·certificate·manipulation·tools.
717 Severity: ··medium716 Severity: ··medium
Offset 732, 21 lines modifiedOffset 732, 14 lines modified
732 ··tags:732 ··tags:
733 ··-·enable_strategy733 ··-·enable_strategy
734 ··-·low_complexity734 ··-·low_complexity
735 ··-·low_disruption735 ··-·low_disruption
736 ··-·medium_severity736 ··-·medium_severity
737 ··-·no_reboot_needed737 ··-·no_reboot_needed
738 ··-·package_gnutls-utils_installed738 ··-·package_gnutls-utils_installed
739 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
740 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
741 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
742 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
743 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
744 package·--add=gnutls-utils 
745 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8739 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
746 [[packages]]740 [[packages]]
747 name·=·"gnutls-utils"741 name·=·"gnutls-utils"
748 version·=·"*"742 version·=·"*"
749 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8743 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
750 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low744 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 765, 14 lines modifiedOffset 758, 21 lines modified
765 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low758 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
766 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false759 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
767 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable760 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
768 if·!·rpm·-q·--quiet·"gnutls-utils"·;·then761 if·!·rpm·-q·--quiet·"gnutls-utils"·;·then
769 ····yum·install·-y·"gnutls-utils"762 ····yum·install·-y·"gnutls-utils"
770 fi763 fi
 764 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 765 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 766 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 767 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 768 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 769 package·--add=gnutls-utils
771 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·o\x8op\x8pe\x8en\x8ns\x8sc\x8ca\x8ap\x8p-\x8-s\x8sc\x8ca\x8an\x8nn\x8ne\x8er\x8r·P\x8Pa\x8ac\x8ck\x8ka\x8ag\x8ge\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*770 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·o\x8op\x8pe\x8en\x8ns\x8sc\x8ca\x8ap\x8p-\x8-s\x8sc\x8ca\x8an\x8nn\x8ne\x8er\x8r·P\x8Pa\x8ac\x8ck\x8ka\x8ag\x8ge\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
772 The·openscap-scanner·package·can·be·installed·with·the·following·command:771 The·openscap-scanner·package·can·be·installed·with·the·following·command:
773 $·sudo·yum·install·openscap-scanner772 $·sudo·yum·install·openscap-scanner
Max diff block lines reached; 36906/44251 bytes (83.40%) of diff not shown.
227 KB
./usr/share/doc/ssg-nondebian/ssg-ol9-guide-e8.html
    
Offset 19407, 211 lines modifiedOffset 19407, 211 lines modified
0004bce0:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i0004bce0:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i
0004bcf0:·646d·3934·3338·2220·7461·6269·6e64·6578··dm9438"·tabindex0004bcf0:·646d·3934·3338·2220·7461·6269·6e64·6578··dm9438"·tabindex
0004bd00:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto0004bd00:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto
0004bd10:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded0004bd10:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded
0004bd20:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="0004bd20:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="
0004bd30:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve0004bd30:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve
0004bd40:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re0004bd40:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re
0004bd50:·6d65·6469·6174·696f·6e20·416e·6163·6f6e··mediation·Anacon0004bd50:·6d65·6469·6174·696f·6e20·4f53·4275·696c··mediation·OSBuil
 0004bd60:·6420·426c·7565·7072·696e·7420·736e·6970··d·Blueprint·snip
 0004bd70:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br><
 0004bd80:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
 0004bd90:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap
 0004bda0:·7365·2220·6964·3d22·6964·6d39·3433·3822··se"·id="idm9438"
0004bd60:·6461·2073·6e69·7070·6574·20e2·87b2·3c2f··da·snippet·...</ 
0004bd70:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class 
0004bd80:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse 
0004bd90:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i 
0004bda0:·646d·3934·3338·223e·3c74·6162·6c65·2063··dm9438"><table·c 
0004bdb0:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl 
0004bdc0:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table- 
0004bdd0:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c 
0004bde0:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t 
0004bdf0:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t 
0004be00:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></ 
0004be10:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru 
0004be20:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l 
0004be30:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr> 
0004be40:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th> 
0004be50:·3c74·643e·6661·6c73·653c·2f74·643e·3c2f··<td>false</td></ 
0004be60:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat 
0004be70:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena 
0004be80:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t 
0004be90:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>0004bdb0:·3e3c·7072·653e·3c63·6f64·653e·0a5b·5b70··><pre><code>.[[p
0004bea0:·0a70·6163·6b61·6765·202d·2d61·6464·3d72··.package·--add=r0004bdc0:·6163·6b61·6765·735d·5d0a·6e61·6d65·203d··ackages]].name·=
 0004bdd0:·2022·7265·6172·220a·7665·7273·696f·6e20···"rear".version·
0004beb0:·6561·720a·3c2f·636f·6465·3e3c·2f70·7265··ear.</code></pre0004bde0:·3d20·222a·220a·3c2f·636f·6465·3e3c·2f70··=·"*".</code></p
0004bec0:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class=0004bdf0:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas
0004bed0:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success0004be00:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe
0004bee0:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c0004be10:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle=
0004bef0:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta0004be20:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data-
0004bf00:·7267·6574·3d22·2369·646d·3934·3339·2220··rget="#idm9439"·0004be30:·7461·7267·6574·3d22·2369·646d·3934·3339··target="#idm9439
0004bf10:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol0004be40:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r
0004bf20:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-0004be50:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari
0004bf30:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"0004be60:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals
0004bf40:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate0004be70:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa
0004bf50:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href0004be80:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr
0004bf60:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio0004be90:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat
0004bf70:·6e20·4f53·4275·696c·6420·426c·7565·7072··n·OSBuild·Bluepr 
0004bf80:·696e·7420·736e·6970·7065·7420·e287·b23c··int·snippet·...< 
0004bf90:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas 
0004bfa0:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps 
0004bfb0:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id=" 
0004bfc0:·6964·6d39·3433·3922·3e3c·7072·653e·3c63··idm9439"><pre><c 
0004bfd0:·6f64·653e·0a5b·5b70·6163·6b61·6765·735d··ode>.[[packages] 
0004bfe0:·5d0a·6e61·6d65·203d·2022·7265·6172·220a··].name·=·"rear". 
0004bff0:·7665·7273·696f·6e20·3d20·222a·220a·3c2f··version·=·"*".</ 
0004c000:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div0004bea0:·696f·6e20·5075·7070·6574·2073·6e69·7070··ion·Puppet·snipp
 0004beb0:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d
 0004bec0:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-
 0004bed0:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps
 0004bee0:·6522·2069·643d·2269·646d·3934·3339·223e··e"·id="idm9439">
 0004bef0:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta
 0004bf00:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe
 0004bf10:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered
 0004bf20:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed
 0004bf30:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple
 0004bf40:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo
 0004bf50:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
 0004bf60:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</
 0004bf70:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
 0004bf80:·2f74·723e·3c74·723e·3c74·683e·5265·626f··/tr><tr><th>Rebo
 0004bf90:·6f74·3a3c·2f74·683e·3c74·643e·6661·6c73··ot:</th><td>fals
 0004bfa0:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr><
 0004bfb0:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th
 0004bfc0:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td>
 0004bfd0:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr
 0004bfe0:·653e·3c63·6f64·653e·696e·636c·7564·6520··e><code>include·
 0004bff0:·696e·7374·616c·6c5f·7265·6172·0a0a·636c··install_rear..cl
 0004c000:·6173·7320·696e·7374·616c·6c5f·7265·6172··ass·install_rear
 0004c010:·207b·0a20·2070·6163·6b61·6765·207b·2027···{.··package·{·'
 0004c020:·7265·6172·273a·0a20·2020·2065·6e73·7572··rear':.····ensur
 0004c030:·6520·3d26·6774·3b20·2769·6e73·7461·6c6c··e·=&gt;·'install
 0004c040:·6564·272c·0a20·207d·0a7d·0a3c·2f63·6f64··ed',.··}.}.</cod
 0004c050:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a
 0004c060:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn-
 0004c070:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to
 0004c080:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"·
 0004c090:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
 0004c0a0:·6d39·3434·3022·2074·6162·696e·6465·783d··m9440"·tabindex=
 0004c0b0:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button
 0004c0c0:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=
 0004c0d0:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A
 0004c0e0:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea
 0004c0f0:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem
 0004c100:·6564·6961·7469·6f6e·2053·6865·6c6c·2073··ediation·Shell·s
 0004c110:·6372·6970·7420·e287·b23c·2f61·3e3c·6272··cript·...</a><br
0004c010:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b0004c120:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
 0004c130:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
 0004c140:·6170·7365·2220·6964·3d22·6964·6d39·3434··apse"·id="idm944
 0004c150:·3022·3e3c·7461·626c·6520·636c·6173·733d··0"><table·class=
 0004c160:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str
 0004c170:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde
 0004c180:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden
 0004c190:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com
 0004c1a0:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td
0004c020:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data 
0004c030:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps 
0004c040:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target=" 
0004c050:·2369·646d·3934·3430·2220·7461·6269·6e64··#idm9440"·tabind 
0004c060:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but 
0004c070:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand 
0004c080:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title 
0004c090:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re 
0004c0a0:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!"> 
0004c0b0:·5265·6d65·6469·6174·696f·6e20·5075·7070··Remediation·Pupp 
0004c0c0:·6574·2073·6e69·7070·6574·20e2·87b2·3c2f··et·snippet·...</ 
0004c0d0:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class 
0004c0e0:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse 
0004c0f0:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i 
0004c100:·646d·3934·3430·223e·3c74·6162·6c65·2063··dm9440"><table·c 
0004c110:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl 
0004c120:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table- 
0004c130:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c 
0004c140:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t 
0004c150:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t 
0004c160:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></ 
0004c170:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru 
Max diff block lines reached; 181638/209404 bytes (86.74%) of diff not shown.
22.9 KB
html2text {}
    
Offset 1107, 21 lines modifiedOffset 1107, 14 lines modified
1107 ··tags:1107 ··tags:
1108 ··-·enable_strategy1108 ··-·enable_strategy
1109 ··-·low_complexity1109 ··-·low_complexity
1110 ··-·low_disruption1110 ··-·low_disruption
1111 ··-·medium_severity1111 ··-·medium_severity
1112 ··-·no_reboot_needed1112 ··-·no_reboot_needed
1113 ··-·package_rear_installed1113 ··-·package_rear_installed
1114 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
1115 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
1116 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
1117 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
1118 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
1119 package·--add=rear 
1120 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81114 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
1121 [[packages]]1115 [[packages]]
1122 name·=·"rear"1116 name·=·"rear"
1123 version·=·"*"1117 version·=·"*"
1124 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81118 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1125 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1119 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 1146, 14 lines modifiedOffset 1139, 21 lines modified
1146 if·!·rpm·-q·--quiet·"rear"·;·then1139 if·!·rpm·-q·--quiet·"rear"·;·then
1147 ····yum·install·-y·"rear"1140 ····yum·install·-y·"rear"
1148 fi1141 fi
  
1149 else1142 else
1150 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'1143 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
1151 fi1144 fi
 1145 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 1146 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1147 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1148 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1149 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 1150 package·--add=rear
1152 Group  ·Updating·Software·  Group·contains·6·rules1151 Group  ·Updating·Software·  Group·contains·6·rules
1153 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·yum·command·line·tool·is·used·to·install·and·update·software·packages.·The·system·also·provides·a·graphical·software·update·tool·in·the·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·menu,·in·the·A\x8Ad\x8dm\x8mi\x8in\x8ni\x8is\x8st\x8tr\x8ra\x8at\x8ti\x8io\x8on\x8n·submenu,·called·S\x8So\x8of\x8ft\x8tw\x8wa\x8ar\x8re\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8e.1152 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·yum·command·line·tool·is·used·to·install·and·update·software·packages.·The·system·also·provides·a·graphical·software·update·tool·in·the·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·menu,·in·the·A\x8Ad\x8dm\x8mi\x8in\x8ni\x8is\x8st\x8tr\x8ra\x8at\x8ti\x8io\x8on\x8n·submenu,·called·S\x8So\x8of\x8ft\x8tw\x8wa\x8ar\x8re\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8e.
  
1154 Oracle·Linux·9·systems·contain·an·installed·software·catalog·called·the·RPM·database,·which·records·metadata·of·installed·packages.·Consistently·using·yum·or·the·graphical·S\x8So\x8of\x8ft\x8tw\x8wa\x8ar\x8re\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8e·for·all·software·installation·allows·for·insight·into·the·current·inventory·of·installed·software·on·the·system.1153 Oracle·Linux·9·systems·contain·an·installed·software·catalog·called·the·RPM·database,·which·records·metadata·of·installed·packages.·Consistently·using·yum·or·the·graphical·S\x8So\x8of\x8ft\x8tw\x8wa\x8ar\x8re\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8e·for·all·software·installation·allows·for·insight·into·the·current·inventory·of·installed·software·on·the·system.
  
1155 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·d\x8dn\x8nf\x8f-\x8-a\x8au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8c·t\x8to\x8o·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·O\x8On\x8nl\x8ly\x8y·S\x8Se\x8ec\x8cu\x8ur\x8ri\x8it\x8ty\x8y·U\x8Up\x8pd\x8da\x8at\x8te\x8es\x8s·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*1154 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·d\x8dn\x8nf\x8f-\x8-a\x8au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8c·t\x8to\x8o·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·O\x8On\x8nl\x8ly\x8y·S\x8Se\x8ec\x8cu\x8ur\x8ri\x8it\x8ty\x8y·U\x8Up\x8pd\x8da\x8at\x8te\x8es\x8s·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
1156 To·configure·dnf-automatic·to·install·only·security·updates·automatically,·set·upgrade_type·to·security·under·[commands]·section·in·/etc/dnf/automatic.conf.1155 To·configure·dnf-automatic·to·install·only·security·updates·automatically,·set·upgrade_type·to·security·under·[commands]·section·in·/etc/dnf/automatic.conf.
Offset 2223, 21 lines modifiedOffset 2223, 14 lines modified
2223 ··-·NIST-800-53-CM-6(a)2223 ··-·NIST-800-53-CM-6(a)
2224 ··-·enable_strategy2224 ··-·enable_strategy
2225 ··-·low_complexity2225 ··-·low_complexity
2226 ··-·low_disruption2226 ··-·low_disruption
2227 ··-·medium_severity2227 ··-·medium_severity
2228 ··-·no_reboot_needed2228 ··-·no_reboot_needed
2229 ··-·package_rsyslog_installed2229 ··-·package_rsyslog_installed
2230 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
2231 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
2232 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
2233 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
2234 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
2235 package·--add=rsyslog 
2236 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x82230 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
2237 [[packages]]2231 [[packages]]
2238 name·=·"rsyslog"2232 name·=·"rsyslog"
2239 version·=·"*"2233 version·=·"*"
2240 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x82234 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
2241 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low2235 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 2262, 14 lines modifiedOffset 2255, 21 lines modified
2262 if·!·rpm·-q·--quiet·"rsyslog"·;·then2255 if·!·rpm·-q·--quiet·"rsyslog"·;·then
2263 ····yum·install·-y·"rsyslog"2256 ····yum·install·-y·"rsyslog"
2264 fi2257 fi
  
2265 else2258 else
2266 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'2259 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
2267 fi2260 fi
 2261 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 2262 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 2263 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 2264 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 2265 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 2266 package·--add=rsyslog
2268 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·r\x8rs\x8sy\x8ys\x8sl\x8lo\x8og\x8g·S\x8Se\x8er\x8rv\x8vi\x8ic\x8ce\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*2267 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·r\x8rs\x8sy\x8ys\x8sl\x8lo\x8og\x8g·S\x8Se\x8er\x8rv\x8vi\x8ic\x8ce\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
2269 The·rsyslog·service·provides·syslog-style·logging·by·default·on·Oracle·Linux·9.·The·rsyslog·service·can·be·enabled·with·the·following·command:2268 The·rsyslog·service·provides·syslog-style·logging·by·default·on·Oracle·Linux·9.·The·rsyslog·service·can·be·enabled·with·the·following·command:
2270 $·sudo·systemctl·enable·rsyslog.service2269 $·sudo·systemctl·enable·rsyslog.service
2271 Rationale:··The·rsyslog·service·must·be·running·in·order·to·provide·logging·services,·which·are·essential·to·system·administration.2270 Rationale:··The·rsyslog·service·must·be·running·in·order·to·provide·logging·services,·which·are·essential·to·system·administration.
2272 Severity: ··medium2271 Severity: ··medium
2273 Rule·ID:····xccdf_org.ssgproject.content_rule_service_rsyslog_enabled2272 Rule·ID:····xccdf_org.ssgproject.content_rule_service_rsyslog_enabled
2274 ············_\x8c_\x8i_\x8s_\x8-_\x8c_\x8s_\x8c········1,·12,·13,·14,·15,·16,·2,·3,·5,·6,·7,·8,·92273 ············_\x8c_\x8i_\x8s_\x8-_\x8c_\x8s_\x8c········1,·12,·13,·14,·15,·16,·2,·3,·5,·6,·7,·8,·9
Offset 2455, 21 lines modifiedOffset 2455, 14 lines modified
2455 ··-·PCI-DSSv4-1.2.12455 ··-·PCI-DSSv4-1.2.1
2456 ··-·enable_strategy2456 ··-·enable_strategy
2457 ··-·low_complexity2457 ··-·low_complexity
2458 ··-·low_disruption2458 ··-·low_disruption
2459 ··-·medium_severity2459 ··-·medium_severity
2460 ··-·no_reboot_needed2460 ··-·no_reboot_needed
2461 ··-·package_firewalld_installed2461 ··-·package_firewalld_installed
2462 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
2463 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
2464 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
2465 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
2466 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
2467 package·--add=firewalld 
2468 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x82462 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
2469 [[packages]]2463 [[packages]]
2470 name·=·"firewalld"2464 name·=·"firewalld"
2471 version·=·"*"2465 version·=·"*"
2472 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x82466 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
2473 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low2467 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 2494, 14 lines modifiedOffset 2487, 21 lines modified
2494 if·!·rpm·-q·--quiet·"firewalld"·;·then2487 if·!·rpm·-q·--quiet·"firewalld"·;·then
2495 ····yum·install·-y·"firewalld"2488 ····yum·install·-y·"firewalld"
2496 fi2489 fi
  
2497 else2490 else
2498 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'2491 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
2499 fi2492 fi
 2493 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 2494 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 2495 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 2496 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 2497 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 2498 package·--add=firewalld
2500 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·f\x8fi\x8ir\x8re\x8ew\x8wa\x8al\x8ll\x8ld\x8d·E\x8En\x8na\x8ab\x8bl\x8le\x8ed\x8d·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*2499 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·f\x8fi\x8ir\x8re\x8ew\x8wa\x8al\x8ll\x8ld\x8d·E\x8En\x8na\x8ab\x8bl\x8le\x8ed\x8d·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
2501 The·firewalld·service·can·be·enabled·with·the·following·command:2500 The·firewalld·service·can·be·enabled·with·the·following·command:
2502 $·sudo·systemctl·enable·firewalld.service2501 $·sudo·systemctl·enable·firewalld.service
Max diff block lines reached; 17719/23406 bytes (75.70%) of diff not shown.
126 KB
./usr/share/doc/ssg-nondebian/ssg-ol9-guide-hipaa.html
    
Offset 37909, 174 lines modifiedOffset 37909, 174 lines modified
00094140:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=00094140:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
00094150:·2223·6964·6d33·3339·3530·2220·7461·6269··"#idm33950"·tabi00094150:·2223·6964·6d33·3339·3530·2220·7461·6269··"#idm33950"·tabi
00094160:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b00094160:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
00094170:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa00094170:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
00094180:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit00094180:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
00094190:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·00094190:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
000941a0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!000941a0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
000941b0:·223e·5265·6d65·6469·6174·696f·6e20·416e··">Remediation·An000941b0:·223e·5265·6d65·6469·6174·696f·6e20·4f53··">Remediation·OS
000941c0:·6163·6f6e·6461·2073·6e69·7070·6574·20e2··aconda·snippet·.000941c0:·4275·696c·6420·426c·7565·7072·696e·7420··Build·Blueprint·
 000941d0:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><
 000941e0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
 000941f0:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
 00094200:·6c6c·6170·7365·2220·6964·3d22·6964·6d33··llapse"·id="idm3
 00094210:·3339·3530·223e·3c70·7265·3e3c·636f·6465··3950"><pre><code
 00094220:·3e0a·5b63·7573·746f·6d69·7a61·7469·6f6e··>.[customization
 00094230:·732e·7365·7276·6963·6573·5d0a·6d61·736b··s.services].mask
 00094240:·6564·203d·205b·226b·6475·6d70·225d·0a3c··ed·=·["kdump"].<
 00094250:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di
 00094260:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn·
 00094270:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat
 00094280:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap
 00094290:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
 000942a0:·2223·6964·6d33·3339·3531·2220·7461·6269··"#idm33951"·tabi
 000942b0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
 000942c0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
 000942d0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
 000942e0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
 000942f0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
 00094300:·223e·5265·6d65·6469·6174·696f·6e20·5075··">Remediation·Pu
 00094310:·7070·6574·2073·6e69·7070·6574·20e2·87b2··ppet·snippet·...
000941d0:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c00094320:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
000941e0:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll00094330:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
000941f0:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i00094340:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
00094200:·643d·2269·646d·3333·3935·3022·3e3c·7072··d="idm33950"><pr00094350:·2269·646d·3333·3935·3122·3e3c·7461·626c··"idm33951"><tabl
00094210:·653e·3c63·6f64·653e·0a6b·6475·6d70·202d··e><code>.kdump·- 
00094220:·2d64·6973·6162·6c65·0a3c·2f63·6f64·653e··-disable.</code> 
00094230:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c 
00094240:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su 
00094250:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg 
00094260:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da 
00094270:·7461·2d74·6172·6765·743d·2223·6964·6d33··ta-target="#idm3 
00094280:·3339·3531·2220·7461·6269·6e64·6578·3d22··3951"·tabindex=" 
00094290:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button" 
000942a0:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded=" 
000942b0:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac 
000942c0:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal 
000942d0:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme 
000942e0:·6469·6174·696f·6e20·4f53·4275·696c·6420··diation·OSBuild· 
000942f0:·426c·7565·7072·696e·7420·736e·6970·7065··Blueprint·snippe 
00094300:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di 
00094310:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c00094360:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t
 00094370:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab
 00094380:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl
 00094390:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr
 000943a0:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:
00094320:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse 
00094330:·2220·6964·3d22·6964·6d33·3339·3531·223e··"·id="idm33951"> 
00094340:·3c70·7265·3e3c·636f·6465·3e0a·5b63·7573··<pre><code>.[cus 
00094350:·746f·6d69·7a61·7469·6f6e·732e·7365·7276··tomizations.serv 
00094360:·6963·6573·5d0a·6d61·736b·6564·203d·205b··ices].masked·=·[ 
00094370:·226b·6475·6d70·225d·0a3c·2f63·6f64·653e··"kdump"].</code> 
00094380:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c 
00094390:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su 
000943a0:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg 
000943b0:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da 
000943c0:·7461·2d74·6172·6765·743d·2223·6964·6d33··ta-target="#idm3 
000943d0:·3339·3532·2220·7461·6269·6e64·6578·3d22··3952"·tabindex=" 
000943e0:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button" 
000943f0:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded=" 
00094400:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac 
00094410:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal 
00094420:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme 
00094430:·6469·6174·696f·6e20·5075·7070·6574·2073··diation·Puppet·s 
00094440:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b 
00094450:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa 
00094460:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col 
00094470:·6c61·7073·6522·2069·643d·2269·646d·3333··lapse"·id="idm33 
00094480:·3935·3222·3e3c·7461·626c·6520·636c·6173··952"><table·clas 
00094490:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s 
000944a0:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor 
000944b0:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond 
000944c0:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C 
000944d0:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th>< 
000944e0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
000944f0:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti 
00094500:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low< 
00094510:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
00094520:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td 
00094530:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr> 
00094540:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy 
00094550:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable 
00094560:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl 
00094570:·653e·3c70·7265·3e3c·636f·6465·3e69·6e63··e><pre><code>inc 
00094580:·6c75·6465·2064·6973·6162·6c65·5f6b·6475··lude·disable_kdu 
00094590:·6d70·0a0a·636c·6173·7320·6469·7361·626c··mp..class·disabl 
000945a0:·655f·6b64·756d·7020·7b0a·2020·7365·7276··e_kdump·{.··serv 
000945b0:·6963·6520·7b27·6b64·756d·7027·3a0a·2020··ice·{'kdump':.·· 
000945c0:·2020·656e·6162·6c65·203d·2667·743b·2066····enable·=&gt;·f 
000945d0:·616c·7365·2c0a·2020·2020·656e·7375·7265··alse,.····ensure 
000945e0:·203d·2667·743b·2027·7374·6f70·7065·6427···=&gt;·'stopped' 
000945f0:·2c0a·2020·7d0a·7d0a·3c2f·636f·6465·3e3c··,.··}.}.</code>< 
00094600:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl 
00094610:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc 
00094620:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl 
00094630:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat 
00094640:·612d·7461·7267·6574·3d22·2369·646d·3333··a-target="#idm33 
00094650:·3935·3322·2074·6162·696e·6465·783d·2230··953"·tabindex="0 
00094660:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"· 
00094670:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f 
00094680:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act 
00094690:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal" 
000946a0:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed 
000946b0:·6961·7469·6f6e·2053·6865·6c6c·2073·6372··iation·Shell·scr 
000946c0:·6970·7420·e287·b23c·2f61·3e3c·6272·3e3c··ipt·...</a><br>< 
000946d0:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel 
000946e0:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap 
000946f0:·7365·2220·6964·3d22·6964·6d33·3339·3533··se"·id="idm33953 
00094700:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class=" 
00094710:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri 
00094720:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border 
00094730:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens 
00094740:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp 
00094750:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td> 
00094760:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr 
00094770:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption: 
00094780:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td000943b0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
00094790:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re000943c0:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di
Max diff block lines reached; 91662/114322 bytes (80.18%) of diff not shown.
13.9 KB
html2text {}
    
Offset 4752, 17 lines modifiedOffset 4752, 14 lines modified
4752 ··-·NIST-800-53-CM-7(b)4752 ··-·NIST-800-53-CM-7(b)
4753 ··-·disable_strategy4753 ··-·disable_strategy
4754 ··-·low_complexity4754 ··-·low_complexity
4755 ··-·low_disruption4755 ··-·low_disruption
4756 ··-·medium_severity4756 ··-·medium_severity
4757 ··-·no_reboot_needed4757 ··-·no_reboot_needed
4758 ··-·service_kdump_disabled4758 ··-·service_kdump_disabled
4759 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
4760 kdump·--disable 
4761 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x84759 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
4762 [customizations.services]4760 [customizations.services]
4763 masked·=·["kdump"]4761 masked·=·["kdump"]
4764 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x84762 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
4765 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low4763 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
4766 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low4764 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
Offset 4801, 14 lines modifiedOffset 4798, 17 lines modified
4801 #·so·let's·reset·the·state·so·OVAL·checks·pass.4798 #·so·let's·reset·the·state·so·OVAL·checks·pass.
4802 #·Service·should·be·'inactive',·not·'failed'·after·reboot·though.4799 #·Service·should·be·'inactive',·not·'failed'·after·reboot·though.
4803 "$SYSTEMCTL_EXEC"·reset-failed·'kdump.service'·||·true4800 "$SYSTEMCTL_EXEC"·reset-failed·'kdump.service'·||·true
  
4804 else4801 else
4805 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'4802 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
4806 fi4803 fi
 4804 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 4805 kdump·--disable
4807 Group  ·Cron·and·At·Daemons·  Group·contains·1·rule4806 Group  ·Cron·and·At·Daemons·  Group·contains·1·rule
4808 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·cron·and·at·services·are·used·to·allow·commands·to·be·executed·at·a·later·time.·The·cron·service·is·required·by·almost·all·systems·to·perform·necessary·maintenance·tasks,·while·at·may·or·may·not·be·required·on·a·given·system.·Both·daemons·should·be·configured·defensively.4807 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·cron·and·at·services·are·used·to·allow·commands·to·be·executed·at·a·later·time.·The·cron·service·is·required·by·almost·all·systems·to·perform·necessary·maintenance·tasks,·while·at·may·or·may·not·be·required·on·a·given·system.·Both·daemons·should·be·configured·defensively.
4809 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·c\x8cr\x8ro\x8on\x8n·S\x8Se\x8er\x8rv\x8vi\x8ic\x8ce\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*4808 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·c\x8cr\x8ro\x8on\x8n·S\x8Se\x8er\x8rv\x8vi\x8ic\x8ce\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
4810 The·crond·service·is·used·to·execute·commands·at·preconfigured·times.·It·is·required·by·almost·all·systems·to·perform·necessary·maintenance·tasks,·such·as·notifying·root·of·system·activity.·The·crond·service·can·be·enabled·with·the·following·command:4809 The·crond·service·is·used·to·execute·commands·at·preconfigured·times.·It·is·required·by·almost·all·systems·to·perform·necessary·maintenance·tasks,·such·as·notifying·root·of·system·activity.·The·crond·service·can·be·enabled·with·the·following·command:
4811 $·sudo·systemctl·enable·crond.service4810 $·sudo·systemctl·enable·crond.service
4812 Rationale:··Due·to·its·usage·for·maintenance·and·security-supporting·tasks,·enabling·the·cron·daemon·is·essential.4811 Rationale:··Due·to·its·usage·for·maintenance·and·security-supporting·tasks,·enabling·the·cron·daemon·is·essential.
4813 Severity: ··medium4812 Severity: ··medium
Offset 5021, 21 lines modifiedOffset 5021, 14 lines modified
5021 ··-·PCI-DSSv4-2.2.45021 ··-·PCI-DSSv4-2.2.4
5022 ··-·disable_strategy5022 ··-·disable_strategy
5023 ··-·high_severity5023 ··-·high_severity
5024 ··-·low_complexity5024 ··-·low_complexity
5025 ··-·low_disruption5025 ··-·low_disruption
5026 ··-·no_reboot_needed5026 ··-·no_reboot_needed
5027 ··-·package_rsh-server_removed5027 ··-·package_rsh-server_removed
5028 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
5029 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
5030 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
5031 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
5032 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable 
  
5033 package·--remove=rsh-server 
5034 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x85028 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
5035 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low5029 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
5036 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low5030 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
5037 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false5031 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
5038 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable5032 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
5039 include·remove_rsh-server5033 include·remove_rsh-server
  
Offset 5055, 14 lines modifiedOffset 5048, 21 lines modified
5055 #»      ···that·depend·on·rsh-server.·Execute·this5048 #»      ···that·depend·on·rsh-server.·Execute·this
5056 #»      ···remediation·AFTER·testing·on·a·non-production5049 #»      ···remediation·AFTER·testing·on·a·non-production
5057 #»      ···system!5050 #»      ···system!
  
5058 if·rpm·-q·--quiet·"rsh-server"·;·then5051 if·rpm·-q·--quiet·"rsh-server"·;·then
5059 yum·remove·-y·"rsh-server"5052 yum·remove·-y·"rsh-server"
5060 fi5053 fi
 5054 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 5055 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 5056 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 5057 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 5058 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
  
 5059 package·--remove=rsh-server
5061 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·D\x8Di\x8is\x8sa\x8ab\x8bl\x8le\x8e·r\x8rl\x8lo\x8og\x8gi\x8in\x8n·S\x8Se\x8er\x8rv\x8vi\x8ic\x8ce\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*5060 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·D\x8Di\x8is\x8sa\x8ab\x8bl\x8le\x8e·r\x8rl\x8lo\x8og\x8gi\x8in\x8n·S\x8Se\x8er\x8rv\x8vi\x8ic\x8ce\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
5062 The·rlogin·service,·which·is·available·with·the·rsh-server·package·and·runs·as·a·service·through·xinetd·or·separately·as·a·systemd·socket,·should·be·disabled.·If·using·xinetd,·set·disable·to·yes·in·/etc/xinetd.d/rlogin.·The·rlogin·socket·can·be·disabled·with·the·following·command:5061 The·rlogin·service,·which·is·available·with·the·rsh-server·package·and·runs·as·a·service·through·xinetd·or·separately·as·a·systemd·socket,·should·be·disabled.·If·using·xinetd,·set·disable·to·yes·in·/etc/xinetd.d/rlogin.·The·rlogin·socket·can·be·disabled·with·the·following·command:
5063 $·sudo·systemctl·mask·--now·rlogin.socket5062 $·sudo·systemctl·mask·--now·rlogin.socket
5064 Rationale:··The·rlogin·service·uses·unencrypted·network·communications,·which·means·that·data·from·the·login·session,·including·passwords·and·all·other·information·transmitted·during·the·session,·can·be·stolen·by·eavesdroppers·on·the·network.5063 Rationale:··The·rlogin·service·uses·unencrypted·network·communications,·which·means·that·data·from·the·login·session,·including·passwords·and·all·other·information·transmitted·during·the·session,·can·be·stolen·by·eavesdroppers·on·the·network.
5065 Severity: ··high5064 Severity: ··high
5066 Rule·ID:····xccdf_org.ssgproject.content_rule_service_rlogin_disabled5065 Rule·ID:····xccdf_org.ssgproject.content_rule_service_rlogin_disabled
5067 ············_\x8c_\x8i_\x8s_\x8-_\x8c_\x8s_\x8c········1,·11,·12,·14,·15,·16,·3,·5,·8,·95066 ············_\x8c_\x8i_\x8s_\x8-_\x8c_\x8s_\x8c········1,·11,·12,·14,·15,·16,·3,·5,·8,·9
Offset 5358, 21 lines modifiedOffset 5358, 14 lines modified
5358 ··-·PCI-DSSv4-2.2.45358 ··-·PCI-DSSv4-2.2.4
5359 ··-·disable_strategy5359 ··-·disable_strategy
5360 ··-·low_complexity5360 ··-·low_complexity
5361 ··-·low_disruption5361 ··-·low_disruption
5362 ··-·medium_severity5362 ··-·medium_severity
5363 ··-·no_reboot_needed5363 ··-·no_reboot_needed
5364 ··-·package_talk-server_removed5364 ··-·package_talk-server_removed
5365 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
5366 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
5367 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
5368 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
5369 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable 
  
5370 package·--remove=talk-server 
5371 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x85365 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
5372 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low5366 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
5373 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low5367 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
5374 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false5368 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
5375 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable5369 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
5376 include·remove_talk-server5370 include·remove_talk-server
  
Offset 5392, 14 lines modifiedOffset 5385, 21 lines modified
5392 #»      ···that·depend·on·talk-server.·Execute·this5385 #»      ···that·depend·on·talk-server.·Execute·this
5393 #»      ···remediation·AFTER·testing·on·a·non-production5386 #»      ···remediation·AFTER·testing·on·a·non-production
5394 #»      ···system!5387 #»      ···system!
  
5395 if·rpm·-q·--quiet·"talk-server"·;·then5388 if·rpm·-q·--quiet·"talk-server"·;·then
5396 yum·remove·-y·"talk-server"5389 yum·remove·-y·"talk-server"
5397 fi5390 fi
 5391 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 5392 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 5393 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 5394 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 5395 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
  
 5396 package·--remove=talk-server
5398 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·U\x8Un\x8ni\x8in\x8ns\x8st\x8ta\x8al\x8ll\x8l·t\x8ta\x8al\x8lk\x8k·P\x8Pa\x8ac\x8ck\x8ka\x8ag\x8ge\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*5397 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·U\x8Un\x8ni\x8in\x8ns\x8st\x8ta\x8al\x8ll\x8l·t\x8ta\x8al\x8lk\x8k·P\x8Pa\x8ac\x8ck\x8ka\x8ag\x8ge\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
5399 The·talk·package·contains·the·client·program·for·the·Internet·talk·protocol,·which·allows·the·user·to·chat·with·other·users·on·different·systems.·Talk·is·a·communication·program·which·copies·lines·from·one·terminal·to·the·terminal·of·another·user.·The·talk·package·can·be·removed·with·the·following·command:5398 The·talk·package·contains·the·client·program·for·the·Internet·talk·protocol,·which·allows·the·user·to·chat·with·other·users·on·different·systems.·Talk·is·a·communication·program·which·copies·lines·from·one·terminal·to·the·terminal·of·another·user.·The·talk·package·can·be·removed·with·the·following·command:
5400 $·sudo·yum·erase·talk5399 $·sudo·yum·erase·talk
5401 Rationale:··The·talk·software·presents·a·security·risk·as·it·uses·unencrypted·protocols·for·communications.·Removing·the·talk·package·decreases·the·risk·of·the·accidental·(or·intentional)·activation·of·talk·client·program.5400 Rationale:··The·talk·software·presents·a·security·risk·as·it·uses·unencrypted·protocols·for·communications.·Removing·the·talk·package·decreases·the·risk·of·the·accidental·(or·intentional)·activation·of·talk·client·program.
5402 Severity: ··medium5401 Severity: ··medium
5403 Rule·ID:····xccdf_org.ssgproject.content_rule_package_talk_removed5402 Rule·ID:····xccdf_org.ssgproject.content_rule_package_talk_removed
5404 ············_\x8h_\x8i_\x8p_\x8a_\x8a···164.308(a)(4)(i),·164.308(b)(1),·164.308(b)(3),·164.310(b),·164.312(e)(1),·164.312(e)(2)(ii)5403 ············_\x8h_\x8i_\x8p_\x8a_\x8a···164.308(a)(4)(i),·164.308(b)(1),·164.308(b)(3),·164.310(b),·164.312(e)(1),·164.312(e)(2)(ii)
Offset 5419, 21 lines modifiedOffset 5419, 14 lines modified
5419 ··-·PCI-DSSv4-2.2.45419 ··-·PCI-DSSv4-2.2.4
5420 ··-·disable_strategy5420 ··-·disable_strategy
5421 ··-·low_complexity5421 ··-·low_complexity
Max diff block lines reached; 7979/14178 bytes (56.28%) of diff not shown.
410 KB
./usr/share/doc/ssg-nondebian/ssg-ol9-guide-ism_o.html
    
Offset 17388, 143 lines modifiedOffset 17388, 143 lines modified
00043eb0:·2d74·6172·6765·743d·2223·6964·6d36·3238··-target="#idm62800043eb0:·2d74·6172·6765·743d·2223·6964·6d36·3238··-target="#idm628
00043ec0:·3022·2074·6162·696e·6465·783d·2230·2220··0"·tabindex="0"·00043ec0:·3022·2074·6162·696e·6465·783d·2230·2220··0"·tabindex="0"·
00043ed0:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar00043ed0:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar
00043ee0:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal00043ee0:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal
00043ef0:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ00043ef0:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ
00043f00:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h00043f00:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h
00043f10:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia00043f10:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia
 00043f20:·7469·6f6e·204f·5342·7569·6c64·2042·6c75··tion·OSBuild·Blu
 00043f30:·6570·7269·6e74·2073·6e69·7070·6574·20e2··eprint·snippet·.
 00043f40:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c
 00043f50:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
 00043f60:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
 00043f70:·643d·2269·646d·3632·3830·223e·3c70·7265··d="idm6280"><pre
 00043f80:·3e3c·636f·6465·3e0a·5b5b·7061·636b·6167··><code>.[[packag
 00043f90:·6573·5d5d·0a6e·616d·6520·3d20·2261·6964··es]].name·=·"aid
 00043fa0:·6522·0a76·6572·7369·6f6e·203d·2022·2a22··e".version·=·"*"
 00043fb0:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></
 00043fc0:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt
 00043fd0:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d
 00043fe0:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll
 00043ff0:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
 00044000:·743d·2223·6964·6d36·3238·3122·2074·6162··t="#idm6281"·tab
 00044010:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
 00044020:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
 00044030:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
 00044040:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
 00044050:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
 00044060:·2122·3e52·656d·6564·6961·7469·6f6e·2050··!">Remediation·P
 00044070:·7570·7065·7420·736e·6970·7065·7420·e287··uppet·snippet·..
 00044080:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl
 00044090:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla
 000440a0:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id
 000440b0:·3d22·6964·6d36·3238·3122·3e3c·7461·626c··="idm6281"><tabl
 000440c0:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t
 000440d0:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab
 000440e0:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl
 000440f0:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr
 00044100:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:
 00044110:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
 00044120:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di
 00044130:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t
 00044140:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
 00044150:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</
 00044160:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td
 00044170:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St
 00044180:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>
 00044190:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr>
 000441a0:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co
 000441b0:·6465·3e69·6e63·6c75·6465·2069·6e73·7461··de>include·insta
 000441c0:·6c6c·5f61·6964·650a·0a63·6c61·7373·2069··ll_aide..class·i
 000441d0:·6e73·7461·6c6c·5f61·6964·6520·7b0a·2020··nstall_aide·{.··
 000441e0:·7061·636b·6167·6520·7b20·2761·6964·6527··package·{·'aide'
 000441f0:·3a0a·2020·2020·656e·7375·7265·203d·2667··:.····ensure·=&g
 00044200:·743b·2027·696e·7374·616c·6c65·6427·2c0a··t;·'installed',.
 00044210:·2020·7d0a·7d0a·3c2f·636f·6465·3e3c·2f70····}.}.</code></p
 00044220:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas
 00044230:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe
 00044240:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle=
 00044250:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data-
 00044260:·7461·7267·6574·3d22·2369·646d·3632·3832··target="#idm6282
 00044270:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r
 00044280:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari
 00044290:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals
 000442a0:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa
 000442b0:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr
 000442c0:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat
 000442d0:·696f·6e20·5368·656c·6c20·7363·7269·7074··ion·Shell·script
 000442e0:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
 000442f0:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
 00044300:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
 00044310:·2069·643d·2269·646d·3632·3832·223e·3c74···id="idm6282"><t
 00044320:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl
 00044330:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·
 00044340:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t
 00044350:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">
 00044360:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi
 00044370:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<
 00044380:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 00044390:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th
 000443a0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
 000443b0:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot
 000443c0:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false<
 000443d0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 000443e0:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><
 000443f0:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></
 00044400:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>
 00044410:·3c63·6f64·653e·2320·5265·6d65·6469·6174··<code>#·Remediat
 00044420:·696f·6e20·6973·2061·7070·6c69·6361·626c··ion·is·applicabl
 00044430:·6520·6f6e·6c79·2069·6e20·6365·7274·6169··e·only·in·certai
 00044440:·6e20·706c·6174·666f·726d·730a·6966·2072··n·platforms.if·r
 00044450:·706d·202d·2d71·7569·6574·202d·7120·6b65··pm·--quiet·-q·ke
 00044460:·726e·656c·207c·7c20·7270·6d20·2d2d·7175··rnel·||·rpm·--qu
 00044470:·6965·7420·2d71·206b·6572·6e65·6c2d·7565··iet·-q·kernel-ue
 00044480:·6b3b·2074·6865·6e0a·0a69·6620·2120·7270··k;·then..if·!·rp
 00044490:·6d20·2d71·202d·2d71·7569·6574·2022·6169··m·-q·--quiet·"ai
 000444a0:·6465·2220·3b20·7468·656e·0a20·2020·2079··de"·;·then.····y
 000444b0:·756d·2069·6e73·7461·6c6c·202d·7920·2261··um·install·-y·"a
 000444c0:·6964·6522·0a66·690a·0a65·6c73·650a·2020··ide".fi..else.··
 000444d0:·2020·2667·743b·2661·6d70·3b32·2065·6368····&gt;&amp;2·ech
 000444e0:·6f20·2752·656d·6564·6961·7469·6f6e·2069··o·'Remediation·i
 000444f0:·7320·6e6f·7420·6170·706c·6963·6162·6c65··s·not·applicable
 00044500:·2c20·6e6f·7468·696e·6720·7761·7320·646f··,·nothing·was·do
 00044510:·6e65·270a·6669·0a3c·2f63·6f64·653e·3c2f··ne'.fi.</code></
 00044520:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla
 00044530:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ
 00044540:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle
 00044550:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data
 00044560:·2d74·6172·6765·743d·2223·6964·6d36·3238··-target="#idm628
 00044570:·3322·2074·6162·696e·6465·783d·2230·2220··3"·tabindex="0"·
 00044580:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar
 00044590:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal
 000445a0:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ
 000445b0:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h
 000445c0:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia
00043f20:·7469·6f6e·2041·6e61·636f·6e64·6120·736e··tion·Anaconda·sn000445d0:·7469·6f6e·2041·6e61·636f·6e64·6120·736e··tion·Anaconda·sn
00043f30:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br 
00043f40:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan 
00043f50:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll 
00043f60:·6170·7365·2220·6964·3d22·6964·6d36·3238··apse"·id="idm628 
00043f70:·3022·3e3c·7461·626c·6520·636c·6173·733d··0"><table·class= 
00043f80:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str 
00043f90:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde 
00043fa0:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden 
00043fb0:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com 
00043fc0:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td 
00043fd0:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t 
00043fe0:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption 
Max diff block lines reached; 358950/377332 bytes (95.13%) of diff not shown.
41.5 KB
html2text {}
    
Offset 716, 21 lines modifiedOffset 716, 14 lines modified
716 ··-·PCI-DSSv4-11.5.2716 ··-·PCI-DSSv4-11.5.2
717 ··-·enable_strategy717 ··-·enable_strategy
718 ··-·low_complexity718 ··-·low_complexity
719 ··-·low_disruption719 ··-·low_disruption
720 ··-·medium_severity720 ··-·medium_severity
721 ··-·no_reboot_needed721 ··-·no_reboot_needed
722 ··-·package_aide_installed722 ··-·package_aide_installed
723 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
724 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
725 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
726 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
727 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
728 package·--add=aide 
729 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8723 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
730 [[packages]]724 [[packages]]
731 name·=·"aide"725 name·=·"aide"
732 version·=·"*"726 version·=·"*"
733 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8727 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
734 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low728 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 755, 14 lines modifiedOffset 748, 21 lines modified
755 if·!·rpm·-q·--quiet·"aide"·;·then748 if·!·rpm·-q·--quiet·"aide"·;·then
756 ····yum·install·-y·"aide"749 ····yum·install·-y·"aide"
757 fi750 fi
  
758 else751 else
759 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'752 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
760 fi753 fi
 754 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 755 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 756 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 757 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 758 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 759 package·--add=aide
761 Group  ·Federal·Information·Processing·Standard·(FIPS)·  Group·contains·3·rules760 Group  ·Federal·Information·Processing·Standard·(FIPS)·  Group·contains·3·rules
762 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·Federal·Information·Processing·Standard·(FIPS)·is·a·computer·security·standard·which·is·developed·by·the·U.S.·Government·and·industry·working·groups·to·validate·the·quality·of·cryptographic·modules.·The·FIPS·standard·provides·four·security·levels·to·ensure·adequate·coverage·of·different·industries,·implementation·of·cryptographic·modules,·and·organizational·sizes·and·requirements.761 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·Federal·Information·Processing·Standard·(FIPS)·is·a·computer·security·standard·which·is·developed·by·the·U.S.·Government·and·industry·working·groups·to·validate·the·quality·of·cryptographic·modules.·The·FIPS·standard·provides·four·security·levels·to·ensure·adequate·coverage·of·different·industries,·implementation·of·cryptographic·modules,·and·organizational·sizes·and·requirements.
  
763 FIPS·140-2·is·the·current·standard·for·validating·that·mechanisms·used·to·access·cryptographic·modules·utilize·authentication·that·meets·industry·and·government·requirements.·For·government·systems,·this·allows·Security·Levels·1,·2,·3,·or·4·for·use·on·Oracle·Linux·9.762 FIPS·140-2·is·the·current·standard·for·validating·that·mechanisms·used·to·access·cryptographic·modules·utilize·authentication·that·meets·industry·and·government·requirements.·For·government·systems,·this·allows·Security·Levels·1,·2,·3,·or·4·for·use·on·Oracle·Linux·9.
  
764 See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8c\x8c_\x8s\x8s_\x8r\x8r_\x8c\x8c_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8l\x8l_\x8i\x8i_\x8c\x8c_\x8a\x8a_\x8t\x8t_\x8i\x8i_\x8o\x8o_\x8n\x8n_\x8s\x8s_\x8/\x8/_\x8P\x8P_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x8h\x8h_\x8t\x8t_\x8m\x8m_\x8l\x8l·for·more·information.763 See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8c\x8c_\x8s\x8s_\x8r\x8r_\x8c\x8c_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8l\x8l_\x8i\x8i_\x8c\x8c_\x8a\x8a_\x8t\x8t_\x8i\x8i_\x8o\x8o_\x8n\x8n_\x8s\x8s_\x8/\x8/_\x8P\x8P_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x8h\x8h_\x8t\x8t_\x8m\x8m_\x8l\x8l·for·more·information.
765 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·D\x8Dr\x8ra\x8ac\x8cu\x8ut\x8t·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8du\x8ul\x8le\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*764 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·D\x8Dr\x8ra\x8ac\x8cu\x8ut\x8t·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8du\x8ul\x8le\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
Offset 1163, 21 lines modifiedOffset 1163, 14 lines modified
1163 ··-·PCI-DSSv4-2.2.61163 ··-·PCI-DSSv4-2.2.6
1164 ··-·enable_strategy1164 ··-·enable_strategy
1165 ··-·low_complexity1165 ··-·low_complexity
1166 ··-·low_disruption1166 ··-·low_disruption
1167 ··-·medium_severity1167 ··-·medium_severity
1168 ··-·no_reboot_needed1168 ··-·no_reboot_needed
1169 ··-·package_sudo_installed1169 ··-·package_sudo_installed
1170 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
1171 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
1172 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
1173 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
1174 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
1175 package·--add=sudo 
1176 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81170 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
1177 [[packages]]1171 [[packages]]
1178 name·=·"sudo"1172 name·=·"sudo"
1179 version·=·"*"1173 version·=·"*"
1180 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81174 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1181 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1175 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 1202, 14 lines modifiedOffset 1195, 21 lines modified
1202 if·!·rpm·-q·--quiet·"sudo"·;·then1195 if·!·rpm·-q·--quiet·"sudo"·;·then
1203 ····yum·install·-y·"sudo"1196 ····yum·install·-y·"sudo"
1204 fi1197 fi
  
1205 else1198 else
1206 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'1199 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
1207 fi1200 fi
 1201 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 1202 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1203 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1204 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1205 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 1206 package·--add=sudo
1208 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·U\x8Us\x8se\x8er\x8rs\x8s·R\x8Re\x8e-\x8-A\x8Au\x8ut\x8th\x8he\x8en\x8nt\x8ti\x8ic\x8ca\x8at\x8te\x8e·f\x8fo\x8or\x8r·P\x8Pr\x8ri\x8iv\x8vi\x8il\x8le\x8eg\x8ge\x8e·E\x8Es\x8sc\x8ca\x8al\x8la\x8at\x8ti\x8io\x8on\x8n·-\x8-·s\x8su\x8ud\x8do\x8o·!\x8!a\x8au\x8ut\x8th\x8he\x8en\x8nt\x8ti\x8ic\x8ca\x8at\x8te\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*1207 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·U\x8Us\x8se\x8er\x8rs\x8s·R\x8Re\x8e-\x8-A\x8Au\x8ut\x8th\x8he\x8en\x8nt\x8ti\x8ic\x8ca\x8at\x8te\x8e·f\x8fo\x8or\x8r·P\x8Pr\x8ri\x8iv\x8vi\x8il\x8le\x8eg\x8ge\x8e·E\x8Es\x8sc\x8ca\x8al\x8la\x8at\x8ti\x8io\x8on\x8n·-\x8-·s\x8su\x8ud\x8do\x8o·!\x8!a\x8au\x8ut\x8th\x8he\x8en\x8nt\x8ti\x8ic\x8ca\x8at\x8te\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
1209 The·sudo·!authenticate·option,·when·specified,·allows·a·user·to·execute·commands·using·sudo·without·having·to·authenticate.·This·should·be·disabled·by·making·sure·that·the·!authenticate·option·does·not·exist·in·/etc/sudoers·configuration·file·or·any·sudo·configuration·snippets·in·/etc/sudoers.d/.1208 The·sudo·!authenticate·option,·when·specified,·allows·a·user·to·execute·commands·using·sudo·without·having·to·authenticate.·This·should·be·disabled·by·making·sure·that·the·!authenticate·option·does·not·exist·in·/etc/sudoers·configuration·file·or·any·sudo·configuration·snippets·in·/etc/sudoers.d/.
1210 ············Without·re-authentication,·users·may·access·resources·or·perform·tasks·for·which·they·do·not·have·authorization.1209 ············Without·re-authentication,·users·may·access·resources·or·perform·tasks·for·which·they·do·not·have·authorization.
1211 Rationale:1210 Rationale:
1212 ············When·operating·systems·provide·the·capability·to·escalate·a·functional·capability,·it·is·critical·that·the·user·re-authenticate.1211 ············When·operating·systems·provide·the·capability·to·escalate·a·functional·capability,·it·is·critical·that·the·user·re-authenticate.
1213 Severity: ··medium1212 Severity: ··medium
1214 Rule·ID:····xccdf_org.ssgproject.content_rule_sudo_remove_no_authenticate1213 Rule·ID:····xccdf_org.ssgproject.content_rule_sudo_remove_no_authenticate
Offset 1512, 21 lines modifiedOffset 1512, 14 lines modified
1512 ··tags:1512 ··tags:
1513 ··-·enable_strategy1513 ··-·enable_strategy
1514 ··-·low_complexity1514 ··-·low_complexity
1515 ··-·low_disruption1515 ··-·low_disruption
1516 ··-·medium_severity1516 ··-·medium_severity
1517 ··-·no_reboot_needed1517 ··-·no_reboot_needed
1518 ··-·package_rear_installed1518 ··-·package_rear_installed
1519 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
1520 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
1521 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
1522 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
1523 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
1524 package·--add=rear 
1525 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81519 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
1526 [[packages]]1520 [[packages]]
1527 name·=·"rear"1521 name·=·"rear"
1528 version·=·"*"1522 version·=·"*"
1529 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81523 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1530 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1524 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 1551, 14 lines modifiedOffset 1544, 21 lines modified
1551 if·!·rpm·-q·--quiet·"rear"·;·then1544 if·!·rpm·-q·--quiet·"rear"·;·then
1552 ····yum·install·-y·"rear"1545 ····yum·install·-y·"rear"
1553 fi1546 fi
  
1554 else1547 else
1555 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'1548 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
1556 fi1549 fi
 1550 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 1551 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1552 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1553 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1554 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 1555 package·--add=rear
1557 Group  ·Updating·Software·  Group·contains·7·rules1556 Group  ·Updating·Software·  Group·contains·7·rules
1558 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·yum·command·line·tool·is·used·to·install·and·update·software·packages.·The·system·also·provides·a·graphical·software·update·tool·in·the·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·menu,·in·the·A\x8Ad\x8dm\x8mi\x8in\x8ni\x8is\x8st\x8tr\x8ra\x8at\x8ti\x8io\x8on\x8n·submenu,·called·S\x8So\x8of\x8ft\x8tw\x8wa\x8ar\x8re\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8e.1557 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·yum·command·line·tool·is·used·to·install·and·update·software·packages.·The·system·also·provides·a·graphical·software·update·tool·in·the·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·menu,·in·the·A\x8Ad\x8dm\x8mi\x8in\x8ni\x8is\x8st\x8tr\x8ra\x8at\x8ti\x8io\x8on\x8n·submenu,·called·S\x8So\x8of\x8ft\x8tw\x8wa\x8ar\x8re\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8e.
  
Max diff block lines reached; 36246/42506 bytes (85.27%) of diff not shown.
440 KB
./usr/share/doc/ssg-nondebian/ssg-ol9-guide-ospp.html
    
Offset 15917, 136 lines modifiedOffset 15917, 136 lines modified
0003e2c0:·612d·7461·7267·6574·3d22·2369·646d·3639··a-target="#idm690003e2c0:·612d·7461·7267·6574·3d22·2369·646d·3639··a-target="#idm69
0003e2d0:·3635·2220·7461·6269·6e64·6578·3d22·3022··65"·tabindex="0"0003e2d0:·3635·2220·7461·6269·6e64·6578·3d22·3022··65"·tabindex="0"
0003e2e0:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a0003e2e0:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
0003e2f0:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa0003e2f0:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
0003e300:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti0003e300:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
0003e310:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·0003e310:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
0003e320:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi0003e320:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
0003e330:·6174·696f·6e20·416e·6163·6f6e·6461·2073··ation·Anaconda·s 
0003e340:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b 
0003e350:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa 
0003e360:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col 
0003e370:·6c61·7073·6522·2069·643d·2269·646d·3639··lapse"·id="idm69 
0003e380:·3635·223e·3c74·6162·6c65·2063·6c61·7373··65"><table·class 
0003e390:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st0003e330:·6174·696f·6e20·4f53·4275·696c·6420·426c··ation·OSBuild·Bl
 0003e340:·7565·7072·696e·7420·736e·6970·7065·7420··ueprint·snippet·
 0003e350:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·
 0003e360:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col
 0003e370:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·
 0003e380:·6964·3d22·6964·6d36·3936·3522·3e3c·7072··id="idm6965"><pr
 0003e390:·653e·3c63·6f64·653e·0a5b·5b70·6163·6b61··e><code>.[[packa
 0003e3a0:·6765·735d·5d0a·6e61·6d65·203d·2022·6372··ges]].name·=·"cr
 0003e3b0:·7970·746f·2d70·6f6c·6963·6965·7322·0a76··ypto-policies".v
 0003e3c0:·6572·7369·6f6e·203d·2022·2a22·0a3c·2f63··ersion·=·"*".</c
 0003e3d0:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div>
 0003e3e0:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt
 0003e3f0:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data-
 0003e400:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse
 0003e410:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
 0003e420:·6964·6d36·3936·3622·2074·6162·696e·6465··idm6966"·tabinde
 0003e430:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt
 0003e440:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande
 0003e450:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=
 0003e460:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev
 0003e470:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R
 0003e480:·656d·6564·6961·7469·6f6e·2050·7570·7065··emediation·Puppe
 0003e490:·7420·736e·6970·7065·7420·e287·b23c·2f61··t·snippet·...</a
 0003e4a0:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
 0003e4b0:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
 0003e4c0:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
 0003e4d0:·6d36·3936·3622·3e3c·7461·626c·6520·636c··m6966"><table·cl
 0003e4e0:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table
 0003e4f0:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b
0003e3a0:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord0003e500:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co
0003e3b0:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde 
0003e3c0:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co 
0003e3d0:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t0003e510:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th
 0003e520:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th
 0003e530:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
 0003e540:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup
 0003e550:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo
 0003e560:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
 0003e570:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th><
 0003e580:·7464·3e66·616c·7365·3c2f·7464·3e3c·2f74··td>false</td></t
 0003e590:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate
 0003e5a0:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab
 0003e5b0:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta
 0003e5c0:·626c·653e·3c70·7265·3e3c·636f·6465·3e69··ble><pre><code>i
 0003e5d0:·6e63·6c75·6465·2069·6e73·7461·6c6c·5f63··nclude·install_c
 0003e5e0:·7279·7074·6f2d·706f·6c69·6369·6573·0a0a··rypto-policies..
 0003e5f0:·636c·6173·7320·696e·7374·616c·6c5f·6372··class·install_cr
 0003e600:·7970·746f·2d70·6f6c·6963·6965·7320·7b0a··ypto-policies·{.
 0003e610:·2020·7061·636b·6167·6520·7b20·2763·7279····package·{·'cry
 0003e620:·7074·6f2d·706f·6c69·6369·6573·273a·0a20··pto-policies':.·
 0003e630:·2020·2065·6e73·7572·6520·3d26·6774·3b20·····ensure·=&gt;·
 0003e640:·2769·6e73·7461·6c6c·6564·272c·0a20·207d··'installed',.··}
 0003e650:·0a7d·0a3c·2f63·6f64·653e·3c2f·7072·653e··.}.</code></pre>
 0003e660:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class="
 0003e670:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success"
 0003e680:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co
 0003e690:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar
 0003e6a0:·6765·743d·2223·6964·6d36·3936·3722·2074··get="#idm6967"·t
 0003e6b0:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
 0003e6c0:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
 0003e6d0:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
 0003e6e0:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
 0003e6f0:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
 0003e700:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
 0003e710:·2053·6865·6c6c·2073·6372·6970·7420·e287···Shell·script·..
 0003e720:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl
 0003e730:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla
 0003e740:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id
 0003e750:·3d22·6964·6d36·3936·3722·3e3c·7461·626c··="idm6967"><tabl
 0003e760:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t
 0003e770:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab
 0003e780:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl
 0003e790:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr
 0003e7a0:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:
 0003e7b0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
 0003e7c0:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di
 0003e7d0:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t
0003e3e0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><0003e7e0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
0003e3f0:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio 
0003e400:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</0003e7f0:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</
 0003e800:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td
0003e410:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>0003e810:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St
0003e420:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td>0003e820:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>
0003e430:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr>< 
0003e440:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy: 
0003e450:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable< 
0003e460:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table 
0003e470:·3e3c·7072·653e·3c63·6f64·653e·0a70·6163··><pre><code>.pac 
0003e480:·6b61·6765·202d·2d61·6464·3d63·7279·7074··kage·--add=crypt 
0003e490:·6f2d·706f·6c69·6369·6573·0a3c·2f63·6f64··o-policies.</cod0003e830:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr>
 0003e840:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co
 0003e850:·6465·3e0a·6966·2021·2072·706d·202d·7120··de>.if·!·rpm·-q·
 0003e860:·2d2d·7175·6965·7420·2263·7279·7074·6f2d··--quiet·"crypto-
 0003e870:·706f·6c69·6369·6573·2220·3b20·7468·656e··policies"·;·then
 0003e880:·0a20·2020·2079·756d·2069·6e73·7461·6c6c··.····yum·install
 0003e890:·202d·7920·2263·7279·7074·6f2d·706f·6c69···-y·"crypto-poli
 0003e8a0:·6369·6573·220a·6669·0a3c·2f63·6f64·653e··cies".fi.</code>
0003e4a0:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a0003e8b0:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c
0003e4b0:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn-0003e8c0:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su
0003e4c0:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to0003e8d0:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg
0003e4d0:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"·0003e8e0:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da
0003e4e0:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id0003e8f0:·7461·2d74·6172·6765·743d·2223·6964·6d36··ta-target="#idm6
0003e4f0:·6d36·3936·3622·2074·6162·696e·6465·783d··m6966"·tabindex=0003e900:·3936·3822·2074·6162·696e·6465·783d·2230··968"·tabindex="0
0003e500:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button0003e910:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
0003e510:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=0003e920:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
0003e520:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A0003e930:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
0003e530:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea0003e940:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
0003e540:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem0003e950:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
 0003e960:·6961·7469·6f6e·2041·6e61·636f·6e64·6120··iation·Anaconda·
 0003e970:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><
 0003e980:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
 0003e990:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
 0003e9a0:·6c6c·6170·7365·2220·6964·3d22·6964·6d36··llapse"·id="idm6
 0003e9b0:·3936·3822·3e3c·7461·626c·6520·636c·6173··968"><table·clas
Max diff block lines reached; 388860/406276 bytes (95.71%) of diff not shown.
43.2 KB
html2text {}
    
Offset 267, 21 lines modifiedOffset 267, 14 lines modified
267 ··tags:267 ··tags:
268 ··-·enable_strategy268 ··-·enable_strategy
269 ··-·low_complexity269 ··-·low_complexity
270 ··-·low_disruption270 ··-·low_disruption
271 ··-·medium_severity271 ··-·medium_severity
272 ··-·no_reboot_needed272 ··-·no_reboot_needed
273 ··-·package_crypto-policies_installed273 ··-·package_crypto-policies_installed
274 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
275 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
276 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
277 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
278 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
279 package·--add=crypto-policies 
280 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8274 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
281 [[packages]]275 [[packages]]
282 name·=·"crypto-policies"276 name·=·"crypto-policies"
283 version·=·"*"277 version·=·"*"
284 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8278 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
285 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low279 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 300, 14 lines modifiedOffset 293, 21 lines modified
300 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low293 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
301 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false294 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
302 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable295 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
303 if·!·rpm·-q·--quiet·"crypto-policies"·;·then296 if·!·rpm·-q·--quiet·"crypto-policies"·;·then
304 ····yum·install·-y·"crypto-policies"297 ····yum·install·-y·"crypto-policies"
305 fi298 fi
 299 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 300 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 301 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 302 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 303 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 304 package·--add=crypto-policies
306 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8og\x8gr\x8ra\x8ap\x8ph\x8hy\x8y·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*305 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8og\x8gr\x8ra\x8ap\x8ph\x8hy\x8y·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
307 To·configure·the·system·cryptography·policy·to·use·ciphers·only·from·the·FIPS:OSPP·policy,·run·the·following·command:306 To·configure·the·system·cryptography·policy·to·use·ciphers·only·from·the·FIPS:OSPP·policy,·run·the·following·command:
308 $·sudo·update-crypto-policies·--set·FIPS:OSPP307 $·sudo·update-crypto-policies·--set·FIPS:OSPP
309 The·rule·checks·if·settings·for·selected·crypto·policy·are·configured·as·expected.·Configuration·files·in·the·/etc/crypto-policies/back-ends·are·either·symlinks·to·correct·files·provided·by·Crypto-policies·package·or·they·are·regular·files·in·case·crypto·policy·customizations·are·applied.·Crypto·policies·may·be·customized·by·crypto·policy·modules,·in·which·case·it·is·delimited·from·the·base·policy·using·a·colon.308 The·rule·checks·if·settings·for·selected·crypto·policy·are·configured·as·expected.·Configuration·files·in·the·/etc/crypto-policies/back-ends·are·either·symlinks·to·correct·files·provided·by·Crypto-policies·package·or·they·are·regular·files·in·case·crypto·policy·customizations·are·applied.·Crypto·policies·may·be·customized·by·crypto·policy·modules,·in·which·case·it·is·delimited·from·the·base·policy·using·a·colon.
310 Warning: ·The·system·needs·to·be·rebooted·for·these·changes·to·take·effect.309 Warning: ·The·system·needs·to·be·rebooted·for·these·changes·to·take·effect.
311 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8n\x8n_\x8v\x8v_\x8l\x8l_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8/\x8/_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8/\x8/_\x8N\x8N_\x8I\x8I_\x8S\x8S_\x8T\x8T_\x8.\x8._\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x81\x81_\x84\x84_\x80\x80_\x8-\x8-_\x82\x82_\x8.\x8._\x8p\x8p_\x8d\x8d_\x8f\x8f·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.310 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8n\x8n_\x8v\x8v_\x8l\x8l_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8/\x8/_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8/\x8/_\x8N\x8N_\x8I\x8I_\x8S\x8S_\x8T\x8T_\x8.\x8._\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x81\x81_\x84\x84_\x80\x80_\x8-\x8-_\x82\x82_\x8.\x8._\x8p\x8p_\x8d\x8d_\x8f\x8f·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.
312 Rationale:··Centralized·cryptographic·policies·simplify·applying·secure·ciphers·across·an·operating·system·and·the·applications·that·run·on·that·operating·system.·Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.311 Rationale:··Centralized·cryptographic·policies·simplify·applying·secure·ciphers·across·an·operating·system·and·the·applications·that·run·on·that·operating·system.·Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.
Offset 658, 21 lines modifiedOffset 658, 14 lines modified
658 ··-·PCI-DSSv4-2.2.6658 ··-·PCI-DSSv4-2.2.6
659 ··-·enable_strategy659 ··-·enable_strategy
660 ··-·low_complexity660 ··-·low_complexity
661 ··-·low_disruption661 ··-·low_disruption
662 ··-·medium_severity662 ··-·medium_severity
663 ··-·no_reboot_needed663 ··-·no_reboot_needed
664 ··-·package_sudo_installed664 ··-·package_sudo_installed
665 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
666 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
667 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
668 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
669 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
670 package·--add=sudo 
671 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8665 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
672 [[packages]]666 [[packages]]
673 name·=·"sudo"667 name·=·"sudo"
674 version·=·"*"668 version·=·"*"
675 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8669 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
676 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low670 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 697, 14 lines modifiedOffset 690, 21 lines modified
697 if·!·rpm·-q·--quiet·"sudo"·;·then690 if·!·rpm·-q·--quiet·"sudo"·;·then
698 ····yum·install·-y·"sudo"691 ····yum·install·-y·"sudo"
699 fi692 fi
  
700 else693 else
701 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'694 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
702 fi695 fi
 696 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 697 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 698 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 699 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 700 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 701 package·--add=sudo
703 Group  ·System·Tooling·/·Utilities·  Group·contains·3·rules702 Group  ·System·Tooling·/·Utilities·  Group·contains·3·rules
704 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·following·checks·evaluate·the·system·for·recommended·base·packages·--·both·for·installation·and·removal.703 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·following·checks·evaluate·the·system·for·recommended·base·packages·--·both·for·installation·and·removal.
705 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·g\x8gn\x8nu\x8ut\x8tl\x8ls\x8s-\x8-u\x8ut\x8ti\x8il\x8ls\x8s·i\x8is\x8s·i\x8in\x8ns\x8st\x8ta\x8al\x8ll\x8le\x8ed\x8d·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*704 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·g\x8gn\x8nu\x8ut\x8tl\x8ls\x8s-\x8-u\x8ut\x8ti\x8il\x8ls\x8s·i\x8is\x8s·i\x8in\x8ns\x8st\x8ta\x8al\x8ll\x8le\x8ed\x8d·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
706 The·gnutls-utils·package·can·be·installed·with·the·following·command:705 The·gnutls-utils·package·can·be·installed·with·the·following·command:
707 $·sudo·yum·install·gnutls-utils706 $·sudo·yum·install·gnutls-utils
708 Rationale:··GnuTLS·is·a·secure·communications·library·implementing·the·SSL,·TLS·and·DTLS·protocols·and·technologies·around·them.·It·provides·a·simple·C·language·application·programming·interface·(API)·to·access·the·secure·communications·protocols·as·well·as·APIs·to·parse·and·write·X.509,·PKCS·#12,·OpenPGP·and·other·required·structures.·This·package·contains·command·line·TLS·client·and·server·and·certificate·manipulation·tools.707 Rationale:··GnuTLS·is·a·secure·communications·library·implementing·the·SSL,·TLS·and·DTLS·protocols·and·technologies·around·them.·It·provides·a·simple·C·language·application·programming·interface·(API)·to·access·the·secure·communications·protocols·as·well·as·APIs·to·parse·and·write·X.509,·PKCS·#12,·OpenPGP·and·other·required·structures.·This·package·contains·command·line·TLS·client·and·server·and·certificate·manipulation·tools.
709 Severity: ··medium708 Severity: ··medium
Offset 724, 21 lines modifiedOffset 724, 14 lines modified
724 ··tags:724 ··tags:
725 ··-·enable_strategy725 ··-·enable_strategy
726 ··-·low_complexity726 ··-·low_complexity
727 ··-·low_disruption727 ··-·low_disruption
728 ··-·medium_severity728 ··-·medium_severity
729 ··-·no_reboot_needed729 ··-·no_reboot_needed
730 ··-·package_gnutls-utils_installed730 ··-·package_gnutls-utils_installed
731 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
732 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
733 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
734 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
735 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
736 package·--add=gnutls-utils 
737 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8731 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
738 [[packages]]732 [[packages]]
739 name·=·"gnutls-utils"733 name·=·"gnutls-utils"
740 version·=·"*"734 version·=·"*"
741 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8735 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
742 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low736 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 757, 14 lines modifiedOffset 750, 21 lines modified
757 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low750 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
758 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false751 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
759 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable752 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
760 if·!·rpm·-q·--quiet·"gnutls-utils"·;·then753 if·!·rpm·-q·--quiet·"gnutls-utils"·;·then
761 ····yum·install·-y·"gnutls-utils"754 ····yum·install·-y·"gnutls-utils"
762 fi755 fi
 756 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 757 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 758 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 759 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 760 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 761 package·--add=gnutls-utils
763 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·o\x8op\x8pe\x8en\x8ns\x8sc\x8ca\x8ap\x8p-\x8-s\x8sc\x8ca\x8an\x8nn\x8ne\x8er\x8r·P\x8Pa\x8ac\x8ck\x8ka\x8ag\x8ge\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*762 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·o\x8op\x8pe\x8en\x8ns\x8sc\x8ca\x8ap\x8p-\x8-s\x8sc\x8ca\x8an\x8nn\x8ne\x8er\x8r·P\x8Pa\x8ac\x8ck\x8ka\x8ag\x8ge\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
764 The·openscap-scanner·package·can·be·installed·with·the·following·command:763 The·openscap-scanner·package·can·be·installed·with·the·following·command:
765 $·sudo·yum·install·openscap-scanner764 $·sudo·yum·install·openscap-scanner
Max diff block lines reached; 36906/44251 bytes (83.40%) of diff not shown.
344 KB
./usr/share/doc/ssg-nondebian/ssg-ol9-guide-pci-dss.html
    
Offset 16642, 144 lines modifiedOffset 16642, 144 lines modified
00041010:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm00041010:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
00041020:·3632·3830·2220·7461·6269·6e64·6578·3d22··6280"·tabindex="00041020:·3632·3830·2220·7461·6269·6e64·6578·3d22··6280"·tabindex="
00041030:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"00041030:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
00041040:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="00041040:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
00041050:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac00041050:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
00041060:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal00041060:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
00041070:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme00041070:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
 00041080:·6469·6174·696f·6e20·4f53·4275·696c·6420··diation·OSBuild·
 00041090:·426c·7565·7072·696e·7420·736e·6970·7065··Blueprint·snippe
 000410a0:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di
 000410b0:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c
 000410c0:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse
 000410d0:·2220·6964·3d22·6964·6d36·3238·3022·3e3c··"·id="idm6280"><
 000410e0:·7072·653e·3c63·6f64·653e·0a5b·5b70·6163··pre><code>.[[pac
 000410f0:·6b61·6765·735d·5d0a·6e61·6d65·203d·2022··kages]].name·=·"
 00041100:·6169·6465·220a·7665·7273·696f·6e20·3d20··aide".version·=·
 00041110:·222a·220a·3c2f·636f·6465·3e3c·2f70·7265··"*".</code></pre
 00041120:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class=
 00041130:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success
 00041140:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c
 00041150:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta
 00041160:·7267·6574·3d22·2369·646d·3632·3831·2220··rget="#idm6281"·
 00041170:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol
 00041180:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-
 00041190:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"
 000411a0:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate
 000411b0:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href
 000411c0:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio
 000411d0:·6e20·5075·7070·6574·2073·6e69·7070·6574··n·Puppet·snippet
 000411e0:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
 000411f0:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
 00041200:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
 00041210:·2069·643d·2269·646d·3632·3831·223e·3c74···id="idm6281"><t
 00041220:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl
 00041230:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·
 00041240:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t
 00041250:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">
 00041260:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi
 00041270:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<
 00041280:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 00041290:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th
 000412a0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
 000412b0:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot
 000412c0:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false<
 000412d0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 000412e0:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><
 000412f0:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></
 00041300:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>
 00041310:·3c63·6f64·653e·696e·636c·7564·6520·696e··<code>include·in
 00041320:·7374·616c·6c5f·6169·6465·0a0a·636c·6173··stall_aide..clas
 00041330:·7320·696e·7374·616c·6c5f·6169·6465·207b··s·install_aide·{
 00041340:·0a20·2070·6163·6b61·6765·207b·2027·6169··.··package·{·'ai
 00041350:·6465·273a·0a20·2020·2065·6e73·7572·6520··de':.····ensure·
 00041360:·3d26·6774·3b20·2769·6e73·7461·6c6c·6564··=&gt;·'installed
 00041370:·272c·0a20·207d·0a7d·0a3c·2f63·6f64·653e··',.··}.}.</code>
 00041380:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c
 00041390:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su
 000413a0:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg
 000413b0:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da
 000413c0:·7461·2d74·6172·6765·743d·2223·6964·6d36··ta-target="#idm6
 000413d0:·3238·3222·2074·6162·696e·6465·783d·2230··282"·tabindex="0
 000413e0:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
 000413f0:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
 00041400:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
 00041410:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
 00041420:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
 00041430:·6961·7469·6f6e·2053·6865·6c6c·2073·6372··iation·Shell·scr
 00041440:·6970·7420·e287·b23c·2f61·3e3c·6272·3e3c··ipt·...</a><br><
 00041450:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
 00041460:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap
 00041470:·7365·2220·6964·3d22·6964·6d36·3238·3222··se"·id="idm6282"
 00041480:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t
 00041490:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip
 000414a0:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere
 000414b0:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense
 000414c0:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl
 000414d0:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l
 000414e0:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
 000414f0:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:<
 00041500:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
 00041510:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb
 00041520:·6f6f·743a·3c2f·7468·3e3c·7464·3e66·616c··oot:</th><td>fal
 00041530:·7365·3c2f·7464·3e3c·2f74·723e·3c74·723e··se</td></tr><tr>
 00041540:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t
 00041550:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td
 00041560:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p
 00041570:·7265·3e3c·636f·6465·3e23·2052·656d·6564··re><code>#·Remed
 00041580:·6961·7469·6f6e·2069·7320·6170·706c·6963··iation·is·applic
 00041590:·6162·6c65·206f·6e6c·7920·696e·2063·6572··able·only·in·cer
 000415a0:·7461·696e·2070·6c61·7466·6f72·6d73·0a69··tain·platforms.i
 000415b0:·6620·7270·6d20·2d2d·7175·6965·7420·2d71··f·rpm·--quiet·-q
 000415c0:·206b·6572·6e65·6c20·7c7c·2072·706d·202d···kernel·||·rpm·-
 000415d0:·2d71·7569·6574·202d·7120·6b65·726e·656c··-quiet·-q·kernel
 000415e0:·2d75·656b·3b20·7468·656e·0a0a·6966·2021··-uek;·then..if·!
 000415f0:·2072·706d·202d·7120·2d2d·7175·6965·7420···rpm·-q·--quiet·
 00041600:·2261·6964·6522·203b·2074·6865·6e0a·2020··"aide"·;·then.··
 00041610:·2020·7975·6d20·696e·7374·616c·6c20·2d79····yum·install·-y
 00041620:·2022·6169·6465·220a·6669·0a0a·656c·7365···"aide".fi..else
 00041630:·0a20·2020·2026·6774·3b26·616d·703b·3220··.····&gt;&amp;2·
 00041640:·6563·686f·2027·5265·6d65·6469·6174·696f··echo·'Remediatio
 00041650:·6e20·6973·206e·6f74·2061·7070·6c69·6361··n·is·not·applica
 00041660:·626c·652c·206e·6f74·6869·6e67·2077·6173··ble,·nothing·was
 00041670:·2064·6f6e·6527·0a66·690a·3c2f·636f·6465···done'.fi.</code
 00041680:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a·
 00041690:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s
 000416a0:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog
 000416b0:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d
 000416c0:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
 000416d0:·3632·3833·2220·7461·6269·6e64·6578·3d22··6283"·tabindex="
 000416e0:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
 000416f0:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
 00041700:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
 00041710:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
 00041720:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
00041080:·6469·6174·696f·6e20·416e·6163·6f6e·6461··diation·Anaconda00041730:·6469·6174·696f·6e20·416e·6163·6f6e·6461··diation·Anaconda
00041090:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>00041740:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>
000410a0:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="00041750:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="
000410b0:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c00041760:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c
000410c0:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm00041770:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm
000410d0:·3632·3830·223e·3c74·6162·6c65·2063·6c61··6280"><table·cla00041780:·3632·3833·223e·3c74·6162·6c65·2063·6c61··6283"><table·cla
000410e0:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-00041790:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-
000410f0:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo000417a0:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo
00041100:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con000417b0:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con
00041110:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th> 
00041120:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th> 
00041130:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
00041140:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt 
Max diff block lines reached; 296094/314614 bytes (94.11%) of diff not shown.
36.3 KB
html2text {}
    
Offset 530, 21 lines modifiedOffset 530, 14 lines modified
530 ··-·PCI-DSSv4-11.5.2530 ··-·PCI-DSSv4-11.5.2
531 ··-·enable_strategy531 ··-·enable_strategy
532 ··-·low_complexity532 ··-·low_complexity
533 ··-·low_disruption533 ··-·low_disruption
534 ··-·medium_severity534 ··-·medium_severity
535 ··-·no_reboot_needed535 ··-·no_reboot_needed
536 ··-·package_aide_installed536 ··-·package_aide_installed
537 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
538 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
539 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
540 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
541 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
542 package·--add=aide 
543 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8537 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
544 [[packages]]538 [[packages]]
545 name·=·"aide"539 name·=·"aide"
546 version·=·"*"540 version·=·"*"
547 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8541 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
548 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low542 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 569, 14 lines modifiedOffset 562, 21 lines modified
569 if·!·rpm·-q·--quiet·"aide"·;·then562 if·!·rpm·-q·--quiet·"aide"·;·then
570 ····yum·install·-y·"aide"563 ····yum·install·-y·"aide"
571 fi564 fi
  
572 else565 else
573 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'566 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
574 fi567 fi
 568 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 569 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 570 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 571 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 572 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 573 package·--add=aide
575 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*574 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
576 Run·the·following·command·to·generate·a·new·database:575 Run·the·following·command·to·generate·a·new·database:
577 $·sudo·/usr/sbin/aide·--init576 $·sudo·/usr/sbin/aide·--init
578 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:577 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
579 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz578 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
580 To·initiate·a·manual·check,·run·the·following·command:579 To·initiate·a·manual·check,·run·the·following·command:
581 $·sudo·/usr/sbin/aide·--check580 $·sudo·/usr/sbin/aide·--check
Offset 2586, 21 lines modifiedOffset 2586, 14 lines modified
2586 ··-·PCI-DSSv4-2.2.62586 ··-·PCI-DSSv4-2.2.6
2587 ··-·enable_strategy2587 ··-·enable_strategy
2588 ··-·low_complexity2588 ··-·low_complexity
2589 ··-·low_disruption2589 ··-·low_disruption
2590 ··-·medium_severity2590 ··-·medium_severity
2591 ··-·no_reboot_needed2591 ··-·no_reboot_needed
2592 ··-·package_sudo_installed2592 ··-·package_sudo_installed
2593 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
2594 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
2595 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
2596 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
2597 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
2598 package·--add=sudo 
2599 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x82593 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
2600 [[packages]]2594 [[packages]]
2601 name·=·"sudo"2595 name·=·"sudo"
2602 version·=·"*"2596 version·=·"*"
2603 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x82597 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
2604 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low2598 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 2625, 14 lines modifiedOffset 2618, 21 lines modified
2625 if·!·rpm·-q·--quiet·"sudo"·;·then2618 if·!·rpm·-q·--quiet·"sudo"·;·then
2626 ····yum·install·-y·"sudo"2619 ····yum·install·-y·"sudo"
2627 fi2620 fi
  
2628 else2621 else
2629 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'2622 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
2630 fi2623 fi
 2624 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 2625 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 2626 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 2627 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 2628 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 2629 package·--add=sudo
2631 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·O\x8On\x8nl\x8ly\x8y·U\x8Us\x8se\x8er\x8rs\x8s·L\x8Lo\x8og\x8gg\x8ge\x8ed\x8d·I\x8In\x8n·T\x8To\x8o·R\x8Re\x8ea\x8al\x8l·t\x8tt\x8ty\x8y·C\x8Ca\x8an\x8n·E\x8Ex\x8xe\x8ec\x8cu\x8ut\x8te\x8e·S\x8Su\x8ud\x8do\x8o·-\x8-·s\x8su\x8ud\x8do\x8o·u\x8us\x8se\x8e_\x8_p\x8pt\x8ty\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*2630 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·O\x8On\x8nl\x8ly\x8y·U\x8Us\x8se\x8er\x8rs\x8s·L\x8Lo\x8og\x8gg\x8ge\x8ed\x8d·I\x8In\x8n·T\x8To\x8o·R\x8Re\x8ea\x8al\x8l·t\x8tt\x8ty\x8y·C\x8Ca\x8an\x8n·E\x8Ex\x8xe\x8ec\x8cu\x8ut\x8te\x8e·S\x8Su\x8ud\x8do\x8o·-\x8-·s\x8su\x8ud\x8do\x8o·u\x8us\x8se\x8e_\x8_p\x8pt\x8ty\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
2632 The·sudo·use_pty·tag,·when·specified,·will·only·execute·sudo·commands·from·users·logged·in·to·a·real·tty.·This·should·be·enabled·by·making·sure·that·the·use_pty·tag·exists·in·/etc/sudoers·configuration·file·or·any·sudo·configuration·snippets·in·/etc/sudoers.d/.2631 The·sudo·use_pty·tag,·when·specified,·will·only·execute·sudo·commands·from·users·logged·in·to·a·real·tty.·This·should·be·enabled·by·making·sure·that·the·use_pty·tag·exists·in·/etc/sudoers·configuration·file·or·any·sudo·configuration·snippets·in·/etc/sudoers.d/.
2633 Rationale:··Requiring·that·sudo·commands·be·run·in·a·pseudo-terminal·can·prevent·an·attacker·from·retaining·access·to·the·user's·terminal·after·the·main·program·has·finished·executing.2632 Rationale:··Requiring·that·sudo·commands·be·run·in·a·pseudo-terminal·can·prevent·an·attacker·from·retaining·access·to·the·user's·terminal·after·the·main·program·has·finished·executing.
2634 Severity: ··medium2633 Severity: ··medium
2635 Rule·ID:····xccdf_org.ssgproject.content_rule_sudo_add_use_pty2634 Rule·ID:····xccdf_org.ssgproject.content_rule_sudo_add_use_pty
2636 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s··Req-10.2.52635 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s··Req-10.2.5
2637 References:·_\x8a_\x8n_\x8s_\x8s_\x8i···R392636 References:·_\x8a_\x8n_\x8s_\x8s_\x8i···R39
Offset 15017, 21 lines modifiedOffset 15017, 14 lines modified
15017 ··-·PCI-DSSv4-10.5.115017 ··-·PCI-DSSv4-10.5.1
15018 ··-·enable_strategy15018 ··-·enable_strategy
15019 ··-·low_complexity15019 ··-·low_complexity
15020 ··-·low_disruption15020 ··-·low_disruption
15021 ··-·medium_severity15021 ··-·medium_severity
15022 ··-·no_reboot_needed15022 ··-·no_reboot_needed
15023 ··-·package_logrotate_installed15023 ··-·package_logrotate_installed
15024 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
15025 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
15026 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
15027 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
15028 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
15029 package·--add=logrotate 
15030 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x815024 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
15031 [[packages]]15025 [[packages]]
15032 name·=·"logrotate"15026 name·=·"logrotate"
15033 version·=·"*"15027 version·=·"*"
15034 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x815028 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
15035 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low15029 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 15056, 14 lines modifiedOffset 15049, 21 lines modified
15056 if·!·rpm·-q·--quiet·"logrotate"·;·then15049 if·!·rpm·-q·--quiet·"logrotate"·;·then
15057 ····yum·install·-y·"logrotate"15050 ····yum·install·-y·"logrotate"
15058 fi15051 fi
  
15059 else15052 else
15060 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'15053 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
15061 fi15054 fi
 15055 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 15056 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 15057 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 15058 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 15059 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 15060 package·--add=logrotate
15062 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·l\x8lo\x8og\x8gr\x8ro\x8ot\x8ta\x8at\x8te\x8e·T\x8Ti\x8im\x8me\x8er\x8r·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*15061 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·l\x8lo\x8og\x8gr\x8ro\x8ot\x8ta\x8at\x8te\x8e·T\x8Ti\x8im\x8me\x8er\x8r·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
15063 The·logrotate·timer·can·be·enabled·with·the·following·command:15062 The·logrotate·timer·can·be·enabled·with·the·following·command:
15064 $·sudo·systemctl·enable·logrotate.timer15063 $·sudo·systemctl·enable·logrotate.timer
Max diff block lines reached; 31535/37117 bytes (84.96%) of diff not shown.
20.5 KB
./usr/share/doc/ssg-nondebian/ssg-ol9-guide-standard.html
    
Offset 23654, 145 lines modifiedOffset 23654, 145 lines modified
0005c650:·2d74·6172·6765·743d·2223·6964·6d31·3934··-target="#idm1940005c650:·2d74·6172·6765·743d·2223·6964·6d31·3934··-target="#idm194
0005c660:·3130·2220·7461·6269·6e64·6578·3d22·3022··10"·tabindex="0"0005c660:·3130·2220·7461·6269·6e64·6578·3d22·3022··10"·tabindex="0"
0005c670:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a0005c670:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
0005c680:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa0005c680:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
0005c690:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti0005c690:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
0005c6a0:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·0005c6a0:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
0005c6b0:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi0005c6b0:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
 0005c6c0:·6174·696f·6e20·4f53·4275·696c·6420·426c··ation·OSBuild·Bl
 0005c6d0:·7565·7072·696e·7420·736e·6970·7065·7420··ueprint·snippet·
 0005c6e0:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·
 0005c6f0:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col
 0005c700:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·
 0005c710:·6964·3d22·6964·6d31·3934·3130·223e·3c70··id="idm19410"><p
0005c6c0:·6174·696f·6e20·416e·6163·6f6e·6461·2073··ation·Anaconda·s 
0005c6d0:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b 
0005c6e0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa 
0005c6f0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col 
0005c700:·6c61·7073·6522·2069·643d·2269·646d·3139··lapse"·id="idm19 
0005c710:·3431·3022·3e3c·7461·626c·6520·636c·6173··410"><table·clas 
0005c720:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s 
0005c730:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor 
0005c740:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond 
0005c750:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C 
0005c760:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th>< 
0005c770:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
0005c780:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti 
0005c790:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low< 
0005c7a0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0005c7b0:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td 
0005c7c0:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr> 
0005c7d0:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy 
0005c7e0:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable 
0005c7f0:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl 
0005c800:·653e·3c70·7265·3e3c·636f·6465·3e0a·7061··e><pre><code>.pa0005c720:·7265·3e3c·636f·6465·3e0a·5b5b·7061·636b··re><code>.[[pack
0005c810:·636b·6167·6520·2d2d·6164·643d·7273·7973··ckage·--add=rsys 
0005c820:·6c6f·670a·3c2f·636f·6465·3e3c·2f70·7265··log.</code></pre0005c730:·6167·6573·5d5d·0a6e·616d·6520·3d20·2272··ages]].name·=·"r
 0005c740:·7379·736c·6f67·220a·7665·7273·696f·6e20··syslog".version·
 0005c750:·3d20·222a·220a·3c2f·636f·6465·3e3c·2f70··=·"*".</code></p
0005c830:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class=0005c760:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas
0005c840:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success0005c770:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe
0005c850:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c0005c780:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle=
0005c860:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta0005c790:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data-
0005c870:·7267·6574·3d22·2369·646d·3139·3431·3122··rget="#idm19411"0005c7a0:·7461·7267·6574·3d22·2369·646d·3139·3431··target="#idm1941
0005c880:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro0005c7b0:·3122·2074·6162·696e·6465·783d·2230·2220··1"·tabindex="0"·
0005c890:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria0005c7c0:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar
0005c8a0:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false0005c7d0:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal
0005c8b0:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat0005c7e0:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ
0005c8c0:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre0005c7f0:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h
0005c8d0:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati0005c800:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia
0005c8e0:·6f6e·204f·5342·7569·6c64·2042·6c75·6570··on·OSBuild·Bluep 
0005c8f0:·7269·6e74·2073·6e69·7070·6574·20e2·87b2··rint·snippet·... 
0005c900:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla 
0005c910:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap0005c810:·7469·6f6e·2050·7570·7065·7420·736e·6970··tion·Puppet·snip
 0005c820:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br><
 0005c830:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
 0005c840:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap
 0005c850:·7365·2220·6964·3d22·6964·6d31·3934·3131··se"·id="idm19411
 0005c860:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="
 0005c870:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri
 0005c880:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border
 0005c890:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens
 0005c8a0:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp
 0005c8b0:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>
 0005c8c0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
 0005c8d0:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:
 0005c8e0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
 0005c8f0:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re
 0005c900:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa
 0005c910:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr
 0005c920:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</
 0005c930:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t
 0005c940:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><
 0005c950:·7072·653e·3c63·6f64·653e·696e·636c·7564··pre><code>includ
 0005c960:·6520·696e·7374·616c·6c5f·7273·7973·6c6f··e·install_rsyslo
 0005c970:·670a·0a63·6c61·7373·2069·6e73·7461·6c6c··g..class·install
 0005c980:·5f72·7379·736c·6f67·207b·0a20·2070·6163··_rsyslog·{.··pac
 0005c990:·6b61·6765·207b·2027·7273·7973·6c6f·6727··kage·{·'rsyslog'
 0005c9a0:·3a0a·2020·2020·656e·7375·7265·203d·2667··:.····ensure·=&g
 0005c9b0:·743b·2027·696e·7374·616c·6c65·6427·2c0a··t;·'installed',.
 0005c9c0:·2020·7d0a·7d0a·3c2f·636f·6465·3e3c·2f70····}.}.</code></p
 0005c9d0:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas
 0005c9e0:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe
 0005c9f0:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle=
0005c920:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=0005ca00:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data-
 0005ca10:·7461·7267·6574·3d22·2369·646d·3139·3431··target="#idm1941
 0005ca20:·3222·2074·6162·696e·6465·783d·2230·2220··2"·tabindex="0"·
 0005ca30:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar
 0005ca40:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal
 0005ca50:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ
 0005ca60:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h
 0005ca70:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia
 0005ca80:·7469·6f6e·2053·6865·6c6c·2073·6372·6970··tion·Shell·scrip
 0005ca90:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di
 0005caa0:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c
 0005cab0:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse
 0005cac0:·2220·6964·3d22·6964·6d31·3934·3132·223e··"·id="idm19412">
 0005cad0:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta
 0005cae0:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe
 0005caf0:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered
0005c930:·2269·646d·3139·3431·3122·3e3c·7072·653e··"idm19411"><pre> 
0005c940:·3c63·6f64·653e·0a5b·5b70·6163·6b61·6765··<code>.[[package 
0005c950:·735d·5d0a·6e61·6d65·203d·2022·7273·7973··s]].name·=·"rsys 
0005c960:·6c6f·6722·0a76·6572·7369·6f6e·203d·2022··log".version·=·" 
0005c970:·2a22·0a3c·2f63·6f64·653e·3c2f·7072·653e··*".</code></pre> 
0005c980:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class=" 
0005c990:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success" 
0005c9a0:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co 
0005c9b0:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar 
0005c9c0:·6765·743d·2223·6964·6d31·3934·3132·2220··get="#idm19412"· 
0005c9d0:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol 
0005c9e0:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria- 
0005c9f0:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false" 
0005ca00:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate 
0005ca10:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href 
0005ca20:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio 
0005ca30:·6e20·5075·7070·6574·2073·6e69·7070·6574··n·Puppet·snippet 
0005ca40:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div 
0005ca50:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co 
0005ca60:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse" 
0005ca70:·2069·643d·2269·646d·3139·3431·3222·3e3c···id="idm19412">< 
0005ca80:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab 
0005ca90:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped 
0005caa0:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·0005cb00:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed
0005cab0:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed" 
0005cac0:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex0005cb10:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple
0005cad0:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low 
0005cae0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
Max diff block lines reached; 414/19072 bytes (2.17%) of diff not shown.
1.79 KB
html2text {}
    
Offset 1724, 21 lines modifiedOffset 1724, 14 lines modified
1724 ··-·NIST-800-53-CM-6(a)1724 ··-·NIST-800-53-CM-6(a)
1725 ··-·enable_strategy1725 ··-·enable_strategy
1726 ··-·low_complexity1726 ··-·low_complexity
1727 ··-·low_disruption1727 ··-·low_disruption
1728 ··-·medium_severity1728 ··-·medium_severity
1729 ··-·no_reboot_needed1729 ··-·no_reboot_needed
1730 ··-·package_rsyslog_installed1730 ··-·package_rsyslog_installed
1731 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
1732 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
1733 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
1734 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
1735 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
1736 package·--add=rsyslog 
1737 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81731 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
1738 [[packages]]1732 [[packages]]
1739 name·=·"rsyslog"1733 name·=·"rsyslog"
1740 version·=·"*"1734 version·=·"*"
1741 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81735 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1742 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1736 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 1763, 14 lines modifiedOffset 1756, 21 lines modified
1763 if·!·rpm·-q·--quiet·"rsyslog"·;·then1756 if·!·rpm·-q·--quiet·"rsyslog"·;·then
1764 ····yum·install·-y·"rsyslog"1757 ····yum·install·-y·"rsyslog"
1765 fi1758 fi
  
1766 else1759 else
1767 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'1760 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
1768 fi1761 fi
 1762 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 1763 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1764 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1765 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1766 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 1767 package·--add=rsyslog
1769 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·r\x8rs\x8sy\x8ys\x8sl\x8lo\x8og\x8g·S\x8Se\x8er\x8rv\x8vi\x8ic\x8ce\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*1768 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·r\x8rs\x8sy\x8ys\x8sl\x8lo\x8og\x8g·S\x8Se\x8er\x8rv\x8vi\x8ic\x8ce\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
1770 The·rsyslog·service·provides·syslog-style·logging·by·default·on·Oracle·Linux·9.·The·rsyslog·service·can·be·enabled·with·the·following·command:1769 The·rsyslog·service·provides·syslog-style·logging·by·default·on·Oracle·Linux·9.·The·rsyslog·service·can·be·enabled·with·the·following·command:
1771 $·sudo·systemctl·enable·rsyslog.service1770 $·sudo·systemctl·enable·rsyslog.service
1772 Rationale:··The·rsyslog·service·must·be·running·in·order·to·provide·logging·services,·which·are·essential·to·system·administration.1771 Rationale:··The·rsyslog·service·must·be·running·in·order·to·provide·logging·services,·which·are·essential·to·system·administration.
1773 Severity: ··medium1772 Severity: ··medium
1774 Rule·ID:····xccdf_org.ssgproject.content_rule_service_rsyslog_enabled1773 Rule·ID:····xccdf_org.ssgproject.content_rule_service_rsyslog_enabled
1775 ············_\x8c_\x8i_\x8s_\x8-_\x8c_\x8s_\x8c········1,·12,·13,·14,·15,·16,·2,·3,·5,·6,·7,·8,·91774 ············_\x8c_\x8i_\x8s_\x8-_\x8c_\x8s_\x8c········1,·12,·13,·14,·15,·16,·2,·3,·5,·6,·7,·8,·9
1.21 MB
./usr/share/doc/ssg-nondebian/ssg-ol9-guide-stig.html
    
Offset 15141, 144 lines modifiedOffset 15141, 144 lines modified
0003b240:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i0003b240:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i
0003b250:·646d·3632·3830·2220·7461·6269·6e64·6578··dm6280"·tabindex0003b250:·646d·3632·3830·2220·7461·6269·6e64·6578··dm6280"·tabindex
0003b260:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto0003b260:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto
0003b270:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded0003b270:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded
0003b280:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="0003b280:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="
0003b290:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve0003b290:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve
0003b2a0:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re0003b2a0:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re
 0003b2b0:·6d65·6469·6174·696f·6e20·4f53·4275·696c··mediation·OSBuil
 0003b2c0:·6420·426c·7565·7072·696e·7420·736e·6970··d·Blueprint·snip
 0003b2d0:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br><
 0003b2e0:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
 0003b2f0:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap
 0003b300:·7365·2220·6964·3d22·6964·6d36·3238·3022··se"·id="idm6280"
 0003b310:·3e3c·7072·653e·3c63·6f64·653e·0a5b·5b70··><pre><code>.[[p
 0003b320:·6163·6b61·6765·735d·5d0a·6e61·6d65·203d··ackages]].name·=
 0003b330:·2022·6169·6465·220a·7665·7273·696f·6e20···"aide".version·
 0003b340:·3d20·222a·220a·3c2f·636f·6465·3e3c·2f70··=·"*".</code></p
 0003b350:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas
 0003b360:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe
 0003b370:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle=
 0003b380:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data-
 0003b390:·7461·7267·6574·3d22·2369·646d·3632·3831··target="#idm6281
 0003b3a0:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r
 0003b3b0:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari
 0003b3c0:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals
 0003b3d0:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa
 0003b3e0:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr
 0003b3f0:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat
 0003b400:·696f·6e20·5075·7070·6574·2073·6e69·7070··ion·Puppet·snipp
 0003b410:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d
 0003b420:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-
 0003b430:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps
 0003b440:·6522·2069·643d·2269·646d·3632·3831·223e··e"·id="idm6281">
 0003b450:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta
 0003b460:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe
 0003b470:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered
 0003b480:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed
 0003b490:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple
 0003b4a0:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo
 0003b4b0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
 0003b4c0:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</
 0003b4d0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
 0003b4e0:·2f74·723e·3c74·723e·3c74·683e·5265·626f··/tr><tr><th>Rebo
 0003b4f0:·6f74·3a3c·2f74·683e·3c74·643e·6661·6c73··ot:</th><td>fals
 0003b500:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr><
 0003b510:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th
 0003b520:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td>
 0003b530:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr
 0003b540:·653e·3c63·6f64·653e·696e·636c·7564·6520··e><code>include·
 0003b550:·696e·7374·616c·6c5f·6169·6465·0a0a·636c··install_aide..cl
 0003b560:·6173·7320·696e·7374·616c·6c5f·6169·6465··ass·install_aide
 0003b570:·207b·0a20·2070·6163·6b61·6765·207b·2027···{.··package·{·'
 0003b580:·6169·6465·273a·0a20·2020·2065·6e73·7572··aide':.····ensur
 0003b590:·6520·3d26·6774·3b20·2769·6e73·7461·6c6c··e·=&gt;·'install
 0003b5a0:·6564·272c·0a20·207d·0a7d·0a3c·2f63·6f64··ed',.··}.}.</cod
 0003b5b0:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a
 0003b5c0:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn-
 0003b5d0:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to
 0003b5e0:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"·
 0003b5f0:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
 0003b600:·6d36·3238·3222·2074·6162·696e·6465·783d··m6282"·tabindex=
 0003b610:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button
 0003b620:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=
 0003b630:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A
 0003b640:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea
 0003b650:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem
 0003b660:·6564·6961·7469·6f6e·2053·6865·6c6c·2073··ediation·Shell·s
 0003b670:·6372·6970·7420·e287·b23c·2f61·3e3c·6272··cript·...</a><br
 0003b680:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
 0003b690:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
 0003b6a0:·6170·7365·2220·6964·3d22·6964·6d36·3238··apse"·id="idm628
 0003b6b0:·3222·3e3c·7461·626c·6520·636c·6173·733d··2"><table·class=
 0003b6c0:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str
 0003b6d0:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde
 0003b6e0:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden
 0003b6f0:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com
 0003b700:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td
 0003b710:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
 0003b720:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption
 0003b730:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
 0003b740:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e52··d></tr><tr><th>R
 0003b750:·6562·6f6f·743a·3c2f·7468·3e3c·7464·3e66··eboot:</th><td>f
 0003b760:·616c·7365·3c2f·7464·3e3c·2f74·723e·3c74··alse</td></tr><t
 0003b770:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<
 0003b780:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</
 0003b790:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table>
 0003b7a0:·3c70·7265·3e3c·636f·6465·3e23·2052·656d··<pre><code>#·Rem
 0003b7b0:·6564·6961·7469·6f6e·2069·7320·6170·706c··ediation·is·appl
 0003b7c0:·6963·6162·6c65·206f·6e6c·7920·696e·2063··icable·only·in·c
 0003b7d0:·6572·7461·696e·2070·6c61·7466·6f72·6d73··ertain·platforms
 0003b7e0:·0a69·6620·7270·6d20·2d2d·7175·6965·7420··.if·rpm·--quiet·
 0003b7f0:·2d71·206b·6572·6e65·6c20·7c7c·2072·706d··-q·kernel·||·rpm
 0003b800:·202d·2d71·7569·6574·202d·7120·6b65·726e···--quiet·-q·kern
 0003b810:·656c·2d75·656b·3b20·7468·656e·0a0a·6966··el-uek;·then..if
 0003b820:·2021·2072·706d·202d·7120·2d2d·7175·6965···!·rpm·-q·--quie
 0003b830:·7420·2261·6964·6522·203b·2074·6865·6e0a··t·"aide"·;·then.
 0003b840:·2020·2020·7975·6d20·696e·7374·616c·6c20······yum·install·
 0003b850:·2d79·2022·6169·6465·220a·6669·0a0a·656c··-y·"aide".fi..el
 0003b860:·7365·0a20·2020·2026·6774·3b26·616d·703b··se.····&gt;&amp;
 0003b870:·3220·6563·686f·2027·5265·6d65·6469·6174··2·echo·'Remediat
 0003b880:·696f·6e20·6973·206e·6f74·2061·7070·6c69··ion·is·not·appli
 0003b890:·6361·626c·652c·206e·6f74·6869·6e67·2077··cable,·nothing·w
 0003b8a0:·6173·2064·6f6e·6527·0a66·690a·3c2f·636f··as·done'.fi.</co
 0003b8b0:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div><
 0003b8c0:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn
 0003b8d0:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t
 0003b8e0:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse"
 0003b8f0:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i
 0003b900:·646d·3632·3833·2220·7461·6269·6e64·6578··dm6283"·tabindex
 0003b910:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto
 0003b920:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded
 0003b930:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="
 0003b940:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve
 0003b950:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re
0003b2b0:·6d65·6469·6174·696f·6e20·416e·6163·6f6e··mediation·Anacon0003b960:·6d65·6469·6174·696f·6e20·416e·6163·6f6e··mediation·Anacon
0003b2c0:·6461·2073·6e69·7070·6574·20e2·87b2·3c2f··da·snippet·...</0003b970:·6461·2073·6e69·7070·6574·20e2·87b2·3c2f··da·snippet·...</
0003b2d0:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class0003b980:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
0003b2e0:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse0003b990:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
0003b2f0:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i0003b9a0:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
0003b300:·646d·3632·3830·223e·3c74·6162·6c65·2063··dm6280"><table·c0003b9b0:·646d·3632·3833·223e·3c74·6162·6c65·2063··dm6283"><table·c
0003b310:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl0003b9c0:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl
0003b320:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-0003b9d0:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-
0003b330:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c 
0003b340:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t 
0003b350:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t 
0003b360:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></ 
0003b370:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru 
Max diff block lines reached; 1139756/1158276 bytes (98.40%) of diff not shown.
111 KB
html2text {}
    
Offset 135, 21 lines modifiedOffset 135, 14 lines modified
135 ··-·PCI-DSSv4-11.5.2135 ··-·PCI-DSSv4-11.5.2
136 ··-·enable_strategy136 ··-·enable_strategy
137 ··-·low_complexity137 ··-·low_complexity
138 ··-·low_disruption138 ··-·low_disruption
139 ··-·medium_severity139 ··-·medium_severity
140 ··-·no_reboot_needed140 ··-·no_reboot_needed
141 ··-·package_aide_installed141 ··-·package_aide_installed
142 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
143 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
144 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
145 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
146 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
147 package·--add=aide 
148 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8142 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
149 [[packages]]143 [[packages]]
150 name·=·"aide"144 name·=·"aide"
151 version·=·"*"145 version·=·"*"
152 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8146 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
153 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low147 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 174, 14 lines modifiedOffset 167, 21 lines modified
174 if·!·rpm·-q·--quiet·"aide"·;·then167 if·!·rpm·-q·--quiet·"aide"·;·then
175 ····yum·install·-y·"aide"168 ····yum·install·-y·"aide"
176 fi169 fi
  
177 else170 else
178 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'171 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
179 fi172 fi
 173 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 174 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 175 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 176 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 177 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 178 package·--add=aide
180 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·A\x8AI\x8ID\x8DE\x8E·t\x8to\x8o·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·t\x8th\x8he\x8e·A\x8Au\x8ud\x8di\x8it\x8t·T\x8To\x8oo\x8ol\x8ls\x8s·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*179 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·A\x8AI\x8ID\x8DE\x8E·t\x8to\x8o·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·t\x8th\x8he\x8e·A\x8Au\x8ud\x8di\x8it\x8t·T\x8To\x8oo\x8ol\x8ls\x8s·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
181 The·operating·system·file·integrity·tool·must·be·configured·to·protect·the·integrity·of·the·audit·tools.180 The·operating·system·file·integrity·tool·must·be·configured·to·protect·the·integrity·of·the·audit·tools.
182 Rationale:··Protecting·the·integrity·of·the·tools·used·for·auditing·purposes·is·a·critical·step·toward·ensuring·the·integrity·of·audit·information.·Audit·information·includes·all·information·(e.g.,·audit·records,·audit·settings,·and·audit·reports)·needed·to·successfully·audit·information·system·activity.·Audit·tools·include·but·are·not·limited·to·vendor-provided·and·open-source·audit·tools·needed·to·successfully·view·and·manipulate·audit·information·system·activity·and·records.·Audit·tools·include·custom·queries·and·report·generators.·It·is·not·uncommon·for·attackers·to·replace·the·audit·tools·or·inject·code·into·the·existing·tools·to·provide·the·capability·to·hide·or·erase·system·activity·from·the·audit·logs.·To·address·this·risk,·audit·tools·must·be·cryptographically·signed·to·provide·the·capability·to·identify·when·the·audit·tools·have·been·modified,·manipulated,·or·replaced.·An·example·is·a·checksum·hash·of·the·file·or·files.181 Rationale:··Protecting·the·integrity·of·the·tools·used·for·auditing·purposes·is·a·critical·step·toward·ensuring·the·integrity·of·audit·information.·Audit·information·includes·all·information·(e.g.,·audit·records,·audit·settings,·and·audit·reports)·needed·to·successfully·audit·information·system·activity.·Audit·tools·include·but·are·not·limited·to·vendor-provided·and·open-source·audit·tools·needed·to·successfully·view·and·manipulate·audit·information·system·activity·and·records.·Audit·tools·include·custom·queries·and·report·generators.·It·is·not·uncommon·for·attackers·to·replace·the·audit·tools·or·inject·code·into·the·existing·tools·to·provide·the·capability·to·hide·or·erase·system·activity·from·the·audit·logs.·To·address·this·risk,·audit·tools·must·be·cryptographically·signed·to·provide·the·capability·to·identify·when·the·audit·tools·have·been·modified,·manipulated,·or·replaced.·An·example·is·a·checksum·hash·of·the·file·or·files.
183 Severity: ··medium182 Severity: ··medium
184 Rule·ID:····xccdf_org.ssgproject.content_rule_aide_check_audit_tools183 Rule·ID:····xccdf_org.ssgproject.content_rule_aide_check_audit_tools
185 ············_\x8d_\x8i_\x8s_\x8a···CCI-001496,·CCI-001494,·CCI-001495,·CCI-001493184 ············_\x8d_\x8i_\x8s_\x8a···CCI-001496,·CCI-001494,·CCI-001495,·CCI-001493
186 References:·_\x8n_\x8i_\x8s_\x8t···AU-9(3),·AU-9(3).1185 References:·_\x8n_\x8i_\x8s_\x8t···AU-9(3),·AU-9(3).1
Offset 1975, 21 lines modifiedOffset 1975, 14 lines modified
1975 ··tags:1975 ··tags:
1976 ··-·enable_strategy1976 ··-·enable_strategy
1977 ··-·low_complexity1977 ··-·low_complexity
1978 ··-·low_disruption1978 ··-·low_disruption
1979 ··-·medium_severity1979 ··-·medium_severity
1980 ··-·no_reboot_needed1980 ··-·no_reboot_needed
1981 ··-·package_crypto-policies_installed1981 ··-·package_crypto-policies_installed
1982 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
1983 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
1984 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
1985 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
1986 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
1987 package·--add=crypto-policies 
1988 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81982 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
1989 [[packages]]1983 [[packages]]
1990 name·=·"crypto-policies"1984 name·=·"crypto-policies"
1991 version·=·"*"1985 version·=·"*"
1992 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81986 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1993 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1987 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 2008, 14 lines modifiedOffset 2001, 21 lines modified
2008 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low2001 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
2009 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false2002 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
2010 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable2003 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
2011 if·!·rpm·-q·--quiet·"crypto-policies"·;·then2004 if·!·rpm·-q·--quiet·"crypto-policies"·;·then
2012 ····yum·install·-y·"crypto-policies"2005 ····yum·install·-y·"crypto-policies"
2013 fi2006 fi
 2007 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 2008 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 2009 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 2010 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 2011 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 2012 package·--add=crypto-policies
2014 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·B\x8BI\x8IN\x8ND\x8D·t\x8to\x8o·u\x8us\x8se\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8o·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*2013 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·B\x8BI\x8IN\x8ND\x8D·t\x8to\x8o·u\x8us\x8se\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8o·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
2015 Crypto·Policies·provide·a·centralized·control·over·crypto·algorithms·usage·of·many·packages.·BIND·is·supported·by·crypto·policy,·but·the·BIND·configuration·may·be·set·up·to·ignore·it.·To·check·that·Crypto·Policies·settings·are·configured·correctly,·ensure·that·the·/etc/named.conf·includes·the·appropriate·configuration:·In·the·options·section·of·/etc/named.conf,·make·sure·that·the·following·line·is·not·commented·out·or·superseded·by·later·includes:·include·"/etc/crypto-policies/back-ends/bind.config";2014 Crypto·Policies·provide·a·centralized·control·over·crypto·algorithms·usage·of·many·packages.·BIND·is·supported·by·crypto·policy,·but·the·BIND·configuration·may·be·set·up·to·ignore·it.·To·check·that·Crypto·Policies·settings·are·configured·correctly,·ensure·that·the·/etc/named.conf·includes·the·appropriate·configuration:·In·the·options·section·of·/etc/named.conf,·make·sure·that·the·following·line·is·not·commented·out·or·superseded·by·later·includes:·include·"/etc/crypto-policies/back-ends/bind.config";
2016 Rationale:··Overriding·the·system·crypto·policy·makes·the·behavior·of·the·BIND·service·violate·expectations,·and·makes·system·configuration·more·fragmented.2015 Rationale:··Overriding·the·system·crypto·policy·makes·the·behavior·of·the·BIND·service·violate·expectations,·and·makes·system·configuration·more·fragmented.
2017 Severity: ··high2016 Severity: ··high
2018 Rule·ID:····xccdf_org.ssgproject.content_rule_configure_bind_crypto_policy2017 Rule·ID:····xccdf_org.ssgproject.content_rule_configure_bind_crypto_policy
2019 ············_\x8d_\x8i_\x8s_\x8a·····CCI-002418,·CCI-0024222018 ············_\x8d_\x8i_\x8s_\x8a·····CCI-002418,·CCI-002422
2020 References:·_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.12019 References:·_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1
Offset 4875, 21 lines modifiedOffset 4875, 14 lines modified
4875 ··-·PCI-DSSv4-2.2.64875 ··-·PCI-DSSv4-2.2.6
4876 ··-·enable_strategy4876 ··-·enable_strategy
4877 ··-·low_complexity4877 ··-·low_complexity
4878 ··-·low_disruption4878 ··-·low_disruption
4879 ··-·medium_severity4879 ··-·medium_severity
4880 ··-·no_reboot_needed4880 ··-·no_reboot_needed
4881 ··-·package_sudo_installed4881 ··-·package_sudo_installed
4882 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
4883 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
4884 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
4885 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
4886 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
4887 package·--add=sudo 
4888 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x84882 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
4889 [[packages]]4883 [[packages]]
4890 name·=·"sudo"4884 name·=·"sudo"
4891 version·=·"*"4885 version·=·"*"
4892 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x84886 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
4893 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low4887 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 4914, 14 lines modifiedOffset 4907, 21 lines modified
4914 if·!·rpm·-q·--quiet·"sudo"·;·then4907 if·!·rpm·-q·--quiet·"sudo"·;·then
4915 ····yum·install·-y·"sudo"4908 ····yum·install·-y·"sudo"
4916 fi4909 fi
  
4917 else4910 else
4918 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'4911 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
4919 fi4912 fi
 4913 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 4914 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 4915 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 4916 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 4917 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 4918 package·--add=sudo
4920 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·U\x8Us\x8se\x8er\x8rs\x8s·R\x8Re\x8e-\x8-A\x8Au\x8ut\x8th\x8he\x8en\x8nt\x8ti\x8ic\x8ca\x8at\x8te\x8e·f\x8fo\x8or\x8r·P\x8Pr\x8ri\x8iv\x8vi\x8il\x8le\x8eg\x8ge\x8e·E\x8Es\x8sc\x8ca\x8al\x8la\x8at\x8ti\x8io\x8on\x8n·-\x8-·s\x8su\x8ud\x8do\x8o·!\x8!a\x8au\x8ut\x8th\x8he\x8en\x8nt\x8ti\x8ic\x8ca\x8at\x8te\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*4919 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·U\x8Us\x8se\x8er\x8rs\x8s·R\x8Re\x8e-\x8-A\x8Au\x8ut\x8th\x8he\x8en\x8nt\x8ti\x8ic\x8ca\x8at\x8te\x8e·f\x8fo\x8or\x8r·P\x8Pr\x8ri\x8iv\x8vi\x8il\x8le\x8eg\x8ge\x8e·E\x8Es\x8sc\x8ca\x8al\x8la\x8at\x8ti\x8io\x8on\x8n·-\x8-·s\x8su\x8ud\x8do\x8o·!\x8!a\x8au\x8ut\x8th\x8he\x8en\x8nt\x8ti\x8ic\x8ca\x8at\x8te\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
4921 The·sudo·!authenticate·option,·when·specified,·allows·a·user·to·execute·commands·using·sudo·without·having·to·authenticate.·This·should·be·disabled·by·making·sure·that·the·!authenticate·option·does·not·exist·in·/etc/sudoers·configuration·file·or·any·sudo·configuration·snippets·in·/etc/sudoers.d/.4920 The·sudo·!authenticate·option,·when·specified,·allows·a·user·to·execute·commands·using·sudo·without·having·to·authenticate.·This·should·be·disabled·by·making·sure·that·the·!authenticate·option·does·not·exist·in·/etc/sudoers·configuration·file·or·any·sudo·configuration·snippets·in·/etc/sudoers.d/.
4922 ············Without·re-authentication,·users·may·access·resources·or·perform·tasks·for·which·they·do·not·have·authorization.4921 ············Without·re-authentication,·users·may·access·resources·or·perform·tasks·for·which·they·do·not·have·authorization.
Max diff block lines reached; 107109/113901 bytes (94.04%) of diff not shown.
1.18 MB
./usr/share/doc/ssg-nondebian/ssg-ol9-guide-stig_gui.html
    
Offset 15159, 143 lines modifiedOffset 15159, 143 lines modified
0003b360:·612d·7461·7267·6574·3d22·2369·646d·3632··a-target="#idm620003b360:·612d·7461·7267·6574·3d22·2369·646d·3632··a-target="#idm62
0003b370:·3830·2220·7461·6269·6e64·6578·3d22·3022··80"·tabindex="0"0003b370:·3830·2220·7461·6269·6e64·6578·3d22·3022··80"·tabindex="0"
0003b380:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a0003b380:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
0003b390:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa0003b390:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
0003b3a0:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti0003b3a0:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
0003b3b0:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·0003b3b0:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
0003b3c0:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi0003b3c0:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
 0003b3d0:·6174·696f·6e20·4f53·4275·696c·6420·426c··ation·OSBuild·Bl
 0003b3e0:·7565·7072·696e·7420·736e·6970·7065·7420··ueprint·snippet·
 0003b3f0:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·
 0003b400:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col
 0003b410:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·
 0003b420:·6964·3d22·6964·6d36·3238·3022·3e3c·7072··id="idm6280"><pr
 0003b430:·653e·3c63·6f64·653e·0a5b·5b70·6163·6b61··e><code>.[[packa
 0003b440:·6765·735d·5d0a·6e61·6d65·203d·2022·6169··ges]].name·=·"ai
 0003b450:·6465·220a·7665·7273·696f·6e20·3d20·222a··de".version·=·"*
 0003b460:·220a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··".</code></pre><
 0003b470:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b
 0003b480:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"·
 0003b490:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col
 0003b4a0:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ
 0003b4b0:·6574·3d22·2369·646d·3632·3831·2220·7461··et="#idm6281"·ta
 0003b4c0:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
 0003b4d0:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
 0003b4e0:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
 0003b4f0:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
 0003b500:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
 0003b510:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
 0003b520:·5075·7070·6574·2073·6e69·7070·6574·20e2··Puppet·snippet·.
 0003b530:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c
 0003b540:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
 0003b550:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
 0003b560:·643d·2269·646d·3632·3831·223e·3c74·6162··d="idm6281"><tab
 0003b570:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·
 0003b580:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta
 0003b590:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab
 0003b5a0:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t
 0003b5b0:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity
 0003b5c0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
 0003b5d0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D
 0003b5e0:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><
 0003b5f0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
 0003b600:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:<
 0003b610:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t
 0003b620:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S
 0003b630:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td
 0003b640:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr
 0003b650:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c
 0003b660:·6f64·653e·696e·636c·7564·6520·696e·7374··ode>include·inst
 0003b670:·616c·6c5f·6169·6465·0a0a·636c·6173·7320··all_aide..class·
 0003b680:·696e·7374·616c·6c5f·6169·6465·207b·0a20··install_aide·{.·
 0003b690:·2070·6163·6b61·6765·207b·2027·6169·6465···package·{·'aide
 0003b6a0:·273a·0a20·2020·2065·6e73·7572·6520·3d26··':.····ensure·=&
 0003b6b0:·6774·3b20·2769·6e73·7461·6c6c·6564·272c··gt;·'installed',
 0003b6c0:·0a20·207d·0a7d·0a3c·2f63·6f64·653e·3c2f··.··}.}.</code></
 0003b6d0:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla
 0003b6e0:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ
 0003b6f0:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle
 0003b700:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data
 0003b710:·2d74·6172·6765·743d·2223·6964·6d36·3238··-target="#idm628
 0003b720:·3222·2074·6162·696e·6465·783d·2230·2220··2"·tabindex="0"·
 0003b730:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar
 0003b740:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal
 0003b750:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ
 0003b760:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h
 0003b770:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia
 0003b780:·7469·6f6e·2053·6865·6c6c·2073·6372·6970··tion·Shell·scrip
 0003b790:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di
 0003b7a0:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c
 0003b7b0:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse
 0003b7c0:·2220·6964·3d22·6964·6d36·3238·3222·3e3c··"·id="idm6282"><
 0003b7d0:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab
 0003b7e0:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped
 0003b7f0:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·
 0003b800:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"
 0003b810:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex
 0003b820:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low
 0003b830:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
 0003b840:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t
 0003b850:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
 0003b860:·7472·3e3c·7472·3e3c·7468·3e52·6562·6f6f··tr><tr><th>Reboo
 0003b870:·743a·3c2f·7468·3e3c·7464·3e66·616c·7365··t:</th><td>false
 0003b880:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
 0003b890:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th>
 0003b8a0:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td><
 0003b8b0:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre
 0003b8c0:·3e3c·636f·6465·3e23·2052·656d·6564·6961··><code>#·Remedia
 0003b8d0:·7469·6f6e·2069·7320·6170·706c·6963·6162··tion·is·applicab
 0003b8e0:·6c65·206f·6e6c·7920·696e·2063·6572·7461··le·only·in·certa
 0003b8f0:·696e·2070·6c61·7466·6f72·6d73·0a69·6620··in·platforms.if·
 0003b900:·7270·6d20·2d2d·7175·6965·7420·2d71·206b··rpm·--quiet·-q·k
 0003b910:·6572·6e65·6c20·7c7c·2072·706d·202d·2d71··ernel·||·rpm·--q
 0003b920:·7569·6574·202d·7120·6b65·726e·656c·2d75··uiet·-q·kernel-u
 0003b930:·656b·3b20·7468·656e·0a0a·6966·2021·2072··ek;·then..if·!·r
 0003b940:·706d·202d·7120·2d2d·7175·6965·7420·2261··pm·-q·--quiet·"a
 0003b950:·6964·6522·203b·2074·6865·6e0a·2020·2020··ide"·;·then.····
 0003b960:·7975·6d20·696e·7374·616c·6c20·2d79·2022··yum·install·-y·"
 0003b970:·6169·6465·220a·6669·0a0a·656c·7365·0a20··aide".fi..else.·
 0003b980:·2020·2026·6774·3b26·616d·703b·3220·6563·····&gt;&amp;2·ec
 0003b990:·686f·2027·5265·6d65·6469·6174·696f·6e20··ho·'Remediation·
 0003b9a0:·6973·206e·6f74·2061·7070·6c69·6361·626c··is·not·applicabl
 0003b9b0:·652c·206e·6f74·6869·6e67·2077·6173·2064··e,·nothing·was·d
 0003b9c0:·6f6e·6527·0a66·690a·3c2f·636f·6465·3e3c··one'.fi.</code><
 0003b9d0:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl
 0003b9e0:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc
 0003b9f0:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl
 0003ba00:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat
 0003ba10:·612d·7461·7267·6574·3d22·2369·646d·3632··a-target="#idm62
 0003ba20:·3833·2220·7461·6269·6e64·6578·3d22·3022··83"·tabindex="0"
 0003ba30:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
 0003ba40:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
 0003ba50:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
 0003ba60:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
 0003ba70:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
0003b3d0:·6174·696f·6e20·416e·6163·6f6e·6461·2073··ation·Anaconda·s0003ba80:·6174·696f·6e20·416e·6163·6f6e·6461·2073··ation·Anaconda·s
0003b3e0:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b0003ba90:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b
0003b3f0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa0003baa0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
0003b400:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col0003bab0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
0003b410:·6c61·7073·6522·2069·643d·2269·646d·3632··lapse"·id="idm620003bac0:·6c61·7073·6522·2069·643d·2269·646d·3632··lapse"·id="idm62
0003b420:·3830·223e·3c74·6162·6c65·2063·6c61·7373··80"><table·class0003bad0:·3833·223e·3c74·6162·6c65·2063·6c61·7373··83"><table·class
0003b430:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st0003bae0:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st
0003b440:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord 
0003b450:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde 
0003b460:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co 
0003b470:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t 
0003b480:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr>< 
0003b490:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio 
Max diff block lines reached; 1112098/1130480 bytes (98.37%) of diff not shown.
107 KB
html2text {}
    
Offset 139, 21 lines modifiedOffset 139, 14 lines modified
139 ··-·PCI-DSSv4-11.5.2139 ··-·PCI-DSSv4-11.5.2
140 ··-·enable_strategy140 ··-·enable_strategy
141 ··-·low_complexity141 ··-·low_complexity
142 ··-·low_disruption142 ··-·low_disruption
143 ··-·medium_severity143 ··-·medium_severity
144 ··-·no_reboot_needed144 ··-·no_reboot_needed
145 ··-·package_aide_installed145 ··-·package_aide_installed
146 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
147 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
148 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
149 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
150 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
151 package·--add=aide 
152 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8146 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
153 [[packages]]147 [[packages]]
154 name·=·"aide"148 name·=·"aide"
155 version·=·"*"149 version·=·"*"
156 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8150 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
157 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low151 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 178, 14 lines modifiedOffset 171, 21 lines modified
178 if·!·rpm·-q·--quiet·"aide"·;·then171 if·!·rpm·-q·--quiet·"aide"·;·then
179 ····yum·install·-y·"aide"172 ····yum·install·-y·"aide"
180 fi173 fi
  
181 else174 else
182 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'175 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
183 fi176 fi
 177 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 178 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 179 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 180 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 181 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 182 package·--add=aide
184 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·A\x8AI\x8ID\x8DE\x8E·t\x8to\x8o·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·t\x8th\x8he\x8e·A\x8Au\x8ud\x8di\x8it\x8t·T\x8To\x8oo\x8ol\x8ls\x8s·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*183 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·A\x8AI\x8ID\x8DE\x8E·t\x8to\x8o·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·t\x8th\x8he\x8e·A\x8Au\x8ud\x8di\x8it\x8t·T\x8To\x8oo\x8ol\x8ls\x8s·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
185 The·operating·system·file·integrity·tool·must·be·configured·to·protect·the·integrity·of·the·audit·tools.184 The·operating·system·file·integrity·tool·must·be·configured·to·protect·the·integrity·of·the·audit·tools.
186 Rationale:··Protecting·the·integrity·of·the·tools·used·for·auditing·purposes·is·a·critical·step·toward·ensuring·the·integrity·of·audit·information.·Audit·information·includes·all·information·(e.g.,·audit·records,·audit·settings,·and·audit·reports)·needed·to·successfully·audit·information·system·activity.·Audit·tools·include·but·are·not·limited·to·vendor-provided·and·open-source·audit·tools·needed·to·successfully·view·and·manipulate·audit·information·system·activity·and·records.·Audit·tools·include·custom·queries·and·report·generators.·It·is·not·uncommon·for·attackers·to·replace·the·audit·tools·or·inject·code·into·the·existing·tools·to·provide·the·capability·to·hide·or·erase·system·activity·from·the·audit·logs.·To·address·this·risk,·audit·tools·must·be·cryptographically·signed·to·provide·the·capability·to·identify·when·the·audit·tools·have·been·modified,·manipulated,·or·replaced.·An·example·is·a·checksum·hash·of·the·file·or·files.185 Rationale:··Protecting·the·integrity·of·the·tools·used·for·auditing·purposes·is·a·critical·step·toward·ensuring·the·integrity·of·audit·information.·Audit·information·includes·all·information·(e.g.,·audit·records,·audit·settings,·and·audit·reports)·needed·to·successfully·audit·information·system·activity.·Audit·tools·include·but·are·not·limited·to·vendor-provided·and·open-source·audit·tools·needed·to·successfully·view·and·manipulate·audit·information·system·activity·and·records.·Audit·tools·include·custom·queries·and·report·generators.·It·is·not·uncommon·for·attackers·to·replace·the·audit·tools·or·inject·code·into·the·existing·tools·to·provide·the·capability·to·hide·or·erase·system·activity·from·the·audit·logs.·To·address·this·risk,·audit·tools·must·be·cryptographically·signed·to·provide·the·capability·to·identify·when·the·audit·tools·have·been·modified,·manipulated,·or·replaced.·An·example·is·a·checksum·hash·of·the·file·or·files.
187 Severity: ··medium186 Severity: ··medium
188 Rule·ID:····xccdf_org.ssgproject.content_rule_aide_check_audit_tools187 Rule·ID:····xccdf_org.ssgproject.content_rule_aide_check_audit_tools
189 ············_\x8d_\x8i_\x8s_\x8a···CCI-001496,·CCI-001494,·CCI-001495,·CCI-001493188 ············_\x8d_\x8i_\x8s_\x8a···CCI-001496,·CCI-001494,·CCI-001495,·CCI-001493
190 References:·_\x8n_\x8i_\x8s_\x8t···AU-9(3),·AU-9(3).1189 References:·_\x8n_\x8i_\x8s_\x8t···AU-9(3),·AU-9(3).1
Offset 1979, 21 lines modifiedOffset 1979, 14 lines modified
1979 ··tags:1979 ··tags:
1980 ··-·enable_strategy1980 ··-·enable_strategy
1981 ··-·low_complexity1981 ··-·low_complexity
1982 ··-·low_disruption1982 ··-·low_disruption
1983 ··-·medium_severity1983 ··-·medium_severity
1984 ··-·no_reboot_needed1984 ··-·no_reboot_needed
1985 ··-·package_crypto-policies_installed1985 ··-·package_crypto-policies_installed
1986 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
1987 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
1988 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
1989 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
1990 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
1991 package·--add=crypto-policies 
1992 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81986 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
1993 [[packages]]1987 [[packages]]
1994 name·=·"crypto-policies"1988 name·=·"crypto-policies"
1995 version·=·"*"1989 version·=·"*"
1996 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81990 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1997 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1991 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 2012, 14 lines modifiedOffset 2005, 21 lines modified
2012 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low2005 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
2013 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false2006 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
2014 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable2007 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
2015 if·!·rpm·-q·--quiet·"crypto-policies"·;·then2008 if·!·rpm·-q·--quiet·"crypto-policies"·;·then
2016 ····yum·install·-y·"crypto-policies"2009 ····yum·install·-y·"crypto-policies"
2017 fi2010 fi
 2011 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 2012 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 2013 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 2014 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 2015 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 2016 package·--add=crypto-policies
2018 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·B\x8BI\x8IN\x8ND\x8D·t\x8to\x8o·u\x8us\x8se\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8o·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*2017 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·B\x8BI\x8IN\x8ND\x8D·t\x8to\x8o·u\x8us\x8se\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8o·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
2019 Crypto·Policies·provide·a·centralized·control·over·crypto·algorithms·usage·of·many·packages.·BIND·is·supported·by·crypto·policy,·but·the·BIND·configuration·may·be·set·up·to·ignore·it.·To·check·that·Crypto·Policies·settings·are·configured·correctly,·ensure·that·the·/etc/named.conf·includes·the·appropriate·configuration:·In·the·options·section·of·/etc/named.conf,·make·sure·that·the·following·line·is·not·commented·out·or·superseded·by·later·includes:·include·"/etc/crypto-policies/back-ends/bind.config";2018 Crypto·Policies·provide·a·centralized·control·over·crypto·algorithms·usage·of·many·packages.·BIND·is·supported·by·crypto·policy,·but·the·BIND·configuration·may·be·set·up·to·ignore·it.·To·check·that·Crypto·Policies·settings·are·configured·correctly,·ensure·that·the·/etc/named.conf·includes·the·appropriate·configuration:·In·the·options·section·of·/etc/named.conf,·make·sure·that·the·following·line·is·not·commented·out·or·superseded·by·later·includes:·include·"/etc/crypto-policies/back-ends/bind.config";
2020 Rationale:··Overriding·the·system·crypto·policy·makes·the·behavior·of·the·BIND·service·violate·expectations,·and·makes·system·configuration·more·fragmented.2019 Rationale:··Overriding·the·system·crypto·policy·makes·the·behavior·of·the·BIND·service·violate·expectations,·and·makes·system·configuration·more·fragmented.
2021 Severity: ··high2020 Severity: ··high
2022 Rule·ID:····xccdf_org.ssgproject.content_rule_configure_bind_crypto_policy2021 Rule·ID:····xccdf_org.ssgproject.content_rule_configure_bind_crypto_policy
2023 ············_\x8d_\x8i_\x8s_\x8a·····CCI-002418,·CCI-0024222022 ············_\x8d_\x8i_\x8s_\x8a·····CCI-002418,·CCI-002422
2024 References:·_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.12023 References:·_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1
Offset 4879, 21 lines modifiedOffset 4879, 14 lines modified
4879 ··-·PCI-DSSv4-2.2.64879 ··-·PCI-DSSv4-2.2.6
4880 ··-·enable_strategy4880 ··-·enable_strategy
4881 ··-·low_complexity4881 ··-·low_complexity
4882 ··-·low_disruption4882 ··-·low_disruption
4883 ··-·medium_severity4883 ··-·medium_severity
4884 ··-·no_reboot_needed4884 ··-·no_reboot_needed
4885 ··-·package_sudo_installed4885 ··-·package_sudo_installed
4886 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
4887 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
4888 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
4889 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
4890 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
4891 package·--add=sudo 
4892 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x84886 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
4893 [[packages]]4887 [[packages]]
4894 name·=·"sudo"4888 name·=·"sudo"
4895 version·=·"*"4889 version·=·"*"
4896 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x84890 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
4897 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low4891 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 4918, 14 lines modifiedOffset 4911, 21 lines modified
4918 if·!·rpm·-q·--quiet·"sudo"·;·then4911 if·!·rpm·-q·--quiet·"sudo"·;·then
4919 ····yum·install·-y·"sudo"4912 ····yum·install·-y·"sudo"
4920 fi4913 fi
  
4921 else4914 else
4922 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'4915 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
4923 fi4916 fi
 4917 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 4918 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 4919 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 4920 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 4921 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 4922 package·--add=sudo
4924 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·U\x8Us\x8se\x8er\x8rs\x8s·R\x8Re\x8e-\x8-A\x8Au\x8ut\x8th\x8he\x8en\x8nt\x8ti\x8ic\x8ca\x8at\x8te\x8e·f\x8fo\x8or\x8r·P\x8Pr\x8ri\x8iv\x8vi\x8il\x8le\x8eg\x8ge\x8e·E\x8Es\x8sc\x8ca\x8al\x8la\x8at\x8ti\x8io\x8on\x8n·-\x8-·s\x8su\x8ud\x8do\x8o·!\x8!a\x8au\x8ut\x8th\x8he\x8en\x8nt\x8ti\x8ic\x8ca\x8at\x8te\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*4923 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·U\x8Us\x8se\x8er\x8rs\x8s·R\x8Re\x8e-\x8-A\x8Au\x8ut\x8th\x8he\x8en\x8nt\x8ti\x8ic\x8ca\x8at\x8te\x8e·f\x8fo\x8or\x8r·P\x8Pr\x8ri\x8iv\x8vi\x8il\x8le\x8eg\x8ge\x8e·E\x8Es\x8sc\x8ca\x8al\x8la\x8at\x8ti\x8io\x8on\x8n·-\x8-·s\x8su\x8ud\x8do\x8o·!\x8!a\x8au\x8ut\x8th\x8he\x8en\x8nt\x8ti\x8ic\x8ca\x8at\x8te\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
4925 The·sudo·!authenticate·option,·when·specified,·allows·a·user·to·execute·commands·using·sudo·without·having·to·authenticate.·This·should·be·disabled·by·making·sure·that·the·!authenticate·option·does·not·exist·in·/etc/sudoers·configuration·file·or·any·sudo·configuration·snippets·in·/etc/sudoers.d/.4924 The·sudo·!authenticate·option,·when·specified,·allows·a·user·to·execute·commands·using·sudo·without·having·to·authenticate.·This·should·be·disabled·by·making·sure·that·the·!authenticate·option·does·not·exist·in·/etc/sudoers·configuration·file·or·any·sudo·configuration·snippets·in·/etc/sudoers.d/.
4926 ············Without·re-authentication,·users·may·access·resources·or·perform·tasks·for·which·they·do·not·have·authorization.4925 ············Without·re-authentication,·users·may·access·resources·or·perform·tasks·for·which·they·do·not·have·authorization.
Max diff block lines reached; 102701/109493 bytes (93.80%) of diff not shown.
13.2 KB
./usr/share/doc/ssg-nondebian/ssg-openeuler2203-guide-standard.html
    
Offset 99253, 90 lines modifiedOffset 99253, 90 lines modified
00183b40:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target00183b40:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
00183b50:·3d22·2369·646d·3134·3739·3022·2074·6162··="#idm14790"·tab00183b50:·3d22·2369·646d·3134·3739·3022·2074·6162··="#idm14790"·tab
00183b60:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="00183b60:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
00183b70:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp00183b70:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
00183b80:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti00183b80:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
00183b90:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to00183b90:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
00183ba0:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#00183ba0:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
00183bb0:·2122·3e52·656d·6564·6961·7469·6f6e·2041··!">Remediation·A00183bb0:·2122·3e52·656d·6564·6961·7469·6f6e·2053··!">Remediation·S
 00183bc0:·6865·6c6c·2073·6372·6970·7420·e287·b23c··hell·script·...<
 00183bd0:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas
 00183be0:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps
 00183bf0:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="
 00183c00:·6964·6d31·3437·3930·223e·3c74·6162·6c65··idm14790"><table
 00183c10:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta
 00183c20:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl
 00183c30:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table
 00183c40:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>
 00183c50:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<
 00183c60:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
 00183c70:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis
 00183c80:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td
 00183c90:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
 00183ca0:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t
 00183cb0:·683e·3c74·643e·7472·7565·3c2f·7464·3e3c··h><td>true</td><
 00183cc0:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra
 00183cd0:·7465·6779·3a3c·2f74·683e·3c74·643e·7265··tegy:</th><td>re
 00183ce0:·7374·7269·6374·3c2f·7464·3e3c·2f74·723e··strict</td></tr>
 00183cf0:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co
 00183d00:·6465·3e0a·0a23·2072·656d·6f76·6520·7061··de>..#·remove·pa
 00183d10:·636b·6167·6573·0a69·6620·7270·6d20·2d71··ckages.if·rpm·-q
 00183d20:·202d·2d71·7569·6574·2022·786f·7267·2d78···--quiet·"xorg-x
 00183d30:·3131·2d73·6572·7665·722d·586f·7267·2220··11-server-Xorg"·
 00183d40:·3b20·7468·656e·0a64·6e66·2072·656d·6f76··;·then.dnf·remov
 00183d50:·6520·2d79·202d·2d6e·6f61·7574·6f72·656d··e·-y·--noautorem
 00183d60:·6f76·6520·2278·6f72·672d·7831·312d·7365··ove·"xorg-x11-se
 00183d70:·7276·6572·2d58·6f72·6722·0a66·690a·6966··rver-Xorg".fi.if
 00183d80:·2072·706d·202d·7120·2d2d·7175·6965·7420···rpm·-q·--quiet·
 00183d90:·2278·6f72·672d·7831·312d·7365·7276·6572··"xorg-x11-server
 00183da0:·2d75·7469·6c73·2220·3b20·7468·656e·0a64··-utils"·;·then.d
 00183db0:·6e66·2072·656d·6f76·6520·2d79·202d·2d6e··nf·remove·-y·--n
 00183dc0:·6f61·7574·6f72·656d·6f76·6520·2278·6f72··oautoremove·"xor
 00183dd0:·672d·7831·312d·7365·7276·6572·2d75·7469··g-x11-server-uti
 00183de0:·6c73·220a·6669·0a69·6620·7270·6d20·2d71··ls".fi.if·rpm·-q
 00183df0:·202d·2d71·7569·6574·2022·786f·7267·2d78···--quiet·"xorg-x
 00183e00:·3131·2d73·6572·7665·722d·636f·6d6d·6f6e··11-server-common
 00183e10:·2220·3b20·7468·656e·0a64·6e66·2072·656d··"·;·then.dnf·rem
 00183e20:·6f76·6520·2d79·202d·2d6e·6f61·7574·6f72··ove·-y·--noautor
 00183e30:·656d·6f76·6520·2278·6f72·672d·7831·312d··emove·"xorg-x11-
 00183e40:·7365·7276·6572·2d63·6f6d·6d6f·6e22·0a66··server-common".f
 00183e50:·690a·0a69·6620·7270·6d20·2d71·202d·2d71··i..if·rpm·-q·--q
 00183e60:·7569·6574·2022·786f·7267·2d78·3131·2d73··uiet·"xorg-x11-s
 00183e70:·6572·7665·722d·5877·6179·6c61·6e64·2220··erver-Xwayland"·
 00183e80:·3b20·7468·656e·0a64·6e66·2072·656d·6f76··;·then.dnf·remov
 00183e90:·6520·2d79·202d·2d6e·6f61·7574·6f72·656d··e·-y·--noautorem
 00183ea0:·6f76·6520·2278·6f72·672d·7831·312d·7365··ove·"xorg-x11-se
 00183eb0:·7276·6572·2d58·7761·796c·616e·6422·0a66··rver-Xwayland".f
 00183ec0:·690a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··i.</code></pre><
 00183ed0:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b
 00183ee0:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"·
 00183ef0:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col
 00183f00:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ
 00183f10:·6574·3d22·2369·646d·3134·3739·3122·2074··et="#idm14791"·t
 00183f20:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
 00183f30:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
 00183f40:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
 00183f50:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
 00183f60:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
 00183f70:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
00183bc0:·6e61·636f·6e64·6120·736e·6970·7065·7420··naconda·snippet·00183f80:·2041·6e61·636f·6e64·6120·736e·6970·7065···Anaconda·snippe
00183bd0:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·00183f90:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di
00183be0:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col00183fa0:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c
00183bf0:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·00183fb0:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse
00183c00:·6964·3d22·6964·6d31·3437·3930·223e·3c70··id="idm14790"><p00183fc0:·2220·6964·3d22·6964·6d31·3437·3931·223e··"·id="idm14791">
00183c10:·7265·3e3c·636f·6465·3e0a·7061·636b·6167··re><code>.packag00183fd0:·3c70·7265·3e3c·636f·6465·3e0a·7061·636b··<pre><code>.pack
 00183fe0:·6167·6520·2d2d·7265·6d6f·7665·3d78·6f72··age·--remove=xor
 00183ff0:·672d·7831·312d·7365·7276·6572·2d58·6f72··g-x11-server-Xor
00183c20:·6520·2d2d·7265·6d6f·7665·3d78·6f72·672d··e·--remove=xorg-00184000:·6720·2d2d·7265·6d6f·7665·3d78·6f72·672d··g·--remove=xorg-
00183c30:·7831·312d·7365·7276·6572·2d58·6f72·6720··x11-server-Xorg· 
00183c40:·2d2d·7265·6d6f·7665·3d78·6f72·672d·7831··--remove=xorg-x1 
00183c50:·312d·7365·7276·6572·2d63·6f6d·6d6f·6e20··1-server-common· 
00183c60:·2d2d·7265·6d6f·7665·3d78·6f72·672d·7831··--remove=xorg-x1 
00183c70:·312d·7365·7276·6572·2d75·7469·6c73·202d··1-server-utils·- 
00183c80:·2d72·656d·6f76·653d·786f·7267·2d78·3131··-remove=xorg-x11 
00183c90:·2d73·6572·7665·722d·5877·6179·6c61·6e64··-server-Xwayland 
00183ca0:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></ 
00183cb0:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt 
00183cc0:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d 
00183cd0:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll 
00183ce0:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe 
00183cf0:·743d·2223·6964·6d31·3437·3931·2220·7461··t="#idm14791"·ta 
00183d00:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role= 
00183d10:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex 
00183d20:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t 
00183d30:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t 
00183d40:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href=" 
00183d50:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation· 
00183d60:·5368·656c·6c20·7363·7269·7074·20e2·87b2··Shell·script·... 
00183d70:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla 
00183d80:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap 
00183d90:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id= 
00183da0:·2269·646d·3134·3739·3122·3e3c·7461·626c··"idm14791"><tabl 
00183db0:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t 
00183dc0:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab 
00183dd0:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl 
00183de0:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr 
00183df0:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity: 
00183e00:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td 
00183e10:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di 
00183e20:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t 
00183e30:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr>< 
00183e40:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</ 
00183e50:·7468·3e3c·7464·3e74·7275·653c·2f74·643e··th><td>true</td> 
00183e60:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str 
00183e70:·6174·6567·793a·3c2f·7468·3e3c·7464·3e72··ategy:</th><td>r 
00183e80:·6573·7472·6963·743c·2f74·643e·3c2f·7472··estrict</td></tr 
00183e90:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c 
00183ea0:·6f64·653e·0a0a·2320·7265·6d6f·7665·2070··ode>..#·remove·p 
00183eb0:·6163·6b61·6765·730a·6966·2072·706d·202d··ackages.if·rpm·- 
00183ec0:·7120·2d2d·7175·6965·7420·2278·6f72·672d··q·--quiet·"xorg- 
00183ed0:·7831·312d·7365·7276·6572·2d58·6f72·6722··x11-server-Xorg" 
00183ee0:·203b·2074·6865·6e0a·646e·6620·7265·6d6f···;·then.dnf·remo 
00183ef0:·7665·202d·7920·2d2d·6e6f·6175·746f·7265··ve·-y·--noautore 
00183f00:·6d6f·7665·2022·786f·7267·2d78·3131·2d73··move·"xorg-x11-s 
00183f10:·6572·7665·722d·586f·7267·220a·6669·0a69··erver-Xorg".fi.i 
00183f20:·6620·7270·6d20·2d71·202d·2d71·7569·6574··f·rpm·-q·--quiet 
00183f30:·2022·786f·7267·2d78·3131·2d73·6572·7665···"xorg-x11-serve 
00183f40:·722d·7574·696c·7322·203b·2074·6865·6e0a··r-utils"·;·then. 
Max diff block lines reached; 414/11480 bytes (3.61%) of diff not shown.
1.86 KB
html2text {}
    
Offset 19125, 18 lines modifiedOffset 19125, 14 lines modified
19125 Rationale:··the·system.·X·windows·has·a·long·history·of·security·vulnerabilities·and·should·not·be19125 Rationale:··the·system.·X·windows·has·a·long·history·of·security·vulnerabilities·and·should·not·be
19126 ············installed·unless·approved·and·documented.19126 ············installed·unless·approved·and·documented.
19127 Severity: ··low19127 Severity: ··low
19128 Rule·ID:····xccdf_org.ssgproject.content_rule_xwindows_remove_packages19128 Rule·ID:····xccdf_org.ssgproject.content_rule_xwindows_remove_packages
19129 ············_\x8d_\x8i_\x8s_\x8a···CCI-00036619129 ············_\x8d_\x8i_\x8s_\x8a···CCI-000366
19130 References:·_\x8n_\x8i_\x8s_\x8t···CM-6(b)19130 References:·_\x8n_\x8i_\x8s_\x8t···CM-6(b)
19131 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000480-GPOS-0022719131 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000480-GPOS-00227
19132 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
19133 package·--remove=xorg-x11-server-Xorg·--remove=xorg-x11-server-common·--remove=xorg-x11-server- 
19134 utils·--remove=xorg-x11-server-Xwayland 
19135 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x819132 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
19136 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low19133 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
19137 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low19134 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
19138 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true19135 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
19139 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict19136 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
  
  
Offset 19150, 14 lines modifiedOffset 19146, 18 lines modified
19150 if·rpm·-q·--quiet·"xorg-x11-server-common"·;·then19146 if·rpm·-q·--quiet·"xorg-x11-server-common"·;·then
19151 dnf·remove·-y·--noautoremove·"xorg-x11-server-common"19147 dnf·remove·-y·--noautoremove·"xorg-x11-server-common"
19152 fi19148 fi
  
19153 if·rpm·-q·--quiet·"xorg-x11-server-Xwayland"·;·then19149 if·rpm·-q·--quiet·"xorg-x11-server-Xwayland"·;·then
19154 dnf·remove·-y·--noautoremove·"xorg-x11-server-Xwayland"19150 dnf·remove·-y·--noautoremove·"xorg-x11-server-Xwayland"
19155 fi19151 fi
 19152 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 19153 package·--remove=xorg-x11-server-Xorg·--remove=xorg-x11-server-common·--remove=xorg-x11-server-
 19154 utils·--remove=xorg-x11-server-Xwayland
19156 Group  ·System·Accounting·with·auditd·  Group·contains·7·groups·and·50·rules19155 Group  ·System·Accounting·with·auditd·  Group·contains·7·groups·and·50·rules
19157 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·audit·service·provides·substantial·capabilities·for·recording·system·activities.·By19156 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·audit·service·provides·substantial·capabilities·for·recording·system·activities.·By
19158 default,·the·service·audits·about·SELinux·AVC·denials·and·certain·types·of·security-relevant19157 default,·the·service·audits·about·SELinux·AVC·denials·and·certain·types·of·security-relevant
19159 events·such·as·system·logins,·account·modifications,·and·authentication·events·performed·by19158 events·such·as·system·logins,·account·modifications,·and·authentication·events·performed·by
19160 programs·such·as·sudo.·Under·its·default·configuration,·auditd·has·modest·disk·space·requirements,19159 programs·such·as·sudo.·Under·its·default·configuration,·auditd·has·modest·disk·space·requirements,
19161 and·should·not·noticeably·impact·system·performance.19160 and·should·not·noticeably·impact·system·performance.
  
39.3 KB
./usr/share/doc/ssg-nondebian/ssg-rhcos4-guide-high-rev-4.html
    
Offset 19069, 66 lines modifiedOffset 19069, 66 lines modified
0004a7c0:·7461·7267·6574·3d22·2369·646d·3736·3334··target="#idm76340004a7c0:·7461·7267·6574·3d22·2369·646d·3736·3334··target="#idm7634
0004a7d0:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r0004a7d0:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r
0004a7e0:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari0004a7e0:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari
0004a7f0:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals0004a7f0:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals
0004a800:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa0004a800:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa
0004a810:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr0004a810:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr
0004a820:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat0004a820:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat
 0004a830:·696f·6e20·7363·7269·7074·20e2·87b2·3c2f··ion·script·...</
0004a830:·696f·6e20·4b75·6265·726e·6574·6573·2073··ion·Kubernetes·s 
0004a840:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b 
0004a850:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa0004a840:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
0004a860:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col0004a850:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
0004a870:·6c61·7073·6522·2069·643d·2269·646d·3736··lapse"·id="idm760004a860:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
0004a880:·3334·223e·3c74·6162·6c65·2063·6c61·7373··34"><table·class0004a870:·646d·3736·3334·223e·3c74·6162·6c65·2063··dm7634"><table·c
0004a890:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st0004a880:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl
0004a8a0:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord0004a890:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-
0004a8b0:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde0004a8a0:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c
0004a8c0:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co0004a8b0:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t
0004a8d0:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t0004a8c0:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t
 0004a8d0:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
 0004a8e0:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru
 0004a8f0:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6d··ption:</th><td>m
0004a8e0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><0004a900:·6564·6975·6d3c·2f74·643e·3c2f·7472·3e3c··edium</td></tr><
0004a8f0:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio 
0004a900:·6e3a·3c2f·7468·3e3c·7464·3e6d·6564·6975··n:</th><td>mediu 
0004a910:·6d3c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··m</td></tr><tr>< 
0004a920:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th><0004a910:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</
0004a930:·7464·3e74·7275·653c·2f74·643e·3c2f·7472··td>true</td></tr0004a920:·7468·3e3c·7464·3e74·7275·653c·2f74·643e··th><td>true</td>
0004a940:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg0004a930:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str
0004a950:·793a·3c2f·7468·3e3c·7464·3e64·6973·6162··y:</th><td>disab0004a940:·6174·6567·793a·3c2f·7468·3e3c·7464·3e64··ategy:</th><td>d
0004a960:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta0004a950:·6973·6162·6c65·3c2f·7464·3e3c·2f74·723e··isable</td></tr>
0004a970:·626c·653e·3c70·7265·3e3c·636f·6465·3e61··ble><pre><code>a0004a960:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co
0004a980:·7069·5665·7273·696f·6e3a·206d·6163·6869··piVersion:·machi0004a970:·6465·3e61·7069·5665·7273·696f·6e3a·206d··de>apiVersion:·m
0004a990:·6e65·636f·6e66·6967·7572·6174·696f·6e2e··neconfiguration.0004a980:·6163·6869·6e65·636f·6e66·6967·7572·6174··achineconfigurat
0004a9a0:·6f70·656e·7368·6966·742e·696f·2f76·310a··openshift.io/v1.0004a990:·696f·6e2e·6f70·656e·7368·6966·742e·696f··ion.openshift.io
0004a9b0:·6b69·6e64·3a20·4d61·6368·696e·6543·6f6e··kind:·MachineCon0004a9a0:·2f76·310a·6b69·6e64·3a20·4d61·6368·696e··/v1.kind:·Machin
0004a9c0:·6669·670a·7370·6563·3a0a·2020·636f·6e66··fig.spec:.··conf0004a9b0:·6543·6f6e·6669·670a·7370·6563·3a0a·2020··eConfig.spec:.··
0004a9d0:·6967·3a0a·2020·2020·6967·6e69·7469·6f6e··ig:.····ignition0004a9c0:·636f·6e66·6967·3a0a·2020·2020·6967·6e69··config:.····igni
0004a9e0:·3a0a·2020·2020·2020·7665·7273·696f·6e3a··:.······version:0004a9d0:·7469·6f6e·3a0a·2020·2020·2020·7665·7273··tion:.······vers
0004a9f0:·2033·2e31·2e30·0a20·2020·2073·7973·7465···3.1.0.····syste0004a9e0:·696f·6e3a·2033·2e31·2e30·0a20·2020·2073··ion:·3.1.0.····s
0004aa00:·6d64·3a0a·2020·2020·2020·756e·6974·733a··md:.······units:0004a9f0:·7973·7465·6d64·3a0a·2020·2020·2020·756e··ystemd:.······un
 0004aa00:·6974·733a·0a20·2020·2020·202d·206e·616d··its:.······-·nam
 0004aa10:·653a·2064·6562·7567·2d73·6865·6c6c·2e73··e:·debug-shell.s
 0004aa20:·6572·7669·6365·0a20·2020·2020·2020·2065··ervice.········e
 0004aa30:·6e61·626c·6564·3a20·6661·6c73·650a·2020··nabled:·false.··
 0004aa40:·2020·2020·2020·6d61·736b·3a20·7472·7565········mask:·true
0004aa10:·0a20·2020·2020·202d·206e·616d·653a·2064··.······-·name:·d0004aa50:·0a20·2020·2020·202d·206e·616d·653a·2064··.······-·name:·d
0004aa20:·6562·7567·2d73·6865·6c6c·2e73·6572·7669··ebug-shell.servi0004aa60:·6562·7567·2d73·6865·6c6c·2e73·6f63·6b65··ebug-shell.socke
0004aa30:·6365·0a20·2020·2020·2020·2065·6e61·626c··ce.········enabl 
0004aa40:·6564·3a20·6661·6c73·650a·2020·2020·2020··ed:·false.······ 
0004aa50:·2020·6d61·736b·3a20·7472·7565·0a20·2020····mask:·true.··· 
0004aa60:·2020·202d·206e·616d·653a·2064·6562·7567·····-·name:·debug 
0004aa70:·2d73·6865·6c6c·2e73·6f63·6b65·740a·2020··-shell.socket.·· 
0004aa80:·2020·2020·2020·656e·6162·6c65·643a·2066········enabled:·f0004aa70:·740a·2020·2020·2020·2020·656e·6162·6c65··t.········enable
0004aa90:·616c·7365·0a20·2020·2020·2020·206d·6173··alse.········mas0004aa80:·643a·2066·616c·7365·0a20·2020·2020·2020··d:·false.·······
0004aaa0:·6b3a·2074·7275·650a·3c2f·636f·6465·3e3c··k:·true.</code><0004aa90:·206d·6173·6b3a·2074·7275·650a·3c2f·636f···mask:·true.</co
0004aab0:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl0004aaa0:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div><
0004aac0:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc0004aab0:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn
0004aad0:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl0004aac0:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t
0004aae0:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat0004aad0:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse"
0004aaf0:·612d·7461·7267·6574·3d22·2369·646d·3736··a-target="#idm760004aae0:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i
0004ab00:·3335·2220·7461·6269·6e64·6578·3d22·3022··35"·tabindex="0"0004aaf0:·646d·3736·3335·2220·7461·6269·6e64·6578··dm7635"·tabindex
0004ab10:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a0004ab00:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto
0004ab20:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa0004ab10:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded
0004ab30:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti0004ab20:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="
0004ab40:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·0004ab30:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve
0004ab50:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi0004ab40:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re
0004ab60:·6174·696f·6e20·7363·7269·7074·20e2·87b2··ation·script·...0004ab50:·6d65·6469·6174·696f·6e20·4b75·6265·726e··mediation·Kubern
 0004ab60:·6574·6573·2073·6e69·7070·6574·20e2·87b2··etes·snippet·...
0004ab70:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla0004ab70:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
0004ab80:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap0004ab80:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
0004ab90:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=0004ab90:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
0004aba0:·2269·646d·3736·3335·223e·3c74·6162·6c65··"idm7635"><table0004aba0:·2269·646d·3736·3335·223e·3c74·6162·6c65··"idm7635"><table
0004abb0:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta0004abb0:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta
0004abc0:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl0004abc0:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl
0004abd0:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table0004abd0:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table
Offset 34734, 66 lines modifiedOffset 34734, 66 lines modified
00087ad0:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id00087ad0:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
00087ae0:·6d31·3833·3933·2220·7461·6269·6e64·6578··m18393"·tabindex00087ae0:·6d31·3833·3933·2220·7461·6269·6e64·6578··m18393"·tabindex
00087af0:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto00087af0:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto
00087b00:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded00087b00:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded
00087b10:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="00087b10:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="
00087b20:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve00087b20:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve
00087b30:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re00087b30:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re
00087b40:·6d65·6469·6174·696f·6e20·4b75·6265·726e··mediation·Kubern 
00087b50:·6574·6573·2073·6e69·7070·6574·20e2·87b2··etes·snippet·... 
00087b60:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla 
00087b70:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap 
00087b80:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id= 
00087b90:·2269·646d·3138·3339·3322·3e3c·7461·626c··"idm18393"><tabl 
00087ba0:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t 
00087bb0:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab 
00087bc0:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl 
00087bd0:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr 
00087be0:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity: 
00087bf0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td 
00087c00:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di 
00087c10:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t 
00087c20:·643e·6d65·6469·756d·3c2f·7464·3e3c·2f74··d>medium</td></t 
00087c30:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot 
00087c40:·3a3c·2f74·683e·3c74·643e·7472·7565·3c2f··:</th><td>true</ 
00087c50:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
00087c60:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t 
00087c70:·643e·6469·7361·626c·653c·2f74·643e·3c2f··d>disable</td></ 
00087c80:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre> 
00087c90:·3c63·6f64·653e·6170·6956·6572·7369·6f6e··<code>apiVersion 
00087ca0:·3a20·6d61·6368·696e·6563·6f6e·6669·6775··:·machineconfigu 
00087cb0:·7261·7469·6f6e·2e6f·7065·6e73·6869·6674··ration.openshift 
00087cc0:·2e69·6f2f·7631·0a6b·696e·643a·204d·6163··.io/v1.kind:·Mac 
00087cd0:·6869·6e65·436f·6e66·6967·0a73·7065·633a··hineConfig.spec: 
00087ce0:·0a20·2063·6f6e·6669·673a·0a20·2020·2069··.··config:.····i 
00087cf0:·676e·6974·696f·6e3a·0a20·2020·2020·2076··gnition:.······v 
00087d00:·6572·7369·6f6e·3a20·332e·312e·300a·2020··ersion:·3.1.0.·· 
00087d10:·2020·7379·7374·656d·643a·0a20·2020·2020····systemd:.····· 
00087d20:·2075·6e69·7473·3a0a·2020·2020·2020·2d20···units:.······-· 
00087d30:·6e61·6d65·3a20·626c·7565·746f·6f74·682e··name:·bluetooth. 
00087d40:·7365·7276·6963·650a·2020·2020·2020·2020··service.········ 
00087d50:·656e·6162·6c65·643a·2066·616c·7365·0a20··enabled:·false.· 
00087d60:·2020·2020·2020·206d·6173·6b3a·2074·7275·········mask:·tru 
00087d70:·650a·2020·2020·2020·2d20·6e61·6d65·3a20··e.······-·name:· 
00087d80:·626c·7565·746f·6f74·682e·736f·636b·6574··bluetooth.socket 
00087d90:·0a20·2020·2020·2020·2065·6e61·626c·6564··.········enabled 
00087da0:·3a20·6661·6c73·650a·2020·2020·2020·2020··:·false.········ 
00087db0:·6d61·736b·3a20·7472·7565·0a3c·2f63·6f64··mask:·true.</cod 
00087dc0:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a 
00087dd0:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn- 
00087de0:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to 
Max diff block lines reached; 16750/32672 bytes (51.27%) of diff not shown.
7.24 KB
html2text {}
    
Offset 432, 15 lines modifiedOffset 432, 15 lines modified
432 Identifiers:·CCE-82496-1432 Identifiers:·CCE-82496-1
433 ·············_\x8c_\x8u_\x8i····3.4.5433 ·············_\x8c_\x8u_\x8i····3.4.5
434 ·············_\x8d_\x8i_\x8s_\x8a···CCI-000366,·CCI-002235434 ·············_\x8d_\x8i_\x8s_\x8a···CCI-000366,·CCI-002235
435 References:··_\x8h_\x8i_\x8p_\x8a_\x8a··164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),·164.310(d)(2)(iii)435 References:··_\x8h_\x8i_\x8p_\x8a_\x8a··164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),·164.310(d)(2)(iii)
436 ·············_\x8n_\x8i_\x8s_\x8t···CM-6436 ·············_\x8n_\x8i_\x8s_\x8t···CM-6
437 ·············_\x8o_\x8s_\x8p_\x8p···FIA_UAU.1437 ·············_\x8o_\x8s_\x8p_\x8p···FIA_UAU.1
438 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000324-GPOS-00125,·SRG-OS-000480-GPOS-00227438 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000324-GPOS-00125,·SRG-OS-000480-GPOS-00227
439 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_.u_.b_.e_.r_.n_.e_.t_.e_.s_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8439 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
440 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low440 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
441 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium441 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
442 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true442 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
443 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable443 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
444 apiVersion:·machineconfiguration.openshift.io/v1444 apiVersion:·machineconfiguration.openshift.io/v1
445 kind:·MachineConfig445 kind:·MachineConfig
446 spec:446 spec:
Offset 451, 15 lines modifiedOffset 451, 15 lines modified
451 ······units:451 ······units:
452 ······-·name:·debug-shell.service452 ······-·name:·debug-shell.service
453 ········enabled:·false453 ········enabled:·false
454 ········mask:·true454 ········mask:·true
455 ······-·name:·debug-shell.socket455 ······-·name:·debug-shell.socket
456 ········enabled:·false456 ········enabled:·false
457 ········mask:·true457 ········mask:·true
458 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8458 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_.u_.b_.e_.r_.n_.e_.t_.e_.s_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8
459 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low459 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
460 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium460 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
461 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true461 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
462 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable462 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
463 apiVersion:·machineconfiguration.openshift.io/v1463 apiVersion:·machineconfiguration.openshift.io/v1
464 kind:·MachineConfig464 kind:·MachineConfig
465 spec:465 spec:
Offset 1881, 15 lines modifiedOffset 1881, 15 lines modified
1881 ············_\x8c_\x8u_\x8i············3.1.161881 ············_\x8c_\x8u_\x8i············3.1.16
1882 ············_\x8d_\x8i_\x8s_\x8a···········CCI-000085,·CCI-0015511882 ············_\x8d_\x8i_\x8s_\x8a···········CCI-000085,·CCI-001551
1883 References:·_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x80_\x89·4.3.3.5.1,·4.3.3.5.2,·4.3.3.5.3,·4.3.3.5.4,·4.3.3.5.5,·4.3.3.5.6,·4.3.3.5.7,·4.3.3.5.8,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.1,·4.3.3.7.2,·4.3.3.7.3,·4.3.3.7.4,·4.3.4.3.2,·4.3.4.3.31883 References:·_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x80_\x89·4.3.3.5.1,·4.3.3.5.2,·4.3.3.5.3,·4.3.3.5.4,·4.3.3.5.5,·4.3.3.5.6,·4.3.3.5.7,·4.3.3.5.8,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.1,·4.3.3.7.2,·4.3.3.7.3,·4.3.3.7.4,·4.3.4.3.2,·4.3.4.3.3
1884 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·1.1,·SR·1.10,·SR·1.11,·SR·1.12,·SR·1.13,·SR·1.2,·SR·1.3,·SR·1.4,·SR·1.5,·SR·1.6,·SR·1.7,·SR·1.8,·SR·1.9,·SR·2.1,·SR·2.2,·SR·2.3,·SR·2.4,·SR·2.5,·SR·2.6,·SR·2.7,·SR·3.1,·SR·3.5,·SR·3.8,·SR·4.1,·SR·4.3,·SR·5.1,·SR·5.2,·SR·5.3,·SR·7.1,·SR·7.61884 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·1.1,·SR·1.10,·SR·1.11,·SR·1.12,·SR·1.13,·SR·1.2,·SR·1.3,·SR·1.4,·SR·1.5,·SR·1.6,·SR·1.7,·SR·1.8,·SR·1.9,·SR·2.1,·SR·2.2,·SR·2.3,·SR·2.4,·SR·2.5,·SR·2.6,·SR·2.7,·SR·3.1,·SR·3.5,·SR·3.8,·SR·4.1,·SR·4.3,·SR·5.1,·SR·5.2,·SR·5.3,·SR·7.1,·SR·7.6
1885 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.6,·A.12.1.2,·A.12.5.1,·A.12.6.2,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.2.1,·A.6.2.2,·A.9.1.21885 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.6,·A.12.1.2,·A.12.5.1,·A.12.6.2,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.2.1,·A.6.2.2,·A.9.1.2
1886 ············_\x8n_\x8i_\x8s_\x8t···········AC-18(a),·AC-18(3),·CM-7(a),·CM-7(b),·CM-6(a),·MP-71886 ············_\x8n_\x8i_\x8s_\x8t···········AC-18(a),·AC-18(3),·CM-7(a),·CM-7(b),·CM-6(a),·MP-7
1887 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-3,·PR.IP-1,·PR.PT-3,·PR.PT-41887 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-3,·PR.IP-1,·PR.PT-3,·PR.PT-4
1888 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_.u_.b_.e_.r_.n_.e_.t_.e_.s_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x81888 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
1889 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1889 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1890 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium1890 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
1891 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true1891 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
1892 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable1892 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
1893 apiVersion:·machineconfiguration.openshift.io/v11893 apiVersion:·machineconfiguration.openshift.io/v1
1894 kind:·MachineConfig1894 kind:·MachineConfig
1895 spec:1895 spec:
Offset 1900, 15 lines modifiedOffset 1900, 15 lines modified
1900 ······units:1900 ······units:
1901 ······-·name:·bluetooth.service1901 ······-·name:·bluetooth.service
1902 ········enabled:·false1902 ········enabled:·false
1903 ········mask:·true1903 ········mask:·true
1904 ······-·name:·bluetooth.socket1904 ······-·name:·bluetooth.socket
1905 ········enabled:·false1905 ········enabled:·false
1906 ········mask:·true1906 ········mask:·true
1907 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x81907 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_.u_.b_.e_.r_.n_.e_.t_.e_.s_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8
1908 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1908 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1909 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium1909 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
1910 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true1910 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
1911 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable1911 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
1912 apiVersion:·machineconfiguration.openshift.io/v11912 apiVersion:·machineconfiguration.openshift.io/v1
1913 kind:·MachineConfig1913 kind:·MachineConfig
1914 spec:1914 spec:
Offset 2218, 15 lines modifiedOffset 2218, 15 lines modified
2218 ·············_\x8h_\x8i_\x8p_\x8a_\x8a··········164.308(a)(3)(i),·164.308(a)(3)(ii)(A),·164.310(d)(1),·164.310(d)(2),·164.312(a)(1),·164.312(a)(2)(iv),·164.312(b)2218 ·············_\x8h_\x8i_\x8p_\x8a_\x8a··········164.308(a)(3)(i),·164.308(a)(3)(ii)(A),·164.310(d)(1),·164.310(d)(2),·164.312(a)(1),·164.312(a)(2)(iv),·164.312(b)
2219 References:··_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x80_\x89·4.3.3.2.2,·4.3.3.5.1,·4.3.3.5.2,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.2,·4.3.3.7.42219 References:··_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x80_\x89·4.3.3.2.2,·4.3.3.5.1,·4.3.3.5.2,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.2,·4.3.3.7.4
2220 ·············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·1.1,·SR·1.10,·SR·1.13,·SR·1.2,·SR·1.3,·SR·1.4,·SR·1.5,·SR·1.7,·SR·1.8,·SR·1.9,·SR·2.1,·SR·2.62220 ·············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·1.1,·SR·1.10,·SR·1.13,·SR·1.2,·SR·1.3,·SR·1.4,·SR·1.5,·SR·1.7,·SR·1.8,·SR·1.9,·SR·2.1,·SR·2.6
2221 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.6,·A.13.1.1,·A.13.2.1,·A.18.1.4,·A.6.2.1,·A.6.2.2,·A.7.1.1,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,·A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.32221 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.6,·A.13.1.1,·A.13.2.1,·A.18.1.4,·A.6.2.1,·A.6.2.2,·A.7.1.1,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,·A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.3
2222 ·············_\x8n_\x8i_\x8s_\x8t···········CM-7(a),·CM-7(b),·CM-6(a),·MP-72222 ·············_\x8n_\x8i_\x8s_\x8t···········CM-7(a),·CM-7(b),·CM-6(a),·MP-7
2223 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-1,·PR.AC-3,·PR.AC-6,·PR.AC-72223 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-1,·PR.AC-3,·PR.AC-6,·PR.AC-7
2224 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000114-GPOS-00059,·SRG-OS-000378-GPOS-00163,·SRG-OS-000480-GPOS-002272224 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000114-GPOS-00059,·SRG-OS-000378-GPOS-00163,·SRG-OS-000480-GPOS-00227
2225 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_.u_.b_.e_.r_.n_.e_.t_.e_.s_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x82225 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
2226 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low2226 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
2227 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium2227 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
2228 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true2228 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
2229 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable2229 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
2230 apiVersion:·machineconfiguration.openshift.io/v12230 apiVersion:·machineconfiguration.openshift.io/v1
2231 kind:·MachineConfig2231 kind:·MachineConfig
2232 spec:2232 spec:
Offset 2237, 15 lines modifiedOffset 2237, 15 lines modified
2237 ······units:2237 ······units:
2238 ······-·name:·autofs.service2238 ······-·name:·autofs.service
2239 ········enabled:·false2239 ········enabled:·false
2240 ········mask:·true2240 ········mask:·true
2241 ······-·name:·autofs.socket2241 ······-·name:·autofs.socket
2242 ········enabled:·false2242 ········enabled:·false
2243 ········mask:·true2243 ········mask:·true
2244 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x82244 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_.u_.b_.e_.r_.n_.e_.t_.e_.s_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8
2245 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low2245 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
2246 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium2246 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
2247 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true2247 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
2248 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable2248 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
2249 apiVersion:·machineconfiguration.openshift.io/v12249 apiVersion:·machineconfiguration.openshift.io/v1
2250 kind:·MachineConfig2250 kind:·MachineConfig
2251 spec:2251 spec:
Offset 3587, 15 lines modifiedOffset 3587, 15 lines modified
3587 For·more·information·on·how·to·configure·nodes·with·the·Machine·Config·Operator·see·_\x8t_\x8h_\x8e_\x8·_\x8r_\x8e_\x8l_\x8e_\x8v_\x8a_\x8n_\x8t_\x8·_\x8d_\x8o_\x8c_\x8u_\x8m_\x8e_\x8n_\x8t_\x8a_\x8t_\x8i_\x8o_\x8n.3587 For·more·information·on·how·to·configure·nodes·with·the·Machine·Config·Operator·see·_\x8t_\x8h_\x8e_\x8·_\x8r_\x8e_\x8l_\x8e_\x8v_\x8a_\x8n_\x8t_\x8·_\x8d_\x8o_\x8c_\x8u_\x8m_\x8e_\x8n_\x8t_\x8a_\x8t_\x8i_\x8o_\x8n.
3588 Rationale:···Red·Hat·Enterprise·Linux·CoreOS·(RHCOS)·is·a·single-purpose·container·operating·system.·RHCOS·is·only·supported·as·a·component·of·the·OpenShift·Container·Platform.·Remote·management·of·the·RHCOS·nodes·is·performed·at·the·OpenShift·Container·Platform·API·level.·As·a·result,·any·direct·remote·access·to·the·RHCOS·nodes·is·unnecessary.·Disabling·the·SSHD·service·helps·reduce·the·number·of·open·ports·on·each·host.3588 Rationale:···Red·Hat·Enterprise·Linux·CoreOS·(RHCOS)·is·a·single-purpose·container·operating·system.·RHCOS·is·only·supported·as·a·component·of·the·OpenShift·Container·Platform.·Remote·management·of·the·RHCOS·nodes·is·performed·at·the·OpenShift·Container·Platform·API·level.·As·a·result,·any·direct·remote·access·to·the·RHCOS·nodes·is·unnecessary.·Disabling·the·SSHD·service·helps·reduce·the·number·of·open·ports·on·each·host.
3589 Severity: ···high3589 Severity: ···high
3590 Rule·ID:·····xccdf_org.ssgproject.content_rule_service_sshd_disabled3590 Rule·ID:·····xccdf_org.ssgproject.content_rule_service_sshd_disabled
3591 Identifiers:·CCE-86189-83591 Identifiers:·CCE-86189-8
3592 References:··_\x8n_\x8i_\x8s_\x8t········CM-3(6),·IA-2(4)3592 References:··_\x8n_\x8i_\x8s_\x8t········CM-3(6),·IA-2(4)
3593 ·············_\x8a_\x8p_\x8p_\x8-_\x8s_\x8r_\x8g_\x8-_\x8c_\x8t_\x8r·SRG-APP-000185-CTR-000490,·SRG-APP-000141-CTR-000315,·CNTR-OS-001010,·CNTR-OS-001020,·CNTR-OS-0010303593 ·············_\x8a_\x8p_\x8p_\x8-_\x8s_\x8r_\x8g_\x8-_\x8c_\x8t_\x8r·SRG-APP-000185-CTR-000490,·SRG-APP-000141-CTR-000315,·CNTR-OS-001010,·CNTR-OS-001020,·CNTR-OS-001030
3594 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_.u_.b_.e_.r_.n_.e_.t_.e_.s_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x83594 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
3595 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low3595 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
3596 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium3596 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
3597 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true3597 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
3598 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable3598 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
3599 apiVersion:·machineconfiguration.openshift.io/v13599 apiVersion:·machineconfiguration.openshift.io/v1
3600 kind:·MachineConfig3600 kind:·MachineConfig
3601 spec:3601 spec:
Offset 3606, 15 lines modifiedOffset 3606, 15 lines modified
3606 ······units:3606 ······units:
3607 ······-·name:·sshd.service3607 ······-·name:·sshd.service
3608 ········enabled:·false3608 ········enabled:·false
3609 ········mask:·true3609 ········mask:·true
3610 ······-·name:·sshd.socket3610 ······-·name:·sshd.socket
3611 ········enabled:·false3611 ········enabled:·false
3612 ········mask:·true3612 ········mask:·true
3613 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x83613 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_.u_.b_.e_.r_.n_.e_.t_.e_.s_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8
3614 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low3614 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
3615 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium3615 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
3616 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true3616 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
3617 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable3617 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
3618 apiVersion:·machineconfiguration.openshift.io/v13618 apiVersion:·machineconfiguration.openshift.io/v1
3619 kind:·MachineConfig3619 kind:·MachineConfig
3620 spec:3620 spec:
Max diff block lines reached; -1/7394 bytes (-0.01%) of diff not shown.
39.3 KB
./usr/share/doc/ssg-nondebian/ssg-rhcos4-guide-high.html
    
Offset 19068, 67 lines modifiedOffset 19068, 67 lines modified
0004a7b0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target0004a7b0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
0004a7c0:·3d22·2369·646d·3736·3334·2220·7461·6269··="#idm7634"·tabi0004a7c0:·3d22·2369·646d·3736·3334·2220·7461·6269··="#idm7634"·tabi
0004a7d0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b0004a7d0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
0004a7e0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa0004a7e0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
0004a7f0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit0004a7f0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
0004a800:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·0004a800:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
0004a810:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!0004a810:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
0004a820:·223e·5265·6d65·6469·6174·696f·6e20·4b75··">Remediation·Ku0004a820:·223e·5265·6d65·6469·6174·696f·6e20·7363··">Remediation·sc
0004a830:·6265·726e·6574·6573·2073·6e69·7070·6574··bernetes·snippet 
0004a840:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div0004a830:·7269·7074·20e2·87b2·3c2f·613e·3c62·723e··ript·...</a><br>
0004a850:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co0004a840:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
0004a860:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"0004a850:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
0004a870:·2069·643d·2269·646d·3736·3334·223e·3c74···id="idm7634"><t0004a860:·7073·6522·2069·643d·2269·646d·3736·3334··pse"·id="idm7634
0004a880:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl0004a870:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="
0004a890:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·0004a880:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri
0004a8a0:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t0004a890:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border
0004a8b0:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">0004a8a0:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens
0004a8c0:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi0004a8b0:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp
0004a8d0:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<0004a8c0:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>
 0004a8d0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
 0004a8e0:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:
 0004a8f0:·3c2f·7468·3e3c·7464·3e6d·6564·6975·6d3c··</th><td>medium<
0004a8e0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th0004a900:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
0004a8f0:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th 
0004a900:·3e3c·7464·3e6d·6564·6975·6d3c·2f74·643e··><td>medium</td> 
0004a910:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb 
0004a920:·6f6f·743a·3c2f·7468·3e3c·7464·3e74·7275··oot:</th><td>tru0004a910:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td
0004a930:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr><0004a920:·3e74·7275·653c·2f74·643e·3c2f·7472·3e3c··>true</td></tr><
0004a940:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th0004a930:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:
0004a950:·3e3c·7464·3e64·6973·6162·6c65·3c2f·7464··><td>disable</td0004a940:·3c2f·7468·3e3c·7464·3e64·6973·6162·6c65··</th><td>disable
0004a960:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p0004a950:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl
0004a970:·7265·3e3c·636f·6465·3e61·7069·5665·7273··re><code>apiVers0004a960:·653e·3c70·7265·3e3c·636f·6465·3e61·7069··e><pre><code>api
0004a980:·696f·6e3a·206d·6163·6869·6e65·636f·6e66··ion:·machineconf0004a970:·5665·7273·696f·6e3a·206d·6163·6869·6e65··Version:·machine
0004a990:·6967·7572·6174·696f·6e2e·6f70·656e·7368··iguration.opensh0004a980:·636f·6e66·6967·7572·6174·696f·6e2e·6f70··configuration.op
0004a9a0:·6966·742e·696f·2f76·310a·6b69·6e64·3a20··ift.io/v1.kind:·0004a990:·656e·7368·6966·742e·696f·2f76·310a·6b69··enshift.io/v1.ki
0004a9b0:·4d61·6368·696e·6543·6f6e·6669·670a·7370··MachineConfig.sp0004a9a0:·6e64·3a20·4d61·6368·696e·6543·6f6e·6669··nd:·MachineConfi
0004a9c0:·6563·3a0a·2020·636f·6e66·6967·3a0a·2020··ec:.··config:.··0004a9b0:·670a·7370·6563·3a0a·2020·636f·6e66·6967··g.spec:.··config
0004a9d0:·2020·6967·6e69·7469·6f6e·3a0a·2020·2020····ignition:.····0004a9c0:·3a0a·2020·2020·6967·6e69·7469·6f6e·3a0a··:.····ignition:.
0004a9e0:·2020·7665·7273·696f·6e3a·2033·2e31·2e30····version:·3.1.00004a9d0:·2020·2020·2020·7665·7273·696f·6e3a·2033········version:·3
0004a9f0:·0a20·2020·2073·7973·7465·6d64·3a0a·2020··.····systemd:.··0004a9e0:·2e31·2e30·0a20·2020·2073·7973·7465·6d64··.1.0.····systemd
0004aa00:·2020·2020·756e·6974·733a·0a20·2020·2020······units:.·····0004a9f0:·3a0a·2020·2020·2020·756e·6974·733a·0a20··:.······units:.·
 0004aa00:·2020·2020·202d·206e·616d·653a·2064·6562·······-·name:·deb
 0004aa10:·7567·2d73·6865·6c6c·2e73·6572·7669·6365··ug-shell.service
 0004aa20:·0a20·2020·2020·2020·2065·6e61·626c·6564··.········enabled
 0004aa30:·3a20·6661·6c73·650a·2020·2020·2020·2020··:·false.········
 0004aa40:·6d61·736b·3a20·7472·7565·0a20·2020·2020··mask:·true.·····
0004aa10:·202d·206e·616d·653a·2064·6562·7567·2d73···-·name:·debug-s0004aa50:·202d·206e·616d·653a·2064·6562·7567·2d73···-·name:·debug-s
0004aa20:·6865·6c6c·2e73·6572·7669·6365·0a20·2020··hell.service.···0004aa60:·6865·6c6c·2e73·6f63·6b65·740a·2020·2020··hell.socket.····
0004aa30:·2020·2020·2065·6e61·626c·6564·3a20·6661·······enabled:·fa0004aa70:·2020·2020·656e·6162·6c65·643a·2066·616c······enabled:·fal
0004aa40:·6c73·650a·2020·2020·2020·2020·6d61·736b··lse.········mask0004aa80:·7365·0a20·2020·2020·2020·206d·6173·6b3a··se.········mask:
0004aa50:·3a20·7472·7565·0a20·2020·2020·202d·206e··:·true.······-·n 
0004aa60:·616d·653a·2064·6562·7567·2d73·6865·6c6c··ame:·debug-shell 
0004aa70:·2e73·6f63·6b65·740a·2020·2020·2020·2020··.socket.········ 
0004aa80:·656e·6162·6c65·643a·2066·616c·7365·0a20··enabled:·false.· 
0004aa90:·2020·2020·2020·206d·6173·6b3a·2074·7275·········mask:·tru 
0004aaa0:·650a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··e.</code></pre><0004aa90:·2074·7275·650a·3c2f·636f·6465·3e3c·2f70···true.</code></p
0004aab0:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b0004aaa0:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas
0004aac0:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"·0004aab0:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe
0004aad0:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col0004aac0:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle=
0004aae0:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ0004aad0:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data-
0004aaf0:·6574·3d22·2369·646d·3736·3335·2220·7461··et="#idm7635"·ta0004aae0:·7461·7267·6574·3d22·2369·646d·3736·3335··target="#idm7635
0004ab00:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=0004aaf0:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r
0004ab10:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex0004ab00:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari
0004ab20:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t0004ab10:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals
0004ab30:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t0004ab20:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa
0004ab40:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="0004ab30:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr
0004ab50:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·0004ab40:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat
 0004ab50:·696f·6e20·4b75·6265·726e·6574·6573·2073··ion·Kubernetes·s
0004ab60:·7363·7269·7074·20e2·87b2·3c2f·613e·3c62··script·...</a><b0004ab60:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b
0004ab70:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa0004ab70:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
0004ab80:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col0004ab80:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
0004ab90:·6c61·7073·6522·2069·643d·2269·646d·3736··lapse"·id="idm760004ab90:·6c61·7073·6522·2069·643d·2269·646d·3736··lapse"·id="idm76
0004aba0:·3335·223e·3c74·6162·6c65·2063·6c61·7373··35"><table·class0004aba0:·3335·223e·3c74·6162·6c65·2063·6c61·7373··35"><table·class
0004abb0:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st0004abb0:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st
0004abc0:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord0004abc0:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord
0004abd0:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde0004abd0:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde
Offset 34734, 66 lines modifiedOffset 34734, 66 lines modified
00087ad0:·6172·6765·743d·2223·6964·6d31·3833·3933··arget="#idm1839300087ad0:·6172·6765·743d·2223·6964·6d31·3833·3933··arget="#idm18393
00087ae0:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r00087ae0:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r
00087af0:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari00087af0:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari
00087b00:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals00087b00:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals
00087b10:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa00087b10:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa
00087b20:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr00087b20:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr
00087b30:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat00087b30:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat
00087b40:·696f·6e20·4b75·6265·726e·6574·6573·2073··ion·Kubernetes·s 
00087b50:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b 
00087b60:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa 
00087b70:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col 
00087b80:·6c61·7073·6522·2069·643d·2269·646d·3138··lapse"·id="idm18 
00087b90:·3339·3322·3e3c·7461·626c·6520·636c·6173··393"><table·clas 
00087ba0:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s 
00087bb0:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor 
00087bc0:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond 
00087bd0:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C 
00087be0:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th>< 
00087bf0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
00087c00:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti 
00087c10:·6f6e·3a3c·2f74·683e·3c74·643e·6d65·6469··on:</th><td>medi 
00087c20:·756d·3c2f·7464·3e3c·2f74·723e·3c74·723e··um</td></tr><tr> 
00087c30:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th> 
00087c40:·3c74·643e·7472·7565·3c2f·7464·3e3c·2f74··<td>true</td></t 
00087c50:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate 
00087c60:·6779·3a3c·2f74·683e·3c74·643e·6469·7361··gy:</th><td>disa 
00087c70:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t 
00087c80:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code> 
00087c90:·6170·6956·6572·7369·6f6e·3a20·6d61·6368··apiVersion:·mach 
00087ca0:·696e·6563·6f6e·6669·6775·7261·7469·6f6e··ineconfiguration 
00087cb0:·2e6f·7065·6e73·6869·6674·2e69·6f2f·7631··.openshift.io/v1 
00087cc0:·0a6b·696e·643a·204d·6163·6869·6e65·436f··.kind:·MachineCo 
00087cd0:·6e66·6967·0a73·7065·633a·0a20·2063·6f6e··nfig.spec:.··con 
00087ce0:·6669·673a·0a20·2020·2069·676e·6974·696f··fig:.····ignitio 
00087cf0:·6e3a·0a20·2020·2020·2076·6572·7369·6f6e··n:.······version 
00087d00:·3a20·332e·312e·300a·2020·2020·7379·7374··:·3.1.0.····syst 
00087d10:·656d·643a·0a20·2020·2020·2075·6e69·7473··emd:.······units 
00087d20:·3a0a·2020·2020·2020·2d20·6e61·6d65·3a20··:.······-·name:· 
00087d30:·626c·7565·746f·6f74·682e·7365·7276·6963··bluetooth.servic 
00087d40:·650a·2020·2020·2020·2020·656e·6162·6c65··e.········enable 
00087d50:·643a·2066·616c·7365·0a20·2020·2020·2020··d:·false.······· 
00087d60:·206d·6173·6b3a·2074·7275·650a·2020·2020···mask:·true.···· 
00087d70:·2020·2d20·6e61·6d65·3a20·626c·7565·746f····-·name:·blueto 
00087d80:·6f74·682e·736f·636b·6574·0a20·2020·2020··oth.socket.····· 
00087d90:·2020·2065·6e61·626c·6564·3a20·6661·6c73·····enabled:·fals 
00087da0:·650a·2020·2020·2020·2020·6d61·736b·3a20··e.········mask:· 
00087db0:·7472·7565·0a3c·2f63·6f64·653e·3c2f·7072··true.</code></pr 
00087dc0:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class 
00087dd0:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes 
00087de0:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle=" 
Max diff block lines reached; 16612/32672 bytes (50.84%) of diff not shown.
7.24 KB
html2text {}
    
Offset 432, 15 lines modifiedOffset 432, 15 lines modified
432 Identifiers:·CCE-82496-1432 Identifiers:·CCE-82496-1
433 ·············_\x8c_\x8u_\x8i····3.4.5433 ·············_\x8c_\x8u_\x8i····3.4.5
434 ·············_\x8d_\x8i_\x8s_\x8a···CCI-000366,·CCI-002235434 ·············_\x8d_\x8i_\x8s_\x8a···CCI-000366,·CCI-002235
435 References:··_\x8h_\x8i_\x8p_\x8a_\x8a··164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),·164.310(d)(2)(iii)435 References:··_\x8h_\x8i_\x8p_\x8a_\x8a··164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),·164.310(d)(2)(iii)
436 ·············_\x8n_\x8i_\x8s_\x8t···CM-6436 ·············_\x8n_\x8i_\x8s_\x8t···CM-6
437 ·············_\x8o_\x8s_\x8p_\x8p···FIA_UAU.1437 ·············_\x8o_\x8s_\x8p_\x8p···FIA_UAU.1
438 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000324-GPOS-00125,·SRG-OS-000480-GPOS-00227438 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000324-GPOS-00125,·SRG-OS-000480-GPOS-00227
439 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_.u_.b_.e_.r_.n_.e_.t_.e_.s_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8439 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
440 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low440 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
441 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium441 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
442 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true442 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
443 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable443 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
444 apiVersion:·machineconfiguration.openshift.io/v1444 apiVersion:·machineconfiguration.openshift.io/v1
445 kind:·MachineConfig445 kind:·MachineConfig
446 spec:446 spec:
Offset 451, 15 lines modifiedOffset 451, 15 lines modified
451 ······units:451 ······units:
452 ······-·name:·debug-shell.service452 ······-·name:·debug-shell.service
453 ········enabled:·false453 ········enabled:·false
454 ········mask:·true454 ········mask:·true
455 ······-·name:·debug-shell.socket455 ······-·name:·debug-shell.socket
456 ········enabled:·false456 ········enabled:·false
457 ········mask:·true457 ········mask:·true
458 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8458 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_.u_.b_.e_.r_.n_.e_.t_.e_.s_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8
459 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low459 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
460 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium460 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
461 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true461 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
462 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable462 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
463 apiVersion:·machineconfiguration.openshift.io/v1463 apiVersion:·machineconfiguration.openshift.io/v1
464 kind:·MachineConfig464 kind:·MachineConfig
465 spec:465 spec:
Offset 1881, 15 lines modifiedOffset 1881, 15 lines modified
1881 ············_\x8c_\x8u_\x8i············3.1.161881 ············_\x8c_\x8u_\x8i············3.1.16
1882 ············_\x8d_\x8i_\x8s_\x8a···········CCI-000085,·CCI-0015511882 ············_\x8d_\x8i_\x8s_\x8a···········CCI-000085,·CCI-001551
1883 References:·_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x80_\x89·4.3.3.5.1,·4.3.3.5.2,·4.3.3.5.3,·4.3.3.5.4,·4.3.3.5.5,·4.3.3.5.6,·4.3.3.5.7,·4.3.3.5.8,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.1,·4.3.3.7.2,·4.3.3.7.3,·4.3.3.7.4,·4.3.4.3.2,·4.3.4.3.31883 References:·_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x80_\x89·4.3.3.5.1,·4.3.3.5.2,·4.3.3.5.3,·4.3.3.5.4,·4.3.3.5.5,·4.3.3.5.6,·4.3.3.5.7,·4.3.3.5.8,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.1,·4.3.3.7.2,·4.3.3.7.3,·4.3.3.7.4,·4.3.4.3.2,·4.3.4.3.3
1884 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·1.1,·SR·1.10,·SR·1.11,·SR·1.12,·SR·1.13,·SR·1.2,·SR·1.3,·SR·1.4,·SR·1.5,·SR·1.6,·SR·1.7,·SR·1.8,·SR·1.9,·SR·2.1,·SR·2.2,·SR·2.3,·SR·2.4,·SR·2.5,·SR·2.6,·SR·2.7,·SR·3.1,·SR·3.5,·SR·3.8,·SR·4.1,·SR·4.3,·SR·5.1,·SR·5.2,·SR·5.3,·SR·7.1,·SR·7.61884 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·1.1,·SR·1.10,·SR·1.11,·SR·1.12,·SR·1.13,·SR·1.2,·SR·1.3,·SR·1.4,·SR·1.5,·SR·1.6,·SR·1.7,·SR·1.8,·SR·1.9,·SR·2.1,·SR·2.2,·SR·2.3,·SR·2.4,·SR·2.5,·SR·2.6,·SR·2.7,·SR·3.1,·SR·3.5,·SR·3.8,·SR·4.1,·SR·4.3,·SR·5.1,·SR·5.2,·SR·5.3,·SR·7.1,·SR·7.6
1885 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.6,·A.12.1.2,·A.12.5.1,·A.12.6.2,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.2.1,·A.6.2.2,·A.9.1.21885 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.6,·A.12.1.2,·A.12.5.1,·A.12.6.2,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.2.1,·A.6.2.2,·A.9.1.2
1886 ············_\x8n_\x8i_\x8s_\x8t···········AC-18(a),·AC-18(3),·CM-7(a),·CM-7(b),·CM-6(a),·MP-71886 ············_\x8n_\x8i_\x8s_\x8t···········AC-18(a),·AC-18(3),·CM-7(a),·CM-7(b),·CM-6(a),·MP-7
1887 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-3,·PR.IP-1,·PR.PT-3,·PR.PT-41887 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-3,·PR.IP-1,·PR.PT-3,·PR.PT-4
1888 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_.u_.b_.e_.r_.n_.e_.t_.e_.s_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x81888 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
1889 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1889 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1890 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium1890 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
1891 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true1891 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
1892 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable1892 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
1893 apiVersion:·machineconfiguration.openshift.io/v11893 apiVersion:·machineconfiguration.openshift.io/v1
1894 kind:·MachineConfig1894 kind:·MachineConfig
1895 spec:1895 spec:
Offset 1900, 15 lines modifiedOffset 1900, 15 lines modified
1900 ······units:1900 ······units:
1901 ······-·name:·bluetooth.service1901 ······-·name:·bluetooth.service
1902 ········enabled:·false1902 ········enabled:·false
1903 ········mask:·true1903 ········mask:·true
1904 ······-·name:·bluetooth.socket1904 ······-·name:·bluetooth.socket
1905 ········enabled:·false1905 ········enabled:·false
1906 ········mask:·true1906 ········mask:·true
1907 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x81907 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_.u_.b_.e_.r_.n_.e_.t_.e_.s_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8
1908 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1908 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1909 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium1909 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
1910 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true1910 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
1911 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable1911 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
1912 apiVersion:·machineconfiguration.openshift.io/v11912 apiVersion:·machineconfiguration.openshift.io/v1
1913 kind:·MachineConfig1913 kind:·MachineConfig
1914 spec:1914 spec:
Offset 2218, 15 lines modifiedOffset 2218, 15 lines modified
2218 ·············_\x8h_\x8i_\x8p_\x8a_\x8a··········164.308(a)(3)(i),·164.308(a)(3)(ii)(A),·164.310(d)(1),·164.310(d)(2),·164.312(a)(1),·164.312(a)(2)(iv),·164.312(b)2218 ·············_\x8h_\x8i_\x8p_\x8a_\x8a··········164.308(a)(3)(i),·164.308(a)(3)(ii)(A),·164.310(d)(1),·164.310(d)(2),·164.312(a)(1),·164.312(a)(2)(iv),·164.312(b)
2219 References:··_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x80_\x89·4.3.3.2.2,·4.3.3.5.1,·4.3.3.5.2,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.2,·4.3.3.7.42219 References:··_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x80_\x89·4.3.3.2.2,·4.3.3.5.1,·4.3.3.5.2,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.2,·4.3.3.7.4
2220 ·············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·1.1,·SR·1.10,·SR·1.13,·SR·1.2,·SR·1.3,·SR·1.4,·SR·1.5,·SR·1.7,·SR·1.8,·SR·1.9,·SR·2.1,·SR·2.62220 ·············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·1.1,·SR·1.10,·SR·1.13,·SR·1.2,·SR·1.3,·SR·1.4,·SR·1.5,·SR·1.7,·SR·1.8,·SR·1.9,·SR·2.1,·SR·2.6
2221 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.6,·A.13.1.1,·A.13.2.1,·A.18.1.4,·A.6.2.1,·A.6.2.2,·A.7.1.1,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,·A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.32221 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.6,·A.13.1.1,·A.13.2.1,·A.18.1.4,·A.6.2.1,·A.6.2.2,·A.7.1.1,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,·A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.3
2222 ·············_\x8n_\x8i_\x8s_\x8t···········CM-7(a),·CM-7(b),·CM-6(a),·MP-72222 ·············_\x8n_\x8i_\x8s_\x8t···········CM-7(a),·CM-7(b),·CM-6(a),·MP-7
2223 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-1,·PR.AC-3,·PR.AC-6,·PR.AC-72223 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-1,·PR.AC-3,·PR.AC-6,·PR.AC-7
2224 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000114-GPOS-00059,·SRG-OS-000378-GPOS-00163,·SRG-OS-000480-GPOS-002272224 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000114-GPOS-00059,·SRG-OS-000378-GPOS-00163,·SRG-OS-000480-GPOS-00227
2225 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_.u_.b_.e_.r_.n_.e_.t_.e_.s_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x82225 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
2226 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low2226 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
2227 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium2227 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
2228 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true2228 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
2229 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable2229 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
2230 apiVersion:·machineconfiguration.openshift.io/v12230 apiVersion:·machineconfiguration.openshift.io/v1
2231 kind:·MachineConfig2231 kind:·MachineConfig
2232 spec:2232 spec:
Offset 2237, 15 lines modifiedOffset 2237, 15 lines modified
2237 ······units:2237 ······units:
2238 ······-·name:·autofs.service2238 ······-·name:·autofs.service
2239 ········enabled:·false2239 ········enabled:·false
2240 ········mask:·true2240 ········mask:·true
2241 ······-·name:·autofs.socket2241 ······-·name:·autofs.socket
2242 ········enabled:·false2242 ········enabled:·false
2243 ········mask:·true2243 ········mask:·true
2244 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x82244 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_.u_.b_.e_.r_.n_.e_.t_.e_.s_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8
2245 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low2245 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
2246 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium2246 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
2247 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true2247 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
2248 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable2248 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
2249 apiVersion:·machineconfiguration.openshift.io/v12249 apiVersion:·machineconfiguration.openshift.io/v1
2250 kind:·MachineConfig2250 kind:·MachineConfig
2251 spec:2251 spec:
Offset 3587, 15 lines modifiedOffset 3587, 15 lines modified
3587 For·more·information·on·how·to·configure·nodes·with·the·Machine·Config·Operator·see·_\x8t_\x8h_\x8e_\x8·_\x8r_\x8e_\x8l_\x8e_\x8v_\x8a_\x8n_\x8t_\x8·_\x8d_\x8o_\x8c_\x8u_\x8m_\x8e_\x8n_\x8t_\x8a_\x8t_\x8i_\x8o_\x8n.3587 For·more·information·on·how·to·configure·nodes·with·the·Machine·Config·Operator·see·_\x8t_\x8h_\x8e_\x8·_\x8r_\x8e_\x8l_\x8e_\x8v_\x8a_\x8n_\x8t_\x8·_\x8d_\x8o_\x8c_\x8u_\x8m_\x8e_\x8n_\x8t_\x8a_\x8t_\x8i_\x8o_\x8n.
3588 Rationale:···Red·Hat·Enterprise·Linux·CoreOS·(RHCOS)·is·a·single-purpose·container·operating·system.·RHCOS·is·only·supported·as·a·component·of·the·OpenShift·Container·Platform.·Remote·management·of·the·RHCOS·nodes·is·performed·at·the·OpenShift·Container·Platform·API·level.·As·a·result,·any·direct·remote·access·to·the·RHCOS·nodes·is·unnecessary.·Disabling·the·SSHD·service·helps·reduce·the·number·of·open·ports·on·each·host.3588 Rationale:···Red·Hat·Enterprise·Linux·CoreOS·(RHCOS)·is·a·single-purpose·container·operating·system.·RHCOS·is·only·supported·as·a·component·of·the·OpenShift·Container·Platform.·Remote·management·of·the·RHCOS·nodes·is·performed·at·the·OpenShift·Container·Platform·API·level.·As·a·result,·any·direct·remote·access·to·the·RHCOS·nodes·is·unnecessary.·Disabling·the·SSHD·service·helps·reduce·the·number·of·open·ports·on·each·host.
3589 Severity: ···high3589 Severity: ···high
3590 Rule·ID:·····xccdf_org.ssgproject.content_rule_service_sshd_disabled3590 Rule·ID:·····xccdf_org.ssgproject.content_rule_service_sshd_disabled
3591 Identifiers:·CCE-86189-83591 Identifiers:·CCE-86189-8
3592 References:··_\x8n_\x8i_\x8s_\x8t········CM-3(6),·IA-2(4)3592 References:··_\x8n_\x8i_\x8s_\x8t········CM-3(6),·IA-2(4)
3593 ·············_\x8a_\x8p_\x8p_\x8-_\x8s_\x8r_\x8g_\x8-_\x8c_\x8t_\x8r·SRG-APP-000185-CTR-000490,·SRG-APP-000141-CTR-000315,·CNTR-OS-001010,·CNTR-OS-001020,·CNTR-OS-0010303593 ·············_\x8a_\x8p_\x8p_\x8-_\x8s_\x8r_\x8g_\x8-_\x8c_\x8t_\x8r·SRG-APP-000185-CTR-000490,·SRG-APP-000141-CTR-000315,·CNTR-OS-001010,·CNTR-OS-001020,·CNTR-OS-001030
3594 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_.u_.b_.e_.r_.n_.e_.t_.e_.s_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x83594 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
3595 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low3595 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
3596 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium3596 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
3597 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true3597 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
3598 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable3598 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
3599 apiVersion:·machineconfiguration.openshift.io/v13599 apiVersion:·machineconfiguration.openshift.io/v1
3600 kind:·MachineConfig3600 kind:·MachineConfig
3601 spec:3601 spec:
Offset 3606, 15 lines modifiedOffset 3606, 15 lines modified
3606 ······units:3606 ······units:
3607 ······-·name:·sshd.service3607 ······-·name:·sshd.service
3608 ········enabled:·false3608 ········enabled:·false
3609 ········mask:·true3609 ········mask:·true
3610 ······-·name:·sshd.socket3610 ······-·name:·sshd.socket
3611 ········enabled:·false3611 ········enabled:·false
3612 ········mask:·true3612 ········mask:·true
3613 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x83613 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_.u_.b_.e_.r_.n_.e_.t_.e_.s_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8
3614 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low3614 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
3615 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium3615 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
3616 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true3616 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
3617 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable3617 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
3618 apiVersion:·machineconfiguration.openshift.io/v13618 apiVersion:·machineconfiguration.openshift.io/v1
3619 kind:·MachineConfig3619 kind:·MachineConfig
3620 spec:3620 spec:
Max diff block lines reached; -1/7394 bytes (-0.01%) of diff not shown.
29.6 KB
./usr/share/doc/ssg-nondebian/ssg-rhcos4-guide-moderate-rev-4.html
    
Offset 19070, 66 lines modifiedOffset 19070, 66 lines modified
0004a7d0:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm0004a7d0:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
0004a7e0:·3736·3334·2220·7461·6269·6e64·6578·3d22··7634"·tabindex="0004a7e0:·3736·3334·2220·7461·6269·6e64·6578·3d22··7634"·tabindex="
0004a7f0:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"0004a7f0:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
0004a800:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="0004a800:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
0004a810:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac0004a810:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
0004a820:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal0004a820:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
0004a830:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme0004a830:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
0004a840:·6469·6174·696f·6e20·4b75·6265·726e·6574··diation·Kubernet0004a840:·6469·6174·696f·6e20·7363·7269·7074·20e2··diation·script·.
0004a850:·6573·2073·6e69·7070·6574·20e2·87b2·3c2f··es·snippet·...</ 
0004a860:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class0004a850:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c
0004a870:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse0004a860:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
0004a880:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i0004a870:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
0004a890:·646d·3736·3334·223e·3c74·6162·6c65·2063··dm7634"><table·c0004a880:·643d·2269·646d·3736·3334·223e·3c74·6162··d="idm7634"><tab
0004a8a0:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl0004a890:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·
0004a8b0:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-0004a8a0:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta
0004a8c0:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c0004a8b0:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab
0004a8d0:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t0004a8c0:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t
0004a8e0:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t0004a8d0:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity
0004a8f0:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></0004a8e0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
0004a900:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru 
0004a910:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6d··ption:</th><td>m 
0004a920:·6564·6975·6d3c·2f74·643e·3c2f·7472·3e3c··edium</td></tr>< 
0004a930:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</ 
0004a940:·7468·3e3c·7464·3e74·7275·653c·2f74·643e··th><td>true</td> 
0004a950:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str0004a8f0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D
 0004a900:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><
 0004a910:·7464·3e6d·6564·6975·6d3c·2f74·643e·3c2f··td>medium</td></
 0004a920:·7472·3e3c·7472·3e3c·7468·3e52·6562·6f6f··tr><tr><th>Reboo
 0004a930:·743a·3c2f·7468·3e3c·7464·3e74·7275·653c··t:</th><td>true<
 0004a940:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
0004a960:·6174·6567·793a·3c2f·7468·3e3c·7464·3e64··ategy:</th><td>d0004a950:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><
0004a970:·6973·6162·6c65·3c2f·7464·3e3c·2f74·723e··isable</td></tr>0004a960:·7464·3e64·6973·6162·6c65·3c2f·7464·3e3c··td>disable</td><
0004a980:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co0004a970:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre
0004a990:·6465·3e61·7069·5665·7273·696f·6e3a·206d··de>apiVersion:·m0004a980:·3e3c·636f·6465·3e61·7069·5665·7273·696f··><code>apiVersio
0004a9a0:·6163·6869·6e65·636f·6e66·6967·7572·6174··achineconfigurat0004a990:·6e3a·206d·6163·6869·6e65·636f·6e66·6967··n:·machineconfig
0004a9b0:·696f·6e2e·6f70·656e·7368·6966·742e·696f··ion.openshift.io0004a9a0:·7572·6174·696f·6e2e·6f70·656e·7368·6966··uration.openshif
0004a9c0:·2f76·310a·6b69·6e64·3a20·4d61·6368·696e··/v1.kind:·Machin0004a9b0:·742e·696f·2f76·310a·6b69·6e64·3a20·4d61··t.io/v1.kind:·Ma
0004a9d0:·6543·6f6e·6669·670a·7370·6563·3a0a·2020··eConfig.spec:.··0004a9c0:·6368·696e·6543·6f6e·6669·670a·7370·6563··chineConfig.spec
0004a9e0:·636f·6e66·6967·3a0a·2020·2020·6967·6e69··config:.····igni0004a9d0:·3a0a·2020·636f·6e66·6967·3a0a·2020·2020··:.··config:.····
0004a9f0:·7469·6f6e·3a0a·2020·2020·2020·7665·7273··tion:.······vers0004a9e0:·6967·6e69·7469·6f6e·3a0a·2020·2020·2020··ignition:.······
0004aa00:·696f·6e3a·2033·2e31·2e30·0a20·2020·2073··ion:·3.1.0.····s0004a9f0:·7665·7273·696f·6e3a·2033·2e31·2e30·0a20··version:·3.1.0.·
0004aa10:·7973·7465·6d64·3a0a·2020·2020·2020·756e··ystemd:.······un0004aa00:·2020·2073·7973·7465·6d64·3a0a·2020·2020·····systemd:.····
 0004aa10:·2020·756e·6974·733a·0a20·2020·2020·202d····units:.······-
 0004aa20:·206e·616d·653a·2064·6562·7567·2d73·6865···name:·debug-she
 0004aa30:·6c6c·2e73·6572·7669·6365·0a20·2020·2020··ll.service.·····
 0004aa40:·2020·2065·6e61·626c·6564·3a20·6661·6c73·····enabled:·fals
 0004aa50:·650a·2020·2020·2020·2020·6d61·736b·3a20··e.········mask:·
0004aa20:·6974·733a·0a20·2020·2020·202d·206e·616d··its:.······-·nam0004aa60:·7472·7565·0a20·2020·2020·202d·206e·616d··true.······-·nam
0004aa30:·653a·2064·6562·7567·2d73·6865·6c6c·2e73··e:·debug-shell.s0004aa70:·653a·2064·6562·7567·2d73·6865·6c6c·2e73··e:·debug-shell.s
0004aa40:·6572·7669·6365·0a20·2020·2020·2020·2065··ervice.········e 
0004aa50:·6e61·626c·6564·3a20·6661·6c73·650a·2020··nabled:·false.·· 
0004aa60:·2020·2020·2020·6d61·736b·3a20·7472·7565········mask:·true 
0004aa70:·0a20·2020·2020·202d·206e·616d·653a·2064··.······-·name:·d 
0004aa80:·6562·7567·2d73·6865·6c6c·2e73·6f63·6b65··ebug-shell.socke 
0004aa90:·740a·2020·2020·2020·2020·656e·6162·6c65··t.········enable0004aa80:·6f63·6b65·740a·2020·2020·2020·2020·656e··ocket.········en
0004aaa0:·643a·2066·616c·7365·0a20·2020·2020·2020··d:·false.·······0004aa90:·6162·6c65·643a·2066·616c·7365·0a20·2020··abled:·false.···
0004aab0:·206d·6173·6b3a·2074·7275·650a·3c2f·636f···mask:·true.</co0004aaa0:·2020·2020·206d·6173·6b3a·2074·7275·650a·······mask:·true.
0004aac0:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div><0004aab0:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d
0004aad0:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn0004aac0:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn
0004aae0:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t0004aad0:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da
0004aaf0:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse"0004aae0:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla
0004ab00:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i0004aaf0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
0004ab10:·646d·3736·3335·2220·7461·6269·6e64·6578··dm7635"·tabindex0004ab00:·3d22·2369·646d·3736·3335·2220·7461·6269··="#idm7635"·tabi
0004ab20:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto0004ab10:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
0004ab30:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded0004ab20:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
0004ab40:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="0004ab30:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
0004ab50:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve0004ab40:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
0004ab60:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re0004ab50:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
0004ab70:·6d65·6469·6174·696f·6e20·7363·7269·7074··mediation·script0004ab60:·223e·5265·6d65·6469·6174·696f·6e20·4b75··">Remediation·Ku
 0004ab70:·6265·726e·6574·6573·2073·6e69·7070·6574··bernetes·snippet
0004ab80:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div0004ab80:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
0004ab90:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co0004ab90:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
0004aba0:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"0004aba0:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
0004abb0:·2069·643d·2269·646d·3736·3335·223e·3c74···id="idm7635"><t0004abb0:·2069·643d·2269·646d·3736·3335·223e·3c74···id="idm7635"><t
0004abc0:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl0004abc0:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl
0004abd0:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·0004abd0:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·
0004abe0:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t0004abe0:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t
Offset 34735, 67 lines modifiedOffset 34735, 67 lines modified
00087ae0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=00087ae0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
00087af0:·2223·6964·6d31·3833·3933·2220·7461·6269··"#idm18393"·tabi00087af0:·2223·6964·6d31·3833·3933·2220·7461·6269··"#idm18393"·tabi
00087b00:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b00087b00:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
00087b10:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa00087b10:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
00087b20:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit00087b20:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
00087b30:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·00087b30:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
00087b40:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!00087b40:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
00087b50:·223e·5265·6d65·6469·6174·696f·6e20·4b75··">Remediation·Ku00087b50:·223e·5265·6d65·6469·6174·696f·6e20·7363··">Remediation·sc
00087b60:·6265·726e·6574·6573·2073·6e69·7070·6574··bernetes·snippet 
00087b70:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div00087b60:·7269·7074·20e2·87b2·3c2f·613e·3c62·723e··ript·...</a><br>
00087b80:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co00087b70:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
00087b90:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"00087b80:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
00087ba0:·2069·643d·2269·646d·3138·3339·3322·3e3c···id="idm18393"><00087b90:·7073·6522·2069·643d·2269·646d·3138·3339··pse"·id="idm1839
00087bb0:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab00087ba0:·3322·3e3c·7461·626c·6520·636c·6173·733d··3"><table·class=
00087bc0:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped00087bb0:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str
00087bd0:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·00087bc0:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde
00087be0:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"00087bd0:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden
00087bf0:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex00087be0:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com
00087c00:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low00087bf0:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td
 00087c00:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
 00087c10:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption
 00087c20:·3a3c·2f74·683e·3c74·643e·6d65·6469·756d··:</th><td>medium
00087c10:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t00087c30:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
00087c20:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t 
00087c30:·683e·3c74·643e·6d65·6469·756d·3c2f·7464··h><td>medium</td 
00087c40:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re 
00087c50:·626f·6f74·3a3c·2f74·683e·3c74·643e·7472··boot:</th><td>tr00087c40:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t
00087c60:·7565·3c2f·7464·3e3c·2f74·723e·3c74·723e··ue</td></tr><tr>00087c50:·643e·7472·7565·3c2f·7464·3e3c·2f74·723e··d>true</td></tr>
00087c70:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t00087c60:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy
00087c80:·683e·3c74·643e·6469·7361·626c·653c·2f74··h><td>disable</t00087c70:·3a3c·2f74·683e·3c74·643e·6469·7361·626c··:</th><td>disabl
00087c90:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><00087c80:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab
00087ca0:·7072·653e·3c63·6f64·653e·6170·6956·6572··pre><code>apiVer00087c90:·6c65·3e3c·7072·653e·3c63·6f64·653e·6170··le><pre><code>ap
00087cb0:·7369·6f6e·3a20·6d61·6368·696e·6563·6f6e··sion:·machinecon00087ca0:·6956·6572·7369·6f6e·3a20·6d61·6368·696e··iVersion:·machin
00087cc0:·6669·6775·7261·7469·6f6e·2e6f·7065·6e73··figuration.opens00087cb0:·6563·6f6e·6669·6775·7261·7469·6f6e·2e6f··econfiguration.o
00087cd0:·6869·6674·2e69·6f2f·7631·0a6b·696e·643a··hift.io/v1.kind:00087cc0:·7065·6e73·6869·6674·2e69·6f2f·7631·0a6b··penshift.io/v1.k
00087ce0:·204d·6163·6869·6e65·436f·6e66·6967·0a73···MachineConfig.s00087cd0:·696e·643a·204d·6163·6869·6e65·436f·6e66··ind:·MachineConf
00087cf0:·7065·633a·0a20·2063·6f6e·6669·673a·0a20··pec:.··config:.·00087ce0:·6967·0a73·7065·633a·0a20·2063·6f6e·6669··ig.spec:.··confi
00087d00:·2020·2069·676e·6974·696f·6e3a·0a20·2020·····ignition:.···00087cf0:·673a·0a20·2020·2069·676e·6974·696f·6e3a··g:.····ignition:
00087d10:·2020·2076·6572·7369·6f6e·3a20·332e·312e·····version:·3.1.00087d00:·0a20·2020·2020·2076·6572·7369·6f6e·3a20··.······version:·
00087d20:·300a·2020·2020·7379·7374·656d·643a·0a20··0.····systemd:.·00087d10:·332e·312e·300a·2020·2020·7379·7374·656d··3.1.0.····system
00087d30:·2020·2020·2075·6e69·7473·3a0a·2020·2020·······units:.····00087d20:·643a·0a20·2020·2020·2075·6e69·7473·3a0a··d:.······units:.
 00087d30:·2020·2020·2020·2d20·6e61·6d65·3a20·626c········-·name:·bl
 00087d40:·7565·746f·6f74·682e·7365·7276·6963·650a··uetooth.service.
 00087d50:·2020·2020·2020·2020·656e·6162·6c65·643a··········enabled:
 00087d60:·2066·616c·7365·0a20·2020·2020·2020·206d···false.········m
 00087d70:·6173·6b3a·2074·7275·650a·2020·2020·2020··ask:·true.······
00087d40:·2020·2d20·6e61·6d65·3a20·626c·7565·746f····-·name:·blueto00087d80:·2d20·6e61·6d65·3a20·626c·7565·746f·6f74··-·name:·bluetoot
00087d50:·6f74·682e·7365·7276·6963·650a·2020·2020··oth.service.···· 
00087d60:·2020·2020·656e·6162·6c65·643a·2066·616c······enabled:·fal 
Max diff block lines reached; 8582/24642 bytes (34.83%) of diff not shown.
5.4 KB
html2text {}
    
Offset 432, 15 lines modifiedOffset 432, 15 lines modified
432 Identifiers:·CCE-82496-1432 Identifiers:·CCE-82496-1
433 ·············_\x8c_\x8u_\x8i····3.4.5433 ·············_\x8c_\x8u_\x8i····3.4.5
434 ·············_\x8d_\x8i_\x8s_\x8a···CCI-000366,·CCI-002235434 ·············_\x8d_\x8i_\x8s_\x8a···CCI-000366,·CCI-002235
435 References:··_\x8h_\x8i_\x8p_\x8a_\x8a··164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),·164.310(d)(2)(iii)435 References:··_\x8h_\x8i_\x8p_\x8a_\x8a··164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),·164.310(d)(2)(iii)
436 ·············_\x8n_\x8i_\x8s_\x8t···CM-6436 ·············_\x8n_\x8i_\x8s_\x8t···CM-6
437 ·············_\x8o_\x8s_\x8p_\x8p···FIA_UAU.1437 ·············_\x8o_\x8s_\x8p_\x8p···FIA_UAU.1
438 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000324-GPOS-00125,·SRG-OS-000480-GPOS-00227438 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000324-GPOS-00125,·SRG-OS-000480-GPOS-00227
439 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_.u_.b_.e_.r_.n_.e_.t_.e_.s_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8439 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
440 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low440 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
441 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium441 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
442 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true442 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
443 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable443 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
444 apiVersion:·machineconfiguration.openshift.io/v1444 apiVersion:·machineconfiguration.openshift.io/v1
445 kind:·MachineConfig445 kind:·MachineConfig
446 spec:446 spec:
Offset 451, 15 lines modifiedOffset 451, 15 lines modified
451 ······units:451 ······units:
452 ······-·name:·debug-shell.service452 ······-·name:·debug-shell.service
453 ········enabled:·false453 ········enabled:·false
454 ········mask:·true454 ········mask:·true
455 ······-·name:·debug-shell.socket455 ······-·name:·debug-shell.socket
456 ········enabled:·false456 ········enabled:·false
457 ········mask:·true457 ········mask:·true
458 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8458 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_.u_.b_.e_.r_.n_.e_.t_.e_.s_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8
459 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low459 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
460 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium460 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
461 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true461 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
462 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable462 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
463 apiVersion:·machineconfiguration.openshift.io/v1463 apiVersion:·machineconfiguration.openshift.io/v1
464 kind:·MachineConfig464 kind:·MachineConfig
465 spec:465 spec:
Offset 1881, 15 lines modifiedOffset 1881, 15 lines modified
1881 ············_\x8c_\x8u_\x8i············3.1.161881 ············_\x8c_\x8u_\x8i············3.1.16
1882 ············_\x8d_\x8i_\x8s_\x8a···········CCI-000085,·CCI-0015511882 ············_\x8d_\x8i_\x8s_\x8a···········CCI-000085,·CCI-001551
1883 References:·_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x80_\x89·4.3.3.5.1,·4.3.3.5.2,·4.3.3.5.3,·4.3.3.5.4,·4.3.3.5.5,·4.3.3.5.6,·4.3.3.5.7,·4.3.3.5.8,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.1,·4.3.3.7.2,·4.3.3.7.3,·4.3.3.7.4,·4.3.4.3.2,·4.3.4.3.31883 References:·_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x80_\x89·4.3.3.5.1,·4.3.3.5.2,·4.3.3.5.3,·4.3.3.5.4,·4.3.3.5.5,·4.3.3.5.6,·4.3.3.5.7,·4.3.3.5.8,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.1,·4.3.3.7.2,·4.3.3.7.3,·4.3.3.7.4,·4.3.4.3.2,·4.3.4.3.3
1884 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·1.1,·SR·1.10,·SR·1.11,·SR·1.12,·SR·1.13,·SR·1.2,·SR·1.3,·SR·1.4,·SR·1.5,·SR·1.6,·SR·1.7,·SR·1.8,·SR·1.9,·SR·2.1,·SR·2.2,·SR·2.3,·SR·2.4,·SR·2.5,·SR·2.6,·SR·2.7,·SR·3.1,·SR·3.5,·SR·3.8,·SR·4.1,·SR·4.3,·SR·5.1,·SR·5.2,·SR·5.3,·SR·7.1,·SR·7.61884 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·1.1,·SR·1.10,·SR·1.11,·SR·1.12,·SR·1.13,·SR·1.2,·SR·1.3,·SR·1.4,·SR·1.5,·SR·1.6,·SR·1.7,·SR·1.8,·SR·1.9,·SR·2.1,·SR·2.2,·SR·2.3,·SR·2.4,·SR·2.5,·SR·2.6,·SR·2.7,·SR·3.1,·SR·3.5,·SR·3.8,·SR·4.1,·SR·4.3,·SR·5.1,·SR·5.2,·SR·5.3,·SR·7.1,·SR·7.6
1885 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.6,·A.12.1.2,·A.12.5.1,·A.12.6.2,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.2.1,·A.6.2.2,·A.9.1.21885 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.6,·A.12.1.2,·A.12.5.1,·A.12.6.2,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.2.1,·A.6.2.2,·A.9.1.2
1886 ············_\x8n_\x8i_\x8s_\x8t···········AC-18(a),·AC-18(3),·CM-7(a),·CM-7(b),·CM-6(a),·MP-71886 ············_\x8n_\x8i_\x8s_\x8t···········AC-18(a),·AC-18(3),·CM-7(a),·CM-7(b),·CM-6(a),·MP-7
1887 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-3,·PR.IP-1,·PR.PT-3,·PR.PT-41887 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-3,·PR.IP-1,·PR.PT-3,·PR.PT-4
1888 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_.u_.b_.e_.r_.n_.e_.t_.e_.s_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x81888 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
1889 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1889 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1890 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium1890 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
1891 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true1891 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
1892 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable1892 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
1893 apiVersion:·machineconfiguration.openshift.io/v11893 apiVersion:·machineconfiguration.openshift.io/v1
1894 kind:·MachineConfig1894 kind:·MachineConfig
1895 spec:1895 spec:
Offset 1900, 15 lines modifiedOffset 1900, 15 lines modified
1900 ······units:1900 ······units:
1901 ······-·name:·bluetooth.service1901 ······-·name:·bluetooth.service
1902 ········enabled:·false1902 ········enabled:·false
1903 ········mask:·true1903 ········mask:·true
1904 ······-·name:·bluetooth.socket1904 ······-·name:·bluetooth.socket
1905 ········enabled:·false1905 ········enabled:·false
1906 ········mask:·true1906 ········mask:·true
1907 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x81907 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_.u_.b_.e_.r_.n_.e_.t_.e_.s_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8
1908 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1908 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1909 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium1909 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
1910 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true1910 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
1911 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable1911 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
1912 apiVersion:·machineconfiguration.openshift.io/v11912 apiVersion:·machineconfiguration.openshift.io/v1
1913 kind:·MachineConfig1913 kind:·MachineConfig
1914 spec:1914 spec:
Offset 2218, 15 lines modifiedOffset 2218, 15 lines modified
2218 ·············_\x8h_\x8i_\x8p_\x8a_\x8a··········164.308(a)(3)(i),·164.308(a)(3)(ii)(A),·164.310(d)(1),·164.310(d)(2),·164.312(a)(1),·164.312(a)(2)(iv),·164.312(b)2218 ·············_\x8h_\x8i_\x8p_\x8a_\x8a··········164.308(a)(3)(i),·164.308(a)(3)(ii)(A),·164.310(d)(1),·164.310(d)(2),·164.312(a)(1),·164.312(a)(2)(iv),·164.312(b)
2219 References:··_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x80_\x89·4.3.3.2.2,·4.3.3.5.1,·4.3.3.5.2,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.2,·4.3.3.7.42219 References:··_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x80_\x89·4.3.3.2.2,·4.3.3.5.1,·4.3.3.5.2,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.2,·4.3.3.7.4
2220 ·············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·1.1,·SR·1.10,·SR·1.13,·SR·1.2,·SR·1.3,·SR·1.4,·SR·1.5,·SR·1.7,·SR·1.8,·SR·1.9,·SR·2.1,·SR·2.62220 ·············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·1.1,·SR·1.10,·SR·1.13,·SR·1.2,·SR·1.3,·SR·1.4,·SR·1.5,·SR·1.7,·SR·1.8,·SR·1.9,·SR·2.1,·SR·2.6
2221 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.6,·A.13.1.1,·A.13.2.1,·A.18.1.4,·A.6.2.1,·A.6.2.2,·A.7.1.1,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,·A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.32221 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.6,·A.13.1.1,·A.13.2.1,·A.18.1.4,·A.6.2.1,·A.6.2.2,·A.7.1.1,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,·A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.3
2222 ·············_\x8n_\x8i_\x8s_\x8t···········CM-7(a),·CM-7(b),·CM-6(a),·MP-72222 ·············_\x8n_\x8i_\x8s_\x8t···········CM-7(a),·CM-7(b),·CM-6(a),·MP-7
2223 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-1,·PR.AC-3,·PR.AC-6,·PR.AC-72223 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-1,·PR.AC-3,·PR.AC-6,·PR.AC-7
2224 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000114-GPOS-00059,·SRG-OS-000378-GPOS-00163,·SRG-OS-000480-GPOS-002272224 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000114-GPOS-00059,·SRG-OS-000378-GPOS-00163,·SRG-OS-000480-GPOS-00227
2225 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_.u_.b_.e_.r_.n_.e_.t_.e_.s_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x82225 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
2226 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low2226 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
2227 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium2227 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
2228 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true2228 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
2229 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable2229 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
2230 apiVersion:·machineconfiguration.openshift.io/v12230 apiVersion:·machineconfiguration.openshift.io/v1
2231 kind:·MachineConfig2231 kind:·MachineConfig
2232 spec:2232 spec:
Offset 2237, 15 lines modifiedOffset 2237, 15 lines modified
2237 ······units:2237 ······units:
2238 ······-·name:·autofs.service2238 ······-·name:·autofs.service
2239 ········enabled:·false2239 ········enabled:·false
2240 ········mask:·true2240 ········mask:·true
2241 ······-·name:·autofs.socket2241 ······-·name:·autofs.socket
2242 ········enabled:·false2242 ········enabled:·false
2243 ········mask:·true2243 ········mask:·true
2244 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x82244 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_.u_.b_.e_.r_.n_.e_.t_.e_.s_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8
2245 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low2245 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
2246 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium2246 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
2247 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true2247 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
2248 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable2248 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
2249 apiVersion:·machineconfiguration.openshift.io/v12249 apiVersion:·machineconfiguration.openshift.io/v1
2250 kind:·MachineConfig2250 kind:·MachineConfig
2251 spec:2251 spec:
29.3 KB
./usr/share/doc/ssg-nondebian/ssg-rhcos4-guide-moderate.html
    
Offset 19070, 66 lines modifiedOffset 19070, 66 lines modified
0004a7d0:·7267·6574·3d22·2369·646d·3736·3334·2220··rget="#idm7634"·0004a7d0:·7267·6574·3d22·2369·646d·3736·3334·2220··rget="#idm7634"·
0004a7e0:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol0004a7e0:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol
0004a7f0:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-0004a7f0:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-
0004a800:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"0004a800:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"
0004a810:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate0004a810:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate
0004a820:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href0004a820:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href
0004a830:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio0004a830:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio
 0004a840:·6e20·7363·7269·7074·20e2·87b2·3c2f·613e··n·script·...</a>
0004a840:·6e20·4b75·6265·726e·6574·6573·2073·6e69··n·Kubernetes·sni 
0004a850:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br> 
0004a860:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane0004a850:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="
0004a870:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla0004a860:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c
0004a880:·7073·6522·2069·643d·2269·646d·3736·3334··pse"·id="idm76340004a870:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm
0004a890:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="0004a880:·3736·3334·223e·3c74·6162·6c65·2063·6c61··7634"><table·cla
0004a8a0:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri0004a890:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-
0004a8b0:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border0004a8a0:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo
0004a8c0:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens0004a8b0:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con
0004a8d0:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp0004a8c0:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>
0004a8e0:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>0004a8d0:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>
 0004a8e0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
 0004a8f0:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt
 0004a900:·696f·6e3a·3c2f·7468·3e3c·7464·3e6d·6564··ion:</th><td>med
0004a8f0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr0004a910:·6975·6d3c·2f74·643e·3c2f·7472·3e3c·7472··ium</td></tr><tr
0004a900:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption: 
0004a910:·3c2f·7468·3e3c·7464·3e6d·6564·6975·6d3c··</th><td>medium< 
0004a920:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0004a930:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td0004a920:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th
0004a940:·3e74·7275·653c·2f74·643e·3c2f·7472·3e3c··>true</td></tr><0004a930:·3e3c·7464·3e74·7275·653c·2f74·643e·3c2f··><td>true</td></
0004a950:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:0004a940:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat
0004a960:·3c2f·7468·3e3c·7464·3e64·6973·6162·6c65··</th><td>disable0004a950:·6567·793a·3c2f·7468·3e3c·7464·3e64·6973··egy:</th><td>dis
0004a970:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl0004a960:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></
0004a980:·653e·3c70·7265·3e3c·636f·6465·3e61·7069··e><pre><code>api0004a970:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code
0004a990:·5665·7273·696f·6e3a·206d·6163·6869·6e65··Version:·machine0004a980:·3e61·7069·5665·7273·696f·6e3a·206d·6163··>apiVersion:·mac
0004a9a0:·636f·6e66·6967·7572·6174·696f·6e2e·6f70··configuration.op0004a990:·6869·6e65·636f·6e66·6967·7572·6174·696f··hineconfiguratio
0004a9b0:·656e·7368·6966·742e·696f·2f76·310a·6b69··enshift.io/v1.ki0004a9a0:·6e2e·6f70·656e·7368·6966·742e·696f·2f76··n.openshift.io/v
0004a9c0:·6e64·3a20·4d61·6368·696e·6543·6f6e·6669··nd:·MachineConfi0004a9b0:·310a·6b69·6e64·3a20·4d61·6368·696e·6543··1.kind:·MachineC
0004a9d0:·670a·7370·6563·3a0a·2020·636f·6e66·6967··g.spec:.··config0004a9c0:·6f6e·6669·670a·7370·6563·3a0a·2020·636f··onfig.spec:.··co
0004a9e0:·3a0a·2020·2020·6967·6e69·7469·6f6e·3a0a··:.····ignition:.0004a9d0:·6e66·6967·3a0a·2020·2020·6967·6e69·7469··nfig:.····igniti
0004a9f0:·2020·2020·2020·7665·7273·696f·6e3a·2033········version:·30004a9e0:·6f6e·3a0a·2020·2020·2020·7665·7273·696f··on:.······versio
0004aa00:·2e31·2e30·0a20·2020·2073·7973·7465·6d64··.1.0.····systemd0004a9f0:·6e3a·2033·2e31·2e30·0a20·2020·2073·7973··n:·3.1.0.····sys
0004aa10:·3a0a·2020·2020·2020·756e·6974·733a·0a20··:.······units:.·0004aa00:·7465·6d64·3a0a·2020·2020·2020·756e·6974··temd:.······unit
 0004aa10:·733a·0a20·2020·2020·202d·206e·616d·653a··s:.······-·name:
 0004aa20:·2064·6562·7567·2d73·6865·6c6c·2e73·6572···debug-shell.ser
 0004aa30:·7669·6365·0a20·2020·2020·2020·2065·6e61··vice.········ena
 0004aa40:·626c·6564·3a20·6661·6c73·650a·2020·2020··bled:·false.····
 0004aa50:·2020·2020·6d61·736b·3a20·7472·7565·0a20······mask:·true.·
0004aa20:·2020·2020·202d·206e·616d·653a·2064·6562·······-·name:·deb0004aa60:·2020·2020·202d·206e·616d·653a·2064·6562·······-·name:·deb
0004aa30:·7567·2d73·6865·6c6c·2e73·6572·7669·6365··ug-shell.service 
0004aa40:·0a20·2020·2020·2020·2065·6e61·626c·6564··.········enabled 
0004aa50:·3a20·6661·6c73·650a·2020·2020·2020·2020··:·false.········ 
0004aa60:·6d61·736b·3a20·7472·7565·0a20·2020·2020··mask:·true.····· 
0004aa70:·202d·206e·616d·653a·2064·6562·7567·2d73···-·name:·debug-s 
0004aa80:·6865·6c6c·2e73·6f63·6b65·740a·2020·2020··hell.socket.····0004aa70:·7567·2d73·6865·6c6c·2e73·6f63·6b65·740a··ug-shell.socket.
0004aa90:·2020·2020·656e·6162·6c65·643a·2066·616c······enabled:·fal0004aa80:·2020·2020·2020·2020·656e·6162·6c65·643a··········enabled:
0004aaa0:·7365·0a20·2020·2020·2020·206d·6173·6b3a··se.········mask:0004aa90:·2066·616c·7365·0a20·2020·2020·2020·206d···false.········m
0004aab0:·2074·7275·650a·3c2f·636f·6465·3e3c·2f70···true.</code></p0004aaa0:·6173·6b3a·2074·7275·650a·3c2f·636f·6465··ask:·true.</code
0004aac0:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas0004aab0:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a·
0004aad0:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe0004aac0:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s
0004aae0:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle=0004aad0:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog
0004aaf0:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data-0004aae0:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d
0004ab00:·7461·7267·6574·3d22·2369·646d·3736·3335··target="#idm76350004aaf0:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
0004ab10:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r0004ab00:·3736·3335·2220·7461·6269·6e64·6578·3d22··7635"·tabindex="
0004ab20:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari0004ab10:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
0004ab30:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals0004ab20:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
0004ab40:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa0004ab30:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
0004ab50:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr0004ab40:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
0004ab60:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat0004ab50:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
0004ab70:·696f·6e20·7363·7269·7074·20e2·87b2·3c2f··ion·script·...</0004ab60:·6469·6174·696f·6e20·4b75·6265·726e·6574··diation·Kubernet
 0004ab70:·6573·2073·6e69·7070·6574·20e2·87b2·3c2f··es·snippet·...</
0004ab80:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class0004ab80:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
0004ab90:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse0004ab90:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
0004aba0:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i0004aba0:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
0004abb0:·646d·3736·3335·223e·3c74·6162·6c65·2063··dm7635"><table·c0004abb0:·646d·3736·3335·223e·3c74·6162·6c65·2063··dm7635"><table·c
0004abc0:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl0004abc0:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl
0004abd0:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-0004abd0:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-
0004abe0:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c0004abe0:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c
Offset 34735, 66 lines modifiedOffset 34735, 66 lines modified
00087ae0:·7461·2d74·6172·6765·743d·2223·6964·6d31··ta-target="#idm100087ae0:·7461·2d74·6172·6765·743d·2223·6964·6d31··ta-target="#idm1
00087af0:·3833·3933·2220·7461·6269·6e64·6578·3d22··8393"·tabindex="00087af0:·3833·3933·2220·7461·6269·6e64·6578·3d22··8393"·tabindex="
00087b00:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"00087b00:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
00087b10:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="00087b10:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
00087b20:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac00087b20:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
00087b30:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal00087b30:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
00087b40:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme00087b40:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
00087b50:·6469·6174·696f·6e20·4b75·6265·726e·6574··diation·Kubernet 
00087b60:·6573·2073·6e69·7070·6574·20e2·87b2·3c2f··es·snippet·...</ 
00087b70:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class 
00087b80:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse 
00087b90:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i 
00087ba0:·646d·3138·3339·3322·3e3c·7461·626c·6520··dm18393"><table· 
00087bb0:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab 
00087bc0:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table 
00087bd0:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table- 
00087be0:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr>< 
00087bf0:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</ 
00087c00:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td>< 
00087c10:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr 
00087c20:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td> 
00087c30:·6d65·6469·756d·3c2f·7464·3e3c·2f74·723e··medium</td></tr> 
00087c40:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:< 
00087c50:·2f74·683e·3c74·643e·7472·7565·3c2f·7464··/th><td>true</td 
00087c60:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St 
00087c70:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td> 
00087c80:·6469·7361·626c·653c·2f74·643e·3c2f·7472··disable</td></tr 
00087c90:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c 
00087ca0:·6f64·653e·6170·6956·6572·7369·6f6e·3a20··ode>apiVersion:· 
00087cb0:·6d61·6368·696e·6563·6f6e·6669·6775·7261··machineconfigura 
00087cc0:·7469·6f6e·2e6f·7065·6e73·6869·6674·2e69··tion.openshift.i 
00087cd0:·6f2f·7631·0a6b·696e·643a·204d·6163·6869··o/v1.kind:·Machi 
00087ce0:·6e65·436f·6e66·6967·0a73·7065·633a·0a20··neConfig.spec:.· 
00087cf0:·2063·6f6e·6669·673a·0a20·2020·2069·676e···config:.····ign 
00087d00:·6974·696f·6e3a·0a20·2020·2020·2076·6572··ition:.······ver 
00087d10:·7369·6f6e·3a20·332e·312e·300a·2020·2020··sion:·3.1.0.···· 
00087d20:·7379·7374·656d·643a·0a20·2020·2020·2075··systemd:.······u 
00087d30:·6e69·7473·3a0a·2020·2020·2020·2d20·6e61··nits:.······-·na 
00087d40:·6d65·3a20·626c·7565·746f·6f74·682e·7365··me:·bluetooth.se 
00087d50:·7276·6963·650a·2020·2020·2020·2020·656e··rvice.········en 
00087d60:·6162·6c65·643a·2066·616c·7365·0a20·2020··abled:·false.··· 
00087d70:·2020·2020·206d·6173·6b3a·2074·7275·650a·······mask:·true. 
00087d80:·2020·2020·2020·2d20·6e61·6d65·3a20·626c········-·name:·bl 
00087d90:·7565·746f·6f74·682e·736f·636b·6574·0a20··uetooth.socket.· 
00087da0:·2020·2020·2020·2065·6e61·626c·6564·3a20·········enabled:· 
00087db0:·6661·6c73·650a·2020·2020·2020·2020·6d61··false.········ma 
00087dc0:·736b·3a20·7472·7565·0a3c·2f63·6f64·653e··sk:·true.</code> 
00087dd0:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c 
00087de0:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su 
00087df0:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg 
Max diff block lines reached; 8444/24366 bytes (34.65%) of diff not shown.
5.4 KB
html2text {}
    
Offset 432, 15 lines modifiedOffset 432, 15 lines modified
432 Identifiers:·CCE-82496-1432 Identifiers:·CCE-82496-1
433 ·············_\x8c_\x8u_\x8i····3.4.5433 ·············_\x8c_\x8u_\x8i····3.4.5
434 ·············_\x8d_\x8i_\x8s_\x8a···CCI-000366,·CCI-002235434 ·············_\x8d_\x8i_\x8s_\x8a···CCI-000366,·CCI-002235
435 References:··_\x8h_\x8i_\x8p_\x8a_\x8a··164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),·164.310(d)(2)(iii)435 References:··_\x8h_\x8i_\x8p_\x8a_\x8a··164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),·164.310(d)(2)(iii)
436 ·············_\x8n_\x8i_\x8s_\x8t···CM-6436 ·············_\x8n_\x8i_\x8s_\x8t···CM-6
437 ·············_\x8o_\x8s_\x8p_\x8p···FIA_UAU.1437 ·············_\x8o_\x8s_\x8p_\x8p···FIA_UAU.1
438 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000324-GPOS-00125,·SRG-OS-000480-GPOS-00227438 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000324-GPOS-00125,·SRG-OS-000480-GPOS-00227
439 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_.u_.b_.e_.r_.n_.e_.t_.e_.s_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8439 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
440 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low440 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
441 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium441 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
442 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true442 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
443 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable443 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
444 apiVersion:·machineconfiguration.openshift.io/v1444 apiVersion:·machineconfiguration.openshift.io/v1
445 kind:·MachineConfig445 kind:·MachineConfig
446 spec:446 spec:
Offset 451, 15 lines modifiedOffset 451, 15 lines modified
451 ······units:451 ······units:
452 ······-·name:·debug-shell.service452 ······-·name:·debug-shell.service
453 ········enabled:·false453 ········enabled:·false
454 ········mask:·true454 ········mask:·true
455 ······-·name:·debug-shell.socket455 ······-·name:·debug-shell.socket
456 ········enabled:·false456 ········enabled:·false
457 ········mask:·true457 ········mask:·true
458 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8458 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_.u_.b_.e_.r_.n_.e_.t_.e_.s_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8
459 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low459 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
460 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium460 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
461 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true461 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
462 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable462 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
463 apiVersion:·machineconfiguration.openshift.io/v1463 apiVersion:·machineconfiguration.openshift.io/v1
464 kind:·MachineConfig464 kind:·MachineConfig
465 spec:465 spec:
Offset 1881, 15 lines modifiedOffset 1881, 15 lines modified
1881 ············_\x8c_\x8u_\x8i············3.1.161881 ············_\x8c_\x8u_\x8i············3.1.16
1882 ············_\x8d_\x8i_\x8s_\x8a···········CCI-000085,·CCI-0015511882 ············_\x8d_\x8i_\x8s_\x8a···········CCI-000085,·CCI-001551
1883 References:·_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x80_\x89·4.3.3.5.1,·4.3.3.5.2,·4.3.3.5.3,·4.3.3.5.4,·4.3.3.5.5,·4.3.3.5.6,·4.3.3.5.7,·4.3.3.5.8,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.1,·4.3.3.7.2,·4.3.3.7.3,·4.3.3.7.4,·4.3.4.3.2,·4.3.4.3.31883 References:·_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x80_\x89·4.3.3.5.1,·4.3.3.5.2,·4.3.3.5.3,·4.3.3.5.4,·4.3.3.5.5,·4.3.3.5.6,·4.3.3.5.7,·4.3.3.5.8,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.1,·4.3.3.7.2,·4.3.3.7.3,·4.3.3.7.4,·4.3.4.3.2,·4.3.4.3.3
1884 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·1.1,·SR·1.10,·SR·1.11,·SR·1.12,·SR·1.13,·SR·1.2,·SR·1.3,·SR·1.4,·SR·1.5,·SR·1.6,·SR·1.7,·SR·1.8,·SR·1.9,·SR·2.1,·SR·2.2,·SR·2.3,·SR·2.4,·SR·2.5,·SR·2.6,·SR·2.7,·SR·3.1,·SR·3.5,·SR·3.8,·SR·4.1,·SR·4.3,·SR·5.1,·SR·5.2,·SR·5.3,·SR·7.1,·SR·7.61884 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·1.1,·SR·1.10,·SR·1.11,·SR·1.12,·SR·1.13,·SR·1.2,·SR·1.3,·SR·1.4,·SR·1.5,·SR·1.6,·SR·1.7,·SR·1.8,·SR·1.9,·SR·2.1,·SR·2.2,·SR·2.3,·SR·2.4,·SR·2.5,·SR·2.6,·SR·2.7,·SR·3.1,·SR·3.5,·SR·3.8,·SR·4.1,·SR·4.3,·SR·5.1,·SR·5.2,·SR·5.3,·SR·7.1,·SR·7.6
1885 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.6,·A.12.1.2,·A.12.5.1,·A.12.6.2,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.2.1,·A.6.2.2,·A.9.1.21885 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.6,·A.12.1.2,·A.12.5.1,·A.12.6.2,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.2.1,·A.6.2.2,·A.9.1.2
1886 ············_\x8n_\x8i_\x8s_\x8t···········AC-18(a),·AC-18(3),·CM-7(a),·CM-7(b),·CM-6(a),·MP-71886 ············_\x8n_\x8i_\x8s_\x8t···········AC-18(a),·AC-18(3),·CM-7(a),·CM-7(b),·CM-6(a),·MP-7
1887 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-3,·PR.IP-1,·PR.PT-3,·PR.PT-41887 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-3,·PR.IP-1,·PR.PT-3,·PR.PT-4
1888 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_.u_.b_.e_.r_.n_.e_.t_.e_.s_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x81888 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
1889 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1889 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1890 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium1890 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
1891 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true1891 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
1892 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable1892 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
1893 apiVersion:·machineconfiguration.openshift.io/v11893 apiVersion:·machineconfiguration.openshift.io/v1
1894 kind:·MachineConfig1894 kind:·MachineConfig
1895 spec:1895 spec:
Offset 1900, 15 lines modifiedOffset 1900, 15 lines modified
1900 ······units:1900 ······units:
1901 ······-·name:·bluetooth.service1901 ······-·name:·bluetooth.service
1902 ········enabled:·false1902 ········enabled:·false
1903 ········mask:·true1903 ········mask:·true
1904 ······-·name:·bluetooth.socket1904 ······-·name:·bluetooth.socket
1905 ········enabled:·false1905 ········enabled:·false
1906 ········mask:·true1906 ········mask:·true
1907 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x81907 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_.u_.b_.e_.r_.n_.e_.t_.e_.s_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8
1908 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1908 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1909 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium1909 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
1910 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true1910 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
1911 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable1911 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
1912 apiVersion:·machineconfiguration.openshift.io/v11912 apiVersion:·machineconfiguration.openshift.io/v1
1913 kind:·MachineConfig1913 kind:·MachineConfig
1914 spec:1914 spec:
Offset 2218, 15 lines modifiedOffset 2218, 15 lines modified
2218 ·············_\x8h_\x8i_\x8p_\x8a_\x8a··········164.308(a)(3)(i),·164.308(a)(3)(ii)(A),·164.310(d)(1),·164.310(d)(2),·164.312(a)(1),·164.312(a)(2)(iv),·164.312(b)2218 ·············_\x8h_\x8i_\x8p_\x8a_\x8a··········164.308(a)(3)(i),·164.308(a)(3)(ii)(A),·164.310(d)(1),·164.310(d)(2),·164.312(a)(1),·164.312(a)(2)(iv),·164.312(b)
2219 References:··_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x80_\x89·4.3.3.2.2,·4.3.3.5.1,·4.3.3.5.2,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.2,·4.3.3.7.42219 References:··_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x80_\x89·4.3.3.2.2,·4.3.3.5.1,·4.3.3.5.2,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.2,·4.3.3.7.4
2220 ·············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·1.1,·SR·1.10,·SR·1.13,·SR·1.2,·SR·1.3,·SR·1.4,·SR·1.5,·SR·1.7,·SR·1.8,·SR·1.9,·SR·2.1,·SR·2.62220 ·············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·1.1,·SR·1.10,·SR·1.13,·SR·1.2,·SR·1.3,·SR·1.4,·SR·1.5,·SR·1.7,·SR·1.8,·SR·1.9,·SR·2.1,·SR·2.6
2221 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.6,·A.13.1.1,·A.13.2.1,·A.18.1.4,·A.6.2.1,·A.6.2.2,·A.7.1.1,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,·A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.32221 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.6,·A.13.1.1,·A.13.2.1,·A.18.1.4,·A.6.2.1,·A.6.2.2,·A.7.1.1,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,·A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.3
2222 ·············_\x8n_\x8i_\x8s_\x8t···········CM-7(a),·CM-7(b),·CM-6(a),·MP-72222 ·············_\x8n_\x8i_\x8s_\x8t···········CM-7(a),·CM-7(b),·CM-6(a),·MP-7
2223 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-1,·PR.AC-3,·PR.AC-6,·PR.AC-72223 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-1,·PR.AC-3,·PR.AC-6,·PR.AC-7
2224 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000114-GPOS-00059,·SRG-OS-000378-GPOS-00163,·SRG-OS-000480-GPOS-002272224 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000114-GPOS-00059,·SRG-OS-000378-GPOS-00163,·SRG-OS-000480-GPOS-00227
2225 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_.u_.b_.e_.r_.n_.e_.t_.e_.s_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x82225 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
2226 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low2226 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
2227 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium2227 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
2228 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true2228 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
2229 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable2229 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
2230 apiVersion:·machineconfiguration.openshift.io/v12230 apiVersion:·machineconfiguration.openshift.io/v1
2231 kind:·MachineConfig2231 kind:·MachineConfig
2232 spec:2232 spec:
Offset 2237, 15 lines modifiedOffset 2237, 15 lines modified
2237 ······units:2237 ······units:
2238 ······-·name:·autofs.service2238 ······-·name:·autofs.service
2239 ········enabled:·false2239 ········enabled:·false
2240 ········mask:·true2240 ········mask:·true
2241 ······-·name:·autofs.socket2241 ······-·name:·autofs.socket
2242 ········enabled:·false2242 ········enabled:·false
2243 ········mask:·true2243 ········mask:·true
2244 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x82244 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_.u_.b_.e_.r_.n_.e_.t_.e_.s_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8
2245 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low2245 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
2246 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium2246 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
2247 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true2247 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
2248 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable2248 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
2249 apiVersion:·machineconfiguration.openshift.io/v12249 apiVersion:·machineconfiguration.openshift.io/v1
2250 kind:·MachineConfig2250 kind:·MachineConfig
2251 spec:2251 spec:
29.6 KB
./usr/share/doc/ssg-nondebian/ssg-rhcos4-guide-nerc-cip.html
    
Offset 19028, 67 lines modifiedOffset 19028, 67 lines modified
0004a530:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#0004a530:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
0004a540:·6964·6d37·3633·3422·2074·6162·696e·6465··idm7634"·tabinde0004a540:·6964·6d37·3633·3422·2074·6162·696e·6465··idm7634"·tabinde
0004a550:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt0004a550:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt
0004a560:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande0004a560:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande
0004a570:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=0004a570:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=
0004a580:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev0004a580:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev
0004a590:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R0004a590:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R
0004a5a0:·656d·6564·6961·7469·6f6e·204b·7562·6572··emediation·Kuber0004a5a0:·656d·6564·6961·7469·6f6e·2073·6372·6970··emediation·scrip
0004a5b0:·6e65·7465·7320·736e·6970·7065·7420·e287··netes·snippet·.. 
0004a5c0:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl0004a5b0:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di
0004a5d0:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla0004a5c0:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c
0004a5e0:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id0004a5d0:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse
0004a5f0:·3d22·6964·6d37·3633·3422·3e3c·7461·626c··="idm7634"><tabl0004a5e0:·2220·6964·3d22·6964·6d37·3633·3422·3e3c··"·id="idm7634"><
0004a600:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t0004a5f0:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab
0004a610:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab0004a600:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped
0004a620:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl0004a610:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·
0004a630:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr0004a620:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"
0004a640:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:0004a630:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex
0004a650:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td0004a640:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low
 0004a650:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
 0004a660:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t
 0004a670:·683e·3c74·643e·6d65·6469·756d·3c2f·7464··h><td>medium</td
0004a660:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di0004a680:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re
0004a670:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t 
0004a680:·643e·6d65·6469·756d·3c2f·7464·3e3c·2f74··d>medium</td></t 
0004a690:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot 
0004a6a0:·3a3c·2f74·683e·3c74·643e·7472·7565·3c2f··:</th><td>true</0004a690:·626f·6f74·3a3c·2f74·683e·3c74·643e·7472··boot:</th><td>tr
0004a6b0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>0004a6a0:·7565·3c2f·7464·3e3c·2f74·723e·3c74·723e··ue</td></tr><tr>
0004a6c0:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t0004a6b0:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t
0004a6d0:·643e·6469·7361·626c·653c·2f74·643e·3c2f··d>disable</td></0004a6c0:·683e·3c74·643e·6469·7361·626c·653c·2f74··h><td>disable</t
0004a6e0:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>0004a6d0:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><
0004a6f0:·3c63·6f64·653e·6170·6956·6572·7369·6f6e··<code>apiVersion0004a6e0:·7072·653e·3c63·6f64·653e·6170·6956·6572··pre><code>apiVer
0004a700:·3a20·6d61·6368·696e·6563·6f6e·6669·6775··:·machineconfigu0004a6f0:·7369·6f6e·3a20·6d61·6368·696e·6563·6f6e··sion:·machinecon
0004a710:·7261·7469·6f6e·2e6f·7065·6e73·6869·6674··ration.openshift0004a700:·6669·6775·7261·7469·6f6e·2e6f·7065·6e73··figuration.opens
0004a720:·2e69·6f2f·7631·0a6b·696e·643a·204d·6163··.io/v1.kind:·Mac0004a710:·6869·6674·2e69·6f2f·7631·0a6b·696e·643a··hift.io/v1.kind:
0004a730:·6869·6e65·436f·6e66·6967·0a73·7065·633a··hineConfig.spec:0004a720:·204d·6163·6869·6e65·436f·6e66·6967·0a73···MachineConfig.s
0004a740:·0a20·2063·6f6e·6669·673a·0a20·2020·2069··.··config:.····i0004a730:·7065·633a·0a20·2063·6f6e·6669·673a·0a20··pec:.··config:.·
0004a750:·676e·6974·696f·6e3a·0a20·2020·2020·2076··gnition:.······v0004a740:·2020·2069·676e·6974·696f·6e3a·0a20·2020·····ignition:.···
0004a760:·6572·7369·6f6e·3a20·332e·312e·300a·2020··ersion:·3.1.0.··0004a750:·2020·2076·6572·7369·6f6e·3a20·332e·312e·····version:·3.1.
0004a770:·2020·7379·7374·656d·643a·0a20·2020·2020····systemd:.·····0004a760:·300a·2020·2020·7379·7374·656d·643a·0a20··0.····systemd:.·
0004a780:·2075·6e69·7473·3a0a·2020·2020·2020·2d20···units:.······-·0004a770:·2020·2020·2075·6e69·7473·3a0a·2020·2020·······units:.····
 0004a780:·2020·2d20·6e61·6d65·3a20·6465·6275·672d····-·name:·debug-
 0004a790:·7368·656c·6c2e·7365·7276·6963·650a·2020··shell.service.··
 0004a7a0:·2020·2020·2020·656e·6162·6c65·643a·2066········enabled:·f
 0004a7b0:·616c·7365·0a20·2020·2020·2020·206d·6173··alse.········mas
 0004a7c0:·6b3a·2074·7275·650a·2020·2020·2020·2d20··k:·true.······-·
0004a790:·6e61·6d65·3a20·6465·6275·672d·7368·656c··name:·debug-shel0004a7d0:·6e61·6d65·3a20·6465·6275·672d·7368·656c··name:·debug-shel
0004a7a0:·6c2e·7365·7276·6963·650a·2020·2020·2020··l.service.······0004a7e0:·6c2e·736f·636b·6574·0a20·2020·2020·2020··l.socket.·······
0004a7b0:·2020·656e·6162·6c65·643a·2066·616c·7365····enabled:·false 
0004a7c0:·0a20·2020·2020·2020·206d·6173·6b3a·2074··.········mask:·t 
0004a7d0:·7275·650a·2020·2020·2020·2d20·6e61·6d65··rue.······-·name 
0004a7e0:·3a20·6465·6275·672d·7368·656c·6c2e·736f··:·debug-shell.so 
0004a7f0:·636b·6574·0a20·2020·2020·2020·2065·6e61··cket.········ena 
0004a800:·626c·6564·3a20·6661·6c73·650a·2020·2020··bled:·false.····0004a7f0:·2065·6e61·626c·6564·3a20·6661·6c73·650a···enabled:·false.
0004a810:·2020·2020·6d61·736b·3a20·7472·7565·0a3c······mask:·true.<0004a800:·2020·2020·2020·2020·6d61·736b·3a20·7472··········mask:·tr
0004a820:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di0004a810:·7565·0a3c·2f63·6f64·653e·3c2f·7072·653e··ue.</code></pre>
0004a830:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn·0004a820:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class="
0004a840:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat0004a830:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success"
0004a850:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap0004a840:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co
0004a860:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=0004a850:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar
0004a870:·2223·6964·6d37·3633·3522·2074·6162·696e··"#idm7635"·tabin0004a860:·6765·743d·2223·6964·6d37·3633·3522·2074··get="#idm7635"·t
0004a880:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu0004a870:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
0004a890:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan0004a880:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
0004a8a0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl0004a890:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
0004a8b0:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r0004a8a0:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
0004a8c0:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"0004a8b0:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
0004a8d0:·3e52·656d·6564·6961·7469·6f6e·2073·6372··>Remediation·scr0004a8c0:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
 0004a8d0:·204b·7562·6572·6e65·7465·7320·736e·6970···Kubernetes·snip
0004a8e0:·6970·7420·e287·b23c·2f61·3e3c·6272·3e3c··ipt·...</a><br><0004a8e0:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br><
0004a8f0:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel0004a8f0:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
0004a900:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap0004a900:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap
0004a910:·7365·2220·6964·3d22·6964·6d37·3633·3522··se"·id="idm7635"0004a910:·7365·2220·6964·3d22·6964·6d37·3633·3522··se"·id="idm7635"
0004a920:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t0004a920:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t
0004a930:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip0004a930:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip
0004a940:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere0004a940:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere
0004a950:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense0004a950:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense
Offset 34694, 66 lines modifiedOffset 34694, 66 lines modified
00087850:·6574·3d22·2369·646d·3138·3339·3322·2074··et="#idm18393"·t00087850:·6574·3d22·2369·646d·3138·3339·3322·2074··et="#idm18393"·t
00087860:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role00087860:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
00087870:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e00087870:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
00087880:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·00087880:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
00087890:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·00087890:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
000878a0:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=000878a0:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
000878b0:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation000878b0:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
000878c0:·204b·7562·6572·6e65·7465·7320·736e·6970···Kubernetes·snip 
000878d0:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br>< 
000878e0:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel 
000878f0:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap 
00087900:·7365·2220·6964·3d22·6964·6d31·3833·3933··se"·id="idm18393 
00087910:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class=" 
00087920:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri 
00087930:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border 
00087940:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens 
00087950:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp 
00087960:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td> 
00087970:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr 
00087980:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption: 
00087990:·3c2f·7468·3e3c·7464·3e6d·6564·6975·6d3c··</th><td>medium< 
000879a0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
000879b0:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td 
000879c0:·3e74·7275·653c·2f74·643e·3c2f·7472·3e3c··>true</td></tr>< 
000879d0:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy: 
000879e0:·3c2f·7468·3e3c·7464·3e64·6973·6162·6c65··</th><td>disable 
000879f0:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl 
00087a00:·653e·3c70·7265·3e3c·636f·6465·3e61·7069··e><pre><code>api 
00087a10:·5665·7273·696f·6e3a·206d·6163·6869·6e65··Version:·machine 
00087a20:·636f·6e66·6967·7572·6174·696f·6e2e·6f70··configuration.op 
00087a30:·656e·7368·6966·742e·696f·2f76·310a·6b69··enshift.io/v1.ki 
00087a40:·6e64·3a20·4d61·6368·696e·6543·6f6e·6669··nd:·MachineConfi 
00087a50:·670a·7370·6563·3a0a·2020·636f·6e66·6967··g.spec:.··config 
00087a60:·3a0a·2020·2020·6967·6e69·7469·6f6e·3a0a··:.····ignition:. 
00087a70:·2020·2020·2020·7665·7273·696f·6e3a·2033········version:·3 
00087a80:·2e31·2e30·0a20·2020·2073·7973·7465·6d64··.1.0.····systemd 
00087a90:·3a0a·2020·2020·2020·756e·6974·733a·0a20··:.······units:.· 
00087aa0:·2020·2020·202d·206e·616d·653a·2062·6c75·······-·name:·blu 
00087ab0:·6574·6f6f·7468·2e73·6572·7669·6365·0a20··etooth.service.· 
00087ac0:·2020·2020·2020·2065·6e61·626c·6564·3a20·········enabled:· 
00087ad0:·6661·6c73·650a·2020·2020·2020·2020·6d61··false.········ma 
00087ae0:·736b·3a20·7472·7565·0a20·2020·2020·202d··sk:·true.······- 
00087af0:·206e·616d·653a·2062·6c75·6574·6f6f·7468···name:·bluetooth 
00087b00:·2e73·6f63·6b65·740a·2020·2020·2020·2020··.socket.········ 
00087b10:·656e·6162·6c65·643a·2066·616c·7365·0a20··enabled:·false.· 
00087b20:·2020·2020·2020·206d·6173·6b3a·2074·7275·········mask:·tru 
00087b30:·650a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··e.</code></pre>< 
00087b40:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b 
00087b50:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"· 
00087b60:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col 
Max diff block lines reached; 8582/24642 bytes (34.83%) of diff not shown.
5.4 KB
html2text {}
    
Offset 421, 15 lines modifiedOffset 421, 15 lines modified
421 Identifiers:·CCE-82496-1421 Identifiers:·CCE-82496-1
422 ·············_\x8c_\x8u_\x8i····3.4.5422 ·············_\x8c_\x8u_\x8i····3.4.5
423 ·············_\x8d_\x8i_\x8s_\x8a···CCI-000366,·CCI-002235423 ·············_\x8d_\x8i_\x8s_\x8a···CCI-000366,·CCI-002235
424 References:··_\x8h_\x8i_\x8p_\x8a_\x8a··164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),·164.310(d)(2)(iii)424 References:··_\x8h_\x8i_\x8p_\x8a_\x8a··164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),·164.310(d)(2)(iii)
425 ·············_\x8n_\x8i_\x8s_\x8t···CM-6425 ·············_\x8n_\x8i_\x8s_\x8t···CM-6
426 ·············_\x8o_\x8s_\x8p_\x8p···FIA_UAU.1426 ·············_\x8o_\x8s_\x8p_\x8p···FIA_UAU.1
427 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000324-GPOS-00125,·SRG-OS-000480-GPOS-00227427 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000324-GPOS-00125,·SRG-OS-000480-GPOS-00227
428 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_.u_.b_.e_.r_.n_.e_.t_.e_.s_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8428 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
429 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low429 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
430 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium430 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
431 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true431 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
432 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable432 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
433 apiVersion:·machineconfiguration.openshift.io/v1433 apiVersion:·machineconfiguration.openshift.io/v1
434 kind:·MachineConfig434 kind:·MachineConfig
435 spec:435 spec:
Offset 440, 15 lines modifiedOffset 440, 15 lines modified
440 ······units:440 ······units:
441 ······-·name:·debug-shell.service441 ······-·name:·debug-shell.service
442 ········enabled:·false442 ········enabled:·false
443 ········mask:·true443 ········mask:·true
444 ······-·name:·debug-shell.socket444 ······-·name:·debug-shell.socket
445 ········enabled:·false445 ········enabled:·false
446 ········mask:·true446 ········mask:·true
447 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8447 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_.u_.b_.e_.r_.n_.e_.t_.e_.s_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8
448 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low448 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
449 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium449 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
450 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true450 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
451 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable451 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
452 apiVersion:·machineconfiguration.openshift.io/v1452 apiVersion:·machineconfiguration.openshift.io/v1
453 kind:·MachineConfig453 kind:·MachineConfig
454 spec:454 spec:
Offset 1870, 15 lines modifiedOffset 1870, 15 lines modified
1870 ············_\x8c_\x8u_\x8i············3.1.161870 ············_\x8c_\x8u_\x8i············3.1.16
1871 ············_\x8d_\x8i_\x8s_\x8a···········CCI-000085,·CCI-0015511871 ············_\x8d_\x8i_\x8s_\x8a···········CCI-000085,·CCI-001551
1872 References:·_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x80_\x89·4.3.3.5.1,·4.3.3.5.2,·4.3.3.5.3,·4.3.3.5.4,·4.3.3.5.5,·4.3.3.5.6,·4.3.3.5.7,·4.3.3.5.8,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.1,·4.3.3.7.2,·4.3.3.7.3,·4.3.3.7.4,·4.3.4.3.2,·4.3.4.3.31872 References:·_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x80_\x89·4.3.3.5.1,·4.3.3.5.2,·4.3.3.5.3,·4.3.3.5.4,·4.3.3.5.5,·4.3.3.5.6,·4.3.3.5.7,·4.3.3.5.8,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.1,·4.3.3.7.2,·4.3.3.7.3,·4.3.3.7.4,·4.3.4.3.2,·4.3.4.3.3
1873 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·1.1,·SR·1.10,·SR·1.11,·SR·1.12,·SR·1.13,·SR·1.2,·SR·1.3,·SR·1.4,·SR·1.5,·SR·1.6,·SR·1.7,·SR·1.8,·SR·1.9,·SR·2.1,·SR·2.2,·SR·2.3,·SR·2.4,·SR·2.5,·SR·2.6,·SR·2.7,·SR·3.1,·SR·3.5,·SR·3.8,·SR·4.1,·SR·4.3,·SR·5.1,·SR·5.2,·SR·5.3,·SR·7.1,·SR·7.61873 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·1.1,·SR·1.10,·SR·1.11,·SR·1.12,·SR·1.13,·SR·1.2,·SR·1.3,·SR·1.4,·SR·1.5,·SR·1.6,·SR·1.7,·SR·1.8,·SR·1.9,·SR·2.1,·SR·2.2,·SR·2.3,·SR·2.4,·SR·2.5,·SR·2.6,·SR·2.7,·SR·3.1,·SR·3.5,·SR·3.8,·SR·4.1,·SR·4.3,·SR·5.1,·SR·5.2,·SR·5.3,·SR·7.1,·SR·7.6
1874 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.6,·A.12.1.2,·A.12.5.1,·A.12.6.2,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.2.1,·A.6.2.2,·A.9.1.21874 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.6,·A.12.1.2,·A.12.5.1,·A.12.6.2,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.2.1,·A.6.2.2,·A.9.1.2
1875 ············_\x8n_\x8i_\x8s_\x8t···········AC-18(a),·AC-18(3),·CM-7(a),·CM-7(b),·CM-6(a),·MP-71875 ············_\x8n_\x8i_\x8s_\x8t···········AC-18(a),·AC-18(3),·CM-7(a),·CM-7(b),·CM-6(a),·MP-7
1876 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-3,·PR.IP-1,·PR.PT-3,·PR.PT-41876 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-3,·PR.IP-1,·PR.PT-3,·PR.PT-4
1877 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_.u_.b_.e_.r_.n_.e_.t_.e_.s_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x81877 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
1878 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1878 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1879 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium1879 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
1880 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true1880 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
1881 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable1881 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
1882 apiVersion:·machineconfiguration.openshift.io/v11882 apiVersion:·machineconfiguration.openshift.io/v1
1883 kind:·MachineConfig1883 kind:·MachineConfig
1884 spec:1884 spec:
Offset 1889, 15 lines modifiedOffset 1889, 15 lines modified
1889 ······units:1889 ······units:
1890 ······-·name:·bluetooth.service1890 ······-·name:·bluetooth.service
1891 ········enabled:·false1891 ········enabled:·false
1892 ········mask:·true1892 ········mask:·true
1893 ······-·name:·bluetooth.socket1893 ······-·name:·bluetooth.socket
1894 ········enabled:·false1894 ········enabled:·false
1895 ········mask:·true1895 ········mask:·true
1896 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x81896 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_.u_.b_.e_.r_.n_.e_.t_.e_.s_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8
1897 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1897 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1898 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium1898 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
1899 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true1899 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
1900 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable1900 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
1901 apiVersion:·machineconfiguration.openshift.io/v11901 apiVersion:·machineconfiguration.openshift.io/v1
1902 kind:·MachineConfig1902 kind:·MachineConfig
1903 spec:1903 spec:
Offset 2207, 15 lines modifiedOffset 2207, 15 lines modified
2207 ·············_\x8h_\x8i_\x8p_\x8a_\x8a··········164.308(a)(3)(i),·164.308(a)(3)(ii)(A),·164.310(d)(1),·164.310(d)(2),·164.312(a)(1),·164.312(a)(2)(iv),·164.312(b)2207 ·············_\x8h_\x8i_\x8p_\x8a_\x8a··········164.308(a)(3)(i),·164.308(a)(3)(ii)(A),·164.310(d)(1),·164.310(d)(2),·164.312(a)(1),·164.312(a)(2)(iv),·164.312(b)
2208 References:··_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x80_\x89·4.3.3.2.2,·4.3.3.5.1,·4.3.3.5.2,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.2,·4.3.3.7.42208 References:··_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x80_\x89·4.3.3.2.2,·4.3.3.5.1,·4.3.3.5.2,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.2,·4.3.3.7.4
2209 ·············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·1.1,·SR·1.10,·SR·1.13,·SR·1.2,·SR·1.3,·SR·1.4,·SR·1.5,·SR·1.7,·SR·1.8,·SR·1.9,·SR·2.1,·SR·2.62209 ·············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·1.1,·SR·1.10,·SR·1.13,·SR·1.2,·SR·1.3,·SR·1.4,·SR·1.5,·SR·1.7,·SR·1.8,·SR·1.9,·SR·2.1,·SR·2.6
2210 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.6,·A.13.1.1,·A.13.2.1,·A.18.1.4,·A.6.2.1,·A.6.2.2,·A.7.1.1,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,·A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.32210 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.6,·A.13.1.1,·A.13.2.1,·A.18.1.4,·A.6.2.1,·A.6.2.2,·A.7.1.1,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,·A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.3
2211 ·············_\x8n_\x8i_\x8s_\x8t···········CM-7(a),·CM-7(b),·CM-6(a),·MP-72211 ·············_\x8n_\x8i_\x8s_\x8t···········CM-7(a),·CM-7(b),·CM-6(a),·MP-7
2212 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-1,·PR.AC-3,·PR.AC-6,·PR.AC-72212 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-1,·PR.AC-3,·PR.AC-6,·PR.AC-7
2213 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000114-GPOS-00059,·SRG-OS-000378-GPOS-00163,·SRG-OS-000480-GPOS-002272213 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000114-GPOS-00059,·SRG-OS-000378-GPOS-00163,·SRG-OS-000480-GPOS-00227
2214 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_.u_.b_.e_.r_.n_.e_.t_.e_.s_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x82214 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
2215 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low2215 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
2216 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium2216 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
2217 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true2217 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
2218 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable2218 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
2219 apiVersion:·machineconfiguration.openshift.io/v12219 apiVersion:·machineconfiguration.openshift.io/v1
2220 kind:·MachineConfig2220 kind:·MachineConfig
2221 spec:2221 spec:
Offset 2226, 15 lines modifiedOffset 2226, 15 lines modified
2226 ······units:2226 ······units:
2227 ······-·name:·autofs.service2227 ······-·name:·autofs.service
2228 ········enabled:·false2228 ········enabled:·false
2229 ········mask:·true2229 ········mask:·true
2230 ······-·name:·autofs.socket2230 ······-·name:·autofs.socket
2231 ········enabled:·false2231 ········enabled:·false
2232 ········mask:·true2232 ········mask:·true
2233 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x82233 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_.u_.b_.e_.r_.n_.e_.t_.e_.s_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8
2234 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low2234 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
2235 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium2235 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
2236 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true2236 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
2237 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable2237 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
2238 apiVersion:·machineconfiguration.openshift.io/v12238 apiVersion:·machineconfiguration.openshift.io/v1
2239 kind:·MachineConfig2239 kind:·MachineConfig
2240 spec:2240 spec:
9.96 KB
./usr/share/doc/ssg-nondebian/ssg-rhcos4-guide-stig-v1r1.html
    
Offset 23059, 66 lines modifiedOffset 23059, 66 lines modified
0005a120:·2d74·6172·6765·743d·2223·6964·6d32·3733··-target="#idm2730005a120:·2d74·6172·6765·743d·2223·6964·6d32·3733··-target="#idm273
0005a130:·3636·2220·7461·6269·6e64·6578·3d22·3022··66"·tabindex="0"0005a130:·3636·2220·7461·6269·6e64·6578·3d22·3022··66"·tabindex="0"
0005a140:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a0005a140:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
0005a150:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa0005a150:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
0005a160:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti0005a160:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
0005a170:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·0005a170:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
0005a180:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi0005a180:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
 0005a190:·6174·696f·6e20·7363·7269·7074·20e2·87b2··ation·script·...
0005a190:·6174·696f·6e20·4b75·6265·726e·6574·6573··ation·Kubernetes 
0005a1a0:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a> 
0005a1b0:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="0005a1a0:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
0005a1c0:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c0005a1b0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
0005a1d0:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm0005a1c0:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
0005a1e0:·3237·3336·3622·3e3c·7461·626c·6520·636c··27366"><table·cl0005a1d0:·2269·646d·3237·3336·3622·3e3c·7461·626c··"idm27366"><tabl
0005a1f0:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table0005a1e0:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t
0005a200:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b0005a1f0:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab
0005a210:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co0005a200:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl
0005a220:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th0005a210:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr
0005a230:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th0005a220:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:
0005a240:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t0005a230:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
0005a250:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup 
0005a260:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6d65··tion:</th><td>me 
0005a270:·6469·756d·3c2f·7464·3e3c·2f74·723e·3c74··dium</td></tr><t 
0005a280:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t 
0005a290:·683e·3c74·643e·7472·7565·3c2f·7464·3e3c··h><td>true</td>< 
0005a2a0:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra0005a240:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di
 0005a250:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t
 0005a260:·643e·6d65·6469·756d·3c2f·7464·3e3c·2f74··d>medium</td></t
 0005a270:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot
 0005a280:·3a3c·2f74·683e·3c74·643e·7472·7565·3c2f··:</th><td>true</
 0005a290:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
0005a2b0:·7465·6779·3a3c·2f74·683e·3c74·643e·6469··tegy:</th><td>di0005a2a0:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t
0005a2c0:·7361·626c·653c·2f74·643e·3c2f·7472·3e3c··sable</td></tr><0005a2b0:·643e·6469·7361·626c·653c·2f74·643e·3c2f··d>disable</td></
0005a2d0:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod0005a2c0:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>
0005a2e0:·653e·6170·6956·6572·7369·6f6e·3a20·6d61··e>apiVersion:·ma0005a2d0:·3c63·6f64·653e·6170·6956·6572·7369·6f6e··<code>apiVersion
0005a2f0:·6368·696e·6563·6f6e·6669·6775·7261·7469··chineconfigurati0005a2e0:·3a20·6d61·6368·696e·6563·6f6e·6669·6775··:·machineconfigu
0005a300:·6f6e·2e6f·7065·6e73·6869·6674·2e69·6f2f··on.openshift.io/0005a2f0:·7261·7469·6f6e·2e6f·7065·6e73·6869·6674··ration.openshift
0005a310:·7631·0a6b·696e·643a·204d·6163·6869·6e65··v1.kind:·Machine0005a300:·2e69·6f2f·7631·0a6b·696e·643a·204d·6163··.io/v1.kind:·Mac
0005a320:·436f·6e66·6967·0a73·7065·633a·0a20·2063··Config.spec:.··c0005a310:·6869·6e65·436f·6e66·6967·0a73·7065·633a··hineConfig.spec:
0005a330:·6f6e·6669·673a·0a20·2020·2069·676e·6974··onfig:.····ignit0005a320:·0a20·2063·6f6e·6669·673a·0a20·2020·2069··.··config:.····i
0005a340:·696f·6e3a·0a20·2020·2020·2076·6572·7369··ion:.······versi0005a330:·676e·6974·696f·6e3a·0a20·2020·2020·2076··gnition:.······v
0005a350:·6f6e·3a20·332e·312e·300a·2020·2020·7379··on:·3.1.0.····sy0005a340:·6572·7369·6f6e·3a20·332e·312e·300a·2020··ersion:·3.1.0.··
0005a360:·7374·656d·643a·0a20·2020·2020·2075·6e69··stemd:.······uni0005a350:·2020·7379·7374·656d·643a·0a20·2020·2020····systemd:.·····
0005a370:·7473·3a0a·2020·2020·2020·2d20·6e61·6d65··ts:.······-·name0005a360:·2075·6e69·7473·3a0a·2020·2020·2020·2d20···units:.······-·
0005a380:·3a20·7373·6864·2e73·6572·7669·6365·0a20··:·sshd.service.·0005a370:·6e61·6d65·3a20·7373·6864·2e73·6572·7669··name:·sshd.servi
0005a390:·2020·2020·2020·2065·6e61·626c·6564·3a20·········enabled:· 
0005a3a0:·6661·6c73·650a·2020·2020·2020·2020·6d61··false.········ma 
0005a3b0:·736b·3a20·7472·7565·0a20·2020·2020·202d··sk:·true.······- 
0005a3c0:·206e·616d·653a·2073·7368·642e·736f·636b···name:·sshd.sock 
0005a3d0:·6574·0a20·2020·2020·2020·2065·6e61·626c··et.········enabl0005a380:·6365·0a20·2020·2020·2020·2065·6e61·626c··ce.········enabl
0005a3e0:·6564·3a20·6661·6c73·650a·2020·2020·2020··ed:·false.······0005a390:·6564·3a20·6661·6c73·650a·2020·2020·2020··ed:·false.······
0005a3f0:·2020·6d61·736b·3a20·7472·7565·0a3c·2f63····mask:·true.</c0005a3a0:·2020·6d61·736b·3a20·7472·7565·0a20·2020····mask:·true.···
 0005a3b0:·2020·202d·206e·616d·653a·2073·7368·642e·····-·name:·sshd.
 0005a3c0:·736f·636b·6574·0a20·2020·2020·2020·2065··socket.········e
 0005a3d0:·6e61·626c·6564·3a20·6661·6c73·650a·2020··nabled:·false.··
 0005a3e0:·2020·2020·2020·6d61·736b·3a20·7472·7565········mask:·true
0005a400:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div>0005a3f0:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></
0005a410:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt0005a400:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt
0005a420:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data-0005a410:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d
0005a430:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse0005a420:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll
0005a440:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#0005a430:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
0005a450:·6964·6d32·3733·3637·2220·7461·6269·6e64··idm27367"·tabind0005a440:·743d·2223·6964·6d32·3733·3637·2220·7461··t="#idm27367"·ta
0005a460:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but0005a450:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
0005a470:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand0005a460:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
0005a480:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title0005a470:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
0005a490:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re0005a480:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
0005a4a0:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">0005a490:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
0005a4b0:·5265·6d65·6469·6174·696f·6e20·7363·7269··Remediation·scri0005a4a0:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
 0005a4b0:·4b75·6265·726e·6574·6573·2073·6e69·7070··Kubernetes·snipp
0005a4c0:·7074·20e2·87b2·3c2f·613e·3c62·723e·3c64··pt·...</a><br><d0005a4c0:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d
0005a4d0:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-0005a4d0:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-
0005a4e0:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps0005a4e0:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps
0005a4f0:·6522·2069·643d·2269·646d·3237·3336·3722··e"·id="idm27367"0005a4f0:·6522·2069·643d·2269·646d·3237·3336·3722··e"·id="idm27367"
0005a500:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t0005a500:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t
0005a510:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip0005a510:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip
0005a520:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere0005a520:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere
0005a530:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense0005a530:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense
1.87 KB
html2text {}
    
Offset 705, 15 lines modifiedOffset 705, 15 lines modified
705 For·more·information·on·how·to·configure·nodes·with·the·Machine·Config·Operator·see·_\x8t_\x8h_\x8e_\x8·_\x8r_\x8e_\x8l_\x8e_\x8v_\x8a_\x8n_\x8t_\x8·_\x8d_\x8o_\x8c_\x8u_\x8m_\x8e_\x8n_\x8t_\x8a_\x8t_\x8i_\x8o_\x8n.705 For·more·information·on·how·to·configure·nodes·with·the·Machine·Config·Operator·see·_\x8t_\x8h_\x8e_\x8·_\x8r_\x8e_\x8l_\x8e_\x8v_\x8a_\x8n_\x8t_\x8·_\x8d_\x8o_\x8c_\x8u_\x8m_\x8e_\x8n_\x8t_\x8a_\x8t_\x8i_\x8o_\x8n.
706 Rationale:···Red·Hat·Enterprise·Linux·CoreOS·(RHCOS)·is·a·single-purpose·container·operating·system.·RHCOS·is·only·supported·as·a·component·of·the·OpenShift·Container·Platform.·Remote·management·of·the·RHCOS·nodes·is·performed·at·the·OpenShift·Container·Platform·API·level.·As·a·result,·any·direct·remote·access·to·the·RHCOS·nodes·is·unnecessary.·Disabling·the·SSHD·service·helps·reduce·the·number·of·open·ports·on·each·host.706 Rationale:···Red·Hat·Enterprise·Linux·CoreOS·(RHCOS)·is·a·single-purpose·container·operating·system.·RHCOS·is·only·supported·as·a·component·of·the·OpenShift·Container·Platform.·Remote·management·of·the·RHCOS·nodes·is·performed·at·the·OpenShift·Container·Platform·API·level.·As·a·result,·any·direct·remote·access·to·the·RHCOS·nodes·is·unnecessary.·Disabling·the·SSHD·service·helps·reduce·the·number·of·open·ports·on·each·host.
707 Severity: ···high707 Severity: ···high
708 Rule·ID:·····xccdf_org.ssgproject.content_rule_service_sshd_disabled708 Rule·ID:·····xccdf_org.ssgproject.content_rule_service_sshd_disabled
709 Identifiers:·CCE-86189-8709 Identifiers:·CCE-86189-8
710 References:··_\x8n_\x8i_\x8s_\x8t········CM-3(6),·IA-2(4)710 References:··_\x8n_\x8i_\x8s_\x8t········CM-3(6),·IA-2(4)
711 ·············_\x8a_\x8p_\x8p_\x8-_\x8s_\x8r_\x8g_\x8-_\x8c_\x8t_\x8r·SRG-APP-000185-CTR-000490,·SRG-APP-000141-CTR-000315,·CNTR-OS-001010,·CNTR-OS-001020,·CNTR-OS-001030711 ·············_\x8a_\x8p_\x8p_\x8-_\x8s_\x8r_\x8g_\x8-_\x8c_\x8t_\x8r·SRG-APP-000185-CTR-000490,·SRG-APP-000141-CTR-000315,·CNTR-OS-001010,·CNTR-OS-001020,·CNTR-OS-001030
712 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_.u_.b_.e_.r_.n_.e_.t_.e_.s_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8712 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
713 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low713 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
714 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium714 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
715 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true715 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
716 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable716 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
717 apiVersion:·machineconfiguration.openshift.io/v1717 apiVersion:·machineconfiguration.openshift.io/v1
718 kind:·MachineConfig718 kind:·MachineConfig
719 spec:719 spec:
Offset 724, 15 lines modifiedOffset 724, 15 lines modified
724 ······units:724 ······units:
725 ······-·name:·sshd.service725 ······-·name:·sshd.service
726 ········enabled:·false726 ········enabled:·false
727 ········mask:·true727 ········mask:·true
728 ······-·name:·sshd.socket728 ······-·name:·sshd.socket
729 ········enabled:·false729 ········enabled:·false
730 ········mask:·true730 ········mask:·true
731 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8731 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_.u_.b_.e_.r_.n_.e_.t_.e_.s_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8
732 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low732 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
733 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium733 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
734 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true734 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
735 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable735 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
736 apiVersion:·machineconfiguration.openshift.io/v1736 apiVersion:·machineconfiguration.openshift.io/v1
737 kind:·MachineConfig737 kind:·MachineConfig
738 spec:738 spec:
9.96 KB
./usr/share/doc/ssg-nondebian/ssg-rhcos4-guide-stig-v2r1.html
    
Offset 23059, 66 lines modifiedOffset 23059, 66 lines modified
0005a120:·2d74·6172·6765·743d·2223·6964·6d32·3733··-target="#idm2730005a120:·2d74·6172·6765·743d·2223·6964·6d32·3733··-target="#idm273
0005a130:·3636·2220·7461·6269·6e64·6578·3d22·3022··66"·tabindex="0"0005a130:·3636·2220·7461·6269·6e64·6578·3d22·3022··66"·tabindex="0"
0005a140:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a0005a140:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
0005a150:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa0005a150:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
0005a160:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti0005a160:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
0005a170:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·0005a170:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
0005a180:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi0005a180:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
 0005a190:·6174·696f·6e20·7363·7269·7074·20e2·87b2··ation·script·...
0005a190:·6174·696f·6e20·4b75·6265·726e·6574·6573··ation·Kubernetes 
0005a1a0:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a> 
0005a1b0:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="0005a1a0:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
0005a1c0:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c0005a1b0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
0005a1d0:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm0005a1c0:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
0005a1e0:·3237·3336·3622·3e3c·7461·626c·6520·636c··27366"><table·cl0005a1d0:·2269·646d·3237·3336·3622·3e3c·7461·626c··"idm27366"><tabl
0005a1f0:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table0005a1e0:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t
0005a200:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b0005a1f0:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab
0005a210:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co0005a200:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl
0005a220:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th0005a210:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr
0005a230:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th0005a220:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:
0005a240:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t0005a230:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
0005a250:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup 
0005a260:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6d65··tion:</th><td>me 
0005a270:·6469·756d·3c2f·7464·3e3c·2f74·723e·3c74··dium</td></tr><t 
0005a280:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t 
0005a290:·683e·3c74·643e·7472·7565·3c2f·7464·3e3c··h><td>true</td>< 
0005a2a0:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra0005a240:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di
 0005a250:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t
 0005a260:·643e·6d65·6469·756d·3c2f·7464·3e3c·2f74··d>medium</td></t
 0005a270:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot
 0005a280:·3a3c·2f74·683e·3c74·643e·7472·7565·3c2f··:</th><td>true</
 0005a290:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
0005a2b0:·7465·6779·3a3c·2f74·683e·3c74·643e·6469··tegy:</th><td>di0005a2a0:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t
0005a2c0:·7361·626c·653c·2f74·643e·3c2f·7472·3e3c··sable</td></tr><0005a2b0:·643e·6469·7361·626c·653c·2f74·643e·3c2f··d>disable</td></
0005a2d0:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod0005a2c0:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>
0005a2e0:·653e·6170·6956·6572·7369·6f6e·3a20·6d61··e>apiVersion:·ma0005a2d0:·3c63·6f64·653e·6170·6956·6572·7369·6f6e··<code>apiVersion
0005a2f0:·6368·696e·6563·6f6e·6669·6775·7261·7469··chineconfigurati0005a2e0:·3a20·6d61·6368·696e·6563·6f6e·6669·6775··:·machineconfigu
0005a300:·6f6e·2e6f·7065·6e73·6869·6674·2e69·6f2f··on.openshift.io/0005a2f0:·7261·7469·6f6e·2e6f·7065·6e73·6869·6674··ration.openshift
0005a310:·7631·0a6b·696e·643a·204d·6163·6869·6e65··v1.kind:·Machine0005a300:·2e69·6f2f·7631·0a6b·696e·643a·204d·6163··.io/v1.kind:·Mac
0005a320:·436f·6e66·6967·0a73·7065·633a·0a20·2063··Config.spec:.··c0005a310:·6869·6e65·436f·6e66·6967·0a73·7065·633a··hineConfig.spec:
0005a330:·6f6e·6669·673a·0a20·2020·2069·676e·6974··onfig:.····ignit0005a320:·0a20·2063·6f6e·6669·673a·0a20·2020·2069··.··config:.····i
0005a340:·696f·6e3a·0a20·2020·2020·2076·6572·7369··ion:.······versi0005a330:·676e·6974·696f·6e3a·0a20·2020·2020·2076··gnition:.······v
0005a350:·6f6e·3a20·332e·312e·300a·2020·2020·7379··on:·3.1.0.····sy0005a340:·6572·7369·6f6e·3a20·332e·312e·300a·2020··ersion:·3.1.0.··
0005a360:·7374·656d·643a·0a20·2020·2020·2075·6e69··stemd:.······uni0005a350:·2020·7379·7374·656d·643a·0a20·2020·2020····systemd:.·····
0005a370:·7473·3a0a·2020·2020·2020·2d20·6e61·6d65··ts:.······-·name0005a360:·2075·6e69·7473·3a0a·2020·2020·2020·2d20···units:.······-·
0005a380:·3a20·7373·6864·2e73·6572·7669·6365·0a20··:·sshd.service.·0005a370:·6e61·6d65·3a20·7373·6864·2e73·6572·7669··name:·sshd.servi
0005a390:·2020·2020·2020·2065·6e61·626c·6564·3a20·········enabled:· 
0005a3a0:·6661·6c73·650a·2020·2020·2020·2020·6d61··false.········ma 
0005a3b0:·736b·3a20·7472·7565·0a20·2020·2020·202d··sk:·true.······- 
0005a3c0:·206e·616d·653a·2073·7368·642e·736f·636b···name:·sshd.sock 
0005a3d0:·6574·0a20·2020·2020·2020·2065·6e61·626c··et.········enabl0005a380:·6365·0a20·2020·2020·2020·2065·6e61·626c··ce.········enabl
0005a3e0:·6564·3a20·6661·6c73·650a·2020·2020·2020··ed:·false.······0005a390:·6564·3a20·6661·6c73·650a·2020·2020·2020··ed:·false.······
0005a3f0:·2020·6d61·736b·3a20·7472·7565·0a3c·2f63····mask:·true.</c0005a3a0:·2020·6d61·736b·3a20·7472·7565·0a20·2020····mask:·true.···
 0005a3b0:·2020·202d·206e·616d·653a·2073·7368·642e·····-·name:·sshd.
 0005a3c0:·736f·636b·6574·0a20·2020·2020·2020·2065··socket.········e
 0005a3d0:·6e61·626c·6564·3a20·6661·6c73·650a·2020··nabled:·false.··
 0005a3e0:·2020·2020·2020·6d61·736b·3a20·7472·7565········mask:·true
0005a400:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div>0005a3f0:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></
0005a410:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt0005a400:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt
0005a420:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data-0005a410:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d
0005a430:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse0005a420:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll
0005a440:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#0005a430:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
0005a450:·6964·6d32·3733·3637·2220·7461·6269·6e64··idm27367"·tabind0005a440:·743d·2223·6964·6d32·3733·3637·2220·7461··t="#idm27367"·ta
0005a460:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but0005a450:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
0005a470:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand0005a460:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
0005a480:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title0005a470:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
0005a490:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re0005a480:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
0005a4a0:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">0005a490:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
0005a4b0:·5265·6d65·6469·6174·696f·6e20·7363·7269··Remediation·scri0005a4a0:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
 0005a4b0:·4b75·6265·726e·6574·6573·2073·6e69·7070··Kubernetes·snipp
0005a4c0:·7074·20e2·87b2·3c2f·613e·3c62·723e·3c64··pt·...</a><br><d0005a4c0:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d
0005a4d0:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-0005a4d0:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-
0005a4e0:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps0005a4e0:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps
0005a4f0:·6522·2069·643d·2269·646d·3237·3336·3722··e"·id="idm27367"0005a4f0:·6522·2069·643d·2269·646d·3237·3336·3722··e"·id="idm27367"
0005a500:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t0005a500:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t
0005a510:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip0005a510:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip
0005a520:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere0005a520:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere
0005a530:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense0005a530:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense
1.87 KB
html2text {}
    
Offset 705, 15 lines modifiedOffset 705, 15 lines modified
705 For·more·information·on·how·to·configure·nodes·with·the·Machine·Config·Operator·see·_\x8t_\x8h_\x8e_\x8·_\x8r_\x8e_\x8l_\x8e_\x8v_\x8a_\x8n_\x8t_\x8·_\x8d_\x8o_\x8c_\x8u_\x8m_\x8e_\x8n_\x8t_\x8a_\x8t_\x8i_\x8o_\x8n.705 For·more·information·on·how·to·configure·nodes·with·the·Machine·Config·Operator·see·_\x8t_\x8h_\x8e_\x8·_\x8r_\x8e_\x8l_\x8e_\x8v_\x8a_\x8n_\x8t_\x8·_\x8d_\x8o_\x8c_\x8u_\x8m_\x8e_\x8n_\x8t_\x8a_\x8t_\x8i_\x8o_\x8n.
706 Rationale:···Red·Hat·Enterprise·Linux·CoreOS·(RHCOS)·is·a·single-purpose·container·operating·system.·RHCOS·is·only·supported·as·a·component·of·the·OpenShift·Container·Platform.·Remote·management·of·the·RHCOS·nodes·is·performed·at·the·OpenShift·Container·Platform·API·level.·As·a·result,·any·direct·remote·access·to·the·RHCOS·nodes·is·unnecessary.·Disabling·the·SSHD·service·helps·reduce·the·number·of·open·ports·on·each·host.706 Rationale:···Red·Hat·Enterprise·Linux·CoreOS·(RHCOS)·is·a·single-purpose·container·operating·system.·RHCOS·is·only·supported·as·a·component·of·the·OpenShift·Container·Platform.·Remote·management·of·the·RHCOS·nodes·is·performed·at·the·OpenShift·Container·Platform·API·level.·As·a·result,·any·direct·remote·access·to·the·RHCOS·nodes·is·unnecessary.·Disabling·the·SSHD·service·helps·reduce·the·number·of·open·ports·on·each·host.
707 Severity: ···high707 Severity: ···high
708 Rule·ID:·····xccdf_org.ssgproject.content_rule_service_sshd_disabled708 Rule·ID:·····xccdf_org.ssgproject.content_rule_service_sshd_disabled
709 Identifiers:·CCE-86189-8709 Identifiers:·CCE-86189-8
710 References:··_\x8n_\x8i_\x8s_\x8t········CM-3(6),·IA-2(4)710 References:··_\x8n_\x8i_\x8s_\x8t········CM-3(6),·IA-2(4)
711 ·············_\x8a_\x8p_\x8p_\x8-_\x8s_\x8r_\x8g_\x8-_\x8c_\x8t_\x8r·SRG-APP-000185-CTR-000490,·SRG-APP-000141-CTR-000315,·CNTR-OS-001010,·CNTR-OS-001020,·CNTR-OS-001030711 ·············_\x8a_\x8p_\x8p_\x8-_\x8s_\x8r_\x8g_\x8-_\x8c_\x8t_\x8r·SRG-APP-000185-CTR-000490,·SRG-APP-000141-CTR-000315,·CNTR-OS-001010,·CNTR-OS-001020,·CNTR-OS-001030
712 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_.u_.b_.e_.r_.n_.e_.t_.e_.s_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8712 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
713 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low713 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
714 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium714 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
715 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true715 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
716 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable716 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
717 apiVersion:·machineconfiguration.openshift.io/v1717 apiVersion:·machineconfiguration.openshift.io/v1
718 kind:·MachineConfig718 kind:·MachineConfig
719 spec:719 spec:
Offset 724, 15 lines modifiedOffset 724, 15 lines modified
724 ······units:724 ······units:
725 ······-·name:·sshd.service725 ······-·name:·sshd.service
726 ········enabled:·false726 ········enabled:·false
727 ········mask:·true727 ········mask:·true
728 ······-·name:·sshd.socket728 ······-·name:·sshd.socket
729 ········enabled:·false729 ········enabled:·false
730 ········mask:·true730 ········mask:·true
731 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8731 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_.u_.b_.e_.r_.n_.e_.t_.e_.s_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8
732 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low732 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
733 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium733 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
734 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true734 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
735 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable735 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
736 apiVersion:·machineconfiguration.openshift.io/v1736 apiVersion:·machineconfiguration.openshift.io/v1
737 kind:·MachineConfig737 kind:·MachineConfig
738 spec:738 spec:
9.82 KB
./usr/share/doc/ssg-nondebian/ssg-rhcos4-guide-stig.html
    
Offset 23059, 65 lines modifiedOffset 23059, 65 lines modified
0005a120:·6574·3d22·2369·646d·3237·3336·3622·2074··et="#idm27366"·t0005a120:·6574·3d22·2369·646d·3237·3336·3622·2074··et="#idm27366"·t
0005a130:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role0005a130:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
0005a140:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e0005a140:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
0005a150:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·0005a150:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
0005a160:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·0005a160:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
0005a170:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=0005a170:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
0005a180:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation0005a180:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
 0005a190:·2073·6372·6970·7420·e287·b23c·2f61·3e3c···script·...</a><
0005a190:·204b·7562·6572·6e65·7465·7320·736e·6970···Kubernetes·snip 
0005a1a0:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br>< 
0005a1b0:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel0005a1a0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
0005a1c0:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap0005a1b0:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
0005a1d0:·7365·2220·6964·3d22·6964·6d32·3733·3636··se"·id="idm273660005a1c0:·6c6c·6170·7365·2220·6964·3d22·6964·6d32··llapse"·id="idm2
0005a1e0:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="0005a1d0:·3733·3636·223e·3c74·6162·6c65·2063·6c61··7366"><table·cla
0005a1f0:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri0005a1e0:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-
0005a200:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border0005a1f0:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo
0005a210:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens0005a200:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con
0005a220:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp0005a210:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>
0005a230:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>0005a220:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>
 0005a230:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
 0005a240:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt
 0005a250:·696f·6e3a·3c2f·7468·3e3c·7464·3e6d·6564··ion:</th><td>med
0005a240:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr0005a260:·6975·6d3c·2f74·643e·3c2f·7472·3e3c·7472··ium</td></tr><tr
0005a250:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption: 
0005a260:·3c2f·7468·3e3c·7464·3e6d·6564·6975·6d3c··</th><td>medium< 
0005a270:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0005a280:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td0005a270:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th
0005a290:·3e74·7275·653c·2f74·643e·3c2f·7472·3e3c··>true</td></tr><0005a280:·3e3c·7464·3e74·7275·653c·2f74·643e·3c2f··><td>true</td></
0005a2a0:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:0005a290:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat
0005a2b0:·3c2f·7468·3e3c·7464·3e64·6973·6162·6c65··</th><td>disable0005a2a0:·6567·793a·3c2f·7468·3e3c·7464·3e64·6973··egy:</th><td>dis
0005a2c0:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl0005a2b0:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></
0005a2d0:·653e·3c70·7265·3e3c·636f·6465·3e61·7069··e><pre><code>api0005a2c0:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code
0005a2e0:·5665·7273·696f·6e3a·206d·6163·6869·6e65··Version:·machine0005a2d0:·3e61·7069·5665·7273·696f·6e3a·206d·6163··>apiVersion:·mac
0005a2f0:·636f·6e66·6967·7572·6174·696f·6e2e·6f70··configuration.op0005a2e0:·6869·6e65·636f·6e66·6967·7572·6174·696f··hineconfiguratio
0005a300:·656e·7368·6966·742e·696f·2f76·310a·6b69··enshift.io/v1.ki0005a2f0:·6e2e·6f70·656e·7368·6966·742e·696f·2f76··n.openshift.io/v
0005a310:·6e64·3a20·4d61·6368·696e·6543·6f6e·6669··nd:·MachineConfi0005a300:·310a·6b69·6e64·3a20·4d61·6368·696e·6543··1.kind:·MachineC
0005a320:·670a·7370·6563·3a0a·2020·636f·6e66·6967··g.spec:.··config0005a310:·6f6e·6669·670a·7370·6563·3a0a·2020·636f··onfig.spec:.··co
0005a330:·3a0a·2020·2020·6967·6e69·7469·6f6e·3a0a··:.····ignition:.0005a320:·6e66·6967·3a0a·2020·2020·6967·6e69·7469··nfig:.····igniti
0005a340:·2020·2020·2020·7665·7273·696f·6e3a·2033········version:·30005a330:·6f6e·3a0a·2020·2020·2020·7665·7273·696f··on:.······versio
0005a350:·2e31·2e30·0a20·2020·2073·7973·7465·6d64··.1.0.····systemd0005a340:·6e3a·2033·2e31·2e30·0a20·2020·2073·7973··n:·3.1.0.····sys
0005a360:·3a0a·2020·2020·2020·756e·6974·733a·0a20··:.······units:.·0005a350:·7465·6d64·3a0a·2020·2020·2020·756e·6974··temd:.······unit
0005a370:·2020·2020·202d·206e·616d·653a·2073·7368·······-·name:·ssh0005a360:·733a·0a20·2020·2020·202d·206e·616d·653a··s:.······-·name:
0005a380:·642e·7365·7276·6963·650a·2020·2020·2020··d.service.······0005a370:·2073·7368·642e·7365·7276·6963·650a·2020···sshd.service.··
0005a390:·2020·656e·6162·6c65·643a·2066·616c·7365····enabled:·false 
0005a3a0:·0a20·2020·2020·2020·206d·6173·6b3a·2074··.········mask:·t 
0005a3b0:·7275·650a·2020·2020·2020·2d20·6e61·6d65··rue.······-·name 
0005a3c0:·3a20·7373·6864·2e73·6f63·6b65·740a·2020··:·sshd.socket.·· 
0005a3d0:·2020·2020·2020·656e·6162·6c65·643a·2066········enabled:·f0005a380:·2020·2020·2020·656e·6162·6c65·643a·2066········enabled:·f
0005a3e0:·616c·7365·0a20·2020·2020·2020·206d·6173··alse.········mas0005a390:·616c·7365·0a20·2020·2020·2020·206d·6173··alse.········mas
 0005a3a0:·6b3a·2074·7275·650a·2020·2020·2020·2d20··k:·true.······-·
 0005a3b0:·6e61·6d65·3a20·7373·6864·2e73·6f63·6b65··name:·sshd.socke
 0005a3c0:·740a·2020·2020·2020·2020·656e·6162·6c65··t.········enable
 0005a3d0:·643a·2066·616c·7365·0a20·2020·2020·2020··d:·false.·······
0005a3f0:·6b3a·2074·7275·650a·3c2f·636f·6465·3e3c··k:·true.</code><0005a3e0:·206d·6173·6b3a·2074·7275·650a·3c2f·636f···mask:·true.</co
0005a400:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl0005a3f0:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div><
0005a410:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc0005a400:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn
0005a420:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl0005a410:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t
0005a430:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat0005a420:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse"
0005a440:·612d·7461·7267·6574·3d22·2369·646d·3237··a-target="#idm270005a430:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i
0005a450:·3336·3722·2074·6162·696e·6465·783d·2230··367"·tabindex="00005a440:·646d·3237·3336·3722·2074·6162·696e·6465··dm27367"·tabinde
0005a460:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·0005a450:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt
0005a470:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f0005a460:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande
0005a480:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act0005a470:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=
0005a490:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"0005a480:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev
0005a4a0:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed0005a490:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R
0005a4b0:·6961·7469·6f6e·2073·6372·6970·7420·e287··iation·script·..0005a4a0:·656d·6564·6961·7469·6f6e·204b·7562·6572··emediation·Kuber
 0005a4b0:·6e65·7465·7320·736e·6970·7065·7420·e287··netes·snippet·..
0005a4c0:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl0005a4c0:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl
0005a4d0:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla0005a4d0:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla
0005a4e0:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id0005a4e0:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id
0005a4f0:·3d22·6964·6d32·3733·3637·223e·3c74·6162··="idm27367"><tab0005a4f0:·3d22·6964·6d32·3733·3637·223e·3c74·6162··="idm27367"><tab
0005a500:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·0005a500:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·
0005a510:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta0005a510:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta
0005a520:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab0005a520:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab
1.87 KB
html2text {}
    
Offset 705, 15 lines modifiedOffset 705, 15 lines modified
705 For·more·information·on·how·to·configure·nodes·with·the·Machine·Config·Operator·see·_\x8t_\x8h_\x8e_\x8·_\x8r_\x8e_\x8l_\x8e_\x8v_\x8a_\x8n_\x8t_\x8·_\x8d_\x8o_\x8c_\x8u_\x8m_\x8e_\x8n_\x8t_\x8a_\x8t_\x8i_\x8o_\x8n.705 For·more·information·on·how·to·configure·nodes·with·the·Machine·Config·Operator·see·_\x8t_\x8h_\x8e_\x8·_\x8r_\x8e_\x8l_\x8e_\x8v_\x8a_\x8n_\x8t_\x8·_\x8d_\x8o_\x8c_\x8u_\x8m_\x8e_\x8n_\x8t_\x8a_\x8t_\x8i_\x8o_\x8n.
706 Rationale:···Red·Hat·Enterprise·Linux·CoreOS·(RHCOS)·is·a·single-purpose·container·operating·system.·RHCOS·is·only·supported·as·a·component·of·the·OpenShift·Container·Platform.·Remote·management·of·the·RHCOS·nodes·is·performed·at·the·OpenShift·Container·Platform·API·level.·As·a·result,·any·direct·remote·access·to·the·RHCOS·nodes·is·unnecessary.·Disabling·the·SSHD·service·helps·reduce·the·number·of·open·ports·on·each·host.706 Rationale:···Red·Hat·Enterprise·Linux·CoreOS·(RHCOS)·is·a·single-purpose·container·operating·system.·RHCOS·is·only·supported·as·a·component·of·the·OpenShift·Container·Platform.·Remote·management·of·the·RHCOS·nodes·is·performed·at·the·OpenShift·Container·Platform·API·level.·As·a·result,·any·direct·remote·access·to·the·RHCOS·nodes·is·unnecessary.·Disabling·the·SSHD·service·helps·reduce·the·number·of·open·ports·on·each·host.
707 Severity: ···high707 Severity: ···high
708 Rule·ID:·····xccdf_org.ssgproject.content_rule_service_sshd_disabled708 Rule·ID:·····xccdf_org.ssgproject.content_rule_service_sshd_disabled
709 Identifiers:·CCE-86189-8709 Identifiers:·CCE-86189-8
710 References:··_\x8n_\x8i_\x8s_\x8t········CM-3(6),·IA-2(4)710 References:··_\x8n_\x8i_\x8s_\x8t········CM-3(6),·IA-2(4)
711 ·············_\x8a_\x8p_\x8p_\x8-_\x8s_\x8r_\x8g_\x8-_\x8c_\x8t_\x8r·SRG-APP-000185-CTR-000490,·SRG-APP-000141-CTR-000315,·CNTR-OS-001010,·CNTR-OS-001020,·CNTR-OS-001030711 ·············_\x8a_\x8p_\x8p_\x8-_\x8s_\x8r_\x8g_\x8-_\x8c_\x8t_\x8r·SRG-APP-000185-CTR-000490,·SRG-APP-000141-CTR-000315,·CNTR-OS-001010,·CNTR-OS-001020,·CNTR-OS-001030
712 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_.u_.b_.e_.r_.n_.e_.t_.e_.s_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8712 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
713 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low713 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
714 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium714 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
715 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true715 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
716 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable716 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
717 apiVersion:·machineconfiguration.openshift.io/v1717 apiVersion:·machineconfiguration.openshift.io/v1
718 kind:·MachineConfig718 kind:·MachineConfig
719 spec:719 spec:
Offset 724, 15 lines modifiedOffset 724, 15 lines modified
724 ······units:724 ······units:
725 ······-·name:·sshd.service725 ······-·name:·sshd.service
726 ········enabled:·false726 ········enabled:·false
727 ········mask:·true727 ········mask:·true
728 ······-·name:·sshd.socket728 ······-·name:·sshd.socket
729 ········enabled:·false729 ········enabled:·false
730 ········mask:·true730 ········mask:·true
731 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8731 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_.u_.b_.e_.r_.n_.e_.t_.e_.s_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8
732 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low732 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
733 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium733 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
734 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true734 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
735 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable735 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
736 apiVersion:·machineconfiguration.openshift.io/v1736 apiVersion:·machineconfiguration.openshift.io/v1
737 kind:·MachineConfig737 kind:·MachineConfig
738 spec:738 spec:
988 KB
./usr/share/doc/ssg-nondebian/ssg-rhel10-guide-anssi_bp28_enhanced.html
    
Offset 15168, 208 lines modifiedOffset 15168, 208 lines modified
0003b3f0:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe0003b3f0:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
0003b400:·743d·2223·6964·6d37·3330·3822·2074·6162··t="#idm7308"·tab0003b400:·743d·2223·6964·6d37·3330·3822·2074·6162··t="#idm7308"·tab
0003b410:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="0003b410:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
0003b420:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp0003b420:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
0003b430:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti0003b430:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
0003b440:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to0003b440:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
0003b450:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#0003b450:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
0003b460:·2122·3e52·656d·6564·6961·7469·6f6e·2073··!">Remediation·s0003b460:·2122·3e52·656d·6564·6961·7469·6f6e·204f··!">Remediation·O
 0003b470:·5342·7569·6c64·2042·6c75·6570·7269·6e74··SBuild·Blueprint
 0003b480:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>
 0003b490:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="
 0003b4a0:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c
 0003b4b0:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm
 0003b4c0:·3733·3038·223e·3c70·7265·3e3c·636f·6465··7308"><pre><code
 0003b4d0:·3e0a·5b5b·7061·636b·6167·6573·5d5d·0a6e··>.[[packages]].n
 0003b4e0:·616d·6520·3d20·2261·6964·6522·0a76·6572··ame·=·"aide".ver
 0003b4f0:·7369·6f6e·203d·2022·2a22·0a3c·2f63·6f64··sion·=·"*".</cod
0003b470:·6372·6970·7420·e287·b23c·2f61·3e3c·6272··cript·...</a><br 
0003b480:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan 
0003b490:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll 
0003b4a0:·6170·7365·2220·6964·3d22·6964·6d37·3330··apse"·id="idm730 
0003b4b0:·3822·3e3c·7461·626c·6520·636c·6173·733d··8"><table·class= 
0003b4c0:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str 
0003b4d0:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde 
0003b4e0:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden 
0003b4f0:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com 
0003b500:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td 
0003b510:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t 
0003b520:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption 
0003b530:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t 
0003b540:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e52··d></tr><tr><th>R 
0003b550:·6562·6f6f·743a·3c2f·7468·3e3c·7464·3e66··eboot:</th><td>f 
0003b560:·616c·7365·3c2f·7464·3e3c·2f74·723e·3c74··alse</td></tr><t 
0003b570:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:< 
0003b580:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</ 
0003b590:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table> 
0003b5a0:·3c70·7265·3e3c·636f·6465·3e0a·646e·6620··<pre><code>.dnf· 
0003b5b0:·696e·7374·616c·6c20·6169·6465·0a3c·2f63··install·aide.</c 
0003b5c0:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div>0003b500:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a
0003b5d0:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt0003b510:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn-
0003b5e0:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data-0003b520:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to
0003b5f0:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse0003b530:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"·
0003b600:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#0003b540:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
0003b610:·6964·6d37·3330·3922·2074·6162·696e·6465··idm7309"·tabinde0003b550:·6d37·3330·3922·2074·6162·696e·6465·783d··m7309"·tabindex=
0003b620:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt0003b560:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button
0003b630:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande0003b570:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=
0003b640:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=0003b580:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A
0003b650:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev0003b590:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea
0003b660:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R0003b5a0:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem
0003b670:·656d·6564·6961·7469·6f6e·2041·6e61·636f··emediation·Anaco0003b5b0:·6564·6961·7469·6f6e·2050·7570·7065·7420··ediation·Puppet·
0003b680:·6e64·6120·736e·6970·7065·7420·e287·b23c··nda·snippet·...<0003b5c0:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><
0003b690:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas0003b5d0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
0003b6a0:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps0003b5e0:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
0003b6b0:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="0003b5f0:·6c6c·6170·7365·2220·6964·3d22·6964·6d37··llapse"·id="idm7
0003b6c0:·6964·6d37·3330·3922·3e3c·7461·626c·6520··idm7309"><table·0003b600:·3330·3922·3e3c·7461·626c·6520·636c·6173··309"><table·clas
0003b6d0:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab0003b610:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s
0003b6e0:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table0003b620:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor
0003b6f0:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-0003b630:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond
0003b700:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><0003b640:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C
0003b710:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</0003b650:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><
0003b720:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><0003b660:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
0003b730:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr0003b670:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti
0003b740:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>0003b680:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<
0003b750:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr0003b690:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
0003b760:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th0003b6a0:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td
0003b770:·3e3c·7464·3e66·616c·7365·3c2f·7464·3e3c··><td>false</td>< 
0003b780:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra 
0003b790:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en 
0003b7a0:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></0003b6b0:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr>
 0003b6c0:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy
 0003b6d0:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable
 0003b6e0:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl
0003b7b0:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code0003b6f0:·653e·3c70·7265·3e3c·636f·6465·3e69·6e63··e><pre><code>inc
 0003b700:·6c75·6465·2069·6e73·7461·6c6c·5f61·6964··lude·install_aid
 0003b710:·650a·0a63·6c61·7373·2069·6e73·7461·6c6c··e..class·install
 0003b720:·5f61·6964·6520·7b0a·2020·7061·636b·6167··_aide·{.··packag
 0003b730:·6520·7b20·2761·6964·6527·3a0a·2020·2020··e·{·'aide':.····
 0003b740:·656e·7375·7265·203d·2667·743b·2027·696e··ensure·=&gt;·'in
 0003b750:·7374·616c·6c65·6427·2c0a·2020·7d0a·7d0a··stalled',.··}.}.
 0003b760:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d
0003b7c0:·3e0a·7061·636b·6167·6520·2d2d·6164·643d··>.package·--add= 
0003b7d0:·6169·6465·0a3c·2f63·6f64·653e·3c2f·7072··aide.</code></pr 
0003b7e0:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class 
0003b7f0:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes 
0003b800:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle=" 
0003b810:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t 
0003b820:·6172·6765·743d·2223·6964·6d37·3331·3022··arget="#idm7310" 
0003b830:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro 
0003b840:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria 
0003b850:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false 
0003b860:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat 
0003b870:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre 
0003b880:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati 
0003b890:·6f6e·204f·5342·7569·6c64·2042·6c75·6570··on·OSBuild·Bluep 
0003b8a0:·7269·6e74·2073·6e69·7070·6574·20e2·87b2··rint·snippet·... 
0003b8b0:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla 
0003b8c0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap 
0003b8d0:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id= 
0003b8e0:·2269·646d·3733·3130·223e·3c70·7265·3e3c··"idm7310"><pre>< 
0003b8f0:·636f·6465·3e0a·5b5b·7061·636b·6167·6573··code>.[[packages 
0003b900:·5d5d·0a6e·616d·6520·3d20·2261·6964·6522··]].name·=·"aide" 
0003b910:·0a76·6572·7369·6f6e·203d·2022·2a22·0a3c··.version·=·"*".< 
0003b920:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di 
0003b930:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn·0003b770:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn
0003b940:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat 
0003b950:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap 
0003b960:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target= 
0003b970:·2223·6964·6d37·3331·3122·2074·6162·696e··"#idm7311"·tabin 
0003b980:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu 
0003b990:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan 
0003b9a0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl 
0003b9b0:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r 
0003b9c0:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!" 
0003b9d0:·3e52·656d·6564·6961·7469·6f6e·2073·6372··>Remediation·scr 
0003b9e0:·6970·7420·e287·b23c·2f61·3e3c·6272·3e3c··ipt·...</a><br>< 
0003b9f0:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel 
0003ba00:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap 
0003ba10:·7365·2220·6964·3d22·6964·6d37·3331·3122··se"·id="idm7311" 
0003ba20:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t 
0003ba30:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip0003b780:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da
 0003b790:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla
 0003b7a0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
 0003b7b0:·3d22·2369·646d·3733·3130·2220·7461·6269··="#idm7310"·tabi
 0003b7c0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
 0003b7d0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
 0003b7e0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
 0003b7f0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
Max diff block lines reached; 884596/911948 bytes (97.00%) of diff not shown.
97.8 KB
html2text {}
    
Offset 140, 52 lines modifiedOffset 140, 38 lines modified
140 ··-·PCI-DSSv4-11.5.2140 ··-·PCI-DSSv4-11.5.2
141 ··-·enable_strategy141 ··-·enable_strategy
142 ··-·low_complexity142 ··-·low_complexity
143 ··-·low_disruption143 ··-·low_disruption
144 ··-·medium_severity144 ··-·medium_severity
145 ··-·no_reboot_needed145 ··-·no_reboot_needed
146 ··-·package_aide_installed146 ··-·package_aide_installed
147 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
148 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
149 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
150 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
151 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
152 dnf·install·aide 
153 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
154 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
155 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
156 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
157 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
158 package·--add=aide 
159 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8147 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
160 [[packages]]148 [[packages]]
161 name·=·"aide"149 name·=·"aide"
162 version·=·"*"150 version·=·"*"
163 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
164 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
165 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
166 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
167 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
168 package·install·aide 
169 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8151 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
170 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low152 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
171 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low153 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
172 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false154 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
173 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable155 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
174 include·install_aide156 include·install_aide
  
175 class·install_aide·{157 class·install_aide·{
176 ··package·{·'aide':158 ··package·{·'aide':
177 ····ensure·=>·'installed',159 ····ensure·=>·'installed',
178 ··}160 ··}
179 }161 }
 162 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 163 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 164 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 165 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 166 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 167 package·install·aide
180 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8168 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
181 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low169 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
182 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low170 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
183 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false171 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
184 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable172 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
185 #·Remediation·is·applicable·only·in·certain·platforms173 #·Remediation·is·applicable·only·in·certain·platforms
186 if·rpm·--quiet·-q·kernel;·then174 if·rpm·--quiet·-q·kernel;·then
Offset 193, 14 lines modifiedOffset 179, 28 lines modified
193 if·!·rpm·-q·--quiet·"aide"·;·then179 if·!·rpm·-q·--quiet·"aide"·;·then
194 ····dnf·install·-y·"aide"180 ····dnf·install·-y·"aide"
195 fi181 fi
  
196 else182 else
197 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'183 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
198 fi184 fi
 185 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 186 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 187 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 188 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 189 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 190 package·--add=aide
 191 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 192 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 193 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 194 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 195 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 196 dnf·install·aide
199 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*197 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
200 Run·the·following·command·to·generate·a·new·database:198 Run·the·following·command·to·generate·a·new·database:
201 $·sudo·/usr/sbin/aide·--init199 $·sudo·/usr/sbin/aide·--init
202 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:200 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
203 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz201 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
204 To·initiate·a·manual·check,·run·the·following·command:202 To·initiate·a·manual·check,·run·the·following·command:
205 $·sudo·/usr/sbin/aide·--check203 $·sudo·/usr/sbin/aide·--check
Offset 342, 26 lines modifiedOffset 342, 26 lines modified
342 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/b\x8bo\x8oo\x8ot\x8t·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*342 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/b\x8bo\x8oo\x8ot\x8t·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
343 It·is·recommended·that·the·/boot·directory·resides·on·a·separate·partition.·This·makes·it·easier·to·apply·restrictions·e.g.·through·the·noexec·mount·option.·Eventually,·the·/boot·partition·can·be·configured·not·to·be·mounted·automatically·with·the·noauto·mount·option.343 It·is·recommended·that·the·/boot·directory·resides·on·a·separate·partition.·This·makes·it·easier·to·apply·restrictions·e.g.·through·the·noexec·mount·option.·Eventually,·the·/boot·partition·can·be·configured·not·to·be·mounted·automatically·with·the·noauto·mount·option.
344 Rationale:···The·/boot·partition·contains·the·kernel·and·bootloader·files.·Access·to·this·partition·should·be·restricted.344 Rationale:···The·/boot·partition·contains·the·kernel·and·bootloader·files.·Access·to·this·partition·should·be·restricted.
345 Severity: ···medium345 Severity: ···medium
346 Rule·ID:·····xccdf_org.ssgproject.content_rule_partition_for_boot346 Rule·ID:·····xccdf_org.ssgproject.content_rule_partition_for_boot
347 Identifiers:·CCE-90755-0347 Identifiers:·CCE-90755-0
348 References:··_\x8a_\x8n_\x8s_\x8s_\x8i·R28348 References:··_\x8a_\x8n_\x8s_\x8s_\x8i·R28
 349 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 350 [[customizations.filesystem]]
 351 mountpoint·=·"/boot"
 352 size·=·1073741824
349 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8353 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
350 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low354 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
351 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high355 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high
352 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false356 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
353 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable357 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
354 part·/boot358 part·/boot
355 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
356 [[customizations.filesystem]] 
357 mountpoint·=·"/boot" 
358 size·=·1073741824 
359 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/h\x8ho\x8om\x8me\x8e·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*359 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/h\x8ho\x8om\x8me\x8e·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
360 If·user·home·directories·will·be·stored·locally,·create·a·separate·partition·for·/home·at·installation·time·(or·migrate·it·later·using·LVM).·If·/home·will·be·mounted·from·another·system·such·as·an·NFS·server,·then·creating·a·separate·partition·is·not·necessary·at·installation·time,·and·the·mountpoint·can·instead·be·configured·later.360 If·user·home·directories·will·be·stored·locally,·create·a·separate·partition·for·/home·at·installation·time·(or·migrate·it·later·using·LVM).·If·/home·will·be·mounted·from·another·system·such·as·an·NFS·server,·then·creating·a·separate·partition·is·not·necessary·at·installation·time,·and·the·mountpoint·can·instead·be·configured·later.
361 Rationale:···Ensuring·that·/home·is·mounted·on·its·own·partition·enables·the·setting·of·more·restrictive·mount·options,·and·also·helps·ensure·that·users·cannot·trivially·fill·partitions·used·for·log·or·audit·data·storage.361 Rationale:···Ensuring·that·/home·is·mounted·on·its·own·partition·enables·the·setting·of·more·restrictive·mount·options,·and·also·helps·ensure·that·users·cannot·trivially·fill·partitions·used·for·log·or·audit·data·storage.
362 Severity: ···low362 Severity: ···low
363 Rule·ID:·····xccdf_org.ssgproject.content_rule_partition_for_home363 Rule·ID:·····xccdf_org.ssgproject.content_rule_partition_for_home
364 Identifiers:·CCE-88231-6364 Identifiers:·CCE-88231-6
365 ·············_\x8c_\x8i_\x8s_\x8-_\x8c_\x8s_\x8c········12,·15,·8365 ·············_\x8c_\x8i_\x8s_\x8-_\x8c_\x8s_\x8c········12,·15,·8
Offset 370, 95 lines modifiedOffset 370, 95 lines modified
370 ·············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.5,·SR·3.8,·SR·4.1,·SR·4.3,·SR·5.1,·SR·5.2,·SR·5.3,·SR·7.1,·SR·7.6370 ·············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.5,·SR·3.8,·SR·4.1,·SR·4.3,·SR·5.1,·SR·5.2,·SR·5.3,·SR·7.1,·SR·7.6
371 References:··_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.3371 References:··_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.3
372 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)372 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)
373 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4373 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4
374 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227374 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
375 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R28375 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R28
Max diff block lines reached; 93910/100086 bytes (93.83%) of diff not shown.
1.05 MB
./usr/share/doc/ssg-nondebian/ssg-rhel10-guide-anssi_bp28_high.html
    
Offset 15174, 207 lines modifiedOffset 15174, 207 lines modified
0003b450:·7267·6574·3d22·2369·646d·3733·3038·2220··rget="#idm7308"·0003b450:·7267·6574·3d22·2369·646d·3733·3038·2220··rget="#idm7308"·
0003b460:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol0003b460:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol
0003b470:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-0003b470:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-
0003b480:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"0003b480:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"
0003b490:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate0003b490:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate
0003b4a0:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href0003b4a0:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href
0003b4b0:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio0003b4b0:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio
0003b4c0:·6e20·7363·7269·7074·20e2·87b2·3c2f·613e··n·script·...</a>0003b4c0:·6e20·4f53·4275·696c·6420·426c·7565·7072··n·OSBuild·Bluepr
 0003b4d0:·696e·7420·736e·6970·7065·7420·e287·b23c··int·snippet·...<
 0003b4e0:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas
 0003b4f0:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps
 0003b500:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="
 0003b510:·6964·6d37·3330·3822·3e3c·7072·653e·3c63··idm7308"><pre><c
 0003b520:·6f64·653e·0a5b·5b70·6163·6b61·6765·735d··ode>.[[packages]
 0003b530:·5d0a·6e61·6d65·203d·2022·6169·6465·220a··].name·=·"aide".
 0003b540:·7665·7273·696f·6e20·3d20·222a·220a·3c2f··version·=·"*".</
 0003b550:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div
 0003b560:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b
 0003b570:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data
 0003b580:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps
 0003b590:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
 0003b5a0:·2369·646d·3733·3039·2220·7461·6269·6e64··#idm7309"·tabind
 0003b5b0:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
 0003b5c0:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
 0003b5d0:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
 0003b5e0:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
 0003b5f0:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
 0003b600:·5265·6d65·6469·6174·696f·6e20·5075·7070··Remediation·Pupp
 0003b610:·6574·2073·6e69·7070·6574·20e2·87b2·3c2f··et·snippet·...</
0003b4d0:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="0003b620:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
0003b4e0:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c0003b630:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
0003b4f0:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm0003b640:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
0003b500:·3733·3038·223e·3c74·6162·6c65·2063·6c61··7308"><table·cla0003b650:·646d·3733·3039·223e·3c74·6162·6c65·2063··dm7309"><table·c
0003b510:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-0003b660:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl
0003b520:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo0003b670:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-
0003b530:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con0003b680:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c
0003b540:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>0003b690:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t
0003b550:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>0003b6a0:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t
0003b560:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr0003b6b0:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
0003b570:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt0003b6c0:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru
0003b580:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low0003b6d0:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l
0003b590:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t0003b6e0:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
0003b5a0:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t0003b6f0:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th>
0003b5b0:·643e·6661·6c73·653c·2f74·643e·3c2f·7472··d>false</td></tr0003b700:·3c74·643e·6661·6c73·653c·2f74·643e·3c2f··<td>false</td></
0003b5c0:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg0003b710:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat
0003b5d0:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl0003b720:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena
0003b5e0:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab0003b730:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t
0003b5f0:·6c65·3e3c·7072·653e·3c63·6f64·653e·0a64··le><pre><code>.d0003b740:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>
 0003b750:·696e·636c·7564·6520·696e·7374·616c·6c5f··include·install_
 0003b760:·6169·6465·0a0a·636c·6173·7320·696e·7374··aide..class·inst
 0003b770:·616c·6c5f·6169·6465·207b·0a20·2070·6163··all_aide·{.··pac
 0003b780:·6b61·6765·207b·2027·6169·6465·273a·0a20··kage·{·'aide':.·
 0003b790:·2020·2065·6e73·7572·6520·3d26·6774·3b20·····ensure·=&gt;·
 0003b7a0:·2769·6e73·7461·6c6c·6564·272c·0a20·207d··'installed',.··}
 0003b7b0:·0a7d·0a3c·2f63·6f64·653e·3c2f·7072·653e··.}.</code></pre>
 0003b7c0:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class="
 0003b7d0:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success"
 0003b7e0:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co
 0003b7f0:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar
 0003b800:·6765·743d·2223·6964·6d37·3331·3022·2074··get="#idm7310"·t
 0003b810:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
 0003b820:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
 0003b830:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
 0003b840:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
 0003b850:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
 0003b860:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
 0003b870:·2073·6372·6970·7420·e287·b23c·2f61·3e3c···script·...</a><
0003b600:·6e66·2069·6e73·7461·6c6c·2061·6964·650a··nf·install·aide. 
0003b610:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d 
0003b620:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn 
0003b630:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da 
0003b640:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla 
0003b650:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target 
0003b660:·3d22·2369·646d·3733·3039·2220·7461·6269··="#idm7309"·tabi 
0003b670:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b 
0003b680:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa 
0003b690:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit 
0003b6a0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to· 
0003b6b0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#! 
0003b6c0:·223e·5265·6d65·6469·6174·696f·6e20·416e··">Remediation·An 
0003b6d0:·6163·6f6e·6461·2073·6e69·7070·6574·20e2··aconda·snippet·. 
0003b6e0:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c 
0003b6f0:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll 
0003b700:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i 
0003b710:·643d·2269·646d·3733·3039·223e·3c74·6162··d="idm7309"><tab 
0003b720:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table· 
0003b730:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta 
0003b740:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab 
0003b750:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t 
0003b760:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity 
0003b770:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t 
0003b780:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D 
0003b790:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th>< 
0003b7a0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
0003b7b0:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:< 
0003b7c0:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t 
0003b7d0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S 
0003b7e0:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td 
0003b7f0:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr 
0003b800:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c 
0003b810:·6f64·653e·0a70·6163·6b61·6765·202d·2d61··ode>.package·--a 
0003b820:·6464·3d61·6964·650a·3c2f·636f·6465·3e3c··dd=aide.</code>< 
0003b830:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl 
0003b840:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc 
0003b850:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl 
0003b860:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat 
0003b870:·612d·7461·7267·6574·3d22·2369·646d·3733··a-target="#idm73 
0003b880:·3130·2220·7461·6269·6e64·6578·3d22·3022··10"·tabindex="0" 
0003b890:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a 
0003b8a0:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa 
0003b8b0:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti 
0003b8c0:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"· 
0003b8d0:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi 
0003b8e0:·6174·696f·6e20·4f53·4275·696c·6420·426c··ation·OSBuild·Bl 
0003b8f0:·7565·7072·696e·7420·736e·6970·7065·7420··ueprint·snippet· 
0003b900:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div· 
0003b910:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col 
0003b920:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"· 
0003b930:·6964·3d22·6964·6d37·3331·3022·3e3c·7072··id="idm7310"><pr 
0003b940:·653e·3c63·6f64·653e·0a5b·5b70·6163·6b61··e><code>.[[packa 
0003b950:·6765·735d·5d0a·6e61·6d65·203d·2022·6169··ges]].name·=·"ai 
0003b960:·6465·220a·7665·7273·696f·6e20·3d20·222a··de".version·=·"* 
0003b970:·220a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··".</code></pre>< 
0003b980:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b0003b880:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
 0003b890:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
 0003b8a0:·6c6c·6170·7365·2220·6964·3d22·6964·6d37··llapse"·id="idm7
 0003b8b0:·3331·3022·3e3c·7461·626c·6520·636c·6173··310"><table·clas
Max diff block lines reached; 968659/995873 bytes (97.27%) of diff not shown.
108 KB
html2text {}
    
Offset 141, 52 lines modifiedOffset 141, 38 lines modified
141 ··-·PCI-DSSv4-11.5.2141 ··-·PCI-DSSv4-11.5.2
142 ··-·enable_strategy142 ··-·enable_strategy
143 ··-·low_complexity143 ··-·low_complexity
144 ··-·low_disruption144 ··-·low_disruption
145 ··-·medium_severity145 ··-·medium_severity
146 ··-·no_reboot_needed146 ··-·no_reboot_needed
147 ··-·package_aide_installed147 ··-·package_aide_installed
148 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
149 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
150 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
151 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
152 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
153 dnf·install·aide 
154 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
155 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
156 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
157 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
158 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
159 package·--add=aide 
160 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8148 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
161 [[packages]]149 [[packages]]
162 name·=·"aide"150 name·=·"aide"
163 version·=·"*"151 version·=·"*"
164 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
165 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
166 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
167 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
168 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
169 package·install·aide 
170 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8152 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
171 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low153 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
172 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low154 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
173 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false155 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
174 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable156 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
175 include·install_aide157 include·install_aide
  
176 class·install_aide·{158 class·install_aide·{
177 ··package·{·'aide':159 ··package·{·'aide':
178 ····ensure·=>·'installed',160 ····ensure·=>·'installed',
179 ··}161 ··}
180 }162 }
 163 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 164 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 165 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 166 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 167 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 168 package·install·aide
181 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8169 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
182 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low170 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
183 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low171 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
184 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false172 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
185 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable173 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
186 #·Remediation·is·applicable·only·in·certain·platforms174 #·Remediation·is·applicable·only·in·certain·platforms
187 if·rpm·--quiet·-q·kernel;·then175 if·rpm·--quiet·-q·kernel;·then
Offset 194, 14 lines modifiedOffset 180, 28 lines modified
194 if·!·rpm·-q·--quiet·"aide"·;·then180 if·!·rpm·-q·--quiet·"aide"·;·then
195 ····dnf·install·-y·"aide"181 ····dnf·install·-y·"aide"
196 fi182 fi
  
197 else183 else
198 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'184 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
199 fi185 fi
 186 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 187 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 188 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 189 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 190 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 191 package·--add=aide
 192 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 193 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 194 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 195 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 196 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 197 dnf·install·aide
200 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*198 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
201 Run·the·following·command·to·generate·a·new·database:199 Run·the·following·command·to·generate·a·new·database:
202 $·sudo·/usr/sbin/aide·--init200 $·sudo·/usr/sbin/aide·--init
203 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:201 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
204 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz202 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
205 To·initiate·a·manual·check,·run·the·following·command:203 To·initiate·a·manual·check,·run·the·following·command:
206 $·sudo·/usr/sbin/aide·--check204 $·sudo·/usr/sbin/aide·--check
Offset 855, 26 lines modifiedOffset 855, 26 lines modified
855 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/b\x8bo\x8oo\x8ot\x8t·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*855 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/b\x8bo\x8oo\x8ot\x8t·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
856 It·is·recommended·that·the·/boot·directory·resides·on·a·separate·partition.·This·makes·it·easier·to·apply·restrictions·e.g.·through·the·noexec·mount·option.·Eventually,·the·/boot·partition·can·be·configured·not·to·be·mounted·automatically·with·the·noauto·mount·option.856 It·is·recommended·that·the·/boot·directory·resides·on·a·separate·partition.·This·makes·it·easier·to·apply·restrictions·e.g.·through·the·noexec·mount·option.·Eventually,·the·/boot·partition·can·be·configured·not·to·be·mounted·automatically·with·the·noauto·mount·option.
857 Rationale:···The·/boot·partition·contains·the·kernel·and·bootloader·files.·Access·to·this·partition·should·be·restricted.857 Rationale:···The·/boot·partition·contains·the·kernel·and·bootloader·files.·Access·to·this·partition·should·be·restricted.
858 Severity: ···medium858 Severity: ···medium
859 Rule·ID:·····xccdf_org.ssgproject.content_rule_partition_for_boot859 Rule·ID:·····xccdf_org.ssgproject.content_rule_partition_for_boot
860 Identifiers:·CCE-90755-0860 Identifiers:·CCE-90755-0
861 References:··_\x8a_\x8n_\x8s_\x8s_\x8i·R28861 References:··_\x8a_\x8n_\x8s_\x8s_\x8i·R28
 862 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 863 [[customizations.filesystem]]
 864 mountpoint·=·"/boot"
 865 size·=·1073741824
862 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8866 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
863 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low867 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
864 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high868 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high
865 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false869 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
866 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable870 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
867 part·/boot871 part·/boot
868 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
869 [[customizations.filesystem]] 
870 mountpoint·=·"/boot" 
871 size·=·1073741824 
872 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/h\x8ho\x8om\x8me\x8e·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*872 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/h\x8ho\x8om\x8me\x8e·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
873 If·user·home·directories·will·be·stored·locally,·create·a·separate·partition·for·/home·at·installation·time·(or·migrate·it·later·using·LVM).·If·/home·will·be·mounted·from·another·system·such·as·an·NFS·server,·then·creating·a·separate·partition·is·not·necessary·at·installation·time,·and·the·mountpoint·can·instead·be·configured·later.873 If·user·home·directories·will·be·stored·locally,·create·a·separate·partition·for·/home·at·installation·time·(or·migrate·it·later·using·LVM).·If·/home·will·be·mounted·from·another·system·such·as·an·NFS·server,·then·creating·a·separate·partition·is·not·necessary·at·installation·time,·and·the·mountpoint·can·instead·be·configured·later.
874 Rationale:···Ensuring·that·/home·is·mounted·on·its·own·partition·enables·the·setting·of·more·restrictive·mount·options,·and·also·helps·ensure·that·users·cannot·trivially·fill·partitions·used·for·log·or·audit·data·storage.874 Rationale:···Ensuring·that·/home·is·mounted·on·its·own·partition·enables·the·setting·of·more·restrictive·mount·options,·and·also·helps·ensure·that·users·cannot·trivially·fill·partitions·used·for·log·or·audit·data·storage.
875 Severity: ···low875 Severity: ···low
876 Rule·ID:·····xccdf_org.ssgproject.content_rule_partition_for_home876 Rule·ID:·····xccdf_org.ssgproject.content_rule_partition_for_home
877 Identifiers:·CCE-88231-6877 Identifiers:·CCE-88231-6
878 ·············_\x8c_\x8i_\x8s_\x8-_\x8c_\x8s_\x8c········12,·15,·8878 ·············_\x8c_\x8i_\x8s_\x8-_\x8c_\x8s_\x8c········12,·15,·8
Offset 883, 95 lines modifiedOffset 883, 95 lines modified
883 ·············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.5,·SR·3.8,·SR·4.1,·SR·4.3,·SR·5.1,·SR·5.2,·SR·5.3,·SR·7.1,·SR·7.6883 ·············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.5,·SR·3.8,·SR·4.1,·SR·4.3,·SR·5.1,·SR·5.2,·SR·5.3,·SR·7.1,·SR·7.6
884 References:··_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.3884 References:··_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.3
885 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)885 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)
886 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4886 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4
887 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227887 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
888 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R28888 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R28
Max diff block lines reached; 104003/110179 bytes (94.39%) of diff not shown.
866 KB
./usr/share/doc/ssg-nondebian/ssg-rhel10-guide-anssi_bp28_intermediary.html
    
Offset 15164, 208 lines modifiedOffset 15164, 208 lines modified
0003b3b0:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="0003b3b0:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
0003b3c0:·2369·646d·3733·3038·2220·7461·6269·6e64··#idm7308"·tabind0003b3c0:·2369·646d·3733·3038·2220·7461·6269·6e64··#idm7308"·tabind
0003b3d0:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but0003b3d0:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
0003b3e0:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand0003b3e0:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
0003b3f0:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title0003b3f0:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
0003b400:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re0003b400:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
0003b410:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">0003b410:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
0003b420:·5265·6d65·6469·6174·696f·6e20·7363·7269··Remediation·scri0003b420:·5265·6d65·6469·6174·696f·6e20·4f53·4275··Remediation·OSBu
 0003b430:·696c·6420·426c·7565·7072·696e·7420·736e··ild·Blueprint·sn
 0003b440:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br
 0003b450:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
 0003b460:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
 0003b470:·6170·7365·2220·6964·3d22·6964·6d37·3330··apse"·id="idm730
 0003b480:·3822·3e3c·7072·653e·3c63·6f64·653e·0a5b··8"><pre><code>.[
 0003b490:·5b70·6163·6b61·6765·735d·5d0a·6e61·6d65··[packages]].name
 0003b4a0:·203d·2022·6169·6465·220a·7665·7273·696f···=·"aide".versio
 0003b4b0:·6e20·3d20·222a·220a·3c2f·636f·6465·3e3c··n·=·"*".</code><
0003b430:·7074·20e2·87b2·3c2f·613e·3c62·723e·3c64··pt·...</a><br><d 
0003b440:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel- 
0003b450:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps 
0003b460:·6522·2069·643d·2269·646d·3733·3038·223e··e"·id="idm7308"> 
0003b470:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta 
0003b480:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe 
0003b490:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered 
0003b4a0:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed 
0003b4b0:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple 
0003b4c0:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo 
0003b4d0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr>< 
0003b4e0:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</ 
0003b4f0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td>< 
0003b500:·2f74·723e·3c74·723e·3c74·683e·5265·626f··/tr><tr><th>Rebo 
0003b510:·6f74·3a3c·2f74·683e·3c74·643e·6661·6c73··ot:</th><td>fals 
0003b520:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr>< 
0003b530:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th 
0003b540:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td> 
0003b550:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr 
0003b560:·653e·3c63·6f64·653e·0a64·6e66·2069·6e73··e><code>.dnf·ins 
0003b570:·7461·6c6c·2061·6964·650a·3c2f·636f·6465··tall·aide.</code 
0003b580:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a·0003b4c0:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl
0003b590:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s0003b4d0:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc
0003b5a0:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog0003b4e0:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl
0003b5b0:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d0003b4f0:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat
0003b5c0:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm0003b500:·612d·7461·7267·6574·3d22·2369·646d·3733··a-target="#idm73
0003b5d0:·3733·3039·2220·7461·6269·6e64·6578·3d22··7309"·tabindex="0003b510:·3039·2220·7461·6269·6e64·6578·3d22·3022··09"·tabindex="0"
0003b5e0:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"0003b520:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
0003b5f0:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="0003b530:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
0003b600:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac0003b540:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
0003b610:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal0003b550:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
0003b620:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme0003b560:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
0003b630:·6469·6174·696f·6e20·416e·6163·6f6e·6461··diation·Anaconda0003b570:·6174·696f·6e20·5075·7070·6574·2073·6e69··ation·Puppet·sni
0003b640:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>0003b580:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>
0003b650:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="0003b590:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
0003b660:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c0003b5a0:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
0003b670:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm0003b5b0:·7073·6522·2069·643d·2269·646d·3733·3039··pse"·id="idm7309
0003b680:·3733·3039·223e·3c74·6162·6c65·2063·6c61··7309"><table·cla0003b5c0:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="
0003b690:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-0003b5d0:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri
0003b6a0:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo0003b5e0:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border
0003b6b0:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con0003b5f0:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens
0003b6c0:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>0003b600:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp
0003b6d0:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>0003b610:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>
0003b6e0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr0003b620:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
0003b6f0:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt0003b630:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:
 0003b640:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
 0003b650:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re
 0003b660:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa
 0003b670:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr
 0003b680:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</
 0003b690:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t
 0003b6a0:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><
 0003b6b0:·7072·653e·3c63·6f64·653e·696e·636c·7564··pre><code>includ
 0003b6c0:·6520·696e·7374·616c·6c5f·6169·6465·0a0a··e·install_aide..
 0003b6d0:·636c·6173·7320·696e·7374·616c·6c5f·6169··class·install_ai
 0003b6e0:·6465·207b·0a20·2070·6163·6b61·6765·207b··de·{.··package·{
 0003b6f0:·2027·6169·6465·273a·0a20·2020·2065·6e73···'aide':.····ens
 0003b700:·7572·6520·3d26·6774·3b20·2769·6e73·7461··ure·=&gt;·'insta
 0003b710:·6c6c·6564·272c·0a20·207d·0a7d·0a3c·2f63··lled',.··}.}.</c
 0003b720:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div>
 0003b730:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt
 0003b740:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data-
 0003b750:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse
 0003b760:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
 0003b770:·6964·6d37·3331·3022·2074·6162·696e·6465··idm7310"·tabinde
 0003b780:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt
 0003b790:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande
 0003b7a0:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=
 0003b7b0:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev
 0003b7c0:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R
 0003b7d0:·656d·6564·6961·7469·6f6e·2073·6372·6970··emediation·scrip
 0003b7e0:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di
 0003b7f0:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c
 0003b800:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse
 0003b810:·2220·6964·3d22·6964·6d37·3331·3022·3e3c··"·id="idm7310"><
 0003b820:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab
 0003b830:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped
 0003b840:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·
 0003b850:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"
 0003b860:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex
0003b700:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low0003b870:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low
0003b710:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
0003b720:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t 
0003b730:·643e·6661·6c73·653c·2f74·643e·3c2f·7472··d>false</td></tr 
0003b740:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg 
0003b750:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl 
0003b760:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab 
0003b770:·6c65·3e3c·7072·653e·3c63·6f64·653e·0a70··le><pre><code>.p 
0003b780:·6163·6b61·6765·202d·2d61·6464·3d61·6964··ackage·--add=aid 
0003b790:·650a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··e.</code></pre>< 
0003b7a0:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b 
0003b7b0:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"· 
0003b7c0:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col 
0003b7d0:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ 
0003b7e0:·6574·3d22·2369·646d·3733·3130·2220·7461··et="#idm7310"·ta 
0003b7f0:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role= 
0003b800:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex 
0003b810:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t 
0003b820:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t 
0003b830:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href=" 
0003b840:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation· 
0003b850:·4f53·4275·696c·6420·426c·7565·7072·696e··OSBuild·Blueprin 
0003b860:·7420·736e·6970·7065·7420·e287·b23c·2f61··t·snippet·...</a 
0003b870:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class= 
0003b880:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse· 
0003b890:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id 
0003b8a0:·6d37·3331·3022·3e3c·7072·653e·3c63·6f64··m7310"><pre><cod 
0003b8b0:·653e·0a5b·5b70·6163·6b61·6765·735d·5d0a··e>.[[packages]]. 
0003b8c0:·6e61·6d65·203d·2022·6169·6465·220a·7665··name·=·"aide".ve 
0003b8d0:·7273·696f·6e20·3d20·222a·220a·3c2f·636f··rsion·=·"*".</co 
Max diff block lines reached; 780956/808308 bytes (96.62%) of diff not shown.
76.6 KB
html2text {}
    
Offset 156, 52 lines modifiedOffset 156, 38 lines modified
156 ··-·PCI-DSSv4-11.5.2156 ··-·PCI-DSSv4-11.5.2
157 ··-·enable_strategy157 ··-·enable_strategy
158 ··-·low_complexity158 ··-·low_complexity
159 ··-·low_disruption159 ··-·low_disruption
160 ··-·medium_severity160 ··-·medium_severity
161 ··-·no_reboot_needed161 ··-·no_reboot_needed
162 ··-·package_aide_installed162 ··-·package_aide_installed
163 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
164 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
165 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
166 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
167 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
168 dnf·install·aide 
169 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
170 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
171 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
172 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
173 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
174 package·--add=aide 
175 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8163 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
176 [[packages]]164 [[packages]]
177 name·=·"aide"165 name·=·"aide"
178 version·=·"*"166 version·=·"*"
179 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
180 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
181 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
182 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
183 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
184 package·install·aide 
185 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8167 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
186 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low168 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
187 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low169 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
188 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false170 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
189 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable171 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
190 include·install_aide172 include·install_aide
  
191 class·install_aide·{173 class·install_aide·{
192 ··package·{·'aide':174 ··package·{·'aide':
193 ····ensure·=>·'installed',175 ····ensure·=>·'installed',
194 ··}176 ··}
195 }177 }
 178 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 179 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 180 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 181 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 182 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 183 package·install·aide
196 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8184 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
197 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low185 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
198 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low186 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
199 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false187 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
200 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable188 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
201 #·Remediation·is·applicable·only·in·certain·platforms189 #·Remediation·is·applicable·only·in·certain·platforms
202 if·rpm·--quiet·-q·kernel;·then190 if·rpm·--quiet·-q·kernel;·then
Offset 209, 14 lines modifiedOffset 195, 28 lines modified
209 if·!·rpm·-q·--quiet·"aide"·;·then195 if·!·rpm·-q·--quiet·"aide"·;·then
210 ····dnf·install·-y·"aide"196 ····dnf·install·-y·"aide"
211 fi197 fi
  
212 else198 else
213 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'199 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
214 fi200 fi
 201 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 202 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 203 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 204 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 205 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 206 package·--add=aide
 207 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 208 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 209 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 210 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 211 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 212 dnf·install·aide
215 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*213 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
216 Run·the·following·command·to·generate·a·new·database:214 Run·the·following·command·to·generate·a·new·database:
217 $·sudo·/usr/sbin/aide·--init215 $·sudo·/usr/sbin/aide·--init
218 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the216 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the
219 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these217 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these
220 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their218 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their
221 integrity.·The·newly-generated·database·can·be·installed·as·follows:219 integrity.·The·newly-generated·database·can·be·installed·as·follows:
Offset 378, 26 lines modifiedOffset 378, 26 lines modified
378 configured·not·to·be·mounted·automatically·with·the·noauto·mount·option.378 configured·not·to·be·mounted·automatically·with·the·noauto·mount·option.
379 Rationale:···The·/boot·partition·contains·the·kernel·and·bootloader·files.·Access·to·this·partition379 Rationale:···The·/boot·partition·contains·the·kernel·and·bootloader·files.·Access·to·this·partition
380 ·············should·be·restricted.380 ·············should·be·restricted.
381 Severity: ···medium381 Severity: ···medium
382 Rule·ID:·····xccdf_org.ssgproject.content_rule_partition_for_boot382 Rule·ID:·····xccdf_org.ssgproject.content_rule_partition_for_boot
383 Identifiers:·CCE-90755-0383 Identifiers:·CCE-90755-0
384 References:··_\x8a_\x8n_\x8s_\x8s_\x8i·R28384 References:··_\x8a_\x8n_\x8s_\x8s_\x8i·R28
 385 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 386 [[customizations.filesystem]]
 387 mountpoint·=·"/boot"
 388 size·=·1073741824
385 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8389 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
386 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low390 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
387 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high391 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high
388 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false392 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
389 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable393 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
390 part·/boot394 part·/boot
391 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
392 [[customizations.filesystem]] 
393 mountpoint·=·"/boot" 
394 size·=·1073741824 
395 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/h\x8ho\x8om\x8me\x8e·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*395 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/h\x8ho\x8om\x8me\x8e·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
396 If·user·home·directories·will·be·stored·locally,·create·a·separate·partition·for·/home·at396 If·user·home·directories·will·be·stored·locally,·create·a·separate·partition·for·/home·at
397 installation·time·(or·migrate·it·later·using·LVM).·If·/home·will·be·mounted·from·another·system·such397 installation·time·(or·migrate·it·later·using·LVM).·If·/home·will·be·mounted·from·another·system·such
398 as·an·NFS·server,·then·creating·a·separate·partition·is·not·necessary·at·installation·time,·and·the398 as·an·NFS·server,·then·creating·a·separate·partition·is·not·necessary·at·installation·time,·and·the
399 mountpoint·can·instead·be·configured·later.399 mountpoint·can·instead·be·configured·later.
400 ·············Ensuring·that·/home·is·mounted·on·its·own·partition·enables·the·setting·of·more400 ·············Ensuring·that·/home·is·mounted·on·its·own·partition·enables·the·setting·of·more
401 Rationale:···restrictive·mount·options,·and·also·helps·ensure·that·users·cannot·trivially·fill401 Rationale:···restrictive·mount·options,·and·also·helps·ensure·that·users·cannot·trivially·fill
Offset 412, 105 lines modifiedOffset 412, 105 lines modified
412 ····························SR·7.6412 ····························SR·7.6
413 References:··_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.3413 References:··_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.3
414 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)414 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)
415 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4415 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4
416 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227416 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
417 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R28417 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R28
Max diff block lines reached; 73071/78435 bytes (93.16%) of diff not shown.
173 KB
./usr/share/doc/ssg-nondebian/ssg-rhel10-guide-anssi_bp28_minimal.html
    
Offset 14847, 222 lines modifiedOffset 14847, 222 lines modified
00039fe0:·6574·3d22·2369·646d·3130·3630·3822·2074··et="#idm10608"·t00039fe0:·6574·3d22·2369·646d·3130·3630·3822·2074··et="#idm10608"·t
00039ff0:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role00039ff0:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
0003a000:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e0003a000:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
0003a010:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·0003a010:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
0003a020:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·0003a020:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
0003a030:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=0003a030:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
0003a040:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation0003a040:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
0003a050:·2073·6372·6970·7420·e287·b23c·2f61·3e3c···script·...</a>< 
0003a060:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p 
0003a070:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co 
0003a080:·6c6c·6170·7365·2220·6964·3d22·6964·6d31··llapse"·id="idm1 
0003a090:·3036·3038·223e·3c74·6162·6c65·2063·6c61··0608"><table·cla 
0003a0a0:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table- 
0003a0b0:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo 
0003a0c0:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con 
0003a0d0:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th> 
0003a0e0:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th> 
0003a0f0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
0003a100:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt 
0003a110:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low0003a050:·204f·5342·7569·6c64·2042·6c75·6570·7269···OSBuild·Bluepri
 0003a060:·6e74·2073·6e69·7070·6574·20e2·87b2·3c2f··nt·snippet·...</
 0003a070:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
 0003a080:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
 0003a090:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
 0003a0a0:·646d·3130·3630·3822·3e3c·7072·653e·3c63··dm10608"><pre><c
 0003a0b0:·6f64·653e·0a5b·5b70·6163·6b61·6765·735d··ode>.[[packages]
 0003a0c0:·5d0a·6e61·6d65·203d·2022·646e·662d·6175··].name·=·"dnf-au
 0003a0d0:·746f·6d61·7469·6322·0a76·6572·7369·6f6e··tomatic".version
 0003a0e0:·203d·2022·2a22·0a3c·2f63·6f64·653e·3c2f···=·"*".</code></
 0003a0f0:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla
 0003a100:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ
 0003a110:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle
 0003a120:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data
 0003a130:·2d74·6172·6765·743d·2223·6964·6d31·3036··-target="#idm106
 0003a140:·3039·2220·7461·6269·6e64·6578·3d22·3022··09"·tabindex="0"
 0003a150:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
 0003a160:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
 0003a170:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
 0003a180:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
 0003a190:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
 0003a1a0:·6174·696f·6e20·5075·7070·6574·2073·6e69··ation·Puppet·sni
 0003a1b0:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>
 0003a1c0:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
 0003a1d0:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
 0003a1e0:·7073·6522·2069·643d·2269·646d·3130·3630··pse"·id="idm1060
 0003a1f0:·3922·3e3c·7461·626c·6520·636c·6173·733d··9"><table·class=
 0003a200:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str
 0003a210:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde
 0003a220:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden
 0003a230:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com
 0003a240:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td
0003a120:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t0003a250:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
0003a130:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t 
0003a140:·643e·6661·6c73·653c·2f74·643e·3c2f·7472··d>false</td></tr 
0003a150:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg 
0003a160:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl 
0003a170:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab 
0003a180:·6c65·3e3c·7072·653e·3c63·6f64·653e·0a64··le><pre><code>.d0003a260:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption
 0003a270:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
 0003a280:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e52··d></tr><tr><th>R
 0003a290:·6562·6f6f·743a·3c2f·7468·3e3c·7464·3e66··eboot:</th><td>f
 0003a2a0:·616c·7365·3c2f·7464·3e3c·2f74·723e·3c74··alse</td></tr><t
 0003a2b0:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<
 0003a2c0:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</
 0003a2d0:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table>
 0003a2e0:·3c70·7265·3e3c·636f·6465·3e69·6e63·6c75··<pre><code>inclu
0003a190:·6e66·2069·6e73·7461·6c6c·2064·6e66·2d61··nf·install·dnf-a0003a2f0:·6465·2069·6e73·7461·6c6c·5f64·6e66·2d61··de·install_dnf-a
0003a1a0:·7574·6f6d·6174·6963·0a3c·2f63·6f64·653e··utomatic.</code>0003a300:·7574·6f6d·6174·6963·0a0a·636c·6173·7320··utomatic..class·
 0003a310:·696e·7374·616c·6c5f·646e·662d·6175·746f··install_dnf-auto
 0003a320:·6d61·7469·6320·7b0a·2020·7061·636b·6167··matic·{.··packag
 0003a330:·6520·7b20·2764·6e66·2d61·7574·6f6d·6174··e·{·'dnf-automat
 0003a340:·6963·273a·0a20·2020·2065·6e73·7572·6520··ic':.····ensure·
 0003a350:·3d26·6774·3b20·2769·6e73·7461·6c6c·6564··=&gt;·'installed
 0003a360:·272c·0a20·207d·0a7d·0a3c·2f63·6f64·653e··',.··}.}.</code>
0003a1b0:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c0003a370:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c
0003a1c0:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su0003a380:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su
0003a1d0:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg0003a390:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg
0003a1e0:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da0003a3a0:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da
0003a1f0:·7461·2d74·6172·6765·743d·2223·6964·6d31··ta-target="#idm10003a3b0:·7461·2d74·6172·6765·743d·2223·6964·6d31··ta-target="#idm1
0003a200:·3036·3039·2220·7461·6269·6e64·6578·3d22··0609"·tabindex="0003a3c0:·3036·3130·2220·7461·6269·6e64·6578·3d22··0610"·tabindex="
0003a210:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"0003a3d0:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
0003a220:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="0003a3e0:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
0003a230:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac0003a3f0:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
0003a240:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal0003a400:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
0003a250:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme0003a410:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
0003a260:·6469·6174·696f·6e20·416e·6163·6f6e·6461··diation·Anaconda 
0003a270:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a> 
0003a280:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class=" 
0003a290:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c 
0003a2a0:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm 
0003a2b0:·3130·3630·3922·3e3c·7461·626c·6520·636c··10609"><table·cl 
0003a2c0:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table 
0003a2d0:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b 
0003a2e0:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co 
0003a2f0:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th 
0003a300:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th 
0003a310:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t 
0003a320:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup 
0003a330:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo 
0003a340:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr>< 
0003a350:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th><0003a420:·6469·6174·696f·6e20·7363·7269·7074·20e2··diation·script·.
 0003a430:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c
 0003a440:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
 0003a450:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
 0003a460:·643d·2269·646d·3130·3631·3022·3e3c·7461··d="idm10610"><ta
 0003a470:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table
 0003a480:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t
 0003a490:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta
 0003a4a0:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><
 0003a4b0:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit
 0003a4c0:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</
 0003a4d0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 0003a4e0:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th>
 0003a4f0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
 0003a500:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot:
 0003a510:·3c2f·7468·3e3c·7464·3e66·616c·7365·3c2f··</th><td>false</
 0003a520:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 0003a530:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t
0003a360:·7464·3e66·616c·7365·3c2f·7464·3e3c·2f74··td>false</td></t0003a540:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t
 0003a550:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><
 0003a560:·636f·6465·3e0a·7061·636b·6167·6520·696e··code>.package·in
 0003a570:·7374·616c·6c20·646e·662d·6175·746f·6d61··stall·dnf-automa
 0003a580:·7469·630a·3c2f·636f·6465·3e3c·2f70·7265··tic.</code></pre
 0003a590:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class=
 0003a5a0:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success
 0003a5b0:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c
 0003a5c0:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta
Max diff block lines reached; 128618/157902 bytes (81.45%) of diff not shown.
18.3 KB
html2text {}
    
Offset 117, 52 lines modifiedOffset 117, 38 lines modified
117 ··-·CCE-87561-7117 ··-·CCE-87561-7
118 ··-·enable_strategy118 ··-·enable_strategy
119 ··-·low_complexity119 ··-·low_complexity
120 ··-·low_disruption120 ··-·low_disruption
121 ··-·medium_severity121 ··-·medium_severity
122 ··-·no_reboot_needed122 ··-·no_reboot_needed
123 ··-·package_dnf-automatic_installed123 ··-·package_dnf-automatic_installed
124 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
125 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
126 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
127 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
128 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
129 dnf·install·dnf-automatic 
130 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
131 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
132 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
133 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
134 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
135 package·--add=dnf-automatic 
136 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8124 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
137 [[packages]]125 [[packages]]
138 name·=·"dnf-automatic"126 name·=·"dnf-automatic"
139 version·=·"*"127 version·=·"*"
140 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
141 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
142 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
143 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
144 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
145 package·install·dnf-automatic 
146 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8128 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
147 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low129 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
148 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low130 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
149 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false131 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
150 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable132 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
151 include·install_dnf-automatic133 include·install_dnf-automatic
  
152 class·install_dnf-automatic·{134 class·install_dnf-automatic·{
153 ··package·{·'dnf-automatic':135 ··package·{·'dnf-automatic':
154 ····ensure·=>·'installed',136 ····ensure·=>·'installed',
155 ··}137 ··}
156 }138 }
 139 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 140 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 141 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 142 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 143 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 144 package·install·dnf-automatic
157 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8145 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
158 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low146 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
159 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low147 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
160 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false148 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
161 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable149 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
162 #·Remediation·is·applicable·only·in·certain·platforms150 #·Remediation·is·applicable·only·in·certain·platforms
163 if·!·(·{·rpm·--quiet·-q·kernel·;}·&&·{·rpm·--quiet·-q·rpm-ostree·;}·&&·{·rpm·--quiet·-q·bootc151 if·!·(·{·rpm·--quiet·-q·kernel·;}·&&·{·rpm·--quiet·-q·rpm-ostree·;}·&&·{·rpm·--quiet·-q·bootc
Offset 171, 14 lines modifiedOffset 157, 28 lines modified
171 if·!·rpm·-q·--quiet·"dnf-automatic"·;·then157 if·!·rpm·-q·--quiet·"dnf-automatic"·;·then
172 ····dnf·install·-y·"dnf-automatic"158 ····dnf·install·-y·"dnf-automatic"
173 fi159 fi
  
174 else160 else
175 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'161 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
176 fi162 fi
 163 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 164 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 165 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 166 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 167 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 168 package·--add=dnf-automatic
 169 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 170 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 171 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 172 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 173 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 174 dnf·install·dnf-automatic
177 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·d\x8dn\x8nf\x8f-\x8-a\x8au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8c·t\x8to\x8o·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·A\x8Av\x8va\x8ai\x8il\x8la\x8ab\x8bl\x8le\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8es\x8s·A\x8Au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8ca\x8al\x8ll\x8ly\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*175 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·d\x8dn\x8nf\x8f-\x8-a\x8au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8c·t\x8to\x8o·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·A\x8Av\x8va\x8ai\x8il\x8la\x8ab\x8bl\x8le\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8es\x8s·A\x8Au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8ca\x8al\x8ll\x8ly\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
178 To·ensure·that·the·packages·comprising·the·available·updates·will·be·automatically·installed176 To·ensure·that·the·packages·comprising·the·available·updates·will·be·automatically·installed
179 by·dnf-automatic,·set·apply_updates·to·yes·under·[commands]·section·in·/etc/dnf/177 by·dnf-automatic,·set·apply_updates·to·yes·under·[commands]·section·in·/etc/dnf/
180 automatic.conf.178 automatic.conf.
181 ·············Installing·software·updates·is·a·fundamental·mitigation·against·the·exploitation179 ·············Installing·software·updates·is·a·fundamental·mitigation·against·the·exploitation
182 ·············of·publicly-known·vulnerabilities.·If·the·most·recent·security·patches·and180 ·············of·publicly-known·vulnerabilities.·If·the·most·recent·security·patches·and
183 Rationale:···updates·are·not·installed,·unauthorized·users·may·take·advantage·of·weaknesses·in181 Rationale:···updates·are·not·installed,·unauthorized·users·may·take·advantage·of·weaknesses·in
Offset 9399, 47 lines modifiedOffset 9399, 33 lines modified
9399 ··-·CCE-86596-49399 ··-·CCE-86596-4
9400 ··-·disable_strategy9400 ··-·disable_strategy
9401 ··-·low_complexity9401 ··-·low_complexity
9402 ··-·low_disruption9402 ··-·low_disruption
9403 ··-·medium_severity9403 ··-·medium_severity
9404 ··-·no_reboot_needed9404 ··-·no_reboot_needed
9405 ··-·package_kea_removed9405 ··-·package_kea_removed
9406 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
9407 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
9408 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
9409 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
9410 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable 
  
9411 dnf·remove·kea 
9412 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
9413 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
9414 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
9415 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
9416 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable 
  
9417 package·--remove=kea 
9418 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
9419 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
9420 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
9421 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
9422 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable 
  
9423 package·remove·kea 
9424 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x89406 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
9425 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low9407 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
9426 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low9408 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
9427 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false9409 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
9428 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable9410 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
9429 include·remove_kea9411 include·remove_kea
  
9430 class·remove_kea·{9412 class·remove_kea·{
9431 ··package·{·'kea':9413 ··package·{·'kea':
9432 ····ensure·=>·'purged',9414 ····ensure·=>·'purged',
Max diff block lines reached; 13938/18691 bytes (74.57%) of diff not shown.
1.63 MB
./usr/share/doc/ssg-nondebian/ssg-rhel10-guide-cis.html
    
Offset 15215, 207 lines modifiedOffset 15215, 207 lines modified
0003b6e0:·612d·7461·7267·6574·3d22·2369·646d·3733··a-target="#idm730003b6e0:·612d·7461·7267·6574·3d22·2369·646d·3733··a-target="#idm73
0003b6f0:·3038·2220·7461·6269·6e64·6578·3d22·3022··08"·tabindex="0"0003b6f0:·3038·2220·7461·6269·6e64·6578·3d22·3022··08"·tabindex="0"
0003b700:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a0003b700:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
0003b710:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa0003b710:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
0003b720:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti0003b720:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
0003b730:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·0003b730:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
0003b740:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi0003b740:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
 0003b750:·6174·696f·6e20·4f53·4275·696c·6420·426c··ation·OSBuild·Bl
 0003b760:·7565·7072·696e·7420·736e·6970·7065·7420··ueprint·snippet·
 0003b770:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·
 0003b780:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col
 0003b790:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·
 0003b7a0:·6964·3d22·6964·6d37·3330·3822·3e3c·7072··id="idm7308"><pr
 0003b7b0:·653e·3c63·6f64·653e·0a5b·5b70·6163·6b61··e><code>.[[packa
 0003b7c0:·6765·735d·5d0a·6e61·6d65·203d·2022·6169··ges]].name·=·"ai
 0003b7d0:·6465·220a·7665·7273·696f·6e20·3d20·222a··de".version·=·"*
0003b750:·6174·696f·6e20·7363·7269·7074·20e2·87b2··ation·script·... 
0003b760:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla 
0003b770:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap 
0003b780:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id= 
0003b790:·2269·646d·3733·3038·223e·3c74·6162·6c65··"idm7308"><table 
0003b7a0:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta 
0003b7b0:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl 
0003b7c0:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table 
0003b7d0:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr> 
0003b7e0:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:< 
0003b7f0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td> 
0003b800:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis 
0003b810:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td 
0003b820:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t 
0003b830:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t 
0003b840:·683e·3c74·643e·6661·6c73·653c·2f74·643e··h><td>false</td> 
0003b850:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str 
0003b860:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e 
0003b870:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr>< 
0003b880:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod 
0003b890:·653e·0a64·6e66·2069·6e73·7461·6c6c·2061··e>.dnf·install·a 
0003b8a0:·6964·650a·3c2f·636f·6465·3e3c·2f70·7265··ide.</code></pre0003b7e0:·220a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··".</code></pre><
0003b8b0:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class=0003b7f0:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b
0003b8c0:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success0003b800:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"·
0003b8d0:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c0003b810:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col
0003b8e0:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta0003b820:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ
0003b8f0:·7267·6574·3d22·2369·646d·3733·3039·2220··rget="#idm7309"·0003b830:·6574·3d22·2369·646d·3733·3039·2220·7461··et="#idm7309"·ta
0003b900:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol0003b840:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
0003b910:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-0003b850:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
0003b920:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"0003b860:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
0003b930:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate0003b870:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
0003b940:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href0003b880:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
0003b950:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio0003b890:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
0003b960:·6e20·416e·6163·6f6e·6461·2073·6e69·7070··n·Anaconda·snipp0003b8a0:·5075·7070·6574·2073·6e69·7070·6574·20e2··Puppet·snippet·.
0003b970:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d0003b8b0:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c
0003b980:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-0003b8c0:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
0003b990:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps0003b8d0:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
0003b9a0:·6522·2069·643d·2269·646d·3733·3039·223e··e"·id="idm7309">0003b8e0:·643d·2269·646d·3733·3039·223e·3c74·6162··d="idm7309"><tab
0003b9b0:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta0003b8f0:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·
0003b9c0:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe0003b900:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta
0003b9d0:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered0003b910:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab
0003b9e0:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed0003b920:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t
0003b9f0:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple0003b930:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity
0003ba00:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo0003b940:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
 0003b950:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D
 0003b960:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><
 0003b970:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
 0003b980:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:<
 0003b990:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t
0003ba10:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><0003b9a0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S
0003ba20:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</0003b9b0:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td
 0003b9c0:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr
 0003b9d0:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c
 0003b9e0:·6f64·653e·696e·636c·7564·6520·696e·7374··ode>include·inst
 0003b9f0:·616c·6c5f·6169·6465·0a0a·636c·6173·7320··all_aide..class·
 0003ba00:·696e·7374·616c·6c5f·6169·6465·207b·0a20··install_aide·{.·
 0003ba10:·2070·6163·6b61·6765·207b·2027·6169·6465···package·{·'aide
 0003ba20:·273a·0a20·2020·2065·6e73·7572·6520·3d26··':.····ensure·=&
 0003ba30:·6774·3b20·2769·6e73·7461·6c6c·6564·272c··gt;·'installed',
 0003ba40:·0a20·207d·0a7d·0a3c·2f63·6f64·653e·3c2f··.··}.}.</code></
 0003ba50:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla
 0003ba60:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ
 0003ba70:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle
 0003ba80:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data
 0003ba90:·2d74·6172·6765·743d·2223·6964·6d37·3331··-target="#idm731
 0003baa0:·3022·2074·6162·696e·6465·783d·2230·2220··0"·tabindex="0"·
 0003bab0:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar
 0003bac0:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal
 0003bad0:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ
 0003bae0:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h
 0003baf0:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia
 0003bb00:·7469·6f6e·2073·6372·6970·7420·e287·b23c··tion·script·...<
 0003bb10:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas
 0003bb20:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps
 0003bb30:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="
 0003bb40:·6964·6d37·3331·3022·3e3c·7461·626c·6520··idm7310"><table·
 0003bb50:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab
 0003bb60:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table
 0003bb70:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-
 0003bb80:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><
 0003bb90:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</
0003ba30:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><0003bba0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
0003ba40:·2f74·723e·3c74·723e·3c74·683e·5265·626f··/tr><tr><th>Rebo0003bbb0:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr
0003ba50:·6f74·3a3c·2f74·683e·3c74·643e·6661·6c73··ot:</th><td>fals0003bbc0:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>
0003ba60:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr><0003bbd0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
0003ba70:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th0003bbe0:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th
0003ba80:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td>0003bbf0:·3e3c·7464·3e66·616c·7365·3c2f·7464·3e3c··><td>false</td><
0003ba90:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr 
0003baa0:·653e·3c63·6f64·653e·0a70·6163·6b61·6765··e><code>.package 
0003bab0:·202d·2d61·6464·3d61·6964·650a·3c2f·636f···--add=aide.</co 
0003bac0:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div>< 
0003bad0:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn 
0003bae0:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t 
0003baf0:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse" 
0003bb00:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i 
0003bb10:·646d·3733·3130·2220·7461·6269·6e64·6578··dm7310"·tabindex 
0003bb20:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto 
0003bb30:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded 
0003bb40:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title=" 
0003bb50:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve 
0003bb60:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re 
0003bb70:·6d65·6469·6174·696f·6e20·4f53·4275·696c··mediation·OSBuil 
0003bb80:·6420·426c·7565·7072·696e·7420·736e·6970··d·Blueprint·snip0003bc00:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra
 0003bc10:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en
 0003bc20:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></
 0003bc30:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code
 0003bc40:·3e0a·7061·636b·6167·6520·696e·7374·616c··>.package·instal
 0003bc50:·6c20·6169·6465·0a3c·2f63·6f64·653e·3c2f··l·aide.</code></
 0003bc60:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla
 0003bc70:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ
 0003bc80:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle
Max diff block lines reached; 1509082/1536296 bytes (98.23%) of diff not shown.
173 KB
html2text {}
    
Offset 147, 52 lines modifiedOffset 147, 38 lines modified
147 ··-·PCI-DSSv4-11.5.2147 ··-·PCI-DSSv4-11.5.2
148 ··-·enable_strategy148 ··-·enable_strategy
149 ··-·low_complexity149 ··-·low_complexity
150 ··-·low_disruption150 ··-·low_disruption
151 ··-·medium_severity151 ··-·medium_severity
152 ··-·no_reboot_needed152 ··-·no_reboot_needed
153 ··-·package_aide_installed153 ··-·package_aide_installed
154 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
155 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
156 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
157 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
158 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
159 dnf·install·aide 
160 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
161 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
162 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
163 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
164 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
165 package·--add=aide 
166 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8154 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
167 [[packages]]155 [[packages]]
168 name·=·"aide"156 name·=·"aide"
169 version·=·"*"157 version·=·"*"
170 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
171 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
172 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
173 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
174 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
175 package·install·aide 
176 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8158 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
177 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low159 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
178 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low160 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
179 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false161 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
180 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable162 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
181 include·install_aide163 include·install_aide
  
182 class·install_aide·{164 class·install_aide·{
183 ··package·{·'aide':165 ··package·{·'aide':
184 ····ensure·=>·'installed',166 ····ensure·=>·'installed',
185 ··}167 ··}
186 }168 }
 169 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 170 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 171 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 172 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 173 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 174 package·install·aide
187 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8175 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
188 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low176 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
189 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low177 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
190 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false178 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
191 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable179 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
192 #·Remediation·is·applicable·only·in·certain·platforms180 #·Remediation·is·applicable·only·in·certain·platforms
193 if·rpm·--quiet·-q·kernel;·then181 if·rpm·--quiet·-q·kernel;·then
Offset 200, 14 lines modifiedOffset 186, 28 lines modified
200 if·!·rpm·-q·--quiet·"aide"·;·then186 if·!·rpm·-q·--quiet·"aide"·;·then
201 ····dnf·install·-y·"aide"187 ····dnf·install·-y·"aide"
202 fi188 fi
  
203 else189 else
204 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'190 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
205 fi191 fi
 192 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 193 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 194 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 195 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 196 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 197 package·--add=aide
 198 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 199 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 200 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 201 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 202 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 203 dnf·install·aide
206 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*204 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
207 Run·the·following·command·to·generate·a·new·database:205 Run·the·following·command·to·generate·a·new·database:
208 $·sudo·/usr/sbin/aide·--init206 $·sudo·/usr/sbin/aide·--init
209 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:207 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
210 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz208 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
211 To·initiate·a·manual·check,·run·the·following·command:209 To·initiate·a·manual·check,·run·the·following·command:
212 $·sudo·/usr/sbin/aide·--check210 $·sudo·/usr/sbin/aide·--check
Offset 900, 29 lines modifiedOffset 900, 29 lines modified
900 ·············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.5,·SR·3.8,·SR·4.1,·SR·4.3,·SR·5.1,·SR·5.2,·SR·5.3,·SR·7.1,·SR·7.6900 ·············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.5,·SR·3.8,·SR·4.1,·SR·4.3,·SR·5.1,·SR·5.2,·SR·5.3,·SR·7.1,·SR·7.6
901 References:··_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.3901 References:··_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.3
902 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)902 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)
903 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4903 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4
904 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227904 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
905 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R28905 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R28
906 ·············_\x8c_\x8i_\x8s············1.1.2.3.1906 ·············_\x8c_\x8i_\x8s············1.1.2.3.1
907 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
908 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
909 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high 
910 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
911 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
912 part·/home 
913 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8907 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
914 [[customizations.filesystem]]908 [[customizations.filesystem]]
915 mountpoint·=·"/home"909 mountpoint·=·"/home"
916 size·=·1073741824910 size·=·1073741824
917 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8911 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
918 logvol·/home·1024912 logvol·/home·1024
 913 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 914 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 915 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high
 916 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 917 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 918 part·/home
919 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/t\x8tm\x8mp\x8p·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*919 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/t\x8tm\x8mp\x8p·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
920 The·/tmp·directory·is·a·world-writable·directory·used·for·temporary·file·storage.·Ensure·it·has·its·own·partition·or·logical·volume·at·installation·time,·or·migrate·it·using·LVM.920 The·/tmp·directory·is·a·world-writable·directory·used·for·temporary·file·storage.·Ensure·it·has·its·own·partition·or·logical·volume·at·installation·time,·or·migrate·it·using·LVM.
921 Rationale:···The·/tmp·partition·is·used·as·temporary·storage·by·many·programs.·Placing·/tmp·in·its·own·partition·enables·the·setting·of·more·restrictive·mount·options,·which·can·help·protect·programs·which·use·it.921 Rationale:···The·/tmp·partition·is·used·as·temporary·storage·by·many·programs.·Placing·/tmp·in·its·own·partition·enables·the·setting·of·more·restrictive·mount·options,·which·can·help·protect·programs·which·use·it.
922 Severity: ···low922 Severity: ···low
923 Rule·ID:·····xccdf_org.ssgproject.content_rule_partition_for_tmp923 Rule·ID:·····xccdf_org.ssgproject.content_rule_partition_for_tmp
924 Identifiers:·CCE-89606-8924 Identifiers:·CCE-89606-8
925 ·············_\x8c_\x8i_\x8s_\x8-_\x8c_\x8s_\x8c········12,·15,·8925 ·············_\x8c_\x8i_\x8s_\x8-_\x8c_\x8s_\x8c········12,·15,·8
Offset 930, 29 lines modifiedOffset 930, 29 lines modified
930 ·············_\x8d_\x8i_\x8s_\x8a···········CCI-000366930 ·············_\x8d_\x8i_\x8s_\x8a···········CCI-000366
Max diff block lines reached; 171108/176716 bytes (96.83%) of diff not shown.
1.45 MB
./usr/share/doc/ssg-nondebian/ssg-rhel10-guide-cis_server_l1.html
    
Offset 15177, 207 lines modifiedOffset 15177, 207 lines modified
0003b480:·6765·743d·2223·6964·6d37·3330·3822·2074··get="#idm7308"·t0003b480:·6765·743d·2223·6964·6d37·3330·3822·2074··get="#idm7308"·t
0003b490:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role0003b490:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
0003b4a0:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e0003b4a0:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
0003b4b0:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·0003b4b0:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
0003b4c0:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·0003b4c0:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
0003b4d0:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=0003b4d0:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
0003b4e0:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation0003b4e0:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
 0003b4f0:·204f·5342·7569·6c64·2042·6c75·6570·7269···OSBuild·Bluepri
 0003b500:·6e74·2073·6e69·7070·6574·20e2·87b2·3c2f··nt·snippet·...</
 0003b510:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
 0003b520:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
 0003b530:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
 0003b540:·646d·3733·3038·223e·3c70·7265·3e3c·636f··dm7308"><pre><co
 0003b550:·6465·3e0a·5b5b·7061·636b·6167·6573·5d5d··de>.[[packages]]
 0003b560:·0a6e·616d·6520·3d20·2261·6964·6522·0a76··.name·=·"aide".v
 0003b570:·6572·7369·6f6e·203d·2022·2a22·0a3c·2f63··ersion·=·"*".</c
0003b4f0:·2073·6372·6970·7420·e287·b23c·2f61·3e3c···script·...</a>< 
0003b500:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p 
0003b510:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co 
0003b520:·6c6c·6170·7365·2220·6964·3d22·6964·6d37··llapse"·id="idm7 
0003b530:·3330·3822·3e3c·7461·626c·6520·636c·6173··308"><table·clas 
0003b540:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s 
0003b550:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor 
0003b560:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond 
0003b570:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C 
0003b580:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th>< 
0003b590:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
0003b5a0:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti 
0003b5b0:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low< 
0003b5c0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0003b5d0:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td 
0003b5e0:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr> 
0003b5f0:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy 
0003b600:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable 
0003b610:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl 
0003b620:·653e·3c70·7265·3e3c·636f·6465·3e0a·646e··e><pre><code>.dn 
0003b630:·6620·696e·7374·616c·6c20·6169·6465·0a3c··f·install·aide.< 
0003b640:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di0003b580:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div>
0003b650:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn·0003b590:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt
0003b660:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat0003b5a0:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data-
0003b670:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap0003b5b0:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse
0003b680:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=0003b5c0:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
0003b690:·2223·6964·6d37·3330·3922·2074·6162·696e··"#idm7309"·tabin0003b5d0:·6964·6d37·3330·3922·2074·6162·696e·6465··idm7309"·tabinde
0003b6a0:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu0003b5e0:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt
0003b6b0:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan0003b5f0:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande
0003b6c0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl0003b600:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=
0003b6d0:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r0003b610:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev
0003b6e0:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"0003b620:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R
0003b6f0:·3e52·656d·6564·6961·7469·6f6e·2041·6e61··>Remediation·Ana0003b630:·656d·6564·6961·7469·6f6e·2050·7570·7065··emediation·Puppe
0003b700:·636f·6e64·6120·736e·6970·7065·7420·e287··conda·snippet·..0003b640:·7420·736e·6970·7065·7420·e287·b23c·2f61··t·snippet·...</a
0003b710:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl0003b650:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
0003b720:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla0003b660:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
0003b730:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id0003b670:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
0003b740:·3d22·6964·6d37·3330·3922·3e3c·7461·626c··="idm7309"><tabl0003b680:·6d37·3330·3922·3e3c·7461·626c·6520·636c··m7309"><table·cl
0003b750:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t0003b690:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table
0003b760:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab0003b6a0:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b
0003b770:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl0003b6b0:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co
0003b780:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr0003b6c0:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th
0003b790:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:0003b6d0:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th
0003b7a0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td0003b6e0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
0003b7b0:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di0003b6f0:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup
0003b7c0:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t0003b700:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo
0003b7d0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><0003b710:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
0003b7e0:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</0003b720:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th><
0003b7f0:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td0003b730:·7464·3e66·616c·7365·3c2f·7464·3e3c·2f74··td>false</td></t
0003b800:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St0003b740:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate
0003b810:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>0003b750:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab
0003b820:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr> 
0003b830:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co 
0003b840:·6465·3e0a·7061·636b·6167·6520·2d2d·6164··de>.package·--ad 
0003b850:·643d·6169·6465·0a3c·2f63·6f64·653e·3c2f··d=aide.</code></ 
0003b860:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla 
0003b870:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ 
0003b880:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle 
0003b890:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data 
0003b8a0:·2d74·6172·6765·743d·2223·6964·6d37·3331··-target="#idm731 
0003b8b0:·3022·2074·6162·696e·6465·783d·2230·2220··0"·tabindex="0"· 
0003b8c0:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar 
0003b8d0:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal 
0003b8e0:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ 
0003b8f0:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h 
0003b900:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia 
0003b910:·7469·6f6e·204f·5342·7569·6c64·2042·6c75··tion·OSBuild·Blu 
0003b920:·6570·7269·6e74·2073·6e69·7070·6574·20e2··eprint·snippet·. 
0003b930:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c 
0003b940:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll 
0003b950:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i 
0003b960:·643d·2269·646d·3733·3130·223e·3c70·7265··d="idm7310"><pre 
0003b970:·3e3c·636f·6465·3e0a·5b5b·7061·636b·6167··><code>.[[packag 
0003b980:·6573·5d5d·0a6e·616d·6520·3d20·2261·6964··es]].name·=·"aid 
0003b990:·6522·0a76·6572·7369·6f6e·203d·2022·2a22··e".version·=·"*" 
0003b9a0:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></ 
0003b9b0:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt 
0003b9c0:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d 
0003b9d0:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll 
0003b9e0:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe 
0003b9f0:·743d·2223·6964·6d37·3331·3122·2074·6162··t="#idm7311"·tab 
0003ba00:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role=" 
0003ba10:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp 
0003ba20:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti 
0003ba30:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to 
0003ba40:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="# 
0003ba50:·2122·3e52·656d·6564·6961·7469·6f6e·2073··!">Remediation·s 
0003ba60:·6372·6970·7420·e287·b23c·2f61·3e3c·6272··cript·...</a><br 
0003ba70:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan 
0003ba80:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll 
0003ba90:·6170·7365·2220·6964·3d22·6964·6d37·3331··apse"·id="idm731 
0003baa0:·3122·3e3c·7461·626c·6520·636c·6173·733d··1"><table·class= 
0003bab0:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str 
0003bac0:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde 
0003bad0:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden 
0003bae0:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com 
0003baf0:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td 
0003bb00:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t 
0003bb10:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption 
0003bb20:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t 
0003bb30:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e52··d></tr><tr><th>R 
0003bb40:·6562·6f6f·743a·3c2f·7468·3e3c·7464·3e66··eboot:</th><td>f 
0003bb50:·616c·7365·3c2f·7464·3e3c·2f74·723e·3c74··alse</td></tr><t0003b760:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta
0003bb60:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:< 
0003bb70:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</ 
0003bb80:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table> 
0003bb90:·3c70·7265·3e3c·636f·6465·3e0a·7061·636b··<pre><code>.pack 
0003bba0:·6167·6520·696e·7374·616c·6c20·6169·6465··age·install·aide 
0003bbb0:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></0003b770:·626c·653e·3c70·7265·3e3c·636f·6465·3e69··ble><pre><code>i
 0003b780:·6e63·6c75·6465·2069·6e73·7461·6c6c·5f61··nclude·install_a
 0003b790:·6964·650a·0a63·6c61·7373·2069·6e73·7461··ide..class·insta
Max diff block lines reached; 1338926/1366140 bytes (98.01%) of diff not shown.
146 KB
html2text {}
    
Offset 141, 52 lines modifiedOffset 141, 38 lines modified
141 ··-·PCI-DSSv4-11.5.2141 ··-·PCI-DSSv4-11.5.2
142 ··-·enable_strategy142 ··-·enable_strategy
143 ··-·low_complexity143 ··-·low_complexity
144 ··-·low_disruption144 ··-·low_disruption
145 ··-·medium_severity145 ··-·medium_severity
146 ··-·no_reboot_needed146 ··-·no_reboot_needed
147 ··-·package_aide_installed147 ··-·package_aide_installed
148 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
149 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
150 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
151 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
152 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
153 dnf·install·aide 
154 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
155 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
156 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
157 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
158 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
159 package·--add=aide 
160 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8148 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
161 [[packages]]149 [[packages]]
162 name·=·"aide"150 name·=·"aide"
163 version·=·"*"151 version·=·"*"
164 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
165 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
166 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
167 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
168 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
169 package·install·aide 
170 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8152 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
171 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low153 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
172 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low154 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
173 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false155 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
174 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable156 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
175 include·install_aide157 include·install_aide
  
176 class·install_aide·{158 class·install_aide·{
177 ··package·{·'aide':159 ··package·{·'aide':
178 ····ensure·=>·'installed',160 ····ensure·=>·'installed',
179 ··}161 ··}
180 }162 }
 163 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 164 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 165 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 166 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 167 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 168 package·install·aide
181 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8169 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
182 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low170 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
183 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low171 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
184 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false172 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
185 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable173 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
186 #·Remediation·is·applicable·only·in·certain·platforms174 #·Remediation·is·applicable·only·in·certain·platforms
187 if·rpm·--quiet·-q·kernel;·then175 if·rpm·--quiet·-q·kernel;·then
Offset 194, 14 lines modifiedOffset 180, 28 lines modified
194 if·!·rpm·-q·--quiet·"aide"·;·then180 if·!·rpm·-q·--quiet·"aide"·;·then
195 ····dnf·install·-y·"aide"181 ····dnf·install·-y·"aide"
196 fi182 fi
  
197 else183 else
198 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'184 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
199 fi185 fi
 186 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 187 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 188 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 189 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 190 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 191 package·--add=aide
 192 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 193 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 194 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 195 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 196 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 197 dnf·install·aide
200 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*198 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
201 Run·the·following·command·to·generate·a·new·database:199 Run·the·following·command·to·generate·a·new·database:
202 $·sudo·/usr/sbin/aide·--init200 $·sudo·/usr/sbin/aide·--init
203 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:201 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
204 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz202 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
205 To·initiate·a·manual·check,·run·the·following·command:203 To·initiate·a·manual·check,·run·the·following·command:
206 $·sudo·/usr/sbin/aide·--check204 $·sudo·/usr/sbin/aide·--check
Offset 893, 29 lines modifiedOffset 893, 29 lines modified
893 ·············_\x8d_\x8i_\x8s_\x8a···········CCI-000366893 ·············_\x8d_\x8i_\x8s_\x8a···········CCI-000366
894 ·············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.5,·SR·3.8,·SR·4.1,·SR·4.3,·SR·5.1,·SR·5.2,·SR·5.3,·SR·7.1,·SR·7.6894 ·············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.5,·SR·3.8,·SR·4.1,·SR·4.3,·SR·5.1,·SR·5.2,·SR·5.3,·SR·7.1,·SR·7.6
895 References:··_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.3895 References:··_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.3
896 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)896 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)
897 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4897 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4
898 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227898 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
899 ·············_\x8c_\x8i_\x8s············1.1.2.1.1899 ·············_\x8c_\x8i_\x8s············1.1.2.1.1
900 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
901 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
902 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high 
903 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
904 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
905 part·/tmp 
906 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8900 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
907 [[customizations.filesystem]]901 [[customizations.filesystem]]
908 mountpoint·=·"/tmp"902 mountpoint·=·"/tmp"
909 size·=·1073741824903 size·=·1073741824
910 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8904 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
911 logvol·/tmp·1024905 logvol·/tmp·1024
 906 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 907 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 908 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high
 909 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 910 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 911 part·/tmp
912 Group  ·GNOME·Desktop·Environment·  Group·contains·3·groups·and·9·rules912 Group  ·GNOME·Desktop·Environment·  Group·contains·3·groups·and·9·rules
913 _\x8[_\x8r_\x8e_\x8f_\x8]  ·GNOME·is·a·graphical·desktop·environment·bundled·with·many·Linux·distributions·that·allow·users·to·easily·interact·with·the·operating·system·graphically·rather·than·textually.·The·GNOME·Graphical·Display·Manager·(GDM)·provides·login,·logout,·and·user·switching·contexts·as·well·as·display·server·management.913 _\x8[_\x8r_\x8e_\x8f_\x8]  ·GNOME·is·a·graphical·desktop·environment·bundled·with·many·Linux·distributions·that·allow·users·to·easily·interact·with·the·operating·system·graphically·rather·than·textually.·The·GNOME·Graphical·Display·Manager·(GDM)·provides·login,·logout,·and·user·switching·contexts·as·well·as·display·server·management.
  
914 GNOME·is·developed·by·the·GNOME·Project·and·is·considered·the·default·Red·Hat·Graphical·environment.914 GNOME·is·developed·by·the·GNOME·Project·and·is·considered·the·default·Red·Hat·Graphical·environment.
  
915 For·more·information·on·GNOME·and·the·GNOME·Project,·see·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8w\x8w_\x8w\x8w_\x8w\x8w_\x8.\x8._\x8g\x8g_\x8n\x8n_\x8o\x8o_\x8m\x8m_\x8e\x8e_\x8.\x8._\x8o\x8o_\x8r\x8r_\x8g\x8g.915 For·more·information·on·GNOME·and·the·GNOME·Project,·see·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8w\x8w_\x8w\x8w_\x8w\x8w_\x8.\x8._\x8g\x8g_\x8n\x8n_\x8o\x8o_\x8m\x8m_\x8e\x8e_\x8.\x8._\x8o\x8o_\x8r\x8r_\x8g\x8g.
916 Group  ·Configure·GNOME·Login·Screen·  Group·contains·1·rule916 Group  ·Configure·GNOME·Login·Screen·  Group·contains·1·rule
Offset 2210, 52 lines modifiedOffset 2210, 38 lines modified
2210 ··-·PCI-DSSv4-2.2.62210 ··-·PCI-DSSv4-2.2.6
Max diff block lines reached; 144445/149903 bytes (96.36%) of diff not shown.
1.34 MB
./usr/share/doc/ssg-nondebian/ssg-rhel10-guide-cis_workstation_l1.html
    
Offset 15168, 207 lines modifiedOffset 15168, 207 lines modified
0003b3f0:·7267·6574·3d22·2369·646d·3733·3038·2220··rget="#idm7308"·0003b3f0:·7267·6574·3d22·2369·646d·3733·3038·2220··rget="#idm7308"·
0003b400:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol0003b400:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol
0003b410:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-0003b410:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-
0003b420:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"0003b420:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"
0003b430:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate0003b430:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate
0003b440:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href0003b440:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href
0003b450:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio0003b450:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio
 0003b460:·6e20·4f53·4275·696c·6420·426c·7565·7072··n·OSBuild·Bluepr
 0003b470:·696e·7420·736e·6970·7065·7420·e287·b23c··int·snippet·...<
 0003b480:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas
 0003b490:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps
 0003b4a0:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="
 0003b4b0:·6964·6d37·3330·3822·3e3c·7072·653e·3c63··idm7308"><pre><c
 0003b4c0:·6f64·653e·0a5b·5b70·6163·6b61·6765·735d··ode>.[[packages]
 0003b4d0:·5d0a·6e61·6d65·203d·2022·6169·6465·220a··].name·=·"aide".
 0003b4e0:·7665·7273·696f·6e20·3d20·222a·220a·3c2f··version·=·"*".</
0003b460:·6e20·7363·7269·7074·20e2·87b2·3c2f·613e··n·script·...</a> 
0003b470:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class=" 
0003b480:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c 
0003b490:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm 
0003b4a0:·3733·3038·223e·3c74·6162·6c65·2063·6c61··7308"><table·cla 
0003b4b0:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table- 
0003b4c0:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo 
0003b4d0:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con 
0003b4e0:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th> 
0003b4f0:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th> 
0003b500:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
0003b510:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt 
0003b520:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low 
0003b530:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
0003b540:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t 
0003b550:·643e·6661·6c73·653c·2f74·643e·3c2f·7472··d>false</td></tr 
0003b560:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg 
0003b570:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl 
0003b580:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab 
0003b590:·6c65·3e3c·7072·653e·3c63·6f64·653e·0a64··le><pre><code>.d 
0003b5a0:·6e66·2069·6e73·7461·6c6c·2061·6964·650a··nf·install·aide. 
0003b5b0:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d0003b4f0:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div
0003b5c0:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn0003b500:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b
0003b5d0:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da0003b510:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data
0003b5e0:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla0003b520:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps
0003b5f0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target0003b530:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
0003b600:·3d22·2369·646d·3733·3039·2220·7461·6269··="#idm7309"·tabi0003b540:·2369·646d·3733·3039·2220·7461·6269·6e64··#idm7309"·tabind
0003b610:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b0003b550:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
0003b620:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa0003b560:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
0003b630:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit0003b570:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
0003b640:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·0003b580:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
0003b650:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!0003b590:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
0003b660:·223e·5265·6d65·6469·6174·696f·6e20·416e··">Remediation·An0003b5a0:·5265·6d65·6469·6174·696f·6e20·5075·7070··Remediation·Pupp
0003b670:·6163·6f6e·6461·2073·6e69·7070·6574·20e2··aconda·snippet·.0003b5b0:·6574·2073·6e69·7070·6574·20e2·87b2·3c2f··et·snippet·...</
0003b680:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c0003b5c0:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
0003b690:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll0003b5d0:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
0003b6a0:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i0003b5e0:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
0003b6b0:·643d·2269·646d·3733·3039·223e·3c74·6162··d="idm7309"><tab0003b5f0:·646d·3733·3039·223e·3c74·6162·6c65·2063··dm7309"><table·c
0003b6c0:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·0003b600:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl
0003b6d0:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta0003b610:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-
0003b6e0:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab0003b620:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c
0003b6f0:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t0003b630:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t
0003b700:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity 
0003b710:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t 
0003b720:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D 
0003b730:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th>< 
0003b740:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
0003b750:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:< 
0003b760:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t 
0003b770:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S 
0003b780:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td 
0003b790:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr 
0003b7a0:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c 
0003b7b0:·6f64·653e·0a70·6163·6b61·6765·202d·2d61··ode>.package·--a 
0003b7c0:·6464·3d61·6964·650a·3c2f·636f·6465·3e3c··dd=aide.</code>< 
0003b7d0:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl 
0003b7e0:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc 
0003b7f0:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl 
0003b800:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat 
0003b810:·612d·7461·7267·6574·3d22·2369·646d·3733··a-target="#idm73 
0003b820:·3130·2220·7461·6269·6e64·6578·3d22·3022··10"·tabindex="0" 
0003b830:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a 
0003b840:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa 
0003b850:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti 
0003b860:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"· 
0003b870:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi 
0003b880:·6174·696f·6e20·4f53·4275·696c·6420·426c··ation·OSBuild·Bl 
0003b890:·7565·7072·696e·7420·736e·6970·7065·7420··ueprint·snippet· 
0003b8a0:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div· 
0003b8b0:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col 
0003b8c0:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"· 
0003b8d0:·6964·3d22·6964·6d37·3331·3022·3e3c·7072··id="idm7310"><pr 
0003b8e0:·653e·3c63·6f64·653e·0a5b·5b70·6163·6b61··e><code>.[[packa 
0003b8f0:·6765·735d·5d0a·6e61·6d65·203d·2022·6169··ges]].name·=·"ai 
0003b900:·6465·220a·7665·7273·696f·6e20·3d20·222a··de".version·=·"* 
0003b910:·220a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··".</code></pre>< 
0003b920:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b 
0003b930:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"· 
0003b940:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col 
0003b950:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ 
0003b960:·6574·3d22·2369·646d·3733·3131·2220·7461··et="#idm7311"·ta 
0003b970:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role= 
0003b980:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex 
0003b990:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t 
0003b9a0:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t 
0003b9b0:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href=" 
0003b9c0:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation· 
0003b9d0:·7363·7269·7074·20e2·87b2·3c2f·613e·3c62··script·...</a><b 
0003b9e0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa 
0003b9f0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col 
0003ba00:·6c61·7073·6522·2069·643d·2269·646d·3733··lapse"·id="idm73 
0003ba10:·3131·223e·3c74·6162·6c65·2063·6c61·7373··11"><table·class 
0003ba20:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st 
0003ba30:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord 
0003ba40:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde 
0003ba50:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co 
0003ba60:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t0003b640:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t
0003ba70:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><0003b650:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
0003ba80:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio0003b660:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru
0003ba90:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</0003b670:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l
0003baa0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>0003b680:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
0003bab0:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td>0003b690:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th>
 0003b6a0:·3c74·643e·6661·6c73·653c·2f74·643e·3c2f··<td>false</td></
 0003b6b0:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat
 0003b6c0:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena
0003bac0:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr><0003b6d0:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t
0003bad0:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy: 
0003bae0:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable< 
0003baf0:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table 
0003bb00:·3e3c·7072·653e·3c63·6f64·653e·0a70·6163··><pre><code>.pac0003b6e0:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>
0003bb10:·6b61·6765·2069·6e73·7461·6c6c·2061·6964··kage·install·aid 
Max diff block lines reached; 1243483/1270697 bytes (97.86%) of diff not shown.
134 KB
html2text {}
    
Offset 139, 52 lines modifiedOffset 139, 38 lines modified
139 ··-·PCI-DSSv4-11.5.2139 ··-·PCI-DSSv4-11.5.2
140 ··-·enable_strategy140 ··-·enable_strategy
141 ··-·low_complexity141 ··-·low_complexity
142 ··-·low_disruption142 ··-·low_disruption
143 ··-·medium_severity143 ··-·medium_severity
144 ··-·no_reboot_needed144 ··-·no_reboot_needed
145 ··-·package_aide_installed145 ··-·package_aide_installed
146 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
147 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
148 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
149 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
150 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
151 dnf·install·aide 
152 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
153 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
154 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
155 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
156 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
157 package·--add=aide 
158 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8146 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
159 [[packages]]147 [[packages]]
160 name·=·"aide"148 name·=·"aide"
161 version·=·"*"149 version·=·"*"
162 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
163 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
164 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
165 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
166 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
167 package·install·aide 
168 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8150 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
169 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low151 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
170 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low152 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
171 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false153 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
172 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable154 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
173 include·install_aide155 include·install_aide
  
174 class·install_aide·{156 class·install_aide·{
175 ··package·{·'aide':157 ··package·{·'aide':
176 ····ensure·=>·'installed',158 ····ensure·=>·'installed',
177 ··}159 ··}
178 }160 }
 161 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 162 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 163 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 164 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 165 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 166 package·install·aide
179 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8167 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
180 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low168 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
181 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low169 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
182 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false170 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
183 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable171 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
184 #·Remediation·is·applicable·only·in·certain·platforms172 #·Remediation·is·applicable·only·in·certain·platforms
185 if·rpm·--quiet·-q·kernel;·then173 if·rpm·--quiet·-q·kernel;·then
Offset 192, 14 lines modifiedOffset 178, 28 lines modified
192 if·!·rpm·-q·--quiet·"aide"·;·then178 if·!·rpm·-q·--quiet·"aide"·;·then
193 ····dnf·install·-y·"aide"179 ····dnf·install·-y·"aide"
194 fi180 fi
  
195 else181 else
196 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'182 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
197 fi183 fi
 184 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 185 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 186 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 187 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 188 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 189 package·--add=aide
 190 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 191 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 192 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 193 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 194 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 195 dnf·install·aide
198 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*196 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
199 Run·the·following·command·to·generate·a·new·database:197 Run·the·following·command·to·generate·a·new·database:
200 $·sudo·/usr/sbin/aide·--init198 $·sudo·/usr/sbin/aide·--init
201 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:199 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
202 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz200 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
203 To·initiate·a·manual·check,·run·the·following·command:201 To·initiate·a·manual·check,·run·the·following·command:
204 $·sudo·/usr/sbin/aide·--check202 $·sudo·/usr/sbin/aide·--check
Offset 891, 29 lines modifiedOffset 891, 29 lines modified
891 ·············_\x8d_\x8i_\x8s_\x8a···········CCI-000366891 ·············_\x8d_\x8i_\x8s_\x8a···········CCI-000366
892 ·············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.5,·SR·3.8,·SR·4.1,·SR·4.3,·SR·5.1,·SR·5.2,·SR·5.3,·SR·7.1,·SR·7.6892 ·············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.5,·SR·3.8,·SR·4.1,·SR·4.3,·SR·5.1,·SR·5.2,·SR·5.3,·SR·7.1,·SR·7.6
893 References:··_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.3893 References:··_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.3
894 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)894 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)
895 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4895 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4
896 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227896 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
897 ·············_\x8c_\x8i_\x8s············1.1.2.1.1897 ·············_\x8c_\x8i_\x8s············1.1.2.1.1
898 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
899 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
900 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high 
901 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
902 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
903 part·/tmp 
904 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8898 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
905 [[customizations.filesystem]]899 [[customizations.filesystem]]
906 mountpoint·=·"/tmp"900 mountpoint·=·"/tmp"
907 size·=·1073741824901 size·=·1073741824
908 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8902 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
909 logvol·/tmp·1024903 logvol·/tmp·1024
 904 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 905 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 906 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high
 907 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 908 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 909 part·/tmp
910 Group  ·GNOME·Desktop·Environment·  Group·contains·3·groups·and·7·rules910 Group  ·GNOME·Desktop·Environment·  Group·contains·3·groups·and·7·rules
911 _\x8[_\x8r_\x8e_\x8f_\x8]  ·GNOME·is·a·graphical·desktop·environment·bundled·with·many·Linux·distributions·that·allow·users·to·easily·interact·with·the·operating·system·graphically·rather·than·textually.·The·GNOME·Graphical·Display·Manager·(GDM)·provides·login,·logout,·and·user·switching·contexts·as·well·as·display·server·management.911 _\x8[_\x8r_\x8e_\x8f_\x8]  ·GNOME·is·a·graphical·desktop·environment·bundled·with·many·Linux·distributions·that·allow·users·to·easily·interact·with·the·operating·system·graphically·rather·than·textually.·The·GNOME·Graphical·Display·Manager·(GDM)·provides·login,·logout,·and·user·switching·contexts·as·well·as·display·server·management.
  
912 GNOME·is·developed·by·the·GNOME·Project·and·is·considered·the·default·Red·Hat·Graphical·environment.912 GNOME·is·developed·by·the·GNOME·Project·and·is·considered·the·default·Red·Hat·Graphical·environment.
  
913 For·more·information·on·GNOME·and·the·GNOME·Project,·see·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8w\x8w_\x8w\x8w_\x8w\x8w_\x8.\x8._\x8g\x8g_\x8n\x8n_\x8o\x8o_\x8m\x8m_\x8e\x8e_\x8.\x8._\x8o\x8o_\x8r\x8r_\x8g\x8g.913 For·more·information·on·GNOME·and·the·GNOME·Project,·see·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8w\x8w_\x8w\x8w_\x8w\x8w_\x8.\x8._\x8g\x8g_\x8n\x8n_\x8o\x8o_\x8m\x8m_\x8e\x8e_\x8.\x8._\x8o\x8o_\x8r\x8r_\x8g\x8g.
914 Group  ·Configure·GNOME·Login·Screen·  Group·contains·1·rule914 Group  ·Configure·GNOME·Login·Screen·  Group·contains·1·rule
Offset 1858, 52 lines modifiedOffset 1858, 38 lines modified
1858 ··-·PCI-DSSv4-2.2.61858 ··-·PCI-DSSv4-2.2.6
Max diff block lines reached; 131876/137334 bytes (96.03%) of diff not shown.
1.56 MB
./usr/share/doc/ssg-nondebian/ssg-rhel10-guide-cis_workstation_l2.html
    
Offset 15206, 208 lines modifiedOffset 15206, 208 lines modified
0003b650:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#0003b650:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
0003b660:·6964·6d37·3330·3822·2074·6162·696e·6465··idm7308"·tabinde0003b660:·6964·6d37·3330·3822·2074·6162·696e·6465··idm7308"·tabinde
0003b670:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt0003b670:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt
0003b680:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande0003b680:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande
0003b690:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=0003b690:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=
0003b6a0:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev0003b6a0:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev
0003b6b0:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R0003b6b0:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R
0003b6c0:·656d·6564·6961·7469·6f6e·2073·6372·6970··emediation·scrip0003b6c0:·656d·6564·6961·7469·6f6e·204f·5342·7569··emediation·OSBui
 0003b6d0:·6c64·2042·6c75·6570·7269·6e74·2073·6e69··ld·Blueprint·sni
 0003b6e0:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>
 0003b6f0:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
 0003b700:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
 0003b710:·7073·6522·2069·643d·2269·646d·3733·3038··pse"·id="idm7308
 0003b720:·223e·3c70·7265·3e3c·636f·6465·3e0a·5b5b··"><pre><code>.[[
 0003b730:·7061·636b·6167·6573·5d5d·0a6e·616d·6520··packages]].name·
 0003b740:·3d20·2261·6964·6522·0a76·6572·7369·6f6e··=·"aide".version
 0003b750:·203d·2022·2a22·0a3c·2f63·6f64·653e·3c2f···=·"*".</code></
0003b6d0:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di 
0003b6e0:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c 
0003b6f0:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse 
0003b700:·2220·6964·3d22·6964·6d37·3330·3822·3e3c··"·id="idm7308">< 
0003b710:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab 
0003b720:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped 
0003b730:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered· 
0003b740:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed" 
0003b750:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex 
0003b760:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low 
0003b770:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
0003b780:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t 
0003b790:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></ 
0003b7a0:·7472·3e3c·7472·3e3c·7468·3e52·6562·6f6f··tr><tr><th>Reboo 
0003b7b0:·743a·3c2f·7468·3e3c·7464·3e66·616c·7365··t:</th><td>false 
0003b7c0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
0003b7d0:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th> 
0003b7e0:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td>< 
0003b7f0:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre 
0003b800:·3e3c·636f·6465·3e0a·646e·6620·696e·7374··><code>.dnf·inst 
0003b810:·616c·6c20·6169·6465·0a3c·2f63·6f64·653e··all·aide.</code> 
0003b820:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c0003b760:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla
0003b830:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su0003b770:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ
0003b840:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg0003b780:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle
0003b850:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da0003b790:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data
0003b860:·7461·2d74·6172·6765·743d·2223·6964·6d37··ta-target="#idm70003b7a0:·2d74·6172·6765·743d·2223·6964·6d37·3330··-target="#idm730
0003b870:·3330·3922·2074·6162·696e·6465·783d·2230··309"·tabindex="00003b7b0:·3922·2074·6162·696e·6465·783d·2230·2220··9"·tabindex="0"·
0003b880:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·0003b7c0:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar
0003b890:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f0003b7d0:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal
0003b8a0:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act0003b7e0:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ
0003b8b0:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"0003b7f0:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h
0003b8c0:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed0003b800:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia
0003b8d0:·6961·7469·6f6e·2041·6e61·636f·6e64·6120··iation·Anaconda·0003b810:·7469·6f6e·2050·7570·7065·7420·736e·6970··tion·Puppet·snip
0003b8e0:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><0003b820:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br><
0003b8f0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p0003b830:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
0003b900:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co0003b840:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap
0003b910:·6c6c·6170·7365·2220·6964·3d22·6964·6d37··llapse"·id="idm70003b850:·7365·2220·6964·3d22·6964·6d37·3330·3922··se"·id="idm7309"
0003b920:·3330·3922·3e3c·7461·626c·6520·636c·6173··309"><table·clas0003b860:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t
0003b930:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s0003b870:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip
0003b940:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor0003b880:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere
0003b950:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond0003b890:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense
0003b960:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C0003b8a0:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl
0003b970:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><0003b8b0:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l
0003b980:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>0003b8c0:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
0003b990:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti0003b8d0:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:<
 0003b8e0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
 0003b8f0:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb
 0003b900:·6f6f·743a·3c2f·7468·3e3c·7464·3e66·616c··oot:</th><td>fal
 0003b910:·7365·3c2f·7464·3e3c·2f74·723e·3c74·723e··se</td></tr><tr>
 0003b920:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t
 0003b930:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td
 0003b940:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p
 0003b950:·7265·3e3c·636f·6465·3e69·6e63·6c75·6465··re><code>include
 0003b960:·2069·6e73·7461·6c6c·5f61·6964·650a·0a63···install_aide..c
 0003b970:·6c61·7373·2069·6e73·7461·6c6c·5f61·6964··lass·install_aid
 0003b980:·6520·7b0a·2020·7061·636b·6167·6520·7b20··e·{.··package·{·
 0003b990:·2761·6964·6527·3a0a·2020·2020·656e·7375··'aide':.····ensu
 0003b9a0:·7265·203d·2667·743b·2027·696e·7374·616c··re·=&gt;·'instal
 0003b9b0:·6c65·6427·2c0a·2020·7d0a·7d0a·3c2f·636f··led',.··}.}.</co
 0003b9c0:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div><
 0003b9d0:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn
 0003b9e0:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t
 0003b9f0:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse"
 0003ba00:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i
 0003ba10:·646d·3733·3130·2220·7461·6269·6e64·6578··dm7310"·tabindex
 0003ba20:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto
 0003ba30:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded
 0003ba40:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="
 0003ba50:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve
 0003ba60:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re
 0003ba70:·6d65·6469·6174·696f·6e20·7363·7269·7074··mediation·script
 0003ba80:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
 0003ba90:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
 0003baa0:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
 0003bab0:·2069·643d·2269·646d·3733·3130·223e·3c74···id="idm7310"><t
 0003bac0:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl
 0003bad0:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·
 0003bae0:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t
 0003baf0:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">
 0003bb00:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi
0003b9a0:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<0003bb10:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<
0003b9b0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th0003bb20:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
0003b9c0:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td 
0003b9d0:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr> 
0003b9e0:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy0003bb30:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th
 0003bb40:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
 0003bb50:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot
0003b9f0:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable0003bb60:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false<
0003ba00:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl 
0003ba10:·653e·3c70·7265·3e3c·636f·6465·3e0a·7061··e><pre><code>.pa 
0003ba20:·636b·6167·6520·2d2d·6164·643d·6169·6465··ckage·--add=aide 
0003ba30:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></ 
0003ba40:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt 
0003ba50:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d 
0003ba60:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll 
0003ba70:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe 
0003ba80:·743d·2223·6964·6d37·3331·3022·2074·6162··t="#idm7310"·tab 
0003ba90:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role=" 
0003baa0:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp 
0003bab0:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti 
0003bac0:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to 
0003bad0:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="# 
0003bae0:·2122·3e52·656d·6564·6961·7469·6f6e·204f··!">Remediation·O 
0003baf0:·5342·7569·6c64·2042·6c75·6570·7269·6e74··SBuild·Blueprint0003bb70:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 0003bb80:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><
 0003bb90:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></
 0003bba0:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>
 0003bbb0:·3c63·6f64·653e·0a70·6163·6b61·6765·2069··<code>.package·i
 0003bbc0:·6e73·7461·6c6c·2061·6964·650a·3c2f·636f··nstall·aide.</co
 0003bbd0:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div><
Max diff block lines reached; 1438614/1465966 bytes (98.13%) of diff not shown.
164 KB
html2text {}
    
Offset 145, 52 lines modifiedOffset 145, 38 lines modified
145 ··-·PCI-DSSv4-11.5.2145 ··-·PCI-DSSv4-11.5.2
146 ··-·enable_strategy146 ··-·enable_strategy
147 ··-·low_complexity147 ··-·low_complexity
148 ··-·low_disruption148 ··-·low_disruption
149 ··-·medium_severity149 ··-·medium_severity
150 ··-·no_reboot_needed150 ··-·no_reboot_needed
151 ··-·package_aide_installed151 ··-·package_aide_installed
152 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
153 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
154 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
155 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
156 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
157 dnf·install·aide 
158 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
159 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
160 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
161 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
162 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
163 package·--add=aide 
164 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8152 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
165 [[packages]]153 [[packages]]
166 name·=·"aide"154 name·=·"aide"
167 version·=·"*"155 version·=·"*"
168 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
169 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
170 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
171 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
172 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
173 package·install·aide 
174 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8156 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
175 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low157 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
176 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low158 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
177 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false159 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
178 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable160 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
179 include·install_aide161 include·install_aide
  
180 class·install_aide·{162 class·install_aide·{
181 ··package·{·'aide':163 ··package·{·'aide':
182 ····ensure·=>·'installed',164 ····ensure·=>·'installed',
183 ··}165 ··}
184 }166 }
 167 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 168 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 169 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 170 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 171 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 172 package·install·aide
185 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8173 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
186 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low174 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
187 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low175 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
188 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false176 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
189 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable177 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
190 #·Remediation·is·applicable·only·in·certain·platforms178 #·Remediation·is·applicable·only·in·certain·platforms
191 if·rpm·--quiet·-q·kernel;·then179 if·rpm·--quiet·-q·kernel;·then
Offset 198, 14 lines modifiedOffset 184, 28 lines modified
198 if·!·rpm·-q·--quiet·"aide"·;·then184 if·!·rpm·-q·--quiet·"aide"·;·then
199 ····dnf·install·-y·"aide"185 ····dnf·install·-y·"aide"
200 fi186 fi
  
201 else187 else
202 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'188 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
203 fi189 fi
 190 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 191 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 192 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 193 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 194 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 195 package·--add=aide
 196 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 197 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 198 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 199 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 200 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 201 dnf·install·aide
204 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*202 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
205 Run·the·following·command·to·generate·a·new·database:203 Run·the·following·command·to·generate·a·new·database:
206 $·sudo·/usr/sbin/aide·--init204 $·sudo·/usr/sbin/aide·--init
207 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:205 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
208 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz206 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
209 To·initiate·a·manual·check,·run·the·following·command:207 To·initiate·a·manual·check,·run·the·following·command:
210 $·sudo·/usr/sbin/aide·--check208 $·sudo·/usr/sbin/aide·--check
Offset 898, 29 lines modifiedOffset 898, 29 lines modified
898 ·············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.5,·SR·3.8,·SR·4.1,·SR·4.3,·SR·5.1,·SR·5.2,·SR·5.3,·SR·7.1,·SR·7.6898 ·············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.5,·SR·3.8,·SR·4.1,·SR·4.3,·SR·5.1,·SR·5.2,·SR·5.3,·SR·7.1,·SR·7.6
899 References:··_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.3899 References:··_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.3
900 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)900 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)
901 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4901 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4
902 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227902 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
903 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R28903 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R28
904 ·············_\x8c_\x8i_\x8s············1.1.2.3.1904 ·············_\x8c_\x8i_\x8s············1.1.2.3.1
905 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
906 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
907 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high 
908 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
909 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
910 part·/home 
911 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8905 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
912 [[customizations.filesystem]]906 [[customizations.filesystem]]
913 mountpoint·=·"/home"907 mountpoint·=·"/home"
914 size·=·1073741824908 size·=·1073741824
915 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8909 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
916 logvol·/home·1024910 logvol·/home·1024
 911 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 912 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 913 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high
 914 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 915 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 916 part·/home
917 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/t\x8tm\x8mp\x8p·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*917 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/t\x8tm\x8mp\x8p·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
918 The·/tmp·directory·is·a·world-writable·directory·used·for·temporary·file·storage.·Ensure·it·has·its·own·partition·or·logical·volume·at·installation·time,·or·migrate·it·using·LVM.918 The·/tmp·directory·is·a·world-writable·directory·used·for·temporary·file·storage.·Ensure·it·has·its·own·partition·or·logical·volume·at·installation·time,·or·migrate·it·using·LVM.
919 Rationale:···The·/tmp·partition·is·used·as·temporary·storage·by·many·programs.·Placing·/tmp·in·its·own·partition·enables·the·setting·of·more·restrictive·mount·options,·which·can·help·protect·programs·which·use·it.919 Rationale:···The·/tmp·partition·is·used·as·temporary·storage·by·many·programs.·Placing·/tmp·in·its·own·partition·enables·the·setting·of·more·restrictive·mount·options,·which·can·help·protect·programs·which·use·it.
920 Severity: ···low920 Severity: ···low
921 Rule·ID:·····xccdf_org.ssgproject.content_rule_partition_for_tmp921 Rule·ID:·····xccdf_org.ssgproject.content_rule_partition_for_tmp
922 Identifiers:·CCE-89606-8922 Identifiers:·CCE-89606-8
923 ·············_\x8c_\x8i_\x8s_\x8-_\x8c_\x8s_\x8c········12,·15,·8923 ·············_\x8c_\x8i_\x8s_\x8-_\x8c_\x8s_\x8c········12,·15,·8
Offset 928, 29 lines modifiedOffset 928, 29 lines modified
928 ·············_\x8d_\x8i_\x8s_\x8a···········CCI-000366928 ·············_\x8d_\x8i_\x8s_\x8a···········CCI-000366
Max diff block lines reached; 162200/167808 bytes (96.66%) of diff not shown.
280 KB
./usr/share/doc/ssg-nondebian/ssg-rhel10-guide-e8.html
    
Offset 23622, 210 lines modifiedOffset 23622, 210 lines modified
0005c450:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="0005c450:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
0005c460:·2369·646d·3230·3434·3322·2074·6162·696e··#idm20443"·tabin0005c460:·2369·646d·3230·3434·3322·2074·6162·696e··#idm20443"·tabin
0005c470:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu0005c470:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
0005c480:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan0005c480:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
0005c490:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl0005c490:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
0005c4a0:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r0005c4a0:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
0005c4b0:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"0005c4b0:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
0005c4c0:·3e52·656d·6564·6961·7469·6f6e·2073·6372··>Remediation·scr0005c4c0:·3e52·656d·6564·6961·7469·6f6e·204f·5342··>Remediation·OSB
0005c4d0:·6970·7420·e287·b23c·2f61·3e3c·6272·3e3c··ipt·...</a><br>< 
0005c4e0:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel 
0005c4f0:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap 
0005c500:·7365·2220·6964·3d22·6964·6d32·3034·3433··se"·id="idm20443 
0005c510:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class=" 
0005c520:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri 
0005c530:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border 
0005c540:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens 
0005c550:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp0005c4d0:·7569·6c64·2042·6c75·6570·7269·6e74·2073··uild·Blueprint·s
 0005c4e0:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b
 0005c4f0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
 0005c500:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
 0005c510:·6c61·7073·6522·2069·643d·2269·646d·3230··lapse"·id="idm20
 0005c520:·3434·3322·3e3c·7072·653e·3c63·6f64·653e··443"><pre><code>
 0005c530:·0a5b·5b70·6163·6b61·6765·735d·5d0a·6e61··.[[packages]].na
 0005c540:·6d65·203d·2022·7273·7973·6c6f·6722·0a76··me·=·"rsyslog".v
 0005c550:·6572·7369·6f6e·203d·2022·2a22·0a3c·2f63··ersion·=·"*".</c
 0005c560:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div>
 0005c570:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt
 0005c580:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data-
 0005c590:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse
 0005c5a0:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
 0005c5b0:·6964·6d32·3034·3434·2220·7461·6269·6e64··idm20444"·tabind
 0005c5c0:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
 0005c5d0:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
 0005c5e0:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
 0005c5f0:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
 0005c600:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
 0005c610:·5265·6d65·6469·6174·696f·6e20·5075·7070··Remediation·Pupp
 0005c620:·6574·2073·6e69·7070·6574·20e2·87b2·3c2f··et·snippet·...</
 0005c630:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
 0005c640:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
 0005c650:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
 0005c660:·646d·3230·3434·3422·3e3c·7461·626c·6520··dm20444"><table·
 0005c670:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab
 0005c680:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table
 0005c690:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-
 0005c6a0:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><
 0005c6b0:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</
 0005c6c0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
 0005c6d0:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr
0005c560:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>0005c6e0:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>
0005c570:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr0005c6f0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
0005c580:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption: 
0005c590:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td 
0005c5a0:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re 
0005c5b0:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa 
0005c5c0:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr 
0005c5d0:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</ 
0005c5e0:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t 
0005c5f0:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table>< 
0005c600:·7072·653e·3c63·6f64·653e·0a64·6e66·2069··pre><code>.dnf·i 
0005c610:·6e73·7461·6c6c·2072·7379·736c·6f67·0a3c··nstall·rsyslog.< 
0005c620:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di 
0005c630:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn· 
0005c640:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat 
0005c650:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap 
0005c660:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target= 
0005c670:·2223·6964·6d32·3034·3434·2220·7461·6269··"#idm20444"·tabi 
0005c680:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b 
0005c690:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa 
0005c6a0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit 
0005c6b0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to· 
0005c6c0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#! 
0005c6d0:·223e·5265·6d65·6469·6174·696f·6e20·416e··">Remediation·An 
0005c6e0:·6163·6f6e·6461·2073·6e69·7070·6574·20e2··aconda·snippet·. 
0005c6f0:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c 
0005c700:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll 
0005c710:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i 
0005c720:·643d·2269·646d·3230·3434·3422·3e3c·7461··d="idm20444"><ta 
0005c730:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table 
0005c740:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t 
0005c750:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta 
0005c760:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed">< 
0005c770:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit 
0005c780:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</ 
0005c790:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
0005c7a0:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th> 
0005c7b0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
0005c7c0:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot:0005c700:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th
0005c7d0:·3c2f·7468·3e3c·7464·3e66·616c·7365·3c2f··</th><td>false</ 
0005c7e0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
0005c7f0:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t 
0005c800:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t 
0005c810:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre>< 
0005c820:·636f·6465·3e0a·7061·636b·6167·6520·2d2d··code>.package·-- 
0005c830:·6164·643d·7273·7973·6c6f·670a·3c2f·636f··add=rsyslog.</co 
0005c840:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div>< 
0005c850:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn 
0005c860:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t 
0005c870:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse" 
0005c880:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i 
0005c890:·646d·3230·3434·3522·2074·6162·696e·6465··dm20445"·tabinde 
0005c8a0:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt 
0005c8b0:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande 
0005c8c0:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title= 
0005c8d0:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev 
0005c8e0:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R 
0005c8f0:·656d·6564·6961·7469·6f6e·204f·5342·7569··emediation·OSBui 
0005c900:·6c64·2042·6c75·6570·7269·6e74·2073·6e69··ld·Blueprint·sni 
0005c910:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br> 
0005c920:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane 
0005c930:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla 
0005c940:·7073·6522·2069·643d·2269·646d·3230·3434··pse"·id="idm2044 
0005c950:·3522·3e3c·7072·653e·3c63·6f64·653e·0a5b··5"><pre><code>.[ 
0005c960:·5b70·6163·6b61·6765·735d·5d0a·6e61·6d65··[packages]].name 
0005c970:·203d·2022·7273·7973·6c6f·6722·0a76·6572···=·"rsyslog".ver 
0005c980:·7369·6f6e·203d·2022·2a22·0a3c·2f63·6f64··sion·=·"*".</cod 
0005c990:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a 
0005c9a0:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn- 
0005c9b0:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to 
0005c9c0:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"· 
0005c9d0:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id 
0005c9e0:·6d32·3034·3436·2220·7461·6269·6e64·6578··m20446"·tabindex 
0005c9f0:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto 
0005ca00:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded 
0005ca10:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title=" 
0005ca20:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve 
0005ca30:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re 
Max diff block lines reached; 226374/254002 bytes (89.12%) of diff not shown.
32.1 KB
html2text {}
    
Offset 1776, 52 lines modifiedOffset 1776, 38 lines modified
1776 ··-·NIST-800-53-CM-6(a)1776 ··-·NIST-800-53-CM-6(a)
1777 ··-·enable_strategy1777 ··-·enable_strategy
1778 ··-·low_complexity1778 ··-·low_complexity
1779 ··-·low_disruption1779 ··-·low_disruption
1780 ··-·medium_severity1780 ··-·medium_severity
1781 ··-·no_reboot_needed1781 ··-·no_reboot_needed
1782 ··-·package_rsyslog_installed1782 ··-·package_rsyslog_installed
1783 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
1784 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
1785 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
1786 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
1787 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
1788 dnf·install·rsyslog 
1789 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
1790 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
1791 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
1792 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
1793 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
1794 package·--add=rsyslog 
1795 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81783 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
1796 [[packages]]1784 [[packages]]
1797 name·=·"rsyslog"1785 name·=·"rsyslog"
1798 version·=·"*"1786 version·=·"*"
1799 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
1800 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
1801 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
1802 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
1803 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
1804 package·install·rsyslog 
1805 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81787 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1806 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1788 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1807 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1789 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1808 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1790 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1809 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1791 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1810 include·install_rsyslog1792 include·install_rsyslog
  
1811 class·install_rsyslog·{1793 class·install_rsyslog·{
1812 ··package·{·'rsyslog':1794 ··package·{·'rsyslog':
1813 ····ensure·=>·'installed',1795 ····ensure·=>·'installed',
1814 ··}1796 ··}
1815 }1797 }
 1798 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 1799 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1800 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1801 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1802 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 1803 package·install·rsyslog
1816 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81804 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1817 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1805 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1818 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1806 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1819 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1807 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1820 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1808 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1821 #·Remediation·is·applicable·only·in·certain·platforms1809 #·Remediation·is·applicable·only·in·certain·platforms
1822 if·rpm·--quiet·-q·kernel;·then1810 if·rpm·--quiet·-q·kernel;·then
Offset 1829, 14 lines modifiedOffset 1815, 28 lines modified
1829 if·!·rpm·-q·--quiet·"rsyslog"·;·then1815 if·!·rpm·-q·--quiet·"rsyslog"·;·then
1830 ····dnf·install·-y·"rsyslog"1816 ····dnf·install·-y·"rsyslog"
1831 fi1817 fi
  
1832 else1818 else
1833 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'1819 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
1834 fi1820 fi
 1821 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 1822 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1823 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1824 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1825 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 1826 package·--add=rsyslog
 1827 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 1828 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1829 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1830 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1831 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 1832 dnf·install·rsyslog
1835 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·r\x8rs\x8sy\x8ys\x8sl\x8lo\x8og\x8g·S\x8Se\x8er\x8rv\x8vi\x8ic\x8ce\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*1833 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·r\x8rs\x8sy\x8ys\x8sl\x8lo\x8og\x8g·S\x8Se\x8er\x8rv\x8vi\x8ic\x8ce\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
1836 The·rsyslog·service·provides·syslog-style·logging·by·default·on·Red·Hat·Enterprise·Linux·10.·The·rsyslog·service·can·be·enabled·with·the·following·command:1834 The·rsyslog·service·provides·syslog-style·logging·by·default·on·Red·Hat·Enterprise·Linux·10.·The·rsyslog·service·can·be·enabled·with·the·following·command:
1837 $·sudo·systemctl·enable·rsyslog.service1835 $·sudo·systemctl·enable·rsyslog.service
1838 Rationale:···The·rsyslog·service·must·be·running·in·order·to·provide·logging·services,·which·are·essential·to·system·administration.1836 Rationale:···The·rsyslog·service·must·be·running·in·order·to·provide·logging·services,·which·are·essential·to·system·administration.
1839 Severity: ···medium1837 Severity: ···medium
1840 Rule·ID:·····xccdf_org.ssgproject.content_rule_service_rsyslog_enabled1838 Rule·ID:·····xccdf_org.ssgproject.content_rule_service_rsyslog_enabled
1841 Identifiers:·CCE-90584-41839 Identifiers:·CCE-90584-4
Offset 1895, 34 lines modifiedOffset 1895, 34 lines modified
1895 ··-·medium_severity1895 ··-·medium_severity
1896 ··-·no_reboot_needed1896 ··-·no_reboot_needed
1897 ··-·service_rsyslog_enabled1897 ··-·service_rsyslog_enabled
1898 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81898 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
1899 [customizations.services]1899 [customizations.services]
1900 enabled·=·["rsyslog"]1900 enabled·=·["rsyslog"]
1901 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
1902 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
1903 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
1904 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
1905 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable 
  
1906 service·enable·rsyslog 
1907 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81901 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1908 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1902 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1909 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1903 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1910 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1904 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1911 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1905 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1912 include·enable_rsyslog1906 include·enable_rsyslog
  
1913 class·enable_rsyslog·{1907 class·enable_rsyslog·{
1914 ··service·{'rsyslog':1908 ··service·{'rsyslog':
1915 ····enable·=>·true,1909 ····enable·=>·true,
1916 ····ensure·=>·'running',1910 ····ensure·=>·'running',
1917 ··}1911 ··}
1918 }1912 }
 1913 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 1914 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1915 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1916 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1917 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
  
 1918 service·enable·rsyslog
1919 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81919 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1920 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1920 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1921 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1921 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1922 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1922 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
Max diff block lines reached; 28293/32877 bytes (86.06%) of diff not shown.
354 KB
./usr/share/doc/ssg-nondebian/ssg-rhel10-guide-hipaa.html
    
Offset 18249, 78 lines modifiedOffset 18249, 78 lines modified
00047480:·6172·6765·743d·2223·6964·6d38·3636·3322··arget="#idm8663"00047480:·6172·6765·743d·2223·6964·6d38·3636·3322··arget="#idm8663"
00047490:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro00047490:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro
000474a0:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria000474a0:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria
000474b0:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false000474b0:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false
000474c0:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat000474c0:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat
000474d0:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre000474d0:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre
000474e0:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati000474e0:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati
 000474f0:·6f6e·204f·5342·7569·6c64·2042·6c75·6570··on·OSBuild·Bluep
 00047500:·7269·6e74·2073·6e69·7070·6574·20e2·87b2··rint·snippet·...
 00047510:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
 00047520:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
 00047530:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
 00047540:·2269·646d·3836·3633·223e·3c70·7265·3e3c··"idm8663"><pre><
 00047550:·636f·6465·3e0a·5b5b·6375·7374·6f6d·697a··code>.[[customiz
 00047560:·6174·696f·6e73·2e66·696c·6573·7973·7465··ations.filesyste
 00047570:·6d5d·5d0a·6d6f·756e·7470·6f69·6e74·203d··m]].mountpoint·=
000474f0:·6f6e·2041·6e61·636f·6e64·6120·736e·6970··on·Anaconda·snip 
00047500:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br>< 
00047510:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel 
00047520:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap 
00047530:·7365·2220·6964·3d22·6964·6d38·3636·3322··se"·id="idm8663" 
00047540:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t 
00047550:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip 
00047560:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere 
00047570:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense 
00047580:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl 
00047590:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l 
000475a0:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr> 
000475b0:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:< 
000475c0:·2f74·683e·3c74·643e·6869·6768·3c2f·7464··/th><td>high</td 
000475d0:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re 
000475e0:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa 
000475f0:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr 
00047600:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</ 
00047610:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t 
00047620:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table>< 
00047630:·7072·653e·3c63·6f64·653e·0a70·6172·7420··pre><code>.part· 
00047640:·2f76·6172·2f6c·6f67·2f61·7564·6974·0a3c··/var/log/audit.<00047580:·2022·2f76·6172·2f6c·6f67·2f61·7564·6974···"/var/log/audit
 00047590:·220a·7369·7a65·203d·2031·3037·3337·3431··".size·=·1073741
 000475a0:·3832·3430·0a3c·2f63·6f64·653e·3c2f·7072··8240.</code></pr
 000475b0:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class
 000475c0:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes
 000475d0:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle="
 000475e0:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t
 000475f0:·6172·6765·743d·2223·6964·6d38·3636·3422··arget="#idm8664"
 00047600:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro
 00047610:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria
 00047620:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false
 00047630:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat
 00047640:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre
 00047650:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati
 00047660:·6f6e·2073·6372·6970·7420·e287·b23c·2f61··on·script·...</a
 00047670:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
 00047680:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
 00047690:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
 000476a0:·6d38·3636·3422·3e3c·7072·653e·3c63·6f64··m8664"><pre><cod
 000476b0:·653e·0a6c·6f67·766f·6c20·2f76·6172·2f6c··e>.logvol·/var/l
 000476c0:·6f67·2f61·7564·6974·2031·3032·3430·0a3c··og/audit·10240.<
00047650:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di000476d0:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di
00047660:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn·000476e0:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn·
00047670:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat000476f0:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat
00047680:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap 
00047690:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target= 
000476a0:·2223·6964·6d38·3636·3422·2074·6162·696e··"#idm8664"·tabin 
000476b0:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu 
000476c0:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan 
000476d0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl 
000476e0:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r 
000476f0:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!" 
00047700:·3e52·656d·6564·6961·7469·6f6e·204f·5342··>Remediation·OSB 
00047710:·7569·6c64·2042·6c75·6570·7269·6e74·2073··uild·Blueprint·s 
00047720:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b 
00047730:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa 
00047740:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col 
00047750:·6c61·7073·6522·2069·643d·2269·646d·3836··lapse"·id="idm86 
00047760:·3634·223e·3c70·7265·3e3c·636f·6465·3e0a··64"><pre><code>. 
00047770:·5b5b·6375·7374·6f6d·697a·6174·696f·6e73··[[customizations 
00047780:·2e66·696c·6573·7973·7465·6d5d·5d0a·6d6f··.filesystem]].mo 
00047790:·756e·7470·6f69·6e74·203d·2022·2f76·6172··untpoint·=·"/var 
000477a0:·2f6c·6f67·2f61·7564·6974·220a·7369·7a65··/log/audit".size 
000477b0:·203d·2031·3037·3337·3431·3832·3430·0a3c···=·10737418240.< 
000477c0:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di 
000477d0:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn· 
000477e0:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat 
000477f0:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap00047700:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap
00047800:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=00047710:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
00047810:·2223·6964·6d38·3636·3522·2074·6162·696e··"#idm8665"·tabin00047720:·2223·6964·6d38·3636·3522·2074·6162·696e··"#idm8665"·tabin
00047820:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu00047730:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
00047830:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan00047740:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
00047840:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl00047750:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
00047850:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r00047760:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
00047860:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"00047770:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
00047870:·3e52·656d·6564·6961·7469·6f6e·2073·6372··>Remediation·scr00047780:·3e52·656d·6564·6961·7469·6f6e·2041·6e61··>Remediation·Ana
00047880:·6970·7420·e287·b23c·2f61·3e3c·6272·3e3c··ipt·...</a><br>< 
00047890:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel 
000478a0:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap 
000478b0:·7365·2220·6964·3d22·6964·6d38·3636·3522··se"·id="idm8665" 
000478c0:·3e3c·7072·653e·3c63·6f64·653e·0a6c·6f67··><pre><code>.log 
000478d0:·766f·6c20·2f76·6172·2f6c·6f67·2f61·7564··vol·/var/log/aud 
000478e0:·6974·2031·3032·3430·0a3c·2f63·6f64·653e··it·10240.</code>00047790:·636f·6e64·6120·736e·6970·7065·7420·e287··conda·snippet·..
 000477a0:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl
 000477b0:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla
 000477c0:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id
 000477d0:·3d22·6964·6d38·3636·3522·3e3c·7461·626c··="idm8665"><tabl
 000477e0:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t
 000477f0:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab
 00047800:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl
 00047810:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr
 00047820:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:
 00047830:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
 00047840:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di
 00047850:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t
 00047860:·643e·6869·6768·3c2f·7464·3e3c·2f74·723e··d>high</td></tr>
 00047870:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:<
 00047880:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t
 00047890:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S
 000478a0:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td
 000478b0:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr
 000478c0:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c
 000478d0:·6f64·653e·0a70·6172·7420·2f76·6172·2f6c··ode>.part·/var/l
 000478e0:·6f67·2f61·7564·6974·0a3c·2f63·6f64·653e··og/audit.</code>
000478f0:·3c2f·7072·653e·3c2f·6469·763e·3c2f·6469··</pre></div></di000478f0:·3c2f·7072·653e·3c2f·6469·763e·3c2f·6469··</pre></div></di
00047900:·763e·3c2f·7464·3e3c·2f74·723e·3c2f·7462··v></td></tr></tb00047900:·763e·3c2f·7464·3e3c·2f74·723e·3c2f·7462··v></td></tr></tb
00047910:·6f64·793e·3c2f·7461·626c·653e·3c2f·7464··ody></table></td00047910:·6f64·793e·3c2f·7461·626c·653e·3c2f·7464··ody></table></td
00047920:·3e3c·2f74·723e·3c74·7220·6461·7461·2d74··></tr><tr·data-t00047920:·3e3c·2f74·723e·3c74·7220·6461·7461·2d74··></tr><tr·data-t
00047930:·742d·6964·3d22·6368·696c·6472·656e·2d78··t-id="children-x00047930:·742d·6964·3d22·6368·696c·6472·656e·2d78··t-id="children-x
00047940:·6363·6466·5f6f·7267·2e73·7367·7072·6f6a··ccdf_org.ssgproj00047940:·6363·6466·5f6f·7267·2e73·7367·7072·6f6a··ccdf_org.ssgproj
Max diff block lines reached; 309704/319528 bytes (96.93%) of diff not shown.
41.6 KB
html2text {}
    
Offset 724, 29 lines modifiedOffset 724, 29 lines modified
724 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·AU-4,·SC-5(2)724 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·AU-4,·SC-5(2)
725 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-4,·PR.PT-1,·PR.PT-4725 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-4,·PR.PT-1,·PR.PT-4
726 ·············_\x8o_\x8s_\x8p_\x8p···········FMT_SMF_EXT.1726 ·············_\x8o_\x8s_\x8p_\x8p···········FMT_SMF_EXT.1
727 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000341-GPOS-00132,·SRG-OS-000480-GPOS-00227727 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000341-GPOS-00132,·SRG-OS-000480-GPOS-00227
728 ·············_\x8a_\x8p_\x8p_\x8-_\x8s_\x8r_\x8g_\x8-_\x8c_\x8t_\x8r····SRG-APP-000357-CTR-000800728 ·············_\x8a_\x8p_\x8p_\x8-_\x8s_\x8r_\x8g_\x8-_\x8c_\x8t_\x8r····SRG-APP-000357-CTR-000800
729 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R71729 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R71
730 ·············_\x8c_\x8i_\x8s············1.1.2.7.1730 ·············_\x8c_\x8i_\x8s············1.1.2.7.1
731 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
732 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
733 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high 
734 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
735 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
736 part·/var/log/audit 
737 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8731 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
738 [[customizations.filesystem]]732 [[customizations.filesystem]]
739 mountpoint·=·"/var/log/audit"733 mountpoint·=·"/var/log/audit"
740 size·=·10737418240734 size·=·10737418240
741 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8735 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
742 logvol·/var/log/audit·10240736 logvol·/var/log/audit·10240
 737 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 738 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 739 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high
 740 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 741 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 742 part·/var/log/audit
743 Group  ·GNOME·Desktop·Environment·  Group·contains·1·rule743 Group  ·GNOME·Desktop·Environment·  Group·contains·1·rule
744 _\x8[_\x8r_\x8e_\x8f_\x8]  ·GNOME·is·a·graphical·desktop·environment·bundled·with·many·Linux·distributions·that·allow·users·to·easily·interact·with·the·operating·system·graphically·rather·than·textually.·The·GNOME·Graphical·Display·Manager·(GDM)·provides·login,·logout,·and·user·switching·contexts·as·well·as·display·server·management.744 _\x8[_\x8r_\x8e_\x8f_\x8]  ·GNOME·is·a·graphical·desktop·environment·bundled·with·many·Linux·distributions·that·allow·users·to·easily·interact·with·the·operating·system·graphically·rather·than·textually.·The·GNOME·Graphical·Display·Manager·(GDM)·provides·login,·logout,·and·user·switching·contexts·as·well·as·display·server·management.
  
745 GNOME·is·developed·by·the·GNOME·Project·and·is·considered·the·default·Red·Hat·Graphical·environment.745 GNOME·is·developed·by·the·GNOME·Project·and·is·considered·the·default·Red·Hat·Graphical·environment.
  
746 For·more·information·on·GNOME·and·the·GNOME·Project,·see·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8w\x8w_\x8w\x8w_\x8w\x8w_\x8.\x8._\x8g\x8g_\x8n\x8n_\x8o\x8o_\x8m\x8m_\x8e\x8e_\x8.\x8._\x8o\x8o_\x8r\x8r_\x8g\x8g.746 For·more·information·on·GNOME·and·the·GNOME·Project,·see·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8w\x8w_\x8w\x8w_\x8w\x8w_\x8.\x8._\x8g\x8g_\x8n\x8n_\x8o\x8o_\x8m\x8m_\x8e\x8e_\x8.\x8._\x8o\x8o_\x8r\x8r_\x8g\x8g.
747 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·M\x8Ma\x8ak\x8ke\x8e·s\x8su\x8ur\x8re\x8e·t\x8th\x8ha\x8at\x8t·t\x8th\x8he\x8e·d\x8dc\x8co\x8on\x8nf\x8f·d\x8da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8es\x8s·a\x8ar\x8re\x8e·u\x8up\x8p-\x8-t\x8to\x8o-\x8-d\x8da\x8at\x8te\x8e·w\x8wi\x8it\x8th\x8h·r\x8re\x8eg\x8ga\x8ar\x8rd\x8ds\x8s·t\x8to\x8o·r\x8re\x8es\x8sp\x8pe\x8ec\x8ct\x8ti\x8iv\x8ve\x8e·k\x8ke\x8ey\x8yf\x8fi\x8il\x8le\x8es\x8s·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*747 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·M\x8Ma\x8ak\x8ke\x8e·s\x8su\x8ur\x8re\x8e·t\x8th\x8ha\x8at\x8t·t\x8th\x8he\x8e·d\x8dc\x8co\x8on\x8nf\x8f·d\x8da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8es\x8s·a\x8ar\x8re\x8e·u\x8up\x8p-\x8-t\x8to\x8o-\x8-d\x8da\x8at\x8te\x8e·w\x8wi\x8it\x8th\x8h·r\x8re\x8eg\x8ga\x8ar\x8rd\x8ds\x8s·t\x8to\x8o·r\x8re\x8es\x8sp\x8pe\x8ec\x8ct\x8ti\x8iv\x8ve\x8e·k\x8ke\x8ey\x8yf\x8fi\x8il\x8le\x8es\x8s·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
Offset 1453, 14 lines modifiedOffset 1453, 34 lines modified
1453 ··-·medium_severity1453 ··-·medium_severity
1454 ··-·no_reboot_needed1454 ··-·no_reboot_needed
1455 ··-·service_debug-shell_disabled1455 ··-·service_debug-shell_disabled
1456 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81456 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
1457 [customizations.services]1457 [customizations.services]
1458 masked·=·["debug-shell"]1458 masked·=·["debug-shell"]
 1459 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 1460 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1461 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1462 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1463 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 1464 include·disable_debug-shell
  
 1465 class·disable_debug-shell·{
 1466 ··service·{'debug-shell':
 1467 ····enable·=>·false,
 1468 ····ensure·=>·'stopped',
 1469 ··}
 1470 }
 1471 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 1472 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1473 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1474 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1475 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
  
 1476 service·disable·debug-shell
1459 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81477 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1460 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1478 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1461 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium1479 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
1462 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true1480 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
1463 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable1481 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
1464 apiVersion:·machineconfiguration.openshift.io/v11482 apiVersion:·machineconfiguration.openshift.io/v1
1465 kind:·MachineConfig1483 kind:·MachineConfig
Offset 1472, 34 lines modifiedOffset 1492, 14 lines modified
1472 ······units:1492 ······units:
1473 ······-·name:·debug-shell.service1493 ······-·name:·debug-shell.service
1474 ········enabled:·false1494 ········enabled:·false
1475 ········mask:·true1495 ········mask:·true
1476 ······-·name:·debug-shell.socket1496 ······-·name:·debug-shell.socket
1477 ········enabled:·false1497 ········enabled:·false
1478 ········mask:·true1498 ········mask:·true
1479 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
1480 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
1481 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
1482 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
1483 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable 
  
1484 service·disable·debug-shell 
1485 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
1486 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
1487 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
1488 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
1489 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
1490 include·disable_debug-shell 
  
1491 class·disable_debug-shell·{ 
1492 ··service·{'debug-shell': 
1493 ····enable·=>·false, 
1494 ····ensure·=>·'stopped', 
1495 ··} 
1496 } 
1497 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81499 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1498 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1500 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1499 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1501 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1500 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1502 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1501 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable1503 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
1502 #·Remediation·is·applicable·only·in·certain·platforms1504 #·Remediation·is·applicable·only·in·certain·platforms
1503 if·rpm·--quiet·-q·kernel;·then1505 if·rpm·--quiet·-q·kernel;·then
Offset 3516, 52 lines modifiedOffset 3516, 38 lines modified
3516 ··-·NIST-800-53-CM-6(a)3516 ··-·NIST-800-53-CM-6(a)
3517 ··-·enable_strategy3517 ··-·enable_strategy
3518 ··-·low_complexity3518 ··-·low_complexity
3519 ··-·low_disruption3519 ··-·low_disruption
3520 ··-·medium_severity3520 ··-·medium_severity
3521 ··-·no_reboot_needed3521 ··-·no_reboot_needed
3522 ··-·package_rsyslog_installed3522 ··-·package_rsyslog_installed
3523 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
3524 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
3525 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
3526 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
3527 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
3528 dnf·install·rsyslog 
3529 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
3530 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
3531 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
3532 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
3533 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
Max diff block lines reached; 37202/42603 bytes (87.32%) of diff not shown.
650 KB
./usr/share/doc/ssg-nondebian/ssg-rhel10-guide-ism_o.html
    
Offset 15193, 208 lines modifiedOffset 15193, 208 lines modified
0003b580:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i0003b580:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i
0003b590:·646d·3733·3038·2220·7461·6269·6e64·6578··dm7308"·tabindex0003b590:·646d·3733·3038·2220·7461·6269·6e64·6578··dm7308"·tabindex
0003b5a0:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto0003b5a0:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto
0003b5b0:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded0003b5b0:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded
0003b5c0:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="0003b5c0:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="
0003b5d0:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve0003b5d0:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve
0003b5e0:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re0003b5e0:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re
0003b5f0:·6d65·6469·6174·696f·6e20·7363·7269·7074··mediation·script0003b5f0:·6d65·6469·6174·696f·6e20·4f53·4275·696c··mediation·OSBuil
 0003b600:·6420·426c·7565·7072·696e·7420·736e·6970··d·Blueprint·snip
 0003b610:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br><
 0003b620:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
 0003b630:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap
 0003b640:·7365·2220·6964·3d22·6964·6d37·3330·3822··se"·id="idm7308"
 0003b650:·3e3c·7072·653e·3c63·6f64·653e·0a5b·5b70··><pre><code>.[[p
 0003b660:·6163·6b61·6765·735d·5d0a·6e61·6d65·203d··ackages]].name·=
 0003b670:·2022·6169·6465·220a·7665·7273·696f·6e20···"aide".version·
 0003b680:·3d20·222a·220a·3c2f·636f·6465·3e3c·2f70··=·"*".</code></p
 0003b690:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas
 0003b6a0:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe
 0003b6b0:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle=
 0003b6c0:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data-
 0003b6d0:·7461·7267·6574·3d22·2369·646d·3733·3039··target="#idm7309
 0003b6e0:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r
 0003b6f0:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari
 0003b700:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals
 0003b710:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa
 0003b720:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr
 0003b730:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat
 0003b740:·696f·6e20·5075·7070·6574·2073·6e69·7070··ion·Puppet·snipp
0003b600:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div0003b750:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d
0003b610:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co0003b760:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-
0003b620:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"0003b770:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps
0003b630:·2069·643d·2269·646d·3733·3038·223e·3c74···id="idm7308"><t0003b780:·6522·2069·643d·2269·646d·3733·3039·223e··e"·id="idm7309">
0003b640:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl0003b790:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta
0003b650:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·0003b7a0:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe
0003b660:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t0003b7b0:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered
0003b670:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">0003b7c0:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed
0003b680:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi0003b7d0:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple
0003b690:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<0003b7e0:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo
0003b6a0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0003b6b0:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th 
0003b6c0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t 
0003b6d0:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot 
0003b6e0:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false< 
0003b6f0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th0003b7f0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
 0003b800:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</
 0003b810:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
 0003b820:·2f74·723e·3c74·723e·3c74·683e·5265·626f··/tr><tr><th>Rebo
 0003b830:·6f74·3a3c·2f74·683e·3c74·643e·6661·6c73··ot:</th><td>fals
 0003b840:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr><
0003b700:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><0003b850:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th
0003b710:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></0003b860:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td>
0003b720:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>0003b870:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr
 0003b880:·653e·3c63·6f64·653e·696e·636c·7564·6520··e><code>include·
 0003b890:·696e·7374·616c·6c5f·6169·6465·0a0a·636c··install_aide..cl
 0003b8a0:·6173·7320·696e·7374·616c·6c5f·6169·6465··ass·install_aide
 0003b8b0:·207b·0a20·2070·6163·6b61·6765·207b·2027···{.··package·{·'
 0003b8c0:·6169·6465·273a·0a20·2020·2065·6e73·7572··aide':.····ensur
 0003b8d0:·6520·3d26·6774·3b20·2769·6e73·7461·6c6c··e·=&gt;·'install
 0003b8e0:·6564·272c·0a20·207d·0a7d·0a3c·2f63·6f64··ed',.··}.}.</cod
 0003b8f0:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a
 0003b900:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn-
 0003b910:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to
0003b730:·3c63·6f64·653e·0a64·6e66·2069·6e73·7461··<code>.dnf·insta 
0003b740:·6c6c·2061·6964·650a·3c2f·636f·6465·3e3c··ll·aide.</code>< 
0003b750:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl 
0003b760:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc 
0003b770:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl 
0003b780:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat 
0003b790:·612d·7461·7267·6574·3d22·2369·646d·3733··a-target="#idm73 
0003b7a0:·3039·2220·7461·6269·6e64·6578·3d22·3022··09"·tabindex="0" 
0003b7b0:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a 
0003b7c0:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa 
0003b7d0:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti 
0003b7e0:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"· 
0003b7f0:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi 
0003b800:·6174·696f·6e20·416e·6163·6f6e·6461·2073··ation·Anaconda·s 
0003b810:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b 
0003b820:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa 
0003b830:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col 
0003b840:·6c61·7073·6522·2069·643d·2269·646d·3733··lapse"·id="idm73 
0003b850:·3039·223e·3c74·6162·6c65·2063·6c61·7373··09"><table·class 
0003b860:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st 
0003b870:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord 
0003b880:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde 
0003b890:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co 
0003b8a0:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t 
0003b8b0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr>< 
0003b8c0:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio 
0003b8d0:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</ 
0003b8e0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
0003b8f0:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td> 
0003b900:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr>< 
0003b910:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy: 
0003b920:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable< 
0003b930:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table 
0003b940:·3e3c·7072·653e·3c63·6f64·653e·0a70·6163··><pre><code>.pac 
0003b950:·6b61·6765·202d·2d61·6464·3d61·6964·650a··kage·--add=aide. 
0003b960:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d 
0003b970:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn 
0003b980:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da 
0003b990:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla 
0003b9a0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target 
0003b9b0:·3d22·2369·646d·3733·3130·2220·7461·6269··="#idm7310"·tabi 
0003b9c0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b 
0003b9d0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa 
0003b9e0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit 
0003b9f0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to· 
0003ba00:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#! 
0003ba10:·223e·5265·6d65·6469·6174·696f·6e20·4f53··">Remediation·OS 
0003ba20:·4275·696c·6420·426c·7565·7072·696e·7420··Build·Blueprint· 
0003ba30:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a>< 
0003ba40:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p 
0003ba50:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co 
0003ba60:·6c6c·6170·7365·2220·6964·3d22·6964·6d37··llapse"·id="idm7 
0003ba70:·3331·3022·3e3c·7072·653e·3c63·6f64·653e··310"><pre><code> 
0003ba80:·0a5b·5b70·6163·6b61·6765·735d·5d0a·6e61··.[[packages]].na 
0003ba90:·6d65·203d·2022·6169·6465·220a·7665·7273··me·=·"aide".vers 
0003baa0:·696f·6e20·3d20·222a·220a·3c2f·636f·6465··ion·=·"*".</code 
0003bab0:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a· 
0003bac0:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s 
0003bad0:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog 
0003bae0:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d0003b920:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"·
0003baf0:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm 
0003bb00:·3733·3131·2220·7461·6269·6e64·6578·3d22··7311"·tabindex=" 
0003bb10:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button" 
0003bb20:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded=" 
Max diff block lines reached; 562382/589734 bytes (95.36%) of diff not shown.
74.3 KB
html2text {}
    
Offset 143, 52 lines modifiedOffset 143, 38 lines modified
143 ··-·PCI-DSSv4-11.5.2143 ··-·PCI-DSSv4-11.5.2
144 ··-·enable_strategy144 ··-·enable_strategy
145 ··-·low_complexity145 ··-·low_complexity
146 ··-·low_disruption146 ··-·low_disruption
147 ··-·medium_severity147 ··-·medium_severity
148 ··-·no_reboot_needed148 ··-·no_reboot_needed
149 ··-·package_aide_installed149 ··-·package_aide_installed
150 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
151 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
152 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
153 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
154 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
155 dnf·install·aide 
156 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
157 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
158 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
159 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
160 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
161 package·--add=aide 
162 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8150 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
163 [[packages]]151 [[packages]]
164 name·=·"aide"152 name·=·"aide"
165 version·=·"*"153 version·=·"*"
166 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
167 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
168 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
169 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
170 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
171 package·install·aide 
172 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8154 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
173 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low155 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
174 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low156 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
175 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false157 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
176 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable158 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
177 include·install_aide159 include·install_aide
  
178 class·install_aide·{160 class·install_aide·{
179 ··package·{·'aide':161 ··package·{·'aide':
180 ····ensure·=>·'installed',162 ····ensure·=>·'installed',
181 ··}163 ··}
182 }164 }
 165 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 166 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 167 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 168 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 169 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 170 package·install·aide
183 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8171 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
184 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low172 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
185 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low173 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
186 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false174 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
187 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable175 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
188 #·Remediation·is·applicable·only·in·certain·platforms176 #·Remediation·is·applicable·only·in·certain·platforms
189 if·rpm·--quiet·-q·kernel;·then177 if·rpm·--quiet·-q·kernel;·then
Offset 196, 14 lines modifiedOffset 182, 28 lines modified
196 if·!·rpm·-q·--quiet·"aide"·;·then182 if·!·rpm·-q·--quiet·"aide"·;·then
197 ····dnf·install·-y·"aide"183 ····dnf·install·-y·"aide"
198 fi184 fi
  
199 else185 else
200 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'186 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
201 fi187 fi
 188 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 189 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 190 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 191 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 192 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 193 package·--add=aide
 194 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 195 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 196 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 197 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 198 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 199 dnf·install·aide
202 Group  ·Federal·Information·Processing·Standard·(FIPS)·  Group·contains·2·rules200 Group  ·Federal·Information·Processing·Standard·(FIPS)·  Group·contains·2·rules
203 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·Federal·Information·Processing·Standard·(FIPS)·is·a·computer·security·standard·which·is·developed·by·the·U.S.·Government·and·industry·working·groups·to·validate·the·quality·of·cryptographic·modules.·The·FIPS·standard·provides·four·security·levels·to·ensure·adequate·coverage·of·different·industries,·implementation·of·cryptographic·modules,·and·organizational·sizes·and·requirements.201 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·Federal·Information·Processing·Standard·(FIPS)·is·a·computer·security·standard·which·is·developed·by·the·U.S.·Government·and·industry·working·groups·to·validate·the·quality·of·cryptographic·modules.·The·FIPS·standard·provides·four·security·levels·to·ensure·adequate·coverage·of·different·industries,·implementation·of·cryptographic·modules,·and·organizational·sizes·and·requirements.
  
204 FIPS·140-2·is·the·current·standard·for·validating·that·mechanisms·used·to·access·cryptographic·modules·utilize·authentication·that·meets·industry·and·government·requirements.·For·government·systems,·this·allows·Security·Levels·1,·2,·3,·or·4·for·use·on·Red·Hat·Enterprise·Linux·10.202 FIPS·140-2·is·the·current·standard·for·validating·that·mechanisms·used·to·access·cryptographic·modules·utilize·authentication·that·meets·industry·and·government·requirements.·For·government·systems,·this·allows·Security·Levels·1,·2,·3,·or·4·for·use·on·Red·Hat·Enterprise·Linux·10.
  
205 See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8c\x8c_\x8s\x8s_\x8r\x8r_\x8c\x8c_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8l\x8l_\x8i\x8i_\x8c\x8c_\x8a\x8a_\x8t\x8t_\x8i\x8i_\x8o\x8o_\x8n\x8n_\x8s\x8s_\x8/\x8/_\x8P\x8P_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x8h\x8h_\x8t\x8t_\x8m\x8m_\x8l\x8l·for·more·information.203 See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8c\x8c_\x8s\x8s_\x8r\x8r_\x8c\x8c_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8l\x8l_\x8i\x8i_\x8c\x8c_\x8a\x8a_\x8t\x8t_\x8i\x8i_\x8o\x8o_\x8n\x8n_\x8s\x8s_\x8/\x8/_\x8P\x8P_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x8h\x8h_\x8t\x8t_\x8m\x8m_\x8l\x8l·for·more·information.
206 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8de\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*204 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8de\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
Offset 518, 52 lines modifiedOffset 518, 38 lines modified
518 ··-·PCI-DSSv4-2.2.6518 ··-·PCI-DSSv4-2.2.6
519 ··-·enable_strategy519 ··-·enable_strategy
520 ··-·low_complexity520 ··-·low_complexity
521 ··-·low_disruption521 ··-·low_disruption
522 ··-·medium_severity522 ··-·medium_severity
523 ··-·no_reboot_needed523 ··-·no_reboot_needed
524 ··-·package_sudo_installed524 ··-·package_sudo_installed
525 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
526 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
527 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
528 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
529 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
530 dnf·install·sudo 
531 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
532 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
533 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
534 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
535 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
536 package·--add=sudo 
537 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8525 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
538 [[packages]]526 [[packages]]
539 name·=·"sudo"527 name·=·"sudo"
540 version·=·"*"528 version·=·"*"
541 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
542 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
543 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
544 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
545 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
546 package·install·sudo 
547 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8529 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
548 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low530 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
549 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low531 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
550 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false532 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
551 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable533 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
Max diff block lines reached; 71010/76107 bytes (93.30%) of diff not shown.
650 KB
./usr/share/doc/ssg-nondebian/ssg-rhel10-guide-ism_o_secret.html
    
Offset 15197, 208 lines modifiedOffset 15197, 208 lines modified
0003b5c0:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id0003b5c0:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
0003b5d0:·6d37·3330·3822·2074·6162·696e·6465·783d··m7308"·tabindex=0003b5d0:·6d37·3330·3822·2074·6162·696e·6465·783d··m7308"·tabindex=
0003b5e0:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button0003b5e0:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button
0003b5f0:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=0003b5f0:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=
0003b600:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A0003b600:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A
0003b610:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea0003b610:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea
0003b620:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem0003b620:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem
 0003b630:·6564·6961·7469·6f6e·204f·5342·7569·6c64··ediation·OSBuild
 0003b640:·2042·6c75·6570·7269·6e74·2073·6e69·7070···Blueprint·snipp
 0003b650:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d
 0003b660:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-
 0003b670:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps
 0003b680:·6522·2069·643d·2269·646d·3733·3038·223e··e"·id="idm7308">
0003b630:·6564·6961·7469·6f6e·2073·6372·6970·7420··ediation·script· 
0003b640:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div· 
0003b650:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col 
0003b660:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"· 
0003b670:·6964·3d22·6964·6d37·3330·3822·3e3c·7461··id="idm7308"><ta 
0003b680:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table 
0003b690:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t 
0003b6a0:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta 
0003b6b0:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed">< 
0003b6c0:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit 
0003b6d0:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</ 
0003b6e0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
0003b6f0:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th> 
0003b700:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
0003b710:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot: 
0003b720:·3c2f·7468·3e3c·7464·3e66·616c·7365·3c2f··</th><td>false</ 
0003b730:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
0003b740:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t 
0003b750:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t 
0003b760:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre>< 
0003b770:·636f·6465·3e0a·646e·6620·696e·7374·616c··code>.dnf·instal 
0003b780:·6c20·6169·6465·0a3c·2f63·6f64·653e·3c2f··l·aide.</code></ 
0003b790:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla 
0003b7a0:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ 
0003b7b0:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle 
0003b7c0:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data 
0003b7d0:·2d74·6172·6765·743d·2223·6964·6d37·3330··-target="#idm730 
0003b7e0:·3922·2074·6162·696e·6465·783d·2230·2220··9"·tabindex="0"· 
0003b7f0:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar 
0003b800:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal 
0003b810:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ 
0003b820:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h 
0003b830:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia 
0003b840:·7469·6f6e·2041·6e61·636f·6e64·6120·736e··tion·Anaconda·sn 
0003b850:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br 
0003b860:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan 
0003b870:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll 
0003b880:·6170·7365·2220·6964·3d22·6964·6d37·3330··apse"·id="idm730 
0003b890:·3922·3e3c·7461·626c·6520·636c·6173·733d··9"><table·class= 
0003b8a0:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str 
0003b8b0:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde 
0003b8c0:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden 
0003b8d0:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com 
0003b8e0:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td 
0003b8f0:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t 
0003b900:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption 
0003b910:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t 
0003b920:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e52··d></tr><tr><th>R 
0003b930:·6562·6f6f·743a·3c2f·7468·3e3c·7464·3e66··eboot:</th><td>f 
0003b940:·616c·7365·3c2f·7464·3e3c·2f74·723e·3c74··alse</td></tr><t 
0003b950:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:< 
0003b960:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</ 
0003b970:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table> 
0003b980:·3c70·7265·3e3c·636f·6465·3e0a·7061·636b··<pre><code>.pack0003b690:·3c70·7265·3e3c·636f·6465·3e0a·5b5b·7061··<pre><code>.[[pa
0003b990:·6167·6520·2d2d·6164·643d·6169·6465·0a3c··age·--add=aide.< 
0003b9a0:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di 
0003b9b0:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn· 
0003b9c0:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat 
0003b9d0:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap 
0003b9e0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target= 
0003b9f0:·2223·6964·6d37·3331·3022·2074·6162·696e··"#idm7310"·tabin 
0003ba00:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu 
0003ba10:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan 
0003ba20:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl 
0003ba30:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r 
0003ba40:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!" 
0003ba50:·3e52·656d·6564·6961·7469·6f6e·204f·5342··>Remediation·OSB 
0003ba60:·7569·6c64·2042·6c75·6570·7269·6e74·2073··uild·Blueprint·s 
0003ba70:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b 
0003ba80:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa 
0003ba90:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col 
0003baa0:·6c61·7073·6522·2069·643d·2269·646d·3733··lapse"·id="idm73 
0003bab0:·3130·223e·3c70·7265·3e3c·636f·6465·3e0a··10"><pre><code>. 
0003bac0:·5b5b·7061·636b·6167·6573·5d5d·0a6e·616d··[[packages]].nam0003b6a0:·636b·6167·6573·5d5d·0a6e·616d·6520·3d20··ckages]].name·=·
0003bad0:·6520·3d20·2261·6964·6522·0a76·6572·7369··e·=·"aide".versi0003b6b0:·2261·6964·6522·0a76·6572·7369·6f6e·203d··"aide".version·=
0003bae0:·6f6e·203d·2022·2a22·0a3c·2f63·6f64·653e··on·=·"*".</code>0003b6c0:·2022·2a22·0a3c·2f63·6f64·653e·3c2f·7072···"*".</code></pr
0003baf0:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c 
0003bb00:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su 
0003bb10:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg 
0003bb20:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da 
0003bb30:·7461·2d74·6172·6765·743d·2223·6964·6d37··ta-target="#idm7 
0003bb40:·3331·3122·2074·6162·696e·6465·783d·2230··311"·tabindex="0 
0003bb50:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"· 
0003bb60:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f 
0003bb70:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act 
0003bb80:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal" 
0003bb90:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed 
0003bba0:·6961·7469·6f6e·2073·6372·6970·7420·e287··iation·script·.. 
0003bbb0:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl 
0003bbc0:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla 
0003bbd0:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id 
0003bbe0:·3d22·6964·6d37·3331·3122·3e3c·7461·626c··="idm7311"><tabl 
0003bbf0:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t 
0003bc00:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab 
0003bc10:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl 
0003bc20:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr 
0003bc30:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity: 
0003bc40:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td 
0003bc50:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di 
0003bc60:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t 
0003bc70:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr>< 
0003bc80:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</ 
0003bc90:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td 
0003bca0:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St 
0003bcb0:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td> 
0003bcc0:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr> 
0003bcd0:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co 
0003bce0:·6465·3e0a·7061·636b·6167·6520·696e·7374··de>.package·inst 
0003bcf0:·616c·6c20·6169·6465·0a3c·2f63·6f64·653e··all·aide.</code> 
0003bd00:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c0003b6d0:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class
0003bd10:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su0003b6e0:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes
0003bd20:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg0003b6f0:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle="
0003bd30:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da0003b700:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t
0003bd40:·7461·2d74·6172·6765·743d·2223·6964·6d37··ta-target="#idm70003b710:·6172·6765·743d·2223·6964·6d37·3330·3922··arget="#idm7309"
Max diff block lines reached; 562382/589734 bytes (95.36%) of diff not shown.
74.3 KB
html2text {}
    
Offset 144, 52 lines modifiedOffset 144, 38 lines modified
144 ··-·PCI-DSSv4-11.5.2144 ··-·PCI-DSSv4-11.5.2
145 ··-·enable_strategy145 ··-·enable_strategy
146 ··-·low_complexity146 ··-·low_complexity
147 ··-·low_disruption147 ··-·low_disruption
148 ··-·medium_severity148 ··-·medium_severity
149 ··-·no_reboot_needed149 ··-·no_reboot_needed
150 ··-·package_aide_installed150 ··-·package_aide_installed
151 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
152 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
153 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
154 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
155 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
156 dnf·install·aide 
157 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
158 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
159 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
160 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
161 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
162 package·--add=aide 
163 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8151 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
164 [[packages]]152 [[packages]]
165 name·=·"aide"153 name·=·"aide"
166 version·=·"*"154 version·=·"*"
167 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
168 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
169 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
170 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
171 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
172 package·install·aide 
173 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8155 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
174 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low156 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
175 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low157 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
176 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false158 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
177 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable159 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
178 include·install_aide160 include·install_aide
  
179 class·install_aide·{161 class·install_aide·{
180 ··package·{·'aide':162 ··package·{·'aide':
181 ····ensure·=>·'installed',163 ····ensure·=>·'installed',
182 ··}164 ··}
183 }165 }
 166 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 167 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 168 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 169 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 170 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 171 package·install·aide
184 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8172 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
185 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low173 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
186 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low174 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
187 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false175 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
188 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable176 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
189 #·Remediation·is·applicable·only·in·certain·platforms177 #·Remediation·is·applicable·only·in·certain·platforms
190 if·rpm·--quiet·-q·kernel;·then178 if·rpm·--quiet·-q·kernel;·then
Offset 197, 14 lines modifiedOffset 183, 28 lines modified
197 if·!·rpm·-q·--quiet·"aide"·;·then183 if·!·rpm·-q·--quiet·"aide"·;·then
198 ····dnf·install·-y·"aide"184 ····dnf·install·-y·"aide"
199 fi185 fi
  
200 else186 else
201 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'187 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
202 fi188 fi
 189 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 190 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 191 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 192 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 193 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 194 package·--add=aide
 195 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 196 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 197 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 198 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 199 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 200 dnf·install·aide
203 Group  ·Federal·Information·Processing·Standard·(FIPS)·  Group·contains·2·rules201 Group  ·Federal·Information·Processing·Standard·(FIPS)·  Group·contains·2·rules
204 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·Federal·Information·Processing·Standard·(FIPS)·is·a·computer·security·standard·which·is·developed·by·the·U.S.·Government·and·industry·working·groups·to·validate·the·quality·of·cryptographic·modules.·The·FIPS·standard·provides·four·security·levels·to·ensure·adequate·coverage·of·different·industries,·implementation·of·cryptographic·modules,·and·organizational·sizes·and·requirements.202 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·Federal·Information·Processing·Standard·(FIPS)·is·a·computer·security·standard·which·is·developed·by·the·U.S.·Government·and·industry·working·groups·to·validate·the·quality·of·cryptographic·modules.·The·FIPS·standard·provides·four·security·levels·to·ensure·adequate·coverage·of·different·industries,·implementation·of·cryptographic·modules,·and·organizational·sizes·and·requirements.
  
205 FIPS·140-2·is·the·current·standard·for·validating·that·mechanisms·used·to·access·cryptographic·modules·utilize·authentication·that·meets·industry·and·government·requirements.·For·government·systems,·this·allows·Security·Levels·1,·2,·3,·or·4·for·use·on·Red·Hat·Enterprise·Linux·10.203 FIPS·140-2·is·the·current·standard·for·validating·that·mechanisms·used·to·access·cryptographic·modules·utilize·authentication·that·meets·industry·and·government·requirements.·For·government·systems,·this·allows·Security·Levels·1,·2,·3,·or·4·for·use·on·Red·Hat·Enterprise·Linux·10.
  
206 See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8c\x8c_\x8s\x8s_\x8r\x8r_\x8c\x8c_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8l\x8l_\x8i\x8i_\x8c\x8c_\x8a\x8a_\x8t\x8t_\x8i\x8i_\x8o\x8o_\x8n\x8n_\x8s\x8s_\x8/\x8/_\x8P\x8P_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x8h\x8h_\x8t\x8t_\x8m\x8m_\x8l\x8l·for·more·information.204 See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8c\x8c_\x8s\x8s_\x8r\x8r_\x8c\x8c_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8l\x8l_\x8i\x8i_\x8c\x8c_\x8a\x8a_\x8t\x8t_\x8i\x8i_\x8o\x8o_\x8n\x8n_\x8s\x8s_\x8/\x8/_\x8P\x8P_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x8h\x8h_\x8t\x8t_\x8m\x8m_\x8l\x8l·for·more·information.
207 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8de\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*205 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8de\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
Offset 519, 52 lines modifiedOffset 519, 38 lines modified
519 ··-·PCI-DSSv4-2.2.6519 ··-·PCI-DSSv4-2.2.6
520 ··-·enable_strategy520 ··-·enable_strategy
521 ··-·low_complexity521 ··-·low_complexity
522 ··-·low_disruption522 ··-·low_disruption
523 ··-·medium_severity523 ··-·medium_severity
524 ··-·no_reboot_needed524 ··-·no_reboot_needed
525 ··-·package_sudo_installed525 ··-·package_sudo_installed
526 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
527 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
528 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
529 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
530 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
531 dnf·install·sudo 
532 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
533 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
534 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
535 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
536 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
537 package·--add=sudo 
538 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8526 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
539 [[packages]]527 [[packages]]
540 name·=·"sudo"528 name·=·"sudo"
541 version·=·"*"529 version·=·"*"
542 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
543 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
544 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
545 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
546 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
547 package·install·sudo 
548 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8530 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
549 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low531 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
550 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low532 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
551 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false533 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
552 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable534 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
Max diff block lines reached; 71010/76107 bytes (93.30%) of diff not shown.
650 KB
./usr/share/doc/ssg-nondebian/ssg-rhel10-guide-ism_o_top_secret.html
    
Offset 15195, 207 lines modifiedOffset 15195, 207 lines modified
0003b5a0:·6765·743d·2223·6964·6d37·3330·3822·2074··get="#idm7308"·t0003b5a0:·6765·743d·2223·6964·6d37·3330·3822·2074··get="#idm7308"·t
0003b5b0:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role0003b5b0:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
0003b5c0:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e0003b5c0:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
0003b5d0:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·0003b5d0:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
0003b5e0:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·0003b5e0:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
0003b5f0:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=0003b5f0:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
0003b600:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation0003b600:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
 0003b610:·204f·5342·7569·6c64·2042·6c75·6570·7269···OSBuild·Bluepri
 0003b620:·6e74·2073·6e69·7070·6574·20e2·87b2·3c2f··nt·snippet·...</
 0003b630:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
 0003b640:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
 0003b650:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
 0003b660:·646d·3733·3038·223e·3c70·7265·3e3c·636f··dm7308"><pre><co
 0003b670:·6465·3e0a·5b5b·7061·636b·6167·6573·5d5d··de>.[[packages]]
 0003b680:·0a6e·616d·6520·3d20·2261·6964·6522·0a76··.name·=·"aide".v
 0003b690:·6572·7369·6f6e·203d·2022·2a22·0a3c·2f63··ersion·=·"*".</c
0003b610:·2073·6372·6970·7420·e287·b23c·2f61·3e3c···script·...</a>< 
0003b620:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p 
0003b630:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co 
0003b640:·6c6c·6170·7365·2220·6964·3d22·6964·6d37··llapse"·id="idm7 
0003b650:·3330·3822·3e3c·7461·626c·6520·636c·6173··308"><table·clas 
0003b660:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s 
0003b670:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor 
0003b680:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond 
0003b690:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C 
0003b6a0:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th>< 
0003b6b0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
0003b6c0:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti 
0003b6d0:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low< 
0003b6e0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0003b6f0:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td 
0003b700:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr> 
0003b710:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy 
0003b720:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable 
0003b730:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl 
0003b740:·653e·3c70·7265·3e3c·636f·6465·3e0a·646e··e><pre><code>.dn 
0003b750:·6620·696e·7374·616c·6c20·6169·6465·0a3c··f·install·aide.< 
0003b760:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di0003b6a0:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div>
0003b770:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn·0003b6b0:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt
0003b780:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat0003b6c0:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data-
0003b790:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap0003b6d0:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse
0003b7a0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=0003b6e0:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
0003b7b0:·2223·6964·6d37·3330·3922·2074·6162·696e··"#idm7309"·tabin0003b6f0:·6964·6d37·3330·3922·2074·6162·696e·6465··idm7309"·tabinde
0003b7c0:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu0003b700:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt
0003b7d0:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan0003b710:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande
0003b7e0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl0003b720:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=
0003b7f0:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r0003b730:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev
0003b800:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"0003b740:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R
0003b810:·3e52·656d·6564·6961·7469·6f6e·2041·6e61··>Remediation·Ana 
0003b820:·636f·6e64·6120·736e·6970·7065·7420·e287··conda·snippet·..0003b750:·656d·6564·6961·7469·6f6e·2050·7570·7065··emediation·Puppe
 0003b760:·7420·736e·6970·7065·7420·e287·b23c·2f61··t·snippet·...</a
0003b830:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl0003b770:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
0003b840:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla0003b780:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
0003b850:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id0003b790:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
0003b860:·3d22·6964·6d37·3330·3922·3e3c·7461·626c··="idm7309"><tabl0003b7a0:·6d37·3330·3922·3e3c·7461·626c·6520·636c··m7309"><table·cl
0003b870:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t0003b7b0:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table
0003b880:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab0003b7c0:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b
0003b890:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl0003b7d0:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co
0003b8a0:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr0003b7e0:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th
0003b8b0:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:0003b7f0:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th
0003b8c0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td0003b800:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
0003b8d0:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di0003b810:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup
0003b8e0:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t0003b820:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo
0003b8f0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><0003b830:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
0003b900:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</0003b840:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th><
0003b910:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td0003b850:·7464·3e66·616c·7365·3c2f·7464·3e3c·2f74··td>false</td></t
0003b920:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St0003b860:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate
0003b930:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>0003b870:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab
0003b940:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr> 
0003b950:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co 
0003b960:·6465·3e0a·7061·636b·6167·6520·2d2d·6164··de>.package·--ad 
0003b970:·643d·6169·6465·0a3c·2f63·6f64·653e·3c2f··d=aide.</code></ 
0003b980:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla 
0003b990:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ 
0003b9a0:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle 
0003b9b0:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data 
0003b9c0:·2d74·6172·6765·743d·2223·6964·6d37·3331··-target="#idm731 
0003b9d0:·3022·2074·6162·696e·6465·783d·2230·2220··0"·tabindex="0"· 
0003b9e0:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar 
0003b9f0:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal 
0003ba00:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ 
0003ba10:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h 
0003ba20:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia 
0003ba30:·7469·6f6e·204f·5342·7569·6c64·2042·6c75··tion·OSBuild·Blu 
0003ba40:·6570·7269·6e74·2073·6e69·7070·6574·20e2··eprint·snippet·. 
0003ba50:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c 
0003ba60:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll 
0003ba70:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i 
0003ba80:·643d·2269·646d·3733·3130·223e·3c70·7265··d="idm7310"><pre 
0003ba90:·3e3c·636f·6465·3e0a·5b5b·7061·636b·6167··><code>.[[packag 
0003baa0:·6573·5d5d·0a6e·616d·6520·3d20·2261·6964··es]].name·=·"aid 
0003bab0:·6522·0a76·6572·7369·6f6e·203d·2022·2a22··e".version·=·"*" 
0003bac0:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></ 
0003bad0:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt 
0003bae0:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d 
0003baf0:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll 
0003bb00:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe 
0003bb10:·743d·2223·6964·6d37·3331·3122·2074·6162··t="#idm7311"·tab 
0003bb20:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role=" 
0003bb30:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp 
0003bb40:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti 
0003bb50:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to 
0003bb60:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="# 
0003bb70:·2122·3e52·656d·6564·6961·7469·6f6e·2073··!">Remediation·s 
0003bb80:·6372·6970·7420·e287·b23c·2f61·3e3c·6272··cript·...</a><br 
0003bb90:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan 
0003bba0:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll 
0003bbb0:·6170·7365·2220·6964·3d22·6964·6d37·3331··apse"·id="idm731 
0003bbc0:·3122·3e3c·7461·626c·6520·636c·6173·733d··1"><table·class= 
0003bbd0:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str 
0003bbe0:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde 
0003bbf0:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden 
0003bc00:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com 
0003bc10:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td 
0003bc20:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t 
0003bc30:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption 
0003bc40:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t 
0003bc50:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e52··d></tr><tr><th>R 
0003bc60:·6562·6f6f·743a·3c2f·7468·3e3c·7464·3e66··eboot:</th><td>f 
0003bc70:·616c·7365·3c2f·7464·3e3c·2f74·723e·3c74··alse</td></tr><t0003b880:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta
0003bc80:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:< 
0003bc90:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</ 
0003bca0:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table> 
0003bcb0:·3c70·7265·3e3c·636f·6465·3e0a·7061·636b··<pre><code>.pack 
0003bcc0:·6167·6520·696e·7374·616c·6c20·6169·6465··age·install·aide 
0003bcd0:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></0003b890:·626c·653e·3c70·7265·3e3c·636f·6465·3e69··ble><pre><code>i
 0003b8a0:·6e63·6c75·6465·2069·6e73·7461·6c6c·5f61··nclude·install_a
Max diff block lines reached; 562520/589734 bytes (95.39%) of diff not shown.
74.3 KB
html2text {}
    
Offset 143, 52 lines modifiedOffset 143, 38 lines modified
143 ··-·PCI-DSSv4-11.5.2143 ··-·PCI-DSSv4-11.5.2
144 ··-·enable_strategy144 ··-·enable_strategy
145 ··-·low_complexity145 ··-·low_complexity
146 ··-·low_disruption146 ··-·low_disruption
147 ··-·medium_severity147 ··-·medium_severity
148 ··-·no_reboot_needed148 ··-·no_reboot_needed
149 ··-·package_aide_installed149 ··-·package_aide_installed
150 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
151 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
152 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
153 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
154 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
155 dnf·install·aide 
156 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
157 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
158 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
159 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
160 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
161 package·--add=aide 
162 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8150 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
163 [[packages]]151 [[packages]]
164 name·=·"aide"152 name·=·"aide"
165 version·=·"*"153 version·=·"*"
166 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
167 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
168 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
169 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
170 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
171 package·install·aide 
172 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8154 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
173 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low155 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
174 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low156 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
175 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false157 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
176 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable158 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
177 include·install_aide159 include·install_aide
  
178 class·install_aide·{160 class·install_aide·{
179 ··package·{·'aide':161 ··package·{·'aide':
180 ····ensure·=>·'installed',162 ····ensure·=>·'installed',
181 ··}163 ··}
182 }164 }
 165 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 166 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 167 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 168 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 169 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 170 package·install·aide
183 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8171 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
184 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low172 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
185 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low173 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
186 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false174 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
187 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable175 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
188 #·Remediation·is·applicable·only·in·certain·platforms176 #·Remediation·is·applicable·only·in·certain·platforms
189 if·rpm·--quiet·-q·kernel;·then177 if·rpm·--quiet·-q·kernel;·then
Offset 196, 14 lines modifiedOffset 182, 28 lines modified
196 if·!·rpm·-q·--quiet·"aide"·;·then182 if·!·rpm·-q·--quiet·"aide"·;·then
197 ····dnf·install·-y·"aide"183 ····dnf·install·-y·"aide"
198 fi184 fi
  
199 else185 else
200 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'186 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
201 fi187 fi
 188 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 189 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 190 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 191 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 192 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 193 package·--add=aide
 194 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 195 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 196 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 197 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 198 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 199 dnf·install·aide
202 Group  ·Federal·Information·Processing·Standard·(FIPS)·  Group·contains·2·rules200 Group  ·Federal·Information·Processing·Standard·(FIPS)·  Group·contains·2·rules
203 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·Federal·Information·Processing·Standard·(FIPS)·is·a·computer·security·standard·which·is·developed·by·the·U.S.·Government·and·industry·working·groups·to·validate·the·quality·of·cryptographic·modules.·The·FIPS·standard·provides·four·security·levels·to·ensure·adequate·coverage·of·different·industries,·implementation·of·cryptographic·modules,·and·organizational·sizes·and·requirements.201 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·Federal·Information·Processing·Standard·(FIPS)·is·a·computer·security·standard·which·is·developed·by·the·U.S.·Government·and·industry·working·groups·to·validate·the·quality·of·cryptographic·modules.·The·FIPS·standard·provides·four·security·levels·to·ensure·adequate·coverage·of·different·industries,·implementation·of·cryptographic·modules,·and·organizational·sizes·and·requirements.
  
204 FIPS·140-2·is·the·current·standard·for·validating·that·mechanisms·used·to·access·cryptographic·modules·utilize·authentication·that·meets·industry·and·government·requirements.·For·government·systems,·this·allows·Security·Levels·1,·2,·3,·or·4·for·use·on·Red·Hat·Enterprise·Linux·10.202 FIPS·140-2·is·the·current·standard·for·validating·that·mechanisms·used·to·access·cryptographic·modules·utilize·authentication·that·meets·industry·and·government·requirements.·For·government·systems,·this·allows·Security·Levels·1,·2,·3,·or·4·for·use·on·Red·Hat·Enterprise·Linux·10.
  
205 See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8c\x8c_\x8s\x8s_\x8r\x8r_\x8c\x8c_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8l\x8l_\x8i\x8i_\x8c\x8c_\x8a\x8a_\x8t\x8t_\x8i\x8i_\x8o\x8o_\x8n\x8n_\x8s\x8s_\x8/\x8/_\x8P\x8P_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x8h\x8h_\x8t\x8t_\x8m\x8m_\x8l\x8l·for·more·information.203 See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8c\x8c_\x8s\x8s_\x8r\x8r_\x8c\x8c_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8l\x8l_\x8i\x8i_\x8c\x8c_\x8a\x8a_\x8t\x8t_\x8i\x8i_\x8o\x8o_\x8n\x8n_\x8s\x8s_\x8/\x8/_\x8P\x8P_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x8h\x8h_\x8t\x8t_\x8m\x8m_\x8l\x8l·for·more·information.
206 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8de\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*204 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8de\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
Offset 518, 52 lines modifiedOffset 518, 38 lines modified
518 ··-·PCI-DSSv4-2.2.6518 ··-·PCI-DSSv4-2.2.6
519 ··-·enable_strategy519 ··-·enable_strategy
520 ··-·low_complexity520 ··-·low_complexity
521 ··-·low_disruption521 ··-·low_disruption
522 ··-·medium_severity522 ··-·medium_severity
523 ··-·no_reboot_needed523 ··-·no_reboot_needed
524 ··-·package_sudo_installed524 ··-·package_sudo_installed
525 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
526 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
527 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
528 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
529 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
530 dnf·install·sudo 
531 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
532 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
533 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
534 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
535 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
536 package·--add=sudo 
537 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8525 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
538 [[packages]]526 [[packages]]
539 name·=·"sudo"527 name·=·"sudo"
540 version·=·"*"528 version·=·"*"
541 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
542 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
543 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
544 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
545 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
546 package·install·sudo 
547 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8529 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
548 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low530 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
549 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low531 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
550 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false532 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
551 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable533 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
Max diff block lines reached; 71010/76107 bytes (93.30%) of diff not shown.
655 KB
./usr/share/doc/ssg-nondebian/ssg-rhel10-guide-ospp.html
    
Offset 15474, 203 lines modifiedOffset 15474, 203 lines modified
0003c710:·6765·743d·2223·6964·6d37·3934·3622·2074··get="#idm7946"·t0003c710:·6765·743d·2223·6964·6d37·3934·3622·2074··get="#idm7946"·t
0003c720:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role0003c720:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
0003c730:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e0003c730:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
0003c740:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·0003c740:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
0003c750:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·0003c750:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
0003c760:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=0003c760:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
0003c770:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation0003c770:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
 0003c780:·204f·5342·7569·6c64·2042·6c75·6570·7269···OSBuild·Bluepri
 0003c790:·6e74·2073·6e69·7070·6574·20e2·87b2·3c2f··nt·snippet·...</
 0003c7a0:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
 0003c7b0:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
 0003c7c0:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
 0003c7d0:·646d·3739·3436·223e·3c70·7265·3e3c·636f··dm7946"><pre><co
 0003c7e0:·6465·3e0a·5b5b·7061·636b·6167·6573·5d5d··de>.[[packages]]
 0003c7f0:·0a6e·616d·6520·3d20·2263·7279·7074·6f2d··.name·=·"crypto-
 0003c800:·706f·6c69·6369·6573·220a·7665·7273·696f··policies".versio
 0003c810:·6e20·3d20·222a·220a·3c2f·636f·6465·3e3c··n·=·"*".</code><
0003c780:·2073·6372·6970·7420·e287·b23c·2f61·3e3c···script·...</a>< 
0003c790:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p 
0003c7a0:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co 
0003c7b0:·6c6c·6170·7365·2220·6964·3d22·6964·6d37··llapse"·id="idm7 
0003c7c0:·3934·3622·3e3c·7461·626c·6520·636c·6173··946"><table·clas 
0003c7d0:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s 
0003c7e0:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor 
0003c7f0:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond 
0003c800:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C 
0003c810:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th>< 
0003c820:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
0003c830:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti 
0003c840:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low< 
0003c850:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0003c860:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td 
0003c870:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr> 
0003c880:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy 
0003c890:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable 
0003c8a0:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl 
0003c8b0:·653e·3c70·7265·3e3c·636f·6465·3e0a·646e··e><pre><code>.dn 
0003c8c0:·6620·696e·7374·616c·6c20·6372·7970·746f··f·install·crypto 
0003c8d0:·2d70·6f6c·6963·6965·730a·3c2f·636f·6465··-policies.</code 
0003c8e0:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a·0003c820:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl
0003c8f0:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s0003c830:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc
0003c900:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog0003c840:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl
0003c910:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d0003c850:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat
0003c920:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm0003c860:·612d·7461·7267·6574·3d22·2369·646d·3739··a-target="#idm79
0003c930:·3739·3437·2220·7461·6269·6e64·6578·3d22··7947"·tabindex="0003c870:·3437·2220·7461·6269·6e64·6578·3d22·3022··47"·tabindex="0"
0003c940:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"0003c880:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
0003c950:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="0003c890:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
0003c960:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac0003c8a0:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
0003c970:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal0003c8b0:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
0003c980:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme0003c8c0:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
 0003c8d0:·6174·696f·6e20·5075·7070·6574·2073·6e69··ation·Puppet·sni
0003c990:·6469·6174·696f·6e20·416e·6163·6f6e·6461··diation·Anaconda 
0003c9a0:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a> 
0003c9b0:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class=" 
0003c9c0:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c 
0003c9d0:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm 
0003c9e0:·3739·3437·223e·3c74·6162·6c65·2063·6c61··7947"><table·cla 
0003c9f0:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table- 
0003ca00:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo 
0003ca10:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con 
0003ca20:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th> 
0003ca30:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th> 
0003ca40:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
0003ca50:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt 
0003ca60:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low 
0003ca70:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
0003ca80:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t 
0003ca90:·643e·6661·6c73·653c·2f74·643e·3c2f·7472··d>false</td></tr 
0003caa0:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg 
0003cab0:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl 
0003cac0:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab 
0003cad0:·6c65·3e3c·7072·653e·3c63·6f64·653e·0a70··le><pre><code>.p 
0003cae0:·6163·6b61·6765·202d·2d61·6464·3d63·7279··ackage·--add=cry 
0003caf0:·7074·6f2d·706f·6c69·6369·6573·0a3c·2f63··pto-policies.</c 
0003cb00:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div> 
0003cb10:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt 
0003cb20:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data- 
0003cb30:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse 
0003cb40:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="# 
0003cb50:·6964·6d37·3934·3822·2074·6162·696e·6465··idm7948"·tabinde 
0003cb60:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt 
0003cb70:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande 
0003cb80:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title= 
0003cb90:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev 
0003cba0:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R 
0003cbb0:·656d·6564·6961·7469·6f6e·204f·5342·7569··emediation·OSBui 
0003cbc0:·6c64·2042·6c75·6570·7269·6e74·2073·6e69··ld·Blueprint·sni 
0003cbd0:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>0003c8e0:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>
0003cbe0:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane0003c8f0:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
0003cbf0:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla0003c900:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
0003cc00:·7073·6522·2069·643d·2269·646d·3739·3438··pse"·id="idm79480003c910:·7073·6522·2069·643d·2269·646d·3739·3437··pse"·id="idm7947
0003cc10:·223e·3c70·7265·3e3c·636f·6465·3e0a·5b5b··"><pre><code>.[[ 
0003cc20:·7061·636b·6167·6573·5d5d·0a6e·616d·6520··packages]].name· 
0003cc30:·3d20·2263·7279·7074·6f2d·706f·6c69·6369··=·"crypto-polici 
0003cc40:·6573·220a·7665·7273·696f·6e20·3d20·222a··es".version·=·"* 
0003cc50:·220a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··".</code></pre>< 
0003cc60:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b 
0003cc70:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"· 
0003cc80:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col 
0003cc90:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ 
0003cca0:·6574·3d22·2369·646d·3739·3439·2220·7461··et="#idm7949"·ta 
0003ccb0:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role= 
0003ccc0:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex 
0003ccd0:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t 
0003cce0:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t 
0003ccf0:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href=" 
0003cd00:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation· 
0003cd10:·7363·7269·7074·20e2·87b2·3c2f·613e·3c62··script·...</a><b 
0003cd20:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa 
0003cd30:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col 
0003cd40:·6c61·7073·6522·2069·643d·2269·646d·3739··lapse"·id="idm79 
0003cd50:·3439·223e·3c74·6162·6c65·2063·6c61·7373··49"><table·class0003c920:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="
0003cd60:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st0003c930:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri
0003cd70:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord0003c940:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border
0003cd80:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde0003c950:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens
0003cd90:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co0003c960:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp
0003cda0:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t0003c970:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>
0003cdb0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><0003c980:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
0003cdc0:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio0003c990:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:
0003cdd0:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</0003c9a0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
0003cde0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>0003c9b0:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re
0003cdf0:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td>0003c9c0:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa
0003ce00:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr><0003c9d0:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr
0003ce10:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:0003c9e0:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</
0003ce20:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<0003c9f0:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t
0003ce30:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table0003ca00:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><
0003ce40:·3e3c·7072·653e·3c63·6f64·653e·0a70·6163··><pre><code>.pac 
Max diff block lines reached; 570996/597658 bytes (95.54%) of diff not shown.
71.6 KB
html2text {}
    
Offset 146, 61 lines modifiedOffset 146, 61 lines modified
146 ··-·CCE-89668-8146 ··-·CCE-89668-8
147 ··-·enable_strategy147 ··-·enable_strategy
148 ··-·low_complexity148 ··-·low_complexity
149 ··-·low_disruption149 ··-·low_disruption
150 ··-·medium_severity150 ··-·medium_severity
151 ··-·no_reboot_needed151 ··-·no_reboot_needed
152 ··-·package_crypto-policies_installed152 ··-·package_crypto-policies_installed
153 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
154 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
155 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
156 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
157 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
158 dnf·install·crypto-policies 
159 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
160 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
161 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
162 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
163 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
164 package·--add=crypto-policies 
165 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8153 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
166 [[packages]]154 [[packages]]
167 name·=·"crypto-policies"155 name·=·"crypto-policies"
168 version·=·"*"156 version·=·"*"
169 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
170 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
171 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
172 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
173 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
174 package·install·crypto-policies 
175 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8157 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
176 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low158 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
177 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low159 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
178 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false160 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
179 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable161 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
180 include·install_crypto-policies162 include·install_crypto-policies
  
181 class·install_crypto-policies·{163 class·install_crypto-policies·{
182 ··package·{·'crypto-policies':164 ··package·{·'crypto-policies':
183 ····ensure·=>·'installed',165 ····ensure·=>·'installed',
184 ··}166 ··}
185 }167 }
 168 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 169 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 170 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 171 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 172 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 173 package·install·crypto-policies
186 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8174 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
187 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low175 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
188 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low176 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
189 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false177 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
190 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable178 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
191 if·!·rpm·-q·--quiet·"crypto-policies"·;·then179 if·!·rpm·-q·--quiet·"crypto-policies"·;·then
192 ····dnf·install·-y·"crypto-policies"180 ····dnf·install·-y·"crypto-policies"
193 fi181 fi
 182 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 183 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 184 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 185 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 186 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 187 package·--add=crypto-policies
 188 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 189 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 190 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 191 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 192 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 193 dnf·install·crypto-policies
194 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8og\x8gr\x8ra\x8ap\x8ph\x8hy\x8y·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*194 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8og\x8gr\x8ra\x8ap\x8ph\x8hy\x8y·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
195 To·configure·the·system·cryptography·policy·to·use·ciphers·only·from·the·FIPS:OSPP·policy,·run·the·following·command:195 To·configure·the·system·cryptography·policy·to·use·ciphers·only·from·the·FIPS:OSPP·policy,·run·the·following·command:
196 $·sudo·update-crypto-policies·--set·FIPS:OSPP196 $·sudo·update-crypto-policies·--set·FIPS:OSPP
197 The·rule·checks·if·settings·for·selected·crypto·policy·are·configured·as·expected.·Configuration·files·in·the·/etc/crypto-policies/back-ends·are·either·symlinks·to·correct·files·provided·by·Crypto-policies·package·or·they·are·regular·files·in·case·crypto·policy·customizations·are·applied.·Crypto·policies·may·be·customized·by·crypto·policy·modules,·in·which·case·it·is·delimited·from·the·base·policy·using·a·colon.197 The·rule·checks·if·settings·for·selected·crypto·policy·are·configured·as·expected.·Configuration·files·in·the·/etc/crypto-policies/back-ends·are·either·symlinks·to·correct·files·provided·by·Crypto-policies·package·or·they·are·regular·files·in·case·crypto·policy·customizations·are·applied.·Crypto·policies·may·be·customized·by·crypto·policy·modules,·in·which·case·it·is·delimited·from·the·base·policy·using·a·colon.
198 Warning: ·The·system·needs·to·be·rebooted·for·these·changes·to·take·effect.198 Warning: ·The·system·needs·to·be·rebooted·for·these·changes·to·take·effect.
199 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8n\x8n_\x8v\x8v_\x8l\x8l_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8/\x8/_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8/\x8/_\x8N\x8N_\x8I\x8I_\x8S\x8S_\x8T\x8T_\x8.\x8._\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x81\x81_\x84\x84_\x80\x80_\x8-\x8-_\x82\x82_\x8.\x8._\x8p\x8p_\x8d\x8d_\x8f\x8f·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.199 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8n\x8n_\x8v\x8v_\x8l\x8l_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8/\x8/_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8/\x8/_\x8N\x8N_\x8I\x8I_\x8S\x8S_\x8T\x8T_\x8.\x8._\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x81\x81_\x84\x84_\x80\x80_\x8-\x8-_\x82\x82_\x8.\x8._\x8p\x8p_\x8d\x8d_\x8f\x8f·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.
200 Rationale:···Centralized·cryptographic·policies·simplify·applying·secure·ciphers·across·an·operating·system·and·the·applications·that·run·on·that·operating·system.·Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.200 Rationale:···Centralized·cryptographic·policies·simplify·applying·secure·ciphers·across·an·operating·system·and·the·applications·that·run·on·that·operating·system.·Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.
Offset 530, 29 lines modifiedOffset 530, 29 lines modified
530 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·AU-4,·SC-5(2)530 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·AU-4,·SC-5(2)
531 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-4,·PR.PT-1,·PR.PT-4531 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-4,·PR.PT-1,·PR.PT-4
532 ·············_\x8o_\x8s_\x8p_\x8p···········FMT_SMF_EXT.1532 ·············_\x8o_\x8s_\x8p_\x8p···········FMT_SMF_EXT.1
533 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000341-GPOS-00132,·SRG-OS-000480-GPOS-00227533 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000341-GPOS-00132,·SRG-OS-000480-GPOS-00227
534 ·············_\x8a_\x8p_\x8p_\x8-_\x8s_\x8r_\x8g_\x8-_\x8c_\x8t_\x8r····SRG-APP-000357-CTR-000800534 ·············_\x8a_\x8p_\x8p_\x8-_\x8s_\x8r_\x8g_\x8-_\x8c_\x8t_\x8r····SRG-APP-000357-CTR-000800
535 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R71535 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R71
536 ·············_\x8c_\x8i_\x8s············1.1.2.7.1536 ·············_\x8c_\x8i_\x8s············1.1.2.7.1
537 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
538 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
539 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high 
540 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
541 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
542 part·/var/log/audit 
543 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8537 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
544 [[customizations.filesystem]]538 [[customizations.filesystem]]
545 mountpoint·=·"/var/log/audit"539 mountpoint·=·"/var/log/audit"
546 size·=·10737418240540 size·=·10737418240
547 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8541 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
548 logvol·/var/log/audit·10240542 logvol·/var/log/audit·10240
 543 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 544 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 545 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high
 546 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 547 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 548 part·/var/log/audit
549 Group  ·Sudo·  Group·contains·1·rule549 Group  ·Sudo·  Group·contains·1·rule
550 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Sudo,·which·stands·for·"su·'do'",·provides·the·ability·to·delegate·authority·to·certain·users,·groups·of·users,·or·system·administrators.·When·configured·for·system·users·and/or·groups,·Sudo·can·allow·a·user·or·group·to·execute·privileged·commands·that·normally·only·root·is·allowed·to·execute.550 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Sudo,·which·stands·for·"su·'do'",·provides·the·ability·to·delegate·authority·to·certain·users,·groups·of·users,·or·system·administrators.·When·configured·for·system·users·and/or·groups,·Sudo·can·allow·a·user·or·group·to·execute·privileged·commands·that·normally·only·root·is·allowed·to·execute.
  
551 For·more·information·on·Sudo·and·addition·Sudo·configuration·options,·see·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8w\x8w_\x8w\x8w_\x8w\x8w_\x8.\x8._\x8s\x8s_\x8u\x8u_\x8d\x8d_\x8o\x8o_\x8.\x8._\x8w\x8w_\x8s\x8s.551 For·more·information·on·Sudo·and·addition·Sudo·configuration·options,·see·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8w\x8w_\x8w\x8w_\x8w\x8w_\x8.\x8._\x8s\x8s_\x8u\x8u_\x8d\x8d_\x8o\x8o_\x8.\x8._\x8w\x8w_\x8s\x8s.
552 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·s\x8su\x8ud\x8do\x8o·P\x8Pa\x8ac\x8ck\x8ka\x8ag\x8ge\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*552 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·s\x8su\x8ud\x8do\x8o·P\x8Pa\x8ac\x8ck\x8ka\x8ag\x8ge\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
553 The·sudo·package·can·be·installed·with·the·following·command:553 The·sudo·package·can·be·installed·with·the·following·command:
554 $·sudo·dnf·install·sudo554 $·sudo·dnf·install·sudo
Offset 600, 52 lines modifiedOffset 600, 38 lines modified
600 ··-·PCI-DSSv4-2.2.6600 ··-·PCI-DSSv4-2.2.6
601 ··-·enable_strategy601 ··-·enable_strategy
602 ··-·low_complexity602 ··-·low_complexity
603 ··-·low_disruption603 ··-·low_disruption
604 ··-·medium_severity604 ··-·medium_severity
605 ··-·no_reboot_needed605 ··-·no_reboot_needed
606 ··-·package_sudo_installed606 ··-·package_sudo_installed
Max diff block lines reached; 65509/73247 bytes (89.44%) of diff not shown.
610 KB
./usr/share/doc/ssg-nondebian/ssg-rhel10-guide-pci-dss.html
    
Offset 16774, 208 lines modifiedOffset 16774, 208 lines modified
00041850:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe00041850:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
00041860:·743d·2223·6964·6d37·3330·3822·2074·6162··t="#idm7308"·tab00041860:·743d·2223·6964·6d37·3330·3822·2074·6162··t="#idm7308"·tab
00041870:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="00041870:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
00041880:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp00041880:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
00041890:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti00041890:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
000418a0:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to000418a0:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
000418b0:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#000418b0:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
000418c0:·2122·3e52·656d·6564·6961·7469·6f6e·2073··!">Remediation·s000418c0:·2122·3e52·656d·6564·6961·7469·6f6e·204f··!">Remediation·O
 000418d0:·5342·7569·6c64·2042·6c75·6570·7269·6e74··SBuild·Blueprint
 000418e0:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>
 000418f0:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="
 00041900:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c
 00041910:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm
 00041920:·3733·3038·223e·3c70·7265·3e3c·636f·6465··7308"><pre><code
 00041930:·3e0a·5b5b·7061·636b·6167·6573·5d5d·0a6e··>.[[packages]].n
 00041940:·616d·6520·3d20·2261·6964·6522·0a76·6572··ame·=·"aide".ver
 00041950:·7369·6f6e·203d·2022·2a22·0a3c·2f63·6f64··sion·=·"*".</cod
000418d0:·6372·6970·7420·e287·b23c·2f61·3e3c·6272··cript·...</a><br 
000418e0:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan 
000418f0:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll 
00041900:·6170·7365·2220·6964·3d22·6964·6d37·3330··apse"·id="idm730 
00041910:·3822·3e3c·7461·626c·6520·636c·6173·733d··8"><table·class= 
00041920:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str 
00041930:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde 
00041940:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden 
00041950:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com 
00041960:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td 
00041970:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t 
00041980:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption 
00041990:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t 
000419a0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e52··d></tr><tr><th>R 
000419b0:·6562·6f6f·743a·3c2f·7468·3e3c·7464·3e66··eboot:</th><td>f 
000419c0:·616c·7365·3c2f·7464·3e3c·2f74·723e·3c74··alse</td></tr><t 
000419d0:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:< 
000419e0:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</ 
000419f0:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table> 
00041a00:·3c70·7265·3e3c·636f·6465·3e0a·646e·6620··<pre><code>.dnf· 
00041a10:·696e·7374·616c·6c20·6169·6465·0a3c·2f63··install·aide.</c 
00041a20:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div>00041960:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a
00041a30:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt00041970:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn-
00041a40:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data-00041980:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to
00041a50:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse00041990:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"·
00041a60:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#000419a0:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
00041a70:·6964·6d37·3330·3922·2074·6162·696e·6465··idm7309"·tabinde000419b0:·6d37·3330·3922·2074·6162·696e·6465·783d··m7309"·tabindex=
00041a80:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt000419c0:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button
00041a90:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande000419d0:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=
00041aa0:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=000419e0:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A
00041ab0:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev000419f0:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea
00041ac0:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R00041a00:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem
00041ad0:·656d·6564·6961·7469·6f6e·2041·6e61·636f··emediation·Anaco00041a10:·6564·6961·7469·6f6e·2050·7570·7065·7420··ediation·Puppet·
00041ae0:·6e64·6120·736e·6970·7065·7420·e287·b23c··nda·snippet·...<00041a20:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><
00041af0:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas00041a30:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
00041b00:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps00041a40:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
00041b10:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="00041a50:·6c6c·6170·7365·2220·6964·3d22·6964·6d37··llapse"·id="idm7
00041b20:·6964·6d37·3330·3922·3e3c·7461·626c·6520··idm7309"><table·00041a60:·3330·3922·3e3c·7461·626c·6520·636c·6173··309"><table·clas
00041b30:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab00041a70:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s
00041b40:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table00041a80:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor
00041b50:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-00041a90:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond
00041b60:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><00041aa0:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C
00041b70:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</00041ab0:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><
00041b80:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><00041ac0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
00041b90:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr00041ad0:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti
00041ba0:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>00041ae0:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<
00041bb0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr00041af0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
00041bc0:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th00041b00:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td
00041bd0:·3e3c·7464·3e66·616c·7365·3c2f·7464·3e3c··><td>false</td>< 
00041be0:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra 
00041bf0:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en 
00041c00:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></00041b10:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr>
 00041b20:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy
 00041b30:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable
 00041b40:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl
00041c10:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code00041b50:·653e·3c70·7265·3e3c·636f·6465·3e69·6e63··e><pre><code>inc
 00041b60:·6c75·6465·2069·6e73·7461·6c6c·5f61·6964··lude·install_aid
 00041b70:·650a·0a63·6c61·7373·2069·6e73·7461·6c6c··e..class·install
 00041b80:·5f61·6964·6520·7b0a·2020·7061·636b·6167··_aide·{.··packag
 00041b90:·6520·7b20·2761·6964·6527·3a0a·2020·2020··e·{·'aide':.····
 00041ba0:·656e·7375·7265·203d·2667·743b·2027·696e··ensure·=&gt;·'in
 00041bb0:·7374·616c·6c65·6427·2c0a·2020·7d0a·7d0a··stalled',.··}.}.
 00041bc0:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d
00041c20:·3e0a·7061·636b·6167·6520·2d2d·6164·643d··>.package·--add= 
00041c30:·6169·6465·0a3c·2f63·6f64·653e·3c2f·7072··aide.</code></pr 
00041c40:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class 
00041c50:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes 
00041c60:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle=" 
00041c70:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t 
00041c80:·6172·6765·743d·2223·6964·6d37·3331·3022··arget="#idm7310" 
00041c90:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro 
00041ca0:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria 
00041cb0:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false 
00041cc0:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat 
00041cd0:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre 
00041ce0:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati 
00041cf0:·6f6e·204f·5342·7569·6c64·2042·6c75·6570··on·OSBuild·Bluep 
00041d00:·7269·6e74·2073·6e69·7070·6574·20e2·87b2··rint·snippet·... 
00041d10:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla 
00041d20:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap 
00041d30:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id= 
00041d40:·2269·646d·3733·3130·223e·3c70·7265·3e3c··"idm7310"><pre>< 
00041d50:·636f·6465·3e0a·5b5b·7061·636b·6167·6573··code>.[[packages 
00041d60:·5d5d·0a6e·616d·6520·3d20·2261·6964·6522··]].name·=·"aide" 
00041d70:·0a76·6572·7369·6f6e·203d·2022·2a22·0a3c··.version·=·"*".< 
00041d80:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di 
00041d90:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn·00041bd0:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn
00041da0:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat 
00041db0:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap 
00041dc0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target= 
00041dd0:·2223·6964·6d37·3331·3122·2074·6162·696e··"#idm7311"·tabin 
00041de0:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu 
00041df0:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan 
00041e00:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl 
00041e10:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r 
00041e20:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!" 
00041e30:·3e52·656d·6564·6961·7469·6f6e·2073·6372··>Remediation·scr 
00041e40:·6970·7420·e287·b23c·2f61·3e3c·6272·3e3c··ipt·...</a><br>< 
00041e50:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel 
00041e60:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap 
00041e70:·7365·2220·6964·3d22·6964·6d37·3331·3122··se"·id="idm7311" 
00041e80:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t 
00041e90:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip00041be0:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da
 00041bf0:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla
 00041c00:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
 00041c10:·3d22·2369·646d·3733·3130·2220·7461·6269··="#idm7310"·tabi
 00041c20:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
 00041c30:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
 00041c40:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
 00041c50:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
Max diff block lines reached; 524354/551706 bytes (95.04%) of diff not shown.
70.6 KB
html2text {}
    
Offset 549, 52 lines modifiedOffset 549, 38 lines modified
549 ··-·PCI-DSSv4-11.5.2549 ··-·PCI-DSSv4-11.5.2
550 ··-·enable_strategy550 ··-·enable_strategy
551 ··-·low_complexity551 ··-·low_complexity
552 ··-·low_disruption552 ··-·low_disruption
553 ··-·medium_severity553 ··-·medium_severity
554 ··-·no_reboot_needed554 ··-·no_reboot_needed
555 ··-·package_aide_installed555 ··-·package_aide_installed
556 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
557 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
558 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
559 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
560 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
561 dnf·install·aide 
562 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
563 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
564 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
565 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
566 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
567 package·--add=aide 
568 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8556 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
569 [[packages]]557 [[packages]]
570 name·=·"aide"558 name·=·"aide"
571 version·=·"*"559 version·=·"*"
572 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
573 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
574 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
575 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
576 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
577 package·install·aide 
578 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8560 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
579 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low561 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
580 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low562 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
581 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false563 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
582 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable564 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
583 include·install_aide565 include·install_aide
  
584 class·install_aide·{566 class·install_aide·{
585 ··package·{·'aide':567 ··package·{·'aide':
586 ····ensure·=>·'installed',568 ····ensure·=>·'installed',
587 ··}569 ··}
588 }570 }
 571 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 572 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 573 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 574 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 575 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 576 package·install·aide
589 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8577 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
590 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low578 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
591 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low579 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
592 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false580 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
593 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable581 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
594 #·Remediation·is·applicable·only·in·certain·platforms582 #·Remediation·is·applicable·only·in·certain·platforms
595 if·rpm·--quiet·-q·kernel;·then583 if·rpm·--quiet·-q·kernel;·then
Offset 602, 14 lines modifiedOffset 588, 28 lines modified
602 if·!·rpm·-q·--quiet·"aide"·;·then588 if·!·rpm·-q·--quiet·"aide"·;·then
603 ····dnf·install·-y·"aide"589 ····dnf·install·-y·"aide"
604 fi590 fi
  
605 else591 else
606 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'592 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
607 fi593 fi
 594 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 595 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 596 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 597 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 598 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 599 package·--add=aide
 600 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 601 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 602 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 603 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 604 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 605 dnf·install·aide
608 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*606 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
609 Run·the·following·command·to·generate·a·new·database:607 Run·the·following·command·to·generate·a·new·database:
610 $·sudo·/usr/sbin/aide·--init608 $·sudo·/usr/sbin/aide·--init
611 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:609 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
612 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz610 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
613 To·initiate·a·manual·check,·run·the·following·command:611 To·initiate·a·manual·check,·run·the·following·command:
614 $·sudo·/usr/sbin/aide·--check612 $·sudo·/usr/sbin/aide·--check
Offset 2786, 52 lines modifiedOffset 2786, 38 lines modified
2786 ··-·PCI-DSSv4-2.2.62786 ··-·PCI-DSSv4-2.2.6
2787 ··-·enable_strategy2787 ··-·enable_strategy
2788 ··-·low_complexity2788 ··-·low_complexity
2789 ··-·low_disruption2789 ··-·low_disruption
2790 ··-·medium_severity2790 ··-·medium_severity
2791 ··-·no_reboot_needed2791 ··-·no_reboot_needed
2792 ··-·package_sudo_installed2792 ··-·package_sudo_installed
2793 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
2794 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
2795 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
2796 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
2797 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
2798 dnf·install·sudo 
2799 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
2800 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
2801 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
2802 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
2803 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
2804 package·--add=sudo 
2805 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x82793 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
2806 [[packages]]2794 [[packages]]
2807 name·=·"sudo"2795 name·=·"sudo"
2808 version·=·"*"2796 version·=·"*"
2809 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
2810 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
2811 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
2812 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
2813 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
2814 package·install·sudo 
2815 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x82797 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
2816 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low2798 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
2817 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low2799 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
2818 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false2800 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
2819 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable2801 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
Max diff block lines reached; 67585/72280 bytes (93.50%) of diff not shown.
1.86 MB
./usr/share/doc/ssg-nondebian/ssg-rhel10-guide-stig.html
    
Offset 15202, 207 lines modifiedOffset 15202, 207 lines modified
0003b610:·2d74·6172·6765·743d·2223·6964·6d37·3330··-target="#idm7300003b610:·2d74·6172·6765·743d·2223·6964·6d37·3330··-target="#idm730
0003b620:·3822·2074·6162·696e·6465·783d·2230·2220··8"·tabindex="0"·0003b620:·3822·2074·6162·696e·6465·783d·2230·2220··8"·tabindex="0"·
0003b630:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar0003b630:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar
0003b640:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal0003b640:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal
0003b650:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ0003b650:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ
0003b660:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h0003b660:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h
0003b670:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia0003b670:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia
 0003b680:·7469·6f6e·204f·5342·7569·6c64·2042·6c75··tion·OSBuild·Blu
 0003b690:·6570·7269·6e74·2073·6e69·7070·6574·20e2··eprint·snippet·.
 0003b6a0:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c
 0003b6b0:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
 0003b6c0:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
 0003b6d0:·643d·2269·646d·3733·3038·223e·3c70·7265··d="idm7308"><pre
 0003b6e0:·3e3c·636f·6465·3e0a·5b5b·7061·636b·6167··><code>.[[packag
 0003b6f0:·6573·5d5d·0a6e·616d·6520·3d20·2261·6964··es]].name·=·"aid
 0003b700:·6522·0a76·6572·7369·6f6e·203d·2022·2a22··e".version·=·"*"
0003b680:·7469·6f6e·2073·6372·6970·7420·e287·b23c··tion·script·...< 
0003b690:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas 
0003b6a0:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps 
0003b6b0:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id=" 
0003b6c0:·6964·6d37·3330·3822·3e3c·7461·626c·6520··idm7308"><table· 
0003b6d0:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab 
0003b6e0:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table 
0003b6f0:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table- 
0003b700:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr>< 
0003b710:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</ 
0003b720:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td>< 
0003b730:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr 
0003b740:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td> 
0003b750:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr 
0003b760:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th 
0003b770:·3e3c·7464·3e66·616c·7365·3c2f·7464·3e3c··><td>false</td>< 
0003b780:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra 
0003b790:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en 
0003b7a0:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></ 
0003b7b0:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code 
0003b7c0:·3e0a·646e·6620·696e·7374·616c·6c20·6169··>.dnf·install·ai 
0003b7d0:·6465·0a3c·2f63·6f64·653e·3c2f·7072·653e··de.</code></pre>0003b710:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></
0003b7e0:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class="0003b720:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt
0003b7f0:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success"0003b730:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d
0003b800:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co0003b740:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll
0003b810:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar0003b750:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
0003b820:·6765·743d·2223·6964·6d37·3330·3922·2074··get="#idm7309"·t0003b760:·743d·2223·6964·6d37·3330·3922·2074·6162··t="#idm7309"·tab
0003b830:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role0003b770:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
0003b840:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e0003b780:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
0003b850:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·0003b790:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
0003b860:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·0003b7a0:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
0003b870:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=0003b7b0:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
0003b880:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation0003b7c0:·2122·3e52·656d·6564·6961·7469·6f6e·2050··!">Remediation·P
0003b890:·2041·6e61·636f·6e64·6120·736e·6970·7065···Anaconda·snippe 
0003b8a0:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di 
0003b8b0:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c 
0003b8c0:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse 
0003b8d0:·2220·6964·3d22·6964·6d37·3330·3922·3e3c··"·id="idm7309">< 
0003b8e0:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab 
0003b8f0:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped 
0003b900:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered· 
0003b910:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed" 
0003b920:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex 
0003b930:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low 
0003b940:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
0003b950:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t 
0003b960:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></ 
0003b970:·7472·3e3c·7472·3e3c·7468·3e52·6562·6f6f··tr><tr><th>Reboo 
0003b980:·743a·3c2f·7468·3e3c·7464·3e66·616c·7365··t:</th><td>false 
0003b990:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
0003b9a0:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th> 
0003b9b0:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td>< 
0003b9c0:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre 
0003b9d0:·3e3c·636f·6465·3e0a·7061·636b·6167·6520··><code>.package· 
0003b9e0:·2d2d·6164·643d·6169·6465·0a3c·2f63·6f64··--add=aide.</cod 
0003b9f0:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a 
0003ba00:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn- 
0003ba10:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to 
0003ba20:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"· 
0003ba30:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id 
0003ba40:·6d37·3331·3022·2074·6162·696e·6465·783d··m7310"·tabindex= 
0003ba50:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button 
0003ba60:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded= 
0003ba70:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A 
0003ba80:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea 
0003ba90:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem 
0003baa0:·6564·6961·7469·6f6e·204f·5342·7569·6c64··ediation·OSBuild 
0003bab0:·2042·6c75·6570·7269·6e74·2073·6e69·7070···Blueprint·snipp 
0003bac0:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d 
0003bad0:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel- 
0003bae0:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps 
0003baf0:·6522·2069·643d·2269·646d·3733·3130·223e··e"·id="idm7310"> 
0003bb00:·3c70·7265·3e3c·636f·6465·3e0a·5b5b·7061··<pre><code>.[[pa 
0003bb10:·636b·6167·6573·5d5d·0a6e·616d·6520·3d20··ckages]].name·=· 
0003bb20:·2261·6964·6522·0a76·6572·7369·6f6e·203d··"aide".version·= 
0003bb30:·2022·2a22·0a3c·2f63·6f64·653e·3c2f·7072···"*".</code></pr 
0003bb40:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class 
0003bb50:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes 
0003bb60:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle=" 
0003bb70:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t 
0003bb80:·6172·6765·743d·2223·6964·6d37·3331·3122··arget="#idm7311" 
0003bb90:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro 
0003bba0:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria 
0003bbb0:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false 
0003bbc0:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat 
0003bbd0:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre 
0003bbe0:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati 
0003bbf0:·6f6e·2073·6372·6970·7420·e287·b23c·2f61··on·script·...</a 
0003bc00:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class= 
0003bc10:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse· 
0003bc20:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id 
0003bc30:·6d37·3331·3122·3e3c·7461·626c·6520·636c··m7311"><table·cl 
0003bc40:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table 
0003bc50:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b 
0003bc60:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co 
0003bc70:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th 
0003bc80:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th 
0003bc90:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t 
0003bca0:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup 
0003bcb0:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo 
0003bcc0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr>< 
0003bcd0:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th>< 
0003bce0:·7464·3e66·616c·7365·3c2f·7464·3e3c·2f74··td>false</td></t 
0003bcf0:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate 
0003bd00:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab 
0003bd10:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta 
0003bd20:·626c·653e·3c70·7265·3e3c·636f·6465·3e0a··ble><pre><code>. 
0003bd30:·7061·636b·6167·6520·696e·7374·616c·6c20··package·install· 
0003bd40:·6169·6465·0a3c·2f63·6f64·653e·3c2f·7072··aide.</code></pr 
0003bd50:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class 
0003bd60:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes 
Max diff block lines reached; 1720995/1748209 bytes (98.44%) of diff not shown.
195 KB
html2text {}
    
Offset 143, 52 lines modifiedOffset 143, 38 lines modified
143 ··-·PCI-DSSv4-11.5.2143 ··-·PCI-DSSv4-11.5.2
144 ··-·enable_strategy144 ··-·enable_strategy
145 ··-·low_complexity145 ··-·low_complexity
146 ··-·low_disruption146 ··-·low_disruption
147 ··-·medium_severity147 ··-·medium_severity
148 ··-·no_reboot_needed148 ··-·no_reboot_needed
149 ··-·package_aide_installed149 ··-·package_aide_installed
150 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
151 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
152 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
153 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
154 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
155 dnf·install·aide 
156 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
157 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
158 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
159 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
160 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
161 package·--add=aide 
162 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8150 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
163 [[packages]]151 [[packages]]
164 name·=·"aide"152 name·=·"aide"
165 version·=·"*"153 version·=·"*"
166 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
167 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
168 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
169 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
170 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
171 package·install·aide 
172 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8154 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
173 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low155 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
174 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low156 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
175 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false157 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
176 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable158 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
177 include·install_aide159 include·install_aide
  
178 class·install_aide·{160 class·install_aide·{
179 ··package·{·'aide':161 ··package·{·'aide':
180 ····ensure·=>·'installed',162 ····ensure·=>·'installed',
181 ··}163 ··}
182 }164 }
 165 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 166 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 167 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 168 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 169 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 170 package·install·aide
183 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8171 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
184 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low172 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
185 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low173 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
186 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false174 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
187 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable175 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
188 #·Remediation·is·applicable·only·in·certain·platforms176 #·Remediation·is·applicable·only·in·certain·platforms
189 if·rpm·--quiet·-q·kernel;·then177 if·rpm·--quiet·-q·kernel;·then
Offset 196, 14 lines modifiedOffset 182, 28 lines modified
196 if·!·rpm·-q·--quiet·"aide"·;·then182 if·!·rpm·-q·--quiet·"aide"·;·then
197 ····dnf·install·-y·"aide"183 ····dnf·install·-y·"aide"
198 fi184 fi
  
199 else185 else
200 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'186 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
201 fi187 fi
 188 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 189 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 190 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 191 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 192 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 193 package·--add=aide
 194 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 195 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 196 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 197 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 198 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 199 dnf·install·aide
202 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*200 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
203 Run·the·following·command·to·generate·a·new·database:201 Run·the·following·command·to·generate·a·new·database:
204 $·sudo·/usr/sbin/aide·--init202 $·sudo·/usr/sbin/aide·--init
205 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:203 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
206 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz204 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
207 To·initiate·a·manual·check,·run·the·following·command:205 To·initiate·a·manual·check,·run·the·following·command:
208 $·sudo·/usr/sbin/aide·--check206 $·sudo·/usr/sbin/aide·--check
Offset 2107, 61 lines modifiedOffset 2107, 61 lines modified
2107 ··-·CCE-89668-82107 ··-·CCE-89668-8
2108 ··-·enable_strategy2108 ··-·enable_strategy
2109 ··-·low_complexity2109 ··-·low_complexity
2110 ··-·low_disruption2110 ··-·low_disruption
2111 ··-·medium_severity2111 ··-·medium_severity
2112 ··-·no_reboot_needed2112 ··-·no_reboot_needed
2113 ··-·package_crypto-policies_installed2113 ··-·package_crypto-policies_installed
2114 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
2115 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
2116 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
2117 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
2118 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
2119 dnf·install·crypto-policies 
2120 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
2121 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
2122 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
2123 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
2124 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
2125 package·--add=crypto-policies 
2126 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x82114 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
2127 [[packages]]2115 [[packages]]
2128 name·=·"crypto-policies"2116 name·=·"crypto-policies"
2129 version·=·"*"2117 version·=·"*"
2130 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
2131 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
2132 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
2133 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
2134 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
2135 package·install·crypto-policies 
2136 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x82118 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
2137 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low2119 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
2138 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low2120 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
2139 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false2121 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
2140 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable2122 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
Max diff block lines reached; 195082/199839 bytes (97.62%) of diff not shown.
1.81 MB
./usr/share/doc/ssg-nondebian/ssg-rhel10-guide-stig_gui.html
    
Offset 15197, 207 lines modifiedOffset 15197, 207 lines modified
0003b5c0:·7461·2d74·6172·6765·743d·2223·6964·6d37··ta-target="#idm70003b5c0:·7461·2d74·6172·6765·743d·2223·6964·6d37··ta-target="#idm7
0003b5d0:·3330·3822·2074·6162·696e·6465·783d·2230··308"·tabindex="00003b5d0:·3330·3822·2074·6162·696e·6465·783d·2230··308"·tabindex="0
0003b5e0:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·0003b5e0:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
0003b5f0:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f0003b5f0:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
0003b600:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act0003b600:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
0003b610:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"0003b610:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
0003b620:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed0003b620:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
 0003b630:·6961·7469·6f6e·204f·5342·7569·6c64·2042··iation·OSBuild·B
 0003b640:·6c75·6570·7269·6e74·2073·6e69·7070·6574··lueprint·snippet
 0003b650:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
 0003b660:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
 0003b670:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
 0003b680:·2069·643d·2269·646d·3733·3038·223e·3c70···id="idm7308"><p
 0003b690:·7265·3e3c·636f·6465·3e0a·5b5b·7061·636b··re><code>.[[pack
 0003b6a0:·6167·6573·5d5d·0a6e·616d·6520·3d20·2261··ages]].name·=·"a
 0003b6b0:·6964·6522·0a76·6572·7369·6f6e·203d·2022··ide".version·=·"
0003b630:·6961·7469·6f6e·2073·6372·6970·7420·e287··iation·script·.. 
0003b640:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl 
0003b650:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla 
0003b660:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id 
0003b670:·3d22·6964·6d37·3330·3822·3e3c·7461·626c··="idm7308"><tabl 
0003b680:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t 
0003b690:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab 
0003b6a0:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl 
0003b6b0:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr 
0003b6c0:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity: 
0003b6d0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td 
0003b6e0:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di 
0003b6f0:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t 
0003b700:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr>< 
0003b710:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</ 
0003b720:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td 
0003b730:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St 
0003b740:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td> 
0003b750:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr> 
0003b760:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co 
0003b770:·6465·3e0a·646e·6620·696e·7374·616c·6c20··de>.dnf·install· 
0003b780:·6169·6465·0a3c·2f63·6f64·653e·3c2f·7072··aide.</code></pr0003b6c0:·2a22·0a3c·2f63·6f64·653e·3c2f·7072·653e··*".</code></pre>
0003b790:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class0003b6d0:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class="
0003b7a0:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes0003b6e0:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success"
0003b7b0:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle="0003b6f0:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co
0003b7c0:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t0003b700:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar
0003b7d0:·6172·6765·743d·2223·6964·6d37·3330·3922··arget="#idm7309"0003b710:·6765·743d·2223·6964·6d37·3330·3922·2074··get="#idm7309"·t
0003b7e0:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro0003b720:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
0003b7f0:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria0003b730:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
0003b800:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false0003b740:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
0003b810:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat0003b750:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
0003b820:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre0003b760:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
0003b830:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati0003b770:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
0003b840:·6f6e·2041·6e61·636f·6e64·6120·736e·6970··on·Anaconda·snip0003b780:·2050·7570·7065·7420·736e·6970·7065·7420···Puppet·snippet·
0003b850:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br><0003b790:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·
0003b860:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel0003b7a0:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col
0003b870:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap0003b7b0:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·
0003b880:·7365·2220·6964·3d22·6964·6d37·3330·3922··se"·id="idm7309"0003b7c0:·6964·3d22·6964·6d37·3330·3922·3e3c·7461··id="idm7309"><ta
0003b890:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t 
0003b8a0:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip 
0003b8b0:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere 
0003b8c0:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense 
0003b8d0:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl 
0003b8e0:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l 
0003b8f0:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr> 
0003b900:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:< 
0003b910:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td> 
0003b920:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb 
0003b930:·6f6f·743a·3c2f·7468·3e3c·7464·3e66·616c··oot:</th><td>fal 
0003b940:·7365·3c2f·7464·3e3c·2f74·723e·3c74·723e··se</td></tr><tr> 
0003b950:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t 
0003b960:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td 
0003b970:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p 
0003b980:·7265·3e3c·636f·6465·3e0a·7061·636b·6167··re><code>.packag 
0003b990:·6520·2d2d·6164·643d·6169·6465·0a3c·2f63··e·--add=aide.</c 
0003b9a0:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div> 
0003b9b0:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt 
0003b9c0:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data- 
0003b9d0:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse 
0003b9e0:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="# 
0003b9f0:·6964·6d37·3331·3022·2074·6162·696e·6465··idm7310"·tabinde 
0003ba00:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt 
0003ba10:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande 
0003ba20:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title= 
0003ba30:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev 
0003ba40:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R 
0003ba50:·656d·6564·6961·7469·6f6e·204f·5342·7569··emediation·OSBui 
0003ba60:·6c64·2042·6c75·6570·7269·6e74·2073·6e69··ld·Blueprint·sni 
0003ba70:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br> 
0003ba80:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane 
0003ba90:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla 
0003baa0:·7073·6522·2069·643d·2269·646d·3733·3130··pse"·id="idm7310 
0003bab0:·223e·3c70·7265·3e3c·636f·6465·3e0a·5b5b··"><pre><code>.[[ 
0003bac0:·7061·636b·6167·6573·5d5d·0a6e·616d·6520··packages]].name· 
0003bad0:·3d20·2261·6964·6522·0a76·6572·7369·6f6e··=·"aide".version 
0003bae0:·203d·2022·2a22·0a3c·2f63·6f64·653e·3c2f···=·"*".</code></ 
0003baf0:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla 
0003bb00:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ 
0003bb10:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle 
0003bb20:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data 
0003bb30:·2d74·6172·6765·743d·2223·6964·6d37·3331··-target="#idm731 
0003bb40:·3122·2074·6162·696e·6465·783d·2230·2220··1"·tabindex="0"· 
0003bb50:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar 
0003bb60:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal 
0003bb70:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ 
0003bb80:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h 
0003bb90:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia 
0003bba0:·7469·6f6e·2073·6372·6970·7420·e287·b23c··tion·script·...< 
0003bbb0:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas 
0003bbc0:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps 
0003bbd0:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id=" 
0003bbe0:·6964·6d37·3331·3122·3e3c·7461·626c·6520··idm7311"><table· 
0003bbf0:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab 
0003bc00:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table 
0003bc10:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table- 
0003bc20:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr>< 
0003bc30:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</ 
0003bc40:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td>< 
0003bc50:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr 
0003bc60:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td> 
0003bc70:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr 
0003bc80:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th 
0003bc90:·3e3c·7464·3e66·616c·7365·3c2f·7464·3e3c··><td>false</td>< 
0003bca0:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra 
0003bcb0:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en 
0003bcc0:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></ 
0003bcd0:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code 
0003bce0:·3e0a·7061·636b·6167·6520·696e·7374·616c··>.package·instal 
0003bcf0:·6c20·6169·6465·0a3c·2f63·6f64·653e·3c2f··l·aide.</code></ 
0003bd00:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla 
0003bd10:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ 
Max diff block lines reached; 1673810/1701024 bytes (98.40%) of diff not shown.
189 KB
html2text {}
    
Offset 142, 52 lines modifiedOffset 142, 38 lines modified
142 ··-·PCI-DSSv4-11.5.2142 ··-·PCI-DSSv4-11.5.2
143 ··-·enable_strategy143 ··-·enable_strategy
144 ··-·low_complexity144 ··-·low_complexity
145 ··-·low_disruption145 ··-·low_disruption
146 ··-·medium_severity146 ··-·medium_severity
147 ··-·no_reboot_needed147 ··-·no_reboot_needed
148 ··-·package_aide_installed148 ··-·package_aide_installed
149 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
150 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
151 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
152 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
153 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
154 dnf·install·aide 
155 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
156 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
157 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
158 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
159 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
160 package·--add=aide 
161 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8149 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
162 [[packages]]150 [[packages]]
163 name·=·"aide"151 name·=·"aide"
164 version·=·"*"152 version·=·"*"
165 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
166 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
167 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
168 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
169 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
170 package·install·aide 
171 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8153 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
172 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low154 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
173 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low155 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
174 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false156 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
175 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable157 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
176 include·install_aide158 include·install_aide
  
177 class·install_aide·{159 class·install_aide·{
178 ··package·{·'aide':160 ··package·{·'aide':
179 ····ensure·=>·'installed',161 ····ensure·=>·'installed',
180 ··}162 ··}
181 }163 }
 164 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 165 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 166 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 167 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 168 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 169 package·install·aide
182 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8170 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
183 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low171 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
184 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low172 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
185 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false173 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
186 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable174 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
187 #·Remediation·is·applicable·only·in·certain·platforms175 #·Remediation·is·applicable·only·in·certain·platforms
188 if·rpm·--quiet·-q·kernel;·then176 if·rpm·--quiet·-q·kernel;·then
Offset 195, 14 lines modifiedOffset 181, 28 lines modified
195 if·!·rpm·-q·--quiet·"aide"·;·then181 if·!·rpm·-q·--quiet·"aide"·;·then
196 ····dnf·install·-y·"aide"182 ····dnf·install·-y·"aide"
197 fi183 fi
  
198 else184 else
199 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'185 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
200 fi186 fi
 187 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 188 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 189 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 190 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 191 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 192 package·--add=aide
 193 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 194 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 195 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 196 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 197 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 198 dnf·install·aide
201 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*199 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
202 Run·the·following·command·to·generate·a·new·database:200 Run·the·following·command·to·generate·a·new·database:
203 $·sudo·/usr/sbin/aide·--init201 $·sudo·/usr/sbin/aide·--init
204 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:202 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
205 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz203 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
206 To·initiate·a·manual·check,·run·the·following·command:204 To·initiate·a·manual·check,·run·the·following·command:
207 $·sudo·/usr/sbin/aide·--check205 $·sudo·/usr/sbin/aide·--check
Offset 2106, 61 lines modifiedOffset 2106, 61 lines modified
2106 ··-·CCE-89668-82106 ··-·CCE-89668-8
2107 ··-·enable_strategy2107 ··-·enable_strategy
2108 ··-·low_complexity2108 ··-·low_complexity
2109 ··-·low_disruption2109 ··-·low_disruption
2110 ··-·medium_severity2110 ··-·medium_severity
2111 ··-·no_reboot_needed2111 ··-·no_reboot_needed
2112 ··-·package_crypto-policies_installed2112 ··-·package_crypto-policies_installed
2113 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
2114 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
2115 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
2116 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
2117 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
2118 dnf·install·crypto-policies 
2119 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
2120 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
2121 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
2122 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
2123 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
2124 package·--add=crypto-policies 
2125 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x82113 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
2126 [[packages]]2114 [[packages]]
2127 name·=·"crypto-policies"2115 name·=·"crypto-policies"
2128 version·=·"*"2116 version·=·"*"
2129 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
2130 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
2131 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
2132 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
2133 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
2134 package·install·crypto-policies 
2135 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x82117 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
2136 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low2118 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
2137 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low2119 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
2138 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false2120 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
2139 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable2121 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
Max diff block lines reached; 188482/193239 bytes (97.54%) of diff not shown.
1.18 MB
./usr/share/doc/ssg-nondebian/ssg-rhel8-guide-anssi_bp28_enhanced.html
    
Offset 15324, 207 lines modifiedOffset 15324, 207 lines modified
0003bdb0:·7267·6574·3d22·2369·646d·3739·3931·2220··rget="#idm7991"·0003bdb0:·7267·6574·3d22·2369·646d·3739·3931·2220··rget="#idm7991"·
0003bdc0:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol0003bdc0:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol
0003bdd0:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-0003bdd0:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-
0003bde0:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"0003bde0:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"
0003bdf0:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate0003bdf0:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate
0003be00:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href0003be00:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href
0003be10:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio0003be10:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio
 0003be20:·6e20·4f53·4275·696c·6420·426c·7565·7072··n·OSBuild·Bluepr
 0003be30:·696e·7420·736e·6970·7065·7420·e287·b23c··int·snippet·...<
 0003be40:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas
 0003be50:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps
 0003be60:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="
 0003be70:·6964·6d37·3939·3122·3e3c·7072·653e·3c63··idm7991"><pre><c
 0003be80:·6f64·653e·0a5b·5b70·6163·6b61·6765·735d··ode>.[[packages]
 0003be90:·5d0a·6e61·6d65·203d·2022·6169·6465·220a··].name·=·"aide".
 0003bea0:·7665·7273·696f·6e20·3d20·222a·220a·3c2f··version·=·"*".</
0003be20:·6e20·7363·7269·7074·20e2·87b2·3c2f·613e··n·script·...</a> 
0003be30:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class=" 
0003be40:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c 
0003be50:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm 
0003be60:·3739·3931·223e·3c74·6162·6c65·2063·6c61··7991"><table·cla 
0003be70:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table- 
0003be80:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo 
0003be90:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con 
0003bea0:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th> 
0003beb0:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th> 
0003bec0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
0003bed0:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt 
0003bee0:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low 
0003bef0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
0003bf00:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t 
0003bf10:·643e·6661·6c73·653c·2f74·643e·3c2f·7472··d>false</td></tr 
0003bf20:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg 
0003bf30:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl 
0003bf40:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab 
0003bf50:·6c65·3e3c·7072·653e·3c63·6f64·653e·0a64··le><pre><code>.d 
0003bf60:·6e66·2069·6e73·7461·6c6c·2061·6964·650a··nf·install·aide. 
0003bf70:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d0003beb0:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div
0003bf80:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn0003bec0:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b
0003bf90:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da0003bed0:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data
0003bfa0:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla0003bee0:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps
0003bfb0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target0003bef0:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
0003bfc0:·3d22·2369·646d·3739·3932·2220·7461·6269··="#idm7992"·tabi0003bf00:·2369·646d·3739·3932·2220·7461·6269·6e64··#idm7992"·tabind
0003bfd0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b0003bf10:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
0003bfe0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa0003bf20:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
0003bff0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit0003bf30:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
0003c000:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·0003bf40:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
0003c010:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!0003bf50:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
0003c020:·223e·5265·6d65·6469·6174·696f·6e20·416e··">Remediation·An0003bf60:·5265·6d65·6469·6174·696f·6e20·5075·7070··Remediation·Pupp
0003c030:·6163·6f6e·6461·2073·6e69·7070·6574·20e2··aconda·snippet·. 
0003c040:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c 
0003c050:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll 
0003c060:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i 
0003c070:·643d·2269·646d·3739·3932·223e·3c74·6162··d="idm7992"><tab0003bf70:·6574·2073·6e69·7070·6574·20e2·87b2·3c2f··et·snippet·...</
 0003bf80:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
 0003bf90:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
 0003bfa0:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
 0003bfb0:·646d·3739·3932·223e·3c74·6162·6c65·2063··dm7992"><table·c
0003c080:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·0003bfc0:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl
0003c090:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta 
0003c0a0:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab0003bfd0:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-
 0003bfe0:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c
0003c0b0:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t0003bff0:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t
0003c0c0:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity0003c000:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t
0003c0d0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t0003c010:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
0003c0e0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D0003c020:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru
0003c0f0:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><0003c030:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l
0003c100:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>0003c040:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
0003c110:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:<0003c050:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th>
0003c120:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t0003c060:·3c74·643e·6661·6c73·653c·2f74·643e·3c2f··<td>false</td></
0003c130:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S0003c070:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat
0003c140:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td0003c080:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena
0003c150:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr 
0003c160:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c 
0003c170:·6f64·653e·0a70·6163·6b61·6765·202d·2d61··ode>.package·--a 
0003c180:·6464·3d61·6964·650a·3c2f·636f·6465·3e3c··dd=aide.</code>< 
0003c190:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl 
0003c1a0:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc 
0003c1b0:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl 
0003c1c0:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat 
0003c1d0:·612d·7461·7267·6574·3d22·2369·646d·3739··a-target="#idm79 
0003c1e0:·3933·2220·7461·6269·6e64·6578·3d22·3022··93"·tabindex="0" 
0003c1f0:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a 
0003c200:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa 
0003c210:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti 
0003c220:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"· 
0003c230:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi 
0003c240:·6174·696f·6e20·4f53·4275·696c·6420·426c··ation·OSBuild·Bl 
0003c250:·7565·7072·696e·7420·736e·6970·7065·7420··ueprint·snippet· 
0003c260:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div· 
0003c270:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col 
0003c280:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"· 
0003c290:·6964·3d22·6964·6d37·3939·3322·3e3c·7072··id="idm7993"><pr 
0003c2a0:·653e·3c63·6f64·653e·0a5b·5b70·6163·6b61··e><code>.[[packa 
0003c2b0:·6765·735d·5d0a·6e61·6d65·203d·2022·6169··ges]].name·=·"ai 
0003c2c0:·6465·220a·7665·7273·696f·6e20·3d20·222a··de".version·=·"* 
0003c2d0:·220a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··".</code></pre>< 
0003c2e0:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b 
0003c2f0:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"· 
0003c300:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col 
0003c310:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ 
0003c320:·6574·3d22·2369·646d·3739·3934·2220·7461··et="#idm7994"·ta 
0003c330:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role= 
0003c340:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex 
0003c350:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t 
0003c360:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t 
0003c370:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href=" 
0003c380:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation· 
0003c390:·7363·7269·7074·20e2·87b2·3c2f·613e·3c62··script·...</a><b 
0003c3a0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa 
0003c3b0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col 
0003c3c0:·6c61·7073·6522·2069·643d·2269·646d·3739··lapse"·id="idm79 
0003c3d0:·3934·223e·3c74·6162·6c65·2063·6c61·7373··94"><table·class 
0003c3e0:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st 
0003c3f0:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord 
0003c400:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde 
0003c410:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co 
0003c420:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t 
0003c430:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr>< 
0003c440:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio 
0003c450:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</ 
0003c460:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
0003c470:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td> 
0003c480:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr><0003c090:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t
0003c490:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy: 
0003c4a0:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable< 
0003c4b0:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table 
Max diff block lines reached; 1082286/1109500 bytes (97.55%) of diff not shown.
122 KB
html2text {}
    
Offset 155, 52 lines modifiedOffset 155, 38 lines modified
155 ··-·PCI-DSSv4-11.5.2155 ··-·PCI-DSSv4-11.5.2
156 ··-·enable_strategy156 ··-·enable_strategy
157 ··-·low_complexity157 ··-·low_complexity
158 ··-·low_disruption158 ··-·low_disruption
159 ··-·medium_severity159 ··-·medium_severity
160 ··-·no_reboot_needed160 ··-·no_reboot_needed
161 ··-·package_aide_installed161 ··-·package_aide_installed
162 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
163 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
164 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
165 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
166 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
167 dnf·install·aide 
168 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
169 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
170 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
171 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
172 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
173 package·--add=aide 
174 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8162 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
175 [[packages]]163 [[packages]]
176 name·=·"aide"164 name·=·"aide"
177 version·=·"*"165 version·=·"*"
178 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
179 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
180 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
181 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
182 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
183 package·install·aide 
184 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8166 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
185 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low167 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
186 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low168 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
187 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false169 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
188 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable170 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
189 include·install_aide171 include·install_aide
  
190 class·install_aide·{172 class·install_aide·{
191 ··package·{·'aide':173 ··package·{·'aide':
192 ····ensure·=>·'installed',174 ····ensure·=>·'installed',
193 ··}175 ··}
194 }176 }
 177 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 178 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 179 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 180 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 181 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 182 package·install·aide
195 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8183 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
196 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low184 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
197 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low185 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
198 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false186 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
199 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable187 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
200 #·Remediation·is·applicable·only·in·certain·platforms188 #·Remediation·is·applicable·only·in·certain·platforms
201 if·rpm·--quiet·-q·kernel;·then189 if·rpm·--quiet·-q·kernel;·then
Offset 208, 14 lines modifiedOffset 194, 28 lines modified
208 if·!·rpm·-q·--quiet·"aide"·;·then194 if·!·rpm·-q·--quiet·"aide"·;·then
209 ····yum·install·-y·"aide"195 ····yum·install·-y·"aide"
210 fi196 fi
  
211 else197 else
212 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'198 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
213 fi199 fi
 200 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 201 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 202 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 203 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 204 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 205 package·--add=aide
 206 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 207 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 208 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 209 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 210 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 211 dnf·install·aide
214 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*212 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
215 Run·the·following·command·to·generate·a·new·database:213 Run·the·following·command·to·generate·a·new·database:
216 $·sudo·/usr/sbin/aide·--init214 $·sudo·/usr/sbin/aide·--init
217 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:215 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
218 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz216 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
219 To·initiate·a·manual·check,·run·the·following·command:217 To·initiate·a·manual·check,·run·the·following·command:
220 $·sudo·/usr/sbin/aide·--check218 $·sudo·/usr/sbin/aide·--check
Offset 364, 26 lines modifiedOffset 364, 26 lines modified
364 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/b\x8bo\x8oo\x8ot\x8t·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*364 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/b\x8bo\x8oo\x8ot\x8t·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
365 It·is·recommended·that·the·/boot·directory·resides·on·a·separate·partition.·This·makes·it·easier·to·apply·restrictions·e.g.·through·the·noexec·mount·option.·Eventually,·the·/boot·partition·can·be·configured·not·to·be·mounted·automatically·with·the·noauto·mount·option.365 It·is·recommended·that·the·/boot·directory·resides·on·a·separate·partition.·This·makes·it·easier·to·apply·restrictions·e.g.·through·the·noexec·mount·option.·Eventually,·the·/boot·partition·can·be·configured·not·to·be·mounted·automatically·with·the·noauto·mount·option.
366 Rationale:···The·/boot·partition·contains·the·kernel·and·bootloader·files.·Access·to·this·partition·should·be·restricted.366 Rationale:···The·/boot·partition·contains·the·kernel·and·bootloader·files.·Access·to·this·partition·should·be·restricted.
367 Severity: ···medium367 Severity: ···medium
368 Rule·ID:·····xccdf_org.ssgproject.content_rule_partition_for_boot368 Rule·ID:·····xccdf_org.ssgproject.content_rule_partition_for_boot
369 Identifiers:·CCE-83336-8369 Identifiers:·CCE-83336-8
370 References:··_\x8a_\x8n_\x8s_\x8s_\x8i·R28370 References:··_\x8a_\x8n_\x8s_\x8s_\x8i·R28
 371 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 372 [[customizations.filesystem]]
 373 mountpoint·=·"/boot"
 374 size·=·1073741824
371 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8375 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
372 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low376 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
373 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high377 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high
374 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false378 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
375 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable379 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
376 part·/boot380 part·/boot
377 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
378 [[customizations.filesystem]] 
379 mountpoint·=·"/boot" 
380 size·=·1073741824 
381 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/h\x8ho\x8om\x8me\x8e·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*381 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/h\x8ho\x8om\x8me\x8e·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
382 If·user·home·directories·will·be·stored·locally,·create·a·separate·partition·for·/home·at·installation·time·(or·migrate·it·later·using·LVM).·If·/home·will·be·mounted·from·another·system·such·as·an·NFS·server,·then·creating·a·separate·partition·is·not·necessary·at·installation·time,·and·the·mountpoint·can·instead·be·configured·later.382 If·user·home·directories·will·be·stored·locally,·create·a·separate·partition·for·/home·at·installation·time·(or·migrate·it·later·using·LVM).·If·/home·will·be·mounted·from·another·system·such·as·an·NFS·server,·then·creating·a·separate·partition·is·not·necessary·at·installation·time,·and·the·mountpoint·can·instead·be·configured·later.
383 Rationale:···Ensuring·that·/home·is·mounted·on·its·own·partition·enables·the·setting·of·more·restrictive·mount·options,·and·also·helps·ensure·that·users·cannot·trivially·fill·partitions·used·for·log·or·audit·data·storage.383 Rationale:···Ensuring·that·/home·is·mounted·on·its·own·partition·enables·the·setting·of·more·restrictive·mount·options,·and·also·helps·ensure·that·users·cannot·trivially·fill·partitions·used·for·log·or·audit·data·storage.
384 Severity: ···low384 Severity: ···low
385 Rule·ID:·····xccdf_org.ssgproject.content_rule_partition_for_home385 Rule·ID:·····xccdf_org.ssgproject.content_rule_partition_for_home
386 Identifiers:·CCE-81044-0386 Identifiers:·CCE-81044-0
387 ·············_\x8c_\x8i_\x8s_\x8-_\x8c_\x8s_\x8c········12,·15,·8387 ·············_\x8c_\x8i_\x8s_\x8-_\x8c_\x8s_\x8c········12,·15,·8
Offset 394, 95 lines modifiedOffset 394, 95 lines modified
394 References:··_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)394 References:··_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)
395 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4395 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4
396 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227396 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
397 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-08-010800397 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-08-010800
398 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R28398 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R28
399 ·············_\x8c_\x8i_\x8s············1.1.2.3.1399 ·············_\x8c_\x8i_\x8s············1.1.2.3.1
Max diff block lines reached; 119206/125284 bytes (95.15%) of diff not shown.
1.27 MB
./usr/share/doc/ssg-nondebian/ssg-rhel8-guide-anssi_bp28_high.html
    
Offset 15329, 207 lines modifiedOffset 15329, 207 lines modified
0003be00:·2d74·6172·6765·743d·2223·6964·6d37·3939··-target="#idm7990003be00:·2d74·6172·6765·743d·2223·6964·6d37·3939··-target="#idm799
0003be10:·3122·2074·6162·696e·6465·783d·2230·2220··1"·tabindex="0"·0003be10:·3122·2074·6162·696e·6465·783d·2230·2220··1"·tabindex="0"·
0003be20:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar0003be20:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar
0003be30:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal0003be30:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal
0003be40:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ0003be40:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ
0003be50:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h0003be50:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h
0003be60:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia0003be60:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia
 0003be70:·7469·6f6e·204f·5342·7569·6c64·2042·6c75··tion·OSBuild·Blu
 0003be80:·6570·7269·6e74·2073·6e69·7070·6574·20e2··eprint·snippet·.
 0003be90:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c
 0003bea0:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
 0003beb0:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
 0003bec0:·643d·2269·646d·3739·3931·223e·3c70·7265··d="idm7991"><pre
 0003bed0:·3e3c·636f·6465·3e0a·5b5b·7061·636b·6167··><code>.[[packag
 0003bee0:·6573·5d5d·0a6e·616d·6520·3d20·2261·6964··es]].name·=·"aid
 0003bef0:·6522·0a76·6572·7369·6f6e·203d·2022·2a22··e".version·=·"*"
0003be70:·7469·6f6e·2073·6372·6970·7420·e287·b23c··tion·script·...< 
0003be80:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas 
0003be90:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps 
0003bea0:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id=" 
0003beb0:·6964·6d37·3939·3122·3e3c·7461·626c·6520··idm7991"><table· 
0003bec0:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab 
0003bed0:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table 
0003bee0:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table- 
0003bef0:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr>< 
0003bf00:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</ 
0003bf10:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td>< 
0003bf20:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr 
0003bf30:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td> 
0003bf40:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr 
0003bf50:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th 
0003bf60:·3e3c·7464·3e66·616c·7365·3c2f·7464·3e3c··><td>false</td>< 
0003bf70:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra 
0003bf80:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en 
0003bf90:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></ 
0003bfa0:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code 
0003bfb0:·3e0a·646e·6620·696e·7374·616c·6c20·6169··>.dnf·install·ai 
0003bfc0:·6465·0a3c·2f63·6f64·653e·3c2f·7072·653e··de.</code></pre>0003bf00:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></
0003bfd0:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class="0003bf10:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt
0003bfe0:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success"0003bf20:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d
0003bff0:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co0003bf30:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll
0003c000:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar0003bf40:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
0003c010:·6765·743d·2223·6964·6d37·3939·3222·2074··get="#idm7992"·t0003bf50:·743d·2223·6964·6d37·3939·3222·2074·6162··t="#idm7992"·tab
0003c020:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role0003bf60:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
0003c030:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e0003bf70:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
0003c040:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·0003bf80:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
0003c050:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·0003bf90:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
0003c060:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=0003bfa0:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
0003c070:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation0003bfb0:·2122·3e52·656d·6564·6961·7469·6f6e·2050··!">Remediation·P
0003c080:·2041·6e61·636f·6e64·6120·736e·6970·7065···Anaconda·snippe0003bfc0:·7570·7065·7420·736e·6970·7065·7420·e287··uppet·snippet·..
0003c090:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di0003bfd0:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl
0003c0a0:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c0003bfe0:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla
0003c0b0:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse0003bff0:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id
0003c0c0:·2220·6964·3d22·6964·6d37·3939·3222·3e3c··"·id="idm7992"><0003c000:·3d22·6964·6d37·3939·3222·3e3c·7461·626c··="idm7992"><tabl
0003c0d0:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab0003c010:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t
0003c0e0:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped0003c020:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab
0003c0f0:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·0003c030:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl
0003c100:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed" 
0003c110:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex 
0003c120:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low 
0003c130:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
0003c140:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t 
0003c150:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></ 
0003c160:·7472·3e3c·7472·3e3c·7468·3e52·6562·6f6f··tr><tr><th>Reboo 
0003c170:·743a·3c2f·7468·3e3c·7464·3e66·616c·7365··t:</th><td>false 
0003c180:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
0003c190:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th> 
0003c1a0:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td>< 
0003c1b0:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre 
0003c1c0:·3e3c·636f·6465·3e0a·7061·636b·6167·6520··><code>.package· 
0003c1d0:·2d2d·6164·643d·6169·6465·0a3c·2f63·6f64··--add=aide.</cod 
0003c1e0:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a 
0003c1f0:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn- 
0003c200:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to 
0003c210:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"· 
0003c220:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id 
0003c230:·6d37·3939·3322·2074·6162·696e·6465·783d··m7993"·tabindex= 
0003c240:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button 
0003c250:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded= 
0003c260:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A 
0003c270:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea 
0003c280:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem 
0003c290:·6564·6961·7469·6f6e·204f·5342·7569·6c64··ediation·OSBuild 
0003c2a0:·2042·6c75·6570·7269·6e74·2073·6e69·7070···Blueprint·snipp 
0003c2b0:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d 
0003c2c0:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel- 
0003c2d0:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps 
0003c2e0:·6522·2069·643d·2269·646d·3739·3933·223e··e"·id="idm7993"> 
0003c2f0:·3c70·7265·3e3c·636f·6465·3e0a·5b5b·7061··<pre><code>.[[pa 
0003c300:·636b·6167·6573·5d5d·0a6e·616d·6520·3d20··ckages]].name·=· 
0003c310:·2261·6964·6522·0a76·6572·7369·6f6e·203d··"aide".version·= 
0003c320:·2022·2a22·0a3c·2f63·6f64·653e·3c2f·7072···"*".</code></pr 
0003c330:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class 
0003c340:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes 
0003c350:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle=" 
0003c360:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t 
0003c370:·6172·6765·743d·2223·6964·6d37·3939·3422··arget="#idm7994" 
0003c380:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro 
0003c390:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria 
0003c3a0:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false 
0003c3b0:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat 
0003c3c0:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre 
0003c3d0:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati 
0003c3e0:·6f6e·2073·6372·6970·7420·e287·b23c·2f61··on·script·...</a 
0003c3f0:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class= 
0003c400:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse· 
0003c410:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id 
0003c420:·6d37·3939·3422·3e3c·7461·626c·6520·636c··m7994"><table·cl 
0003c430:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table 
0003c440:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b 
0003c450:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co 
0003c460:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th0003c040:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr
0003c470:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th0003c050:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:
0003c480:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t0003c060:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
0003c490:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup0003c070:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di
0003c4a0:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo0003c080:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t
0003c4b0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><0003c090:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
0003c4c0:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th><0003c0a0:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</
0003c4d0:·7464·3e66·616c·7365·3c2f·7464·3e3c·2f74··td>false</td></t0003c0b0:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td
0003c4e0:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate0003c0c0:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St
0003c4f0:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab0003c0d0:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>
0003c500:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta0003c0e0:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr>
0003c510:·626c·653e·3c70·7265·3e3c·636f·6465·3e0a··ble><pre><code>.0003c0f0:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co
0003c520:·7061·636b·6167·6520·696e·7374·616c·6c20··package·install· 
0003c530:·6169·6465·0a3c·2f63·6f64·653e·3c2f·7072··aide.</code></pr 
0003c540:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class0003c100:·6465·3e69·6e63·6c75·6465·2069·6e73·7461··de>include·insta
 0003c110:·6c6c·5f61·6964·650a·0a63·6c61·7373·2069··ll_aide..class·i
Max diff block lines reached; 1165521/1192735 bytes (97.72%) of diff not shown.
132 KB
html2text {}
    
Offset 156, 52 lines modifiedOffset 156, 38 lines modified
156 ··-·PCI-DSSv4-11.5.2156 ··-·PCI-DSSv4-11.5.2
157 ··-·enable_strategy157 ··-·enable_strategy
158 ··-·low_complexity158 ··-·low_complexity
159 ··-·low_disruption159 ··-·low_disruption
160 ··-·medium_severity160 ··-·medium_severity
161 ··-·no_reboot_needed161 ··-·no_reboot_needed
162 ··-·package_aide_installed162 ··-·package_aide_installed
163 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
164 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
165 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
166 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
167 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
168 dnf·install·aide 
169 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
170 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
171 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
172 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
173 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
174 package·--add=aide 
175 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8163 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
176 [[packages]]164 [[packages]]
177 name·=·"aide"165 name·=·"aide"
178 version·=·"*"166 version·=·"*"
179 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
180 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
181 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
182 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
183 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
184 package·install·aide 
185 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8167 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
186 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low168 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
187 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low169 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
188 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false170 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
189 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable171 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
190 include·install_aide172 include·install_aide
  
191 class·install_aide·{173 class·install_aide·{
192 ··package·{·'aide':174 ··package·{·'aide':
193 ····ensure·=>·'installed',175 ····ensure·=>·'installed',
194 ··}176 ··}
195 }177 }
 178 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 179 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 180 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 181 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 182 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 183 package·install·aide
196 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8184 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
197 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low185 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
198 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low186 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
199 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false187 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
200 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable188 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
201 #·Remediation·is·applicable·only·in·certain·platforms189 #·Remediation·is·applicable·only·in·certain·platforms
202 if·rpm·--quiet·-q·kernel;·then190 if·rpm·--quiet·-q·kernel;·then
Offset 209, 14 lines modifiedOffset 195, 28 lines modified
209 if·!·rpm·-q·--quiet·"aide"·;·then195 if·!·rpm·-q·--quiet·"aide"·;·then
210 ····yum·install·-y·"aide"196 ····yum·install·-y·"aide"
211 fi197 fi
  
212 else198 else
213 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'199 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
214 fi200 fi
 201 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 202 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 203 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 204 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 205 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 206 package·--add=aide
 207 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 208 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 209 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 210 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 211 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 212 dnf·install·aide
215 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*213 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
216 Run·the·following·command·to·generate·a·new·database:214 Run·the·following·command·to·generate·a·new·database:
217 $·sudo·/usr/sbin/aide·--init215 $·sudo·/usr/sbin/aide·--init
218 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:216 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
219 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz217 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
220 To·initiate·a·manual·check,·run·the·following·command:218 To·initiate·a·manual·check,·run·the·following·command:
221 $·sudo·/usr/sbin/aide·--check219 $·sudo·/usr/sbin/aide·--check
Offset 892, 26 lines modifiedOffset 892, 26 lines modified
892 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/b\x8bo\x8oo\x8ot\x8t·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*892 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/b\x8bo\x8oo\x8ot\x8t·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
893 It·is·recommended·that·the·/boot·directory·resides·on·a·separate·partition.·This·makes·it·easier·to·apply·restrictions·e.g.·through·the·noexec·mount·option.·Eventually,·the·/boot·partition·can·be·configured·not·to·be·mounted·automatically·with·the·noauto·mount·option.893 It·is·recommended·that·the·/boot·directory·resides·on·a·separate·partition.·This·makes·it·easier·to·apply·restrictions·e.g.·through·the·noexec·mount·option.·Eventually,·the·/boot·partition·can·be·configured·not·to·be·mounted·automatically·with·the·noauto·mount·option.
894 Rationale:···The·/boot·partition·contains·the·kernel·and·bootloader·files.·Access·to·this·partition·should·be·restricted.894 Rationale:···The·/boot·partition·contains·the·kernel·and·bootloader·files.·Access·to·this·partition·should·be·restricted.
895 Severity: ···medium895 Severity: ···medium
896 Rule·ID:·····xccdf_org.ssgproject.content_rule_partition_for_boot896 Rule·ID:·····xccdf_org.ssgproject.content_rule_partition_for_boot
897 Identifiers:·CCE-83336-8897 Identifiers:·CCE-83336-8
898 References:··_\x8a_\x8n_\x8s_\x8s_\x8i·R28898 References:··_\x8a_\x8n_\x8s_\x8s_\x8i·R28
 899 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 900 [[customizations.filesystem]]
 901 mountpoint·=·"/boot"
 902 size·=·1073741824
899 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8903 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
900 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low904 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
901 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high905 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high
902 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false906 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
903 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable907 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
904 part·/boot908 part·/boot
905 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
906 [[customizations.filesystem]] 
907 mountpoint·=·"/boot" 
908 size·=·1073741824 
909 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/h\x8ho\x8om\x8me\x8e·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*909 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/h\x8ho\x8om\x8me\x8e·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
910 If·user·home·directories·will·be·stored·locally,·create·a·separate·partition·for·/home·at·installation·time·(or·migrate·it·later·using·LVM).·If·/home·will·be·mounted·from·another·system·such·as·an·NFS·server,·then·creating·a·separate·partition·is·not·necessary·at·installation·time,·and·the·mountpoint·can·instead·be·configured·later.910 If·user·home·directories·will·be·stored·locally,·create·a·separate·partition·for·/home·at·installation·time·(or·migrate·it·later·using·LVM).·If·/home·will·be·mounted·from·another·system·such·as·an·NFS·server,·then·creating·a·separate·partition·is·not·necessary·at·installation·time,·and·the·mountpoint·can·instead·be·configured·later.
911 Rationale:···Ensuring·that·/home·is·mounted·on·its·own·partition·enables·the·setting·of·more·restrictive·mount·options,·and·also·helps·ensure·that·users·cannot·trivially·fill·partitions·used·for·log·or·audit·data·storage.911 Rationale:···Ensuring·that·/home·is·mounted·on·its·own·partition·enables·the·setting·of·more·restrictive·mount·options,·and·also·helps·ensure·that·users·cannot·trivially·fill·partitions·used·for·log·or·audit·data·storage.
912 Severity: ···low912 Severity: ···low
913 Rule·ID:·····xccdf_org.ssgproject.content_rule_partition_for_home913 Rule·ID:·····xccdf_org.ssgproject.content_rule_partition_for_home
914 Identifiers:·CCE-81044-0914 Identifiers:·CCE-81044-0
915 ·············_\x8c_\x8i_\x8s_\x8-_\x8c_\x8s_\x8c········12,·15,·8915 ·············_\x8c_\x8i_\x8s_\x8-_\x8c_\x8s_\x8c········12,·15,·8
Offset 922, 95 lines modifiedOffset 922, 95 lines modified
922 References:··_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)922 References:··_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)
923 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4923 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4
924 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227924 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
925 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-08-010800925 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-08-010800
926 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R28926 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R28
927 ·············_\x8c_\x8i_\x8s············1.1.2.3.1927 ·············_\x8c_\x8i_\x8s············1.1.2.3.1
Max diff block lines reached; 129254/135332 bytes (95.51%) of diff not shown.
1.07 MB
./usr/share/doc/ssg-nondebian/ssg-rhel8-guide-anssi_bp28_intermediary.html
    
Offset 15319, 208 lines modifiedOffset 15319, 208 lines modified
0003bd60:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe0003bd60:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
0003bd70:·743d·2223·6964·6d37·3939·3122·2074·6162··t="#idm7991"·tab0003bd70:·743d·2223·6964·6d37·3939·3122·2074·6162··t="#idm7991"·tab
0003bd80:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="0003bd80:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
0003bd90:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp0003bd90:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
0003bda0:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti0003bda0:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
0003bdb0:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to0003bdb0:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
0003bdc0:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#0003bdc0:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
0003bdd0:·2122·3e52·656d·6564·6961·7469·6f6e·2073··!">Remediation·s0003bdd0:·2122·3e52·656d·6564·6961·7469·6f6e·204f··!">Remediation·O
 0003bde0:·5342·7569·6c64·2042·6c75·6570·7269·6e74··SBuild·Blueprint
 0003bdf0:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>
 0003be00:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="
 0003be10:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c
 0003be20:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm
 0003be30:·3739·3931·223e·3c70·7265·3e3c·636f·6465··7991"><pre><code
 0003be40:·3e0a·5b5b·7061·636b·6167·6573·5d5d·0a6e··>.[[packages]].n
 0003be50:·616d·6520·3d20·2261·6964·6522·0a76·6572··ame·=·"aide".ver
 0003be60:·7369·6f6e·203d·2022·2a22·0a3c·2f63·6f64··sion·=·"*".</cod
0003bde0:·6372·6970·7420·e287·b23c·2f61·3e3c·6272··cript·...</a><br 
0003bdf0:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan 
0003be00:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll 
0003be10:·6170·7365·2220·6964·3d22·6964·6d37·3939··apse"·id="idm799 
0003be20:·3122·3e3c·7461·626c·6520·636c·6173·733d··1"><table·class= 
0003be30:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str 
0003be40:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde 
0003be50:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden 
0003be60:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com 
0003be70:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td 
0003be80:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t 
0003be90:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption 
0003bea0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t 
0003beb0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e52··d></tr><tr><th>R 
0003bec0:·6562·6f6f·743a·3c2f·7468·3e3c·7464·3e66··eboot:</th><td>f 
0003bed0:·616c·7365·3c2f·7464·3e3c·2f74·723e·3c74··alse</td></tr><t 
0003bee0:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:< 
0003bef0:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</ 
0003bf00:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table> 
0003bf10:·3c70·7265·3e3c·636f·6465·3e0a·646e·6620··<pre><code>.dnf· 
0003bf20:·696e·7374·616c·6c20·6169·6465·0a3c·2f63··install·aide.</c 
0003bf30:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div>0003be70:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a
0003bf40:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt0003be80:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn-
0003bf50:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data-0003be90:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to
0003bf60:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse0003bea0:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"·
0003bf70:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#0003beb0:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
0003bf80:·6964·6d37·3939·3222·2074·6162·696e·6465··idm7992"·tabinde0003bec0:·6d37·3939·3222·2074·6162·696e·6465·783d··m7992"·tabindex=
0003bf90:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt0003bed0:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button
0003bfa0:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande0003bee0:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=
0003bfb0:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=0003bef0:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A
0003bfc0:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev0003bf00:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea
0003bfd0:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R0003bf10:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem
0003bfe0:·656d·6564·6961·7469·6f6e·2041·6e61·636f··emediation·Anaco0003bf20:·6564·6961·7469·6f6e·2050·7570·7065·7420··ediation·Puppet·
0003bff0:·6e64·6120·736e·6970·7065·7420·e287·b23c··nda·snippet·...<0003bf30:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><
0003c000:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas 
0003c010:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps0003bf40:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
 0003bf50:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
0003c020:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="0003bf60:·6c6c·6170·7365·2220·6964·3d22·6964·6d37··llapse"·id="idm7
0003c030:·6964·6d37·3939·3222·3e3c·7461·626c·6520··idm7992"><table·0003bf70:·3939·3222·3e3c·7461·626c·6520·636c·6173··992"><table·clas
0003c040:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab 
0003c050:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table 
0003c060:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table- 
0003c070:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><0003bf80:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s
 0003bf90:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor
 0003bfa0:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond
 0003bfb0:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C
0003c080:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</0003bfc0:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><
0003c090:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td>< 
0003c0a0:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr0003bfd0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
 0003bfe0:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti
0003c0b0:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>0003bff0:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<
0003c0c0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr0003c000:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
0003c0d0:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th0003c010:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td
0003c0e0:·3e3c·7464·3e66·616c·7365·3c2f·7464·3e3c··><td>false</td>< 
0003c0f0:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra 
0003c100:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en 
0003c110:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></0003c020:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr>
 0003c030:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy
 0003c040:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable
 0003c050:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl
0003c120:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code0003c060:·653e·3c70·7265·3e3c·636f·6465·3e69·6e63··e><pre><code>inc
 0003c070:·6c75·6465·2069·6e73·7461·6c6c·5f61·6964··lude·install_aid
 0003c080:·650a·0a63·6c61·7373·2069·6e73·7461·6c6c··e..class·install
 0003c090:·5f61·6964·6520·7b0a·2020·7061·636b·6167··_aide·{.··packag
 0003c0a0:·6520·7b20·2761·6964·6527·3a0a·2020·2020··e·{·'aide':.····
 0003c0b0:·656e·7375·7265·203d·2667·743b·2027·696e··ensure·=&gt;·'in
 0003c0c0:·7374·616c·6c65·6427·2c0a·2020·7d0a·7d0a··stalled',.··}.}.
 0003c0d0:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d
0003c130:·3e0a·7061·636b·6167·6520·2d2d·6164·643d··>.package·--add= 
0003c140:·6169·6465·0a3c·2f63·6f64·653e·3c2f·7072··aide.</code></pr 
0003c150:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class 
0003c160:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes 
0003c170:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle=" 
0003c180:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t 
0003c190:·6172·6765·743d·2223·6964·6d37·3939·3322··arget="#idm7993" 
0003c1a0:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro 
0003c1b0:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria 
0003c1c0:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false 
0003c1d0:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat 
0003c1e0:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre 
0003c1f0:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati 
0003c200:·6f6e·204f·5342·7569·6c64·2042·6c75·6570··on·OSBuild·Bluep 
0003c210:·7269·6e74·2073·6e69·7070·6574·20e2·87b2··rint·snippet·... 
0003c220:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla 
0003c230:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap 
0003c240:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id= 
0003c250:·2269·646d·3739·3933·223e·3c70·7265·3e3c··"idm7993"><pre>< 
0003c260:·636f·6465·3e0a·5b5b·7061·636b·6167·6573··code>.[[packages 
0003c270:·5d5d·0a6e·616d·6520·3d20·2261·6964·6522··]].name·=·"aide" 
0003c280:·0a76·6572·7369·6f6e·203d·2022·2a22·0a3c··.version·=·"*".< 
0003c290:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di 
0003c2a0:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn·0003c0e0:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn
0003c2b0:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat 
0003c2c0:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap 
0003c2d0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target= 
0003c2e0:·2223·6964·6d37·3939·3422·2074·6162·696e··"#idm7994"·tabin 
0003c2f0:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu 
0003c300:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan 
0003c310:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl 
0003c320:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r 
0003c330:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!" 
0003c340:·3e52·656d·6564·6961·7469·6f6e·2073·6372··>Remediation·scr 
0003c350:·6970·7420·e287·b23c·2f61·3e3c·6272·3e3c··ipt·...</a><br>< 
0003c360:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel 
0003c370:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap 
0003c380:·7365·2220·6964·3d22·6964·6d37·3939·3422··se"·id="idm7994" 
0003c390:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t 
0003c3a0:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip0003c0f0:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da
 0003c100:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla
 0003c110:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
Max diff block lines reached; 988196/1015548 bytes (97.31%) of diff not shown.
101 KB
html2text {}
    
Offset 171, 52 lines modifiedOffset 171, 38 lines modified
171 ··-·PCI-DSSv4-11.5.2171 ··-·PCI-DSSv4-11.5.2
172 ··-·enable_strategy172 ··-·enable_strategy
173 ··-·low_complexity173 ··-·low_complexity
174 ··-·low_disruption174 ··-·low_disruption
175 ··-·medium_severity175 ··-·medium_severity
176 ··-·no_reboot_needed176 ··-·no_reboot_needed
177 ··-·package_aide_installed177 ··-·package_aide_installed
178 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
179 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
180 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
181 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
182 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
183 dnf·install·aide 
184 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
185 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
186 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
187 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
188 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
189 package·--add=aide 
190 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8178 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
191 [[packages]]179 [[packages]]
192 name·=·"aide"180 name·=·"aide"
193 version·=·"*"181 version·=·"*"
194 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
195 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
196 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
197 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
198 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
199 package·install·aide 
200 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8182 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
201 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low183 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
202 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low184 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
203 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false185 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
204 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable186 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
205 include·install_aide187 include·install_aide
  
206 class·install_aide·{188 class·install_aide·{
207 ··package·{·'aide':189 ··package·{·'aide':
208 ····ensure·=>·'installed',190 ····ensure·=>·'installed',
209 ··}191 ··}
210 }192 }
 193 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 194 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 195 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 196 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 197 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 198 package·install·aide
211 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8199 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
212 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low200 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
213 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low201 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
214 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false202 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
215 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable203 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
216 #·Remediation·is·applicable·only·in·certain·platforms204 #·Remediation·is·applicable·only·in·certain·platforms
217 if·rpm·--quiet·-q·kernel;·then205 if·rpm·--quiet·-q·kernel;·then
Offset 224, 14 lines modifiedOffset 210, 28 lines modified
224 if·!·rpm·-q·--quiet·"aide"·;·then210 if·!·rpm·-q·--quiet·"aide"·;·then
225 ····yum·install·-y·"aide"211 ····yum·install·-y·"aide"
226 fi212 fi
  
227 else213 else
228 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'214 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
229 fi215 fi
 216 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 217 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 218 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 219 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 220 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 221 package·--add=aide
 222 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 223 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 224 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 225 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 226 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 227 dnf·install·aide
230 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*228 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
231 Run·the·following·command·to·generate·a·new·database:229 Run·the·following·command·to·generate·a·new·database:
232 $·sudo·/usr/sbin/aide·--init230 $·sudo·/usr/sbin/aide·--init
233 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the231 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the
234 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these232 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these
235 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their233 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their
236 integrity.·The·newly-generated·database·can·be·installed·as·follows:234 integrity.·The·newly-generated·database·can·be·installed·as·follows:
Offset 400, 26 lines modifiedOffset 400, 26 lines modified
400 configured·not·to·be·mounted·automatically·with·the·noauto·mount·option.400 configured·not·to·be·mounted·automatically·with·the·noauto·mount·option.
401 Rationale:···The·/boot·partition·contains·the·kernel·and·bootloader·files.·Access·to·this·partition401 Rationale:···The·/boot·partition·contains·the·kernel·and·bootloader·files.·Access·to·this·partition
402 ·············should·be·restricted.402 ·············should·be·restricted.
403 Severity: ···medium403 Severity: ···medium
404 Rule·ID:·····xccdf_org.ssgproject.content_rule_partition_for_boot404 Rule·ID:·····xccdf_org.ssgproject.content_rule_partition_for_boot
405 Identifiers:·CCE-83336-8405 Identifiers:·CCE-83336-8
406 References:··_\x8a_\x8n_\x8s_\x8s_\x8i·R28406 References:··_\x8a_\x8n_\x8s_\x8s_\x8i·R28
 407 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 408 [[customizations.filesystem]]
 409 mountpoint·=·"/boot"
 410 size·=·1073741824
407 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8411 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
408 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low412 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
409 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high413 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high
410 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false414 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
411 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable415 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
412 part·/boot416 part·/boot
413 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
414 [[customizations.filesystem]] 
415 mountpoint·=·"/boot" 
416 size·=·1073741824 
417 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/h\x8ho\x8om\x8me\x8e·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*417 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/h\x8ho\x8om\x8me\x8e·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
418 If·user·home·directories·will·be·stored·locally,·create·a·separate·partition·for·/home·at418 If·user·home·directories·will·be·stored·locally,·create·a·separate·partition·for·/home·at
419 installation·time·(or·migrate·it·later·using·LVM).·If·/home·will·be·mounted·from·another·system·such419 installation·time·(or·migrate·it·later·using·LVM).·If·/home·will·be·mounted·from·another·system·such
420 as·an·NFS·server,·then·creating·a·separate·partition·is·not·necessary·at·installation·time,·and·the420 as·an·NFS·server,·then·creating·a·separate·partition·is·not·necessary·at·installation·time,·and·the
421 mountpoint·can·instead·be·configured·later.421 mountpoint·can·instead·be·configured·later.
422 ·············Ensuring·that·/home·is·mounted·on·its·own·partition·enables·the·setting·of·more422 ·············Ensuring·that·/home·is·mounted·on·its·own·partition·enables·the·setting·of·more
423 Rationale:···restrictive·mount·options,·and·also·helps·ensure·that·users·cannot·trivially·fill423 Rationale:···restrictive·mount·options,·and·also·helps·ensure·that·users·cannot·trivially·fill
Offset 436, 105 lines modifiedOffset 436, 105 lines modified
436 References:··_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)436 References:··_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)
437 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4437 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4
438 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227438 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
439 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-08-010800439 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-08-010800
440 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R28440 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R28
441 ·············_\x8c_\x8i_\x8s············1.1.2.3.1441 ·············_\x8c_\x8i_\x8s············1.1.2.3.1
Max diff block lines reached; 97910/103276 bytes (94.80%) of diff not shown.
398 KB
./usr/share/doc/ssg-nondebian/ssg-rhel8-guide-anssi_bp28_minimal.html
    
Offset 14982, 222 lines modifiedOffset 14982, 222 lines modified
0003a850:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target0003a850:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
0003a860:·3d22·2369·646d·3133·3432·3222·2074·6162··="#idm13422"·tab0003a860:·3d22·2369·646d·3133·3432·3222·2074·6162··="#idm13422"·tab
0003a870:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="0003a870:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
0003a880:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp0003a880:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
0003a890:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti0003a890:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
0003a8a0:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to0003a8a0:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
0003a8b0:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#0003a8b0:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
0003a8c0:·2122·3e52·656d·6564·6961·7469·6f6e·2073··!">Remediation·s0003a8c0:·2122·3e52·656d·6564·6961·7469·6f6e·204f··!">Remediation·O
0003a8d0:·6372·6970·7420·e287·b23c·2f61·3e3c·6272··cript·...</a><br 
0003a8e0:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan 
0003a8f0:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll 
0003a900:·6170·7365·2220·6964·3d22·6964·6d31·3334··apse"·id="idm134 
0003a910:·3232·223e·3c74·6162·6c65·2063·6c61·7373··22"><table·class 
0003a920:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st 
0003a930:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord0003a8d0:·5342·7569·6c64·2042·6c75·6570·7269·6e74··SBuild·Blueprint
 0003a8e0:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>
 0003a8f0:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="
 0003a900:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c
 0003a910:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm
 0003a920:·3133·3432·3222·3e3c·7072·653e·3c63·6f64··13422"><pre><cod
 0003a930:·653e·0a5b·5b70·6163·6b61·6765·735d·5d0a··e>.[[packages]].
 0003a940:·6e61·6d65·203d·2022·646e·662d·6175·746f··name·=·"dnf-auto
 0003a950:·6d61·7469·6322·0a76·6572·7369·6f6e·203d··matic".version·=
 0003a960:·2022·2a22·0a3c·2f63·6f64·653e·3c2f·7072···"*".</code></pr
 0003a970:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class
 0003a980:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes
 0003a990:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle="
 0003a9a0:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t
 0003a9b0:·6172·6765·743d·2223·6964·6d31·3334·3233··arget="#idm13423
 0003a9c0:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r
 0003a9d0:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari
 0003a9e0:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals
 0003a9f0:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa
 0003aa00:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr
 0003aa10:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat
 0003aa20:·696f·6e20·5075·7070·6574·2073·6e69·7070··ion·Puppet·snipp
 0003aa30:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d
 0003aa40:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-
 0003aa50:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps
 0003aa60:·6522·2069·643d·2269·646d·3133·3432·3322··e"·id="idm13423"
 0003aa70:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t
 0003aa80:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip
0003a940:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde0003aa90:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere
 0003aaa0:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense
 0003aab0:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl
 0003aac0:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l
0003a950:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co 
0003a960:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t 
0003a970:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr>< 
0003a980:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio 
0003a990:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</ 
0003a9a0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>0003aad0:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
0003a9b0:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td> 
0003a9c0:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr>< 
0003a9d0:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy: 
0003a9e0:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable< 
0003a9f0:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table 
0003aa00:·3e3c·7072·653e·3c63·6f64·653e·0a64·6e66··><pre><code>.dnf0003aae0:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:<
 0003aaf0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
 0003ab00:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb
 0003ab10:·6f6f·743a·3c2f·7468·3e3c·7464·3e66·616c··oot:</th><td>fal
 0003ab20:·7365·3c2f·7464·3e3c·2f74·723e·3c74·723e··se</td></tr><tr>
 0003ab30:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t
 0003ab40:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td
 0003ab50:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p
 0003ab60:·7265·3e3c·636f·6465·3e69·6e63·6c75·6465··re><code>include
0003aa10:·2069·6e73·7461·6c6c·2064·6e66·2d61·7574···install·dnf-aut0003ab70:·2069·6e73·7461·6c6c·5f64·6e66·2d61·7574···install_dnf-aut
0003aa20:·6f6d·6174·6963·0a3c·2f63·6f64·653e·3c2f··omatic.</code></0003ab80:·6f6d·6174·6963·0a0a·636c·6173·7320·696e··omatic..class·in
 0003ab90:·7374·616c·6c5f·646e·662d·6175·746f·6d61··stall_dnf-automa
 0003aba0:·7469·6320·7b0a·2020·7061·636b·6167·6520··tic·{.··package·
 0003abb0:·7b20·2764·6e66·2d61·7574·6f6d·6174·6963··{·'dnf-automatic
 0003abc0:·273a·0a20·2020·2065·6e73·7572·6520·3d26··':.····ensure·=&
 0003abd0:·6774·3b20·2769·6e73·7461·6c6c·6564·272c··gt;·'installed',
 0003abe0:·0a20·207d·0a7d·0a3c·2f63·6f64·653e·3c2f··.··}.}.</code></
0003aa30:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla0003abf0:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla
0003aa40:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ0003ac00:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ
0003aa50:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle0003ac10:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle
0003aa60:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data0003ac20:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data
0003aa70:·2d74·6172·6765·743d·2223·6964·6d31·3334··-target="#idm1340003ac30:·2d74·6172·6765·743d·2223·6964·6d31·3334··-target="#idm134
0003aa80:·3233·2220·7461·6269·6e64·6578·3d22·3022··23"·tabindex="0"0003ac40:·3234·2220·7461·6269·6e64·6578·3d22·3022··24"·tabindex="0"
0003aa90:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a0003ac50:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
0003aaa0:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa0003ac60:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
0003aab0:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti0003ac70:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
0003aac0:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·0003ac80:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
0003aad0:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi0003ac90:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
0003aae0:·6174·696f·6e20·416e·6163·6f6e·6461·2073··ation·Anaconda·s 
0003aaf0:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b 
0003ab00:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa 
0003ab10:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col 
0003ab20:·6c61·7073·6522·2069·643d·2269·646d·3133··lapse"·id="idm13 
0003ab30:·3432·3322·3e3c·7461·626c·6520·636c·6173··423"><table·clas 
0003ab40:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s 
0003ab50:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor 
0003ab60:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond 
0003ab70:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C 
0003ab80:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th>< 
0003ab90:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
0003aba0:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti 
0003abb0:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low< 
0003abc0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0003abd0:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td0003aca0:·6174·696f·6e20·7363·7269·7074·20e2·87b2··ation·script·...
 0003acb0:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
 0003acc0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
 0003acd0:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
 0003ace0:·2269·646d·3133·3432·3422·3e3c·7461·626c··"idm13424"><tabl
 0003acf0:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t
 0003ad00:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab
 0003ad10:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl
 0003ad20:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr
 0003ad30:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:
 0003ad40:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
 0003ad50:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di
 0003ad60:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t
 0003ad70:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
 0003ad80:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</
 0003ad90:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td
 0003ada0:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St
 0003adb0:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>
0003abe0:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr>0003adc0:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr>
 0003add0:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co
 0003ade0:·6465·3e0a·7061·636b·6167·6520·696e·7374··de>.package·inst
0003abf0:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy 
0003ac00:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable 
0003ac10:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl 
0003ac20:·653e·3c70·7265·3e3c·636f·6465·3e0a·7061··e><pre><code>.pa 
0003ac30:·636b·6167·6520·2d2d·6164·643d·646e·662d··ckage·--add=dnf- 
0003ac40:·6175·746f·6d61·7469·630a·3c2f·636f·6465··automatic.</code 
Max diff block lines reached; 335428/364712 bytes (91.97%) of diff not shown.
42.1 KB
html2text {}
    
Offset 128, 52 lines modifiedOffset 128, 38 lines modified
128 ··-·CCE-82985-3128 ··-·CCE-82985-3
129 ··-·enable_strategy129 ··-·enable_strategy
130 ··-·low_complexity130 ··-·low_complexity
131 ··-·low_disruption131 ··-·low_disruption
132 ··-·medium_severity132 ··-·medium_severity
133 ··-·no_reboot_needed133 ··-·no_reboot_needed
134 ··-·package_dnf-automatic_installed134 ··-·package_dnf-automatic_installed
135 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
136 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
137 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
138 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
139 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
140 dnf·install·dnf-automatic 
141 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
142 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
143 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
144 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
145 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
146 package·--add=dnf-automatic 
147 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8135 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
148 [[packages]]136 [[packages]]
149 name·=·"dnf-automatic"137 name·=·"dnf-automatic"
150 version·=·"*"138 version·=·"*"
151 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
152 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
153 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
154 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
155 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
156 package·install·dnf-automatic 
157 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8139 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
158 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low140 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
159 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low141 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
160 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false142 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
161 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable143 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
162 include·install_dnf-automatic144 include·install_dnf-automatic
  
163 class·install_dnf-automatic·{145 class·install_dnf-automatic·{
164 ··package·{·'dnf-automatic':146 ··package·{·'dnf-automatic':
165 ····ensure·=>·'installed',147 ····ensure·=>·'installed',
166 ··}148 ··}
167 }149 }
 150 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 151 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 152 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 153 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 154 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 155 package·install·dnf-automatic
168 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8156 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
169 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low157 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
170 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low158 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
171 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false159 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
172 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable160 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
173 #·Remediation·is·applicable·only·in·certain·platforms161 #·Remediation·is·applicable·only·in·certain·platforms
174 if·!·(·{·rpm·--quiet·-q·kernel·;}·&&·{·rpm·--quiet·-q·rpm-ostree·;}·&&·{·rpm·--quiet·-q·bootc162 if·!·(·{·rpm·--quiet·-q·kernel·;}·&&·{·rpm·--quiet·-q·rpm-ostree·;}·&&·{·rpm·--quiet·-q·bootc
Offset 182, 14 lines modifiedOffset 168, 28 lines modified
182 if·!·rpm·-q·--quiet·"dnf-automatic"·;·then168 if·!·rpm·-q·--quiet·"dnf-automatic"·;·then
183 ····yum·install·-y·"dnf-automatic"169 ····yum·install·-y·"dnf-automatic"
184 fi170 fi
  
185 else171 else
186 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'172 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
187 fi173 fi
 174 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 175 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 176 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 177 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 178 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 179 package·--add=dnf-automatic
 180 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 181 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 182 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 183 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 184 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 185 dnf·install·dnf-automatic
188 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·d\x8dn\x8nf\x8f-\x8-a\x8au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8c·t\x8to\x8o·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·A\x8Av\x8va\x8ai\x8il\x8la\x8ab\x8bl\x8le\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8es\x8s·A\x8Au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8ca\x8al\x8ll\x8ly\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*186 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·d\x8dn\x8nf\x8f-\x8-a\x8au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8c·t\x8to\x8o·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·A\x8Av\x8va\x8ai\x8il\x8la\x8ab\x8bl\x8le\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8es\x8s·A\x8Au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8ca\x8al\x8ll\x8ly\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
189 To·ensure·that·the·packages·comprising·the·available·updates·will·be·automatically·installed187 To·ensure·that·the·packages·comprising·the·available·updates·will·be·automatically·installed
190 by·dnf-automatic,·set·apply_updates·to·yes·under·[commands]·section·in·/etc/dnf/188 by·dnf-automatic,·set·apply_updates·to·yes·under·[commands]·section·in·/etc/dnf/
191 automatic.conf.189 automatic.conf.
192 ·············Installing·software·updates·is·a·fundamental·mitigation·against·the·exploitation190 ·············Installing·software·updates·is·a·fundamental·mitigation·against·the·exploitation
193 ·············of·publicly-known·vulnerabilities.·If·the·most·recent·security·patches·and191 ·············of·publicly-known·vulnerabilities.·If·the·most·recent·security·patches·and
194 Rationale:···updates·are·not·installed,·unauthorized·users·may·take·advantage·of·weaknesses·in192 Rationale:···updates·are·not·installed,·unauthorized·users·may·take·advantage·of·weaknesses·in
Offset 10397, 47 lines modifiedOffset 10397, 33 lines modified
10397 ··-·PCI-DSSv4-2.2.410397 ··-·PCI-DSSv4-2.2.4
10398 ··-·disable_strategy10398 ··-·disable_strategy
10399 ··-·low_complexity10399 ··-·low_complexity
10400 ··-·low_disruption10400 ··-·low_disruption
10401 ··-·medium_severity10401 ··-·medium_severity
10402 ··-·no_reboot_needed10402 ··-·no_reboot_needed
10403 ··-·package_dhcp_removed10403 ··-·package_dhcp_removed
10404 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
10405 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
10406 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
10407 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
10408 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable 
  
10409 dnf·remove·dhcp-server 
10410 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
10411 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
10412 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
10413 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
10414 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable 
  
10415 package·--remove=dhcp-server 
10416 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
10417 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
10418 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
10419 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
10420 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable 
  
10421 package·remove·dhcp-server 
10422 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x810404 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
10423 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low10405 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
10424 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low10406 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
10425 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false10407 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
10426 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable10408 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
10427 include·remove_dhcp-server10409 include·remove_dhcp-server
  
10428 class·remove_dhcp-server·{10410 class·remove_dhcp-server·{
10429 ··package·{·'dhcp-server':10411 ··package·{·'dhcp-server':
10430 ····ensure·=>·'purged',10412 ····ensure·=>·'purged',
Max diff block lines reached; 38295/43103 bytes (88.85%) of diff not shown.
1.7 MB
./usr/share/doc/ssg-nondebian/ssg-rhel8-guide-cis.html
    
Offset 15376, 208 lines modifiedOffset 15376, 208 lines modified
0003c0f0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target0003c0f0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
0003c100:·3d22·2369·646d·3739·3931·2220·7461·6269··="#idm7991"·tabi0003c100:·3d22·2369·646d·3739·3931·2220·7461·6269··="#idm7991"·tabi
0003c110:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b0003c110:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
0003c120:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa0003c120:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
0003c130:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit0003c130:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
0003c140:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·0003c140:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
0003c150:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!0003c150:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
0003c160:·223e·5265·6d65·6469·6174·696f·6e20·7363··">Remediation·sc0003c160:·223e·5265·6d65·6469·6174·696f·6e20·4f53··">Remediation·OS
 0003c170:·4275·696c·6420·426c·7565·7072·696e·7420··Build·Blueprint·
 0003c180:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><
 0003c190:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
 0003c1a0:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
 0003c1b0:·6c6c·6170·7365·2220·6964·3d22·6964·6d37··llapse"·id="idm7
 0003c1c0:·3939·3122·3e3c·7072·653e·3c63·6f64·653e··991"><pre><code>
 0003c1d0:·0a5b·5b70·6163·6b61·6765·735d·5d0a·6e61··.[[packages]].na
 0003c1e0:·6d65·203d·2022·6169·6465·220a·7665·7273··me·=·"aide".vers
 0003c1f0:·696f·6e20·3d20·222a·220a·3c2f·636f·6465··ion·=·"*".</code
0003c170:·7269·7074·20e2·87b2·3c2f·613e·3c62·723e··ript·...</a><br> 
0003c180:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane 
0003c190:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla 
0003c1a0:·7073·6522·2069·643d·2269·646d·3739·3931··pse"·id="idm7991 
0003c1b0:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class=" 
0003c1c0:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri 
0003c1d0:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border 
0003c1e0:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens 
0003c1f0:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp 
0003c200:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td> 
0003c210:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr 
0003c220:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption: 
0003c230:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td 
0003c240:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re 
0003c250:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa 
0003c260:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr 
0003c270:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</ 
0003c280:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t 
0003c290:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table>< 
0003c2a0:·7072·653e·3c63·6f64·653e·0a64·6e66·2069··pre><code>.dnf·i 
0003c2b0:·6e73·7461·6c6c·2061·6964·650a·3c2f·636f··nstall·aide.</co 
0003c2c0:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div><0003c200:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a·
0003c2d0:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn0003c210:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s
0003c2e0:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t0003c220:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog
0003c2f0:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse"0003c230:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d
0003c300:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i0003c240:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
0003c310:·646d·3739·3932·2220·7461·6269·6e64·6578··dm7992"·tabindex0003c250:·3739·3932·2220·7461·6269·6e64·6578·3d22··7992"·tabindex="
0003c320:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto0003c260:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
0003c330:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded0003c270:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
0003c340:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="0003c280:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
0003c350:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve0003c290:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
0003c360:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re0003c2a0:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
0003c370:·6d65·6469·6174·696f·6e20·416e·6163·6f6e··mediation·Anacon0003c2b0:·6469·6174·696f·6e20·5075·7070·6574·2073··diation·Puppet·s
0003c380:·6461·2073·6e69·7070·6574·20e2·87b2·3c2f··da·snippet·...</0003c2c0:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b
0003c390:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class0003c2d0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
0003c3a0:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse0003c2e0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
0003c3b0:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i0003c2f0:·6c61·7073·6522·2069·643d·2269·646d·3739··lapse"·id="idm79
0003c3c0:·646d·3739·3932·223e·3c74·6162·6c65·2063··dm7992"><table·c0003c300:·3932·223e·3c74·6162·6c65·2063·6c61·7373··92"><table·class
0003c3d0:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl0003c310:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st
0003c3e0:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-0003c320:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord
0003c3f0:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c0003c330:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde
0003c400:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t0003c340:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co
0003c410:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t0003c350:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t
0003c420:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></0003c360:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
0003c430:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru0003c370:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio
 0003c380:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</
 0003c390:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 0003c3a0:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td>
 0003c3b0:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr><
 0003c3c0:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:
 0003c3d0:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<
 0003c3e0:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table
 0003c3f0:·3e3c·7072·653e·3c63·6f64·653e·696e·636c··><pre><code>incl
 0003c400:·7564·6520·696e·7374·616c·6c5f·6169·6465··ude·install_aide
 0003c410:·0a0a·636c·6173·7320·696e·7374·616c·6c5f··..class·install_
 0003c420:·6169·6465·207b·0a20·2070·6163·6b61·6765··aide·{.··package
 0003c430:·207b·2027·6169·6465·273a·0a20·2020·2065···{·'aide':.····e
 0003c440:·6e73·7572·6520·3d26·6774·3b20·2769·6e73··nsure·=&gt;·'ins
 0003c450:·7461·6c6c·6564·272c·0a20·207d·0a7d·0a3c··talled',.··}.}.<
 0003c460:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di
 0003c470:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn·
 0003c480:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat
 0003c490:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap
 0003c4a0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
 0003c4b0:·2223·6964·6d37·3939·3322·2074·6162·696e··"#idm7993"·tabin
 0003c4c0:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
 0003c4d0:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
 0003c4e0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
 0003c4f0:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
 0003c500:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
 0003c510:·3e52·656d·6564·6961·7469·6f6e·2073·6372··>Remediation·scr
 0003c520:·6970·7420·e287·b23c·2f61·3e3c·6272·3e3c··ipt·...</a><br><
 0003c530:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
 0003c540:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap
 0003c550:·7365·2220·6964·3d22·6964·6d37·3939·3322··se"·id="idm7993"
 0003c560:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t
 0003c570:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip
 0003c580:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere
 0003c590:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense
 0003c5a0:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl
0003c440:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l0003c5b0:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l
0003c450:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>0003c5c0:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
0003c460:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th> 
0003c470:·3c74·643e·6661·6c73·653c·2f74·643e·3c2f··<td>false</td></0003c5d0:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:<
 0003c5e0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
0003c480:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat0003c5f0:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb
0003c490:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena0003c600:·6f6f·743a·3c2f·7468·3e3c·7464·3e66·616c··oot:</th><td>fal
0003c4a0:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t 
0003c4b0:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code> 
0003c4c0:·0a70·6163·6b61·6765·202d·2d61·6464·3d61··.package·--add=a 
0003c4d0:·6964·650a·3c2f·636f·6465·3e3c·2f70·7265··ide.</code></pre 
0003c4e0:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class= 
0003c4f0:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success 
0003c500:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c 
0003c510:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta 
0003c520:·7267·6574·3d22·2369·646d·3739·3933·2220··rget="#idm7993"· 
0003c530:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol 
0003c540:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria- 
0003c550:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false" 
0003c560:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate 
0003c570:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href 
0003c580:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio 
0003c590:·6e20·4f53·4275·696c·6420·426c·7565·7072··n·OSBuild·Bluepr 
0003c5a0:·696e·7420·736e·6970·7065·7420·e287·b23c··int·snippet·...<0003c610:·7365·3c2f·7464·3e3c·2f74·723e·3c74·723e··se</td></tr><tr>
 0003c620:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t
 0003c630:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td
 0003c640:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p
 0003c650:·7265·3e3c·636f·6465·3e0a·7061·636b·6167··re><code>.packag
 0003c660:·6520·696e·7374·616c·6c20·6169·6465·0a3c··e·install·aide.<
 0003c670:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di
Max diff block lines reached; 1566714/1594066 bytes (98.28%) of diff not shown.
180 KB
html2text {}
    
Offset 163, 52 lines modifiedOffset 163, 38 lines modified
163 ··-·PCI-DSSv4-11.5.2163 ··-·PCI-DSSv4-11.5.2
164 ··-·enable_strategy164 ··-·enable_strategy
165 ··-·low_complexity165 ··-·low_complexity
166 ··-·low_disruption166 ··-·low_disruption
167 ··-·medium_severity167 ··-·medium_severity
168 ··-·no_reboot_needed168 ··-·no_reboot_needed
169 ··-·package_aide_installed169 ··-·package_aide_installed
170 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
171 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
172 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
173 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
174 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
175 dnf·install·aide 
176 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
177 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
178 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
179 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
180 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
181 package·--add=aide 
182 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8170 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
183 [[packages]]171 [[packages]]
184 name·=·"aide"172 name·=·"aide"
185 version·=·"*"173 version·=·"*"
186 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
187 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
188 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
189 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
190 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
191 package·install·aide 
192 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8174 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
193 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low175 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
194 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low176 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
195 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false177 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
196 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable178 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
197 include·install_aide179 include·install_aide
  
198 class·install_aide·{180 class·install_aide·{
199 ··package·{·'aide':181 ··package·{·'aide':
200 ····ensure·=>·'installed',182 ····ensure·=>·'installed',
201 ··}183 ··}
202 }184 }
 185 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 186 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 187 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 188 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 189 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 190 package·install·aide
203 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8191 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
204 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low192 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
205 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low193 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
206 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false194 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
207 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable195 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
208 #·Remediation·is·applicable·only·in·certain·platforms196 #·Remediation·is·applicable·only·in·certain·platforms
209 if·rpm·--quiet·-q·kernel;·then197 if·rpm·--quiet·-q·kernel;·then
Offset 216, 14 lines modifiedOffset 202, 28 lines modified
216 if·!·rpm·-q·--quiet·"aide"·;·then202 if·!·rpm·-q·--quiet·"aide"·;·then
217 ····yum·install·-y·"aide"203 ····yum·install·-y·"aide"
218 fi204 fi
  
219 else205 else
220 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'206 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
221 fi207 fi
 208 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 209 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 210 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 211 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 212 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 213 package·--add=aide
 214 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 215 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 216 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 217 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 218 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 219 dnf·install·aide
222 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*220 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
223 Run·the·following·command·to·generate·a·new·database:221 Run·the·following·command·to·generate·a·new·database:
224 $·sudo·/usr/sbin/aide·--init222 $·sudo·/usr/sbin/aide·--init
225 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:223 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
226 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz224 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
227 To·initiate·a·manual·check,·run·the·following·command:225 To·initiate·a·manual·check,·run·the·following·command:
228 $·sudo·/usr/sbin/aide·--check226 $·sudo·/usr/sbin/aide·--check
Offset 940, 29 lines modifiedOffset 940, 29 lines modified
940 References:··_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)940 References:··_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)
941 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4941 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4
942 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227942 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
943 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-08-010800943 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-08-010800
944 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R28944 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R28
945 ·············_\x8c_\x8i_\x8s············1.1.2.3.1945 ·············_\x8c_\x8i_\x8s············1.1.2.3.1
946 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-230328r1017139_rule946 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-230328r1017139_rule
947 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
948 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
949 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high 
950 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
951 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
952 part·/home 
953 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8947 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
954 [[customizations.filesystem]]948 [[customizations.filesystem]]
955 mountpoint·=·"/home"949 mountpoint·=·"/home"
956 size·=·1073741824950 size·=·1073741824
957 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8951 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
958 logvol·/home·1024952 logvol·/home·1024
 953 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 954 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 955 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high
 956 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 957 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 958 part·/home
959 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/t\x8tm\x8mp\x8p·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*959 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/t\x8tm\x8mp\x8p·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
960 The·/tmp·directory·is·a·world-writable·directory·used·for·temporary·file·storage.·Ensure·it·has·its·own·partition·or·logical·volume·at·installation·time,·or·migrate·it·using·LVM.960 The·/tmp·directory·is·a·world-writable·directory·used·for·temporary·file·storage.·Ensure·it·has·its·own·partition·or·logical·volume·at·installation·time,·or·migrate·it·using·LVM.
961 Rationale:···The·/tmp·partition·is·used·as·temporary·storage·by·many·programs.·Placing·/tmp·in·its·own·partition·enables·the·setting·of·more·restrictive·mount·options,·which·can·help·protect·programs·which·use·it.961 Rationale:···The·/tmp·partition·is·used·as·temporary·storage·by·many·programs.·Placing·/tmp·in·its·own·partition·enables·the·setting·of·more·restrictive·mount·options,·which·can·help·protect·programs·which·use·it.
962 Severity: ···low962 Severity: ···low
963 Rule·ID:·····xccdf_org.ssgproject.content_rule_partition_for_tmp963 Rule·ID:·····xccdf_org.ssgproject.content_rule_partition_for_tmp
964 Identifiers:·CCE-80851-9964 Identifiers:·CCE-80851-9
965 ·············_\x8c_\x8i_\x8s_\x8-_\x8c_\x8s_\x8c········12,·15,·8965 ·············_\x8c_\x8i_\x8s_\x8-_\x8c_\x8s_\x8c········12,·15,·8
Offset 972, 29 lines modifiedOffset 972, 29 lines modified
972 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.3972 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.3
Max diff block lines reached; 179302/184766 bytes (97.04%) of diff not shown.
1.51 MB
./usr/share/doc/ssg-nondebian/ssg-rhel8-guide-cis_server_l1.html
    
Offset 15338, 208 lines modifiedOffset 15338, 208 lines modified
0003be90:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id0003be90:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
0003bea0:·6d37·3939·3122·2074·6162·696e·6465·783d··m7991"·tabindex=0003bea0:·6d37·3939·3122·2074·6162·696e·6465·783d··m7991"·tabindex=
0003beb0:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button0003beb0:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button
0003bec0:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=0003bec0:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=
0003bed0:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A0003bed0:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A
0003bee0:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea0003bee0:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea
0003bef0:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem0003bef0:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem
 0003bf00:·6564·6961·7469·6f6e·204f·5342·7569·6c64··ediation·OSBuild
 0003bf10:·2042·6c75·6570·7269·6e74·2073·6e69·7070···Blueprint·snipp
 0003bf20:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d
 0003bf30:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-
 0003bf40:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps
 0003bf50:·6522·2069·643d·2269·646d·3739·3931·223e··e"·id="idm7991">
 0003bf60:·3c70·7265·3e3c·636f·6465·3e0a·5b5b·7061··<pre><code>.[[pa
 0003bf70:·636b·6167·6573·5d5d·0a6e·616d·6520·3d20··ckages]].name·=·
 0003bf80:·2261·6964·6522·0a76·6572·7369·6f6e·203d··"aide".version·=
 0003bf90:·2022·2a22·0a3c·2f63·6f64·653e·3c2f·7072···"*".</code></pr
0003bf00:·6564·6961·7469·6f6e·2073·6372·6970·7420··ediation·script· 
0003bf10:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div· 
0003bf20:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col 
0003bf30:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"· 
0003bf40:·6964·3d22·6964·6d37·3939·3122·3e3c·7461··id="idm7991"><ta 
0003bf50:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table 
0003bf60:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t 
0003bf70:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta 
0003bf80:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed">< 
0003bf90:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit 
0003bfa0:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</ 
0003bfb0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
0003bfc0:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th> 
0003bfd0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
0003bfe0:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot: 
0003bff0:·3c2f·7468·3e3c·7464·3e66·616c·7365·3c2f··</th><td>false</ 
0003c000:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
0003c010:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t 
0003c020:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t 
0003c030:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre>< 
0003c040:·636f·6465·3e0a·646e·6620·696e·7374·616c··code>.dnf·instal 
0003c050:·6c20·6169·6465·0a3c·2f63·6f64·653e·3c2f··l·aide.</code></ 
0003c060:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla0003bfa0:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class
0003c070:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ0003bfb0:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes
0003c080:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle0003bfc0:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle="
0003c090:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data0003bfd0:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t
0003c0a0:·2d74·6172·6765·743d·2223·6964·6d37·3939··-target="#idm7990003bfe0:·6172·6765·743d·2223·6964·6d37·3939·3222··arget="#idm7992"
0003c0b0:·3222·2074·6162·696e·6465·783d·2230·2220··2"·tabindex="0"·0003bff0:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro
0003c0c0:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar0003c000:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria
0003c0d0:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal0003c010:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false
0003c0e0:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ0003c020:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat
0003c0f0:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h0003c030:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre
0003c100:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia0003c040:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati
 0003c050:·6f6e·2050·7570·7065·7420·736e·6970·7065··on·Puppet·snippe
0003c110:·7469·6f6e·2041·6e61·636f·6e64·6120·736e··tion·Anaconda·sn 
0003c120:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br 
0003c130:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan 
0003c140:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll 
0003c150:·6170·7365·2220·6964·3d22·6964·6d37·3939··apse"·id="idm799 
0003c160:·3222·3e3c·7461·626c·6520·636c·6173·733d··2"><table·class= 
0003c170:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str 
0003c180:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde 
0003c190:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden 
0003c1a0:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com 
0003c1b0:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td 
0003c1c0:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t 
0003c1d0:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption 
0003c1e0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t 
0003c1f0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e52··d></tr><tr><th>R 
0003c200:·6562·6f6f·743a·3c2f·7468·3e3c·7464·3e66··eboot:</th><td>f 
0003c210:·616c·7365·3c2f·7464·3e3c·2f74·723e·3c74··alse</td></tr><t 
0003c220:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:< 
0003c230:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</ 
0003c240:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table> 
0003c250:·3c70·7265·3e3c·636f·6465·3e0a·7061·636b··<pre><code>.pack 
0003c260:·6167·6520·2d2d·6164·643d·6169·6465·0a3c··age·--add=aide.< 
0003c270:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di 
0003c280:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn· 
0003c290:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat 
0003c2a0:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap 
0003c2b0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target= 
0003c2c0:·2223·6964·6d37·3939·3322·2074·6162·696e··"#idm7993"·tabin 
0003c2d0:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu 
0003c2e0:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan 
0003c2f0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl 
0003c300:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r 
0003c310:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!" 
0003c320:·3e52·656d·6564·6961·7469·6f6e·204f·5342··>Remediation·OSB 
0003c330:·7569·6c64·2042·6c75·6570·7269·6e74·2073··uild·Blueprint·s 
0003c340:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b 
0003c350:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa 
0003c360:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col 
0003c370:·6c61·7073·6522·2069·643d·2269·646d·3739··lapse"·id="idm79 
0003c380:·3933·223e·3c70·7265·3e3c·636f·6465·3e0a··93"><pre><code>. 
0003c390:·5b5b·7061·636b·6167·6573·5d5d·0a6e·616d··[[packages]].nam 
0003c3a0:·6520·3d20·2261·6964·6522·0a76·6572·7369··e·=·"aide".versi 
0003c3b0:·6f6e·203d·2022·2a22·0a3c·2f63·6f64·653e··on·=·"*".</code> 
0003c3c0:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c 
0003c3d0:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su 
0003c3e0:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg 
0003c3f0:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da 
0003c400:·7461·2d74·6172·6765·743d·2223·6964·6d37··ta-target="#idm7 
0003c410:·3939·3422·2074·6162·696e·6465·783d·2230··994"·tabindex="0 
0003c420:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"· 
0003c430:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f 
0003c440:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act 
0003c450:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal" 
0003c460:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed 
0003c470:·6961·7469·6f6e·2073·6372·6970·7420·e287··iation·script·.. 
0003c480:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl0003c060:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di
0003c490:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla 
0003c4a0:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id 
0003c4b0:·3d22·6964·6d37·3939·3422·3e3c·7461·626c··="idm7994"><tabl 
0003c4c0:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t 
0003c4d0:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab 
0003c4e0:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl 
0003c4f0:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr 
0003c500:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity: 
0003c510:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td 
0003c520:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di 
0003c530:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t 
0003c540:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr>< 
0003c550:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</ 
0003c560:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td 
0003c570:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St 
0003c580:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td> 
0003c590:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr> 
0003c5a0:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co 
0003c5b0:·6465·3e0a·7061·636b·6167·6520·696e·7374··de>.package·inst 
0003c5c0:·616c·6c20·6169·6465·0a3c·2f63·6f64·653e··all·aide.</code> 
Max diff block lines reached; 1397248/1424600 bytes (98.08%) of diff not shown.
154 KB
html2text {}
    
Offset 157, 52 lines modifiedOffset 157, 38 lines modified
157 ··-·PCI-DSSv4-11.5.2157 ··-·PCI-DSSv4-11.5.2
158 ··-·enable_strategy158 ··-·enable_strategy
159 ··-·low_complexity159 ··-·low_complexity
160 ··-·low_disruption160 ··-·low_disruption
161 ··-·medium_severity161 ··-·medium_severity
162 ··-·no_reboot_needed162 ··-·no_reboot_needed
163 ··-·package_aide_installed163 ··-·package_aide_installed
164 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
165 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
166 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
167 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
168 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
169 dnf·install·aide 
170 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
171 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
172 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
173 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
174 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
175 package·--add=aide 
176 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8164 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
177 [[packages]]165 [[packages]]
178 name·=·"aide"166 name·=·"aide"
179 version·=·"*"167 version·=·"*"
180 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
181 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
182 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
183 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
184 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
185 package·install·aide 
186 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8168 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
187 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low169 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
188 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low170 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
189 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false171 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
190 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable172 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
191 include·install_aide173 include·install_aide
  
192 class·install_aide·{174 class·install_aide·{
193 ··package·{·'aide':175 ··package·{·'aide':
194 ····ensure·=>·'installed',176 ····ensure·=>·'installed',
195 ··}177 ··}
196 }178 }
 179 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 180 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 181 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 182 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 183 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 184 package·install·aide
197 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8185 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
198 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low186 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
199 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low187 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
200 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false188 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
201 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable189 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
202 #·Remediation·is·applicable·only·in·certain·platforms190 #·Remediation·is·applicable·only·in·certain·platforms
203 if·rpm·--quiet·-q·kernel;·then191 if·rpm·--quiet·-q·kernel;·then
Offset 210, 14 lines modifiedOffset 196, 28 lines modified
210 if·!·rpm·-q·--quiet·"aide"·;·then196 if·!·rpm·-q·--quiet·"aide"·;·then
211 ····yum·install·-y·"aide"197 ····yum·install·-y·"aide"
212 fi198 fi
  
213 else199 else
214 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'200 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
215 fi201 fi
 202 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 203 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 204 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 205 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 206 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 207 package·--add=aide
 208 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 209 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 210 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 211 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 212 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 213 dnf·install·aide
216 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*214 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
217 Run·the·following·command·to·generate·a·new·database:215 Run·the·following·command·to·generate·a·new·database:
218 $·sudo·/usr/sbin/aide·--init216 $·sudo·/usr/sbin/aide·--init
219 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:217 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
220 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz218 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
221 To·initiate·a·manual·check,·run·the·following·command:219 To·initiate·a·manual·check,·run·the·following·command:
222 $·sudo·/usr/sbin/aide·--check220 $·sudo·/usr/sbin/aide·--check
Offset 933, 29 lines modifiedOffset 933, 29 lines modified
933 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.3933 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.3
934 References:··_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)934 References:··_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)
935 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4935 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4
936 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227936 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
937 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-08-010543937 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-08-010543
938 ·············_\x8c_\x8i_\x8s············1.1.2.1.1938 ·············_\x8c_\x8i_\x8s············1.1.2.1.1
939 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-230295r1017106_rule939 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-230295r1017106_rule
940 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
941 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
942 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high 
943 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
944 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
945 part·/tmp 
946 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8940 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
947 [[customizations.filesystem]]941 [[customizations.filesystem]]
948 mountpoint·=·"/tmp"942 mountpoint·=·"/tmp"
949 size·=·1073741824943 size·=·1073741824
950 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8944 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
951 logvol·/tmp·1024945 logvol·/tmp·1024
 946 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 947 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 948 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high
 949 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 950 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 951 part·/tmp
952 Group  ·GNOME·Desktop·Environment·  Group·contains·3·groups·and·10·rules952 Group  ·GNOME·Desktop·Environment·  Group·contains·3·groups·and·10·rules
953 _\x8[_\x8r_\x8e_\x8f_\x8]  ·GNOME·is·a·graphical·desktop·environment·bundled·with·many·Linux·distributions·that·allow·users·to·easily·interact·with·the·operating·system·graphically·rather·than·textually.·The·GNOME·Graphical·Display·Manager·(GDM)·provides·login,·logout,·and·user·switching·contexts·as·well·as·display·server·management.953 _\x8[_\x8r_\x8e_\x8f_\x8]  ·GNOME·is·a·graphical·desktop·environment·bundled·with·many·Linux·distributions·that·allow·users·to·easily·interact·with·the·operating·system·graphically·rather·than·textually.·The·GNOME·Graphical·Display·Manager·(GDM)·provides·login,·logout,·and·user·switching·contexts·as·well·as·display·server·management.
  
954 GNOME·is·developed·by·the·GNOME·Project·and·is·considered·the·default·Red·Hat·Graphical·environment.954 GNOME·is·developed·by·the·GNOME·Project·and·is·considered·the·default·Red·Hat·Graphical·environment.
  
955 For·more·information·on·GNOME·and·the·GNOME·Project,·see·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8w\x8w_\x8w\x8w_\x8w\x8w_\x8.\x8._\x8g\x8g_\x8n\x8n_\x8o\x8o_\x8m\x8m_\x8e\x8e_\x8.\x8._\x8o\x8o_\x8r\x8r_\x8g\x8g.955 For·more·information·on·GNOME·and·the·GNOME·Project,·see·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8w\x8w_\x8w\x8w_\x8w\x8w_\x8.\x8._\x8g\x8g_\x8n\x8n_\x8o\x8o_\x8m\x8m_\x8e\x8e_\x8.\x8._\x8o\x8o_\x8r\x8r_\x8g\x8g.
956 Group  ·Configure·GNOME·Login·Screen·  Group·contains·2·rules956 Group  ·Configure·GNOME·Login·Screen·  Group·contains·2·rules
Offset 2341, 52 lines modifiedOffset 2341, 38 lines modified
2341 ··-·PCI-DSSv4-2.2.62341 ··-·PCI-DSSv4-2.2.6
Max diff block lines reached; 152664/158062 bytes (96.58%) of diff not shown.
1.41 MB
./usr/share/doc/ssg-nondebian/ssg-rhel8-guide-cis_workstation_l1.html
    
Offset 15329, 208 lines modifiedOffset 15329, 208 lines modified
0003be00:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe0003be00:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
0003be10:·743d·2223·6964·6d37·3939·3122·2074·6162··t="#idm7991"·tab0003be10:·743d·2223·6964·6d37·3939·3122·2074·6162··t="#idm7991"·tab
0003be20:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="0003be20:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
0003be30:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp0003be30:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
0003be40:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti0003be40:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
0003be50:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to0003be50:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
0003be60:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#0003be60:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
0003be70:·2122·3e52·656d·6564·6961·7469·6f6e·2073··!">Remediation·s0003be70:·2122·3e52·656d·6564·6961·7469·6f6e·204f··!">Remediation·O
 0003be80:·5342·7569·6c64·2042·6c75·6570·7269·6e74··SBuild·Blueprint
 0003be90:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>
 0003bea0:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="
 0003beb0:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c
 0003bec0:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm
 0003bed0:·3739·3931·223e·3c70·7265·3e3c·636f·6465··7991"><pre><code
 0003bee0:·3e0a·5b5b·7061·636b·6167·6573·5d5d·0a6e··>.[[packages]].n
 0003bef0:·616d·6520·3d20·2261·6964·6522·0a76·6572··ame·=·"aide".ver
 0003bf00:·7369·6f6e·203d·2022·2a22·0a3c·2f63·6f64··sion·=·"*".</cod
0003be80:·6372·6970·7420·e287·b23c·2f61·3e3c·6272··cript·...</a><br 
0003be90:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan 
0003bea0:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll 
0003beb0:·6170·7365·2220·6964·3d22·6964·6d37·3939··apse"·id="idm799 
0003bec0:·3122·3e3c·7461·626c·6520·636c·6173·733d··1"><table·class= 
0003bed0:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str 
0003bee0:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde 
0003bef0:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden 
0003bf00:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com 
0003bf10:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td 
0003bf20:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t 
0003bf30:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption 
0003bf40:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t 
0003bf50:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e52··d></tr><tr><th>R 
0003bf60:·6562·6f6f·743a·3c2f·7468·3e3c·7464·3e66··eboot:</th><td>f 
0003bf70:·616c·7365·3c2f·7464·3e3c·2f74·723e·3c74··alse</td></tr><t 
0003bf80:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:< 
0003bf90:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</ 
0003bfa0:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table> 
0003bfb0:·3c70·7265·3e3c·636f·6465·3e0a·646e·6620··<pre><code>.dnf· 
0003bfc0:·696e·7374·616c·6c20·6169·6465·0a3c·2f63··install·aide.</c 
0003bfd0:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div>0003bf10:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a
0003bfe0:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt0003bf20:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn-
0003bff0:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data-0003bf30:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to
0003c000:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse0003bf40:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"·
0003c010:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#0003bf50:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
0003c020:·6964·6d37·3939·3222·2074·6162·696e·6465··idm7992"·tabinde0003bf60:·6d37·3939·3222·2074·6162·696e·6465·783d··m7992"·tabindex=
0003c030:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt0003bf70:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button
0003c040:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande0003bf80:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=
0003c050:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=0003bf90:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A
0003c060:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev0003bfa0:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea
0003c070:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R0003bfb0:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem
0003c080:·656d·6564·6961·7469·6f6e·2041·6e61·636f··emediation·Anaco0003bfc0:·6564·6961·7469·6f6e·2050·7570·7065·7420··ediation·Puppet·
0003c090:·6e64·6120·736e·6970·7065·7420·e287·b23c··nda·snippet·...<0003bfd0:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><
0003c0a0:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas0003bfe0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
0003c0b0:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps0003bff0:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
0003c0c0:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="0003c000:·6c6c·6170·7365·2220·6964·3d22·6964·6d37··llapse"·id="idm7
0003c0d0:·6964·6d37·3939·3222·3e3c·7461·626c·6520··idm7992"><table·0003c010:·3939·3222·3e3c·7461·626c·6520·636c·6173··992"><table·clas
0003c0e0:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab0003c020:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s
0003c0f0:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table0003c030:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor
0003c100:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-0003c040:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond
0003c110:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><0003c050:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C
0003c120:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</0003c060:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><
0003c130:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><0003c070:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
0003c140:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr0003c080:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti
0003c150:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>0003c090:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<
0003c160:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr0003c0a0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
0003c170:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th0003c0b0:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td
0003c180:·3e3c·7464·3e66·616c·7365·3c2f·7464·3e3c··><td>false</td>< 
0003c190:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra 
0003c1a0:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en 
0003c1b0:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></0003c0c0:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr>
 0003c0d0:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy
 0003c0e0:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable
 0003c0f0:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl
0003c1c0:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code0003c100:·653e·3c70·7265·3e3c·636f·6465·3e69·6e63··e><pre><code>inc
 0003c110:·6c75·6465·2069·6e73·7461·6c6c·5f61·6964··lude·install_aid
 0003c120:·650a·0a63·6c61·7373·2069·6e73·7461·6c6c··e..class·install
 0003c130:·5f61·6964·6520·7b0a·2020·7061·636b·6167··_aide·{.··packag
 0003c140:·6520·7b20·2761·6964·6527·3a0a·2020·2020··e·{·'aide':.····
 0003c150:·656e·7375·7265·203d·2667·743b·2027·696e··ensure·=&gt;·'in
 0003c160:·7374·616c·6c65·6427·2c0a·2020·7d0a·7d0a··stalled',.··}.}.
 0003c170:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d
0003c1d0:·3e0a·7061·636b·6167·6520·2d2d·6164·643d··>.package·--add= 
0003c1e0:·6169·6465·0a3c·2f63·6f64·653e·3c2f·7072··aide.</code></pr 
0003c1f0:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class 
0003c200:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes 
0003c210:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle=" 
0003c220:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t 
0003c230:·6172·6765·743d·2223·6964·6d37·3939·3322··arget="#idm7993" 
0003c240:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro 
0003c250:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria 
0003c260:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false 
0003c270:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat 
0003c280:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre 
0003c290:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati 
0003c2a0:·6f6e·204f·5342·7569·6c64·2042·6c75·6570··on·OSBuild·Bluep 
0003c2b0:·7269·6e74·2073·6e69·7070·6574·20e2·87b2··rint·snippet·... 
0003c2c0:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla 
0003c2d0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap 
0003c2e0:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id= 
0003c2f0:·2269·646d·3739·3933·223e·3c70·7265·3e3c··"idm7993"><pre>< 
0003c300:·636f·6465·3e0a·5b5b·7061·636b·6167·6573··code>.[[packages 
0003c310:·5d5d·0a6e·616d·6520·3d20·2261·6964·6522··]].name·=·"aide" 
0003c320:·0a76·6572·7369·6f6e·203d·2022·2a22·0a3c··.version·=·"*".< 
0003c330:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di 
0003c340:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn·0003c180:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn
0003c350:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat 
0003c360:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap 
0003c370:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target= 
0003c380:·2223·6964·6d37·3939·3422·2074·6162·696e··"#idm7994"·tabin 
0003c390:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu 
0003c3a0:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan 
0003c3b0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl 
0003c3c0:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r 
0003c3d0:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!" 
0003c3e0:·3e52·656d·6564·6961·7469·6f6e·2073·6372··>Remediation·scr 
0003c3f0:·6970·7420·e287·b23c·2f61·3e3c·6272·3e3c··ipt·...</a><br>< 
0003c400:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel 
0003c410:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap 
0003c420:·7365·2220·6964·3d22·6964·6d37·3939·3422··se"·id="idm7994" 
0003c430:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t 
0003c440:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip0003c190:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da
 0003c1a0:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla
 0003c1b0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
 0003c1c0:·3d22·2369·646d·3739·3933·2220·7461·6269··="#idm7993"·tabi
 0003c1d0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
 0003c1e0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
 0003c1f0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
 0003c200:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
Max diff block lines reached; 1302154/1329506 bytes (97.94%) of diff not shown.
142 KB
html2text {}
    
Offset 156, 52 lines modifiedOffset 156, 38 lines modified
156 ··-·PCI-DSSv4-11.5.2156 ··-·PCI-DSSv4-11.5.2
157 ··-·enable_strategy157 ··-·enable_strategy
158 ··-·low_complexity158 ··-·low_complexity
159 ··-·low_disruption159 ··-·low_disruption
160 ··-·medium_severity160 ··-·medium_severity
161 ··-·no_reboot_needed161 ··-·no_reboot_needed
162 ··-·package_aide_installed162 ··-·package_aide_installed
163 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
164 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
165 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
166 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
167 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
168 dnf·install·aide 
169 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
170 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
171 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
172 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
173 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
174 package·--add=aide 
175 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8163 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
176 [[packages]]164 [[packages]]
177 name·=·"aide"165 name·=·"aide"
178 version·=·"*"166 version·=·"*"
179 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
180 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
181 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
182 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
183 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
184 package·install·aide 
185 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8167 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
186 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low168 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
187 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low169 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
188 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false170 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
189 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable171 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
190 include·install_aide172 include·install_aide
  
191 class·install_aide·{173 class·install_aide·{
192 ··package·{·'aide':174 ··package·{·'aide':
193 ····ensure·=>·'installed',175 ····ensure·=>·'installed',
194 ··}176 ··}
195 }177 }
 178 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 179 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 180 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 181 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 182 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 183 package·install·aide
196 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8184 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
197 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low185 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
198 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low186 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
199 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false187 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
200 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable188 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
201 #·Remediation·is·applicable·only·in·certain·platforms189 #·Remediation·is·applicable·only·in·certain·platforms
202 if·rpm·--quiet·-q·kernel;·then190 if·rpm·--quiet·-q·kernel;·then
Offset 209, 14 lines modifiedOffset 195, 28 lines modified
209 if·!·rpm·-q·--quiet·"aide"·;·then195 if·!·rpm·-q·--quiet·"aide"·;·then
210 ····yum·install·-y·"aide"196 ····yum·install·-y·"aide"
211 fi197 fi
  
212 else198 else
213 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'199 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
214 fi200 fi
 201 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 202 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 203 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 204 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 205 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 206 package·--add=aide
 207 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 208 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 209 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 210 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 211 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 212 dnf·install·aide
215 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*213 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
216 Run·the·following·command·to·generate·a·new·database:214 Run·the·following·command·to·generate·a·new·database:
217 $·sudo·/usr/sbin/aide·--init215 $·sudo·/usr/sbin/aide·--init
218 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:216 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
219 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz217 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
220 To·initiate·a·manual·check,·run·the·following·command:218 To·initiate·a·manual·check,·run·the·following·command:
221 $·sudo·/usr/sbin/aide·--check219 $·sudo·/usr/sbin/aide·--check
Offset 932, 29 lines modifiedOffset 932, 29 lines modified
932 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.3932 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.3
933 References:··_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)933 References:··_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)
934 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4934 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4
935 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227935 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
936 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-08-010543936 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-08-010543
937 ·············_\x8c_\x8i_\x8s············1.1.2.1.1937 ·············_\x8c_\x8i_\x8s············1.1.2.1.1
938 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-230295r1017106_rule938 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-230295r1017106_rule
939 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
940 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
941 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high 
942 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
943 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
944 part·/tmp 
945 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8939 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
946 [[customizations.filesystem]]940 [[customizations.filesystem]]
947 mountpoint·=·"/tmp"941 mountpoint·=·"/tmp"
948 size·=·1073741824942 size·=·1073741824
949 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8943 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
950 logvol·/tmp·1024944 logvol·/tmp·1024
 945 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 946 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 947 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high
 948 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 949 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 950 part·/tmp
951 Group  ·GNOME·Desktop·Environment·  Group·contains·3·groups·and·10·rules951 Group  ·GNOME·Desktop·Environment·  Group·contains·3·groups·and·10·rules
952 _\x8[_\x8r_\x8e_\x8f_\x8]  ·GNOME·is·a·graphical·desktop·environment·bundled·with·many·Linux·distributions·that·allow·users·to·easily·interact·with·the·operating·system·graphically·rather·than·textually.·The·GNOME·Graphical·Display·Manager·(GDM)·provides·login,·logout,·and·user·switching·contexts·as·well·as·display·server·management.952 _\x8[_\x8r_\x8e_\x8f_\x8]  ·GNOME·is·a·graphical·desktop·environment·bundled·with·many·Linux·distributions·that·allow·users·to·easily·interact·with·the·operating·system·graphically·rather·than·textually.·The·GNOME·Graphical·Display·Manager·(GDM)·provides·login,·logout,·and·user·switching·contexts·as·well·as·display·server·management.
  
953 GNOME·is·developed·by·the·GNOME·Project·and·is·considered·the·default·Red·Hat·Graphical·environment.953 GNOME·is·developed·by·the·GNOME·Project·and·is·considered·the·default·Red·Hat·Graphical·environment.
  
954 For·more·information·on·GNOME·and·the·GNOME·Project,·see·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8w\x8w_\x8w\x8w_\x8w\x8w_\x8.\x8._\x8g\x8g_\x8n\x8n_\x8o\x8o_\x8m\x8m_\x8e\x8e_\x8.\x8._\x8o\x8o_\x8r\x8r_\x8g\x8g.954 For·more·information·on·GNOME·and·the·GNOME·Project,·see·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8w\x8w_\x8w\x8w_\x8w\x8w_\x8.\x8._\x8g\x8g_\x8n\x8n_\x8o\x8o_\x8m\x8m_\x8e\x8e_\x8.\x8._\x8o\x8o_\x8r\x8r_\x8g\x8g.
955 Group  ·Configure·GNOME·Login·Screen·  Group·contains·2·rules955 Group  ·Configure·GNOME·Login·Screen·  Group·contains·2·rules
Offset 2340, 52 lines modifiedOffset 2340, 38 lines modified
2340 ··-·PCI-DSSv4-2.2.62340 ··-·PCI-DSSv4-2.2.6
Max diff block lines reached; 140110/145508 bytes (96.29%) of diff not shown.
1.59 MB
./usr/share/doc/ssg-nondebian/ssg-rhel8-guide-cis_workstation_l2.html
    
Offset 15368, 207 lines modifiedOffset 15368, 207 lines modified
0003c070:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm0003c070:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
0003c080:·3739·3931·2220·7461·6269·6e64·6578·3d22··7991"·tabindex="0003c080:·3739·3931·2220·7461·6269·6e64·6578·3d22··7991"·tabindex="
0003c090:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"0003c090:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
0003c0a0:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="0003c0a0:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
0003c0b0:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac0003c0b0:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
0003c0c0:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal0003c0c0:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
0003c0d0:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme0003c0d0:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
0003c0e0:·6469·6174·696f·6e20·7363·7269·7074·20e2··diation·script·.0003c0e0:·6469·6174·696f·6e20·4f53·4275·696c·6420··diation·OSBuild·
 0003c0f0:·426c·7565·7072·696e·7420·736e·6970·7065··Blueprint·snippe
 0003c100:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di
 0003c110:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c
 0003c120:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse
 0003c130:·2220·6964·3d22·6964·6d37·3939·3122·3e3c··"·id="idm7991"><
 0003c140:·7072·653e·3c63·6f64·653e·0a5b·5b70·6163··pre><code>.[[pac
 0003c150:·6b61·6765·735d·5d0a·6e61·6d65·203d·2022··kages]].name·=·"
 0003c160:·6169·6465·220a·7665·7273·696f·6e20·3d20··aide".version·=·
0003c0f0:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c 
0003c100:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll 
0003c110:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i 
0003c120:·643d·2269·646d·3739·3931·223e·3c74·6162··d="idm7991"><tab 
0003c130:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table· 
0003c140:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta 
0003c150:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab 
0003c160:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t 
0003c170:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity 
0003c180:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t 
0003c190:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D 
0003c1a0:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th>< 
0003c1b0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
0003c1c0:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:< 
0003c1d0:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t 
0003c1e0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S 
0003c1f0:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td 
0003c200:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr 
0003c210:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c 
0003c220:·6f64·653e·0a64·6e66·2069·6e73·7461·6c6c··ode>.dnf·install 
0003c230:·2061·6964·650a·3c2f·636f·6465·3e3c·2f70···aide.</code></p0003c170:·222a·220a·3c2f·636f·6465·3e3c·2f70·7265··"*".</code></pre
0003c240:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas0003c180:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class=
0003c250:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe0003c190:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success
0003c260:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle=0003c1a0:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c
0003c270:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data-0003c1b0:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta
0003c280:·7461·7267·6574·3d22·2369·646d·3739·3932··target="#idm79920003c1c0:·7267·6574·3d22·2369·646d·3739·3932·2220··rget="#idm7992"·
0003c290:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r0003c1d0:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol
0003c2a0:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari0003c1e0:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-
0003c2b0:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals0003c1f0:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"
0003c2c0:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa0003c200:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate
0003c2d0:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr0003c210:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href
0003c2e0:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat0003c220:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio
0003c2f0:·696f·6e20·416e·6163·6f6e·6461·2073·6e69··ion·Anaconda·sni0003c230:·6e20·5075·7070·6574·2073·6e69·7070·6574··n·Puppet·snippet
0003c300:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>0003c240:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
0003c310:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane0003c250:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
0003c320:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla0003c260:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
0003c330:·7073·6522·2069·643d·2269·646d·3739·3932··pse"·id="idm79920003c270:·2069·643d·2269·646d·3739·3932·223e·3c74···id="idm7992"><t
0003c340:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="0003c280:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl
0003c350:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri0003c290:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·
0003c360:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border0003c2a0:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t
0003c370:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens0003c2b0:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">
0003c380:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp0003c2c0:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi
0003c390:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>0003c2d0:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<
 0003c2e0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 0003c2f0:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th
 0003c300:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
 0003c310:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot
 0003c320:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false<
0003c3a0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr0003c330:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
0003c3b0:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:0003c340:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><
 0003c350:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></
 0003c360:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>
 0003c370:·3c63·6f64·653e·696e·636c·7564·6520·696e··<code>include·in
 0003c380:·7374·616c·6c5f·6169·6465·0a0a·636c·6173··stall_aide..clas
 0003c390:·7320·696e·7374·616c·6c5f·6169·6465·207b··s·install_aide·{
 0003c3a0:·0a20·2070·6163·6b61·6765·207b·2027·6169··.··package·{·'ai
 0003c3b0:·6465·273a·0a20·2020·2065·6e73·7572·6520··de':.····ensure·
 0003c3c0:·3d26·6774·3b20·2769·6e73·7461·6c6c·6564··=&gt;·'installed
 0003c3d0:·272c·0a20·207d·0a7d·0a3c·2f63·6f64·653e··',.··}.}.</code>
 0003c3e0:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c
 0003c3f0:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su
 0003c400:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg
 0003c410:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da
 0003c420:·7461·2d74·6172·6765·743d·2223·6964·6d37··ta-target="#idm7
 0003c430:·3939·3322·2074·6162·696e·6465·783d·2230··993"·tabindex="0
 0003c440:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
 0003c450:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
 0003c460:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
 0003c470:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
 0003c480:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
 0003c490:·6961·7469·6f6e·2073·6372·6970·7420·e287··iation·script·..
 0003c4a0:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl
 0003c4b0:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla
 0003c4c0:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id
 0003c4d0:·3d22·6964·6d37·3939·3322·3e3c·7461·626c··="idm7993"><tabl
 0003c4e0:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t
 0003c4f0:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab
 0003c500:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl
 0003c510:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr
 0003c520:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:
0003c3c0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td0003c530:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
0003c3d0:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re0003c540:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di
0003c3e0:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa0003c550:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t
0003c3f0:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr0003c560:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
0003c400:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</0003c570:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</
0003c410:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t0003c580:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td
0003c420:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table>< 
0003c430:·7072·653e·3c63·6f64·653e·0a70·6163·6b61··pre><code>.packa 
0003c440:·6765·202d·2d61·6464·3d61·6964·650a·3c2f··ge·--add=aide.</ 
0003c450:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div 
0003c460:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b 
0003c470:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data 
0003c480:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps 
0003c490:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target=" 
0003c4a0:·2369·646d·3739·3933·2220·7461·6269·6e64··#idm7993"·tabind 
0003c4b0:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but 
0003c4c0:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand 
0003c4d0:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title 
0003c4e0:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re 
0003c4f0:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!"> 
0003c500:·5265·6d65·6469·6174·696f·6e20·4f53·4275··Remediation·OSBu 
0003c510:·696c·6420·426c·7565·7072·696e·7420·736e··ild·Blueprint·sn0003c590:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St
 0003c5a0:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>
 0003c5b0:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr>
 0003c5c0:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co
 0003c5d0:·6465·3e0a·7061·636b·6167·6520·696e·7374··de>.package·inst
 0003c5e0:·616c·6c20·6169·6465·0a3c·2f63·6f64·653e··all·aide.</code>
 0003c5f0:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c
 0003c600:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su
 0003c610:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg
 0003c620:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da
Max diff block lines reached; 1469582/1496796 bytes (98.18%) of diff not shown.
168 KB
html2text {}
    
Offset 162, 52 lines modifiedOffset 162, 38 lines modified
162 ··-·PCI-DSSv4-11.5.2162 ··-·PCI-DSSv4-11.5.2
163 ··-·enable_strategy163 ··-·enable_strategy
164 ··-·low_complexity164 ··-·low_complexity
165 ··-·low_disruption165 ··-·low_disruption
166 ··-·medium_severity166 ··-·medium_severity
167 ··-·no_reboot_needed167 ··-·no_reboot_needed
168 ··-·package_aide_installed168 ··-·package_aide_installed
169 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
170 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
171 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
172 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
173 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
174 dnf·install·aide 
175 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
176 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
177 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
178 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
179 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
180 package·--add=aide 
181 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8169 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
182 [[packages]]170 [[packages]]
183 name·=·"aide"171 name·=·"aide"
184 version·=·"*"172 version·=·"*"
185 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
186 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
187 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
188 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
189 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
190 package·install·aide 
191 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8173 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
192 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low174 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
193 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low175 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
194 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false176 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
195 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable177 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
196 include·install_aide178 include·install_aide
  
197 class·install_aide·{179 class·install_aide·{
198 ··package·{·'aide':180 ··package·{·'aide':
199 ····ensure·=>·'installed',181 ····ensure·=>·'installed',
200 ··}182 ··}
201 }183 }
 184 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 185 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 186 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 187 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 188 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 189 package·install·aide
202 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8190 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
203 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low191 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
204 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low192 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
205 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false193 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
206 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable194 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
207 #·Remediation·is·applicable·only·in·certain·platforms195 #·Remediation·is·applicable·only·in·certain·platforms
208 if·rpm·--quiet·-q·kernel;·then196 if·rpm·--quiet·-q·kernel;·then
Offset 215, 14 lines modifiedOffset 201, 28 lines modified
215 if·!·rpm·-q·--quiet·"aide"·;·then201 if·!·rpm·-q·--quiet·"aide"·;·then
216 ····yum·install·-y·"aide"202 ····yum·install·-y·"aide"
217 fi203 fi
  
218 else204 else
219 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'205 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
220 fi206 fi
 207 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 208 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 209 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 210 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 211 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 212 package·--add=aide
 213 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 214 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 215 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 216 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 217 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 218 dnf·install·aide
221 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*219 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
222 Run·the·following·command·to·generate·a·new·database:220 Run·the·following·command·to·generate·a·new·database:
223 $·sudo·/usr/sbin/aide·--init221 $·sudo·/usr/sbin/aide·--init
224 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:222 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
225 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz223 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
226 To·initiate·a·manual·check,·run·the·following·command:224 To·initiate·a·manual·check,·run·the·following·command:
227 $·sudo·/usr/sbin/aide·--check225 $·sudo·/usr/sbin/aide·--check
Offset 939, 29 lines modifiedOffset 939, 29 lines modified
939 References:··_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)939 References:··_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)
940 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4940 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4
941 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227941 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
942 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-08-010800942 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-08-010800
943 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R28943 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R28
944 ·············_\x8c_\x8i_\x8s············1.1.2.3.1944 ·············_\x8c_\x8i_\x8s············1.1.2.3.1
945 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-230328r1017139_rule945 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-230328r1017139_rule
946 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
947 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
948 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high 
949 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
950 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
951 part·/home 
952 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8946 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
953 [[customizations.filesystem]]947 [[customizations.filesystem]]
954 mountpoint·=·"/home"948 mountpoint·=·"/home"
955 size·=·1073741824949 size·=·1073741824
956 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8950 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
957 logvol·/home·1024951 logvol·/home·1024
 952 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 953 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 954 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high
 955 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 956 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 957 part·/home
958 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/t\x8tm\x8mp\x8p·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*958 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/t\x8tm\x8mp\x8p·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
959 The·/tmp·directory·is·a·world-writable·directory·used·for·temporary·file·storage.·Ensure·it·has·its·own·partition·or·logical·volume·at·installation·time,·or·migrate·it·using·LVM.959 The·/tmp·directory·is·a·world-writable·directory·used·for·temporary·file·storage.·Ensure·it·has·its·own·partition·or·logical·volume·at·installation·time,·or·migrate·it·using·LVM.
960 Rationale:···The·/tmp·partition·is·used·as·temporary·storage·by·many·programs.·Placing·/tmp·in·its·own·partition·enables·the·setting·of·more·restrictive·mount·options,·which·can·help·protect·programs·which·use·it.960 Rationale:···The·/tmp·partition·is·used·as·temporary·storage·by·many·programs.·Placing·/tmp·in·its·own·partition·enables·the·setting·of·more·restrictive·mount·options,·which·can·help·protect·programs·which·use·it.
961 Severity: ···low961 Severity: ···low
962 Rule·ID:·····xccdf_org.ssgproject.content_rule_partition_for_tmp962 Rule·ID:·····xccdf_org.ssgproject.content_rule_partition_for_tmp
963 Identifiers:·CCE-80851-9963 Identifiers:·CCE-80851-9
964 ·············_\x8c_\x8i_\x8s_\x8-_\x8c_\x8s_\x8c········12,·15,·8964 ·············_\x8c_\x8i_\x8s_\x8-_\x8c_\x8s_\x8c········12,·15,·8
Offset 971, 29 lines modifiedOffset 971, 29 lines modified
971 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.3971 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.3
Max diff block lines reached; 166761/172225 bytes (96.83%) of diff not shown.
1.65 MB
./usr/share/doc/ssg-nondebian/ssg-rhel8-guide-cui.html
    
Offset 15360, 208 lines modifiedOffset 15360, 208 lines modified
0003bff0:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i0003bff0:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i
0003c000:·646d·3739·3931·2220·7461·6269·6e64·6578··dm7991"·tabindex0003c000:·646d·3739·3931·2220·7461·6269·6e64·6578··dm7991"·tabindex
0003c010:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto0003c010:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto
0003c020:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded0003c020:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded
0003c030:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="0003c030:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="
0003c040:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve0003c040:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve
0003c050:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re0003c050:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re
0003c060:·6d65·6469·6174·696f·6e20·7363·7269·7074··mediation·script0003c060:·6d65·6469·6174·696f·6e20·4f53·4275·696c··mediation·OSBuil
 0003c070:·6420·426c·7565·7072·696e·7420·736e·6970··d·Blueprint·snip
 0003c080:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br><
 0003c090:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
 0003c0a0:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap
 0003c0b0:·7365·2220·6964·3d22·6964·6d37·3939·3122··se"·id="idm7991"
 0003c0c0:·3e3c·7072·653e·3c63·6f64·653e·0a5b·5b70··><pre><code>.[[p
 0003c0d0:·6163·6b61·6765·735d·5d0a·6e61·6d65·203d··ackages]].name·=
 0003c0e0:·2022·6169·6465·220a·7665·7273·696f·6e20···"aide".version·
 0003c0f0:·3d20·222a·220a·3c2f·636f·6465·3e3c·2f70··=·"*".</code></p
0003c070:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div 
0003c080:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co 
0003c090:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse" 
0003c0a0:·2069·643d·2269·646d·3739·3931·223e·3c74···id="idm7991"><t 
0003c0b0:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl 
0003c0c0:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped· 
0003c0d0:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t 
0003c0e0:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed"> 
0003c0f0:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi 
0003c100:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low< 
0003c110:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0003c120:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th 
0003c130:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t 
0003c140:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot 
0003c150:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false< 
0003c160:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0003c170:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th>< 
0003c180:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></ 
0003c190:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre> 
0003c1a0:·3c63·6f64·653e·0a64·6e66·2069·6e73·7461··<code>.dnf·insta 
0003c1b0:·6c6c·2061·6964·650a·3c2f·636f·6465·3e3c··ll·aide.</code>< 
0003c1c0:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl0003c100:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas
0003c1d0:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc0003c110:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe
0003c1e0:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl0003c120:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle=
0003c1f0:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat0003c130:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data-
0003c200:·612d·7461·7267·6574·3d22·2369·646d·3739··a-target="#idm790003c140:·7461·7267·6574·3d22·2369·646d·3739·3932··target="#idm7992
0003c210:·3932·2220·7461·6269·6e64·6578·3d22·3022··92"·tabindex="0"0003c150:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r
0003c220:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a0003c160:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari
0003c230:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa0003c170:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals
0003c240:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti0003c180:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa
0003c250:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·0003c190:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr
0003c260:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi0003c1a0:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat
 0003c1b0:·696f·6e20·5075·7070·6574·2073·6e69·7070··ion·Puppet·snipp
0003c270:·6174·696f·6e20·416e·6163·6f6e·6461·2073··ation·Anaconda·s 
0003c280:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b 
0003c290:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa 
0003c2a0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col 
0003c2b0:·6c61·7073·6522·2069·643d·2269·646d·3739··lapse"·id="idm79 
0003c2c0:·3932·223e·3c74·6162·6c65·2063·6c61·7373··92"><table·class 
0003c2d0:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st 
0003c2e0:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord 
0003c2f0:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde 
0003c300:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co 
0003c310:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t 
0003c320:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr>< 
0003c330:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio 
0003c340:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</ 
0003c350:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
0003c360:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td> 
0003c370:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr>< 
0003c380:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy: 
0003c390:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable< 
0003c3a0:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table 
0003c3b0:·3e3c·7072·653e·3c63·6f64·653e·0a70·6163··><pre><code>.pac 
0003c3c0:·6b61·6765·202d·2d61·6464·3d61·6964·650a··kage·--add=aide. 
0003c3d0:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d 
0003c3e0:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn 
0003c3f0:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da 
0003c400:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla 
0003c410:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target 
0003c420:·3d22·2369·646d·3739·3933·2220·7461·6269··="#idm7993"·tabi 
0003c430:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b 
0003c440:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa 
0003c450:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit 
0003c460:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to· 
0003c470:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#! 
0003c480:·223e·5265·6d65·6469·6174·696f·6e20·4f53··">Remediation·OS 
0003c490:·4275·696c·6420·426c·7565·7072·696e·7420··Build·Blueprint· 
0003c4a0:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a>< 
0003c4b0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p 
0003c4c0:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co 
0003c4d0:·6c6c·6170·7365·2220·6964·3d22·6964·6d37··llapse"·id="idm7 
0003c4e0:·3939·3322·3e3c·7072·653e·3c63·6f64·653e··993"><pre><code> 
0003c4f0:·0a5b·5b70·6163·6b61·6765·735d·5d0a·6e61··.[[packages]].na 
0003c500:·6d65·203d·2022·6169·6465·220a·7665·7273··me·=·"aide".vers 
0003c510:·696f·6e20·3d20·222a·220a·3c2f·636f·6465··ion·=·"*".</code 
0003c520:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a· 
0003c530:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s 
0003c540:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog 
0003c550:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d 
0003c560:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm 
0003c570:·3739·3934·2220·7461·6269·6e64·6578·3d22··7994"·tabindex=" 
0003c580:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button" 
0003c590:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded=" 
0003c5a0:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac 
0003c5b0:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal 
0003c5c0:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme 
0003c5d0:·6469·6174·696f·6e20·7363·7269·7074·20e2··diation·script·. 
0003c5e0:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c0003c1c0:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d
0003c5f0:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll0003c1d0:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-
0003c600:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i0003c1e0:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps
0003c610:·643d·2269·646d·3739·3934·223e·3c74·6162··d="idm7994"><tab0003c1f0:·6522·2069·643d·2269·646d·3739·3932·223e··e"·id="idm7992">
0003c620:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·0003c200:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta
0003c630:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta0003c210:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe
0003c640:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab0003c220:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered
0003c650:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t0003c230:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed
0003c660:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity0003c240:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple
0003c670:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t 
0003c680:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D 
0003c690:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th>< 
0003c6a0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
0003c6b0:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:< 
0003c6c0:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t 
0003c6d0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S 
0003c6e0:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td 
0003c6f0:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr 
0003c700:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c 
0003c710:·6f64·653e·0a70·6163·6b61·6765·2069·6e73··ode>.package·ins 
0003c720:·7461·6c6c·2061·6964·650a·3c2f·636f·6465··tall·aide.</code 
0003c730:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a· 
Max diff block lines reached; 1525920/1553272 bytes (98.24%) of diff not shown.
169 KB
html2text {}
    
Offset 162, 52 lines modifiedOffset 162, 38 lines modified
162 ··-·PCI-DSSv4-11.5.2162 ··-·PCI-DSSv4-11.5.2
163 ··-·enable_strategy163 ··-·enable_strategy
164 ··-·low_complexity164 ··-·low_complexity
165 ··-·low_disruption165 ··-·low_disruption
166 ··-·medium_severity166 ··-·medium_severity
167 ··-·no_reboot_needed167 ··-·no_reboot_needed
168 ··-·package_aide_installed168 ··-·package_aide_installed
169 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
170 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
171 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
172 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
173 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
174 dnf·install·aide 
175 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
176 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
177 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
178 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
179 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
180 package·--add=aide 
181 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8169 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
182 [[packages]]170 [[packages]]
183 name·=·"aide"171 name·=·"aide"
184 version·=·"*"172 version·=·"*"
185 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
186 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
187 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
188 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
189 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
190 package·install·aide 
191 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8173 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
192 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low174 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
193 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low175 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
194 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false176 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
195 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable177 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
196 include·install_aide178 include·install_aide
  
197 class·install_aide·{179 class·install_aide·{
198 ··package·{·'aide':180 ··package·{·'aide':
199 ····ensure·=>·'installed',181 ····ensure·=>·'installed',
200 ··}182 ··}
201 }183 }
 184 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 185 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 186 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 187 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 188 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 189 package·install·aide
202 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8190 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
203 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low191 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
204 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low192 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
205 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false193 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
206 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable194 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
207 #·Remediation·is·applicable·only·in·certain·platforms195 #·Remediation·is·applicable·only·in·certain·platforms
208 if·rpm·--quiet·-q·kernel;·then196 if·rpm·--quiet·-q·kernel;·then
Offset 215, 14 lines modifiedOffset 201, 28 lines modified
215 if·!·rpm·-q·--quiet·"aide"·;·then201 if·!·rpm·-q·--quiet·"aide"·;·then
216 ····yum·install·-y·"aide"202 ····yum·install·-y·"aide"
217 fi203 fi
  
218 else204 else
219 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'205 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
220 fi206 fi
 207 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 208 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 209 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 210 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 211 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 212 package·--add=aide
 213 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 214 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 215 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 216 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 217 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 218 dnf·install·aide
221 Group  ·Federal·Information·Processing·Standard·(FIPS)·  Group·contains·2·rules219 Group  ·Federal·Information·Processing·Standard·(FIPS)·  Group·contains·2·rules
222 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·Federal·Information·Processing·Standard·(FIPS)·is·a·computer·security·standard·which·is·developed·by·the·U.S.·Government·and·industry·working·groups·to·validate·the·quality·of·cryptographic·modules.·The·FIPS·standard·provides·four·security·levels·to·ensure·adequate·coverage·of·different·industries,·implementation·of·cryptographic·modules,·and·organizational·sizes·and·requirements.220 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·Federal·Information·Processing·Standard·(FIPS)·is·a·computer·security·standard·which·is·developed·by·the·U.S.·Government·and·industry·working·groups·to·validate·the·quality·of·cryptographic·modules.·The·FIPS·standard·provides·four·security·levels·to·ensure·adequate·coverage·of·different·industries,·implementation·of·cryptographic·modules,·and·organizational·sizes·and·requirements.
  
223 FIPS·140-2·is·the·current·standard·for·validating·that·mechanisms·used·to·access·cryptographic·modules·utilize·authentication·that·meets·industry·and·government·requirements.·For·government·systems,·this·allows·Security·Levels·1,·2,·3,·or·4·for·use·on·Red·Hat·Enterprise·Linux·8.221 FIPS·140-2·is·the·current·standard·for·validating·that·mechanisms·used·to·access·cryptographic·modules·utilize·authentication·that·meets·industry·and·government·requirements.·For·government·systems,·this·allows·Security·Levels·1,·2,·3,·or·4·for·use·on·Red·Hat·Enterprise·Linux·8.
  
224 See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8c\x8c_\x8s\x8s_\x8r\x8r_\x8c\x8c_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8l\x8l_\x8i\x8i_\x8c\x8c_\x8a\x8a_\x8t\x8t_\x8i\x8i_\x8o\x8o_\x8n\x8n_\x8s\x8s_\x8/\x8/_\x8P\x8P_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x8h\x8h_\x8t\x8t_\x8m\x8m_\x8l\x8l·for·more·information.222 See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8c\x8c_\x8s\x8s_\x8r\x8r_\x8c\x8c_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8l\x8l_\x8i\x8i_\x8c\x8c_\x8a\x8a_\x8t\x8t_\x8i\x8i_\x8o\x8o_\x8n\x8n_\x8s\x8s_\x8/\x8/_\x8P\x8P_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x8h\x8h_\x8t\x8t_\x8m\x8m_\x8l\x8l·for·more·information.
225 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·D\x8Dr\x8ra\x8ac\x8cu\x8ut\x8t·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8du\x8ul\x8le\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*223 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·D\x8Dr\x8ra\x8ac\x8cu\x8ut\x8t·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8du\x8ul\x8le\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
Offset 307, 61 lines modifiedOffset 307, 61 lines modified
307 ··-·CCE-82723-8307 ··-·CCE-82723-8
308 ··-·enable_strategy308 ··-·enable_strategy
309 ··-·low_complexity309 ··-·low_complexity
310 ··-·low_disruption310 ··-·low_disruption
311 ··-·medium_severity311 ··-·medium_severity
312 ··-·no_reboot_needed312 ··-·no_reboot_needed
313 ··-·package_crypto-policies_installed313 ··-·package_crypto-policies_installed
314 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
315 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
316 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
317 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
318 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
319 dnf·install·crypto-policies 
320 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
321 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
322 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
323 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
324 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
325 package·--add=crypto-policies 
326 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8314 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
327 [[packages]]315 [[packages]]
328 name·=·"crypto-policies"316 name·=·"crypto-policies"
329 version·=·"*"317 version·=·"*"
330 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
331 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
332 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
333 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
334 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
335 package·install·crypto-policies 
336 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8318 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
337 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low319 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
338 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low320 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
339 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false321 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
340 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable322 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
Max diff block lines reached; 168074/173257 bytes (97.01%) of diff not shown.
556 KB
./usr/share/doc/ssg-nondebian/ssg-rhel8-guide-e8.html
    
Offset 20025, 278 lines modifiedOffset 20025, 278 lines modified
0004e380:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="0004e380:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
0004e390:·2369·646d·3132·3931·3322·2074·6162·696e··#idm12913"·tabin0004e390:·2369·646d·3132·3931·3322·2074·6162·696e··#idm12913"·tabin
0004e3a0:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu0004e3a0:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
0004e3b0:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan0004e3b0:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
0004e3c0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl0004e3c0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
0004e3d0:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r0004e3d0:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
0004e3e0:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"0004e3e0:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
0004e3f0:·3e52·656d·6564·6961·7469·6f6e·2073·6372··>Remediation·scr0004e3f0:·3e52·656d·6564·6961·7469·6f6e·204f·5342··>Remediation·OSB
 0004e400:·7569·6c64·2042·6c75·6570·7269·6e74·2073··uild·Blueprint·s
 0004e410:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b
0004e400:·6970·7420·e287·b23c·2f61·3e3c·6272·3e3c··ipt·...</a><br>< 
0004e410:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel 
0004e420:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap 
0004e430:·7365·2220·6964·3d22·6964·6d31·3239·3133··se"·id="idm12913 
0004e440:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="0004e420:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
 0004e430:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
 0004e440:·6c61·7073·6522·2069·643d·2269·646d·3132··lapse"·id="idm12
 0004e450:·3931·3322·3e3c·7072·653e·3c63·6f64·653e··913"><pre><code>
 0004e460:·0a5b·5b70·6163·6b61·6765·735d·5d0a·6e61··.[[packages]].na
 0004e470:·6d65·203d·2022·7265·6172·220a·7665·7273··me·=·"rear".vers
 0004e480:·696f·6e20·3d20·222a·220a·3c2f·636f·6465··ion·=·"*".</code
0004e450:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri 
0004e460:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border 
0004e470:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens 
0004e480:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp 
0004e490:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td> 
0004e4a0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr 
0004e4b0:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption: 
0004e4c0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td 
0004e4d0:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re 
0004e4e0:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa 
0004e4f0:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr 
0004e500:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</ 
0004e510:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t 
0004e520:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table>< 
0004e530:·7072·653e·3c63·6f64·653e·0a64·6e66·2069··pre><code>.dnf·i 
0004e540:·6e73·7461·6c6c·2072·6561·720a·3c2f·636f··nstall·rear.</co 
0004e550:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div><0004e490:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a·
0004e560:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn0004e4a0:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s
0004e570:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t0004e4b0:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog
0004e580:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse"0004e4c0:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d
0004e590:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i0004e4d0:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
0004e5a0:·646d·3132·3931·3422·2074·6162·696e·6465··dm12914"·tabinde0004e4e0:·3132·3931·3422·2074·6162·696e·6465·783d··12914"·tabindex=
0004e5b0:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt0004e4f0:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button
0004e5c0:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande0004e500:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=
0004e5d0:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=0004e510:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A
0004e5e0:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev0004e520:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea
0004e5f0:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R0004e530:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem
 0004e540:·6564·6961·7469·6f6e·2050·7570·7065·7420··ediation·Puppet·
0004e600:·656d·6564·6961·7469·6f6e·2041·6e61·636f··emediation·Anaco 
0004e610:·6e64·6120·736e·6970·7065·7420·e287·b23c··nda·snippet·...< 
0004e620:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas 
0004e630:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps 
0004e640:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id=" 
0004e650:·6964·6d31·3239·3134·223e·3c74·6162·6c65··idm12914"><table 
0004e660:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta 
0004e670:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl 
0004e680:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table 
0004e690:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr> 
0004e6a0:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:< 
0004e6b0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td> 
0004e6c0:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis 
0004e6d0:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td 
0004e6e0:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t 
0004e6f0:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t 
0004e700:·683e·3c74·643e·6661·6c73·653c·2f74·643e··h><td>false</td> 
0004e710:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str 
0004e720:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e 
0004e730:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr>< 
0004e740:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod 
0004e750:·653e·0a70·6163·6b61·6765·202d·2d61·6464··e>.package·--add 
0004e760:·3d72·6561·720a·3c2f·636f·6465·3e3c·2f70··=rear.</code></p 
0004e770:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas 
0004e780:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe 
0004e790:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle= 
0004e7a0:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data- 
0004e7b0:·7461·7267·6574·3d22·2369·646d·3132·3931··target="#idm1291 
0004e7c0:·3522·2074·6162·696e·6465·783d·2230·2220··5"·tabindex="0"· 
0004e7d0:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar 
0004e7e0:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal 
0004e7f0:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ 
0004e800:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h 
0004e810:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia 
0004e820:·7469·6f6e·204f·5342·7569·6c64·2042·6c75··tion·OSBuild·Blu 
0004e830:·6570·7269·6e74·2073·6e69·7070·6574·20e2··eprint·snippet·. 
0004e840:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c 
0004e850:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll 
0004e860:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i 
0004e870:·643d·2269·646d·3132·3931·3522·3e3c·7072··d="idm12915"><pr 
0004e880:·653e·3c63·6f64·653e·0a5b·5b70·6163·6b61··e><code>.[[packa 
0004e890:·6765·735d·5d0a·6e61·6d65·203d·2022·7265··ges]].name·=·"re 
0004e8a0:·6172·220a·7665·7273·696f·6e20·3d20·222a··ar".version·=·"* 
0004e8b0:·220a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··".</code></pre>< 
0004e8c0:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b 
0004e8d0:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"· 
0004e8e0:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col 
0004e8f0:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ 
0004e900:·6574·3d22·2369·646d·3132·3931·3622·2074··et="#idm12916"·t 
0004e910:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role 
0004e920:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e 
0004e930:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"· 
0004e940:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate· 
0004e950:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href= 
0004e960:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation 
0004e970:·2073·6372·6970·7420·e287·b23c·2f61·3e3c···script·...</a><0004e550:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><
0004e980:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p0004e560:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
0004e990:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co0004e570:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
0004e9a0:·6c6c·6170·7365·2220·6964·3d22·6964·6d31··llapse"·id="idm10004e580:·6c6c·6170·7365·2220·6964·3d22·6964·6d31··llapse"·id="idm1
0004e9b0:·3239·3136·223e·3c74·6162·6c65·2063·6c61··2916"><table·cla0004e590:·3239·3134·223e·3c74·6162·6c65·2063·6c61··2914"><table·cla
0004e9c0:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-0004e5a0:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-
0004e9d0:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo0004e5b0:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo
0004e9e0:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con0004e5c0:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con
0004e9f0:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>0004e5d0:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>
0004ea00:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>0004e5e0:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>
0004ea10:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr0004e5f0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
0004ea20:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt0004e600:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt
0004ea30:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low0004e610:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low
0004ea40:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t0004e620:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
0004ea50:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t0004e630:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t
0004ea60:·643e·6661·6c73·653c·2f74·643e·3c2f·7472··d>false</td></tr0004e640:·643e·6661·6c73·653c·2f74·643e·3c2f·7472··d>false</td></tr
0004ea70:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg0004e650:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg
0004ea80:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl0004e660:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl
0004ea90:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab0004e670:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab
0004eaa0:·6c65·3e3c·7072·653e·3c63·6f64·653e·0a70··le><pre><code>.p0004e680:·6c65·3e3c·7072·653e·3c63·6f64·653e·696e··le><pre><code>in
0004eab0:·6163·6b61·6765·2069·6e73·7461·6c6c·2072··ackage·install·r 
0004eac0:·6561·720a·3c2f·636f·6465·3e3c·2f70·7265··ear.</code></pre 
0004ead0:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class= 
Max diff block lines reached; 466638/503650 bytes (92.65%) of diff not shown.
63.9 KB
html2text {}
    
Offset 1196, 52 lines modifiedOffset 1196, 38 lines modified
1196 ··-·CCE-82883-01196 ··-·CCE-82883-0
1197 ··-·enable_strategy1197 ··-·enable_strategy
1198 ··-·low_complexity1198 ··-·low_complexity
1199 ··-·low_disruption1199 ··-·low_disruption
1200 ··-·medium_severity1200 ··-·medium_severity
1201 ··-·no_reboot_needed1201 ··-·no_reboot_needed
1202 ··-·package_rear_installed1202 ··-·package_rear_installed
1203 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
1204 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
1205 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
1206 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
1207 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
1208 dnf·install·rear 
1209 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
1210 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
1211 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
1212 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
1213 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
1214 package·--add=rear 
1215 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81203 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
1216 [[packages]]1204 [[packages]]
1217 name·=·"rear"1205 name·=·"rear"
1218 version·=·"*"1206 version·=·"*"
1219 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
1220 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
1221 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
1222 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
1223 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
1224 package·install·rear 
1225 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81207 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1226 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1208 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1227 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1209 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1228 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1210 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1229 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1211 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1230 include·install_rear1212 include·install_rear
  
1231 class·install_rear·{1213 class·install_rear·{
1232 ··package·{·'rear':1214 ··package·{·'rear':
1233 ····ensure·=>·'installed',1215 ····ensure·=>·'installed',
1234 ··}1216 ··}
1235 }1217 }
 1218 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 1219 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1220 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1221 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1222 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 1223 package·install·rear
1236 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81224 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1237 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1225 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1238 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1226 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1239 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1227 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1240 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1228 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1241 #·Remediation·is·applicable·only·in·certain·platforms1229 #·Remediation·is·applicable·only·in·certain·platforms
1242 if·!·(·(·(·(·grep·-sqE·"^.*\.aarch64$"·/proc/sys/kernel/osrelease·||·grep·-sqE·"^aarch64$"·/proc/sys/kernel/arch;·)·&&·grep·-qP·"^ID=[\"']?ol[\"']?$"·"/etc/os-release"·&&·{·real="$(grep·-P·"^VERSION_ID=[\"']?[\w.]+[\"']?$"·/etc/os-release·|·sed·"s/^VERSION_ID=[\"']\?\([^\"']\+\)[\"']\?$/\1/")";·expected="9.0";·printf·"%s\n%s"·"$expected"·"$real"·|·sort·-VC;·}·)·||·(·(·grep·-sqE·"^.*\.aarch64$"·/proc/sys/kernel/osrelease·||·grep·-sqE·"^aarch64$"·/proc/sys/kernel/arch;·)·&&·grep·-qP·"^ID=[\"']?rhel[\"']?$"·"/etc/os-release"·&&·{·real="$(grep·-P·"^VERSION_ID=[\"']?[\w.]+[\"']?$"·/etc/os-release·|·sed·"s/^VERSION_ID=[\"']\?\([^\"']\+\)[\"']\?$/\1/")";·expected="9.0";·printf·"%s\n%s"·"$expected"·"$real"·|·sort·-VC;·}·)·||·(·grep·-qP·"^ID=[\"']?rhel[\"']?$"·"/etc/os-release"·&&·{·real="$(grep·-P·"^VERSION_ID=[\"']?[\w.]+[\"']?$"·/etc/os-release·|·sed·"s/^VERSION_ID=[\"']\?\([^\"']\+\)[\"']\?$/\1/")";·expected="8.4";·printf·"%s\n%s"·"$real"·"$expected"·|·sort·-VC;·}·&&·(·grep·-sqE·"^.*\.s390x$"·/proc/sys/kernel/osrelease·||·grep·-sqE·"^s390x$"·/proc/sys/kernel/arch;·)·)·)·);·then1230 if·!·(·(·(·(·grep·-sqE·"^.*\.aarch64$"·/proc/sys/kernel/osrelease·||·grep·-sqE·"^aarch64$"·/proc/sys/kernel/arch;·)·&&·grep·-qP·"^ID=[\"']?ol[\"']?$"·"/etc/os-release"·&&·{·real="$(grep·-P·"^VERSION_ID=[\"']?[\w.]+[\"']?$"·/etc/os-release·|·sed·"s/^VERSION_ID=[\"']\?\([^\"']\+\)[\"']\?$/\1/")";·expected="9.0";·printf·"%s\n%s"·"$expected"·"$real"·|·sort·-VC;·}·)·||·(·(·grep·-sqE·"^.*\.aarch64$"·/proc/sys/kernel/osrelease·||·grep·-sqE·"^aarch64$"·/proc/sys/kernel/arch;·)·&&·grep·-qP·"^ID=[\"']?rhel[\"']?$"·"/etc/os-release"·&&·{·real="$(grep·-P·"^VERSION_ID=[\"']?[\w.]+[\"']?$"·/etc/os-release·|·sed·"s/^VERSION_ID=[\"']\?\([^\"']\+\)[\"']\?$/\1/")";·expected="9.0";·printf·"%s\n%s"·"$expected"·"$real"·|·sort·-VC;·}·)·||·(·grep·-qP·"^ID=[\"']?rhel[\"']?$"·"/etc/os-release"·&&·{·real="$(grep·-P·"^VERSION_ID=[\"']?[\w.]+[\"']?$"·/etc/os-release·|·sed·"s/^VERSION_ID=[\"']\?\([^\"']\+\)[\"']\?$/\1/")";·expected="8.4";·printf·"%s\n%s"·"$real"·"$expected"·|·sort·-VC;·}·&&·(·grep·-sqE·"^.*\.s390x$"·/proc/sys/kernel/osrelease·||·grep·-sqE·"^s390x$"·/proc/sys/kernel/arch;·)·)·)·);·then
Offset 1249, 14 lines modifiedOffset 1235, 28 lines modified
1249 if·!·rpm·-q·--quiet·"rear"·;·then1235 if·!·rpm·-q·--quiet·"rear"·;·then
1250 ····yum·install·-y·"rear"1236 ····yum·install·-y·"rear"
1251 fi1237 fi
  
1252 else1238 else
1253 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'1239 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
1254 fi1240 fi
 1241 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 1242 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1243 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1244 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1245 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 1246 package·--add=rear
 1247 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 1248 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1249 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1250 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1251 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 1252 dnf·install·rear
1255 Group  ·Updating·Software·  Group·contains·6·rules1253 Group  ·Updating·Software·  Group·contains·6·rules
1256 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·yum·command·line·tool·is·used·to·install·and·update·software·packages.·The·system·also·provides·a·graphical·software·update·tool·in·the·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·menu,·in·the·A\x8Ad\x8dm\x8mi\x8in\x8ni\x8is\x8st\x8tr\x8ra\x8at\x8ti\x8io\x8on\x8n·submenu,·called·S\x8So\x8of\x8ft\x8tw\x8wa\x8ar\x8re\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8e.1254 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·yum·command·line·tool·is·used·to·install·and·update·software·packages.·The·system·also·provides·a·graphical·software·update·tool·in·the·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·menu,·in·the·A\x8Ad\x8dm\x8mi\x8in\x8ni\x8is\x8st\x8tr\x8ra\x8at\x8ti\x8io\x8on\x8n·submenu,·called·S\x8So\x8of\x8ft\x8tw\x8wa\x8ar\x8re\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8e.
  
1257 Red·Hat·Enterprise·Linux·8·systems·contain·an·installed·software·catalog·called·the·RPM·database,·which·records·metadata·of·installed·packages.·Consistently·using·yum·or·the·graphical·S\x8So\x8of\x8ft\x8tw\x8wa\x8ar\x8re\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8e·for·all·software·installation·allows·for·insight·into·the·current·inventory·of·installed·software·on·the·system.1255 Red·Hat·Enterprise·Linux·8·systems·contain·an·installed·software·catalog·called·the·RPM·database,·which·records·metadata·of·installed·packages.·Consistently·using·yum·or·the·graphical·S\x8So\x8of\x8ft\x8tw\x8wa\x8ar\x8re\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8e·for·all·software·installation·allows·for·insight·into·the·current·inventory·of·installed·software·on·the·system.
  
1258 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·d\x8dn\x8nf\x8f-\x8-a\x8au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8c·t\x8to\x8o·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·O\x8On\x8nl\x8ly\x8y·S\x8Se\x8ec\x8cu\x8ur\x8ri\x8it\x8ty\x8y·U\x8Up\x8pd\x8da\x8at\x8te\x8es\x8s·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*1256 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·d\x8dn\x8nf\x8f-\x8-a\x8au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8c·t\x8to\x8o·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·O\x8On\x8nl\x8ly\x8y·S\x8Se\x8ec\x8cu\x8ur\x8ri\x8it\x8ty\x8y·U\x8Up\x8pd\x8da\x8at\x8te\x8es\x8s·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
1259 To·configure·dnf-automatic·to·install·only·security·updates·automatically,·set·upgrade_type·to·security·under·[commands]·section·in·/etc/dnf/automatic.conf.1257 To·configure·dnf-automatic·to·install·only·security·updates·automatically,·set·upgrade_type·to·security·under·[commands]·section·in·/etc/dnf/automatic.conf.
Offset 2426, 52 lines modifiedOffset 2426, 38 lines modified
2426 ··-·NIST-800-53-CM-6(a)2426 ··-·NIST-800-53-CM-6(a)
2427 ··-·enable_strategy2427 ··-·enable_strategy
2428 ··-·low_complexity2428 ··-·low_complexity
2429 ··-·low_disruption2429 ··-·low_disruption
2430 ··-·medium_severity2430 ··-·medium_severity
2431 ··-·no_reboot_needed2431 ··-·no_reboot_needed
2432 ··-·package_rsyslog_installed2432 ··-·package_rsyslog_installed
2433 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
2434 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
2435 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
2436 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
2437 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
2438 dnf·install·rsyslog 
2439 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
2440 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
2441 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
2442 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
2443 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
2444 package·--add=rsyslog 
2445 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x82433 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
2446 [[packages]]2434 [[packages]]
2447 name·=·"rsyslog"2435 name·=·"rsyslog"
2448 version·=·"*"2436 version·=·"*"
2449 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
2450 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
2451 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
2452 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
2453 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
2454 package·install·rsyslog 
2455 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x82437 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
2456 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low2438 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
2457 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low2439 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
2458 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false2440 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
2459 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable2441 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
Max diff block lines reached; 59286/65391 bytes (90.66%) of diff not shown.
359 KB
./usr/share/doc/ssg-nondebian/ssg-rhel8-guide-hipaa.html
    
Offset 22718, 129 lines modifiedOffset 22718, 129 lines modified
00058bd0:·7461·7267·6574·3d22·2369·646d·3137·3139··target="#idm171900058bd0:·7461·7267·6574·3d22·2369·646d·3137·3139··target="#idm1719
00058be0:·3122·2074·6162·696e·6465·783d·2230·2220··1"·tabindex="0"·00058be0:·3122·2074·6162·696e·6465·783d·2230·2220··1"·tabindex="0"·
00058bf0:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar00058bf0:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar
00058c00:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal00058c00:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal
00058c10:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ00058c10:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ
00058c20:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h00058c20:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h
00058c30:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia00058c30:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia
00058c40:·7469·6f6e·204b·7562·6572·6e65·7465·7320··tion·Kubernetes·00058c40:·7469·6f6e·2050·7570·7065·7420·736e·6970··tion·Puppet·snip
00058c50:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><00058c50:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br><
00058c60:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p00058c60:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
00058c70:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co00058c70:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap
00058c80:·6c6c·6170·7365·2220·6964·3d22·6964·6d31··llapse"·id="idm100058c80:·7365·2220·6964·3d22·6964·6d31·3731·3931··se"·id="idm17191
00058c90:·3731·3931·223e·3c74·6162·6c65·2063·6c61··7191"><table·cla00058c90:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="
00058ca0:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-00058ca0:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri
00058cb0:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo00058cb0:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border
00058cc0:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con00058cc0:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens
00058cd0:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>00058cd0:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp
00058ce0:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>00058ce0:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>
00058cf0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr00058cf0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
00058d00:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt00058d00:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:
00058d10:·696f·6e3a·3c2f·7468·3e3c·7464·3e6d·6564··ion:</th><td>med00058d10:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
 00058d20:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re
 00058d30:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa
00058d20:·6975·6d3c·2f74·643e·3c2f·7472·3e3c·7472··ium</td></tr><tr00058d40:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr
 00058d50:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</
 00058d60:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t
 00058d70:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><
 00058d80:·7072·653e·3c63·6f64·653e·696e·636c·7564··pre><code>includ
 00058d90:·6520·6469·7361·626c·655f·6465·6275·672d··e·disable_debug-
 00058da0:·7368·656c·6c0a·0a63·6c61·7373·2064·6973··shell..class·dis
 00058db0:·6162·6c65·5f64·6562·7567·2d73·6865·6c6c··able_debug-shell
 00058dc0:·207b·0a20·2073·6572·7669·6365·207b·2764···{.··service·{'d
 00058dd0:·6562·7567·2d73·6865·6c6c·273a·0a20·2020··ebug-shell':.···
 00058de0:·2065·6e61·626c·6520·3d26·6774·3b20·6661···enable·=&gt;·fa
 00058df0:·6c73·652c·0a20·2020·2065·6e73·7572·6520··lse,.····ensure·
 00058e00:·3d26·6774·3b20·2773·746f·7070·6564·272c··=&gt;·'stopped',
 00058e10:·0a20·207d·0a7d·0a3c·2f63·6f64·653e·3c2f··.··}.}.</code></
 00058e20:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla
 00058e30:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ
 00058e40:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle
 00058e50:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data
 00058e60:·2d74·6172·6765·743d·2223·6964·6d31·3731··-target="#idm171
 00058e70:·3932·2220·7461·6269·6e64·6578·3d22·3022··92"·tabindex="0"
 00058e80:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
 00058e90:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
 00058ea0:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
 00058eb0:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
 00058ec0:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
 00058ed0:·6174·696f·6e20·7363·7269·7074·20e2·87b2··ation·script·...
 00058ee0:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
 00058ef0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
 00058f00:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
 00058f10:·2269·646d·3137·3139·3222·3e3c·7461·626c··"idm17192"><tabl
 00058f20:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t
 00058f30:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab
 00058f40:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl
 00058f50:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr
 00058f60:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:
 00058f70:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
 00058f80:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di
 00058f90:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t
 00058fa0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
00058d30:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th00058fb0:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</
00058d40:·3e3c·7464·3e74·7275·653c·2f74·643e·3c2f··><td>true</td></ 
00058d50:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat00058fc0:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td
 00058fd0:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St
 00058fe0:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>
 00058ff0:·6469·7361·626c·653c·2f74·643e·3c2f·7472··disable</td></tr
 00059000:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c
 00059010:·6f64·653e·0a73·6572·7669·6365·2064·6973··ode>.service·dis
 00059020:·6162·6c65·2064·6562·7567·2d73·6865·6c6c··able·debug-shell
 00059030:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></
 00059040:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt
 00059050:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d
 00059060:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll
 00059070:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
 00059080:·743d·2223·6964·6d31·3731·3933·2220·7461··t="#idm17193"·ta
 00059090:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
 000590a0:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
 000590b0:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
 000590c0:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
 000590d0:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
 000590e0:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
 000590f0:·4b75·6265·726e·6574·6573·2073·6e69·7070··Kubernetes·snipp
 00059100:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d
 00059110:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-
 00059120:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps
 00059130:·6522·2069·643d·2269·646d·3137·3139·3322··e"·id="idm17193"
 00059140:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t
 00059150:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip
 00059160:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere
 00059170:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense
 00059180:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl
00058d60:·6567·793a·3c2f·7468·3e3c·7464·3e64·6973··egy:</th><td>dis00059190:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l
 000591a0:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
 000591b0:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:<
 000591c0:·2f74·683e·3c74·643e·6d65·6469·756d·3c2f··/th><td>medium</
 000591d0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 000591e0:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td>
00058d70:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></000591f0:·7472·7565·3c2f·7464·3e3c·2f74·723e·3c74··true</td></tr><t
 00059200:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<
 00059210:·2f74·683e·3c74·643e·6469·7361·626c·653c··/th><td>disable<
 00059220:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table
 00059230:·3e3c·7072·653e·3c63·6f64·653e·6170·6956··><pre><code>apiV
 00059240:·6572·7369·6f6e·3a20·6d61·6368·696e·6563··ersion:·machinec
 00059250:·6f6e·6669·6775·7261·7469·6f6e·2e6f·7065··onfiguration.ope
 00059260:·6e73·6869·6674·2e69·6f2f·7631·0a6b·696e··nshift.io/v1.kin
 00059270:·643a·204d·6163·6869·6e65·436f·6e66·6967··d:·MachineConfig
 00059280:·0a73·7065·633a·0a20·2063·6f6e·6669·673a··.spec:.··config:
 00059290:·0a20·2020·2069·676e·6974·696f·6e3a·0a20··.····ignition:.·
 000592a0:·2020·2020·2076·6572·7369·6f6e·3a20·332e·······version:·3.
 000592b0:·312e·300a·2020·2020·7379·7374·656d·643a··1.0.····systemd:
 000592c0:·0a20·2020·2020·2075·6e69·7473·3a0a·2020··.······units:.··
 000592d0:·2020·2020·2d20·6e61·6d65·3a20·6465·6275······-·name:·debu
 000592e0:·672d·7368·656c·6c2e·7365·7276·6963·650a··g-shell.service.
00058d80:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code 
00058d90:·3e61·7069·5665·7273·696f·6e3a·206d·6163··>apiVersion:·mac 
00058da0:·6869·6e65·636f·6e66·6967·7572·6174·696f··hineconfiguratio 
00058db0:·6e2e·6f70·656e·7368·6966·742e·696f·2f76··n.openshift.io/v 
00058dc0:·310a·6b69·6e64·3a20·4d61·6368·696e·6543··1.kind:·MachineC 
00058dd0:·6f6e·6669·670a·7370·6563·3a0a·2020·636f··onfig.spec:.··co 
00058de0:·6e66·6967·3a0a·2020·2020·6967·6e69·7469··nfig:.····igniti 
00058df0:·6f6e·3a0a·2020·2020·2020·7665·7273·696f··on:.······versio 
00058e00:·6e3a·2033·2e31·2e30·0a20·2020·2073·7973··n:·3.1.0.····sys 
00058e10:·7465·6d64·3a0a·2020·2020·2020·756e·6974··temd:.······unit 
00058e20:·733a·0a20·2020·2020·202d·206e·616d·653a··s:.······-·name: 
00058e30:·2064·6562·7567·2d73·6865·6c6c·2e73·6572···debug-shell.ser 
Max diff block lines reached; 308022/324472 bytes (94.93%) of diff not shown.
42.1 KB
html2text {}
    
Offset 1761, 14 lines modifiedOffset 1761, 34 lines modified
1761 ··-·medium_severity1761 ··-·medium_severity
1762 ··-·no_reboot_needed1762 ··-·no_reboot_needed
1763 ··-·service_debug-shell_disabled1763 ··-·service_debug-shell_disabled
1764 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81764 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
1765 [customizations.services]1765 [customizations.services]
1766 masked·=·["debug-shell"]1766 masked·=·["debug-shell"]
 1767 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 1768 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1769 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1770 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1771 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 1772 include·disable_debug-shell
  
 1773 class·disable_debug-shell·{
 1774 ··service·{'debug-shell':
 1775 ····enable·=>·false,
 1776 ····ensure·=>·'stopped',
 1777 ··}
 1778 }
 1779 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 1780 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1781 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1782 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1783 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
  
 1784 service·disable·debug-shell
1767 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81785 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1768 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1786 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1769 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium1787 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
1770 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true1788 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
1771 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable1789 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
1772 apiVersion:·machineconfiguration.openshift.io/v11790 apiVersion:·machineconfiguration.openshift.io/v1
1773 kind:·MachineConfig1791 kind:·MachineConfig
Offset 1780, 34 lines modifiedOffset 1800, 14 lines modified
1780 ······units:1800 ······units:
1781 ······-·name:·debug-shell.service1801 ······-·name:·debug-shell.service
1782 ········enabled:·false1802 ········enabled:·false
1783 ········mask:·true1803 ········mask:·true
1784 ······-·name:·debug-shell.socket1804 ······-·name:·debug-shell.socket
1785 ········enabled:·false1805 ········enabled:·false
1786 ········mask:·true1806 ········mask:·true
1787 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
1788 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
1789 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
1790 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
1791 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable 
  
1792 service·disable·debug-shell 
1793 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
1794 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
1795 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
1796 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
1797 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
1798 include·disable_debug-shell 
  
1799 class·disable_debug-shell·{ 
1800 ··service·{'debug-shell': 
1801 ····enable·=>·false, 
1802 ····ensure·=>·'stopped', 
1803 ··} 
1804 } 
1805 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81807 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1806 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1808 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1807 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1809 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1808 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1810 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1809 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable1811 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
1810 #·Remediation·is·applicable·only·in·certain·platforms1812 #·Remediation·is·applicable·only·in·certain·platforms
1811 if·rpm·--quiet·-q·kernel;·then1813 if·rpm·--quiet·-q·kernel;·then
Offset 3551, 14 lines modifiedOffset 3551, 34 lines modified
3551 ··-·medium_severity3551 ··-·medium_severity
3552 ··-·no_reboot_needed3552 ··-·no_reboot_needed
3553 ··-·service_autofs_disabled3553 ··-·service_autofs_disabled
3554 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x83554 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
3555 [customizations.services]3555 [customizations.services]
3556 masked·=·["autofs"]3556 masked·=·["autofs"]
 3557 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 3558 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 3559 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 3560 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 3561 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 3562 include·disable_autofs
  
 3563 class·disable_autofs·{
 3564 ··service·{'autofs':
 3565 ····enable·=>·false,
 3566 ····ensure·=>·'stopped',
 3567 ··}
 3568 }
 3569 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 3570 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 3571 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 3572 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 3573 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
  
 3574 service·disable·autofs
3557 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x83575 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
3558 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low3576 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
3559 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium3577 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
3560 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true3578 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
3561 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable3579 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
3562 apiVersion:·machineconfiguration.openshift.io/v13580 apiVersion:·machineconfiguration.openshift.io/v1
3563 kind:·MachineConfig3581 kind:·MachineConfig
Offset 3570, 34 lines modifiedOffset 3590, 14 lines modified
3570 ······units:3590 ······units:
3571 ······-·name:·autofs.service3591 ······-·name:·autofs.service
3572 ········enabled:·false3592 ········enabled:·false
3573 ········mask:·true3593 ········mask:·true
3574 ······-·name:·autofs.socket3594 ······-·name:·autofs.socket
3575 ········enabled:·false3595 ········enabled:·false
3576 ········mask:·true3596 ········mask:·true
3577 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
3578 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
3579 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
3580 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
3581 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable 
  
3582 service·disable·autofs 
3583 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
3584 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
3585 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
3586 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
3587 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
3588 include·disable_autofs 
  
3589 class·disable_autofs·{ 
Max diff block lines reached; 38680/43083 bytes (89.78%) of diff not shown.
731 KB
./usr/share/doc/ssg-nondebian/ssg-rhel8-guide-ism_o.html
    
Offset 17711, 207 lines modifiedOffset 17711, 207 lines modified
000452e0:·6172·6765·743d·2223·6964·6d37·3939·3122··arget="#idm7991"000452e0:·6172·6765·743d·2223·6964·6d37·3939·3122··arget="#idm7991"
000452f0:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro000452f0:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro
00045300:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria00045300:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria
00045310:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false00045310:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false
00045320:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat00045320:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat
00045330:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre00045330:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre
00045340:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati00045340:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati
 00045350:·6f6e·204f·5342·7569·6c64·2042·6c75·6570··on·OSBuild·Bluep
 00045360:·7269·6e74·2073·6e69·7070·6574·20e2·87b2··rint·snippet·...
 00045370:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
 00045380:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
 00045390:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
 000453a0:·2269·646d·3739·3931·223e·3c70·7265·3e3c··"idm7991"><pre><
 000453b0:·636f·6465·3e0a·5b5b·7061·636b·6167·6573··code>.[[packages
 000453c0:·5d5d·0a6e·616d·6520·3d20·2261·6964·6522··]].name·=·"aide"
 000453d0:·0a76·6572·7369·6f6e·203d·2022·2a22·0a3c··.version·=·"*".<
00045350:·6f6e·2073·6372·6970·7420·e287·b23c·2f61··on·script·...</a 
00045360:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class= 
00045370:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse· 
00045380:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id 
00045390:·6d37·3939·3122·3e3c·7461·626c·6520·636c··m7991"><table·cl 
000453a0:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table 
000453b0:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b 
000453c0:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co 
000453d0:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th 
000453e0:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th 
000453f0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t 
00045400:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup 
00045410:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo 
00045420:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr>< 
00045430:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th>< 
00045440:·7464·3e66·616c·7365·3c2f·7464·3e3c·2f74··td>false</td></t 
00045450:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate 
00045460:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab 
00045470:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta 
00045480:·626c·653e·3c70·7265·3e3c·636f·6465·3e0a··ble><pre><code>. 
00045490:·646e·6620·696e·7374·616c·6c20·6169·6465··dnf·install·aide 
000454a0:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></000453e0:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di
000454b0:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt000453f0:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn·
000454c0:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d00045400:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat
000454d0:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll00045410:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap
000454e0:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe00045420:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
000454f0:·743d·2223·6964·6d37·3939·3222·2074·6162··t="#idm7992"·tab00045430:·2223·6964·6d37·3939·3222·2074·6162·696e··"#idm7992"·tabin
00045500:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="00045440:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
00045510:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp00045450:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
00045520:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti00045460:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
00045530:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to00045470:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
00045540:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#00045480:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
00045550:·2122·3e52·656d·6564·6961·7469·6f6e·2041··!">Remediation·A00045490:·3e52·656d·6564·6961·7469·6f6e·2050·7570··>Remediation·Pup
00045560:·6e61·636f·6e64·6120·736e·6970·7065·7420··naconda·snippet·000454a0:·7065·7420·736e·6970·7065·7420·e287·b23c··pet·snippet·...<
00045570:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·000454b0:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas
00045580:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col000454c0:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps
00045590:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"· 
000455a0:·6964·3d22·6964·6d37·3939·3222·3e3c·7461··id="idm7992"><ta 
000455b0:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table 
000455c0:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t 
000455d0:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta 
000455e0:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed">< 
000455f0:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit 
00045600:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</ 
00045610:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
00045620:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th> 
00045630:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
00045640:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot: 
00045650:·3c2f·7468·3e3c·7464·3e66·616c·7365·3c2f··</th><td>false</ 
00045660:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
00045670:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t 
00045680:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t 
00045690:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre>< 
000456a0:·636f·6465·3e0a·7061·636b·6167·6520·2d2d··code>.package·-- 
000456b0:·6164·643d·6169·6465·0a3c·2f63·6f64·653e··add=aide.</code> 
000456c0:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c 
000456d0:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su 
000456e0:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg 
000456f0:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da000454d0:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="
 000454e0:·6964·6d37·3939·3222·3e3c·7461·626c·6520··idm7992"><table·
00045700:·7461·2d74·6172·6765·743d·2223·6964·6d37··ta-target="#idm7 
00045710:·3939·3322·2074·6162·696e·6465·783d·2230··993"·tabindex="0 
00045720:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"· 
00045730:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f 
00045740:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act 
00045750:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal" 
00045760:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed 
00045770:·6961·7469·6f6e·204f·5342·7569·6c64·2042··iation·OSBuild·B 
00045780:·6c75·6570·7269·6e74·2073·6e69·7070·6574··lueprint·snippet 
00045790:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div 
000457a0:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co 
000457b0:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse" 
000457c0:·2069·643d·2269·646d·3739·3933·223e·3c70···id="idm7993"><p 
000457d0:·7265·3e3c·636f·6465·3e0a·5b5b·7061·636b··re><code>.[[pack 
000457e0:·6167·6573·5d5d·0a6e·616d·6520·3d20·2261··ages]].name·=·"a 
000457f0:·6964·6522·0a76·6572·7369·6f6e·203d·2022··ide".version·=·" 
00045800:·2a22·0a3c·2f63·6f64·653e·3c2f·7072·653e··*".</code></pre> 
00045810:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class=" 
00045820:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success" 
00045830:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co 
00045840:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar 
00045850:·6765·743d·2223·6964·6d37·3939·3422·2074··get="#idm7994"·t 
00045860:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role 
00045870:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e 
00045880:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"· 
00045890:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate· 
000458a0:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href= 
000458b0:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation 
000458c0:·2073·6372·6970·7420·e287·b23c·2f61·3e3c···script·...</a>< 
000458d0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p 
000458e0:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co 
000458f0:·6c6c·6170·7365·2220·6964·3d22·6964·6d37··llapse"·id="idm7 
00045900:·3939·3422·3e3c·7461·626c·6520·636c·6173··994"><table·clas 
00045910:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s000454f0:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab
00045920:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor00045500:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table
00045930:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond00045510:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-
00045940:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C00045520:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><
00045950:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><00045530:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</
00045960:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>00045540:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
00045970:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti00045550:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr
00045980:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<00045560:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>
00045990:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th00045570:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
000459a0:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td00045580:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th
 00045590:·3e3c·7464·3e66·616c·7365·3c2f·7464·3e3c··><td>false</td><
 000455a0:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra
 000455b0:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en
000459b0:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr>000455c0:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></
000459c0:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy 
000459d0:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable 
000459e0:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl 
000459f0:·653e·3c70·7265·3e3c·636f·6465·3e0a·7061··e><pre><code>.pa000455d0:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code
Max diff block lines reached; 634364/661578 bytes (95.89%) of diff not shown.
84.3 KB
html2text {}
    
Offset 753, 52 lines modifiedOffset 753, 38 lines modified
753 ··-·PCI-DSSv4-11.5.2753 ··-·PCI-DSSv4-11.5.2
754 ··-·enable_strategy754 ··-·enable_strategy
755 ··-·low_complexity755 ··-·low_complexity
756 ··-·low_disruption756 ··-·low_disruption
757 ··-·medium_severity757 ··-·medium_severity
758 ··-·no_reboot_needed758 ··-·no_reboot_needed
759 ··-·package_aide_installed759 ··-·package_aide_installed
760 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
761 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
762 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
763 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
764 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
765 dnf·install·aide 
766 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
767 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
768 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
769 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
770 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
771 package·--add=aide 
772 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8760 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
773 [[packages]]761 [[packages]]
774 name·=·"aide"762 name·=·"aide"
775 version·=·"*"763 version·=·"*"
776 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
777 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
778 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
779 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
780 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
781 package·install·aide 
782 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8764 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
783 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low765 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
784 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low766 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
785 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false767 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
786 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable768 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
787 include·install_aide769 include·install_aide
  
788 class·install_aide·{770 class·install_aide·{
789 ··package·{·'aide':771 ··package·{·'aide':
790 ····ensure·=>·'installed',772 ····ensure·=>·'installed',
791 ··}773 ··}
792 }774 }
 775 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 776 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 777 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 778 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 779 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 780 package·install·aide
793 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8781 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
794 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low782 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
795 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low783 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
796 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false784 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
797 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable785 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
798 #·Remediation·is·applicable·only·in·certain·platforms786 #·Remediation·is·applicable·only·in·certain·platforms
799 if·rpm·--quiet·-q·kernel;·then787 if·rpm·--quiet·-q·kernel;·then
Offset 806, 14 lines modifiedOffset 792, 28 lines modified
806 if·!·rpm·-q·--quiet·"aide"·;·then792 if·!·rpm·-q·--quiet·"aide"·;·then
807 ····yum·install·-y·"aide"793 ····yum·install·-y·"aide"
808 fi794 fi
  
809 else795 else
810 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'796 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
811 fi797 fi
 798 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 799 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 800 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 801 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 802 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 803 package·--add=aide
 804 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 805 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 806 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 807 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 808 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 809 dnf·install·aide
812 Group  ·Federal·Information·Processing·Standard·(FIPS)·  Group·contains·1·rule810 Group  ·Federal·Information·Processing·Standard·(FIPS)·  Group·contains·1·rule
813 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·Federal·Information·Processing·Standard·(FIPS)·is·a·computer·security·standard·which·is·developed·by·the·U.S.·Government·and·industry·working·groups·to·validate·the·quality·of·cryptographic·modules.·The·FIPS·standard·provides·four·security·levels·to·ensure·adequate·coverage·of·different·industries,·implementation·of·cryptographic·modules,·and·organizational·sizes·and·requirements.811 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·Federal·Information·Processing·Standard·(FIPS)·is·a·computer·security·standard·which·is·developed·by·the·U.S.·Government·and·industry·working·groups·to·validate·the·quality·of·cryptographic·modules.·The·FIPS·standard·provides·four·security·levels·to·ensure·adequate·coverage·of·different·industries,·implementation·of·cryptographic·modules,·and·organizational·sizes·and·requirements.
  
814 FIPS·140-2·is·the·current·standard·for·validating·that·mechanisms·used·to·access·cryptographic·modules·utilize·authentication·that·meets·industry·and·government·requirements.·For·government·systems,·this·allows·Security·Levels·1,·2,·3,·or·4·for·use·on·Red·Hat·Enterprise·Linux·8.812 FIPS·140-2·is·the·current·standard·for·validating·that·mechanisms·used·to·access·cryptographic·modules·utilize·authentication·that·meets·industry·and·government·requirements.·For·government·systems,·this·allows·Security·Levels·1,·2,·3,·or·4·for·use·on·Red·Hat·Enterprise·Linux·8.
  
815 See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8c\x8c_\x8s\x8s_\x8r\x8r_\x8c\x8c_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8l\x8l_\x8i\x8i_\x8c\x8c_\x8a\x8a_\x8t\x8t_\x8i\x8i_\x8o\x8o_\x8n\x8n_\x8s\x8s_\x8/\x8/_\x8P\x8P_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x8h\x8h_\x8t\x8t_\x8m\x8m_\x8l\x8l·for·more·information.813 See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8c\x8c_\x8s\x8s_\x8r\x8r_\x8c\x8c_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8l\x8l_\x8i\x8i_\x8c\x8c_\x8a\x8a_\x8t\x8t_\x8i\x8i_\x8o\x8o_\x8n\x8n_\x8s\x8s_\x8/\x8/_\x8P\x8P_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x8h\x8h_\x8t\x8t_\x8m\x8m_\x8l\x8l·for·more·information.
816 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8de\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*814 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8de\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
Offset 1194, 52 lines modifiedOffset 1194, 38 lines modified
1194 ··-·PCI-DSSv4-2.2.61194 ··-·PCI-DSSv4-2.2.6
1195 ··-·enable_strategy1195 ··-·enable_strategy
1196 ··-·low_complexity1196 ··-·low_complexity
1197 ··-·low_disruption1197 ··-·low_disruption
1198 ··-·medium_severity1198 ··-·medium_severity
1199 ··-·no_reboot_needed1199 ··-·no_reboot_needed
1200 ··-·package_sudo_installed1200 ··-·package_sudo_installed
1201 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
1202 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
1203 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
1204 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
1205 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
1206 dnf·install·sudo 
1207 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
1208 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
1209 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
1210 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
1211 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
1212 package·--add=sudo 
1213 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81201 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
1214 [[packages]]1202 [[packages]]
1215 name·=·"sudo"1203 name·=·"sudo"
1216 version·=·"*"1204 version·=·"*"
1217 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
1218 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
1219 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
1220 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
1221 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
1222 package·install·sudo 
1223 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81205 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1224 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1206 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1225 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1207 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1226 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1208 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1227 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1209 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
Max diff block lines reached; 81243/86340 bytes (94.10%) of diff not shown.
1.65 MB
./usr/share/doc/ssg-nondebian/ssg-rhel8-guide-ospp.html
    
Offset 15333, 208 lines modifiedOffset 15333, 208 lines modified
0003be40:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target0003be40:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
0003be50:·3d22·2369·646d·3739·3931·2220·7461·6269··="#idm7991"·tabi0003be50:·3d22·2369·646d·3739·3931·2220·7461·6269··="#idm7991"·tabi
0003be60:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b0003be60:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
0003be70:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa0003be70:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
0003be80:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit0003be80:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
0003be90:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·0003be90:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
0003bea0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!0003bea0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
0003beb0:·223e·5265·6d65·6469·6174·696f·6e20·7363··">Remediation·sc0003beb0:·223e·5265·6d65·6469·6174·696f·6e20·4f53··">Remediation·OS
 0003bec0:·4275·696c·6420·426c·7565·7072·696e·7420··Build·Blueprint·
 0003bed0:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><
 0003bee0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
 0003bef0:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
 0003bf00:·6c6c·6170·7365·2220·6964·3d22·6964·6d37··llapse"·id="idm7
 0003bf10:·3939·3122·3e3c·7072·653e·3c63·6f64·653e··991"><pre><code>
 0003bf20:·0a5b·5b70·6163·6b61·6765·735d·5d0a·6e61··.[[packages]].na
 0003bf30:·6d65·203d·2022·6169·6465·220a·7665·7273··me·=·"aide".vers
 0003bf40:·696f·6e20·3d20·222a·220a·3c2f·636f·6465··ion·=·"*".</code
0003bec0:·7269·7074·20e2·87b2·3c2f·613e·3c62·723e··ript·...</a><br> 
0003bed0:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane 
0003bee0:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla 
0003bef0:·7073·6522·2069·643d·2269·646d·3739·3931··pse"·id="idm7991 
0003bf00:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class=" 
0003bf10:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri 
0003bf20:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border 
0003bf30:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens 
0003bf40:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp 
0003bf50:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td> 
0003bf60:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr 
0003bf70:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption: 
0003bf80:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td 
0003bf90:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re 
0003bfa0:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa 
0003bfb0:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr 
0003bfc0:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</ 
0003bfd0:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t 
0003bfe0:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table>< 
0003bff0:·7072·653e·3c63·6f64·653e·0a64·6e66·2069··pre><code>.dnf·i 
0003c000:·6e73·7461·6c6c·2061·6964·650a·3c2f·636f··nstall·aide.</co 
0003c010:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div><0003bf50:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a·
0003c020:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn0003bf60:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s
0003c030:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t0003bf70:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog
0003c040:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse"0003bf80:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d
0003c050:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i0003bf90:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
0003c060:·646d·3739·3932·2220·7461·6269·6e64·6578··dm7992"·tabindex0003bfa0:·3739·3932·2220·7461·6269·6e64·6578·3d22··7992"·tabindex="
0003c070:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto0003bfb0:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
0003c080:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded0003bfc0:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
0003c090:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="0003bfd0:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
0003c0a0:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve0003bfe0:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
0003c0b0:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re0003bff0:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
0003c0c0:·6d65·6469·6174·696f·6e20·416e·6163·6f6e··mediation·Anacon0003c000:·6469·6174·696f·6e20·5075·7070·6574·2073··diation·Puppet·s
0003c0d0:·6461·2073·6e69·7070·6574·20e2·87b2·3c2f··da·snippet·...</0003c010:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b
0003c0e0:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class0003c020:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
0003c0f0:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse0003c030:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
0003c100:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i0003c040:·6c61·7073·6522·2069·643d·2269·646d·3739··lapse"·id="idm79
0003c110:·646d·3739·3932·223e·3c74·6162·6c65·2063··dm7992"><table·c0003c050:·3932·223e·3c74·6162·6c65·2063·6c61·7373··92"><table·class
0003c120:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl0003c060:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st
0003c130:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-0003c070:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord
0003c140:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c0003c080:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde
0003c150:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t0003c090:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co
0003c160:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t0003c0a0:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t
0003c170:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></0003c0b0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
0003c180:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru0003c0c0:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio
 0003c0d0:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</
 0003c0e0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 0003c0f0:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td>
 0003c100:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr><
 0003c110:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:
 0003c120:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<
 0003c130:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table
 0003c140:·3e3c·7072·653e·3c63·6f64·653e·696e·636c··><pre><code>incl
 0003c150:·7564·6520·696e·7374·616c·6c5f·6169·6465··ude·install_aide
 0003c160:·0a0a·636c·6173·7320·696e·7374·616c·6c5f··..class·install_
 0003c170:·6169·6465·207b·0a20·2070·6163·6b61·6765··aide·{.··package
 0003c180:·207b·2027·6169·6465·273a·0a20·2020·2065···{·'aide':.····e
 0003c190:·6e73·7572·6520·3d26·6774·3b20·2769·6e73··nsure·=&gt;·'ins
 0003c1a0:·7461·6c6c·6564·272c·0a20·207d·0a7d·0a3c··talled',.··}.}.<
 0003c1b0:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di
 0003c1c0:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn·
 0003c1d0:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat
 0003c1e0:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap
 0003c1f0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
 0003c200:·2223·6964·6d37·3939·3322·2074·6162·696e··"#idm7993"·tabin
 0003c210:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
 0003c220:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
 0003c230:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
 0003c240:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
 0003c250:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
 0003c260:·3e52·656d·6564·6961·7469·6f6e·2073·6372··>Remediation·scr
 0003c270:·6970·7420·e287·b23c·2f61·3e3c·6272·3e3c··ipt·...</a><br><
 0003c280:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
 0003c290:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap
 0003c2a0:·7365·2220·6964·3d22·6964·6d37·3939·3322··se"·id="idm7993"
 0003c2b0:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t
 0003c2c0:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip
 0003c2d0:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere
 0003c2e0:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense
 0003c2f0:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl
0003c190:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l0003c300:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l
0003c1a0:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>0003c310:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
0003c1b0:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th> 
0003c1c0:·3c74·643e·6661·6c73·653c·2f74·643e·3c2f··<td>false</td></0003c320:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:<
 0003c330:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
0003c1d0:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat0003c340:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb
0003c1e0:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena0003c350:·6f6f·743a·3c2f·7468·3e3c·7464·3e66·616c··oot:</th><td>fal
0003c1f0:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t 
0003c200:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code> 
0003c210:·0a70·6163·6b61·6765·202d·2d61·6464·3d61··.package·--add=a 
0003c220:·6964·650a·3c2f·636f·6465·3e3c·2f70·7265··ide.</code></pre 
0003c230:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class= 
0003c240:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success 
0003c250:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c 
0003c260:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta 
0003c270:·7267·6574·3d22·2369·646d·3739·3933·2220··rget="#idm7993"· 
0003c280:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol 
0003c290:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria- 
0003c2a0:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false" 
0003c2b0:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate 
0003c2c0:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href 
0003c2d0:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio 
0003c2e0:·6e20·4f53·4275·696c·6420·426c·7565·7072··n·OSBuild·Bluepr 
0003c2f0:·696e·7420·736e·6970·7065·7420·e287·b23c··int·snippet·...<0003c360:·7365·3c2f·7464·3e3c·2f74·723e·3c74·723e··se</td></tr><tr>
 0003c370:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t
 0003c380:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td
 0003c390:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p
 0003c3a0:·7265·3e3c·636f·6465·3e0a·7061·636b·6167··re><code>.packag
 0003c3b0:·6520·696e·7374·616c·6c20·6169·6465·0a3c··e·install·aide.<
 0003c3c0:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di
Max diff block lines reached; 1526472/1553824 bytes (98.24%) of diff not shown.
169 KB
html2text {}
    
Offset 154, 52 lines modifiedOffset 154, 38 lines modified
154 ··-·PCI-DSSv4-11.5.2154 ··-·PCI-DSSv4-11.5.2
155 ··-·enable_strategy155 ··-·enable_strategy
156 ··-·low_complexity156 ··-·low_complexity
157 ··-·low_disruption157 ··-·low_disruption
158 ··-·medium_severity158 ··-·medium_severity
159 ··-·no_reboot_needed159 ··-·no_reboot_needed
160 ··-·package_aide_installed160 ··-·package_aide_installed
161 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
162 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
163 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
164 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
165 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
166 dnf·install·aide 
167 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
168 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
169 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
170 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
171 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
172 package·--add=aide 
173 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8161 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
174 [[packages]]162 [[packages]]
175 name·=·"aide"163 name·=·"aide"
176 version·=·"*"164 version·=·"*"
177 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
178 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
179 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
180 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
181 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
182 package·install·aide 
183 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8165 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
184 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low166 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
185 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low167 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
186 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false168 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
187 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable169 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
188 include·install_aide170 include·install_aide
  
189 class·install_aide·{171 class·install_aide·{
190 ··package·{·'aide':172 ··package·{·'aide':
191 ····ensure·=>·'installed',173 ····ensure·=>·'installed',
192 ··}174 ··}
193 }175 }
 176 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 177 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 178 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 179 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 180 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 181 package·install·aide
194 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8182 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
195 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low183 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
196 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low184 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
197 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false185 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
198 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable186 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
199 #·Remediation·is·applicable·only·in·certain·platforms187 #·Remediation·is·applicable·only·in·certain·platforms
200 if·rpm·--quiet·-q·kernel;·then188 if·rpm·--quiet·-q·kernel;·then
Offset 207, 14 lines modifiedOffset 193, 28 lines modified
207 if·!·rpm·-q·--quiet·"aide"·;·then193 if·!·rpm·-q·--quiet·"aide"·;·then
208 ····yum·install·-y·"aide"194 ····yum·install·-y·"aide"
209 fi195 fi
  
210 else196 else
211 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'197 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
212 fi198 fi
 199 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 200 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 201 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 202 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 203 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 204 package·--add=aide
 205 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 206 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 207 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 208 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 209 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 210 dnf·install·aide
213 Group  ·Federal·Information·Processing·Standard·(FIPS)·  Group·contains·2·rules211 Group  ·Federal·Information·Processing·Standard·(FIPS)·  Group·contains·2·rules
214 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·Federal·Information·Processing·Standard·(FIPS)·is·a·computer·security·standard·which·is·developed·by·the·U.S.·Government·and·industry·working·groups·to·validate·the·quality·of·cryptographic·modules.·The·FIPS·standard·provides·four·security·levels·to·ensure·adequate·coverage·of·different·industries,·implementation·of·cryptographic·modules,·and·organizational·sizes·and·requirements.212 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·Federal·Information·Processing·Standard·(FIPS)·is·a·computer·security·standard·which·is·developed·by·the·U.S.·Government·and·industry·working·groups·to·validate·the·quality·of·cryptographic·modules.·The·FIPS·standard·provides·four·security·levels·to·ensure·adequate·coverage·of·different·industries,·implementation·of·cryptographic·modules,·and·organizational·sizes·and·requirements.
  
215 FIPS·140-2·is·the·current·standard·for·validating·that·mechanisms·used·to·access·cryptographic·modules·utilize·authentication·that·meets·industry·and·government·requirements.·For·government·systems,·this·allows·Security·Levels·1,·2,·3,·or·4·for·use·on·Red·Hat·Enterprise·Linux·8.213 FIPS·140-2·is·the·current·standard·for·validating·that·mechanisms·used·to·access·cryptographic·modules·utilize·authentication·that·meets·industry·and·government·requirements.·For·government·systems,·this·allows·Security·Levels·1,·2,·3,·or·4·for·use·on·Red·Hat·Enterprise·Linux·8.
  
216 See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8c\x8c_\x8s\x8s_\x8r\x8r_\x8c\x8c_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8l\x8l_\x8i\x8i_\x8c\x8c_\x8a\x8a_\x8t\x8t_\x8i\x8i_\x8o\x8o_\x8n\x8n_\x8s\x8s_\x8/\x8/_\x8P\x8P_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x8h\x8h_\x8t\x8t_\x8m\x8m_\x8l\x8l·for·more·information.214 See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8c\x8c_\x8s\x8s_\x8r\x8r_\x8c\x8c_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8l\x8l_\x8i\x8i_\x8c\x8c_\x8a\x8a_\x8t\x8t_\x8i\x8i_\x8o\x8o_\x8n\x8n_\x8s\x8s_\x8/\x8/_\x8P\x8P_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x8h\x8h_\x8t\x8t_\x8m\x8m_\x8l\x8l·for·more·information.
217 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·D\x8Dr\x8ra\x8ac\x8cu\x8ut\x8t·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8du\x8ul\x8le\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*215 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·D\x8Dr\x8ra\x8ac\x8cu\x8ut\x8t·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8du\x8ul\x8le\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
Offset 299, 61 lines modifiedOffset 299, 61 lines modified
299 ··-·CCE-82723-8299 ··-·CCE-82723-8
300 ··-·enable_strategy300 ··-·enable_strategy
301 ··-·low_complexity301 ··-·low_complexity
302 ··-·low_disruption302 ··-·low_disruption
303 ··-·medium_severity303 ··-·medium_severity
304 ··-·no_reboot_needed304 ··-·no_reboot_needed
305 ··-·package_crypto-policies_installed305 ··-·package_crypto-policies_installed
306 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
307 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
308 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
309 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
310 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
311 dnf·install·crypto-policies 
312 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
313 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
314 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
315 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
316 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
317 package·--add=crypto-policies 
318 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8306 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
319 [[packages]]307 [[packages]]
320 name·=·"crypto-policies"308 name·=·"crypto-policies"
321 version·=·"*"309 version·=·"*"
322 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
323 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
324 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
325 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
326 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
327 package·install·crypto-policies 
328 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8310 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
329 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low311 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
330 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low312 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
331 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false313 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
332 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable314 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
Max diff block lines reached; 168074/173257 bytes (97.01%) of diff not shown.
694 KB
./usr/share/doc/ssg-nondebian/ssg-rhel8-guide-pci-dss.html
    
Offset 16929, 208 lines modifiedOffset 16929, 208 lines modified
00042200:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target00042200:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
00042210:·3d22·2369·646d·3739·3931·2220·7461·6269··="#idm7991"·tabi00042210:·3d22·2369·646d·3739·3931·2220·7461·6269··="#idm7991"·tabi
00042220:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b00042220:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
00042230:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa00042230:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
00042240:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit00042240:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
00042250:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·00042250:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
00042260:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!00042260:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
00042270:·223e·5265·6d65·6469·6174·696f·6e20·7363··">Remediation·sc00042270:·223e·5265·6d65·6469·6174·696f·6e20·4f53··">Remediation·OS
 00042280:·4275·696c·6420·426c·7565·7072·696e·7420··Build·Blueprint·
 00042290:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><
 000422a0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
 000422b0:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
 000422c0:·6c6c·6170·7365·2220·6964·3d22·6964·6d37··llapse"·id="idm7
 000422d0:·3939·3122·3e3c·7072·653e·3c63·6f64·653e··991"><pre><code>
 000422e0:·0a5b·5b70·6163·6b61·6765·735d·5d0a·6e61··.[[packages]].na
 000422f0:·6d65·203d·2022·6169·6465·220a·7665·7273··me·=·"aide".vers
 00042300:·696f·6e20·3d20·222a·220a·3c2f·636f·6465··ion·=·"*".</code
00042280:·7269·7074·20e2·87b2·3c2f·613e·3c62·723e··ript·...</a><br> 
00042290:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane 
000422a0:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla 
000422b0:·7073·6522·2069·643d·2269·646d·3739·3931··pse"·id="idm7991 
000422c0:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class=" 
000422d0:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri 
000422e0:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border 
000422f0:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens 
00042300:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp 
00042310:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td> 
00042320:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr 
00042330:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption: 
00042340:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td 
00042350:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re 
00042360:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa 
00042370:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr 
00042380:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</ 
00042390:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t 
000423a0:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table>< 
000423b0:·7072·653e·3c63·6f64·653e·0a64·6e66·2069··pre><code>.dnf·i 
000423c0:·6e73·7461·6c6c·2061·6964·650a·3c2f·636f··nstall·aide.</co 
000423d0:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div><00042310:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a·
000423e0:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn00042320:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s
000423f0:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t00042330:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog
00042400:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse"00042340:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d
00042410:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i00042350:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
00042420:·646d·3739·3932·2220·7461·6269·6e64·6578··dm7992"·tabindex00042360:·3739·3932·2220·7461·6269·6e64·6578·3d22··7992"·tabindex="
00042430:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto00042370:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
00042440:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded00042380:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
00042450:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="00042390:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
00042460:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve000423a0:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
00042470:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re000423b0:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
00042480:·6d65·6469·6174·696f·6e20·416e·6163·6f6e··mediation·Anacon000423c0:·6469·6174·696f·6e20·5075·7070·6574·2073··diation·Puppet·s
00042490:·6461·2073·6e69·7070·6574·20e2·87b2·3c2f··da·snippet·...</000423d0:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b
000424a0:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class000423e0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
000424b0:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse000423f0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
000424c0:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i00042400:·6c61·7073·6522·2069·643d·2269·646d·3739··lapse"·id="idm79
000424d0:·646d·3739·3932·223e·3c74·6162·6c65·2063··dm7992"><table·c00042410:·3932·223e·3c74·6162·6c65·2063·6c61·7373··92"><table·class
000424e0:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl00042420:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st
000424f0:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-00042430:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord
00042500:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c00042440:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde
00042510:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t00042450:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co
00042520:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t00042460:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t
00042530:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></00042470:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
00042540:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru00042480:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio
 00042490:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</
 000424a0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 000424b0:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td>
 000424c0:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr><
 000424d0:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:
 000424e0:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<
 000424f0:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table
 00042500:·3e3c·7072·653e·3c63·6f64·653e·696e·636c··><pre><code>incl
 00042510:·7564·6520·696e·7374·616c·6c5f·6169·6465··ude·install_aide
 00042520:·0a0a·636c·6173·7320·696e·7374·616c·6c5f··..class·install_
 00042530:·6169·6465·207b·0a20·2070·6163·6b61·6765··aide·{.··package
 00042540:·207b·2027·6169·6465·273a·0a20·2020·2065···{·'aide':.····e
 00042550:·6e73·7572·6520·3d26·6774·3b20·2769·6e73··nsure·=&gt;·'ins
 00042560:·7461·6c6c·6564·272c·0a20·207d·0a7d·0a3c··talled',.··}.}.<
 00042570:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di
 00042580:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn·
 00042590:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat
 000425a0:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap
 000425b0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
 000425c0:·2223·6964·6d37·3939·3322·2074·6162·696e··"#idm7993"·tabin
 000425d0:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
 000425e0:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
 000425f0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
 00042600:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
 00042610:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
 00042620:·3e52·656d·6564·6961·7469·6f6e·2073·6372··>Remediation·scr
 00042630:·6970·7420·e287·b23c·2f61·3e3c·6272·3e3c··ipt·...</a><br><
 00042640:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
 00042650:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap
 00042660:·7365·2220·6964·3d22·6964·6d37·3939·3322··se"·id="idm7993"
 00042670:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t
 00042680:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip
 00042690:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere
 000426a0:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense
 000426b0:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl
00042550:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l000426c0:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l
00042560:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>000426d0:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
00042570:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th> 
00042580:·3c74·643e·6661·6c73·653c·2f74·643e·3c2f··<td>false</td></000426e0:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:<
 000426f0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
00042590:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat00042700:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb
000425a0:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena00042710:·6f6f·743a·3c2f·7468·3e3c·7464·3e66·616c··oot:</th><td>fal
000425b0:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t 
000425c0:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code> 
000425d0:·0a70·6163·6b61·6765·202d·2d61·6464·3d61··.package·--add=a 
000425e0:·6964·650a·3c2f·636f·6465·3e3c·2f70·7265··ide.</code></pre 
000425f0:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class= 
00042600:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success 
00042610:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c 
00042620:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta 
00042630:·7267·6574·3d22·2369·646d·3739·3933·2220··rget="#idm7993"· 
00042640:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol 
00042650:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria- 
00042660:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false" 
00042670:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate 
00042680:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href 
00042690:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio 
000426a0:·6e20·4f53·4275·696c·6420·426c·7565·7072··n·OSBuild·Bluepr 
000426b0:·696e·7420·736e·6970·7065·7420·e287·b23c··int·snippet·...<00042720:·7365·3c2f·7464·3e3c·2f74·723e·3c74·723e··se</td></tr><tr>
 00042730:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t
 00042740:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td
 00042750:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p
 00042760:·7265·3e3c·636f·6465·3e0a·7061·636b·6167··re><code>.packag
 00042770:·6520·696e·7374·616c·6c20·6169·6465·0a3c··e·install·aide.<
 00042780:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di
Max diff block lines reached; 600208/627560 bytes (95.64%) of diff not shown.
81.0 KB
html2text {}
    
Offset 564, 52 lines modifiedOffset 564, 38 lines modified
564 ··-·PCI-DSSv4-11.5.2564 ··-·PCI-DSSv4-11.5.2
565 ··-·enable_strategy565 ··-·enable_strategy
566 ··-·low_complexity566 ··-·low_complexity
567 ··-·low_disruption567 ··-·low_disruption
568 ··-·medium_severity568 ··-·medium_severity
569 ··-·no_reboot_needed569 ··-·no_reboot_needed
570 ··-·package_aide_installed570 ··-·package_aide_installed
571 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
572 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
573 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
574 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
575 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
576 dnf·install·aide 
577 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
578 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
579 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
580 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
581 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
582 package·--add=aide 
583 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8571 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
584 [[packages]]572 [[packages]]
585 name·=·"aide"573 name·=·"aide"
586 version·=·"*"574 version·=·"*"
587 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
588 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
589 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
590 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
591 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
592 package·install·aide 
593 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8575 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
594 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low576 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
595 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low577 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
596 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false578 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
597 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable579 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
598 include·install_aide580 include·install_aide
  
599 class·install_aide·{581 class·install_aide·{
600 ··package·{·'aide':582 ··package·{·'aide':
601 ····ensure·=>·'installed',583 ····ensure·=>·'installed',
602 ··}584 ··}
603 }585 }
 586 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 587 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 588 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 589 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 590 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 591 package·install·aide
604 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8592 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
605 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low593 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
606 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low594 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
607 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false595 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
608 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable596 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
609 #·Remediation·is·applicable·only·in·certain·platforms597 #·Remediation·is·applicable·only·in·certain·platforms
610 if·rpm·--quiet·-q·kernel;·then598 if·rpm·--quiet·-q·kernel;·then
Offset 617, 14 lines modifiedOffset 603, 28 lines modified
617 if·!·rpm·-q·--quiet·"aide"·;·then603 if·!·rpm·-q·--quiet·"aide"·;·then
618 ····yum·install·-y·"aide"604 ····yum·install·-y·"aide"
619 fi605 fi
  
620 else606 else
621 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'607 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
622 fi608 fi
 609 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 610 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 611 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 612 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 613 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 614 package·--add=aide
 615 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 616 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 617 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 618 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 619 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 620 dnf·install·aide
623 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*621 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
624 Run·the·following·command·to·generate·a·new·database:622 Run·the·following·command·to·generate·a·new·database:
625 $·sudo·/usr/sbin/aide·--init623 $·sudo·/usr/sbin/aide·--init
626 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:624 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
627 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz625 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
628 To·initiate·a·manual·check,·run·the·following·command:626 To·initiate·a·manual·check,·run·the·following·command:
629 $·sudo·/usr/sbin/aide·--check627 $·sudo·/usr/sbin/aide·--check
Offset 2863, 52 lines modifiedOffset 2863, 38 lines modified
2863 ··-·PCI-DSSv4-2.2.62863 ··-·PCI-DSSv4-2.2.6
2864 ··-·enable_strategy2864 ··-·enable_strategy
2865 ··-·low_complexity2865 ··-·low_complexity
2866 ··-·low_disruption2866 ··-·low_disruption
2867 ··-·medium_severity2867 ··-·medium_severity
2868 ··-·no_reboot_needed2868 ··-·no_reboot_needed
2869 ··-·package_sudo_installed2869 ··-·package_sudo_installed
2870 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
2871 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
2872 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
2873 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
2874 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
2875 dnf·install·sudo 
2876 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
2877 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
2878 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
2879 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
2880 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
2881 package·--add=sudo 
2882 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x82870 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
2883 [[packages]]2871 [[packages]]
2884 name·=·"sudo"2872 name·=·"sudo"
2885 version·=·"*"2873 version·=·"*"
2886 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
2887 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
2888 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
2889 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
2890 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
2891 package·install·sudo 
2892 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x82874 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
2893 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low2875 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
2894 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low2876 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
2895 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false2877 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
2896 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable2878 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
Max diff block lines reached; 78255/82950 bytes (94.34%) of diff not shown.
1.62 MB
./usr/share/doc/ssg-nondebian/ssg-rhel8-guide-stig.html
    
Offset 15366, 207 lines modifiedOffset 15366, 207 lines modified
0003c050:·612d·7461·7267·6574·3d22·2369·646d·3739··a-target="#idm790003c050:·612d·7461·7267·6574·3d22·2369·646d·3739··a-target="#idm79
0003c060:·3931·2220·7461·6269·6e64·6578·3d22·3022··91"·tabindex="0"0003c060:·3931·2220·7461·6269·6e64·6578·3d22·3022··91"·tabindex="0"
0003c070:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a0003c070:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
0003c080:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa0003c080:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
0003c090:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti0003c090:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
0003c0a0:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·0003c0a0:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
0003c0b0:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi0003c0b0:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
 0003c0c0:·6174·696f·6e20·4f53·4275·696c·6420·426c··ation·OSBuild·Bl
 0003c0d0:·7565·7072·696e·7420·736e·6970·7065·7420··ueprint·snippet·
 0003c0e0:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·
 0003c0f0:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col
 0003c100:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·
 0003c110:·6964·3d22·6964·6d37·3939·3122·3e3c·7072··id="idm7991"><pr
0003c0c0:·6174·696f·6e20·7363·7269·7074·20e2·87b2··ation·script·... 
0003c0d0:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla 
0003c0e0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap 
0003c0f0:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id= 
0003c100:·2269·646d·3739·3931·223e·3c74·6162·6c65··"idm7991"><table 
0003c110:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta 
0003c120:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl 
0003c130:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table 
0003c140:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr> 
0003c150:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:< 
0003c160:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td> 
0003c170:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis 
0003c180:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td 
0003c190:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t 
0003c1a0:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t 
0003c1b0:·683e·3c74·643e·6661·6c73·653c·2f74·643e··h><td>false</td> 
0003c1c0:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str 
0003c1d0:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e 
0003c1e0:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr>< 
0003c1f0:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod 
0003c200:·653e·0a64·6e66·2069·6e73·7461·6c6c·2061··e>.dnf·install·a 
0003c210:·6964·650a·3c2f·636f·6465·3e3c·2f70·7265··ide.</code></pre 
0003c220:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class= 
0003c230:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success 
0003c240:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c 
0003c250:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta 
0003c260:·7267·6574·3d22·2369·646d·3739·3932·2220··rget="#idm7992"· 
0003c270:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol 
0003c280:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria- 
0003c290:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false" 
0003c2a0:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate 
0003c2b0:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href 
0003c2c0:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio 
0003c2d0:·6e20·416e·6163·6f6e·6461·2073·6e69·7070··n·Anaconda·snipp 
0003c2e0:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d 
0003c2f0:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel- 
0003c300:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps 
0003c310:·6522·2069·643d·2269·646d·3739·3932·223e··e"·id="idm7992"> 
0003c320:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta 
0003c330:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe 
0003c340:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered 
0003c350:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed 
0003c360:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple 
0003c370:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo 
0003c380:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr>< 
0003c390:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</ 
0003c3a0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td>< 
0003c3b0:·2f74·723e·3c74·723e·3c74·683e·5265·626f··/tr><tr><th>Rebo 
0003c3c0:·6f74·3a3c·2f74·683e·3c74·643e·6661·6c73··ot:</th><td>fals 
0003c3d0:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr>< 
0003c3e0:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th 
0003c3f0:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td> 
0003c400:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr 
0003c410:·653e·3c63·6f64·653e·0a70·6163·6b61·6765··e><code>.package0003c120:·653e·3c63·6f64·653e·0a5b·5b70·6163·6b61··e><code>.[[packa
0003c420:·202d·2d61·6464·3d61·6964·650a·3c2f·636f···--add=aide.</co 
0003c430:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div>< 
0003c440:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn 
0003c450:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t 
0003c460:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse" 
0003c470:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i 
0003c480:·646d·3739·3933·2220·7461·6269·6e64·6578··dm7993"·tabindex 
0003c490:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto 
0003c4a0:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded 
0003c4b0:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title=" 
0003c4c0:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve 
0003c4d0:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re 
0003c4e0:·6d65·6469·6174·696f·6e20·4f53·4275·696c··mediation·OSBuil 
0003c4f0:·6420·426c·7565·7072·696e·7420·736e·6970··d·Blueprint·snip 
0003c500:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br>< 
0003c510:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel 
0003c520:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap 
0003c530:·7365·2220·6964·3d22·6964·6d37·3939·3322··se"·id="idm7993" 
0003c540:·3e3c·7072·653e·3c63·6f64·653e·0a5b·5b70··><pre><code>.[[p 
0003c550:·6163·6b61·6765·735d·5d0a·6e61·6d65·203d··ackages]].name·=0003c130:·6765·735d·5d0a·6e61·6d65·203d·2022·6169··ges]].name·=·"ai
0003c560:·2022·6169·6465·220a·7665·7273·696f·6e20···"aide".version·0003c140:·6465·220a·7665·7273·696f·6e20·3d20·222a··de".version·=·"*
0003c570:·3d20·222a·220a·3c2f·636f·6465·3e3c·2f70··=·"*".</code></p0003c150:·220a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··".</code></pre><
0003c580:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas0003c160:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b
0003c590:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe 
0003c5a0:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle= 
0003c5b0:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data- 
0003c5c0:·7461·7267·6574·3d22·2369·646d·3739·3934··target="#idm7994 
0003c5d0:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r 
0003c5e0:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari 
0003c5f0:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals 
0003c600:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa 
0003c610:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr 
0003c620:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat 
0003c630:·696f·6e20·7363·7269·7074·20e2·87b2·3c2f··ion·script·...</ 
0003c640:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class 
0003c650:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse 
0003c660:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i 
0003c670:·646d·3739·3934·223e·3c74·6162·6c65·2063··dm7994"><table·c 
0003c680:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl 
0003c690:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table- 
0003c6a0:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c 
0003c6b0:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t 
0003c6c0:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t 
0003c6d0:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></ 
0003c6e0:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru 
0003c6f0:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l 
0003c700:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr> 
0003c710:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th> 
0003c720:·3c74·643e·6661·6c73·653c·2f74·643e·3c2f··<td>false</td></ 
0003c730:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat 
0003c740:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena 
0003c750:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t 
0003c760:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code> 
0003c770:·0a70·6163·6b61·6765·2069·6e73·7461·6c6c··.package·install 
0003c780:·2061·6964·650a·3c2f·636f·6465·3e3c·2f70···aide.</code></p 
0003c790:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas 
0003c7a0:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe0003c170:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"·
0003c7b0:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle=0003c180:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col
0003c7c0:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data-0003c190:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ
0003c7d0:·7461·7267·6574·3d22·2369·646d·3739·3935··target="#idm79950003c1a0:·6574·3d22·2369·646d·3739·3932·2220·7461··et="#idm7992"·ta
Max diff block lines reached; 1499398/1526612 bytes (98.22%) of diff not shown.
169 KB
html2text {}
    
Offset 160, 52 lines modifiedOffset 160, 38 lines modified
160 ··-·PCI-DSSv4-11.5.2160 ··-·PCI-DSSv4-11.5.2
161 ··-·enable_strategy161 ··-·enable_strategy
162 ··-·low_complexity162 ··-·low_complexity
163 ··-·low_disruption163 ··-·low_disruption
164 ··-·medium_severity164 ··-·medium_severity
165 ··-·no_reboot_needed165 ··-·no_reboot_needed
166 ··-·package_aide_installed166 ··-·package_aide_installed
167 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
168 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
169 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
170 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
171 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
172 dnf·install·aide 
173 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
174 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
175 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
176 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
177 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
178 package·--add=aide 
179 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8167 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
180 [[packages]]168 [[packages]]
181 name·=·"aide"169 name·=·"aide"
182 version·=·"*"170 version·=·"*"
183 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
184 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
185 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
186 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
187 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
188 package·install·aide 
189 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8171 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
190 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low172 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
191 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low173 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
192 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false174 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
193 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable175 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
194 include·install_aide176 include·install_aide
  
195 class·install_aide·{177 class·install_aide·{
196 ··package·{·'aide':178 ··package·{·'aide':
197 ····ensure·=>·'installed',179 ····ensure·=>·'installed',
198 ··}180 ··}
199 }181 }
 182 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 183 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 184 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 185 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 186 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 187 package·install·aide
200 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8188 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
201 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low189 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
202 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low190 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
203 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false191 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
204 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable192 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
205 #·Remediation·is·applicable·only·in·certain·platforms193 #·Remediation·is·applicable·only·in·certain·platforms
206 if·rpm·--quiet·-q·kernel;·then194 if·rpm·--quiet·-q·kernel;·then
Offset 213, 14 lines modifiedOffset 199, 28 lines modified
213 if·!·rpm·-q·--quiet·"aide"·;·then199 if·!·rpm·-q·--quiet·"aide"·;·then
214 ····yum·install·-y·"aide"200 ····yum·install·-y·"aide"
215 fi201 fi
  
216 else202 else
217 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'203 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
218 fi204 fi
 205 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 206 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 207 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 208 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 209 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 210 package·--add=aide
 211 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 212 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 213 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 214 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 215 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 216 dnf·install·aide
219 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*217 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
220 Run·the·following·command·to·generate·a·new·database:218 Run·the·following·command·to·generate·a·new·database:
221 $·sudo·/usr/sbin/aide·--init219 $·sudo·/usr/sbin/aide·--init
222 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:220 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
223 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz221 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
224 To·initiate·a·manual·check,·run·the·following·command:222 To·initiate·a·manual·check,·run·the·following·command:
225 $·sudo·/usr/sbin/aide·--check223 $·sudo·/usr/sbin/aide·--check
Offset 2862, 29 lines modifiedOffset 2862, 29 lines modified
2862 References:··_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)2862 References:··_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)
2863 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-42863 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4
2864 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-002272864 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
2865 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-08-0108002865 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-08-010800
2866 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R282866 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R28
2867 ·············_\x8c_\x8i_\x8s············1.1.2.3.12867 ·············_\x8c_\x8i_\x8s············1.1.2.3.1
2868 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-230328r1017139_rule2868 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-230328r1017139_rule
2869 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
2870 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
2871 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high 
2872 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
2873 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
2874 part·/home 
2875 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x82869 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
2876 [[customizations.filesystem]]2870 [[customizations.filesystem]]
2877 mountpoint·=·"/home"2871 mountpoint·=·"/home"
2878 size·=·10737418242872 size·=·1073741824
2879 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x82873 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
2880 logvol·/home·10242874 logvol·/home·1024
 2875 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 2876 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 2877 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high
 2878 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 2879 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 2880 part·/home
2881 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/t\x8tm\x8mp\x8p·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*2881 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/t\x8tm\x8mp\x8p·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
2882 The·/tmp·directory·is·a·world-writable·directory·used·for·temporary·file·storage.·Ensure·it·has·its·own·partition·or·logical·volume·at·installation·time,·or·migrate·it·using·LVM.2882 The·/tmp·directory·is·a·world-writable·directory·used·for·temporary·file·storage.·Ensure·it·has·its·own·partition·or·logical·volume·at·installation·time,·or·migrate·it·using·LVM.
2883 Rationale:···The·/tmp·partition·is·used·as·temporary·storage·by·many·programs.·Placing·/tmp·in·its·own·partition·enables·the·setting·of·more·restrictive·mount·options,·which·can·help·protect·programs·which·use·it.2883 Rationale:···The·/tmp·partition·is·used·as·temporary·storage·by·many·programs.·Placing·/tmp·in·its·own·partition·enables·the·setting·of·more·restrictive·mount·options,·which·can·help·protect·programs·which·use·it.
2884 Severity: ···low2884 Severity: ···low
2885 Rule·ID:·····xccdf_org.ssgproject.content_rule_partition_for_tmp2885 Rule·ID:·····xccdf_org.ssgproject.content_rule_partition_for_tmp
2886 Identifiers:·CCE-80851-92886 Identifiers:·CCE-80851-9
2887 ·············_\x8c_\x8i_\x8s_\x8-_\x8c_\x8s_\x8c········12,·15,·82887 ·············_\x8c_\x8i_\x8s_\x8-_\x8c_\x8s_\x8c········12,·15,·8
Offset 2894, 29 lines modifiedOffset 2894, 29 lines modified
2894 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.32894 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.3
Max diff block lines reached; 167748/173216 bytes (96.84%) of diff not shown.
1.58 MB
./usr/share/doc/ssg-nondebian/ssg-rhel8-guide-stig_gui.html
    
Offset 15385, 207 lines modifiedOffset 15385, 207 lines modified
0003c180:·7461·2d74·6172·6765·743d·2223·6964·6d37··ta-target="#idm70003c180:·7461·2d74·6172·6765·743d·2223·6964·6d37··ta-target="#idm7
0003c190:·3939·3122·2074·6162·696e·6465·783d·2230··991"·tabindex="00003c190:·3939·3122·2074·6162·696e·6465·783d·2230··991"·tabindex="0
0003c1a0:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·0003c1a0:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
0003c1b0:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f0003c1b0:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
0003c1c0:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act0003c1c0:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
0003c1d0:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"0003c1d0:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
0003c1e0:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed0003c1e0:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
 0003c1f0:·6961·7469·6f6e·204f·5342·7569·6c64·2042··iation·OSBuild·B
 0003c200:·6c75·6570·7269·6e74·2073·6e69·7070·6574··lueprint·snippet
 0003c210:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
 0003c220:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
 0003c230:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
 0003c240:·2069·643d·2269·646d·3739·3931·223e·3c70···id="idm7991"><p
 0003c250:·7265·3e3c·636f·6465·3e0a·5b5b·7061·636b··re><code>.[[pack
 0003c260:·6167·6573·5d5d·0a6e·616d·6520·3d20·2261··ages]].name·=·"a
 0003c270:·6964·6522·0a76·6572·7369·6f6e·203d·2022··ide".version·=·"
0003c1f0:·6961·7469·6f6e·2073·6372·6970·7420·e287··iation·script·.. 
0003c200:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl 
0003c210:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla 
0003c220:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id 
0003c230:·3d22·6964·6d37·3939·3122·3e3c·7461·626c··="idm7991"><tabl 
0003c240:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t 
0003c250:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab 
0003c260:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl 
0003c270:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr 
0003c280:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity: 
0003c290:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td 
0003c2a0:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di 
0003c2b0:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t 
0003c2c0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr>< 
0003c2d0:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</ 
0003c2e0:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td 
0003c2f0:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St 
0003c300:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td> 
0003c310:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr> 
0003c320:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co 
0003c330:·6465·3e0a·646e·6620·696e·7374·616c·6c20··de>.dnf·install· 
0003c340:·6169·6465·0a3c·2f63·6f64·653e·3c2f·7072··aide.</code></pr0003c280:·2a22·0a3c·2f63·6f64·653e·3c2f·7072·653e··*".</code></pre>
0003c350:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class0003c290:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class="
0003c360:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes0003c2a0:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success"
0003c370:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle="0003c2b0:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co
0003c380:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t0003c2c0:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar
0003c390:·6172·6765·743d·2223·6964·6d37·3939·3222··arget="#idm7992"0003c2d0:·6765·743d·2223·6964·6d37·3939·3222·2074··get="#idm7992"·t
0003c3a0:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro0003c2e0:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
0003c3b0:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria0003c2f0:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
0003c3c0:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false0003c300:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
0003c3d0:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat0003c310:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
0003c3e0:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre0003c320:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
0003c3f0:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati0003c330:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
0003c400:·6f6e·2041·6e61·636f·6e64·6120·736e·6970··on·Anaconda·snip0003c340:·2050·7570·7065·7420·736e·6970·7065·7420···Puppet·snippet·
0003c410:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br><0003c350:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·
0003c420:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel0003c360:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col
0003c430:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap0003c370:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·
0003c440:·7365·2220·6964·3d22·6964·6d37·3939·3222··se"·id="idm7992"0003c380:·6964·3d22·6964·6d37·3939·3222·3e3c·7461··id="idm7992"><ta
0003c450:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t0003c390:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table
0003c460:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip0003c3a0:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t
0003c470:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere0003c3b0:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta
0003c480:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense0003c3c0:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><
0003c490:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl0003c3d0:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit
0003c4a0:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l0003c3e0:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</
0003c4b0:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>0003c3f0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
0003c4c0:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:<0003c400:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th>
 0003c410:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
 0003c420:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot:
 0003c430:·3c2f·7468·3e3c·7464·3e66·616c·7365·3c2f··</th><td>false</
 0003c440:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 0003c450:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t
 0003c460:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t
 0003c470:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><
 0003c480:·636f·6465·3e69·6e63·6c75·6465·2069·6e73··code>include·ins
 0003c490:·7461·6c6c·5f61·6964·650a·0a63·6c61·7373··tall_aide..class
 0003c4a0:·2069·6e73·7461·6c6c·5f61·6964·6520·7b0a···install_aide·{.
 0003c4b0:·2020·7061·636b·6167·6520·7b20·2761·6964····package·{·'aid
 0003c4c0:·6527·3a0a·2020·2020·656e·7375·7265·203d··e':.····ensure·=
 0003c4d0:·2667·743b·2027·696e·7374·616c·6c65·6427··&gt;·'installed'
 0003c4e0:·2c0a·2020·7d0a·7d0a·3c2f·636f·6465·3e3c··,.··}.}.</code><
 0003c4f0:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl
 0003c500:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc
 0003c510:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl
 0003c520:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat
 0003c530:·612d·7461·7267·6574·3d22·2369·646d·3739··a-target="#idm79
 0003c540:·3933·2220·7461·6269·6e64·6578·3d22·3022··93"·tabindex="0"
 0003c550:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
 0003c560:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
 0003c570:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
 0003c580:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
 0003c590:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
 0003c5a0:·6174·696f·6e20·7363·7269·7074·20e2·87b2··ation·script·...
 0003c5b0:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
 0003c5c0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
 0003c5d0:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
 0003c5e0:·2269·646d·3739·3933·223e·3c74·6162·6c65··"idm7993"><table
 0003c5f0:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta
 0003c600:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl
 0003c610:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table
 0003c620:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>
 0003c630:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<
0003c4d0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>0003c640:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
 0003c650:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis
 0003c660:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td
 0003c670:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
 0003c680:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t
 0003c690:·683e·3c74·643e·6661·6c73·653c·2f74·643e··h><td>false</td>
0003c4e0:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb0003c6a0:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str
0003c4f0:·6f6f·743a·3c2f·7468·3e3c·7464·3e66·616c··oot:</th><td>fal0003c6b0:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e
 0003c6c0:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr><
 0003c6d0:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod
 0003c6e0:·653e·0a70·6163·6b61·6765·2069·6e73·7461··e>.package·insta
 0003c6f0:·6c6c·2061·6964·650a·3c2f·636f·6465·3e3c··ll·aide.</code><
 0003c700:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl
 0003c710:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc
 0003c720:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl
 0003c730:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat
 0003c740:·612d·7461·7267·6574·3d22·2369·646d·3739··a-target="#idm79
 0003c750:·3934·2220·7461·6269·6e64·6578·3d22·3022··94"·tabindex="0"
 0003c760:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
 0003c770:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
 0003c780:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
 0003c790:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
 0003c7a0:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
 0003c7b0:·6174·696f·6e20·5368·656c·6c20·7363·7269··ation·Shell·scri
0003c500:·7365·3c2f·7464·3e3c·2f74·723e·3c74·723e··se</td></tr><tr> 
0003c510:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t 
0003c520:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td 
0003c530:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p 
0003c540:·7265·3e3c·636f·6465·3e0a·7061·636b·6167··re><code>.packag 
0003c550:·6520·2d2d·6164·643d·6169·6465·0a3c·2f63··e·--add=aide.</c 
Max diff block lines reached; 1461185/1488399 bytes (98.17%) of diff not shown.
164 KB
html2text {}
    
Offset 165, 52 lines modifiedOffset 165, 38 lines modified
165 ··-·PCI-DSSv4-11.5.2165 ··-·PCI-DSSv4-11.5.2
166 ··-·enable_strategy166 ··-·enable_strategy
167 ··-·low_complexity167 ··-·low_complexity
168 ··-·low_disruption168 ··-·low_disruption
169 ··-·medium_severity169 ··-·medium_severity
170 ··-·no_reboot_needed170 ··-·no_reboot_needed
171 ··-·package_aide_installed171 ··-·package_aide_installed
172 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
173 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
174 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
175 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
176 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
177 dnf·install·aide 
178 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
179 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
180 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
181 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
182 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
183 package·--add=aide 
184 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8172 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
185 [[packages]]173 [[packages]]
186 name·=·"aide"174 name·=·"aide"
187 version·=·"*"175 version·=·"*"
188 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
189 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
190 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
191 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
192 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
193 package·install·aide 
194 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8176 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
195 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low177 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
196 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low178 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
197 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false179 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
198 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable180 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
199 include·install_aide181 include·install_aide
  
200 class·install_aide·{182 class·install_aide·{
201 ··package·{·'aide':183 ··package·{·'aide':
202 ····ensure·=>·'installed',184 ····ensure·=>·'installed',
203 ··}185 ··}
204 }186 }
 187 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 188 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 189 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 190 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 191 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 192 package·install·aide
205 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8193 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
206 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low194 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
207 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low195 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
208 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false196 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
209 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable197 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
210 #·Remediation·is·applicable·only·in·certain·platforms198 #·Remediation·is·applicable·only·in·certain·platforms
211 if·rpm·--quiet·-q·kernel;·then199 if·rpm·--quiet·-q·kernel;·then
Offset 218, 14 lines modifiedOffset 204, 28 lines modified
218 if·!·rpm·-q·--quiet·"aide"·;·then204 if·!·rpm·-q·--quiet·"aide"·;·then
219 ····yum·install·-y·"aide"205 ····yum·install·-y·"aide"
220 fi206 fi
  
221 else207 else
222 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'208 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
223 fi209 fi
 210 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 211 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 212 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 213 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 214 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 215 package·--add=aide
 216 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 217 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 218 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 219 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 220 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 221 dnf·install·aide
224 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*222 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
225 Run·the·following·command·to·generate·a·new·database:223 Run·the·following·command·to·generate·a·new·database:
226 $·sudo·/usr/sbin/aide·--init224 $·sudo·/usr/sbin/aide·--init
227 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:225 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
228 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz226 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
229 To·initiate·a·manual·check,·run·the·following·command:227 To·initiate·a·manual·check,·run·the·following·command:
230 $·sudo·/usr/sbin/aide·--check228 $·sudo·/usr/sbin/aide·--check
Offset 2867, 29 lines modifiedOffset 2867, 29 lines modified
2867 References:··_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)2867 References:··_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)
2868 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-42868 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4
2869 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-002272869 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
2870 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-08-0108002870 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-08-010800
2871 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R282871 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R28
2872 ·············_\x8c_\x8i_\x8s············1.1.2.3.12872 ·············_\x8c_\x8i_\x8s············1.1.2.3.1
2873 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-230328r1017139_rule2873 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-230328r1017139_rule
2874 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
2875 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
2876 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high 
2877 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
2878 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
2879 part·/home 
2880 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x82874 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
2881 [[customizations.filesystem]]2875 [[customizations.filesystem]]
2882 mountpoint·=·"/home"2876 mountpoint·=·"/home"
2883 size·=·10737418242877 size·=·1073741824
2884 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x82878 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
2885 logvol·/home·10242879 logvol·/home·1024
 2880 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 2881 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 2882 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high
 2883 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 2884 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 2885 part·/home
2886 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/t\x8tm\x8mp\x8p·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*2886 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/t\x8tm\x8mp\x8p·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
2887 The·/tmp·directory·is·a·world-writable·directory·used·for·temporary·file·storage.·Ensure·it·has·its·own·partition·or·logical·volume·at·installation·time,·or·migrate·it·using·LVM.2887 The·/tmp·directory·is·a·world-writable·directory·used·for·temporary·file·storage.·Ensure·it·has·its·own·partition·or·logical·volume·at·installation·time,·or·migrate·it·using·LVM.
2888 Rationale:···The·/tmp·partition·is·used·as·temporary·storage·by·many·programs.·Placing·/tmp·in·its·own·partition·enables·the·setting·of·more·restrictive·mount·options,·which·can·help·protect·programs·which·use·it.2888 Rationale:···The·/tmp·partition·is·used·as·temporary·storage·by·many·programs.·Placing·/tmp·in·its·own·partition·enables·the·setting·of·more·restrictive·mount·options,·which·can·help·protect·programs·which·use·it.
2889 Severity: ···low2889 Severity: ···low
2890 Rule·ID:·····xccdf_org.ssgproject.content_rule_partition_for_tmp2890 Rule·ID:·····xccdf_org.ssgproject.content_rule_partition_for_tmp
2891 Identifiers:·CCE-80851-92891 Identifiers:·CCE-80851-9
2892 ·············_\x8c_\x8i_\x8s_\x8-_\x8c_\x8s_\x8c········12,·15,·82892 ·············_\x8c_\x8i_\x8s_\x8-_\x8c_\x8s_\x8c········12,·15,·8
Offset 2899, 29 lines modifiedOffset 2899, 29 lines modified
2899 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.32899 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.3
Max diff block lines reached; 162334/167802 bytes (96.74%) of diff not shown.
1.15 MB
./usr/share/doc/ssg-nondebian/ssg-rhel9-guide-anssi_bp28_enhanced.html
    
Offset 15185, 207 lines modifiedOffset 15185, 207 lines modified
0003b500:·6765·743d·2223·6964·6d38·3435·3922·2074··get="#idm8459"·t0003b500:·6765·743d·2223·6964·6d38·3435·3922·2074··get="#idm8459"·t
0003b510:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role0003b510:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
0003b520:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e0003b520:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
0003b530:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·0003b530:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
0003b540:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·0003b540:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
0003b550:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=0003b550:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
0003b560:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation0003b560:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
 0003b570:·204f·5342·7569·6c64·2042·6c75·6570·7269···OSBuild·Bluepri
 0003b580:·6e74·2073·6e69·7070·6574·20e2·87b2·3c2f··nt·snippet·...</
 0003b590:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
 0003b5a0:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
 0003b5b0:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
 0003b5c0:·646d·3834·3539·223e·3c70·7265·3e3c·636f··dm8459"><pre><co
 0003b5d0:·6465·3e0a·5b5b·7061·636b·6167·6573·5d5d··de>.[[packages]]
 0003b5e0:·0a6e·616d·6520·3d20·2261·6964·6522·0a76··.name·=·"aide".v
 0003b5f0:·6572·7369·6f6e·203d·2022·2a22·0a3c·2f63··ersion·=·"*".</c
0003b570:·2073·6372·6970·7420·e287·b23c·2f61·3e3c···script·...</a>< 
0003b580:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p 
0003b590:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co 
0003b5a0:·6c6c·6170·7365·2220·6964·3d22·6964·6d38··llapse"·id="idm8 
0003b5b0:·3435·3922·3e3c·7461·626c·6520·636c·6173··459"><table·clas 
0003b5c0:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s 
0003b5d0:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor 
0003b5e0:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond 
0003b5f0:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C 
0003b600:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th>< 
0003b610:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
0003b620:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti 
0003b630:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low< 
0003b640:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0003b650:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td 
0003b660:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr> 
0003b670:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy 
0003b680:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable 
0003b690:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl 
0003b6a0:·653e·3c70·7265·3e3c·636f·6465·3e0a·646e··e><pre><code>.dn 
0003b6b0:·6620·696e·7374·616c·6c20·6169·6465·0a3c··f·install·aide.< 
0003b6c0:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di0003b600:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div>
0003b6d0:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn·0003b610:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt
0003b6e0:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat0003b620:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data-
0003b6f0:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap0003b630:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse
0003b700:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=0003b640:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
0003b710:·2223·6964·6d38·3436·3022·2074·6162·696e··"#idm8460"·tabin0003b650:·6964·6d38·3436·3022·2074·6162·696e·6465··idm8460"·tabinde
0003b720:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu0003b660:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt
0003b730:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan0003b670:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande
0003b740:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl0003b680:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=
0003b750:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r0003b690:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev
0003b760:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"0003b6a0:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R
0003b770:·3e52·656d·6564·6961·7469·6f6e·2041·6e61··>Remediation·Ana 
0003b780:·636f·6e64·6120·736e·6970·7065·7420·e287··conda·snippet·..0003b6b0:·656d·6564·6961·7469·6f6e·2050·7570·7065··emediation·Puppe
 0003b6c0:·7420·736e·6970·7065·7420·e287·b23c·2f61··t·snippet·...</a
0003b790:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl0003b6d0:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
0003b7a0:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla0003b6e0:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
0003b7b0:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id0003b6f0:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
0003b7c0:·3d22·6964·6d38·3436·3022·3e3c·7461·626c··="idm8460"><tabl0003b700:·6d38·3436·3022·3e3c·7461·626c·6520·636c··m8460"><table·cl
0003b7d0:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t0003b710:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table
0003b7e0:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab0003b720:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b
0003b7f0:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl0003b730:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co
0003b800:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr0003b740:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th
0003b810:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity: 
0003b820:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td 
0003b830:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di 
0003b840:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t 
0003b850:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr>< 
0003b860:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</ 
0003b870:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td 
0003b880:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St 
0003b890:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td> 
0003b8a0:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr> 
0003b8b0:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co 
0003b8c0:·6465·3e0a·7061·636b·6167·6520·2d2d·6164··de>.package·--ad 
0003b8d0:·643d·6169·6465·0a3c·2f63·6f64·653e·3c2f··d=aide.</code></ 
0003b8e0:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla 
0003b8f0:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ 
0003b900:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle 
0003b910:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data 
0003b920:·2d74·6172·6765·743d·2223·6964·6d38·3436··-target="#idm846 
0003b930:·3122·2074·6162·696e·6465·783d·2230·2220··1"·tabindex="0"· 
0003b940:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar 
0003b950:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal 
0003b960:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ 
0003b970:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h 
0003b980:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia 
0003b990:·7469·6f6e·204f·5342·7569·6c64·2042·6c75··tion·OSBuild·Blu 
0003b9a0:·6570·7269·6e74·2073·6e69·7070·6574·20e2··eprint·snippet·. 
0003b9b0:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c 
0003b9c0:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll 
0003b9d0:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i 
0003b9e0:·643d·2269·646d·3834·3631·223e·3c70·7265··d="idm8461"><pre 
0003b9f0:·3e3c·636f·6465·3e0a·5b5b·7061·636b·6167··><code>.[[packag 
0003ba00:·6573·5d5d·0a6e·616d·6520·3d20·2261·6964··es]].name·=·"aid 
0003ba10:·6522·0a76·6572·7369·6f6e·203d·2022·2a22··e".version·=·"*" 
0003ba20:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></ 
0003ba30:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt 
0003ba40:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d 
0003ba50:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll 
0003ba60:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe 
0003ba70:·743d·2223·6964·6d38·3436·3222·2074·6162··t="#idm8462"·tab 
0003ba80:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role=" 
0003ba90:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp 
0003baa0:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti 
0003bab0:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to 
0003bac0:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="# 
0003bad0:·2122·3e52·656d·6564·6961·7469·6f6e·2073··!">Remediation·s 
0003bae0:·6372·6970·7420·e287·b23c·2f61·3e3c·6272··cript·...</a><br 
0003baf0:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan 
0003bb00:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll 
0003bb10:·6170·7365·2220·6964·3d22·6964·6d38·3436··apse"·id="idm846 
0003bb20:·3222·3e3c·7461·626c·6520·636c·6173·733d··2"><table·class= 
0003bb30:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str 
0003bb40:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde 
0003bb50:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden 
0003bb60:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com 
0003bb70:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td0003b750:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th
0003bb80:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t0003b760:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
0003bb90:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption0003b770:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup
0003bba0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t0003b780:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo
0003bbb0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e52··d></tr><tr><th>R0003b790:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
0003bbc0:·6562·6f6f·743a·3c2f·7468·3e3c·7464·3e66··eboot:</th><td>f0003b7a0:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th><
 0003b7b0:·7464·3e66·616c·7365·3c2f·7464·3e3c·2f74··td>false</td></t
 0003b7c0:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate
 0003b7d0:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab
0003bbd0:·616c·7365·3c2f·7464·3e3c·2f74·723e·3c74··alse</td></tr><t0003b7e0:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta
0003bbe0:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:< 
0003bbf0:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</ 
0003bc00:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table> 
0003bc10:·3c70·7265·3e3c·636f·6465·3e0a·7061·636b··<pre><code>.pack 
Max diff block lines reached; 1057851/1085065 bytes (97.49%) of diff not shown.
118 KB
html2text {}
    
Offset 143, 52 lines modifiedOffset 143, 38 lines modified
143 ··-·PCI-DSSv4-11.5.2143 ··-·PCI-DSSv4-11.5.2
144 ··-·enable_strategy144 ··-·enable_strategy
145 ··-·low_complexity145 ··-·low_complexity
146 ··-·low_disruption146 ··-·low_disruption
147 ··-·medium_severity147 ··-·medium_severity
148 ··-·no_reboot_needed148 ··-·no_reboot_needed
149 ··-·package_aide_installed149 ··-·package_aide_installed
150 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
151 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
152 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
153 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
154 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
155 dnf·install·aide 
156 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
157 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
158 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
159 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
160 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
161 package·--add=aide 
162 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8150 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
163 [[packages]]151 [[packages]]
164 name·=·"aide"152 name·=·"aide"
165 version·=·"*"153 version·=·"*"
166 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
167 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
168 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
169 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
170 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
171 package·install·aide 
172 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8154 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
173 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low155 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
174 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low156 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
175 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false157 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
176 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable158 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
177 include·install_aide159 include·install_aide
  
178 class·install_aide·{160 class·install_aide·{
179 ··package·{·'aide':161 ··package·{·'aide':
180 ····ensure·=>·'installed',162 ····ensure·=>·'installed',
181 ··}163 ··}
182 }164 }
 165 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 166 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 167 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 168 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 169 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 170 package·install·aide
183 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8171 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
184 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low172 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
185 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low173 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
186 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false174 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
187 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable175 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
188 #·Remediation·is·applicable·only·in·certain·platforms176 #·Remediation·is·applicable·only·in·certain·platforms
189 if·rpm·--quiet·-q·kernel;·then177 if·rpm·--quiet·-q·kernel;·then
Offset 196, 14 lines modifiedOffset 182, 28 lines modified
196 if·!·rpm·-q·--quiet·"aide"·;·then182 if·!·rpm·-q·--quiet·"aide"·;·then
197 ····dnf·install·-y·"aide"183 ····dnf·install·-y·"aide"
198 fi184 fi
  
199 else185 else
200 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'186 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
201 fi187 fi
 188 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 189 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 190 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 191 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 192 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 193 package·--add=aide
 194 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 195 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 196 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 197 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 198 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 199 dnf·install·aide
202 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*200 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
203 Run·the·following·command·to·generate·a·new·database:201 Run·the·following·command·to·generate·a·new·database:
204 $·sudo·/usr/sbin/aide·--init202 $·sudo·/usr/sbin/aide·--init
205 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:203 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
206 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz204 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
207 To·initiate·a·manual·check,·run·the·following·command:205 To·initiate·a·manual·check,·run·the·following·command:
208 $·sudo·/usr/sbin/aide·--check206 $·sudo·/usr/sbin/aide·--check
Offset 363, 51 lines modifiedOffset 363, 51 lines modified
363 References:··_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)363 References:··_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)
364 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4364 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4
365 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227365 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
366 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R28366 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R28
367 ·············_\x8c_\x8i_\x8s············1.1.2.3.1367 ·············_\x8c_\x8i_\x8s············1.1.2.3.1
368 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-09-231010368 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-09-231010
369 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-257843r991589_rule369 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-257843r991589_rule
370 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
371 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
372 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high 
373 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
374 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
375 part·/home 
376 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8370 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
377 [[customizations.filesystem]]371 [[customizations.filesystem]]
378 mountpoint·=·"/home"372 mountpoint·=·"/home"
379 size·=·1073741824373 size·=·1073741824
380 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8374 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
381 logvol·/home·1024375 logvol·/home·1024
 376 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 377 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 378 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high
 379 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 380 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 381 part·/home
382 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/s\x8sr\x8rv\x8v·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*382 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/s\x8sr\x8rv\x8v·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
383 If·a·file·server·(FTP,·TFTP...)·is·hosted·locally,·create·a·separate·partition·for·/srv·at·installation·time·(or·migrate·it·later·using·LVM).·If·/srv·will·be·mounted·from·another·system·such·as·an·NFS·server,·then·creating·a·separate·partition·is·not·necessary·at·installation·time,·and·the·mountpoint·can·instead·be·configured·later.383 If·a·file·server·(FTP,·TFTP...)·is·hosted·locally,·create·a·separate·partition·for·/srv·at·installation·time·(or·migrate·it·later·using·LVM).·If·/srv·will·be·mounted·from·another·system·such·as·an·NFS·server,·then·creating·a·separate·partition·is·not·necessary·at·installation·time,·and·the·mountpoint·can·instead·be·configured·later.
384 Rationale:···Srv·deserves·files·for·local·network·file·server·such·as·FTP.·Ensuring·that·/srv·is·mounted·on·its·own·partition·enables·the·setting·of·more·restrictive·mount·options,·and·also·helps·ensure·that·users·cannot·trivially·fill·partitions·used·for·log·or·audit·data·storage.384 Rationale:···Srv·deserves·files·for·local·network·file·server·such·as·FTP.·Ensuring·that·/srv·is·mounted·on·its·own·partition·enables·the·setting·of·more·restrictive·mount·options,·and·also·helps·ensure·that·users·cannot·trivially·fill·partitions·used·for·log·or·audit·data·storage.
385 Severity: ···unknown385 Severity: ···unknown
386 Rule·ID:·····xccdf_org.ssgproject.content_rule_partition_for_srv386 Rule·ID:·····xccdf_org.ssgproject.content_rule_partition_for_srv
387 Identifiers:·CCE-90846-7387 Identifiers:·CCE-90846-7
388 References:··_\x8a_\x8n_\x8s_\x8s_\x8i·R28388 References:··_\x8a_\x8n_\x8s_\x8s_\x8i·R28
389 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
390 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
Max diff block lines reached; 115308/121195 bytes (95.14%) of diff not shown.
1.24 MB
./usr/share/doc/ssg-nondebian/ssg-rhel9-guide-anssi_bp28_high.html
    
Offset 15190, 207 lines modifiedOffset 15190, 207 lines modified
0003b550:·7461·7267·6574·3d22·2369·646d·3834·3539··target="#idm84590003b550:·7461·7267·6574·3d22·2369·646d·3834·3539··target="#idm8459
0003b560:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r0003b560:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r
0003b570:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari0003b570:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari
0003b580:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals0003b580:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals
0003b590:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa0003b590:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa
0003b5a0:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr0003b5a0:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr
0003b5b0:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat0003b5b0:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat
0003b5c0:·696f·6e20·7363·7269·7074·20e2·87b2·3c2f··ion·script·...</0003b5c0:·696f·6e20·4f53·4275·696c·6420·426c·7565··ion·OSBuild·Blue
 0003b5d0:·7072·696e·7420·736e·6970·7065·7420·e287··print·snippet·..
 0003b5e0:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl
 0003b5f0:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla
 0003b600:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id
 0003b610:·3d22·6964·6d38·3435·3922·3e3c·7072·653e··="idm8459"><pre>
 0003b620:·3c63·6f64·653e·0a5b·5b70·6163·6b61·6765··<code>.[[package
 0003b630:·735d·5d0a·6e61·6d65·203d·2022·6169·6465··s]].name·=·"aide
 0003b640:·220a·7665·7273·696f·6e20·3d20·222a·220a··".version·=·"*".
 0003b650:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d
 0003b660:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn
 0003b670:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da
 0003b680:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla
 0003b690:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
 0003b6a0:·3d22·2369·646d·3834·3630·2220·7461·6269··="#idm8460"·tabi
 0003b6b0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
 0003b6c0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
 0003b6d0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
 0003b6e0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
 0003b6f0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
 0003b700:·223e·5265·6d65·6469·6174·696f·6e20·5075··">Remediation·Pu
 0003b710:·7070·6574·2073·6e69·7070·6574·20e2·87b2··ppet·snippet·...
0003b5d0:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class0003b720:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
0003b5e0:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse0003b730:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
0003b5f0:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i0003b740:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
0003b600:·646d·3834·3539·223e·3c74·6162·6c65·2063··dm8459"><table·c0003b750:·2269·646d·3834·3630·223e·3c74·6162·6c65··"idm8460"><table
0003b610:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl0003b760:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta
0003b620:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-0003b770:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl
0003b630:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c0003b780:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table
0003b640:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t0003b790:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>
0003b650:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t0003b7a0:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<
0003b660:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></0003b7b0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
0003b670:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru0003b7c0:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis
0003b680:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l0003b7d0:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td
0003b690:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>0003b7e0:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
0003b6a0:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th>0003b7f0:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t
0003b6b0:·3c74·643e·6661·6c73·653c·2f74·643e·3c2f··<td>false</td></0003b800:·683e·3c74·643e·6661·6c73·653c·2f74·643e··h><td>false</td>
0003b6c0:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat0003b810:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str
0003b6d0:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena0003b820:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e
0003b6e0:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t0003b830:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr><
0003b6f0:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>0003b840:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod
0003b700:·0a64·6e66·2069·6e73·7461·6c6c·2061·6964··.dnf·install·aid 
0003b710:·650a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··e.</code></pre>< 
0003b720:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b 
0003b730:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"· 
0003b740:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col 
0003b750:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ 
0003b760:·6574·3d22·2369·646d·3834·3630·2220·7461··et="#idm8460"·ta 
0003b770:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role= 
0003b780:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex 
0003b790:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t 
0003b7a0:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t 
0003b7b0:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href=" 
0003b7c0:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation· 
0003b7d0:·416e·6163·6f6e·6461·2073·6e69·7070·6574··Anaconda·snippet 
0003b7e0:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div 
0003b7f0:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co 
0003b800:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse" 
0003b810:·2069·643d·2269·646d·3834·3630·223e·3c74···id="idm8460"><t 
0003b820:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl 
0003b830:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped· 
0003b840:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t 
0003b850:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed"> 
0003b860:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi 
0003b870:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low< 
0003b880:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0003b890:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th0003b850:·653e·696e·636c·7564·6520·696e·7374·616c··e>include·instal
 0003b860:·6c5f·6169·6465·0a0a·636c·6173·7320·696e··l_aide..class·in
 0003b870:·7374·616c·6c5f·6169·6465·207b·0a20·2070··stall_aide·{.··p
 0003b880:·6163·6b61·6765·207b·2027·6169·6465·273a··ackage·{·'aide':
 0003b890:·0a20·2020·2065·6e73·7572·6520·3d26·6774··.····ensure·=&gt
 0003b8a0:·3b20·2769·6e73·7461·6c6c·6564·272c·0a20··;·'installed',.·
 0003b8b0:·207d·0a7d·0a3c·2f63·6f64·653e·3c2f·7072···}.}.</code></pr
 0003b8c0:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class
 0003b8d0:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes
 0003b8e0:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle="
 0003b8f0:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t
 0003b900:·6172·6765·743d·2223·6964·6d38·3436·3122··arget="#idm8461"
 0003b910:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro
 0003b920:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria
 0003b930:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false
 0003b940:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat
 0003b950:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre
 0003b960:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati
 0003b970:·6f6e·2073·6372·6970·7420·e287·b23c·2f61··on·script·...</a
 0003b980:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
 0003b990:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
 0003b9a0:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
 0003b9b0:·6d38·3436·3122·3e3c·7461·626c·6520·636c··m8461"><table·cl
 0003b9c0:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table
 0003b9d0:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b
 0003b9e0:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co
 0003b9f0:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th
 0003ba00:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th
0003b8a0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t0003ba10:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
0003b8b0:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot 
0003b8c0:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false<0003ba20:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup
 0003ba30:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo
0003b8d0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th0003ba40:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
0003b8e0:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th>< 
0003b8f0:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></ 
0003b900:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre> 
0003b910:·3c63·6f64·653e·0a70·6163·6b61·6765·202d··<code>.package·- 
0003b920:·2d61·6464·3d61·6964·650a·3c2f·636f·6465··-add=aide.</code 
0003b930:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a· 
0003b940:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s 
0003b950:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog 
0003b960:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d 
0003b970:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm 
0003b980:·3834·3631·2220·7461·6269·6e64·6578·3d22··8461"·tabindex=" 
0003b990:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button" 
0003b9a0:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded=" 
0003b9b0:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac 
0003b9c0:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal 
0003b9d0:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme 
0003b9e0:·6469·6174·696f·6e20·4f53·4275·696c·6420··diation·OSBuild· 
0003b9f0:·426c·7565·7072·696e·7420·736e·6970·7065··Blueprint·snippe0003ba50:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th><
 0003ba60:·7464·3e66·616c·7365·3c2f·7464·3e3c·2f74··td>false</td></t
 0003ba70:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate
 0003ba80:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab
Max diff block lines reached; 1141707/1168921 bytes (97.67%) of diff not shown.
128 KB
html2text {}
    
Offset 144, 52 lines modifiedOffset 144, 38 lines modified
144 ··-·PCI-DSSv4-11.5.2144 ··-·PCI-DSSv4-11.5.2
145 ··-·enable_strategy145 ··-·enable_strategy
146 ··-·low_complexity146 ··-·low_complexity
147 ··-·low_disruption147 ··-·low_disruption
148 ··-·medium_severity148 ··-·medium_severity
149 ··-·no_reboot_needed149 ··-·no_reboot_needed
150 ··-·package_aide_installed150 ··-·package_aide_installed
151 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
152 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
153 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
154 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
155 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
156 dnf·install·aide 
157 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
158 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
159 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
160 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
161 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
162 package·--add=aide 
163 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8151 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
164 [[packages]]152 [[packages]]
165 name·=·"aide"153 name·=·"aide"
166 version·=·"*"154 version·=·"*"
167 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
168 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
169 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
170 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
171 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
172 package·install·aide 
173 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8155 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
174 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low156 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
175 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low157 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
176 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false158 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
177 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable159 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
178 include·install_aide160 include·install_aide
  
179 class·install_aide·{161 class·install_aide·{
180 ··package·{·'aide':162 ··package·{·'aide':
181 ····ensure·=>·'installed',163 ····ensure·=>·'installed',
182 ··}164 ··}
183 }165 }
 166 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 167 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 168 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 169 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 170 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 171 package·install·aide
184 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8172 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
185 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low173 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
186 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low174 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
187 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false175 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
188 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable176 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
189 #·Remediation·is·applicable·only·in·certain·platforms177 #·Remediation·is·applicable·only·in·certain·platforms
190 if·rpm·--quiet·-q·kernel;·then178 if·rpm·--quiet·-q·kernel;·then
Offset 197, 14 lines modifiedOffset 183, 28 lines modified
197 if·!·rpm·-q·--quiet·"aide"·;·then183 if·!·rpm·-q·--quiet·"aide"·;·then
198 ····dnf·install·-y·"aide"184 ····dnf·install·-y·"aide"
199 fi185 fi
  
200 else186 else
201 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'187 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
202 fi188 fi
 189 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 190 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 191 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 192 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 193 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 194 package·--add=aide
 195 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 196 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 197 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 198 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 199 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 200 dnf·install·aide
203 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*201 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
204 Run·the·following·command·to·generate·a·new·database:202 Run·the·following·command·to·generate·a·new·database:
205 $·sudo·/usr/sbin/aide·--init203 $·sudo·/usr/sbin/aide·--init
206 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:204 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
207 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz205 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
208 To·initiate·a·manual·check,·run·the·following·command:206 To·initiate·a·manual·check,·run·the·following·command:
209 $·sudo·/usr/sbin/aide·--check207 $·sudo·/usr/sbin/aide·--check
Offset 899, 51 lines modifiedOffset 899, 51 lines modified
899 References:··_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)899 References:··_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)
900 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4900 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4
901 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227901 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
902 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R28902 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R28
903 ·············_\x8c_\x8i_\x8s············1.1.2.3.1903 ·············_\x8c_\x8i_\x8s············1.1.2.3.1
904 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-09-231010904 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-09-231010
905 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-257843r991589_rule905 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-257843r991589_rule
906 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
907 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
908 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high 
909 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
910 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
911 part·/home 
912 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8906 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
913 [[customizations.filesystem]]907 [[customizations.filesystem]]
914 mountpoint·=·"/home"908 mountpoint·=·"/home"
915 size·=·1073741824909 size·=·1073741824
916 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8910 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
917 logvol·/home·1024911 logvol·/home·1024
 912 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 913 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 914 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high
 915 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 916 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 917 part·/home
918 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/s\x8sr\x8rv\x8v·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*918 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/s\x8sr\x8rv\x8v·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
919 If·a·file·server·(FTP,·TFTP...)·is·hosted·locally,·create·a·separate·partition·for·/srv·at·installation·time·(or·migrate·it·later·using·LVM).·If·/srv·will·be·mounted·from·another·system·such·as·an·NFS·server,·then·creating·a·separate·partition·is·not·necessary·at·installation·time,·and·the·mountpoint·can·instead·be·configured·later.919 If·a·file·server·(FTP,·TFTP...)·is·hosted·locally,·create·a·separate·partition·for·/srv·at·installation·time·(or·migrate·it·later·using·LVM).·If·/srv·will·be·mounted·from·another·system·such·as·an·NFS·server,·then·creating·a·separate·partition·is·not·necessary·at·installation·time,·and·the·mountpoint·can·instead·be·configured·later.
920 Rationale:···Srv·deserves·files·for·local·network·file·server·such·as·FTP.·Ensuring·that·/srv·is·mounted·on·its·own·partition·enables·the·setting·of·more·restrictive·mount·options,·and·also·helps·ensure·that·users·cannot·trivially·fill·partitions·used·for·log·or·audit·data·storage.920 Rationale:···Srv·deserves·files·for·local·network·file·server·such·as·FTP.·Ensuring·that·/srv·is·mounted·on·its·own·partition·enables·the·setting·of·more·restrictive·mount·options,·and·also·helps·ensure·that·users·cannot·trivially·fill·partitions·used·for·log·or·audit·data·storage.
921 Severity: ···unknown921 Severity: ···unknown
922 Rule·ID:·····xccdf_org.ssgproject.content_rule_partition_for_srv922 Rule·ID:·····xccdf_org.ssgproject.content_rule_partition_for_srv
923 Identifiers:·CCE-90846-7923 Identifiers:·CCE-90846-7
924 References:··_\x8a_\x8n_\x8s_\x8s_\x8i·R28924 References:··_\x8a_\x8n_\x8s_\x8s_\x8i·R28
925 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
926 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
Max diff block lines reached; 125399/131286 bytes (95.52%) of diff not shown.
1.04 MB
./usr/share/doc/ssg-nondebian/ssg-rhel9-guide-anssi_bp28_intermediary.html
    
Offset 15180, 208 lines modifiedOffset 15180, 208 lines modified
0003b4b0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target0003b4b0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
0003b4c0:·3d22·2369·646d·3834·3539·2220·7461·6269··="#idm8459"·tabi0003b4c0:·3d22·2369·646d·3834·3539·2220·7461·6269··="#idm8459"·tabi
0003b4d0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b0003b4d0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
0003b4e0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa0003b4e0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
0003b4f0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit0003b4f0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
0003b500:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·0003b500:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
0003b510:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!0003b510:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
0003b520:·223e·5265·6d65·6469·6174·696f·6e20·7363··">Remediation·sc0003b520:·223e·5265·6d65·6469·6174·696f·6e20·4f53··">Remediation·OS
 0003b530:·4275·696c·6420·426c·7565·7072·696e·7420··Build·Blueprint·
 0003b540:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><
 0003b550:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
 0003b560:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
 0003b570:·6c6c·6170·7365·2220·6964·3d22·6964·6d38··llapse"·id="idm8
 0003b580:·3435·3922·3e3c·7072·653e·3c63·6f64·653e··459"><pre><code>
 0003b590:·0a5b·5b70·6163·6b61·6765·735d·5d0a·6e61··.[[packages]].na
 0003b5a0:·6d65·203d·2022·6169·6465·220a·7665·7273··me·=·"aide".vers
 0003b5b0:·696f·6e20·3d20·222a·220a·3c2f·636f·6465··ion·=·"*".</code
0003b530:·7269·7074·20e2·87b2·3c2f·613e·3c62·723e··ript·...</a><br> 
0003b540:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane 
0003b550:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla 
0003b560:·7073·6522·2069·643d·2269·646d·3834·3539··pse"·id="idm8459 
0003b570:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class=" 
0003b580:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri 
0003b590:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border 
0003b5a0:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens 
0003b5b0:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp 
0003b5c0:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td> 
0003b5d0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr 
0003b5e0:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption: 
0003b5f0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td 
0003b600:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re 
0003b610:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa 
0003b620:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr 
0003b630:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</ 
0003b640:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t 
0003b650:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table>< 
0003b660:·7072·653e·3c63·6f64·653e·0a64·6e66·2069··pre><code>.dnf·i 
0003b670:·6e73·7461·6c6c·2061·6964·650a·3c2f·636f··nstall·aide.</co 
0003b680:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div><0003b5c0:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a·
0003b690:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn0003b5d0:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s
0003b6a0:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t0003b5e0:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog
0003b6b0:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse"0003b5f0:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d
0003b6c0:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i0003b600:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
0003b6d0:·646d·3834·3630·2220·7461·6269·6e64·6578··dm8460"·tabindex0003b610:·3834·3630·2220·7461·6269·6e64·6578·3d22··8460"·tabindex="
0003b6e0:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto0003b620:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
0003b6f0:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded0003b630:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
0003b700:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="0003b640:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
0003b710:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve0003b650:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
0003b720:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re0003b660:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
0003b730:·6d65·6469·6174·696f·6e20·416e·6163·6f6e··mediation·Anacon0003b670:·6469·6174·696f·6e20·5075·7070·6574·2073··diation·Puppet·s
0003b740:·6461·2073·6e69·7070·6574·20e2·87b2·3c2f··da·snippet·...</0003b680:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b
0003b750:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class0003b690:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
0003b760:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse0003b6a0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
0003b770:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i0003b6b0:·6c61·7073·6522·2069·643d·2269·646d·3834··lapse"·id="idm84
0003b780:·646d·3834·3630·223e·3c74·6162·6c65·2063··dm8460"><table·c0003b6c0:·3630·223e·3c74·6162·6c65·2063·6c61·7373··60"><table·class
0003b790:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl0003b6d0:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st
0003b7a0:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-0003b6e0:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord
0003b7b0:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c0003b6f0:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde
0003b7c0:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t0003b700:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co
0003b7d0:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t0003b710:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t
0003b7e0:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></0003b720:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
0003b7f0:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru0003b730:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio
 0003b740:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</
 0003b750:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 0003b760:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td>
 0003b770:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr><
 0003b780:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:
 0003b790:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<
 0003b7a0:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table
 0003b7b0:·3e3c·7072·653e·3c63·6f64·653e·696e·636c··><pre><code>incl
 0003b7c0:·7564·6520·696e·7374·616c·6c5f·6169·6465··ude·install_aide
 0003b7d0:·0a0a·636c·6173·7320·696e·7374·616c·6c5f··..class·install_
 0003b7e0:·6169·6465·207b·0a20·2070·6163·6b61·6765··aide·{.··package
 0003b7f0:·207b·2027·6169·6465·273a·0a20·2020·2065···{·'aide':.····e
 0003b800:·6e73·7572·6520·3d26·6774·3b20·2769·6e73··nsure·=&gt;·'ins
 0003b810:·7461·6c6c·6564·272c·0a20·207d·0a7d·0a3c··talled',.··}.}.<
 0003b820:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di
 0003b830:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn·
 0003b840:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat
 0003b850:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap
 0003b860:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
 0003b870:·2223·6964·6d38·3436·3122·2074·6162·696e··"#idm8461"·tabin
 0003b880:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
 0003b890:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
 0003b8a0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
 0003b8b0:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
 0003b8c0:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
 0003b8d0:·3e52·656d·6564·6961·7469·6f6e·2073·6372··>Remediation·scr
 0003b8e0:·6970·7420·e287·b23c·2f61·3e3c·6272·3e3c··ipt·...</a><br><
 0003b8f0:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
 0003b900:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap
 0003b910:·7365·2220·6964·3d22·6964·6d38·3436·3122··se"·id="idm8461"
 0003b920:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t
 0003b930:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip
 0003b940:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere
 0003b950:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense
 0003b960:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl
0003b800:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l0003b970:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l
0003b810:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>0003b980:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
0003b820:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th> 
0003b830:·3c74·643e·6661·6c73·653c·2f74·643e·3c2f··<td>false</td></0003b990:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:<
 0003b9a0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
0003b840:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat0003b9b0:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb
0003b850:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena0003b9c0:·6f6f·743a·3c2f·7468·3e3c·7464·3e66·616c··oot:</th><td>fal
0003b860:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t 
0003b870:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code> 
0003b880:·0a70·6163·6b61·6765·202d·2d61·6464·3d61··.package·--add=a 
0003b890:·6964·650a·3c2f·636f·6465·3e3c·2f70·7265··ide.</code></pre 
0003b8a0:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class= 
0003b8b0:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success 
0003b8c0:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c 
0003b8d0:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta 
0003b8e0:·7267·6574·3d22·2369·646d·3834·3631·2220··rget="#idm8461"· 
0003b8f0:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol 
0003b900:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria- 
0003b910:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false" 
0003b920:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate 
0003b930:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href 
0003b940:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio 
0003b950:·6e20·4f53·4275·696c·6420·426c·7565·7072··n·OSBuild·Bluepr 
0003b960:·696e·7420·736e·6970·7065·7420·e287·b23c··int·snippet·...<0003b9d0:·7365·3c2f·7464·3e3c·2f74·723e·3c74·723e··se</td></tr><tr>
 0003b9e0:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t
 0003b9f0:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td
 0003ba00:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p
 0003ba10:·7265·3e3c·636f·6465·3e0a·7061·636b·6167··re><code>.packag
 0003ba20:·6520·696e·7374·616c·6c20·6169·6465·0a3c··e·install·aide.<
 0003ba30:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di
Max diff block lines reached; 962036/989388 bytes (97.24%) of diff not shown.
96.4 KB
html2text {}
    
Offset 159, 52 lines modifiedOffset 159, 38 lines modified
159 ··-·PCI-DSSv4-11.5.2159 ··-·PCI-DSSv4-11.5.2
160 ··-·enable_strategy160 ··-·enable_strategy
161 ··-·low_complexity161 ··-·low_complexity
162 ··-·low_disruption162 ··-·low_disruption
163 ··-·medium_severity163 ··-·medium_severity
164 ··-·no_reboot_needed164 ··-·no_reboot_needed
165 ··-·package_aide_installed165 ··-·package_aide_installed
166 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
167 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
168 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
169 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
170 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
171 dnf·install·aide 
172 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
173 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
174 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
175 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
176 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
177 package·--add=aide 
178 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8166 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
179 [[packages]]167 [[packages]]
180 name·=·"aide"168 name·=·"aide"
181 version·=·"*"169 version·=·"*"
182 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
183 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
184 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
185 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
186 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
187 package·install·aide 
188 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8170 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
189 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low171 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
190 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low172 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
191 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false173 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
192 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable174 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
193 include·install_aide175 include·install_aide
  
194 class·install_aide·{176 class·install_aide·{
195 ··package·{·'aide':177 ··package·{·'aide':
196 ····ensure·=>·'installed',178 ····ensure·=>·'installed',
197 ··}179 ··}
198 }180 }
 181 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 182 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 183 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 184 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 185 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 186 package·install·aide
199 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8187 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
200 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low188 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
201 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low189 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
202 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false190 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
203 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable191 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
204 #·Remediation·is·applicable·only·in·certain·platforms192 #·Remediation·is·applicable·only·in·certain·platforms
205 if·rpm·--quiet·-q·kernel;·then193 if·rpm·--quiet·-q·kernel;·then
Offset 212, 14 lines modifiedOffset 198, 28 lines modified
212 if·!·rpm·-q·--quiet·"aide"·;·then198 if·!·rpm·-q·--quiet·"aide"·;·then
213 ····dnf·install·-y·"aide"199 ····dnf·install·-y·"aide"
214 fi200 fi
  
215 else201 else
216 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'202 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
217 fi203 fi
 204 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 205 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 206 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 207 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 208 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 209 package·--add=aide
 210 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 211 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 212 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 213 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 214 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 215 dnf·install·aide
218 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*216 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
219 Run·the·following·command·to·generate·a·new·database:217 Run·the·following·command·to·generate·a·new·database:
220 $·sudo·/usr/sbin/aide·--init218 $·sudo·/usr/sbin/aide·--init
221 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the219 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the
222 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these220 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these
223 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their221 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their
224 integrity.·The·newly-generated·database·can·be·installed·as·follows:222 integrity.·The·newly-generated·database·can·be·installed·as·follows:
Offset 402, 57 lines modifiedOffset 402, 57 lines modified
402 References:··_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)402 References:··_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)
403 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4403 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4
404 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227404 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
405 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R28405 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R28
406 ·············_\x8c_\x8i_\x8s············1.1.2.3.1406 ·············_\x8c_\x8i_\x8s············1.1.2.3.1
407 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-09-231010407 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-09-231010
408 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-257843r991589_rule408 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-257843r991589_rule
409 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
410 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
411 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high 
412 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
413 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
414 part·/home 
415 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8409 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
416 [[customizations.filesystem]]410 [[customizations.filesystem]]
417 mountpoint·=·"/home"411 mountpoint·=·"/home"
418 size·=·1073741824412 size·=·1073741824
419 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8413 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
420 logvol·/home·1024414 logvol·/home·1024
 415 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 416 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 417 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high
 418 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 419 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 420 part·/home
421 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/s\x8sr\x8rv\x8v·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*421 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/s\x8sr\x8rv\x8v·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
422 If·a·file·server·(FTP,·TFTP...)·is·hosted·locally,·create·a·separate·partition·for·/srv·at422 If·a·file·server·(FTP,·TFTP...)·is·hosted·locally,·create·a·separate·partition·for·/srv·at
423 installation·time·(or·migrate·it·later·using·LVM).·If·/srv·will·be·mounted·from·another·system·such423 installation·time·(or·migrate·it·later·using·LVM).·If·/srv·will·be·mounted·from·another·system·such
424 as·an·NFS·server,·then·creating·a·separate·partition·is·not·necessary·at·installation·time,·and·the424 as·an·NFS·server,·then·creating·a·separate·partition·is·not·necessary·at·installation·time,·and·the
425 mountpoint·can·instead·be·configured·later.425 mountpoint·can·instead·be·configured·later.
426 ·············Srv·deserves·files·for·local·network·file·server·such·as·FTP.·Ensuring·that·/srv·is426 ·············Srv·deserves·files·for·local·network·file·server·such·as·FTP.·Ensuring·that·/srv·is
427 Rationale:···mounted·on·its·own·partition·enables·the·setting·of·more·restrictive·mount·options,·and427 Rationale:···mounted·on·its·own·partition·enables·the·setting·of·more·restrictive·mount·options,·and
428 ·············also·helps·ensure·that·users·cannot·trivially·fill·partitions·used·for·log·or·audit·data428 ·············also·helps·ensure·that·users·cannot·trivially·fill·partitions·used·for·log·or·audit·data
429 ·············storage.429 ·············storage.
Max diff block lines reached; 93433/98716 bytes (94.65%) of diff not shown.
400 KB
./usr/share/doc/ssg-nondebian/ssg-rhel9-guide-anssi_bp28_minimal.html
    
Offset 14848, 222 lines modifiedOffset 14848, 222 lines modified
00039ff0:·6574·3d22·2369·646d·3132·3834·3022·2074··et="#idm12840"·t00039ff0:·6574·3d22·2369·646d·3132·3834·3022·2074··et="#idm12840"·t
0003a000:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role0003a000:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
0003a010:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e0003a010:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
0003a020:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·0003a020:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
0003a030:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·0003a030:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
0003a040:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=0003a040:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
0003a050:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation0003a050:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
0003a060:·2073·6372·6970·7420·e287·b23c·2f61·3e3c···script·...</a>< 
0003a070:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p 
0003a080:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co 
0003a090:·6c6c·6170·7365·2220·6964·3d22·6964·6d31··llapse"·id="idm1 
0003a0a0:·3238·3430·223e·3c74·6162·6c65·2063·6c61··2840"><table·cla 
0003a0b0:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table- 
0003a0c0:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo 
0003a0d0:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con 
0003a0e0:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th> 
0003a0f0:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th> 
0003a100:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
0003a110:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt0003a060:·204f·5342·7569·6c64·2042·6c75·6570·7269···OSBuild·Bluepri
 0003a070:·6e74·2073·6e69·7070·6574·20e2·87b2·3c2f··nt·snippet·...</
 0003a080:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
 0003a090:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
 0003a0a0:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
 0003a0b0:·646d·3132·3834·3022·3e3c·7072·653e·3c63··dm12840"><pre><c
 0003a0c0:·6f64·653e·0a5b·5b70·6163·6b61·6765·735d··ode>.[[packages]
 0003a0d0:·5d0a·6e61·6d65·203d·2022·646e·662d·6175··].name·=·"dnf-au
 0003a0e0:·746f·6d61·7469·6322·0a76·6572·7369·6f6e··tomatic".version
 0003a0f0:·203d·2022·2a22·0a3c·2f63·6f64·653e·3c2f···=·"*".</code></
 0003a100:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla
 0003a110:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ
 0003a120:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle
 0003a130:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data
 0003a140:·2d74·6172·6765·743d·2223·6964·6d31·3238··-target="#idm128
 0003a150:·3431·2220·7461·6269·6e64·6578·3d22·3022··41"·tabindex="0"
 0003a160:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
 0003a170:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
 0003a180:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
 0003a190:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
 0003a1a0:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
 0003a1b0:·6174·696f·6e20·5075·7070·6574·2073·6e69··ation·Puppet·sni
 0003a1c0:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>
 0003a1d0:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
 0003a1e0:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
 0003a1f0:·7073·6522·2069·643d·2269·646d·3132·3834··pse"·id="idm1284
 0003a200:·3122·3e3c·7461·626c·6520·636c·6173·733d··1"><table·class=
 0003a210:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str
 0003a220:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde
 0003a230:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden
 0003a240:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com
 0003a250:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td
 0003a260:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
 0003a270:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption
 0003a280:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
 0003a290:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e52··d></tr><tr><th>R
0003a120:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low0003a2a0:·6562·6f6f·743a·3c2f·7468·3e3c·7464·3e66··eboot:</th><td>f
0003a130:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t0003a2b0:·616c·7365·3c2f·7464·3e3c·2f74·723e·3c74··alse</td></tr><t
 0003a2c0:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<
 0003a2d0:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</
 0003a2e0:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table>
 0003a2f0:·3c70·7265·3e3c·636f·6465·3e69·6e63·6c75··<pre><code>inclu
0003a140:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t 
0003a150:·643e·6661·6c73·653c·2f74·643e·3c2f·7472··d>false</td></tr 
0003a160:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg 
0003a170:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl 
0003a180:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab 
0003a190:·6c65·3e3c·7072·653e·3c63·6f64·653e·0a64··le><pre><code>.d 
0003a1a0:·6e66·2069·6e73·7461·6c6c·2064·6e66·2d61··nf·install·dnf-a0003a300:·6465·2069·6e73·7461·6c6c·5f64·6e66·2d61··de·install_dnf-a
0003a1b0:·7574·6f6d·6174·6963·0a3c·2f63·6f64·653e··utomatic.</code>0003a310:·7574·6f6d·6174·6963·0a0a·636c·6173·7320··utomatic..class·
 0003a320:·696e·7374·616c·6c5f·646e·662d·6175·746f··install_dnf-auto
 0003a330:·6d61·7469·6320·7b0a·2020·7061·636b·6167··matic·{.··packag
 0003a340:·6520·7b20·2764·6e66·2d61·7574·6f6d·6174··e·{·'dnf-automat
 0003a350:·6963·273a·0a20·2020·2065·6e73·7572·6520··ic':.····ensure·
 0003a360:·3d26·6774·3b20·2769·6e73·7461·6c6c·6564··=&gt;·'installed
 0003a370:·272c·0a20·207d·0a7d·0a3c·2f63·6f64·653e··',.··}.}.</code>
0003a1c0:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c0003a380:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c
0003a1d0:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su0003a390:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su
0003a1e0:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg0003a3a0:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg
0003a1f0:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da0003a3b0:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da
0003a200:·7461·2d74·6172·6765·743d·2223·6964·6d31··ta-target="#idm10003a3c0:·7461·2d74·6172·6765·743d·2223·6964·6d31··ta-target="#idm1
0003a210:·3238·3431·2220·7461·6269·6e64·6578·3d22··2841"·tabindex="0003a3d0:·3238·3432·2220·7461·6269·6e64·6578·3d22··2842"·tabindex="
0003a220:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"0003a3e0:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
0003a230:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="0003a3f0:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
0003a240:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac0003a400:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
0003a250:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal0003a410:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
0003a260:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme0003a420:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
0003a270:·6469·6174·696f·6e20·416e·6163·6f6e·6461··diation·Anaconda 
0003a280:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a> 
0003a290:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class=" 
0003a2a0:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c 
0003a2b0:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm 
0003a2c0:·3132·3834·3122·3e3c·7461·626c·6520·636c··12841"><table·cl 
0003a2d0:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table 
0003a2e0:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b 
0003a2f0:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co 
0003a300:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th 
0003a310:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th0003a430:·6469·6174·696f·6e20·7363·7269·7074·20e2··diation·script·.
 0003a440:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c
 0003a450:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
 0003a460:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
 0003a470:·643d·2269·646d·3132·3834·3222·3e3c·7461··d="idm12842"><ta
 0003a480:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table
 0003a490:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t
 0003a4a0:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta
 0003a4b0:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><
 0003a4c0:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit
 0003a4d0:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</
 0003a4e0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 0003a4f0:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th>
 0003a500:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
 0003a510:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot:
 0003a520:·3c2f·7468·3e3c·7464·3e66·616c·7365·3c2f··</th><td>false</
 0003a530:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 0003a540:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t
 0003a550:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t
 0003a560:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><
 0003a570:·636f·6465·3e0a·7061·636b·6167·6520·696e··code>.package·in
 0003a580:·7374·616c·6c20·646e·662d·6175·746f·6d61··stall·dnf-automa
 0003a590:·7469·630a·3c2f·636f·6465·3e3c·2f70·7265··tic.</code></pre
 0003a5a0:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class=
 0003a5b0:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success
 0003a5c0:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c
 0003a5d0:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta
 0003a5e0:·7267·6574·3d22·2369·646d·3132·3834·3322··rget="#idm12843"
 0003a5f0:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro
 0003a600:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria
 0003a610:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false
 0003a620:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat
Max diff block lines reached; 337084/366368 bytes (92.01%) of diff not shown.
42.3 KB
html2text {}
    
Offset 117, 52 lines modifiedOffset 117, 38 lines modified
117 ··-·CCE-83454-9117 ··-·CCE-83454-9
118 ··-·enable_strategy118 ··-·enable_strategy
119 ··-·low_complexity119 ··-·low_complexity
120 ··-·low_disruption120 ··-·low_disruption
121 ··-·medium_severity121 ··-·medium_severity
122 ··-·no_reboot_needed122 ··-·no_reboot_needed
123 ··-·package_dnf-automatic_installed123 ··-·package_dnf-automatic_installed
124 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
125 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
126 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
127 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
128 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
129 dnf·install·dnf-automatic 
130 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
131 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
132 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
133 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
134 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
135 package·--add=dnf-automatic 
136 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8124 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
137 [[packages]]125 [[packages]]
138 name·=·"dnf-automatic"126 name·=·"dnf-automatic"
139 version·=·"*"127 version·=·"*"
140 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
141 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
142 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
143 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
144 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
145 package·install·dnf-automatic 
146 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8128 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
147 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low129 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
148 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low130 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
149 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false131 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
150 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable132 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
151 include·install_dnf-automatic133 include·install_dnf-automatic
  
152 class·install_dnf-automatic·{134 class·install_dnf-automatic·{
153 ··package·{·'dnf-automatic':135 ··package·{·'dnf-automatic':
154 ····ensure·=>·'installed',136 ····ensure·=>·'installed',
155 ··}137 ··}
156 }138 }
 139 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 140 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 141 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 142 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 143 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 144 package·install·dnf-automatic
157 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8145 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
158 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low146 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
159 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low147 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
160 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false148 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
161 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable149 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
162 #·Remediation·is·applicable·only·in·certain·platforms150 #·Remediation·is·applicable·only·in·certain·platforms
163 if·!·(·{·rpm·--quiet·-q·kernel·;}·&&·{·rpm·--quiet·-q·rpm-ostree·;}·&&·{·rpm·--quiet·-q·bootc151 if·!·(·{·rpm·--quiet·-q·kernel·;}·&&·{·rpm·--quiet·-q·rpm-ostree·;}·&&·{·rpm·--quiet·-q·bootc
Offset 171, 14 lines modifiedOffset 157, 28 lines modified
171 if·!·rpm·-q·--quiet·"dnf-automatic"·;·then157 if·!·rpm·-q·--quiet·"dnf-automatic"·;·then
172 ····dnf·install·-y·"dnf-automatic"158 ····dnf·install·-y·"dnf-automatic"
173 fi159 fi
  
174 else160 else
175 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'161 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
176 fi162 fi
 163 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 164 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 165 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 166 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 167 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 168 package·--add=dnf-automatic
 169 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 170 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 171 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 172 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 173 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 174 dnf·install·dnf-automatic
177 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·d\x8dn\x8nf\x8f-\x8-a\x8au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8c·t\x8to\x8o·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·A\x8Av\x8va\x8ai\x8il\x8la\x8ab\x8bl\x8le\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8es\x8s·A\x8Au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8ca\x8al\x8ll\x8ly\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*175 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·d\x8dn\x8nf\x8f-\x8-a\x8au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8c·t\x8to\x8o·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·A\x8Av\x8va\x8ai\x8il\x8la\x8ab\x8bl\x8le\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8es\x8s·A\x8Au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8ca\x8al\x8ll\x8ly\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
178 To·ensure·that·the·packages·comprising·the·available·updates·will·be·automatically·installed176 To·ensure·that·the·packages·comprising·the·available·updates·will·be·automatically·installed
179 by·dnf-automatic,·set·apply_updates·to·yes·under·[commands]·section·in·/etc/dnf/177 by·dnf-automatic,·set·apply_updates·to·yes·under·[commands]·section·in·/etc/dnf/
180 automatic.conf.178 automatic.conf.
181 ·············Installing·software·updates·is·a·fundamental·mitigation·against·the·exploitation179 ·············Installing·software·updates·is·a·fundamental·mitigation·against·the·exploitation
182 ·············of·publicly-known·vulnerabilities.·If·the·most·recent·security·patches·and180 ·············of·publicly-known·vulnerabilities.·If·the·most·recent·security·patches·and
183 Rationale:···updates·are·not·installed,·unauthorized·users·may·take·advantage·of·weaknesses·in181 Rationale:···updates·are·not·installed,·unauthorized·users·may·take·advantage·of·weaknesses·in
Offset 10375, 47 lines modifiedOffset 10375, 33 lines modified
10375 ··-·PCI-DSSv4-2.2.410375 ··-·PCI-DSSv4-2.2.4
10376 ··-·disable_strategy10376 ··-·disable_strategy
10377 ··-·low_complexity10377 ··-·low_complexity
10378 ··-·low_disruption10378 ··-·low_disruption
10379 ··-·medium_severity10379 ··-·medium_severity
10380 ··-·no_reboot_needed10380 ··-·no_reboot_needed
10381 ··-·package_dhcp_removed10381 ··-·package_dhcp_removed
10382 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
10383 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
10384 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
10385 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
10386 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable 
  
10387 dnf·remove·dhcp-server 
10388 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
10389 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
10390 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
10391 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
10392 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable 
  
10393 package·--remove=dhcp-server 
10394 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
10395 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
10396 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
10397 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
10398 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable 
  
10399 package·remove·dhcp-server 
10400 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x810382 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
10401 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low10383 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
10402 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low10384 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
10403 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false10385 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
10404 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable10386 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
10405 include·remove_dhcp-server10387 include·remove_dhcp-server
  
10406 class·remove_dhcp-server·{10388 class·remove_dhcp-server·{
10407 ··package·{·'dhcp-server':10389 ··package·{·'dhcp-server':
10408 ····ensure·=>·'purged',10390 ····ensure·=>·'purged',
Max diff block lines reached; 38502/43310 bytes (88.90%) of diff not shown.
434 KB
./usr/share/doc/ssg-nondebian/ssg-rhel9-guide-ccn_advanced.html
    
Offset 22726, 202 lines modifiedOffset 22726, 202 lines modified
00058c50:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="00058c50:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
00058c60:·2369·646d·3132·3439·3822·2074·6162·696e··#idm12498"·tabin00058c60:·2369·646d·3132·3439·3822·2074·6162·696e··#idm12498"·tabin
00058c70:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu00058c70:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
00058c80:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan00058c80:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
00058c90:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl00058c90:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
00058ca0:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r00058ca0:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
00058cb0:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"00058cb0:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
00058cc0:·3e52·656d·6564·6961·7469·6f6e·2073·6372··>Remediation·scr00058cc0:·3e52·656d·6564·6961·7469·6f6e·204f·5342··>Remediation·OSB
00058cd0:·6970·7420·e287·b23c·2f61·3e3c·6272·3e3c··ipt·...</a><br><00058cd0:·7569·6c64·2042·6c75·6570·7269·6e74·2073··uild·Blueprint·s
 00058ce0:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b
 00058cf0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
 00058d00:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
 00058d10:·6c61·7073·6522·2069·643d·2269·646d·3132··lapse"·id="idm12
 00058d20:·3439·3822·3e3c·7072·653e·3c63·6f64·653e··498"><pre><code>
 00058d30:·0a5b·5b70·6163·6b61·6765·735d·5d0a·6e61··.[[packages]].na
 00058d40:·6d65·203d·2022·6372·7970·7473·6574·7570··me·=·"cryptsetup
 00058d50:·220a·7665·7273·696f·6e20·3d20·222a·220a··".version·=·"*".
 00058d60:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d
 00058d70:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn
 00058d80:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da
 00058d90:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla
 00058da0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
 00058db0:·3d22·2369·646d·3132·3439·3922·2074·6162··="#idm12499"·tab
 00058dc0:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
 00058dd0:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
 00058de0:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
 00058df0:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
 00058e00:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
 00058e10:·2122·3e52·656d·6564·6961·7469·6f6e·2050··!">Remediation·P
 00058e20:·7570·7065·7420·736e·6970·7065·7420·e287··uppet·snippet·..
 00058e30:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl
 00058e40:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla
 00058e50:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id
 00058e60:·3d22·6964·6d31·3234·3939·223e·3c74·6162··="idm12499"><tab
 00058e70:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·
 00058e80:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta
 00058e90:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab
 00058ea0:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t
 00058eb0:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity
 00058ec0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
 00058ed0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D
 00058ee0:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><
 00058ef0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
 00058f00:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:<
 00058f10:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t
 00058f20:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S
 00058f30:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td
 00058f40:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr
 00058f50:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c
 00058f60:·6f64·653e·696e·636c·7564·6520·696e·7374··ode>include·inst
 00058f70:·616c·6c5f·6372·7970·7473·6574·7570·0a0a··all_cryptsetup..
 00058f80:·636c·6173·7320·696e·7374·616c·6c5f·6372··class·install_cr
 00058f90:·7970·7473·6574·7570·207b·0a20·2070·6163··yptsetup·{.··pac
 00058fa0:·6b61·6765·207b·2027·6372·7970·7473·6574··kage·{·'cryptset
 00058fb0:·7570·273a·0a20·2020·2065·6e73·7572·6520··up':.····ensure·
 00058fc0:·3d26·6774·3b20·2769·6e73·7461·6c6c·6564··=&gt;·'installed
 00058fd0:·272c·0a20·207d·0a7d·0a3c·2f63·6f64·653e··',.··}.}.</code>
 00058fe0:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c
 00058ff0:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su
 00059000:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg
 00059010:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da
 00059020:·7461·2d74·6172·6765·743d·2223·6964·6d31··ta-target="#idm1
 00059030:·3235·3030·2220·7461·6269·6e64·6578·3d22··2500"·tabindex="
 00059040:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
 00059050:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
 00059060:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
 00059070:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
 00059080:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
 00059090:·6469·6174·696f·6e20·7363·7269·7074·20e2··diation·script·.
 000590a0:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c
 000590b0:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
 000590c0:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
 000590d0:·643d·2269·646d·3132·3530·3022·3e3c·7461··d="idm12500"><ta
00058ce0:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel000590e0:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table
00058cf0:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap 
00058d00:·7365·2220·6964·3d22·6964·6d31·3234·3938··se"·id="idm12498 
00058d10:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class=" 
00058d20:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri 
00058d30:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border 
00058d40:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens 
00058d50:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp 
00058d60:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td> 
00058d70:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr 
00058d80:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:000590f0:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t
 00059100:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta
 00059110:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><
 00059120:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit
 00059130:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</
 00059140:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 00059150:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th>
 00059160:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
 00059170:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot:
 00059180:·3c2f·7468·3e3c·7464·3e66·616c·7365·3c2f··</th><td>false</
 00059190:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 000591a0:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t
 000591b0:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t
 000591c0:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><
 000591d0:·636f·6465·3e0a·7061·636b·6167·6520·696e··code>.package·in
 000591e0:·7374·616c·6c20·6372·7970·7473·6574·7570··stall·cryptsetup
 000591f0:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></
 00059200:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt
 00059210:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d
 00059220:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll
 00059230:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
 00059240:·743d·2223·6964·6d31·3235·3031·2220·7461··t="#idm12501"·ta
 00059250:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
 00059260:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
 00059270:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
 00059280:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
 00059290:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
 000592a0:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
 000592b0:·5368·656c·6c20·7363·7269·7074·20e2·87b2··Shell·script·...
 000592c0:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
 000592d0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
 000592e0:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
 000592f0:·2269·646d·3132·3530·3122·3e3c·7461·626c··"idm12501"><tabl
 00059300:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t
 00059310:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab
 00059320:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl
 00059330:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr
 00059340:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:
00058d90:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td00059350:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
00058da0:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re00059360:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di
 00059370:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t
00058db0:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa 
00058dc0:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr 
00058dd0:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</ 
Max diff block lines reached; 364876/391400 bytes (93.22%) of diff not shown.
51.2 KB
html2text {}
    
Offset 1828, 61 lines modifiedOffset 1828, 61 lines modified
1828 ··-·PCI-DSSv4-3.5.1.21828 ··-·PCI-DSSv4-3.5.1.2
1829 ··-·enable_strategy1829 ··-·enable_strategy
1830 ··-·low_complexity1830 ··-·low_complexity
1831 ··-·low_disruption1831 ··-·low_disruption
1832 ··-·medium_severity1832 ··-·medium_severity
1833 ··-·no_reboot_needed1833 ··-·no_reboot_needed
1834 ··-·package_cryptsetup-luks_installed1834 ··-·package_cryptsetup-luks_installed
1835 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
1836 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
1837 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
1838 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
1839 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
1840 dnf·install·cryptsetup 
1841 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
1842 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
1843 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
1844 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
1845 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
1846 package·--add=cryptsetup 
1847 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81835 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
1848 [[packages]]1836 [[packages]]
1849 name·=·"cryptsetup"1837 name·=·"cryptsetup"
1850 version·=·"*"1838 version·=·"*"
1851 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
1852 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
1853 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
1854 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
1855 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
1856 package·install·cryptsetup 
1857 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81839 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1858 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1840 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1859 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1841 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1860 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1842 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1861 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1843 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1862 include·install_cryptsetup1844 include·install_cryptsetup
  
1863 class·install_cryptsetup·{1845 class·install_cryptsetup·{
1864 ··package·{·'cryptsetup':1846 ··package·{·'cryptsetup':
1865 ····ensure·=>·'installed',1847 ····ensure·=>·'installed',
1866 ··}1848 ··}
1867 }1849 }
 1850 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 1851 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1852 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1853 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1854 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 1855 package·install·cryptsetup
1868 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81856 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1869 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1857 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1870 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1858 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1871 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1859 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1872 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1860 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
1873 if·!·rpm·-q·--quiet·"cryptsetup"·;·then1861 if·!·rpm·-q·--quiet·"cryptsetup"·;·then
1874 ····dnf·install·-y·"cryptsetup"1862 ····dnf·install·-y·"cryptsetup"
1875 fi1863 fi
 1864 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 1865 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1866 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1867 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1868 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 1869 package·--add=cryptsetup
 1870 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 1871 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1872 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1873 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1874 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 1875 dnf·install·cryptsetup
1876 Group  ·Account·and·Access·Control·  Group·contains·13·groups·and·29·rules1876 Group  ·Account·and·Access·Control·  Group·contains·13·groups·and·29·rules
1877 _\x8[_\x8r_\x8e_\x8f_\x8]  ·In·traditional·Unix·security,·if·an·attacker·gains·shell·access·to·a·certain·login·account,·they·can·perform·any·action·or·access·any·file·to·which·that·account·has·access.·Therefore,·making·it·more·difficult·for·unauthorized·people·to·gain·shell·access·to·accounts,·particularly·to·privileged·accounts,·is·a·necessary·part·of·securing·a·system.·This·section·introduces·mechanisms·for·restricting·access·to·accounts·under·Red·Hat·Enterprise·Linux·9.1877 _\x8[_\x8r_\x8e_\x8f_\x8]  ·In·traditional·Unix·security,·if·an·attacker·gains·shell·access·to·a·certain·login·account,·they·can·perform·any·action·or·access·any·file·to·which·that·account·has·access.·Therefore,·making·it·more·difficult·for·unauthorized·people·to·gain·shell·access·to·accounts,·particularly·to·privileged·accounts,·is·a·necessary·part·of·securing·a·system.·This·section·introduces·mechanisms·for·restricting·access·to·accounts·under·Red·Hat·Enterprise·Linux·9.
1878 Group  ·Warning·Banners·for·System·Accesses·  Group·contains·1·group·and·5·rules1878 Group  ·Warning·Banners·for·System·Accesses·  Group·contains·1·group·and·5·rules
1879 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Each·system·should·expose·as·little·information·about·itself·as·possible.1879 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Each·system·should·expose·as·little·information·about·itself·as·possible.
  
1880 System·banners,·which·are·typically·displayed·just·before·a·login·prompt,·give·out·information·about·the·service·or·the·host's·operating·system.·This·might·include·the·distribution·name·and·the·system·kernel·version,·and·the·particular·version·of·a·network·service.·This·information·can·assist·intruders·in·gaining·access·to·the·system·as·it·can·reveal·whether·the·system·is·running·vulnerable·software.·Most·network·services·can·be·configured·to·limit·what·information·is·displayed.1880 System·banners,·which·are·typically·displayed·just·before·a·login·prompt,·give·out·information·about·the·service·or·the·host's·operating·system.·This·might·include·the·distribution·name·and·the·system·kernel·version,·and·the·particular·version·of·a·network·service.·This·information·can·assist·intruders·in·gaining·access·to·the·system·as·it·can·reveal·whether·the·system·is·running·vulnerable·software.·Most·network·services·can·be·configured·to·limit·what·information·is·displayed.
  
Offset 9335, 52 lines modifiedOffset 9335, 38 lines modified
9335 ··-·PCI-DSSv4-1.2.19335 ··-·PCI-DSSv4-1.2.1
9336 ··-·enable_strategy9336 ··-·enable_strategy
9337 ··-·low_complexity9337 ··-·low_complexity
9338 ··-·low_disruption9338 ··-·low_disruption
9339 ··-·medium_severity9339 ··-·medium_severity
9340 ··-·no_reboot_needed9340 ··-·no_reboot_needed
9341 ··-·package_firewalld_installed9341 ··-·package_firewalld_installed
9342 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
9343 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
9344 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
9345 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
9346 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
9347 dnf·install·firewalld 
9348 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
9349 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
9350 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
9351 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
9352 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
9353 package·--add=firewalld 
9354 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x89342 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
9355 [[packages]]9343 [[packages]]
9356 name·=·"firewalld"9344 name·=·"firewalld"
9357 version·=·"*"9345 version·=·"*"
9358 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
9359 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
9360 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
9361 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
9362 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
9363 package·install·firewalld 
9364 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x89346 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
9365 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low9347 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
9366 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low9348 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
9367 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false9349 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
9368 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable9350 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
9369 include·install_firewalld9351 include·install_firewalld
  
9370 class·install_firewalld·{9352 class·install_firewalld·{
9371 ··package·{·'firewalld':9353 ··package·{·'firewalld':
9372 ····ensure·=>·'installed',9354 ····ensure·=>·'installed',
9373 ··}9355 ··}
Max diff block lines reached; 47252/52430 bytes (90.12%) of diff not shown.
113 KB
./usr/share/doc/ssg-nondebian/ssg-rhel9-guide-ccn_basic.html
    
Offset 38157, 211 lines modifiedOffset 38157, 211 lines modified
000950c0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=000950c0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
000950d0:·2223·6964·6d32·3536·3232·2220·7461·6269··"#idm25622"·tabi000950d0:·2223·6964·6d32·3536·3232·2220·7461·6269··"#idm25622"·tabi
000950e0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b000950e0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
000950f0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa000950f0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
00095100:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit00095100:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
00095110:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·00095110:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
00095120:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!00095120:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
00095130:·223e·5265·6d65·6469·6174·696f·6e20·7363··">Remediation·sc00095130:·223e·5265·6d65·6469·6174·696f·6e20·4f53··">Remediation·OS
00095140:·7269·7074·20e2·87b2·3c2f·613e·3c62·723e··ript·...</a><br> 
00095150:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane 
00095160:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla 
00095170:·7073·6522·2069·643d·2269·646d·3235·3632··pse"·id="idm2562 
00095180:·3222·3e3c·7461·626c·6520·636c·6173·733d··2"><table·class= 
00095190:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str 
000951a0:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde 
000951b0:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden 
000951c0:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com 
000951d0:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td 
000951e0:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t 
000951f0:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption 
00095200:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t 
00095210:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e52··d></tr><tr><th>R 
00095220:·6562·6f6f·743a·3c2f·7468·3e3c·7464·3e66··eboot:</th><td>f 
00095230:·616c·7365·3c2f·7464·3e3c·2f74·723e·3c74··alse</td></tr><t 
00095240:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:< 
00095250:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</ 
00095260:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table> 
00095270:·3c70·7265·3e3c·636f·6465·3e0a·646e·6620··<pre><code>.dnf· 
00095280:·696e·7374·616c·6c20·6669·7265·7761·6c6c··install·firewall 
00095290:·640a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··d.</code></pre>< 
000952a0:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b 
000952b0:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"· 
000952c0:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col 
000952d0:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ 
000952e0:·6574·3d22·2369·646d·3235·3632·3322·2074··et="#idm25623"·t 
000952f0:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role 
00095300:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e 
00095310:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"· 
00095320:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate· 
00095330:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href= 
00095340:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation 
00095350:·2041·6e61·636f·6e64·6120·736e·6970·7065···Anaconda·snippe 
00095360:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di 
00095370:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c 
00095380:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse 
00095390:·2220·6964·3d22·6964·6d32·3536·3233·223e··"·id="idm25623"> 
000953a0:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta 
000953b0:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe 
000953c0:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered 
000953d0:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed 
000953e0:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple 
000953f0:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo 
00095400:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr>< 
00095410:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</ 
00095420:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td>< 
00095430:·2f74·723e·3c74·723e·3c74·683e·5265·626f··/tr><tr><th>Rebo 
00095440:·6f74·3a3c·2f74·683e·3c74·643e·6661·6c73··ot:</th><td>fals 
00095450:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr>< 
00095460:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th 
00095470:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td> 
00095480:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr 
00095490:·653e·3c63·6f64·653e·0a70·6163·6b61·6765··e><code>.package 
000954a0:·202d·2d61·6464·3d66·6972·6577·616c·6c64···--add=firewalld 
000954b0:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></ 
000954c0:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt 
000954d0:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d 
000954e0:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll 
000954f0:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe 
00095500:·743d·2223·6964·6d32·3536·3234·2220·7461··t="#idm25624"·ta 
00095510:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role= 
00095520:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex 
00095530:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t 
00095540:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t 
00095550:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href=" 
00095560:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation· 
00095570:·4f53·4275·696c·6420·426c·7565·7072·696e··OSBuild·Blueprin00095140:·4275·696c·6420·426c·7565·7072·696e·7420··Build·Blueprint·
00095580:·7420·736e·6970·7065·7420·e287·b23c·2f61··t·snippet·...</a00095150:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><
00095590:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class= 
000955a0:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse· 
000955b0:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id 
000955c0:·6d32·3536·3234·223e·3c70·7265·3e3c·636f··m25624"><pre><co 
000955d0:·6465·3e0a·5b5b·7061·636b·6167·6573·5d5d··de>.[[packages]] 
000955e0:·0a6e·616d·6520·3d20·2266·6972·6577·616c··.name·=·"firewal 
000955f0:·6c64·220a·7665·7273·696f·6e20·3d20·222a··ld".version·=·"* 
00095600:·220a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··".</code></pre>< 
00095610:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b 
00095620:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"· 
00095630:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col 
00095640:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ 
00095650:·6574·3d22·2369·646d·3235·3632·3522·2074··et="#idm25625"·t 
00095660:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role 
00095670:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e 
00095680:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"· 
00095690:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate· 
000956a0:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href= 
000956b0:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation 
000956c0:·2073·6372·6970·7420·e287·b23c·2f61·3e3c···script·...</a>< 
000956d0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p00095160:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
000956e0:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co00095170:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
000956f0:·6c6c·6170·7365·2220·6964·3d22·6964·6d32··llapse"·id="idm200095180:·6c6c·6170·7365·2220·6964·3d22·6964·6d32··llapse"·id="idm2
 00095190:·3536·3232·223e·3c70·7265·3e3c·636f·6465··5622"><pre><code
 000951a0:·3e0a·5b5b·7061·636b·6167·6573·5d5d·0a6e··>.[[packages]].n
 000951b0:·616d·6520·3d20·2266·6972·6577·616c·6c64··ame·=·"firewalld
 000951c0:·220a·7665·7273·696f·6e20·3d20·222a·220a··".version·=·"*".
 000951d0:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d
 000951e0:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn
 000951f0:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da
 00095200:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla
 00095210:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
 00095220:·3d22·2369·646d·3235·3632·3322·2074·6162··="#idm25623"·tab
 00095230:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
 00095240:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
 00095250:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
 00095260:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
 00095270:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
 00095280:·2122·3e52·656d·6564·6961·7469·6f6e·2050··!">Remediation·P
 00095290:·7570·7065·7420·736e·6970·7065·7420·e287··uppet·snippet·..
 000952a0:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl
 000952b0:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla
00095700:·3536·3235·223e·3c74·6162·6c65·2063·6c61··5625"><table·cla 
00095710:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table- 
00095720:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo 
00095730:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con 
00095740:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th> 
00095750:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th> 
00095760:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
00095770:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt 
Max diff block lines reached; 74630/102396 bytes (72.88%) of diff not shown.
13.0 KB
html2text {}
    
Offset 5472, 52 lines modifiedOffset 5472, 38 lines modified
5472 ··-·PCI-DSSv4-1.2.15472 ··-·PCI-DSSv4-1.2.1
5473 ··-·enable_strategy5473 ··-·enable_strategy
5474 ··-·low_complexity5474 ··-·low_complexity
5475 ··-·low_disruption5475 ··-·low_disruption
5476 ··-·medium_severity5476 ··-·medium_severity
5477 ··-·no_reboot_needed5477 ··-·no_reboot_needed
5478 ··-·package_firewalld_installed5478 ··-·package_firewalld_installed
5479 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
5480 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
5481 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
5482 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
5483 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
5484 dnf·install·firewalld 
5485 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
5486 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
5487 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
5488 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
5489 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
5490 package·--add=firewalld 
5491 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x85479 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
5492 [[packages]]5480 [[packages]]
5493 name·=·"firewalld"5481 name·=·"firewalld"
5494 version·=·"*"5482 version·=·"*"
5495 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
5496 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
5497 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
5498 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
5499 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
5500 package·install·firewalld 
5501 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x85483 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
5502 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low5484 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
5503 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low5485 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
5504 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false5486 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
5505 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable5487 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
5506 include·install_firewalld5488 include·install_firewalld
  
5507 class·install_firewalld·{5489 class·install_firewalld·{
5508 ··package·{·'firewalld':5490 ··package·{·'firewalld':
5509 ····ensure·=>·'installed',5491 ····ensure·=>·'installed',
5510 ··}5492 ··}
5511 }5493 }
 5494 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 5495 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 5496 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 5497 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 5498 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 5499 package·install·firewalld
5512 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x85500 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
5513 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low5501 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
5514 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low5502 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
5515 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false5503 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
5516 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable5504 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
5517 #·Remediation·is·applicable·only·in·certain·platforms5505 #·Remediation·is·applicable·only·in·certain·platforms
5518 if·rpm·--quiet·-q·kernel;·then5506 if·rpm·--quiet·-q·kernel;·then
Offset 5525, 14 lines modifiedOffset 5511, 28 lines modified
5525 if·!·rpm·-q·--quiet·"firewalld"·;·then5511 if·!·rpm·-q·--quiet·"firewalld"·;·then
5526 ····dnf·install·-y·"firewalld"5512 ····dnf·install·-y·"firewalld"
5527 fi5513 fi
  
5528 else5514 else
5529 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'5515 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
5530 fi5516 fi
 5517 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 5518 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 5519 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 5520 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 5521 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 5522 package·--add=firewalld
 5523 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 5524 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 5525 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 5526 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 5527 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 5528 dnf·install·firewalld
5531 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·f\x8fi\x8ir\x8re\x8ew\x8wa\x8al\x8ll\x8ld\x8d·E\x8En\x8na\x8ab\x8bl\x8le\x8ed\x8d·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*5529 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·f\x8fi\x8ir\x8re\x8ew\x8wa\x8al\x8ll\x8ld\x8d·E\x8En\x8na\x8ab\x8bl\x8le\x8ed\x8d·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
5532 The·firewalld·service·can·be·enabled·with·the·following·command:5530 The·firewalld·service·can·be·enabled·with·the·following·command:
5533 $·sudo·systemctl·enable·firewalld.service5531 $·sudo·systemctl·enable·firewalld.service
5534 Rationale:···Access·control·methods·provide·the·ability·to·enhance·system·security·posture·by·restricting·services·and·known·good·IP·addresses·and·address·ranges.·This·prevents·connections·from·unknown·hosts·and·protocols.5532 Rationale:···Access·control·methods·provide·the·ability·to·enhance·system·security·posture·by·restricting·services·and·known·good·IP·addresses·and·address·ranges.·This·prevents·connections·from·unknown·hosts·and·protocols.
5535 Severity: ···medium5533 Severity: ···medium
5536 Rule·ID:·····xccdf_org.ssgproject.content_rule_service_firewalld_enabled5534 Rule·ID:·····xccdf_org.ssgproject.content_rule_service_firewalld_enabled
5537 Identifiers:·CCE-90833-55535 Identifiers:·CCE-90833-5
Offset 5617, 34 lines modifiedOffset 5617, 34 lines modified
5617 ··-·medium_severity5617 ··-·medium_severity
5618 ··-·no_reboot_needed5618 ··-·no_reboot_needed
5619 ··-·service_firewalld_enabled5619 ··-·service_firewalld_enabled
5620 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x85620 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
5621 [customizations.services]5621 [customizations.services]
5622 enabled·=·["firewalld"]5622 enabled·=·["firewalld"]
5623 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
5624 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
5625 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
5626 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
5627 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable 
  
5628 service·enable·firewalld 
5629 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x85623 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
5630 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low5624 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
5631 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low5625 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
5632 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false5626 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
5633 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable5627 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
5634 include·enable_firewalld5628 include·enable_firewalld
  
5635 class·enable_firewalld·{5629 class·enable_firewalld·{
5636 ··service·{'firewalld':5630 ··service·{'firewalld':
5637 ····enable·=>·true,5631 ····enable·=>·true,
5638 ····ensure·=>·'running',5632 ····ensure·=>·'running',
5639 ··}5633 ··}
5640 }5634 }
 5635 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 5636 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 5637 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 5638 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 5639 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
  
 5640 service·enable·firewalld
5641 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x85641 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
5642 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low5642 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
5643 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low5643 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
5644 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false5644 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
Max diff block lines reached; 8667/13296 bytes (65.19%) of diff not shown.
404 KB
./usr/share/doc/ssg-nondebian/ssg-rhel9-guide-ccn_intermediate.html
    
Offset 44709, 211 lines modifiedOffset 44709, 211 lines modified
000aea40:·6765·743d·2223·6964·6d32·3536·3232·2220··get="#idm25622"·000aea40:·6765·743d·2223·6964·6d32·3536·3232·2220··get="#idm25622"·
000aea50:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol000aea50:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol
000aea60:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-000aea60:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-
000aea70:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"000aea70:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"
000aea80:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate000aea80:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate
000aea90:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href000aea90:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href
000aeaa0:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio000aeaa0:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio
000aeab0:·6e20·7363·7269·7074·20e2·87b2·3c2f·613e··n·script·...</a> 
000aeac0:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class=" 
000aead0:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c 
000aeae0:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm 
000aeaf0:·3235·3632·3222·3e3c·7461·626c·6520·636c··25622"><table·cl 
000aeb00:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table 
000aeb10:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b 
000aeb20:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co 
000aeb30:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th 
000aeb40:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th 
000aeb50:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t 
000aeb60:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup000aeab0:·6e20·4f53·4275·696c·6420·426c·7565·7072··n·OSBuild·Bluepr
 000aeac0:·696e·7420·736e·6970·7065·7420·e287·b23c··int·snippet·...<
 000aead0:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas
 000aeae0:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps
 000aeaf0:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="
 000aeb00:·6964·6d32·3536·3232·223e·3c70·7265·3e3c··idm25622"><pre><
 000aeb10:·636f·6465·3e0a·5b5b·7061·636b·6167·6573··code>.[[packages
 000aeb20:·5d5d·0a6e·616d·6520·3d20·2266·6972·6577··]].name·=·"firew
 000aeb30:·616c·6c64·220a·7665·7273·696f·6e20·3d20··alld".version·=·
 000aeb40:·222a·220a·3c2f·636f·6465·3e3c·2f70·7265··"*".</code></pre
 000aeb50:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class=
 000aeb60:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success
 000aeb70:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c
 000aeb80:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta
 000aeb90:·7267·6574·3d22·2369·646d·3235·3632·3322··rget="#idm25623"
 000aeba0:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro
 000aebb0:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria
 000aebc0:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false
 000aebd0:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat
 000aebe0:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre
 000aebf0:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati
 000aec00:·6f6e·2050·7570·7065·7420·736e·6970·7065··on·Puppet·snippe
 000aec10:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di
 000aec20:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c
 000aec30:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse
 000aec40:·2220·6964·3d22·6964·6d32·3536·3233·223e··"·id="idm25623">
 000aec50:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta
 000aec60:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe
 000aec70:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered
 000aec80:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed
 000aec90:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple
000aeb70:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo000aeca0:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo
000aeb80:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><000aecb0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
000aeb90:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th>< 
000aeba0:·7464·3e66·616c·7365·3c2f·7464·3e3c·2f74··td>false</td></t 
000aebb0:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate000aecc0:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</
 000aecd0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
 000aece0:·2f74·723e·3c74·723e·3c74·683e·5265·626f··/tr><tr><th>Rebo
000aebc0:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab000aecf0:·6f74·3a3c·2f74·683e·3c74·643e·6661·6c73··ot:</th><td>fals
 000aed00:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr><
 000aed10:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th
 000aed20:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td>
 000aed30:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr
 000aed40:·653e·3c63·6f64·653e·696e·636c·7564·6520··e><code>include·
 000aed50:·696e·7374·616c·6c5f·6669·7265·7761·6c6c··install_firewall
 000aed60:·640a·0a63·6c61·7373·2069·6e73·7461·6c6c··d..class·install
 000aed70:·5f66·6972·6577·616c·6c64·207b·0a20·2070··_firewalld·{.··p
 000aed80:·6163·6b61·6765·207b·2027·6669·7265·7761··ackage·{·'firewa
 000aed90:·6c6c·6427·3a0a·2020·2020·656e·7375·7265··lld':.····ensure
 000aeda0:·203d·2667·743b·2027·696e·7374·616c·6c65···=&gt;·'installe
 000aedb0:·6427·2c0a·2020·7d0a·7d0a·3c2f·636f·6465··d',.··}.}.</code
 000aedc0:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a·
 000aedd0:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s
 000aede0:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog
 000aedf0:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d
 000aee00:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
 000aee10:·3235·3632·3422·2074·6162·696e·6465·783d··25624"·tabindex=
 000aee20:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button
 000aee30:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=
 000aee40:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A
 000aee50:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea
 000aee60:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem
 000aee70:·6564·6961·7469·6f6e·2073·6372·6970·7420··ediation·script·
 000aee80:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·
 000aee90:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col
 000aeea0:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·
 000aeeb0:·6964·3d22·6964·6d32·3536·3234·223e·3c74··id="idm25624"><t
 000aeec0:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl
 000aeed0:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·
 000aeee0:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t
 000aeef0:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">
 000aef00:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi
 000aef10:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<
 000aef20:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 000aef30:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th
 000aef40:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
 000aef50:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot
 000aef60:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false<
 000aef70:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 000aef80:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><
 000aef90:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></
 000aefa0:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>
 000aefb0:·3c63·6f64·653e·0a70·6163·6b61·6765·2069··<code>.package·i
 000aefc0:·6e73·7461·6c6c·2066·6972·6577·616c·6c64··nstall·firewalld
 000aefd0:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></
 000aefe0:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt
 000aeff0:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d
 000af000:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll
 000af010:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
 000af020:·743d·2223·6964·6d32·3536·3235·2220·7461··t="#idm25625"·ta
 000af030:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
 000af040:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
 000af050:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
 000af060:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
 000af070:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
 000af080:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
 000af090:·5368·656c·6c20·7363·7269·7074·20e2·87b2··Shell·script·...
 000af0a0:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
 000af0b0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
 000af0c0:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
 000af0d0:·2269·646d·3235·3632·3522·3e3c·7461·626c··"idm25625"><tabl
 000af0e0:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t
 000af0f0:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab
 000af100:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl
 000af110:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr
 000af120:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:
 000af130:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
 000af140:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di
 000af150:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t
Max diff block lines reached; 336696/364462 bytes (92.38%) of diff not shown.
47.6 KB
html2text {}
    
Offset 6934, 52 lines modifiedOffset 6934, 38 lines modified
6934 ··-·PCI-DSSv4-1.2.16934 ··-·PCI-DSSv4-1.2.1
6935 ··-·enable_strategy6935 ··-·enable_strategy
6936 ··-·low_complexity6936 ··-·low_complexity
6937 ··-·low_disruption6937 ··-·low_disruption
6938 ··-·medium_severity6938 ··-·medium_severity
6939 ··-·no_reboot_needed6939 ··-·no_reboot_needed
6940 ··-·package_firewalld_installed6940 ··-·package_firewalld_installed
6941 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
6942 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
6943 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
6944 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
6945 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
6946 dnf·install·firewalld 
6947 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
6948 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
6949 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
6950 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
6951 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
6952 package·--add=firewalld 
6953 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x86941 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
6954 [[packages]]6942 [[packages]]
6955 name·=·"firewalld"6943 name·=·"firewalld"
6956 version·=·"*"6944 version·=·"*"
6957 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
6958 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
6959 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
6960 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
6961 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
6962 package·install·firewalld 
6963 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x86945 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
6964 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low6946 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
6965 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low6947 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
6966 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false6948 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
6967 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable6949 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
6968 include·install_firewalld6950 include·install_firewalld
  
6969 class·install_firewalld·{6951 class·install_firewalld·{
6970 ··package·{·'firewalld':6952 ··package·{·'firewalld':
6971 ····ensure·=>·'installed',6953 ····ensure·=>·'installed',
6972 ··}6954 ··}
6973 }6955 }
 6956 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 6957 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 6958 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 6959 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 6960 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 6961 package·install·firewalld
6974 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x86962 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
6975 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low6963 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
6976 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low6964 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
6977 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false6965 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
6978 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable6966 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
6979 #·Remediation·is·applicable·only·in·certain·platforms6967 #·Remediation·is·applicable·only·in·certain·platforms
6980 if·rpm·--quiet·-q·kernel;·then6968 if·rpm·--quiet·-q·kernel;·then
Offset 6987, 14 lines modifiedOffset 6973, 28 lines modified
6987 if·!·rpm·-q·--quiet·"firewalld"·;·then6973 if·!·rpm·-q·--quiet·"firewalld"·;·then
6988 ····dnf·install·-y·"firewalld"6974 ····dnf·install·-y·"firewalld"
6989 fi6975 fi
  
6990 else6976 else
6991 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'6977 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
6992 fi6978 fi
 6979 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 6980 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 6981 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 6982 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 6983 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 6984 package·--add=firewalld
 6985 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 6986 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 6987 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 6988 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 6989 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 6990 dnf·install·firewalld
6993 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·f\x8fi\x8ir\x8re\x8ew\x8wa\x8al\x8ll\x8ld\x8d·E\x8En\x8na\x8ab\x8bl\x8le\x8ed\x8d·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*6991 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·f\x8fi\x8ir\x8re\x8ew\x8wa\x8al\x8ll\x8ld\x8d·E\x8En\x8na\x8ab\x8bl\x8le\x8ed\x8d·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
6994 The·firewalld·service·can·be·enabled·with·the·following·command:6992 The·firewalld·service·can·be·enabled·with·the·following·command:
6995 $·sudo·systemctl·enable·firewalld.service6993 $·sudo·systemctl·enable·firewalld.service
6996 Rationale:···Access·control·methods·provide·the·ability·to·enhance·system·security·posture·by·restricting·services·and·known·good·IP·addresses·and·address·ranges.·This·prevents·connections·from·unknown·hosts·and·protocols.6994 Rationale:···Access·control·methods·provide·the·ability·to·enhance·system·security·posture·by·restricting·services·and·known·good·IP·addresses·and·address·ranges.·This·prevents·connections·from·unknown·hosts·and·protocols.
6997 Severity: ···medium6995 Severity: ···medium
6998 Rule·ID:·····xccdf_org.ssgproject.content_rule_service_firewalld_enabled6996 Rule·ID:·····xccdf_org.ssgproject.content_rule_service_firewalld_enabled
6999 Identifiers:·CCE-90833-56997 Identifiers:·CCE-90833-5
Offset 7079, 34 lines modifiedOffset 7079, 34 lines modified
7079 ··-·medium_severity7079 ··-·medium_severity
7080 ··-·no_reboot_needed7080 ··-·no_reboot_needed
7081 ··-·service_firewalld_enabled7081 ··-·service_firewalld_enabled
7082 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x87082 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
7083 [customizations.services]7083 [customizations.services]
7084 enabled·=·["firewalld"]7084 enabled·=·["firewalld"]
7085 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
7086 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
7087 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
7088 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
7089 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable 
  
7090 service·enable·firewalld 
7091 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x87085 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
7092 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low7086 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
7093 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low7087 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
7094 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false7088 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
7095 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable7089 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
7096 include·enable_firewalld7090 include·enable_firewalld
  
7097 class·enable_firewalld·{7091 class·enable_firewalld·{
7098 ··service·{'firewalld':7092 ··service·{'firewalld':
7099 ····enable·=>·true,7093 ····enable·=>·true,
7100 ····ensure·=>·'running',7094 ····ensure·=>·'running',
7101 ··}7095 ··}
7102 }7096 }
 7097 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 7098 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 7099 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 7100 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 7101 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
  
 7102 service·enable·firewalld
7103 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x87103 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
7104 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low7104 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
7105 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low7105 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
7106 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false7106 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
Max diff block lines reached; 44072/48701 bytes (90.50%) of diff not shown.
1.78 MB
./usr/share/doc/ssg-nondebian/ssg-rhel9-guide-cis.html
    
Offset 15242, 207 lines modifiedOffset 15242, 207 lines modified
0003b890:·6765·743d·2223·6964·6d38·3435·3922·2074··get="#idm8459"·t0003b890:·6765·743d·2223·6964·6d38·3435·3922·2074··get="#idm8459"·t
0003b8a0:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role0003b8a0:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
0003b8b0:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e0003b8b0:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
0003b8c0:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·0003b8c0:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
0003b8d0:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·0003b8d0:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
0003b8e0:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=0003b8e0:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
0003b8f0:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation0003b8f0:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
 0003b900:·204f·5342·7569·6c64·2042·6c75·6570·7269···OSBuild·Bluepri
 0003b910:·6e74·2073·6e69·7070·6574·20e2·87b2·3c2f··nt·snippet·...</
 0003b920:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
 0003b930:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
 0003b940:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
 0003b950:·646d·3834·3539·223e·3c70·7265·3e3c·636f··dm8459"><pre><co
 0003b960:·6465·3e0a·5b5b·7061·636b·6167·6573·5d5d··de>.[[packages]]
 0003b970:·0a6e·616d·6520·3d20·2261·6964·6522·0a76··.name·=·"aide".v
 0003b980:·6572·7369·6f6e·203d·2022·2a22·0a3c·2f63··ersion·=·"*".</c
0003b900:·2073·6372·6970·7420·e287·b23c·2f61·3e3c···script·...</a>< 
0003b910:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p 
0003b920:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co 
0003b930:·6c6c·6170·7365·2220·6964·3d22·6964·6d38··llapse"·id="idm8 
0003b940:·3435·3922·3e3c·7461·626c·6520·636c·6173··459"><table·clas 
0003b950:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s 
0003b960:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor 
0003b970:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond 
0003b980:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C 
0003b990:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th>< 
0003b9a0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
0003b9b0:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti 
0003b9c0:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low< 
0003b9d0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0003b9e0:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td 
0003b9f0:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr> 
0003ba00:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy 
0003ba10:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable 
0003ba20:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl 
0003ba30:·653e·3c70·7265·3e3c·636f·6465·3e0a·646e··e><pre><code>.dn 
0003ba40:·6620·696e·7374·616c·6c20·6169·6465·0a3c··f·install·aide.< 
0003ba50:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di0003b990:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div>
0003ba60:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn·0003b9a0:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt
0003ba70:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat0003b9b0:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data-
0003ba80:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap0003b9c0:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse
0003ba90:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=0003b9d0:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
0003baa0:·2223·6964·6d38·3436·3022·2074·6162·696e··"#idm8460"·tabin0003b9e0:·6964·6d38·3436·3022·2074·6162·696e·6465··idm8460"·tabinde
0003bab0:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu0003b9f0:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt
0003bac0:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan0003ba00:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande
0003bad0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl0003ba10:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=
0003bae0:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r0003ba20:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev
0003baf0:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"0003ba30:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R
0003bb00:·3e52·656d·6564·6961·7469·6f6e·2041·6e61··>Remediation·Ana 
0003bb10:·636f·6e64·6120·736e·6970·7065·7420·e287··conda·snippet·..0003ba40:·656d·6564·6961·7469·6f6e·2050·7570·7065··emediation·Puppe
 0003ba50:·7420·736e·6970·7065·7420·e287·b23c·2f61··t·snippet·...</a
0003bb20:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl0003ba60:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
0003bb30:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla0003ba70:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
0003bb40:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id0003ba80:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
0003bb50:·3d22·6964·6d38·3436·3022·3e3c·7461·626c··="idm8460"><tabl0003ba90:·6d38·3436·3022·3e3c·7461·626c·6520·636c··m8460"><table·cl
0003bb60:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t0003baa0:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table
0003bb70:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab0003bab0:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b
0003bb80:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl0003bac0:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co
0003bb90:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr0003bad0:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th
0003bba0:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:0003bae0:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th
0003bbb0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td0003baf0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
0003bbc0:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di0003bb00:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup
0003bbd0:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t0003bb10:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo
 0003bb20:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
 0003bb30:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th><
 0003bb40:·7464·3e66·616c·7365·3c2f·7464·3e3c·2f74··td>false</td></t
 0003bb50:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate
 0003bb60:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab
 0003bb70:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta
 0003bb80:·626c·653e·3c70·7265·3e3c·636f·6465·3e69··ble><pre><code>i
 0003bb90:·6e63·6c75·6465·2069·6e73·7461·6c6c·5f61··nclude·install_a
 0003bba0:·6964·650a·0a63·6c61·7373·2069·6e73·7461··ide..class·insta
 0003bbb0:·6c6c·5f61·6964·6520·7b0a·2020·7061·636b··ll_aide·{.··pack
 0003bbc0:·6167·6520·7b20·2761·6964·6527·3a0a·2020··age·{·'aide':.··
 0003bbd0:·2020·656e·7375·7265·203d·2667·743b·2027····ensure·=&gt;·'
 0003bbe0:·696e·7374·616c·6c65·6427·2c0a·2020·7d0a··installed',.··}.
 0003bbf0:·7d0a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··}.</code></pre><
 0003bc00:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b
 0003bc10:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"·
 0003bc20:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col
 0003bc30:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ
 0003bc40:·6574·3d22·2369·646d·3834·3631·2220·7461··et="#idm8461"·ta
 0003bc50:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
 0003bc60:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
 0003bc70:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
 0003bc80:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
 0003bc90:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
 0003bca0:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
 0003bcb0:·7363·7269·7074·20e2·87b2·3c2f·613e·3c62··script·...</a><b
 0003bcc0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
 0003bcd0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
 0003bce0:·6c61·7073·6522·2069·643d·2269·646d·3834··lapse"·id="idm84
 0003bcf0:·3631·223e·3c74·6162·6c65·2063·6c61·7373··61"><table·class
 0003bd00:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st
 0003bd10:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord
 0003bd20:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde
 0003bd30:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co
 0003bd40:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t
0003bbe0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><0003bd50:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
0003bbf0:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</ 
0003bc00:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td0003bd60:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio
 0003bd70:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</
0003bc10:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St0003bd80:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
0003bc20:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>0003bd90:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td>
0003bc30:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr> 
0003bc40:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co 
0003bc50:·6465·3e0a·7061·636b·6167·6520·2d2d·6164··de>.package·--ad 
0003bc60:·643d·6169·6465·0a3c·2f63·6f64·653e·3c2f··d=aide.</code></ 
0003bc70:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla 
0003bc80:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ 
0003bc90:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle 
0003bca0:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data 
0003bcb0:·2d74·6172·6765·743d·2223·6964·6d38·3436··-target="#idm846 
0003bcc0:·3122·2074·6162·696e·6465·783d·2230·2220··1"·tabindex="0"· 
0003bcd0:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar 
0003bce0:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal 
0003bcf0:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ 
0003bd00:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h 
0003bd10:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia 
0003bd20:·7469·6f6e·204f·5342·7569·6c64·2042·6c75··tion·OSBuild·Blu 
0003bd30:·6570·7269·6e74·2073·6e69·7070·6574·20e2··eprint·snippet·.0003bda0:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr><
 0003bdb0:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:
 0003bdc0:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<
 0003bdd0:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table
 0003bde0:·3e3c·7072·653e·3c63·6f64·653e·0a70·6163··><pre><code>.pac
 0003bdf0:·6b61·6765·2069·6e73·7461·6c6c·2061·6964··kage·install·aid
 0003be00:·650a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··e.</code></pre><
Max diff block lines reached; 1643782/1670996 bytes (98.37%) of diff not shown.
190 KB
html2text {}
    
Offset 152, 52 lines modifiedOffset 152, 38 lines modified
152 ··-·PCI-DSSv4-11.5.2152 ··-·PCI-DSSv4-11.5.2
153 ··-·enable_strategy153 ··-·enable_strategy
154 ··-·low_complexity154 ··-·low_complexity
155 ··-·low_disruption155 ··-·low_disruption
156 ··-·medium_severity156 ··-·medium_severity
157 ··-·no_reboot_needed157 ··-·no_reboot_needed
158 ··-·package_aide_installed158 ··-·package_aide_installed
159 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
160 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
161 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
162 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
163 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
164 dnf·install·aide 
165 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
166 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
167 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
168 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
169 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
170 package·--add=aide 
171 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8159 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
172 [[packages]]160 [[packages]]
173 name·=·"aide"161 name·=·"aide"
174 version·=·"*"162 version·=·"*"
175 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
176 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
177 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
178 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
179 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
180 package·install·aide 
181 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8163 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
182 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low164 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
183 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low165 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
184 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false166 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
185 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable167 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
186 include·install_aide168 include·install_aide
  
187 class·install_aide·{169 class·install_aide·{
188 ··package·{·'aide':170 ··package·{·'aide':
189 ····ensure·=>·'installed',171 ····ensure·=>·'installed',
190 ··}172 ··}
191 }173 }
 174 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 175 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 176 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 177 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 178 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 179 package·install·aide
192 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8180 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
193 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low181 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
194 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low182 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
195 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false183 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
196 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable184 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
197 #·Remediation·is·applicable·only·in·certain·platforms185 #·Remediation·is·applicable·only·in·certain·platforms
198 if·rpm·--quiet·-q·kernel;·then186 if·rpm·--quiet·-q·kernel;·then
Offset 205, 14 lines modifiedOffset 191, 28 lines modified
205 if·!·rpm·-q·--quiet·"aide"·;·then191 if·!·rpm·-q·--quiet·"aide"·;·then
206 ····dnf·install·-y·"aide"192 ····dnf·install·-y·"aide"
207 fi193 fi
  
208 else194 else
209 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'195 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
210 fi196 fi
 197 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 198 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 199 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 200 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 201 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 202 package·--add=aide
 203 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 204 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 205 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 206 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 207 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 208 dnf·install·aide
211 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*209 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
212 Run·the·following·command·to·generate·a·new·database:210 Run·the·following·command·to·generate·a·new·database:
213 $·sudo·/usr/sbin/aide·--init211 $·sudo·/usr/sbin/aide·--init
214 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:212 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
215 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz213 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
216 To·initiate·a·manual·check,·run·the·following·command:214 To·initiate·a·manual·check,·run·the·following·command:
217 $·sudo·/usr/sbin/aide·--check215 $·sudo·/usr/sbin/aide·--check
Offset 943, 29 lines modifiedOffset 943, 29 lines modified
943 References:··_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)943 References:··_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)
944 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4944 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4
945 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227945 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
946 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R28946 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R28
947 ·············_\x8c_\x8i_\x8s············1.1.2.3.1947 ·············_\x8c_\x8i_\x8s············1.1.2.3.1
948 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-09-231010948 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-09-231010
949 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-257843r991589_rule949 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-257843r991589_rule
950 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
951 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
952 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high 
953 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
954 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
955 part·/home 
956 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8950 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
957 [[customizations.filesystem]]951 [[customizations.filesystem]]
958 mountpoint·=·"/home"952 mountpoint·=·"/home"
959 size·=·1073741824953 size·=·1073741824
960 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8954 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
961 logvol·/home·1024955 logvol·/home·1024
 956 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 957 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 958 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high
 959 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 960 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 961 part·/home
962 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/t\x8tm\x8mp\x8p·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*962 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/t\x8tm\x8mp\x8p·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
963 The·/tmp·directory·is·a·world-writable·directory·used·for·temporary·file·storage.·Ensure·it·has·its·own·partition·or·logical·volume·at·installation·time,·or·migrate·it·using·LVM.963 The·/tmp·directory·is·a·world-writable·directory·used·for·temporary·file·storage.·Ensure·it·has·its·own·partition·or·logical·volume·at·installation·time,·or·migrate·it·using·LVM.
964 Rationale:···The·/tmp·partition·is·used·as·temporary·storage·by·many·programs.·Placing·/tmp·in·its·own·partition·enables·the·setting·of·more·restrictive·mount·options,·which·can·help·protect·programs·which·use·it.964 Rationale:···The·/tmp·partition·is·used·as·temporary·storage·by·many·programs.·Placing·/tmp·in·its·own·partition·enables·the·setting·of·more·restrictive·mount·options,·which·can·help·protect·programs·which·use·it.
965 Severity: ···low965 Severity: ···low
966 Rule·ID:·····xccdf_org.ssgproject.content_rule_partition_for_tmp966 Rule·ID:·····xccdf_org.ssgproject.content_rule_partition_for_tmp
967 Identifiers:·CCE-90845-9967 Identifiers:·CCE-90845-9
968 ·············_\x8c_\x8i_\x8s_\x8-_\x8c_\x8s_\x8c········12,·15,·8968 ·············_\x8c_\x8i_\x8s_\x8-_\x8c_\x8s_\x8c········12,·15,·8
Offset 975, 29 lines modifiedOffset 975, 29 lines modified
975 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.3975 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.3
Max diff block lines reached; 188677/194140 bytes (97.19%) of diff not shown.
1.56 MB
./usr/share/doc/ssg-nondebian/ssg-rhel9-guide-cis_server_l1.html
    
Offset 15203, 208 lines modifiedOffset 15203, 208 lines modified
0003b620:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="0003b620:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
0003b630:·2369·646d·3834·3539·2220·7461·6269·6e64··#idm8459"·tabind0003b630:·2369·646d·3834·3539·2220·7461·6269·6e64··#idm8459"·tabind
0003b640:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but0003b640:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
0003b650:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand0003b650:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
0003b660:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title0003b660:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
0003b670:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re0003b670:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
0003b680:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">0003b680:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
0003b690:·5265·6d65·6469·6174·696f·6e20·7363·7269··Remediation·scri0003b690:·5265·6d65·6469·6174·696f·6e20·4f53·4275··Remediation·OSBu
 0003b6a0:·696c·6420·426c·7565·7072·696e·7420·736e··ild·Blueprint·sn
 0003b6b0:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br
 0003b6c0:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
 0003b6d0:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
 0003b6e0:·6170·7365·2220·6964·3d22·6964·6d38·3435··apse"·id="idm845
 0003b6f0:·3922·3e3c·7072·653e·3c63·6f64·653e·0a5b··9"><pre><code>.[
 0003b700:·5b70·6163·6b61·6765·735d·5d0a·6e61·6d65··[packages]].name
 0003b710:·203d·2022·6169·6465·220a·7665·7273·696f···=·"aide".versio
 0003b720:·6e20·3d20·222a·220a·3c2f·636f·6465·3e3c··n·=·"*".</code><
0003b6a0:·7074·20e2·87b2·3c2f·613e·3c62·723e·3c64··pt·...</a><br><d 
0003b6b0:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel- 
0003b6c0:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps 
0003b6d0:·6522·2069·643d·2269·646d·3834·3539·223e··e"·id="idm8459"> 
0003b6e0:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta 
0003b6f0:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe 
0003b700:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered 
0003b710:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed 
0003b720:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple 
0003b730:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo 
0003b740:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr>< 
0003b750:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</ 
0003b760:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td>< 
0003b770:·2f74·723e·3c74·723e·3c74·683e·5265·626f··/tr><tr><th>Rebo 
0003b780:·6f74·3a3c·2f74·683e·3c74·643e·6661·6c73··ot:</th><td>fals 
0003b790:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr>< 
0003b7a0:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th 
0003b7b0:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td> 
0003b7c0:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr 
0003b7d0:·653e·3c63·6f64·653e·0a64·6e66·2069·6e73··e><code>.dnf·ins 
0003b7e0:·7461·6c6c·2061·6964·650a·3c2f·636f·6465··tall·aide.</code 
0003b7f0:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a·0003b730:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl
0003b800:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s0003b740:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc
0003b810:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog0003b750:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl
0003b820:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d0003b760:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat
0003b830:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm0003b770:·612d·7461·7267·6574·3d22·2369·646d·3834··a-target="#idm84
0003b840:·3834·3630·2220·7461·6269·6e64·6578·3d22··8460"·tabindex="0003b780:·3630·2220·7461·6269·6e64·6578·3d22·3022··60"·tabindex="0"
0003b850:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"0003b790:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
0003b860:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="0003b7a0:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
0003b870:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac0003b7b0:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
0003b880:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal0003b7c0:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
0003b890:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme0003b7d0:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
0003b8a0:·6469·6174·696f·6e20·416e·6163·6f6e·6461··diation·Anaconda0003b7e0:·6174·696f·6e20·5075·7070·6574·2073·6e69··ation·Puppet·sni
0003b8b0:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>0003b7f0:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>
0003b8c0:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="0003b800:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
0003b8d0:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c0003b810:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
0003b8e0:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm0003b820:·7073·6522·2069·643d·2269·646d·3834·3630··pse"·id="idm8460
0003b8f0:·3834·3630·223e·3c74·6162·6c65·2063·6c61··8460"><table·cla0003b830:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="
0003b900:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-0003b840:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri
0003b910:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo0003b850:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border
0003b920:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con0003b860:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens
0003b930:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>0003b870:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp
0003b940:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>0003b880:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>
0003b950:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr0003b890:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
0003b960:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt0003b8a0:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:
0003b970:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low0003b8b0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
0003b980:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t0003b8c0:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re
0003b990:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t0003b8d0:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa
0003b9a0:·643e·6661·6c73·653c·2f74·643e·3c2f·7472··d>false</td></tr 
0003b9b0:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg 
0003b9c0:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl 
0003b9d0:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab0003b8e0:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr
0003b9e0:·6c65·3e3c·7072·653e·3c63·6f64·653e·0a70··le><pre><code>.p 
0003b9f0:·6163·6b61·6765·202d·2d61·6464·3d61·6964··ackage·--add=aid 
0003ba00:·650a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··e.</code></pre>< 
0003ba10:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b 
0003ba20:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"· 
0003ba30:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col 
0003ba40:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ 
0003ba50:·6574·3d22·2369·646d·3834·3631·2220·7461··et="#idm8461"·ta 
0003ba60:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role= 
0003ba70:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex 
0003ba80:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t 
0003ba90:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t 
0003baa0:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href=" 
0003bab0:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation· 
0003bac0:·4f53·4275·696c·6420·426c·7565·7072·696e··OSBuild·Blueprin 
0003bad0:·7420·736e·6970·7065·7420·e287·b23c·2f61··t·snippet·...</a 
0003bae0:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class= 
0003baf0:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse· 
0003bb00:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id 
0003bb10:·6d38·3436·3122·3e3c·7072·653e·3c63·6f64··m8461"><pre><cod 
0003bb20:·653e·0a5b·5b70·6163·6b61·6765·735d·5d0a··e>.[[packages]]. 
0003bb30:·6e61·6d65·203d·2022·6169·6465·220a·7665··name·=·"aide".ve 
0003bb40:·7273·696f·6e20·3d20·222a·220a·3c2f·636f··rsion·=·"*".</co 
0003bb50:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div>< 
0003bb60:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn 
0003bb70:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t 
0003bb80:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse" 
0003bb90:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i 
0003bba0:·646d·3834·3632·2220·7461·6269·6e64·6578··dm8462"·tabindex 
0003bbb0:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto 
0003bbc0:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded 
0003bbd0:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title=" 
0003bbe0:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve 
0003bbf0:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re 
0003bc00:·6d65·6469·6174·696f·6e20·7363·7269·7074··mediation·script 
0003bc10:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div 
0003bc20:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co 
0003bc30:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse" 
0003bc40:·2069·643d·2269·646d·3834·3632·223e·3c74···id="idm8462"><t 
0003bc50:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl 
0003bc60:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped· 
0003bc70:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t 
0003bc80:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed"> 
0003bc90:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi 
0003bca0:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low< 
0003bcb0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0003bcc0:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th 
0003bcd0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t 
0003bce0:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot 
0003bcf0:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false< 
0003bd00:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0003bd10:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><0003b8f0:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</
0003bd20:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></0003b900:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t
0003bd30:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>0003b910:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><
0003bd40:·3c63·6f64·653e·0a70·6163·6b61·6765·2069··<code>.package·i 
0003bd50:·6e73·7461·6c6c·2061·6964·650a·3c2f·636f··nstall·aide.</co 
0003bd60:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div>< 
0003bd70:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn 
Max diff block lines reached; 1445099/1472451 bytes (98.14%) of diff not shown.
160 KB
html2text {}
    
Offset 146, 52 lines modifiedOffset 146, 38 lines modified
146 ··-·PCI-DSSv4-11.5.2146 ··-·PCI-DSSv4-11.5.2
147 ··-·enable_strategy147 ··-·enable_strategy
148 ··-·low_complexity148 ··-·low_complexity
149 ··-·low_disruption149 ··-·low_disruption
150 ··-·medium_severity150 ··-·medium_severity
151 ··-·no_reboot_needed151 ··-·no_reboot_needed
152 ··-·package_aide_installed152 ··-·package_aide_installed
153 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
154 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
155 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
156 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
157 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
158 dnf·install·aide 
159 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
160 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
161 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
162 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
163 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
164 package·--add=aide 
165 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8153 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
166 [[packages]]154 [[packages]]
167 name·=·"aide"155 name·=·"aide"
168 version·=·"*"156 version·=·"*"
169 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
170 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
171 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
172 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
173 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
174 package·install·aide 
175 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8157 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
176 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low158 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
177 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low159 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
178 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false160 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
179 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable161 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
180 include·install_aide162 include·install_aide
  
181 class·install_aide·{163 class·install_aide·{
182 ··package·{·'aide':164 ··package·{·'aide':
183 ····ensure·=>·'installed',165 ····ensure·=>·'installed',
184 ··}166 ··}
185 }167 }
 168 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 169 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 170 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 171 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 172 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 173 package·install·aide
186 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8174 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
187 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low175 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
188 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low176 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
189 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false177 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
190 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable178 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
191 #·Remediation·is·applicable·only·in·certain·platforms179 #·Remediation·is·applicable·only·in·certain·platforms
192 if·rpm·--quiet·-q·kernel;·then180 if·rpm·--quiet·-q·kernel;·then
Offset 199, 14 lines modifiedOffset 185, 28 lines modified
199 if·!·rpm·-q·--quiet·"aide"·;·then185 if·!·rpm·-q·--quiet·"aide"·;·then
200 ····dnf·install·-y·"aide"186 ····dnf·install·-y·"aide"
201 fi187 fi
  
202 else188 else
203 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'189 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
204 fi190 fi
 191 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 192 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 193 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 194 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 195 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 196 package·--add=aide
 197 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 198 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 199 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 200 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 201 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 202 dnf·install·aide
205 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*203 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
206 Run·the·following·command·to·generate·a·new·database:204 Run·the·following·command·to·generate·a·new·database:
207 $·sudo·/usr/sbin/aide·--init205 $·sudo·/usr/sbin/aide·--init
208 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:206 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
209 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz207 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
210 To·initiate·a·manual·check,·run·the·following·command:208 To·initiate·a·manual·check,·run·the·following·command:
211 $·sudo·/usr/sbin/aide·--check209 $·sudo·/usr/sbin/aide·--check
Offset 936, 29 lines modifiedOffset 936, 29 lines modified
936 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.3936 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.3
937 References:··_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)937 References:··_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)
938 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4938 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4
939 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227939 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
940 ·············_\x8c_\x8i_\x8s············1.1.2.1.1940 ·············_\x8c_\x8i_\x8s············1.1.2.1.1
941 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-09-231015941 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-09-231015
942 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-257844r1044918_rule942 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-257844r1044918_rule
943 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
944 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
945 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high 
946 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
947 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
948 part·/tmp 
949 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8943 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
950 [[customizations.filesystem]]944 [[customizations.filesystem]]
951 mountpoint·=·"/tmp"945 mountpoint·=·"/tmp"
952 size·=·1073741824946 size·=·1073741824
953 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8947 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
954 logvol·/tmp·1024948 logvol·/tmp·1024
 949 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 950 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 951 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high
 952 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 953 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 954 part·/tmp
955 Group  ·GNOME·Desktop·Environment·  Group·contains·3·groups·and·10·rules955 Group  ·GNOME·Desktop·Environment·  Group·contains·3·groups·and·10·rules
956 _\x8[_\x8r_\x8e_\x8f_\x8]  ·GNOME·is·a·graphical·desktop·environment·bundled·with·many·Linux·distributions·that·allow·users·to·easily·interact·with·the·operating·system·graphically·rather·than·textually.·The·GNOME·Graphical·Display·Manager·(GDM)·provides·login,·logout,·and·user·switching·contexts·as·well·as·display·server·management.956 _\x8[_\x8r_\x8e_\x8f_\x8]  ·GNOME·is·a·graphical·desktop·environment·bundled·with·many·Linux·distributions·that·allow·users·to·easily·interact·with·the·operating·system·graphically·rather·than·textually.·The·GNOME·Graphical·Display·Manager·(GDM)·provides·login,·logout,·and·user·switching·contexts·as·well·as·display·server·management.
  
957 GNOME·is·developed·by·the·GNOME·Project·and·is·considered·the·default·Red·Hat·Graphical·environment.957 GNOME·is·developed·by·the·GNOME·Project·and·is·considered·the·default·Red·Hat·Graphical·environment.
  
958 For·more·information·on·GNOME·and·the·GNOME·Project,·see·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8w\x8w_\x8w\x8w_\x8w\x8w_\x8.\x8._\x8g\x8g_\x8n\x8n_\x8o\x8o_\x8m\x8m_\x8e\x8e_\x8.\x8._\x8o\x8o_\x8r\x8r_\x8g\x8g.958 For·more·information·on·GNOME·and·the·GNOME·Project,·see·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8w\x8w_\x8w\x8w_\x8w\x8w_\x8.\x8._\x8g\x8g_\x8n\x8n_\x8o\x8o_\x8m\x8m_\x8e\x8e_\x8.\x8._\x8o\x8o_\x8r\x8r_\x8g\x8g.
959 Group  ·Configure·GNOME·Login·Screen·  Group·contains·2·rules959 Group  ·Configure·GNOME·Login·Screen·  Group·contains·2·rules
Offset 2379, 52 lines modifiedOffset 2379, 38 lines modified
2379 ··-·PCI-DSSv4-2.2.62379 ··-·PCI-DSSv4-2.2.6
Max diff block lines reached; 158413/163811 bytes (96.70%) of diff not shown.
1.46 MB
./usr/share/doc/ssg-nondebian/ssg-rhel9-guide-cis_workstation_l1.html
    
Offset 15195, 207 lines modifiedOffset 15195, 207 lines modified
0003b5a0:·7267·6574·3d22·2369·646d·3834·3539·2220··rget="#idm8459"·0003b5a0:·7267·6574·3d22·2369·646d·3834·3539·2220··rget="#idm8459"·
0003b5b0:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol0003b5b0:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol
0003b5c0:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-0003b5c0:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-
0003b5d0:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"0003b5d0:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"
0003b5e0:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate0003b5e0:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate
0003b5f0:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href0003b5f0:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href
0003b600:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio0003b600:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio
 0003b610:·6e20·4f53·4275·696c·6420·426c·7565·7072··n·OSBuild·Bluepr
 0003b620:·696e·7420·736e·6970·7065·7420·e287·b23c··int·snippet·...<
 0003b630:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas
 0003b640:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps
 0003b650:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="
 0003b660:·6964·6d38·3435·3922·3e3c·7072·653e·3c63··idm8459"><pre><c
 0003b670:·6f64·653e·0a5b·5b70·6163·6b61·6765·735d··ode>.[[packages]
 0003b680:·5d0a·6e61·6d65·203d·2022·6169·6465·220a··].name·=·"aide".
 0003b690:·7665·7273·696f·6e20·3d20·222a·220a·3c2f··version·=·"*".</
0003b610:·6e20·7363·7269·7074·20e2·87b2·3c2f·613e··n·script·...</a> 
0003b620:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class=" 
0003b630:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c 
0003b640:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm 
0003b650:·3834·3539·223e·3c74·6162·6c65·2063·6c61··8459"><table·cla 
0003b660:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table- 
0003b670:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo 
0003b680:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con 
0003b690:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th> 
0003b6a0:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th> 
0003b6b0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
0003b6c0:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt 
0003b6d0:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low 
0003b6e0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
0003b6f0:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t 
0003b700:·643e·6661·6c73·653c·2f74·643e·3c2f·7472··d>false</td></tr 
0003b710:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg 
0003b720:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl 
0003b730:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab 
0003b740:·6c65·3e3c·7072·653e·3c63·6f64·653e·0a64··le><pre><code>.d 
0003b750:·6e66·2069·6e73·7461·6c6c·2061·6964·650a··nf·install·aide. 
0003b760:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d0003b6a0:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div
0003b770:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn0003b6b0:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b
0003b780:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da0003b6c0:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data
0003b790:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla0003b6d0:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps
0003b7a0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target0003b6e0:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
0003b7b0:·3d22·2369·646d·3834·3630·2220·7461·6269··="#idm8460"·tabi0003b6f0:·2369·646d·3834·3630·2220·7461·6269·6e64··#idm8460"·tabind
0003b7c0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b0003b700:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
0003b7d0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa0003b710:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
0003b7e0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit0003b720:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
0003b7f0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·0003b730:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
0003b800:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!0003b740:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
0003b810:·223e·5265·6d65·6469·6174·696f·6e20·416e··">Remediation·An0003b750:·5265·6d65·6469·6174·696f·6e20·5075·7070··Remediation·Pupp
0003b820:·6163·6f6e·6461·2073·6e69·7070·6574·20e2··aconda·snippet·.0003b760:·6574·2073·6e69·7070·6574·20e2·87b2·3c2f··et·snippet·...</
0003b830:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c0003b770:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
0003b840:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll0003b780:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
0003b850:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i0003b790:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
0003b860:·643d·2269·646d·3834·3630·223e·3c74·6162··d="idm8460"><tab0003b7a0:·646d·3834·3630·223e·3c74·6162·6c65·2063··dm8460"><table·c
0003b870:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·0003b7b0:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl
0003b880:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta0003b7c0:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-
0003b890:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab0003b7d0:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c
0003b8a0:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t0003b7e0:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t
0003b8b0:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity0003b7f0:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t
0003b8c0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t0003b800:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
0003b8d0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D0003b810:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru
0003b8e0:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><0003b820:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l
0003b8f0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>0003b830:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
0003b900:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:<0003b840:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th>
0003b910:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t0003b850:·3c74·643e·6661·6c73·653c·2f74·643e·3c2f··<td>false</td></
0003b920:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S0003b860:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat
0003b930:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td0003b870:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena
0003b940:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr 
0003b950:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c 
0003b960:·6f64·653e·0a70·6163·6b61·6765·202d·2d61··ode>.package·--a 
0003b970:·6464·3d61·6964·650a·3c2f·636f·6465·3e3c··dd=aide.</code>< 
0003b980:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl 
0003b990:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc 
0003b9a0:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl 
0003b9b0:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat 
0003b9c0:·612d·7461·7267·6574·3d22·2369·646d·3834··a-target="#idm84 
0003b9d0:·3631·2220·7461·6269·6e64·6578·3d22·3022··61"·tabindex="0" 
0003b9e0:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a 
0003b9f0:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa 
0003ba00:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti 
0003ba10:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"· 
0003ba20:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi 
0003ba30:·6174·696f·6e20·4f53·4275·696c·6420·426c··ation·OSBuild·Bl 
0003ba40:·7565·7072·696e·7420·736e·6970·7065·7420··ueprint·snippet· 
0003ba50:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div· 
0003ba60:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col 
0003ba70:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"· 
0003ba80:·6964·3d22·6964·6d38·3436·3122·3e3c·7072··id="idm8461"><pr 
0003ba90:·653e·3c63·6f64·653e·0a5b·5b70·6163·6b61··e><code>.[[packa 
0003baa0:·6765·735d·5d0a·6e61·6d65·203d·2022·6169··ges]].name·=·"ai 
0003bab0:·6465·220a·7665·7273·696f·6e20·3d20·222a··de".version·=·"* 
0003bac0:·220a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··".</code></pre>< 
0003bad0:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b 
0003bae0:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"· 
0003baf0:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col 
0003bb00:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ 
0003bb10:·6574·3d22·2369·646d·3834·3632·2220·7461··et="#idm8462"·ta 
0003bb20:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role= 
0003bb30:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex 
0003bb40:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t 
0003bb50:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t 
0003bb60:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href=" 
0003bb70:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation· 
0003bb80:·7363·7269·7074·20e2·87b2·3c2f·613e·3c62··script·...</a><b 
0003bb90:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa 
0003bba0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col 
0003bbb0:·6c61·7073·6522·2069·643d·2269·646d·3834··lapse"·id="idm84 
0003bbc0:·3632·223e·3c74·6162·6c65·2063·6c61·7373··62"><table·class 
0003bbd0:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st 
0003bbe0:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord 
0003bbf0:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde 
0003bc00:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co 
0003bc10:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t 
0003bc20:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr>< 
0003bc30:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio 
0003bc40:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</ 
0003bc50:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
0003bc60:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td> 
0003bc70:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr><0003b880:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t
0003bc80:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy: 
0003bc90:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable< 
0003bca0:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table 
0003bcb0:·3e3c·7072·653e·3c63·6f64·653e·0a70·6163··><pre><code>.pac0003b890:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>
0003bcc0:·6b61·6765·2069·6e73·7461·6c6c·2061·6964··kage·install·aid 
0003bcd0:·650a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··e.</code></pre>< 
0003bce0:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b 
0003bcf0:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"· 
Max diff block lines reached; 1350419/1377633 bytes (98.02%) of diff not shown.
148 KB
html2text {}
    
Offset 145, 52 lines modifiedOffset 145, 38 lines modified
145 ··-·PCI-DSSv4-11.5.2145 ··-·PCI-DSSv4-11.5.2
146 ··-·enable_strategy146 ··-·enable_strategy
147 ··-·low_complexity147 ··-·low_complexity
148 ··-·low_disruption148 ··-·low_disruption
149 ··-·medium_severity149 ··-·medium_severity
150 ··-·no_reboot_needed150 ··-·no_reboot_needed
151 ··-·package_aide_installed151 ··-·package_aide_installed
152 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
153 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
154 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
155 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
156 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
157 dnf·install·aide 
158 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
159 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
160 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
161 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
162 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
163 package·--add=aide 
164 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8152 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
165 [[packages]]153 [[packages]]
166 name·=·"aide"154 name·=·"aide"
167 version·=·"*"155 version·=·"*"
168 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
169 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
170 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
171 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
172 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
173 package·install·aide 
174 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8156 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
175 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low157 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
176 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low158 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
177 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false159 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
178 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable160 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
179 include·install_aide161 include·install_aide
  
180 class·install_aide·{162 class·install_aide·{
181 ··package·{·'aide':163 ··package·{·'aide':
182 ····ensure·=>·'installed',164 ····ensure·=>·'installed',
183 ··}165 ··}
184 }166 }
 167 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 168 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 169 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 170 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 171 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 172 package·install·aide
185 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8173 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
186 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low174 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
187 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low175 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
188 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false176 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
189 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable177 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
190 #·Remediation·is·applicable·only·in·certain·platforms178 #·Remediation·is·applicable·only·in·certain·platforms
191 if·rpm·--quiet·-q·kernel;·then179 if·rpm·--quiet·-q·kernel;·then
Offset 198, 14 lines modifiedOffset 184, 28 lines modified
198 if·!·rpm·-q·--quiet·"aide"·;·then184 if·!·rpm·-q·--quiet·"aide"·;·then
199 ····dnf·install·-y·"aide"185 ····dnf·install·-y·"aide"
200 fi186 fi
  
201 else187 else
202 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'188 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
203 fi189 fi
 190 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 191 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 192 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 193 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 194 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 195 package·--add=aide
 196 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 197 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 198 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 199 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 200 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 201 dnf·install·aide
204 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*202 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
205 Run·the·following·command·to·generate·a·new·database:203 Run·the·following·command·to·generate·a·new·database:
206 $·sudo·/usr/sbin/aide·--init204 $·sudo·/usr/sbin/aide·--init
207 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:205 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
208 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz206 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
209 To·initiate·a·manual·check,·run·the·following·command:207 To·initiate·a·manual·check,·run·the·following·command:
210 $·sudo·/usr/sbin/aide·--check208 $·sudo·/usr/sbin/aide·--check
Offset 935, 29 lines modifiedOffset 935, 29 lines modified
935 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.3935 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.3
936 References:··_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)936 References:··_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)
937 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4937 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4
938 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227938 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
939 ·············_\x8c_\x8i_\x8s············1.1.2.1.1939 ·············_\x8c_\x8i_\x8s············1.1.2.1.1
940 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-09-231015940 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-09-231015
941 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-257844r1044918_rule941 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-257844r1044918_rule
942 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
943 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
944 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high 
945 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
946 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
947 part·/tmp 
948 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8942 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
949 [[customizations.filesystem]]943 [[customizations.filesystem]]
950 mountpoint·=·"/tmp"944 mountpoint·=·"/tmp"
951 size·=·1073741824945 size·=·1073741824
952 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8946 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
953 logvol·/tmp·1024947 logvol·/tmp·1024
 948 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 949 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 950 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high
 951 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 952 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 953 part·/tmp
954 Group  ·GNOME·Desktop·Environment·  Group·contains·3·groups·and·8·rules954 Group  ·GNOME·Desktop·Environment·  Group·contains·3·groups·and·8·rules
955 _\x8[_\x8r_\x8e_\x8f_\x8]  ·GNOME·is·a·graphical·desktop·environment·bundled·with·many·Linux·distributions·that·allow·users·to·easily·interact·with·the·operating·system·graphically·rather·than·textually.·The·GNOME·Graphical·Display·Manager·(GDM)·provides·login,·logout,·and·user·switching·contexts·as·well·as·display·server·management.955 _\x8[_\x8r_\x8e_\x8f_\x8]  ·GNOME·is·a·graphical·desktop·environment·bundled·with·many·Linux·distributions·that·allow·users·to·easily·interact·with·the·operating·system·graphically·rather·than·textually.·The·GNOME·Graphical·Display·Manager·(GDM)·provides·login,·logout,·and·user·switching·contexts·as·well·as·display·server·management.
  
956 GNOME·is·developed·by·the·GNOME·Project·and·is·considered·the·default·Red·Hat·Graphical·environment.956 GNOME·is·developed·by·the·GNOME·Project·and·is·considered·the·default·Red·Hat·Graphical·environment.
  
957 For·more·information·on·GNOME·and·the·GNOME·Project,·see·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8w\x8w_\x8w\x8w_\x8w\x8w_\x8.\x8._\x8g\x8g_\x8n\x8n_\x8o\x8o_\x8m\x8m_\x8e\x8e_\x8.\x8._\x8o\x8o_\x8r\x8r_\x8g\x8g.957 For·more·information·on·GNOME·and·the·GNOME·Project,·see·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8w\x8w_\x8w\x8w_\x8w\x8w_\x8.\x8._\x8g\x8g_\x8n\x8n_\x8o\x8o_\x8m\x8m_\x8e\x8e_\x8.\x8._\x8o\x8o_\x8r\x8r_\x8g\x8g.
958 Group  ·Configure·GNOME·Login·Screen·  Group·contains·2·rules958 Group  ·Configure·GNOME·Login·Screen·  Group·contains·2·rules
Offset 2016, 52 lines modifiedOffset 2016, 38 lines modified
2016 ··-·PCI-DSSv4-2.2.62016 ··-·PCI-DSSv4-2.2.6
Max diff block lines reached; 145844/151241 bytes (96.43%) of diff not shown.
1.67 MB
./usr/share/doc/ssg-nondebian/ssg-rhel9-guide-cis_workstation_l2.html
    
Offset 15233, 208 lines modifiedOffset 15233, 208 lines modified
0003b800:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#0003b800:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
0003b810:·6964·6d38·3435·3922·2074·6162·696e·6465··idm8459"·tabinde0003b810:·6964·6d38·3435·3922·2074·6162·696e·6465··idm8459"·tabinde
0003b820:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt0003b820:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt
0003b830:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande0003b830:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande
0003b840:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=0003b840:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=
0003b850:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev0003b850:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev
0003b860:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R0003b860:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R
0003b870:·656d·6564·6961·7469·6f6e·2073·6372·6970··emediation·scrip0003b870:·656d·6564·6961·7469·6f6e·204f·5342·7569··emediation·OSBui
 0003b880:·6c64·2042·6c75·6570·7269·6e74·2073·6e69··ld·Blueprint·sni
 0003b890:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>
 0003b8a0:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
 0003b8b0:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
 0003b8c0:·7073·6522·2069·643d·2269·646d·3834·3539··pse"·id="idm8459
 0003b8d0:·223e·3c70·7265·3e3c·636f·6465·3e0a·5b5b··"><pre><code>.[[
 0003b8e0:·7061·636b·6167·6573·5d5d·0a6e·616d·6520··packages]].name·
 0003b8f0:·3d20·2261·6964·6522·0a76·6572·7369·6f6e··=·"aide".version
 0003b900:·203d·2022·2a22·0a3c·2f63·6f64·653e·3c2f···=·"*".</code></
0003b880:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di 
0003b890:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c 
0003b8a0:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse 
0003b8b0:·2220·6964·3d22·6964·6d38·3435·3922·3e3c··"·id="idm8459">< 
0003b8c0:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab 
0003b8d0:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped 
0003b8e0:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered· 
0003b8f0:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed" 
0003b900:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex 
0003b910:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low 
0003b920:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
0003b930:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t 
0003b940:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></ 
0003b950:·7472·3e3c·7472·3e3c·7468·3e52·6562·6f6f··tr><tr><th>Reboo 
0003b960:·743a·3c2f·7468·3e3c·7464·3e66·616c·7365··t:</th><td>false 
0003b970:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
0003b980:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th> 
0003b990:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td>< 
0003b9a0:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre 
0003b9b0:·3e3c·636f·6465·3e0a·646e·6620·696e·7374··><code>.dnf·inst 
0003b9c0:·616c·6c20·6169·6465·0a3c·2f63·6f64·653e··all·aide.</code> 
0003b9d0:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c0003b910:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla
0003b9e0:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su0003b920:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ
0003b9f0:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg0003b930:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle
0003ba00:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da0003b940:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data
0003ba10:·7461·2d74·6172·6765·743d·2223·6964·6d38··ta-target="#idm80003b950:·2d74·6172·6765·743d·2223·6964·6d38·3436··-target="#idm846
0003ba20:·3436·3022·2074·6162·696e·6465·783d·2230··460"·tabindex="00003b960:·3022·2074·6162·696e·6465·783d·2230·2220··0"·tabindex="0"·
0003ba30:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·0003b970:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar
0003ba40:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f0003b980:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal
0003ba50:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act0003b990:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ
0003ba60:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"0003b9a0:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h
0003ba70:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed0003b9b0:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia
 0003b9c0:·7469·6f6e·2050·7570·7065·7420·736e·6970··tion·Puppet·snip
0003ba80:·6961·7469·6f6e·2041·6e61·636f·6e64·6120··iation·Anaconda· 
0003ba90:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a>< 
0003baa0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p 
0003bab0:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co 
0003bac0:·6c6c·6170·7365·2220·6964·3d22·6964·6d38··llapse"·id="idm8 
0003bad0:·3436·3022·3e3c·7461·626c·6520·636c·6173··460"><table·clas 
0003bae0:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s 
0003baf0:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor 
0003bb00:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond 
0003bb10:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C 
0003bb20:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th>< 
0003bb30:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
0003bb40:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti 
0003bb50:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low< 
0003bb60:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0003bb70:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td 
0003bb80:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr> 
0003bb90:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy 
0003bba0:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable 
0003bbb0:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl 
0003bbc0:·653e·3c70·7265·3e3c·636f·6465·3e0a·7061··e><pre><code>.pa 
0003bbd0:·636b·6167·6520·2d2d·6164·643d·6169·6465··ckage·--add=aide 
0003bbe0:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></ 
0003bbf0:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt 
0003bc00:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d 
0003bc10:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll 
0003bc20:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe 
0003bc30:·743d·2223·6964·6d38·3436·3122·2074·6162··t="#idm8461"·tab 
0003bc40:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role=" 
0003bc50:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp 
0003bc60:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti 
0003bc70:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to 
0003bc80:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="# 
0003bc90:·2122·3e52·656d·6564·6961·7469·6f6e·204f··!">Remediation·O 
0003bca0:·5342·7569·6c64·2042·6c75·6570·7269·6e74··SBuild·Blueprint 
0003bcb0:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a> 
0003bcc0:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class=" 
0003bcd0:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c 
0003bce0:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm 
0003bcf0:·3834·3631·223e·3c70·7265·3e3c·636f·6465··8461"><pre><code 
0003bd00:·3e0a·5b5b·7061·636b·6167·6573·5d5d·0a6e··>.[[packages]].n 
0003bd10:·616d·6520·3d20·2261·6964·6522·0a76·6572··ame·=·"aide".ver 
0003bd20:·7369·6f6e·203d·2022·2a22·0a3c·2f63·6f64··sion·=·"*".</cod 
0003bd30:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a 
0003bd40:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn- 
0003bd50:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to 
0003bd60:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"· 
0003bd70:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id 
0003bd80:·6d38·3436·3222·2074·6162·696e·6465·783d··m8462"·tabindex= 
0003bd90:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button 
0003bda0:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded= 
0003bdb0:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A 
0003bdc0:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea 
0003bdd0:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem 
0003bde0:·6564·6961·7469·6f6e·2073·6372·6970·7420··ediation·script· 
0003bdf0:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·0003b9d0:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br><
0003be00:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col0003b9e0:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
0003be10:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·0003b9f0:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap
0003be20:·6964·3d22·6964·6d38·3436·3222·3e3c·7461··id="idm8462"><ta0003ba00:·7365·2220·6964·3d22·6964·6d38·3436·3022··se"·id="idm8460"
0003be30:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table0003ba10:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t
0003be40:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t0003ba20:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip
0003be50:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta0003ba30:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere
0003be60:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><0003ba40:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense
0003be70:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit0003ba50:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl
0003be80:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</0003ba60:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l
0003be90:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>0003ba70:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
0003bea0:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th>0003ba80:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:<
0003beb0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr0003ba90:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
0003bec0:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot:0003baa0:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb
0003bed0:·3c2f·7468·3e3c·7464·3e66·616c·7365·3c2f··</th><td>false</0003bab0:·6f6f·743a·3c2f·7468·3e3c·7464·3e66·616c··oot:</th><td>fal
0003bee0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>0003bac0:·7365·3c2f·7464·3e3c·2f74·723e·3c74·723e··se</td></tr><tr>
0003bef0:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t0003bad0:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t
0003bf00:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t0003bae0:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td
0003bf10:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><0003baf0:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p
0003bf20:·636f·6465·3e0a·7061·636b·6167·6520·696e··code>.package·in 
0003bf30:·7374·616c·6c20·6169·6465·0a3c·2f63·6f64··stall·aide.</cod 
0003bf40:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a 
Max diff block lines reached; 1545684/1573036 bytes (98.26%) of diff not shown.
177 KB
html2text {}
    
Offset 151, 52 lines modifiedOffset 151, 38 lines modified
151 ··-·PCI-DSSv4-11.5.2151 ··-·PCI-DSSv4-11.5.2
152 ··-·enable_strategy152 ··-·enable_strategy
153 ··-·low_complexity153 ··-·low_complexity
154 ··-·low_disruption154 ··-·low_disruption
155 ··-·medium_severity155 ··-·medium_severity
156 ··-·no_reboot_needed156 ··-·no_reboot_needed
157 ··-·package_aide_installed157 ··-·package_aide_installed
158 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
159 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
160 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
161 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
162 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
163 dnf·install·aide 
164 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
165 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
166 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
167 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
168 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
169 package·--add=aide 
170 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8158 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
171 [[packages]]159 [[packages]]
172 name·=·"aide"160 name·=·"aide"
173 version·=·"*"161 version·=·"*"
174 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
175 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
176 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
177 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
178 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
179 package·install·aide 
180 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8162 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
181 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low163 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
182 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low164 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
183 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false165 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
184 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable166 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
185 include·install_aide167 include·install_aide
  
186 class·install_aide·{168 class·install_aide·{
187 ··package·{·'aide':169 ··package·{·'aide':
188 ····ensure·=>·'installed',170 ····ensure·=>·'installed',
189 ··}171 ··}
190 }172 }
 173 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 174 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 175 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 176 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 177 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 178 package·install·aide
191 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8179 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
192 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low180 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
193 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low181 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
194 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false182 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
195 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable183 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
196 #·Remediation·is·applicable·only·in·certain·platforms184 #·Remediation·is·applicable·only·in·certain·platforms
197 if·rpm·--quiet·-q·kernel;·then185 if·rpm·--quiet·-q·kernel;·then
Offset 204, 14 lines modifiedOffset 190, 28 lines modified
204 if·!·rpm·-q·--quiet·"aide"·;·then190 if·!·rpm·-q·--quiet·"aide"·;·then
205 ····dnf·install·-y·"aide"191 ····dnf·install·-y·"aide"
206 fi192 fi
  
207 else193 else
208 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'194 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
209 fi195 fi
 196 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 197 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 198 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 199 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 200 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 201 package·--add=aide
 202 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 203 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 204 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 205 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 206 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 207 dnf·install·aide
210 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*208 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
211 Run·the·following·command·to·generate·a·new·database:209 Run·the·following·command·to·generate·a·new·database:
212 $·sudo·/usr/sbin/aide·--init210 $·sudo·/usr/sbin/aide·--init
213 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:211 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
214 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz212 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
215 To·initiate·a·manual·check,·run·the·following·command:213 To·initiate·a·manual·check,·run·the·following·command:
216 $·sudo·/usr/sbin/aide·--check214 $·sudo·/usr/sbin/aide·--check
Offset 942, 29 lines modifiedOffset 942, 29 lines modified
942 References:··_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)942 References:··_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)
943 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4943 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4
944 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227944 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
945 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R28945 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R28
946 ·············_\x8c_\x8i_\x8s············1.1.2.3.1946 ·············_\x8c_\x8i_\x8s············1.1.2.3.1
947 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-09-231010947 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-09-231010
948 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-257843r991589_rule948 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-257843r991589_rule
949 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
950 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
951 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high 
952 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
953 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
954 part·/home 
955 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8949 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
956 [[customizations.filesystem]]950 [[customizations.filesystem]]
957 mountpoint·=·"/home"951 mountpoint·=·"/home"
958 size·=·1073741824952 size·=·1073741824
959 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8953 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
960 logvol·/home·1024954 logvol·/home·1024
 955 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 956 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 957 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high
 958 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 959 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 960 part·/home
961 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/t\x8tm\x8mp\x8p·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*961 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/t\x8tm\x8mp\x8p·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
962 The·/tmp·directory·is·a·world-writable·directory·used·for·temporary·file·storage.·Ensure·it·has·its·own·partition·or·logical·volume·at·installation·time,·or·migrate·it·using·LVM.962 The·/tmp·directory·is·a·world-writable·directory·used·for·temporary·file·storage.·Ensure·it·has·its·own·partition·or·logical·volume·at·installation·time,·or·migrate·it·using·LVM.
963 Rationale:···The·/tmp·partition·is·used·as·temporary·storage·by·many·programs.·Placing·/tmp·in·its·own·partition·enables·the·setting·of·more·restrictive·mount·options,·which·can·help·protect·programs·which·use·it.963 Rationale:···The·/tmp·partition·is·used·as·temporary·storage·by·many·programs.·Placing·/tmp·in·its·own·partition·enables·the·setting·of·more·restrictive·mount·options,·which·can·help·protect·programs·which·use·it.
964 Severity: ···low964 Severity: ···low
965 Rule·ID:·····xccdf_org.ssgproject.content_rule_partition_for_tmp965 Rule·ID:·····xccdf_org.ssgproject.content_rule_partition_for_tmp
966 Identifiers:·CCE-90845-9966 Identifiers:·CCE-90845-9
967 ·············_\x8c_\x8i_\x8s_\x8-_\x8c_\x8s_\x8c········12,·15,·8967 ·············_\x8c_\x8i_\x8s_\x8-_\x8c_\x8s_\x8c········12,·15,·8
Offset 974, 29 lines modifiedOffset 974, 29 lines modified
974 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.3974 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.3
Max diff block lines reached; 176088/181551 bytes (96.99%) of diff not shown.
653 KB
./usr/share/doc/ssg-nondebian/ssg-rhel9-guide-cui.html
    
Offset 15894, 203 lines modifiedOffset 15894, 203 lines modified
0003e150:·6574·3d22·2369·646d·3931·3730·2220·7461··et="#idm9170"·ta0003e150:·6574·3d22·2369·646d·3931·3730·2220·7461··et="#idm9170"·ta
0003e160:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=0003e160:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
0003e170:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex0003e170:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
0003e180:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t0003e180:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
0003e190:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t0003e190:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
0003e1a0:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="0003e1a0:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
0003e1b0:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·0003e1b0:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
 0003e1c0:·4f53·4275·696c·6420·426c·7565·7072·696e··OSBuild·Blueprin
 0003e1d0:·7420·736e·6970·7065·7420·e287·b23c·2f61··t·snippet·...</a
 0003e1e0:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
 0003e1f0:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
 0003e200:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
 0003e210:·6d39·3137·3022·3e3c·7072·653e·3c63·6f64··m9170"><pre><cod
 0003e220:·653e·0a5b·5b70·6163·6b61·6765·735d·5d0a··e>.[[packages]].
 0003e230:·6e61·6d65·203d·2022·6372·7970·746f·2d70··name·=·"crypto-p
 0003e240:·6f6c·6963·6965·7322·0a76·6572·7369·6f6e··olicies".version
 0003e250:·203d·2022·2a22·0a3c·2f63·6f64·653e·3c2f···=·"*".</code></
0003e1c0:·7363·7269·7074·20e2·87b2·3c2f·613e·3c62··script·...</a><b 
0003e1d0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa 
0003e1e0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col 
0003e1f0:·6c61·7073·6522·2069·643d·2269·646d·3931··lapse"·id="idm91 
0003e200:·3730·223e·3c74·6162·6c65·2063·6c61·7373··70"><table·class 
0003e210:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st 
0003e220:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord 
0003e230:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde 
0003e240:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co 
0003e250:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t 
0003e260:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr>< 
0003e270:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio 
0003e280:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</ 
0003e290:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
0003e2a0:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td> 
0003e2b0:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr>< 
0003e2c0:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy: 
0003e2d0:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable< 
0003e2e0:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table 
0003e2f0:·3e3c·7072·653e·3c63·6f64·653e·0a64·6e66··><pre><code>.dnf 
0003e300:·2069·6e73·7461·6c6c·2063·7279·7074·6f2d···install·crypto- 
0003e310:·706f·6c69·6369·6573·0a3c·2f63·6f64·653e··policies.</code> 
0003e320:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c0003e260:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla
0003e330:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su0003e270:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ
0003e340:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg0003e280:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle
0003e350:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da0003e290:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data
0003e360:·7461·2d74·6172·6765·743d·2223·6964·6d39··ta-target="#idm90003e2a0:·2d74·6172·6765·743d·2223·6964·6d39·3137··-target="#idm917
0003e370:·3137·3122·2074·6162·696e·6465·783d·2230··171"·tabindex="00003e2b0:·3122·2074·6162·696e·6465·783d·2230·2220··1"·tabindex="0"·
0003e380:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·0003e2c0:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar
0003e390:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f0003e2d0:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal
0003e3a0:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act0003e2e0:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ
0003e3b0:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"0003e2f0:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h
0003e3c0:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed0003e300:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia
 0003e310:·7469·6f6e·2050·7570·7065·7420·736e·6970··tion·Puppet·snip
0003e3d0:·6961·7469·6f6e·2041·6e61·636f·6e64·6120··iation·Anaconda· 
0003e3e0:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a>< 
0003e3f0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p 
0003e400:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co 
0003e410:·6c6c·6170·7365·2220·6964·3d22·6964·6d39··llapse"·id="idm9 
0003e420:·3137·3122·3e3c·7461·626c·6520·636c·6173··171"><table·clas 
0003e430:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s 
0003e440:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor 
0003e450:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond 
0003e460:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C 
0003e470:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th>< 
0003e480:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
0003e490:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti 
0003e4a0:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low< 
0003e4b0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0003e4c0:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td 
0003e4d0:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr> 
0003e4e0:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy 
0003e4f0:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable 
0003e500:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl 
0003e510:·653e·3c70·7265·3e3c·636f·6465·3e0a·7061··e><pre><code>.pa 
0003e520:·636b·6167·6520·2d2d·6164·643d·6372·7970··ckage·--add=cryp 
0003e530:·746f·2d70·6f6c·6963·6965·730a·3c2f·636f··to-policies.</co 
0003e540:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div>< 
0003e550:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn 
0003e560:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t 
0003e570:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse" 
0003e580:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i 
0003e590:·646d·3931·3732·2220·7461·6269·6e64·6578··dm9172"·tabindex 
0003e5a0:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto 
0003e5b0:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded 
0003e5c0:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title=" 
0003e5d0:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve 
0003e5e0:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re 
0003e5f0:·6d65·6469·6174·696f·6e20·4f53·4275·696c··mediation·OSBuil 
0003e600:·6420·426c·7565·7072·696e·7420·736e·6970··d·Blueprint·snip 
0003e610:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br><0003e320:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br><
0003e620:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel0003e330:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
0003e630:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap0003e340:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap
0003e640:·7365·2220·6964·3d22·6964·6d39·3137·3222··se"·id="idm9172"0003e350:·7365·2220·6964·3d22·6964·6d39·3137·3122··se"·id="idm9171"
0003e650:·3e3c·7072·653e·3c63·6f64·653e·0a5b·5b70··><pre><code>.[[p 
0003e660:·6163·6b61·6765·735d·5d0a·6e61·6d65·203d··ackages]].name·= 
0003e670:·2022·6372·7970·746f·2d70·6f6c·6963·6965···"crypto-policie 
0003e680:·7322·0a76·6572·7369·6f6e·203d·2022·2a22··s".version·=·"*" 
0003e690:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></ 
0003e6a0:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt 
0003e6b0:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d 
0003e6c0:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll 
0003e6d0:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe 
0003e6e0:·743d·2223·6964·6d39·3137·3322·2074·6162··t="#idm9173"·tab 
0003e6f0:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role=" 
0003e700:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp 
0003e710:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti 
0003e720:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to 
0003e730:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="# 
0003e740:·2122·3e52·656d·6564·6961·7469·6f6e·2073··!">Remediation·s 
0003e750:·6372·6970·7420·e287·b23c·2f61·3e3c·6272··cript·...</a><br 
0003e760:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan 
0003e770:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll 
0003e780:·6170·7365·2220·6964·3d22·6964·6d39·3137··apse"·id="idm917 
0003e790:·3322·3e3c·7461·626c·6520·636c·6173·733d··3"><table·class=0003e360:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t
0003e7a0:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str0003e370:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip
0003e7b0:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde0003e380:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere
0003e7c0:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden0003e390:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense
0003e7d0:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com0003e3a0:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl
0003e7e0:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td0003e3b0:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l
0003e7f0:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t0003e3c0:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
0003e800:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption0003e3d0:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:<
0003e810:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t0003e3e0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
0003e820:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e52··d></tr><tr><th>R0003e3f0:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb
0003e830:·6562·6f6f·743a·3c2f·7468·3e3c·7464·3e66··eboot:</th><td>f0003e400:·6f6f·743a·3c2f·7468·3e3c·7464·3e66·616c··oot:</th><td>fal
0003e840:·616c·7365·3c2f·7464·3e3c·2f74·723e·3c74··alse</td></tr><t0003e410:·7365·3c2f·7464·3e3c·2f74·723e·3c74·723e··se</td></tr><tr>
0003e850:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<0003e420:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t
0003e860:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</0003e430:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td
0003e870:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table>0003e440:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p
0003e880:·3c70·7265·3e3c·636f·6465·3e0a·7061·636b··<pre><code>.pack 
Max diff block lines reached; 568650/595312 bytes (95.52%) of diff not shown.
71.6 KB
html2text {}
    
Offset 176, 61 lines modifiedOffset 176, 61 lines modified
176 ··-·DISA-STIG-RHEL-09-215100176 ··-·DISA-STIG-RHEL-09-215100
177 ··-·enable_strategy177 ··-·enable_strategy
178 ··-·low_complexity178 ··-·low_complexity
179 ··-·low_disruption179 ··-·low_disruption
180 ··-·medium_severity180 ··-·medium_severity
181 ··-·no_reboot_needed181 ··-·no_reboot_needed
182 ··-·package_crypto-policies_installed182 ··-·package_crypto-policies_installed
183 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
184 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
185 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
186 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
187 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
188 dnf·install·crypto-policies 
189 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
190 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
191 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
192 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
193 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
194 package·--add=crypto-policies 
195 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8183 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
196 [[packages]]184 [[packages]]
197 name·=·"crypto-policies"185 name·=·"crypto-policies"
198 version·=·"*"186 version·=·"*"
199 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
200 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
201 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
202 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
203 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
204 package·install·crypto-policies 
205 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8187 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
206 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low188 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
207 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low189 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
208 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false190 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
209 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable191 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
210 include·install_crypto-policies192 include·install_crypto-policies
  
211 class·install_crypto-policies·{193 class·install_crypto-policies·{
212 ··package·{·'crypto-policies':194 ··package·{·'crypto-policies':
213 ····ensure·=>·'installed',195 ····ensure·=>·'installed',
214 ··}196 ··}
215 }197 }
 198 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 199 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 200 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 201 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 202 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 203 package·install·crypto-policies
216 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8204 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
217 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low205 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
218 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low206 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
219 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false207 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
220 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable208 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
221 if·!·rpm·-q·--quiet·"crypto-policies"·;·then209 if·!·rpm·-q·--quiet·"crypto-policies"·;·then
222 ····dnf·install·-y·"crypto-policies"210 ····dnf·install·-y·"crypto-policies"
223 fi211 fi
 212 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 213 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 214 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 215 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 216 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 217 package·--add=crypto-policies
 218 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 219 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 220 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 221 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 222 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 223 dnf·install·crypto-policies
224 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8og\x8gr\x8ra\x8ap\x8ph\x8hy\x8y·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*224 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8og\x8gr\x8ra\x8ap\x8ph\x8hy\x8y·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
225 To·configure·the·system·cryptography·policy·to·use·ciphers·only·from·the·FIPS·policy,·run·the·following·command:225 To·configure·the·system·cryptography·policy·to·use·ciphers·only·from·the·FIPS·policy,·run·the·following·command:
226 $·sudo·update-crypto-policies·--set·FIPS226 $·sudo·update-crypto-policies·--set·FIPS
227 The·rule·checks·if·settings·for·selected·crypto·policy·are·configured·as·expected.·Configuration·files·in·the·/etc/crypto-policies/back-ends·are·either·symlinks·to·correct·files·provided·by·Crypto-policies·package·or·they·are·regular·files·in·case·crypto·policy·customizations·are·applied.·Crypto·policies·may·be·customized·by·crypto·policy·modules,·in·which·case·it·is·delimited·from·the·base·policy·using·a·colon.227 The·rule·checks·if·settings·for·selected·crypto·policy·are·configured·as·expected.·Configuration·files·in·the·/etc/crypto-policies/back-ends·are·either·symlinks·to·correct·files·provided·by·Crypto-policies·package·or·they·are·regular·files·in·case·crypto·policy·customizations·are·applied.·Crypto·policies·may·be·customized·by·crypto·policy·modules,·in·which·case·it·is·delimited·from·the·base·policy·using·a·colon.
228 Warning: ·The·system·needs·to·be·rebooted·for·these·changes·to·take·effect.228 Warning: ·The·system·needs·to·be·rebooted·for·these·changes·to·take·effect.
229 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8n\x8n_\x8v\x8v_\x8l\x8l_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8/\x8/_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8/\x8/_\x8N\x8N_\x8I\x8I_\x8S\x8S_\x8T\x8T_\x8.\x8._\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x81\x81_\x84\x84_\x80\x80_\x8-\x8-_\x82\x82_\x8.\x8._\x8p\x8p_\x8d\x8d_\x8f\x8f·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.229 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8n\x8n_\x8v\x8v_\x8l\x8l_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8/\x8/_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8/\x8/_\x8N\x8N_\x8I\x8I_\x8S\x8S_\x8T\x8T_\x8.\x8._\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x81\x81_\x84\x84_\x80\x80_\x8-\x8-_\x82\x82_\x8.\x8._\x8p\x8p_\x8d\x8d_\x8f\x8f·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.
230 Rationale:···Centralized·cryptographic·policies·simplify·applying·secure·ciphers·across·an·operating·system·and·the·applications·that·run·on·that·operating·system.·Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.230 Rationale:···Centralized·cryptographic·policies·simplify·applying·secure·ciphers·across·an·operating·system·and·the·applications·that·run·on·that·operating·system.·Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.
Offset 580, 29 lines modifiedOffset 580, 29 lines modified
580 ·············_\x8o_\x8s_\x8p_\x8p···········FMT_SMF_EXT.1580 ·············_\x8o_\x8s_\x8p_\x8p···········FMT_SMF_EXT.1
581 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000341-GPOS-00132,·SRG-OS-000480-GPOS-00227581 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000341-GPOS-00132,·SRG-OS-000480-GPOS-00227
582 ·············_\x8a_\x8p_\x8p_\x8-_\x8s_\x8r_\x8g_\x8-_\x8c_\x8t_\x8r····SRG-APP-000357-CTR-000800582 ·············_\x8a_\x8p_\x8p_\x8-_\x8s_\x8r_\x8g_\x8-_\x8c_\x8t_\x8r····SRG-APP-000357-CTR-000800
583 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R71583 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R71
584 ·············_\x8c_\x8i_\x8s············1.1.2.7.1584 ·············_\x8c_\x8i_\x8s············1.1.2.7.1
585 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-09-231030585 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-09-231030
586 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-257847r1044924_rule586 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-257847r1044924_rule
587 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
588 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
589 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high 
590 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
591 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
592 part·/var/log/audit 
593 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8587 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
594 [[customizations.filesystem]]588 [[customizations.filesystem]]
595 mountpoint·=·"/var/log/audit"589 mountpoint·=·"/var/log/audit"
596 size·=·10737418240590 size·=·10737418240
597 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8591 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
598 logvol·/var/log/audit·10240592 logvol·/var/log/audit·10240
 593 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 594 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 595 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high
 596 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 597 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 598 part·/var/log/audit
599 Group  ·Sudo·  Group·contains·1·rule599 Group  ·Sudo·  Group·contains·1·rule
600 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Sudo,·which·stands·for·"su·'do'",·provides·the·ability·to·delegate·authority·to·certain·users,·groups·of·users,·or·system·administrators.·When·configured·for·system·users·and/or·groups,·Sudo·can·allow·a·user·or·group·to·execute·privileged·commands·that·normally·only·root·is·allowed·to·execute.600 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Sudo,·which·stands·for·"su·'do'",·provides·the·ability·to·delegate·authority·to·certain·users,·groups·of·users,·or·system·administrators.·When·configured·for·system·users·and/or·groups,·Sudo·can·allow·a·user·or·group·to·execute·privileged·commands·that·normally·only·root·is·allowed·to·execute.
  
601 For·more·information·on·Sudo·and·addition·Sudo·configuration·options,·see·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8w\x8w_\x8w\x8w_\x8w\x8w_\x8.\x8._\x8s\x8s_\x8u\x8u_\x8d\x8d_\x8o\x8o_\x8.\x8._\x8w\x8w_\x8s\x8s.601 For·more·information·on·Sudo·and·addition·Sudo·configuration·options,·see·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8w\x8w_\x8w\x8w_\x8w\x8w_\x8.\x8._\x8s\x8s_\x8u\x8u_\x8d\x8d_\x8o\x8o_\x8.\x8._\x8w\x8w_\x8s\x8s.
602 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·s\x8su\x8ud\x8do\x8o·P\x8Pa\x8ac\x8ck\x8ka\x8ag\x8ge\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*602 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·s\x8su\x8ud\x8do\x8o·P\x8Pa\x8ac\x8ck\x8ka\x8ag\x8ge\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
603 The·sudo·package·can·be·installed·with·the·following·command:603 The·sudo·package·can·be·installed·with·the·following·command:
604 $·sudo·dnf·install·sudo604 $·sudo·dnf·install·sudo
Offset 654, 52 lines modifiedOffset 654, 38 lines modified
654 ··-·PCI-DSSv4-2.2.6654 ··-·PCI-DSSv4-2.2.6
655 ··-·enable_strategy655 ··-·enable_strategy
656 ··-·low_complexity656 ··-·low_complexity
657 ··-·low_disruption657 ··-·low_disruption
658 ··-·medium_severity658 ··-·medium_severity
659 ··-·no_reboot_needed659 ··-·no_reboot_needed
660 ··-·package_sudo_installed660 ··-·package_sudo_installed
Max diff block lines reached; 65537/73269 bytes (89.45%) of diff not shown.
523 KB
./usr/share/doc/ssg-nondebian/ssg-rhel9-guide-e8.html
    
Offset 19922, 277 lines modifiedOffset 19922, 277 lines modified
0004dd10:·7461·2d74·6172·6765·743d·2223·6964·6d31··ta-target="#idm10004dd10:·7461·2d74·6172·6765·743d·2223·6964·6d31··ta-target="#idm1
0004dd20:·3235·3931·2220·7461·6269·6e64·6578·3d22··2591"·tabindex="0004dd20:·3235·3931·2220·7461·6269·6e64·6578·3d22··2591"·tabindex="
0004dd30:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"0004dd30:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
0004dd40:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="0004dd40:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
0004dd50:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac0004dd50:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
0004dd60:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal0004dd60:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
0004dd70:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme0004dd70:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
0004dd80:·6469·6174·696f·6e20·7363·7269·7074·20e2··diation·script·.0004dd80:·6469·6174·696f·6e20·4f53·4275·696c·6420··diation·OSBuild·
 0004dd90:·426c·7565·7072·696e·7420·736e·6970·7065··Blueprint·snippe
 0004dda0:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di
0004dd90:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c 
0004dda0:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll 
0004ddb0:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i 
0004ddc0:·643d·2269·646d·3132·3539·3122·3e3c·7461··d="idm12591"><ta 
0004ddd0:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table0004ddb0:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c
 0004ddc0:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse
 0004ddd0:·2220·6964·3d22·6964·6d31·3235·3931·223e··"·id="idm12591">
 0004dde0:·3c70·7265·3e3c·636f·6465·3e0a·5b5b·7061··<pre><code>.[[pa
 0004ddf0:·636b·6167·6573·5d5d·0a6e·616d·6520·3d20··ckages]].name·=·
 0004de00:·2272·6561·7222·0a76·6572·7369·6f6e·203d··"rear".version·=
0004dde0:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t 
0004ddf0:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta 
0004de00:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed">< 
0004de10:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit 
0004de20:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</ 
0004de30:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
0004de40:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th> 
0004de50:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
0004de60:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot: 
0004de70:·3c2f·7468·3e3c·7464·3e66·616c·7365·3c2f··</th><td>false</ 
0004de80:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
0004de90:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t 
0004dea0:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t 
0004deb0:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre>< 
0004dec0:·636f·6465·3e0a·646e·6620·696e·7374·616c··code>.dnf·instal 
0004ded0:·6c20·7265·6172·0a3c·2f63·6f64·653e·3c2f··l·rear.</code></0004de10:·2022·2a22·0a3c·2f63·6f64·653e·3c2f·7072···"*".</code></pr
0004dee0:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla0004de20:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class
0004def0:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ0004de30:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes
0004df00:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle0004de40:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle="
0004df10:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data0004de50:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t
0004df20:·2d74·6172·6765·743d·2223·6964·6d31·3235··-target="#idm1250004de60:·6172·6765·743d·2223·6964·6d31·3235·3932··arget="#idm12592
0004df30:·3932·2220·7461·6269·6e64·6578·3d22·3022··92"·tabindex="0"0004de70:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r
0004df40:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a0004de80:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari
0004df50:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa0004de90:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals
0004df60:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti0004dea0:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa
0004df70:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·0004deb0:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr
0004df80:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi0004dec0:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat
 0004ded0:·696f·6e20·5075·7070·6574·2073·6e69·7070··ion·Puppet·snipp
0004df90:·6174·696f·6e20·416e·6163·6f6e·6461·2073··ation·Anaconda·s 
0004dfa0:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b 
0004dfb0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa 
0004dfc0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col 
0004dfd0:·6c61·7073·6522·2069·643d·2269·646d·3132··lapse"·id="idm12 
0004dfe0:·3539·3222·3e3c·7461·626c·6520·636c·6173··592"><table·clas 
0004dff0:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s 
0004e000:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor 
0004e010:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond 
0004e020:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C 
0004e030:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th>< 
0004e040:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
0004e050:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti 
0004e060:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low< 
0004e070:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0004e080:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td 
0004e090:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr> 
0004e0a0:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy 
0004e0b0:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable 
0004e0c0:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl 
0004e0d0:·653e·3c70·7265·3e3c·636f·6465·3e0a·7061··e><pre><code>.pa 
0004e0e0:·636b·6167·6520·2d2d·6164·643d·7265·6172··ckage·--add=rear 
0004e0f0:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></ 
0004e100:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt 
0004e110:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d 
0004e120:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll 
0004e130:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe 
0004e140:·743d·2223·6964·6d31·3235·3933·2220·7461··t="#idm12593"·ta 
0004e150:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role= 
0004e160:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex 
0004e170:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t 
0004e180:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t 
0004e190:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href=" 
0004e1a0:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation· 
0004e1b0:·4f53·4275·696c·6420·426c·7565·7072·696e··OSBuild·Blueprin 
0004e1c0:·7420·736e·6970·7065·7420·e287·b23c·2f61··t·snippet·...</a 
0004e1d0:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class= 
0004e1e0:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse· 
0004e1f0:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id 
0004e200:·6d31·3235·3933·223e·3c70·7265·3e3c·636f··m12593"><pre><co 
0004e210:·6465·3e0a·5b5b·7061·636b·6167·6573·5d5d··de>.[[packages]] 
0004e220:·0a6e·616d·6520·3d20·2272·6561·7222·0a76··.name·=·"rear".v 
0004e230:·6572·7369·6f6e·203d·2022·2a22·0a3c·2f63··ersion·=·"*".</c 
0004e240:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div> 
0004e250:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt 
0004e260:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data- 
0004e270:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse 
0004e280:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="# 
0004e290:·6964·6d31·3235·3934·2220·7461·6269·6e64··idm12594"·tabind 
0004e2a0:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but 
0004e2b0:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand 
0004e2c0:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title 
0004e2d0:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re 
0004e2e0:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!"> 
0004e2f0:·5265·6d65·6469·6174·696f·6e20·7363·7269··Remediation·scri 
0004e300:·7074·20e2·87b2·3c2f·613e·3c62·723e·3c64··pt·...</a><br><d0004dee0:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d
0004e310:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-0004def0:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-
0004e320:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps0004df00:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps
0004e330:·6522·2069·643d·2269·646d·3132·3539·3422··e"·id="idm12594"0004df10:·6522·2069·643d·2269·646d·3132·3539·3222··e"·id="idm12592"
0004e340:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t0004df20:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t
0004e350:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip0004df30:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip
0004e360:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere0004df40:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere
0004e370:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense0004df50:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense
0004e380:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl0004df60:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl
0004e390:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l0004df70:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l
0004e3a0:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>0004df80:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
0004e3b0:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:<0004df90:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:<
0004e3c0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>0004dfa0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
0004e3d0:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb0004dfb0:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb
0004e3e0:·6f6f·743a·3c2f·7468·3e3c·7464·3e66·616c··oot:</th><td>fal0004dfc0:·6f6f·743a·3c2f·7468·3e3c·7464·3e66·616c··oot:</th><td>fal
0004e3f0:·7365·3c2f·7464·3e3c·2f74·723e·3c74·723e··se</td></tr><tr>0004dfd0:·7365·3c2f·7464·3e3c·2f74·723e·3c74·723e··se</td></tr><tr>
0004e400:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t0004dfe0:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t
0004e410:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td0004dff0:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td
0004e420:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p0004e000:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p
 0004e010:·7265·3e3c·636f·6465·3e69·6e63·6c75·6465··re><code>include
0004e430:·7265·3e3c·636f·6465·3e0a·7061·636b·6167··re><code>.packag 
0004e440:·6520·696e·7374·616c·6c20·7265·6172·0a3c··e·install·rear.< 
0004e450:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di 
0004e460:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn· 
Max diff block lines reached; 436086/472960 bytes (92.20%) of diff not shown.
60.8 KB
html2text {}
    
Offset 1191, 52 lines modifiedOffset 1191, 38 lines modified
1191 ··-·CCE-83503-31191 ··-·CCE-83503-3
1192 ··-·enable_strategy1192 ··-·enable_strategy
1193 ··-·low_complexity1193 ··-·low_complexity
1194 ··-·low_disruption1194 ··-·low_disruption
1195 ··-·medium_severity1195 ··-·medium_severity
1196 ··-·no_reboot_needed1196 ··-·no_reboot_needed
1197 ··-·package_rear_installed1197 ··-·package_rear_installed
1198 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
1199 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
1200 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
1201 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
1202 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
1203 dnf·install·rear 
1204 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
1205 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
1206 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
1207 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
1208 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
1209 package·--add=rear 
1210 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81198 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
1211 [[packages]]1199 [[packages]]
1212 name·=·"rear"1200 name·=·"rear"
1213 version·=·"*"1201 version·=·"*"
1214 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
1215 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
1216 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
1217 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
1218 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
1219 package·install·rear 
1220 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81202 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1221 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1203 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1222 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1204 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1223 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1205 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1224 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1206 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1225 include·install_rear1207 include·install_rear
  
1226 class·install_rear·{1208 class·install_rear·{
1227 ··package·{·'rear':1209 ··package·{·'rear':
1228 ····ensure·=>·'installed',1210 ····ensure·=>·'installed',
1229 ··}1211 ··}
1230 }1212 }
 1213 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 1214 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1215 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1216 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1217 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 1218 package·install·rear
1231 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81219 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1232 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1220 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1233 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1221 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1234 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1222 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1235 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1223 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1236 #·Remediation·is·applicable·only·in·certain·platforms1224 #·Remediation·is·applicable·only·in·certain·platforms
1237 if·!·(·(·(·(·grep·-sqE·"^.*\.aarch64$"·/proc/sys/kernel/osrelease·||·grep·-sqE·"^aarch64$"·/proc/sys/kernel/arch;·)·&&·grep·-qP·"^ID=[\"']?ol[\"']?$"·"/etc/os-release"·&&·{·real="$(grep·-P·"^VERSION_ID=[\"']?[\w.]+[\"']?$"·/etc/os-release·|·sed·"s/^VERSION_ID=[\"']\?\([^\"']\+\)[\"']\?$/\1/")";·expected="9.0";·printf·"%s\n%s"·"$expected"·"$real"·|·sort·-VC;·}·)·||·(·(·grep·-sqE·"^.*\.aarch64$"·/proc/sys/kernel/osrelease·||·grep·-sqE·"^aarch64$"·/proc/sys/kernel/arch;·)·&&·grep·-qP·"^ID=[\"']?rhel[\"']?$"·"/etc/os-release"·&&·{·real="$(grep·-P·"^VERSION_ID=[\"']?[\w.]+[\"']?$"·/etc/os-release·|·sed·"s/^VERSION_ID=[\"']\?\([^\"']\+\)[\"']\?$/\1/")";·expected="9.0";·printf·"%s\n%s"·"$expected"·"$real"·|·sort·-VC;·}·)·||·(·grep·-qP·"^ID=[\"']?rhel[\"']?$"·"/etc/os-release"·&&·{·real="$(grep·-P·"^VERSION_ID=[\"']?[\w.]+[\"']?$"·/etc/os-release·|·sed·"s/^VERSION_ID=[\"']\?\([^\"']\+\)[\"']\?$/\1/")";·expected="8.4";·printf·"%s\n%s"·"$real"·"$expected"·|·sort·-VC;·}·&&·(·grep·-sqE·"^.*\.s390x$"·/proc/sys/kernel/osrelease·||·grep·-sqE·"^s390x$"·/proc/sys/kernel/arch;·)·)·)·);·then1225 if·!·(·(·(·(·grep·-sqE·"^.*\.aarch64$"·/proc/sys/kernel/osrelease·||·grep·-sqE·"^aarch64$"·/proc/sys/kernel/arch;·)·&&·grep·-qP·"^ID=[\"']?ol[\"']?$"·"/etc/os-release"·&&·{·real="$(grep·-P·"^VERSION_ID=[\"']?[\w.]+[\"']?$"·/etc/os-release·|·sed·"s/^VERSION_ID=[\"']\?\([^\"']\+\)[\"']\?$/\1/")";·expected="9.0";·printf·"%s\n%s"·"$expected"·"$real"·|·sort·-VC;·}·)·||·(·(·grep·-sqE·"^.*\.aarch64$"·/proc/sys/kernel/osrelease·||·grep·-sqE·"^aarch64$"·/proc/sys/kernel/arch;·)·&&·grep·-qP·"^ID=[\"']?rhel[\"']?$"·"/etc/os-release"·&&·{·real="$(grep·-P·"^VERSION_ID=[\"']?[\w.]+[\"']?$"·/etc/os-release·|·sed·"s/^VERSION_ID=[\"']\?\([^\"']\+\)[\"']\?$/\1/")";·expected="9.0";·printf·"%s\n%s"·"$expected"·"$real"·|·sort·-VC;·}·)·||·(·grep·-qP·"^ID=[\"']?rhel[\"']?$"·"/etc/os-release"·&&·{·real="$(grep·-P·"^VERSION_ID=[\"']?[\w.]+[\"']?$"·/etc/os-release·|·sed·"s/^VERSION_ID=[\"']\?\([^\"']\+\)[\"']\?$/\1/")";·expected="8.4";·printf·"%s\n%s"·"$real"·"$expected"·|·sort·-VC;·}·&&·(·grep·-sqE·"^.*\.s390x$"·/proc/sys/kernel/osrelease·||·grep·-sqE·"^s390x$"·/proc/sys/kernel/arch;·)·)·)·);·then
Offset 1244, 14 lines modifiedOffset 1230, 28 lines modified
1244 if·!·rpm·-q·--quiet·"rear"·;·then1230 if·!·rpm·-q·--quiet·"rear"·;·then
1245 ····dnf·install·-y·"rear"1231 ····dnf·install·-y·"rear"
1246 fi1232 fi
  
1247 else1233 else
1248 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'1234 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
1249 fi1235 fi
 1236 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 1237 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1238 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1239 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1240 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 1241 package·--add=rear
 1242 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 1243 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1244 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1245 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1246 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 1247 dnf·install·rear
1250 Group  ·Updating·Software·  Group·contains·6·rules1248 Group  ·Updating·Software·  Group·contains·6·rules
1251 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·dnf·command·line·tool·is·used·to·install·and·update·software·packages.·The·system·also·provides·a·graphical·software·update·tool·in·the·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·menu,·in·the·A\x8Ad\x8dm\x8mi\x8in\x8ni\x8is\x8st\x8tr\x8ra\x8at\x8ti\x8io\x8on\x8n·submenu,·called·S\x8So\x8of\x8ft\x8tw\x8wa\x8ar\x8re\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8e.1249 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·dnf·command·line·tool·is·used·to·install·and·update·software·packages.·The·system·also·provides·a·graphical·software·update·tool·in·the·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·menu,·in·the·A\x8Ad\x8dm\x8mi\x8in\x8ni\x8is\x8st\x8tr\x8ra\x8at\x8ti\x8io\x8on\x8n·submenu,·called·S\x8So\x8of\x8ft\x8tw\x8wa\x8ar\x8re\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8e.
  
1252 Red·Hat·Enterprise·Linux·9·systems·contain·an·installed·software·catalog·called·the·RPM·database,·which·records·metadata·of·installed·packages.·Consistently·using·dnf·or·the·graphical·S\x8So\x8of\x8ft\x8tw\x8wa\x8ar\x8re\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8e·for·all·software·installation·allows·for·insight·into·the·current·inventory·of·installed·software·on·the·system.1250 Red·Hat·Enterprise·Linux·9·systems·contain·an·installed·software·catalog·called·the·RPM·database,·which·records·metadata·of·installed·packages.·Consistently·using·dnf·or·the·graphical·S\x8So\x8of\x8ft\x8tw\x8wa\x8ar\x8re\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8e·for·all·software·installation·allows·for·insight·into·the·current·inventory·of·installed·software·on·the·system.
  
1253 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·d\x8dn\x8nf\x8f-\x8-a\x8au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8c·t\x8to\x8o·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·O\x8On\x8nl\x8ly\x8y·S\x8Se\x8ec\x8cu\x8ur\x8ri\x8it\x8ty\x8y·U\x8Up\x8pd\x8da\x8at\x8te\x8es\x8s·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*1251 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·d\x8dn\x8nf\x8f-\x8-a\x8au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8c·t\x8to\x8o·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·O\x8On\x8nl\x8ly\x8y·S\x8Se\x8ec\x8cu\x8ur\x8ri\x8it\x8ty\x8y·U\x8Up\x8pd\x8da\x8at\x8te\x8es\x8s·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
1254 To·configure·dnf-automatic·to·install·only·security·updates·automatically,·set·upgrade_type·to·security·under·[commands]·section·in·/etc/dnf/automatic.conf.1252 To·configure·dnf-automatic·to·install·only·security·updates·automatically,·set·upgrade_type·to·security·under·[commands]·section·in·/etc/dnf/automatic.conf.
Offset 2422, 52 lines modifiedOffset 2422, 38 lines modified
2422 ··-·NIST-800-53-CM-6(a)2422 ··-·NIST-800-53-CM-6(a)
2423 ··-·enable_strategy2423 ··-·enable_strategy
2424 ··-·low_complexity2424 ··-·low_complexity
2425 ··-·low_disruption2425 ··-·low_disruption
2426 ··-·medium_severity2426 ··-·medium_severity
2427 ··-·no_reboot_needed2427 ··-·no_reboot_needed
2428 ··-·package_rsyslog_installed2428 ··-·package_rsyslog_installed
2429 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
2430 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
2431 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
2432 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
2433 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
2434 dnf·install·rsyslog 
2435 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
2436 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
2437 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
2438 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
2439 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
2440 package·--add=rsyslog 
2441 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x82429 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
2442 [[packages]]2430 [[packages]]
2443 name·=·"rsyslog"2431 name·=·"rsyslog"
2444 version·=·"*"2432 version·=·"*"
2445 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
2446 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
2447 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
2448 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
2449 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
2450 package·install·rsyslog 
2451 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x82433 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
2452 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low2434 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
2453 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low2435 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
2454 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false2436 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
2455 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable2437 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
Max diff block lines reached; 56157/62262 bytes (90.19%) of diff not shown.
259 KB
./usr/share/doc/ssg-nondebian/ssg-rhel9-guide-hipaa.html
    
Offset 22665, 129 lines modifiedOffset 22665, 129 lines modified
00058880:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm00058880:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
00058890:·3136·3536·3822·2074·6162·696e·6465·783d··16568"·tabindex=00058890:·3136·3536·3822·2074·6162·696e·6465·783d··16568"·tabindex=
000588a0:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button000588a0:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button
000588b0:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=000588b0:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=
000588c0:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A000588c0:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A
000588d0:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea000588d0:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea
000588e0:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem000588e0:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem
000588f0:·6564·6961·7469·6f6e·204b·7562·6572·6e65··ediation·Kuberne000588f0:·6564·6961·7469·6f6e·2050·7570·7065·7420··ediation·Puppet·
00058900:·7465·7320·736e·6970·7065·7420·e287·b23c··tes·snippet·...<00058900:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><
00058910:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas00058910:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
00058920:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps00058920:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
00058930:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="00058930:·6c6c·6170·7365·2220·6964·3d22·6964·6d31··llapse"·id="idm1
00058940:·6964·6d31·3635·3638·223e·3c74·6162·6c65··idm16568"><table00058940:·3635·3638·223e·3c74·6162·6c65·2063·6c61··6568"><table·cla
00058950:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta00058950:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-
00058960:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl00058960:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo
00058970:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table00058970:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con
00058980:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>00058980:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>
00058990:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<00058990:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>
 000589a0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
 000589b0:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt
 000589c0:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low
 000589d0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
 000589e0:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t
 000589f0:·643e·6661·6c73·653c·2f74·643e·3c2f·7472··d>false</td></tr
 00058a00:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg
 00058a10:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl
 00058a20:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab
 00058a30:·6c65·3e3c·7072·653e·3c63·6f64·653e·696e··le><pre><code>in
 00058a40:·636c·7564·6520·6469·7361·626c·655f·6465··clude·disable_de
 00058a50:·6275·672d·7368·656c·6c0a·0a63·6c61·7373··bug-shell..class
 00058a60:·2064·6973·6162·6c65·5f64·6562·7567·2d73···disable_debug-s
 00058a70:·6865·6c6c·207b·0a20·2073·6572·7669·6365··hell·{.··service
 00058a80:·207b·2764·6562·7567·2d73·6865·6c6c·273a···{'debug-shell':
 00058a90:·0a20·2020·2065·6e61·626c·6520·3d26·6774··.····enable·=&gt
 00058aa0:·3b20·6661·6c73·652c·0a20·2020·2065·6e73··;·false,.····ens
 00058ab0:·7572·6520·3d26·6774·3b20·2773·746f·7070··ure·=&gt;·'stopp
 00058ac0:·6564·272c·0a20·207d·0a7d·0a3c·2f63·6f64··ed',.··}.}.</cod
 00058ad0:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a
 00058ae0:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn-
 00058af0:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to
 00058b00:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"·
 00058b10:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
 00058b20:·6d31·3635·3639·2220·7461·6269·6e64·6578··m16569"·tabindex
 00058b30:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto
 00058b40:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded
 00058b50:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="
 00058b60:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve
 00058b70:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re
 00058b80:·6d65·6469·6174·696f·6e20·7363·7269·7074··mediation·script
 00058b90:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
 00058ba0:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
 00058bb0:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
 00058bc0:·2069·643d·2269·646d·3136·3536·3922·3e3c···id="idm16569"><
 00058bd0:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab
 00058be0:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped
 00058bf0:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·
 00058c00:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"
 00058c10:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex
 00058c20:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low
 00058c30:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
 00058c40:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t
000589a0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>00058c50:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
000589b0:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis 
000589c0:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td 
000589d0:·3e6d·6564·6975·6d3c·2f74·643e·3c2f·7472··>medium</td></tr 
000589e0:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot:00058c60:·7472·3e3c·7472·3e3c·7468·3e52·6562·6f6f··tr><tr><th>Reboo
000589f0:·3c2f·7468·3e3c·7464·3e74·7275·653c·2f74··</th><td>true</t 
00058a00:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S 
00058a10:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td 
00058a20:·3e64·6973·6162·6c65·3c2f·7464·3e3c·2f74··>disable</td></t 
00058a30:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre>< 
00058a40:·636f·6465·3e61·7069·5665·7273·696f·6e3a··code>apiVersion: 
00058a50:·206d·6163·6869·6e65·636f·6e66·6967·7572···machineconfigur 
00058a60:·6174·696f·6e2e·6f70·656e·7368·6966·742e··ation.openshift. 
00058a70:·696f·2f76·310a·6b69·6e64·3a20·4d61·6368··io/v1.kind:·Mach 
00058a80:·696e·6543·6f6e·6669·670a·7370·6563·3a0a··ineConfig.spec:. 
00058a90:·2020·636f·6e66·6967·3a0a·2020·2020·6967····config:.····ig 
00058aa0:·6e69·7469·6f6e·3a0a·2020·2020·2020·7665··nition:.······ve 
00058ab0:·7273·696f·6e3a·2033·2e31·2e30·0a20·2020··rsion:·3.1.0.··· 
00058ac0:·2073·7973·7465·6d64·3a0a·2020·2020·2020···systemd:.······ 
00058ad0:·756e·6974·733a·0a20·2020·2020·202d·206e··units:.······-·n 
00058ae0:·616d·653a·2064·6562·7567·2d73·6865·6c6c··ame:·debug-shell 
00058af0:·2e73·6572·7669·6365·0a20·2020·2020·2020··.service.······· 
00058b00:·2065·6e61·626c·6564·3a20·6661·6c73·650a···enabled:·false. 
00058b10:·2020·2020·2020·2020·6d61·736b·3a20·7472··········mask:·tr00058c70:·743a·3c2f·7468·3e3c·7464·3e66·616c·7365··t:</th><td>false
 00058c80:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
 00058c90:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th>
 00058ca0:·3c74·643e·6469·7361·626c·653c·2f74·643e··<td>disable</td>
 00058cb0:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr
 00058cc0:·653e·3c63·6f64·653e·0a73·6572·7669·6365··e><code>.service
 00058cd0:·2064·6973·6162·6c65·2064·6562·7567·2d73···disable·debug-s
 00058ce0:·6865·6c6c·0a3c·2f63·6f64·653e·3c2f·7072··hell.</code></pr
 00058cf0:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class
 00058d00:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes
 00058d10:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle="
 00058d20:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t
 00058d30:·6172·6765·743d·2223·6964·6d31·3635·3730··arget="#idm16570
 00058d40:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r
 00058d50:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari
 00058d60:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals
 00058d70:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa
 00058d80:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr
 00058d90:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat
 00058da0:·696f·6e20·4b75·6265·726e·6574·6573·2073··ion·Kubernetes·s
 00058db0:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b
 00058dc0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
 00058dd0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
 00058de0:·6c61·7073·6522·2069·643d·2269·646d·3136··lapse"·id="idm16
 00058df0:·3537·3022·3e3c·7461·626c·6520·636c·6173··570"><table·clas
 00058e00:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s
 00058e10:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor
 00058e20:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond
 00058e30:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C
 00058e40:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><
 00058e50:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
 00058e60:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti
 00058e70:·6f6e·3a3c·2f74·683e·3c74·643e·6d65·6469··on:</th><td>medi
 00058e80:·756d·3c2f·7464·3e3c·2f74·723e·3c74·723e··um</td></tr><tr>
 00058e90:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th>
 00058ea0:·3c74·643e·7472·7565·3c2f·7464·3e3c·2f74··<td>true</td></t
 00058eb0:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate
 00058ec0:·6779·3a3c·2f74·683e·3c74·643e·6469·7361··gy:</th><td>disa
 00058ed0:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t
 00058ee0:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>
 00058ef0:·6170·6956·6572·7369·6f6e·3a20·6d61·6368··apiVersion:·mach
 00058f00:·696e·6563·6f6e·6669·6775·7261·7469·6f6e··ineconfiguration
 00058f10:·2e6f·7065·6e73·6869·6674·2e69·6f2f·7631··.openshift.io/v1
Max diff block lines reached; 217354/233804 bytes (92.96%) of diff not shown.
30.1 KB
html2text {}
    
Offset 1760, 14 lines modifiedOffset 1760, 34 lines modified
1760 ··-·medium_severity1760 ··-·medium_severity
1761 ··-·no_reboot_needed1761 ··-·no_reboot_needed
1762 ··-·service_debug-shell_disabled1762 ··-·service_debug-shell_disabled
1763 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81763 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
1764 [customizations.services]1764 [customizations.services]
1765 masked·=·["debug-shell"]1765 masked·=·["debug-shell"]
 1766 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 1767 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1768 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1769 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1770 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 1771 include·disable_debug-shell
  
 1772 class·disable_debug-shell·{
 1773 ··service·{'debug-shell':
 1774 ····enable·=>·false,
 1775 ····ensure·=>·'stopped',
 1776 ··}
 1777 }
 1778 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 1779 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1780 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1781 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1782 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
  
 1783 service·disable·debug-shell
1766 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81784 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1767 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1785 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1768 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium1786 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
1769 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true1787 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
1770 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable1788 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
1771 apiVersion:·machineconfiguration.openshift.io/v11789 apiVersion:·machineconfiguration.openshift.io/v1
1772 kind:·MachineConfig1790 kind:·MachineConfig
Offset 1779, 34 lines modifiedOffset 1799, 14 lines modified
1779 ······units:1799 ······units:
1780 ······-·name:·debug-shell.service1800 ······-·name:·debug-shell.service
1781 ········enabled:·false1801 ········enabled:·false
1782 ········mask:·true1802 ········mask:·true
1783 ······-·name:·debug-shell.socket1803 ······-·name:·debug-shell.socket
1784 ········enabled:·false1804 ········enabled:·false
1785 ········mask:·true1805 ········mask:·true
1786 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
1787 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
1788 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
1789 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
1790 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable 
  
1791 service·disable·debug-shell 
1792 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
1793 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
1794 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
1795 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
1796 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
1797 include·disable_debug-shell 
  
1798 class·disable_debug-shell·{ 
1799 ··service·{'debug-shell': 
1800 ····enable·=>·false, 
1801 ····ensure·=>·'stopped', 
1802 ··} 
1803 } 
1804 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81806 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1805 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1807 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1806 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1808 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1807 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1809 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1808 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable1810 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
1809 #·Remediation·is·applicable·only·in·certain·platforms1811 #·Remediation·is·applicable·only·in·certain·platforms
1810 if·rpm·--quiet·-q·kernel;·then1812 if·rpm·--quiet·-q·kernel;·then
Offset 3572, 14 lines modifiedOffset 3572, 34 lines modified
3572 ··-·medium_severity3572 ··-·medium_severity
3573 ··-·no_reboot_needed3573 ··-·no_reboot_needed
3574 ··-·service_autofs_disabled3574 ··-·service_autofs_disabled
3575 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x83575 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
3576 [customizations.services]3576 [customizations.services]
3577 masked·=·["autofs"]3577 masked·=·["autofs"]
 3578 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 3579 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 3580 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 3581 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 3582 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 3583 include·disable_autofs
  
 3584 class·disable_autofs·{
 3585 ··service·{'autofs':
 3586 ····enable·=>·false,
 3587 ····ensure·=>·'stopped',
 3588 ··}
 3589 }
 3590 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 3591 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 3592 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 3593 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 3594 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
  
 3595 service·disable·autofs
3578 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x83596 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
3579 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low3597 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
3580 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium3598 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
3581 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true3599 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
3582 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable3600 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
3583 apiVersion:·machineconfiguration.openshift.io/v13601 apiVersion:·machineconfiguration.openshift.io/v1
3584 kind:·MachineConfig3602 kind:·MachineConfig
Offset 3591, 34 lines modifiedOffset 3611, 14 lines modified
3591 ······units:3611 ······units:
3592 ······-·name:·autofs.service3612 ······-·name:·autofs.service
3593 ········enabled:·false3613 ········enabled:·false
3594 ········mask:·true3614 ········mask:·true
3595 ······-·name:·autofs.socket3615 ······-·name:·autofs.socket
3596 ········enabled:·false3616 ········enabled:·false
3597 ········mask:·true3617 ········mask:·true
3598 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
3599 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
3600 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
3601 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
3602 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable 
  
3603 service·disable·autofs 
3604 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
3605 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
3606 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
3607 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
3608 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
3609 include·disable_autofs 
  
3610 class·disable_autofs·{ 
Max diff block lines reached; 26398/30801 bytes (85.71%) of diff not shown.
696 KB
./usr/share/doc/ssg-nondebian/ssg-rhel9-guide-ism_o.html
    
Offset 17576, 207 lines modifiedOffset 17576, 207 lines modified
00044a70:·612d·7461·7267·6574·3d22·2369·646d·3834··a-target="#idm8400044a70:·612d·7461·7267·6574·3d22·2369·646d·3834··a-target="#idm84
00044a80:·3539·2220·7461·6269·6e64·6578·3d22·3022··59"·tabindex="0"00044a80:·3539·2220·7461·6269·6e64·6578·3d22·3022··59"·tabindex="0"
00044a90:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a00044a90:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
00044aa0:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa00044aa0:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
00044ab0:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti00044ab0:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
00044ac0:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·00044ac0:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
00044ad0:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi00044ad0:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
 00044ae0:·6174·696f·6e20·4f53·4275·696c·6420·426c··ation·OSBuild·Bl
 00044af0:·7565·7072·696e·7420·736e·6970·7065·7420··ueprint·snippet·
 00044b00:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·
 00044b10:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col
 00044b20:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·
 00044b30:·6964·3d22·6964·6d38·3435·3922·3e3c·7072··id="idm8459"><pr
 00044b40:·653e·3c63·6f64·653e·0a5b·5b70·6163·6b61··e><code>.[[packa
 00044b50:·6765·735d·5d0a·6e61·6d65·203d·2022·6169··ges]].name·=·"ai
 00044b60:·6465·220a·7665·7273·696f·6e20·3d20·222a··de".version·=·"*
00044ae0:·6174·696f·6e20·7363·7269·7074·20e2·87b2··ation·script·... 
00044af0:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla 
00044b00:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap 
00044b10:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id= 
00044b20:·2269·646d·3834·3539·223e·3c74·6162·6c65··"idm8459"><table 
00044b30:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta 
00044b40:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl 
00044b50:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table 
00044b60:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr> 
00044b70:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:< 
00044b80:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td> 
00044b90:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis 
00044ba0:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td 
00044bb0:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t 
00044bc0:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t 
00044bd0:·683e·3c74·643e·6661·6c73·653c·2f74·643e··h><td>false</td> 
00044be0:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str 
00044bf0:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e 
00044c00:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr>< 
00044c10:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod 
00044c20:·653e·0a64·6e66·2069·6e73·7461·6c6c·2061··e>.dnf·install·a 
00044c30:·6964·650a·3c2f·636f·6465·3e3c·2f70·7265··ide.</code></pre00044b70:·220a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··".</code></pre><
00044c40:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class=00044b80:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b
00044c50:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success00044b90:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"·
00044c60:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c00044ba0:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col
00044c70:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta00044bb0:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ
00044c80:·7267·6574·3d22·2369·646d·3834·3630·2220··rget="#idm8460"·00044bc0:·6574·3d22·2369·646d·3834·3630·2220·7461··et="#idm8460"·ta
00044c90:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol00044bd0:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
00044ca0:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-00044be0:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
00044cb0:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"00044bf0:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
00044cc0:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate00044c00:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
00044cd0:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href00044c10:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
00044ce0:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio00044c20:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
00044cf0:·6e20·416e·6163·6f6e·6461·2073·6e69·7070··n·Anaconda·snipp00044c30:·5075·7070·6574·2073·6e69·7070·6574·20e2··Puppet·snippet·.
00044d00:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d00044c40:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c
00044d10:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-00044c50:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
00044d20:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps00044c60:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
00044d30:·6522·2069·643d·2269·646d·3834·3630·223e··e"·id="idm8460">00044c70:·643d·2269·646d·3834·3630·223e·3c74·6162··d="idm8460"><tab
00044d40:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta00044c80:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·
00044d50:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe00044c90:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta
00044d60:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered00044ca0:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab
00044d70:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed00044cb0:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t
00044d80:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple00044cc0:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity
00044d90:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo00044cd0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
 00044ce0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D
 00044cf0:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><
 00044d00:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
 00044d10:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:<
 00044d20:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t
00044da0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><00044d30:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S
00044db0:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</00044d40:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td
 00044d50:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr
 00044d60:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c
 00044d70:·6f64·653e·696e·636c·7564·6520·696e·7374··ode>include·inst
 00044d80:·616c·6c5f·6169·6465·0a0a·636c·6173·7320··all_aide..class·
 00044d90:·696e·7374·616c·6c5f·6169·6465·207b·0a20··install_aide·{.·
 00044da0:·2070·6163·6b61·6765·207b·2027·6169·6465···package·{·'aide
 00044db0:·273a·0a20·2020·2065·6e73·7572·6520·3d26··':.····ensure·=&
 00044dc0:·6774·3b20·2769·6e73·7461·6c6c·6564·272c··gt;·'installed',
 00044dd0:·0a20·207d·0a7d·0a3c·2f63·6f64·653e·3c2f··.··}.}.</code></
 00044de0:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla
 00044df0:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ
 00044e00:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle
 00044e10:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data
 00044e20:·2d74·6172·6765·743d·2223·6964·6d38·3436··-target="#idm846
 00044e30:·3122·2074·6162·696e·6465·783d·2230·2220··1"·tabindex="0"·
 00044e40:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar
 00044e50:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal
 00044e60:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ
 00044e70:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h
 00044e80:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia
 00044e90:·7469·6f6e·2073·6372·6970·7420·e287·b23c··tion·script·...<
 00044ea0:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas
 00044eb0:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps
 00044ec0:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="
 00044ed0:·6964·6d38·3436·3122·3e3c·7461·626c·6520··idm8461"><table·
 00044ee0:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab
 00044ef0:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table
 00044f00:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-
 00044f10:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><
 00044f20:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</
00044dc0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><00044f30:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
00044dd0:·2f74·723e·3c74·723e·3c74·683e·5265·626f··/tr><tr><th>Rebo00044f40:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr
00044de0:·6f74·3a3c·2f74·683e·3c74·643e·6661·6c73··ot:</th><td>fals00044f50:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>
00044df0:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr><00044f60:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
00044e00:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th00044f70:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th
00044e10:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td>00044f80:·3e3c·7464·3e66·616c·7365·3c2f·7464·3e3c··><td>false</td><
00044e20:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr 
00044e30:·653e·3c63·6f64·653e·0a70·6163·6b61·6765··e><code>.package 
00044e40:·202d·2d61·6464·3d61·6964·650a·3c2f·636f···--add=aide.</co 
00044e50:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div>< 
00044e60:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn 
00044e70:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t 
00044e80:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse" 
00044e90:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i 
00044ea0:·646d·3834·3631·2220·7461·6269·6e64·6578··dm8461"·tabindex 
00044eb0:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto 
00044ec0:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded 
00044ed0:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title=" 
00044ee0:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve 
00044ef0:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re 
00044f00:·6d65·6469·6174·696f·6e20·4f53·4275·696c··mediation·OSBuil 
00044f10:·6420·426c·7565·7072·696e·7420·736e·6970··d·Blueprint·snip00044f90:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra
 00044fa0:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en
 00044fb0:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></
 00044fc0:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code
 00044fd0:·3e0a·7061·636b·6167·6520·696e·7374·616c··>.package·instal
 00044fe0:·6c20·6169·6465·0a3c·2f63·6f64·653e·3c2f··l·aide.</code></
 00044ff0:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla
 00045000:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ
 00045010:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle
Max diff block lines reached; 602708/629922 bytes (95.68%) of diff not shown.
80.8 KB
html2text {}
    
Offset 742, 52 lines modifiedOffset 742, 38 lines modified
742 ··-·PCI-DSSv4-11.5.2742 ··-·PCI-DSSv4-11.5.2
743 ··-·enable_strategy743 ··-·enable_strategy
744 ··-·low_complexity744 ··-·low_complexity
745 ··-·low_disruption745 ··-·low_disruption
746 ··-·medium_severity746 ··-·medium_severity
747 ··-·no_reboot_needed747 ··-·no_reboot_needed
748 ··-·package_aide_installed748 ··-·package_aide_installed
749 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
750 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
751 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
752 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
753 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
754 dnf·install·aide 
755 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
756 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
757 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
758 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
759 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
760 package·--add=aide 
761 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8749 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
762 [[packages]]750 [[packages]]
763 name·=·"aide"751 name·=·"aide"
764 version·=·"*"752 version·=·"*"
765 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
766 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
767 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
768 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
769 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
770 package·install·aide 
771 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8753 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
772 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low754 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
773 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low755 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
774 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false756 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
775 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable757 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
776 include·install_aide758 include·install_aide
  
777 class·install_aide·{759 class·install_aide·{
778 ··package·{·'aide':760 ··package·{·'aide':
779 ····ensure·=>·'installed',761 ····ensure·=>·'installed',
780 ··}762 ··}
781 }763 }
 764 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 765 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 766 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 767 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 768 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 769 package·install·aide
782 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8770 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
783 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low771 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
784 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low772 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
785 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false773 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
786 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable774 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
787 #·Remediation·is·applicable·only·in·certain·platforms775 #·Remediation·is·applicable·only·in·certain·platforms
788 if·rpm·--quiet·-q·kernel;·then776 if·rpm·--quiet·-q·kernel;·then
Offset 795, 14 lines modifiedOffset 781, 28 lines modified
795 if·!·rpm·-q·--quiet·"aide"·;·then781 if·!·rpm·-q·--quiet·"aide"·;·then
796 ····dnf·install·-y·"aide"782 ····dnf·install·-y·"aide"
797 fi783 fi
  
798 else784 else
799 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'785 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
800 fi786 fi
 787 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 788 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 789 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 790 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 791 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 792 package·--add=aide
 793 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 794 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 795 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 796 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 797 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 798 dnf·install·aide
801 Group  ·Federal·Information·Processing·Standard·(FIPS)·  Group·contains·2·rules799 Group  ·Federal·Information·Processing·Standard·(FIPS)·  Group·contains·2·rules
802 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·Federal·Information·Processing·Standard·(FIPS)·is·a·computer·security·standard·which·is·developed·by·the·U.S.·Government·and·industry·working·groups·to·validate·the·quality·of·cryptographic·modules.·The·FIPS·standard·provides·four·security·levels·to·ensure·adequate·coverage·of·different·industries,·implementation·of·cryptographic·modules,·and·organizational·sizes·and·requirements.800 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·Federal·Information·Processing·Standard·(FIPS)·is·a·computer·security·standard·which·is·developed·by·the·U.S.·Government·and·industry·working·groups·to·validate·the·quality·of·cryptographic·modules.·The·FIPS·standard·provides·four·security·levels·to·ensure·adequate·coverage·of·different·industries,·implementation·of·cryptographic·modules,·and·organizational·sizes·and·requirements.
  
803 FIPS·140-2·is·the·current·standard·for·validating·that·mechanisms·used·to·access·cryptographic·modules·utilize·authentication·that·meets·industry·and·government·requirements.·For·government·systems,·this·allows·Security·Levels·1,·2,·3,·or·4·for·use·on·Red·Hat·Enterprise·Linux·9.801 FIPS·140-2·is·the·current·standard·for·validating·that·mechanisms·used·to·access·cryptographic·modules·utilize·authentication·that·meets·industry·and·government·requirements.·For·government·systems,·this·allows·Security·Levels·1,·2,·3,·or·4·for·use·on·Red·Hat·Enterprise·Linux·9.
  
804 See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8c\x8c_\x8s\x8s_\x8r\x8r_\x8c\x8c_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8l\x8l_\x8i\x8i_\x8c\x8c_\x8a\x8a_\x8t\x8t_\x8i\x8i_\x8o\x8o_\x8n\x8n_\x8s\x8s_\x8/\x8/_\x8P\x8P_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x8h\x8h_\x8t\x8t_\x8m\x8m_\x8l\x8l·for·more·information.802 See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8c\x8c_\x8s\x8s_\x8r\x8r_\x8c\x8c_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8l\x8l_\x8i\x8i_\x8c\x8c_\x8a\x8a_\x8t\x8t_\x8i\x8i_\x8o\x8o_\x8n\x8n_\x8s\x8s_\x8/\x8/_\x8P\x8P_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x8h\x8h_\x8t\x8t_\x8m\x8m_\x8l\x8l·for·more·information.
805 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·D\x8Dr\x8ra\x8ac\x8cu\x8ut\x8t·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8du\x8ul\x8le\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*803 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·D\x8Dr\x8ra\x8ac\x8cu\x8ut\x8t·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8du\x8ul\x8le\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
Offset 1099, 52 lines modifiedOffset 1099, 38 lines modified
1099 ··-·PCI-DSSv4-2.2.61099 ··-·PCI-DSSv4-2.2.6
1100 ··-·enable_strategy1100 ··-·enable_strategy
1101 ··-·low_complexity1101 ··-·low_complexity
1102 ··-·low_disruption1102 ··-·low_disruption
1103 ··-·medium_severity1103 ··-·medium_severity
1104 ··-·no_reboot_needed1104 ··-·no_reboot_needed
1105 ··-·package_sudo_installed1105 ··-·package_sudo_installed
1106 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
1107 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
1108 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
1109 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
1110 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
1111 dnf·install·sudo 
1112 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
1113 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
1114 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
1115 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
1116 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
1117 package·--add=sudo 
1118 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81106 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
1119 [[packages]]1107 [[packages]]
1120 name·=·"sudo"1108 name·=·"sudo"
1121 version·=·"*"1109 version·=·"*"
1122 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
1123 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
1124 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
1125 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
1126 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
1127 package·install·sudo 
1128 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81110 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1129 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1111 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1130 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1112 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1131 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1113 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1132 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1114 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
Max diff block lines reached; 77551/82674 bytes (93.80%) of diff not shown.
653 KB
./usr/share/doc/ssg-nondebian/ssg-rhel9-guide-ospp.html
    
Offset 15862, 203 lines modifiedOffset 15862, 203 lines modified
0003df50:·6765·743d·2223·6964·6d39·3137·3022·2074··get="#idm9170"·t0003df50:·6765·743d·2223·6964·6d39·3137·3022·2074··get="#idm9170"·t
0003df60:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role0003df60:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
0003df70:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e0003df70:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
0003df80:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·0003df80:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
0003df90:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·0003df90:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
0003dfa0:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=0003dfa0:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
0003dfb0:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation0003dfb0:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
 0003dfc0:·204f·5342·7569·6c64·2042·6c75·6570·7269···OSBuild·Bluepri
 0003dfd0:·6e74·2073·6e69·7070·6574·20e2·87b2·3c2f··nt·snippet·...</
 0003dfe0:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
 0003dff0:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
 0003e000:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
 0003e010:·646d·3931·3730·223e·3c70·7265·3e3c·636f··dm9170"><pre><co
 0003e020:·6465·3e0a·5b5b·7061·636b·6167·6573·5d5d··de>.[[packages]]
 0003e030:·0a6e·616d·6520·3d20·2263·7279·7074·6f2d··.name·=·"crypto-
 0003e040:·706f·6c69·6369·6573·220a·7665·7273·696f··policies".versio
 0003e050:·6e20·3d20·222a·220a·3c2f·636f·6465·3e3c··n·=·"*".</code><
0003dfc0:·2073·6372·6970·7420·e287·b23c·2f61·3e3c···script·...</a>< 
0003dfd0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p 
0003dfe0:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co 
0003dff0:·6c6c·6170·7365·2220·6964·3d22·6964·6d39··llapse"·id="idm9 
0003e000:·3137·3022·3e3c·7461·626c·6520·636c·6173··170"><table·clas 
0003e010:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s 
0003e020:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor 
0003e030:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond 
0003e040:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C 
0003e050:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th>< 
0003e060:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
0003e070:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti 
0003e080:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low< 
0003e090:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0003e0a0:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td 
0003e0b0:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr> 
0003e0c0:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy 
0003e0d0:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable 
0003e0e0:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl 
0003e0f0:·653e·3c70·7265·3e3c·636f·6465·3e0a·646e··e><pre><code>.dn 
0003e100:·6620·696e·7374·616c·6c20·6372·7970·746f··f·install·crypto 
0003e110:·2d70·6f6c·6963·6965·730a·3c2f·636f·6465··-policies.</code 
0003e120:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a·0003e060:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl
0003e130:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s0003e070:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc
0003e140:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog0003e080:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl
0003e150:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d0003e090:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat
0003e160:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm0003e0a0:·612d·7461·7267·6574·3d22·2369·646d·3931··a-target="#idm91
0003e170:·3931·3731·2220·7461·6269·6e64·6578·3d22··9171"·tabindex="0003e0b0:·3731·2220·7461·6269·6e64·6578·3d22·3022··71"·tabindex="0"
0003e180:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"0003e0c0:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
0003e190:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="0003e0d0:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
0003e1a0:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac0003e0e0:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
0003e1b0:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal0003e0f0:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
0003e1c0:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme0003e100:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
 0003e110:·6174·696f·6e20·5075·7070·6574·2073·6e69··ation·Puppet·sni
0003e1d0:·6469·6174·696f·6e20·416e·6163·6f6e·6461··diation·Anaconda 
0003e1e0:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a> 
0003e1f0:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class=" 
0003e200:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c 
0003e210:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm 
0003e220:·3931·3731·223e·3c74·6162·6c65·2063·6c61··9171"><table·cla 
0003e230:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table- 
0003e240:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo 
0003e250:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con 
0003e260:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th> 
0003e270:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th> 
0003e280:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
0003e290:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt 
0003e2a0:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low 
0003e2b0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
0003e2c0:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t 
0003e2d0:·643e·6661·6c73·653c·2f74·643e·3c2f·7472··d>false</td></tr 
0003e2e0:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg 
0003e2f0:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl 
0003e300:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab 
0003e310:·6c65·3e3c·7072·653e·3c63·6f64·653e·0a70··le><pre><code>.p 
0003e320:·6163·6b61·6765·202d·2d61·6464·3d63·7279··ackage·--add=cry 
0003e330:·7074·6f2d·706f·6c69·6369·6573·0a3c·2f63··pto-policies.</c 
0003e340:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div> 
0003e350:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt 
0003e360:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data- 
0003e370:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse 
0003e380:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="# 
0003e390:·6964·6d39·3137·3222·2074·6162·696e·6465··idm9172"·tabinde 
0003e3a0:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt 
0003e3b0:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande 
0003e3c0:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title= 
0003e3d0:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev 
0003e3e0:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R 
0003e3f0:·656d·6564·6961·7469·6f6e·204f·5342·7569··emediation·OSBui 
0003e400:·6c64·2042·6c75·6570·7269·6e74·2073·6e69··ld·Blueprint·sni 
0003e410:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>0003e120:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>
0003e420:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane0003e130:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
0003e430:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla0003e140:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
0003e440:·7073·6522·2069·643d·2269·646d·3931·3732··pse"·id="idm91720003e150:·7073·6522·2069·643d·2269·646d·3931·3731··pse"·id="idm9171
0003e450:·223e·3c70·7265·3e3c·636f·6465·3e0a·5b5b··"><pre><code>.[[ 
0003e460:·7061·636b·6167·6573·5d5d·0a6e·616d·6520··packages]].name· 
0003e470:·3d20·2263·7279·7074·6f2d·706f·6c69·6369··=·"crypto-polici 
0003e480:·6573·220a·7665·7273·696f·6e20·3d20·222a··es".version·=·"* 
0003e490:·220a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··".</code></pre>< 
0003e4a0:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b 
0003e4b0:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"· 
0003e4c0:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col 
0003e4d0:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ 
0003e4e0:·6574·3d22·2369·646d·3931·3733·2220·7461··et="#idm9173"·ta 
0003e4f0:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role= 
0003e500:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex 
0003e510:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t 
0003e520:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t 
0003e530:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href=" 
0003e540:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation· 
0003e550:·7363·7269·7074·20e2·87b2·3c2f·613e·3c62··script·...</a><b 
0003e560:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa 
0003e570:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col 
0003e580:·6c61·7073·6522·2069·643d·2269·646d·3931··lapse"·id="idm91 
0003e590:·3733·223e·3c74·6162·6c65·2063·6c61·7373··73"><table·class0003e160:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="
0003e5a0:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st0003e170:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri
0003e5b0:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord0003e180:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border
0003e5c0:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde0003e190:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens
0003e5d0:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co0003e1a0:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp
0003e5e0:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t0003e1b0:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>
0003e5f0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><0003e1c0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
0003e600:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio0003e1d0:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:
0003e610:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</0003e1e0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
0003e620:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>0003e1f0:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re
0003e630:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td>0003e200:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa
0003e640:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr><0003e210:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr
0003e650:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:0003e220:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</
0003e660:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<0003e230:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t
0003e670:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table0003e240:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><
0003e680:·3e3c·7072·653e·3c63·6f64·653e·0a70·6163··><pre><code>.pac 
Max diff block lines reached; 568512/595174 bytes (95.52%) of diff not shown.
71.6 KB
html2text {}
    
Offset 167, 61 lines modifiedOffset 167, 61 lines modified
167 ··-·DISA-STIG-RHEL-09-215100167 ··-·DISA-STIG-RHEL-09-215100
168 ··-·enable_strategy168 ··-·enable_strategy
169 ··-·low_complexity169 ··-·low_complexity
170 ··-·low_disruption170 ··-·low_disruption
171 ··-·medium_severity171 ··-·medium_severity
172 ··-·no_reboot_needed172 ··-·no_reboot_needed
173 ··-·package_crypto-policies_installed173 ··-·package_crypto-policies_installed
174 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
175 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
176 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
177 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
178 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
179 dnf·install·crypto-policies 
180 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
181 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
182 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
183 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
184 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
185 package·--add=crypto-policies 
186 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8174 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
187 [[packages]]175 [[packages]]
188 name·=·"crypto-policies"176 name·=·"crypto-policies"
189 version·=·"*"177 version·=·"*"
190 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
191 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
192 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
193 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
194 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
195 package·install·crypto-policies 
196 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8178 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
197 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low179 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
198 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low180 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
199 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false181 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
200 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable182 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
201 include·install_crypto-policies183 include·install_crypto-policies
  
202 class·install_crypto-policies·{184 class·install_crypto-policies·{
203 ··package·{·'crypto-policies':185 ··package·{·'crypto-policies':
204 ····ensure·=>·'installed',186 ····ensure·=>·'installed',
205 ··}187 ··}
206 }188 }
 189 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 190 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 191 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 192 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 193 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 194 package·install·crypto-policies
207 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8195 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
208 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low196 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
209 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low197 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
210 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false198 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
211 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable199 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
212 if·!·rpm·-q·--quiet·"crypto-policies"·;·then200 if·!·rpm·-q·--quiet·"crypto-policies"·;·then
213 ····dnf·install·-y·"crypto-policies"201 ····dnf·install·-y·"crypto-policies"
214 fi202 fi
 203 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 204 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 205 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 206 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 207 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 208 package·--add=crypto-policies
 209 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 210 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 211 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 212 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 213 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 214 dnf·install·crypto-policies
215 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8og\x8gr\x8ra\x8ap\x8ph\x8hy\x8y·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*215 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8og\x8gr\x8ra\x8ap\x8ph\x8hy\x8y·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
216 To·configure·the·system·cryptography·policy·to·use·ciphers·only·from·the·FIPS:OSPP·policy,·run·the·following·command:216 To·configure·the·system·cryptography·policy·to·use·ciphers·only·from·the·FIPS:OSPP·policy,·run·the·following·command:
217 $·sudo·update-crypto-policies·--set·FIPS:OSPP217 $·sudo·update-crypto-policies·--set·FIPS:OSPP
218 The·rule·checks·if·settings·for·selected·crypto·policy·are·configured·as·expected.·Configuration·files·in·the·/etc/crypto-policies/back-ends·are·either·symlinks·to·correct·files·provided·by·Crypto-policies·package·or·they·are·regular·files·in·case·crypto·policy·customizations·are·applied.·Crypto·policies·may·be·customized·by·crypto·policy·modules,·in·which·case·it·is·delimited·from·the·base·policy·using·a·colon.218 The·rule·checks·if·settings·for·selected·crypto·policy·are·configured·as·expected.·Configuration·files·in·the·/etc/crypto-policies/back-ends·are·either·symlinks·to·correct·files·provided·by·Crypto-policies·package·or·they·are·regular·files·in·case·crypto·policy·customizations·are·applied.·Crypto·policies·may·be·customized·by·crypto·policy·modules,·in·which·case·it·is·delimited·from·the·base·policy·using·a·colon.
219 Warning: ·The·system·needs·to·be·rebooted·for·these·changes·to·take·effect.219 Warning: ·The·system·needs·to·be·rebooted·for·these·changes·to·take·effect.
220 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8n\x8n_\x8v\x8v_\x8l\x8l_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8/\x8/_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8/\x8/_\x8N\x8N_\x8I\x8I_\x8S\x8S_\x8T\x8T_\x8.\x8._\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x81\x81_\x84\x84_\x80\x80_\x8-\x8-_\x82\x82_\x8.\x8._\x8p\x8p_\x8d\x8d_\x8f\x8f·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.220 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8n\x8n_\x8v\x8v_\x8l\x8l_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8/\x8/_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8/\x8/_\x8N\x8N_\x8I\x8I_\x8S\x8S_\x8T\x8T_\x8.\x8._\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x81\x81_\x84\x84_\x80\x80_\x8-\x8-_\x82\x82_\x8.\x8._\x8p\x8p_\x8d\x8d_\x8f\x8f·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.
221 Rationale:···Centralized·cryptographic·policies·simplify·applying·secure·ciphers·across·an·operating·system·and·the·applications·that·run·on·that·operating·system.·Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.221 Rationale:···Centralized·cryptographic·policies·simplify·applying·secure·ciphers·across·an·operating·system·and·the·applications·that·run·on·that·operating·system.·Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.
Offset 571, 29 lines modifiedOffset 571, 29 lines modified
571 ·············_\x8o_\x8s_\x8p_\x8p···········FMT_SMF_EXT.1571 ·············_\x8o_\x8s_\x8p_\x8p···········FMT_SMF_EXT.1
572 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000341-GPOS-00132,·SRG-OS-000480-GPOS-00227572 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000341-GPOS-00132,·SRG-OS-000480-GPOS-00227
573 ·············_\x8a_\x8p_\x8p_\x8-_\x8s_\x8r_\x8g_\x8-_\x8c_\x8t_\x8r····SRG-APP-000357-CTR-000800573 ·············_\x8a_\x8p_\x8p_\x8-_\x8s_\x8r_\x8g_\x8-_\x8c_\x8t_\x8r····SRG-APP-000357-CTR-000800
574 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R71574 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R71
575 ·············_\x8c_\x8i_\x8s············1.1.2.7.1575 ·············_\x8c_\x8i_\x8s············1.1.2.7.1
576 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-09-231030576 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-09-231030
577 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-257847r1044924_rule577 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-257847r1044924_rule
578 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
579 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
580 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high 
581 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
582 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
583 part·/var/log/audit 
584 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8578 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
585 [[customizations.filesystem]]579 [[customizations.filesystem]]
586 mountpoint·=·"/var/log/audit"580 mountpoint·=·"/var/log/audit"
587 size·=·10737418240581 size·=·10737418240
588 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8582 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
589 logvol·/var/log/audit·10240583 logvol·/var/log/audit·10240
 584 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 585 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 586 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high
 587 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 588 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 589 part·/var/log/audit
590 Group  ·Sudo·  Group·contains·1·rule590 Group  ·Sudo·  Group·contains·1·rule
591 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Sudo,·which·stands·for·"su·'do'",·provides·the·ability·to·delegate·authority·to·certain·users,·groups·of·users,·or·system·administrators.·When·configured·for·system·users·and/or·groups,·Sudo·can·allow·a·user·or·group·to·execute·privileged·commands·that·normally·only·root·is·allowed·to·execute.591 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Sudo,·which·stands·for·"su·'do'",·provides·the·ability·to·delegate·authority·to·certain·users,·groups·of·users,·or·system·administrators.·When·configured·for·system·users·and/or·groups,·Sudo·can·allow·a·user·or·group·to·execute·privileged·commands·that·normally·only·root·is·allowed·to·execute.
  
592 For·more·information·on·Sudo·and·addition·Sudo·configuration·options,·see·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8w\x8w_\x8w\x8w_\x8w\x8w_\x8.\x8._\x8s\x8s_\x8u\x8u_\x8d\x8d_\x8o\x8o_\x8.\x8._\x8w\x8w_\x8s\x8s.592 For·more·information·on·Sudo·and·addition·Sudo·configuration·options,·see·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8w\x8w_\x8w\x8w_\x8w\x8w_\x8.\x8._\x8s\x8s_\x8u\x8u_\x8d\x8d_\x8o\x8o_\x8.\x8._\x8w\x8w_\x8s\x8s.
593 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·s\x8su\x8ud\x8do\x8o·P\x8Pa\x8ac\x8ck\x8ka\x8ag\x8ge\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*593 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·s\x8su\x8ud\x8do\x8o·P\x8Pa\x8ac\x8ck\x8ka\x8ag\x8ge\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
594 The·sudo·package·can·be·installed·with·the·following·command:594 The·sudo·package·can·be·installed·with·the·following·command:
595 $·sudo·dnf·install·sudo595 $·sudo·dnf·install·sudo
Offset 645, 52 lines modifiedOffset 645, 38 lines modified
645 ··-·PCI-DSSv4-2.2.6645 ··-·PCI-DSSv4-2.2.6
646 ··-·enable_strategy646 ··-·enable_strategy
647 ··-·low_complexity647 ··-·low_complexity
648 ··-·low_disruption648 ··-·low_disruption
649 ··-·medium_severity649 ··-·medium_severity
650 ··-·no_reboot_needed650 ··-·no_reboot_needed
651 ··-·package_sudo_installed651 ··-·package_sudo_installed
Max diff block lines reached; 65537/73279 bytes (89.43%) of diff not shown.
638 KB
./usr/share/doc/ssg-nondebian/ssg-rhel9-guide-pci-dss.html
    
Offset 16795, 207 lines modifiedOffset 16795, 207 lines modified
000419a0:·6765·743d·2223·6964·6d38·3435·3922·2074··get="#idm8459"·t000419a0:·6765·743d·2223·6964·6d38·3435·3922·2074··get="#idm8459"·t
000419b0:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role000419b0:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
000419c0:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e000419c0:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
000419d0:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·000419d0:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
000419e0:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·000419e0:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
000419f0:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=000419f0:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
00041a00:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation00041a00:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
 00041a10:·204f·5342·7569·6c64·2042·6c75·6570·7269···OSBuild·Bluepri
 00041a20:·6e74·2073·6e69·7070·6574·20e2·87b2·3c2f··nt·snippet·...</
 00041a30:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
 00041a40:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
 00041a50:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
 00041a60:·646d·3834·3539·223e·3c70·7265·3e3c·636f··dm8459"><pre><co
 00041a70:·6465·3e0a·5b5b·7061·636b·6167·6573·5d5d··de>.[[packages]]
 00041a80:·0a6e·616d·6520·3d20·2261·6964·6522·0a76··.name·=·"aide".v
 00041a90:·6572·7369·6f6e·203d·2022·2a22·0a3c·2f63··ersion·=·"*".</c
00041a10:·2073·6372·6970·7420·e287·b23c·2f61·3e3c···script·...</a>< 
00041a20:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p 
00041a30:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co 
00041a40:·6c6c·6170·7365·2220·6964·3d22·6964·6d38··llapse"·id="idm8 
00041a50:·3435·3922·3e3c·7461·626c·6520·636c·6173··459"><table·clas 
00041a60:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s 
00041a70:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor 
00041a80:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond 
00041a90:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C 
00041aa0:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th>< 
00041ab0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
00041ac0:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti 
00041ad0:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low< 
00041ae0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
00041af0:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td 
00041b00:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr> 
00041b10:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy 
00041b20:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable 
00041b30:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl 
00041b40:·653e·3c70·7265·3e3c·636f·6465·3e0a·646e··e><pre><code>.dn 
00041b50:·6620·696e·7374·616c·6c20·6169·6465·0a3c··f·install·aide.< 
00041b60:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di00041aa0:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div>
00041b70:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn·00041ab0:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt
00041b80:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat00041ac0:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data-
00041b90:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap00041ad0:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse
00041ba0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=00041ae0:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
00041bb0:·2223·6964·6d38·3436·3022·2074·6162·696e··"#idm8460"·tabin00041af0:·6964·6d38·3436·3022·2074·6162·696e·6465··idm8460"·tabinde
00041bc0:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu00041b00:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt
00041bd0:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan00041b10:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande
00041be0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl00041b20:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=
00041bf0:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r00041b30:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev
00041c00:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"00041b40:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R
00041c10:·3e52·656d·6564·6961·7469·6f6e·2041·6e61··>Remediation·Ana 
00041c20:·636f·6e64·6120·736e·6970·7065·7420·e287··conda·snippet·..00041b50:·656d·6564·6961·7469·6f6e·2050·7570·7065··emediation·Puppe
 00041b60:·7420·736e·6970·7065·7420·e287·b23c·2f61··t·snippet·...</a
00041c30:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl00041b70:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
00041c40:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla00041b80:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
00041c50:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id00041b90:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
00041c60:·3d22·6964·6d38·3436·3022·3e3c·7461·626c··="idm8460"><tabl00041ba0:·6d38·3436·3022·3e3c·7461·626c·6520·636c··m8460"><table·cl
00041c70:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t00041bb0:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table
00041c80:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab00041bc0:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b
00041c90:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl00041bd0:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co
00041ca0:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr00041be0:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th
00041cb0:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:00041bf0:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th
00041cc0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td00041c00:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
00041cd0:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di00041c10:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup
00041ce0:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t00041c20:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo
 00041c30:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
 00041c40:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th><
 00041c50:·7464·3e66·616c·7365·3c2f·7464·3e3c·2f74··td>false</td></t
 00041c60:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate
 00041c70:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab
 00041c80:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta
 00041c90:·626c·653e·3c70·7265·3e3c·636f·6465·3e69··ble><pre><code>i
 00041ca0:·6e63·6c75·6465·2069·6e73·7461·6c6c·5f61··nclude·install_a
 00041cb0:·6964·650a·0a63·6c61·7373·2069·6e73·7461··ide..class·insta
 00041cc0:·6c6c·5f61·6964·6520·7b0a·2020·7061·636b··ll_aide·{.··pack
 00041cd0:·6167·6520·7b20·2761·6964·6527·3a0a·2020··age·{·'aide':.··
 00041ce0:·2020·656e·7375·7265·203d·2667·743b·2027····ensure·=&gt;·'
 00041cf0:·696e·7374·616c·6c65·6427·2c0a·2020·7d0a··installed',.··}.
 00041d00:·7d0a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··}.</code></pre><
 00041d10:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b
 00041d20:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"·
 00041d30:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col
 00041d40:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ
 00041d50:·6574·3d22·2369·646d·3834·3631·2220·7461··et="#idm8461"·ta
 00041d60:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
 00041d70:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
 00041d80:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
 00041d90:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
 00041da0:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
 00041db0:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
 00041dc0:·7363·7269·7074·20e2·87b2·3c2f·613e·3c62··script·...</a><b
 00041dd0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
 00041de0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
 00041df0:·6c61·7073·6522·2069·643d·2269·646d·3834··lapse"·id="idm84
 00041e00:·3631·223e·3c74·6162·6c65·2063·6c61·7373··61"><table·class
 00041e10:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st
 00041e20:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord
 00041e30:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde
 00041e40:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co
 00041e50:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t
00041cf0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><00041e60:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
00041d00:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</ 
00041d10:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td00041e70:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio
 00041e80:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</
00041d20:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St00041e90:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
00041d30:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>00041ea0:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td>
00041d40:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr> 
00041d50:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co 
00041d60:·6465·3e0a·7061·636b·6167·6520·2d2d·6164··de>.package·--ad 
00041d70:·643d·6169·6465·0a3c·2f63·6f64·653e·3c2f··d=aide.</code></ 
00041d80:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla 
00041d90:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ 
00041da0:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle 
00041db0:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data 
00041dc0:·2d74·6172·6765·743d·2223·6964·6d38·3436··-target="#idm846 
00041dd0:·3122·2074·6162·696e·6465·783d·2230·2220··1"·tabindex="0"· 
00041de0:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar 
00041df0:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal 
00041e00:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ 
00041e10:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h 
00041e20:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia 
00041e30:·7469·6f6e·204f·5342·7569·6c64·2042·6c75··tion·OSBuild·Blu 
00041e40:·6570·7269·6e74·2073·6e69·7070·6574·20e2··eprint·snippet·.00041eb0:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr><
 00041ec0:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:
 00041ed0:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<
 00041ee0:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table
 00041ef0:·3e3c·7072·653e·3c63·6f64·653e·0a70·6163··><pre><code>.pac
 00041f00:·6b61·6765·2069·6e73·7461·6c6c·2061·6964··kage·install·aid
 00041f10:·650a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··e.</code></pre><
Max diff block lines reached; 550190/577404 bytes (95.29%) of diff not shown.
74.1 KB
html2text {}
    
Offset 553, 52 lines modifiedOffset 553, 38 lines modified
553 ··-·PCI-DSSv4-11.5.2553 ··-·PCI-DSSv4-11.5.2
554 ··-·enable_strategy554 ··-·enable_strategy
555 ··-·low_complexity555 ··-·low_complexity
556 ··-·low_disruption556 ··-·low_disruption
557 ··-·medium_severity557 ··-·medium_severity
558 ··-·no_reboot_needed558 ··-·no_reboot_needed
559 ··-·package_aide_installed559 ··-·package_aide_installed
560 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
561 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
562 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
563 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
564 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
565 dnf·install·aide 
566 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
567 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
568 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
569 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
570 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
571 package·--add=aide 
572 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8560 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
573 [[packages]]561 [[packages]]
574 name·=·"aide"562 name·=·"aide"
575 version·=·"*"563 version·=·"*"
576 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
577 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
578 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
579 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
580 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
581 package·install·aide 
582 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8564 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
583 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low565 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
584 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low566 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
585 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false567 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
586 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable568 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
587 include·install_aide569 include·install_aide
  
588 class·install_aide·{570 class·install_aide·{
589 ··package·{·'aide':571 ··package·{·'aide':
590 ····ensure·=>·'installed',572 ····ensure·=>·'installed',
591 ··}573 ··}
592 }574 }
 575 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 576 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 577 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 578 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 579 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 580 package·install·aide
593 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8581 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
594 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low582 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
595 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low583 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
596 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false584 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
597 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable585 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
598 #·Remediation·is·applicable·only·in·certain·platforms586 #·Remediation·is·applicable·only·in·certain·platforms
599 if·rpm·--quiet·-q·kernel;·then587 if·rpm·--quiet·-q·kernel;·then
Offset 606, 14 lines modifiedOffset 592, 28 lines modified
606 if·!·rpm·-q·--quiet·"aide"·;·then592 if·!·rpm·-q·--quiet·"aide"·;·then
607 ····dnf·install·-y·"aide"593 ····dnf·install·-y·"aide"
608 fi594 fi
  
609 else595 else
610 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'596 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
611 fi597 fi
 598 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 599 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 600 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 601 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 602 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 603 package·--add=aide
 604 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 605 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 606 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 607 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 608 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 609 dnf·install·aide
612 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*610 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
613 Run·the·following·command·to·generate·a·new·database:611 Run·the·following·command·to·generate·a·new·database:
614 $·sudo·/usr/sbin/aide·--init612 $·sudo·/usr/sbin/aide·--init
615 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:613 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
616 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz614 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
617 To·initiate·a·manual·check,·run·the·following·command:615 To·initiate·a·manual·check,·run·the·following·command:
618 $·sudo·/usr/sbin/aide·--check616 $·sudo·/usr/sbin/aide·--check
Offset 2817, 52 lines modifiedOffset 2817, 38 lines modified
2817 ··-·PCI-DSSv4-2.2.62817 ··-·PCI-DSSv4-2.2.6
2818 ··-·enable_strategy2818 ··-·enable_strategy
2819 ··-·low_complexity2819 ··-·low_complexity
2820 ··-·low_disruption2820 ··-·low_disruption
2821 ··-·medium_severity2821 ··-·medium_severity
2822 ··-·no_reboot_needed2822 ··-·no_reboot_needed
2823 ··-·package_sudo_installed2823 ··-·package_sudo_installed
2824 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
2825 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
2826 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
2827 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
2828 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
2829 dnf·install·sudo 
2830 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
2831 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
2832 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
2833 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
2834 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
2835 package·--add=sudo 
2836 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x82824 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
2837 [[packages]]2825 [[packages]]
2838 name·=·"sudo"2826 name·=·"sudo"
2839 version·=·"*"2827 version·=·"*"
2840 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
2841 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
2842 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
2843 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
2844 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
2845 package·install·sudo 
2846 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x82828 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
2847 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low2829 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
2848 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low2830 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
2849 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false2831 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
2850 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable2832 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
Max diff block lines reached; 71160/75855 bytes (93.81%) of diff not shown.
1.86 MB
./usr/share/doc/ssg-nondebian/ssg-rhel9-guide-stig.html
    
Offset 15236, 207 lines modifiedOffset 15236, 207 lines modified
0003b830:·7461·7267·6574·3d22·2369·646d·3834·3539··target="#idm84590003b830:·7461·7267·6574·3d22·2369·646d·3834·3539··target="#idm8459
0003b840:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r0003b840:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r
0003b850:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari0003b850:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari
0003b860:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals0003b860:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals
0003b870:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa0003b870:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa
0003b880:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr0003b880:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr
0003b890:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat0003b890:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat
 0003b8a0:·696f·6e20·4f53·4275·696c·6420·426c·7565··ion·OSBuild·Blue
 0003b8b0:·7072·696e·7420·736e·6970·7065·7420·e287··print·snippet·..
 0003b8c0:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl
 0003b8d0:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla
 0003b8e0:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id
 0003b8f0:·3d22·6964·6d38·3435·3922·3e3c·7072·653e··="idm8459"><pre>
 0003b900:·3c63·6f64·653e·0a5b·5b70·6163·6b61·6765··<code>.[[package
 0003b910:·735d·5d0a·6e61·6d65·203d·2022·6169·6465··s]].name·=·"aide
 0003b920:·220a·7665·7273·696f·6e20·3d20·222a·220a··".version·=·"*".
0003b8a0:·696f·6e20·7363·7269·7074·20e2·87b2·3c2f··ion·script·...</ 
0003b8b0:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class 
0003b8c0:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse 
0003b8d0:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i 
0003b8e0:·646d·3834·3539·223e·3c74·6162·6c65·2063··dm8459"><table·c 
0003b8f0:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl 
0003b900:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table- 
0003b910:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c 
0003b920:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t 
0003b930:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t 
0003b940:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></ 
0003b950:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru 
0003b960:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l 
0003b970:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr> 
0003b980:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th> 
0003b990:·3c74·643e·6661·6c73·653c·2f74·643e·3c2f··<td>false</td></ 
0003b9a0:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat 
0003b9b0:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena 
0003b9c0:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t 
0003b9d0:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code> 
0003b9e0:·0a64·6e66·2069·6e73·7461·6c6c·2061·6964··.dnf·install·aid 
0003b9f0:·650a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··e.</code></pre><0003b930:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d
0003ba00:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b0003b940:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn
0003ba10:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"·0003b950:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da
0003ba20:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col0003b960:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla
0003ba30:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ0003b970:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
0003ba40:·6574·3d22·2369·646d·3834·3630·2220·7461··et="#idm8460"·ta0003b980:·3d22·2369·646d·3834·3630·2220·7461·6269··="#idm8460"·tabi
0003ba50:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=0003b990:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
0003ba60:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex0003b9a0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
0003ba70:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t0003b9b0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
0003ba80:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t0003b9c0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
0003ba90:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="0003b9d0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
0003baa0:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·0003b9e0:·223e·5265·6d65·6469·6174·696f·6e20·5075··">Remediation·Pu
0003bab0:·416e·6163·6f6e·6461·2073·6e69·7070·6574··Anaconda·snippet0003b9f0:·7070·6574·2073·6e69·7070·6574·20e2·87b2··ppet·snippet·...
0003bac0:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div0003ba00:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
0003bad0:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co0003ba10:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
0003bae0:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse" 
0003baf0:·2069·643d·2269·646d·3834·3630·223e·3c74···id="idm8460"><t 
0003bb00:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl 
0003bb10:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped· 
0003bb20:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t 
0003bb30:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed"> 
0003bb40:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi 
0003bb50:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low< 
0003bb60:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0003bb70:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th 
0003bb80:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t 
0003bb90:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot 
0003bba0:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false< 
0003bbb0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0003bbc0:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th>< 
0003bbd0:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></ 
0003bbe0:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre> 
0003bbf0:·3c63·6f64·653e·0a70·6163·6b61·6765·202d··<code>.package·- 
0003bc00:·2d61·6464·3d61·6964·650a·3c2f·636f·6465··-add=aide.</code 
0003bc10:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a· 
0003bc20:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s 
0003bc30:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog 
0003bc40:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d0003ba20:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
 0003ba30:·2269·646d·3834·3630·223e·3c74·6162·6c65··"idm8460"><table
0003bc50:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm 
0003bc60:·3834·3631·2220·7461·6269·6e64·6578·3d22··8461"·tabindex=" 
0003bc70:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button" 
0003bc80:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded=" 
0003bc90:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac 
0003bca0:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal 
0003bcb0:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme 
0003bcc0:·6469·6174·696f·6e20·4f53·4275·696c·6420··diation·OSBuild· 
0003bcd0:·426c·7565·7072·696e·7420·736e·6970·7065··Blueprint·snippe 
0003bce0:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di 
0003bcf0:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c 
0003bd00:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse 
0003bd10:·2220·6964·3d22·6964·6d38·3436·3122·3e3c··"·id="idm8461">< 
0003bd20:·7072·653e·3c63·6f64·653e·0a5b·5b70·6163··pre><code>.[[pac 
0003bd30:·6b61·6765·735d·5d0a·6e61·6d65·203d·2022··kages]].name·=·" 
0003bd40:·6169·6465·220a·7665·7273·696f·6e20·3d20··aide".version·=· 
0003bd50:·222a·220a·3c2f·636f·6465·3e3c·2f70·7265··"*".</code></pre 
0003bd60:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class= 
0003bd70:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success 
0003bd80:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c 
0003bd90:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta 
0003bda0:·7267·6574·3d22·2369·646d·3834·3632·2220··rget="#idm8462"· 
0003bdb0:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol 
0003bdc0:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria- 
0003bdd0:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false" 
0003bde0:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate 
0003bdf0:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href 
0003be00:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio 
0003be10:·6e20·7363·7269·7074·20e2·87b2·3c2f·613e··n·script·...</a> 
0003be20:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class=" 
0003be30:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c 
0003be40:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm 
0003be50:·3834·3632·223e·3c74·6162·6c65·2063·6c61··8462"><table·cla 
0003be60:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-0003ba40:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta
0003be70:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo0003ba50:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl
0003be80:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con0003ba60:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table
0003be90:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>0003ba70:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>
0003bea0:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>0003ba80:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<
0003beb0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr0003ba90:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
0003bec0:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt0003baa0:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis
0003bed0:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low0003bab0:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td
0003bee0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t0003bac0:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
0003bef0:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t0003bad0:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t
 0003bae0:·683e·3c74·643e·6661·6c73·653c·2f74·643e··h><td>false</td>
 0003baf0:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str
 0003bb00:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e
0003bf00:·643e·6661·6c73·653c·2f74·643e·3c2f·7472··d>false</td></tr0003bb10:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr><
0003bf10:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg 
0003bf20:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl 
0003bf30:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab 
0003bf40:·6c65·3e3c·7072·653e·3c63·6f64·653e·0a70··le><pre><code>.p0003bb20:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod
Max diff block lines reached; 1724882/1752096 bytes (98.45%) of diff not shown.
194 KB
html2text {}
    
Offset 150, 52 lines modifiedOffset 150, 38 lines modified
150 ··-·PCI-DSSv4-11.5.2150 ··-·PCI-DSSv4-11.5.2
151 ··-·enable_strategy151 ··-·enable_strategy
152 ··-·low_complexity152 ··-·low_complexity
153 ··-·low_disruption153 ··-·low_disruption
154 ··-·medium_severity154 ··-·medium_severity
155 ··-·no_reboot_needed155 ··-·no_reboot_needed
156 ··-·package_aide_installed156 ··-·package_aide_installed
157 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
158 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
159 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
160 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
161 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
162 dnf·install·aide 
163 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
164 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
165 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
166 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
167 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
168 package·--add=aide 
169 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8157 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
170 [[packages]]158 [[packages]]
171 name·=·"aide"159 name·=·"aide"
172 version·=·"*"160 version·=·"*"
173 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
174 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
175 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
176 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
177 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
178 package·install·aide 
179 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8161 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
180 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low162 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
181 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low163 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
182 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false164 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
183 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable165 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
184 include·install_aide166 include·install_aide
  
185 class·install_aide·{167 class·install_aide·{
186 ··package·{·'aide':168 ··package·{·'aide':
187 ····ensure·=>·'installed',169 ····ensure·=>·'installed',
188 ··}170 ··}
189 }171 }
 172 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 173 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 174 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 175 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 176 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 177 package·install·aide
190 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8178 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
191 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low179 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
192 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low180 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
193 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false181 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
194 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable182 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
195 #·Remediation·is·applicable·only·in·certain·platforms183 #·Remediation·is·applicable·only·in·certain·platforms
196 if·rpm·--quiet·-q·kernel;·then184 if·rpm·--quiet·-q·kernel;·then
Offset 203, 14 lines modifiedOffset 189, 28 lines modified
203 if·!·rpm·-q·--quiet·"aide"·;·then189 if·!·rpm·-q·--quiet·"aide"·;·then
204 ····dnf·install·-y·"aide"190 ····dnf·install·-y·"aide"
205 fi191 fi
  
206 else192 else
207 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'193 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
208 fi194 fi
 195 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 196 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 197 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 198 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 199 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 200 package·--add=aide
 201 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 202 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 203 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 204 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 205 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 206 dnf·install·aide
209 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*207 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
210 Run·the·following·command·to·generate·a·new·database:208 Run·the·following·command·to·generate·a·new·database:
211 $·sudo·/usr/sbin/aide·--init209 $·sudo·/usr/sbin/aide·--init
212 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:210 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
213 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz211 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
214 To·initiate·a·manual·check,·run·the·following·command:212 To·initiate·a·manual·check,·run·the·following·command:
215 $·sudo·/usr/sbin/aide·--check213 $·sudo·/usr/sbin/aide·--check
Offset 2220, 61 lines modifiedOffset 2220, 61 lines modified
2220 ··-·DISA-STIG-RHEL-09-2151002220 ··-·DISA-STIG-RHEL-09-215100
2221 ··-·enable_strategy2221 ··-·enable_strategy
2222 ··-·low_complexity2222 ··-·low_complexity
2223 ··-·low_disruption2223 ··-·low_disruption
2224 ··-·medium_severity2224 ··-·medium_severity
2225 ··-·no_reboot_needed2225 ··-·no_reboot_needed
2226 ··-·package_crypto-policies_installed2226 ··-·package_crypto-policies_installed
2227 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
2228 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
2229 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
2230 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
2231 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
2232 dnf·install·crypto-policies 
2233 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
2234 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
2235 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
2236 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
2237 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
2238 package·--add=crypto-policies 
2239 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x82227 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
2240 [[packages]]2228 [[packages]]
2241 name·=·"crypto-policies"2229 name·=·"crypto-policies"
2242 version·=·"*"2230 version·=·"*"
2243 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
2244 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
2245 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
2246 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
2247 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
2248 package·install·crypto-policies 
2249 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x82231 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
2250 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low2232 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
2251 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low2233 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
2252 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false2234 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
2253 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable2235 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
Max diff block lines reached; 193603/198373 bytes (97.60%) of diff not shown.
1.82 MB
./usr/share/doc/ssg-nondebian/ssg-rhel9-guide-stig_gui.html
    
Offset 15254, 208 lines modifiedOffset 15254, 208 lines modified
0003b950:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=0003b950:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
0003b960:·2223·6964·6d38·3435·3922·2074·6162·696e··"#idm8459"·tabin0003b960:·2223·6964·6d38·3435·3922·2074·6162·696e··"#idm8459"·tabin
0003b970:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu0003b970:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
0003b980:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan0003b980:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
0003b990:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl0003b990:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
0003b9a0:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r0003b9a0:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
0003b9b0:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"0003b9b0:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
0003b9c0:·3e52·656d·6564·6961·7469·6f6e·2073·6372··>Remediation·scr0003b9c0:·3e52·656d·6564·6961·7469·6f6e·204f·5342··>Remediation·OSB
 0003b9d0:·7569·6c64·2042·6c75·6570·7269·6e74·2073··uild·Blueprint·s
 0003b9e0:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b
 0003b9f0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
 0003ba00:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
 0003ba10:·6c61·7073·6522·2069·643d·2269·646d·3834··lapse"·id="idm84
 0003ba20:·3539·223e·3c70·7265·3e3c·636f·6465·3e0a··59"><pre><code>.
 0003ba30:·5b5b·7061·636b·6167·6573·5d5d·0a6e·616d··[[packages]].nam
 0003ba40:·6520·3d20·2261·6964·6522·0a76·6572·7369··e·=·"aide".versi
 0003ba50:·6f6e·203d·2022·2a22·0a3c·2f63·6f64·653e··on·=·"*".</code>
0003b9d0:·6970·7420·e287·b23c·2f61·3e3c·6272·3e3c··ipt·...</a><br>< 
0003b9e0:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel 
0003b9f0:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap 
0003ba00:·7365·2220·6964·3d22·6964·6d38·3435·3922··se"·id="idm8459" 
0003ba10:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t 
0003ba20:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip 
0003ba30:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere 
0003ba40:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense 
0003ba50:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl 
0003ba60:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l 
0003ba70:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr> 
0003ba80:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:< 
0003ba90:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td> 
0003baa0:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb 
0003bab0:·6f6f·743a·3c2f·7468·3e3c·7464·3e66·616c··oot:</th><td>fal 
0003bac0:·7365·3c2f·7464·3e3c·2f74·723e·3c74·723e··se</td></tr><tr> 
0003bad0:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t 
0003bae0:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td 
0003baf0:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p 
0003bb00:·7265·3e3c·636f·6465·3e0a·646e·6620·696e··re><code>.dnf·in 
0003bb10:·7374·616c·6c20·6169·6465·0a3c·2f63·6f64··stall·aide.</cod 
0003bb20:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a0003ba60:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c
0003bb30:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn-0003ba70:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su
0003bb40:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to0003ba80:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg
0003bb50:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"·0003ba90:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da
0003bb60:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id0003baa0:·7461·2d74·6172·6765·743d·2223·6964·6d38··ta-target="#idm8
0003bb70:·6d38·3436·3022·2074·6162·696e·6465·783d··m8460"·tabindex=0003bab0:·3436·3022·2074·6162·696e·6465·783d·2230··460"·tabindex="0
0003bb80:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button0003bac0:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
0003bb90:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=0003bad0:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
0003bba0:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A0003bae0:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
0003bbb0:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea0003baf0:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
0003bbc0:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem0003bb00:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
0003bbd0:·6564·6961·7469·6f6e·2041·6e61·636f·6e64··ediation·Anacond0003bb10:·6961·7469·6f6e·2050·7570·7065·7420·736e··iation·Puppet·sn
0003bbe0:·6120·736e·6970·7065·7420·e287·b23c·2f61··a·snippet·...</a0003bb20:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br
0003bbf0:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=0003bb30:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
0003bc00:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·0003bb40:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
0003bc10:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id0003bb50:·6170·7365·2220·6964·3d22·6964·6d38·3436··apse"·id="idm846
0003bc20:·6d38·3436·3022·3e3c·7461·626c·6520·636c··m8460"><table·cl0003bb60:·3022·3e3c·7461·626c·6520·636c·6173·733d··0"><table·class=
0003bc30:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table0003bb70:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str
0003bc40:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b0003bb80:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde
0003bc50:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co0003bb90:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden
0003bc60:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th0003bba0:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com
0003bc70:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th0003bbb0:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td
0003bc80:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t0003bbc0:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
0003bc90:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup0003bbd0:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption
 0003bbe0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
 0003bbf0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e52··d></tr><tr><th>R
 0003bc00:·6562·6f6f·743a·3c2f·7468·3e3c·7464·3e66··eboot:</th><td>f
 0003bc10:·616c·7365·3c2f·7464·3e3c·2f74·723e·3c74··alse</td></tr><t
 0003bc20:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<
 0003bc30:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</
 0003bc40:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table>
 0003bc50:·3c70·7265·3e3c·636f·6465·3e69·6e63·6c75··<pre><code>inclu
 0003bc60:·6465·2069·6e73·7461·6c6c·5f61·6964·650a··de·install_aide.
 0003bc70:·0a63·6c61·7373·2069·6e73·7461·6c6c·5f61··.class·install_a
 0003bc80:·6964·6520·7b0a·2020·7061·636b·6167·6520··ide·{.··package·
 0003bc90:·7b20·2761·6964·6527·3a0a·2020·2020·656e··{·'aide':.····en
 0003bca0:·7375·7265·203d·2667·743b·2027·696e·7374··sure·=&gt;·'inst
 0003bcb0:·616c·6c65·6427·2c0a·2020·7d0a·7d0a·3c2f··alled',.··}.}.</
 0003bcc0:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div
 0003bcd0:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b
 0003bce0:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data
 0003bcf0:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps
 0003bd00:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
 0003bd10:·2369·646d·3834·3631·2220·7461·6269·6e64··#idm8461"·tabind
 0003bd20:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
 0003bd30:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
 0003bd40:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
 0003bd50:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
 0003bd60:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
 0003bd70:·5265·6d65·6469·6174·696f·6e20·7363·7269··Remediation·scri
 0003bd80:·7074·20e2·87b2·3c2f·613e·3c62·723e·3c64··pt·...</a><br><d
 0003bd90:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-
 0003bda0:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps
 0003bdb0:·6522·2069·643d·2269·646d·3834·3631·223e··e"·id="idm8461">
 0003bdc0:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta
 0003bdd0:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe
 0003bde0:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered
 0003bdf0:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed
 0003be00:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple
0003bca0:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo0003be10:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo
0003bcb0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><0003be20:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
0003bcc0:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th>< 
0003bcd0:·7464·3e66·616c·7365·3c2f·7464·3e3c·2f74··td>false</td></t0003be30:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</
 0003be40:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
0003bce0:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate0003be50:·2f74·723e·3c74·723e·3c74·683e·5265·626f··/tr><tr><th>Rebo
0003bcf0:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab0003be60:·6f74·3a3c·2f74·683e·3c74·643e·6661·6c73··ot:</th><td>fals
0003bd00:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta 
0003bd10:·626c·653e·3c70·7265·3e3c·636f·6465·3e0a··ble><pre><code>. 
0003bd20:·7061·636b·6167·6520·2d2d·6164·643d·6169··package·--add=ai 
0003bd30:·6465·0a3c·2f63·6f64·653e·3c2f·7072·653e··de.</code></pre> 
0003bd40:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class=" 
0003bd50:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success"0003be70:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr><
 0003be80:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th
 0003be90:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td>
 0003bea0:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr
 0003beb0:·653e·3c63·6f64·653e·0a70·6163·6b61·6765··e><code>.package
 0003bec0:·2069·6e73·7461·6c6c·2061·6964·650a·3c2f···install·aide.</
 0003bed0:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div
 0003bee0:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b
 0003bef0:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data
 0003bf00:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps
0003bd60:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co0003bf10:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
 0003bf20:·2369·646d·3834·3632·2220·7461·6269·6e64··#idm8462"·tabind
 0003bf30:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
 0003bf40:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
 0003bf50:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
 0003bf60:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
 0003bf70:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
 0003bf80:·5265·6d65·6469·6174·696f·6e20·5368·656c··Remediation·Shel
Max diff block lines reached; 1692946/1720298 bytes (98.41%) of diff not shown.
188 KB
html2text {}
    
Offset 155, 52 lines modifiedOffset 155, 38 lines modified
155 ··-·PCI-DSSv4-11.5.2155 ··-·PCI-DSSv4-11.5.2
156 ··-·enable_strategy156 ··-·enable_strategy
157 ··-·low_complexity157 ··-·low_complexity
158 ··-·low_disruption158 ··-·low_disruption
159 ··-·medium_severity159 ··-·medium_severity
160 ··-·no_reboot_needed160 ··-·no_reboot_needed
161 ··-·package_aide_installed161 ··-·package_aide_installed
162 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
163 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
164 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
165 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
166 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
167 dnf·install·aide 
168 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
169 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
170 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
171 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
172 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
173 package·--add=aide 
174 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8162 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
175 [[packages]]163 [[packages]]
176 name·=·"aide"164 name·=·"aide"
177 version·=·"*"165 version·=·"*"
178 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
179 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
180 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
181 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
182 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
183 package·install·aide 
184 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8166 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
185 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low167 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
186 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low168 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
187 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false169 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
188 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable170 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
189 include·install_aide171 include·install_aide
  
190 class·install_aide·{172 class·install_aide·{
191 ··package·{·'aide':173 ··package·{·'aide':
192 ····ensure·=>·'installed',174 ····ensure·=>·'installed',
193 ··}175 ··}
194 }176 }
 177 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 178 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 179 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 180 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 181 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 182 package·install·aide
195 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8183 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
196 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low184 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
197 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low185 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
198 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false186 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
199 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable187 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
200 #·Remediation·is·applicable·only·in·certain·platforms188 #·Remediation·is·applicable·only·in·certain·platforms
201 if·rpm·--quiet·-q·kernel;·then189 if·rpm·--quiet·-q·kernel;·then
Offset 208, 14 lines modifiedOffset 194, 28 lines modified
208 if·!·rpm·-q·--quiet·"aide"·;·then194 if·!·rpm·-q·--quiet·"aide"·;·then
209 ····dnf·install·-y·"aide"195 ····dnf·install·-y·"aide"
210 fi196 fi
  
211 else197 else
212 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'198 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
213 fi199 fi
 200 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 201 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 202 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 203 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 204 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 205 package·--add=aide
 206 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 207 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 208 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 209 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 210 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 211 dnf·install·aide
214 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*212 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
215 Run·the·following·command·to·generate·a·new·database:213 Run·the·following·command·to·generate·a·new·database:
216 $·sudo·/usr/sbin/aide·--init214 $·sudo·/usr/sbin/aide·--init
217 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:215 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
218 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz216 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
219 To·initiate·a·manual·check,·run·the·following·command:217 To·initiate·a·manual·check,·run·the·following·command:
220 $·sudo·/usr/sbin/aide·--check218 $·sudo·/usr/sbin/aide·--check
Offset 2225, 61 lines modifiedOffset 2225, 61 lines modified
2225 ··-·DISA-STIG-RHEL-09-2151002225 ··-·DISA-STIG-RHEL-09-215100
2226 ··-·enable_strategy2226 ··-·enable_strategy
2227 ··-·low_complexity2227 ··-·low_complexity
2228 ··-·low_disruption2228 ··-·low_disruption
2229 ··-·medium_severity2229 ··-·medium_severity
2230 ··-·no_reboot_needed2230 ··-·no_reboot_needed
2231 ··-·package_crypto-policies_installed2231 ··-·package_crypto-policies_installed
2232 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
2233 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
2234 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
2235 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
2236 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
2237 dnf·install·crypto-policies 
2238 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
2239 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
2240 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
2241 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
2242 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
2243 package·--add=crypto-policies 
2244 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x82232 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
2245 [[packages]]2233 [[packages]]
2246 name·=·"crypto-policies"2234 name·=·"crypto-policies"
2247 version·=·"*"2235 version·=·"*"
2248 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
2249 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
2250 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
2251 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
2252 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
2253 package·install·crypto-policies 
2254 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x82236 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
2255 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low2237 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
2256 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low2238 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
2257 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false2239 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
2258 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable2240 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
Max diff block lines reached; 188088/192858 bytes (97.53%) of diff not shown.
92.0 KB
./usr/share/doc/ssg-nondebian/ssg-rhv4-guide-pci-dss.html
    
Offset 16653, 141 lines modifiedOffset 16653, 141 lines modified
000410c0:·7461·7267·6574·3d22·2369·646d·3139·3434··target="#idm1944000410c0:·7461·7267·6574·3d22·2369·646d·3139·3434··target="#idm1944
000410d0:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r000410d0:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r
000410e0:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari000410e0:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari
000410f0:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals000410f0:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals
00041100:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa00041100:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa
00041110:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr00041110:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr
00041120:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat00041120:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat
 00041130:·696f·6e20·4f53·4275·696c·6420·426c·7565··ion·OSBuild·Blue
 00041140:·7072·696e·7420·736e·6970·7065·7420·e287··print·snippet·..
 00041150:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl
 00041160:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla
 00041170:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id
 00041180:·3d22·6964·6d31·3934·3422·3e3c·7072·653e··="idm1944"><pre>
00041130:·696f·6e20·416e·6163·6f6e·6461·2073·6e69··ion·Anaconda·sni 
00041140:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br> 
00041150:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane 
00041160:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla 
00041170:·7073·6522·2069·643d·2269·646d·3139·3434··pse"·id="idm1944 
00041180:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class=" 
00041190:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri 
000411a0:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border 
000411b0:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens 
000411c0:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp 
000411d0:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td> 
000411e0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr 
000411f0:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption: 
00041200:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td 
00041210:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re 
00041220:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa 
00041230:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr 
00041240:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</ 
00041250:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t 
00041260:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table>< 
00041270:·7072·653e·3c63·6f64·653e·0a70·6163·6b61··pre><code>.packa00041190:·3c63·6f64·653e·0a5b·5b70·6163·6b61·6765··<code>.[[package
00041280:·6765·202d·2d61·6464·3d61·6964·650a·3c2f··ge·--add=aide.</000411a0:·735d·5d0a·6e61·6d65·203d·2022·6169·6465··s]].name·=·"aide
 000411b0:·220a·7665·7273·696f·6e20·3d20·222a·220a··".version·=·"*".
00041290:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div000411c0:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d
000412a0:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b000411d0:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn
000412b0:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data000411e0:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da
000412c0:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps000411f0:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla
000412d0:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="00041200:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
000412e0:·2369·646d·3139·3435·2220·7461·6269·6e64··#idm1945"·tabind00041210:·3d22·2369·646d·3139·3435·2220·7461·6269··="#idm1945"·tabi
000412f0:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but00041220:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
00041300:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand00041230:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
00041310:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title00041240:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
00041320:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re00041250:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
00041330:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">00041260:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
00041340:·5265·6d65·6469·6174·696f·6e20·4f53·4275··Remediation·OSBu00041270:·223e·5265·6d65·6469·6174·696f·6e20·5075··">Remediation·Pu
 00041280:·7070·6574·2073·6e69·7070·6574·20e2·87b2··ppet·snippet·...
 00041290:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
 000412a0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
00041350:·696c·6420·426c·7565·7072·696e·7420·736e··ild·Blueprint·sn 
00041360:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br 
00041370:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan 
00041380:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll 
00041390:·6170·7365·2220·6964·3d22·6964·6d31·3934··apse"·id="idm194 
000413a0:·3522·3e3c·7072·653e·3c63·6f64·653e·0a5b··5"><pre><code>.[ 
000413b0:·5b70·6163·6b61·6765·735d·5d0a·6e61·6d65··[packages]].name 
000413c0:·203d·2022·6169·6465·220a·7665·7273·696f···=·"aide".versio 
000413d0:·6e20·3d20·222a·220a·3c2f·636f·6465·3e3c··n·=·"*".</code>< 
000413e0:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl 
000413f0:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc 
00041400:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl 
00041410:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat000412b0:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
 000412c0:·2269·646d·3139·3435·223e·3c74·6162·6c65··"idm1945"><table
 000412d0:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta
 000412e0:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl
 000412f0:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table
 00041300:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>
 00041310:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<
 00041320:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
 00041330:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis
 00041340:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td
 00041350:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
 00041360:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t
 00041370:·683e·3c74·643e·6661·6c73·653c·2f74·643e··h><td>false</td>
 00041380:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str
 00041390:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e
00041420:·612d·7461·7267·6574·3d22·2369·646d·3139··a-target="#idm19 
00041430:·3436·2220·7461·6269·6e64·6578·3d22·3022··46"·tabindex="0" 
00041440:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a 
00041450:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa 
00041460:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti 
00041470:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"· 
00041480:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi 
00041490:·6174·696f·6e20·5075·7070·6574·2073·6e69··ation·Puppet·sni 
000414a0:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br> 
000414b0:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane 
000414c0:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla 
000414d0:·7073·6522·2069·643d·2269·646d·3139·3436··pse"·id="idm1946 
000414e0:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class=" 
000414f0:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri 
00041500:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border 
00041510:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens 
00041520:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp 
00041530:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td> 
00041540:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr000413a0:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr><
00041550:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:000413b0:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod
 000413c0:·653e·696e·636c·7564·6520·696e·7374·616c··e>include·instal
 000413d0:·6c5f·6169·6465·0a0a·636c·6173·7320·696e··l_aide..class·in
 000413e0:·7374·616c·6c5f·6169·6465·207b·0a20·2070··stall_aide·{.··p
 000413f0:·6163·6b61·6765·207b·2027·6169·6465·273a··ackage·{·'aide':
 00041400:·0a20·2020·2065·6e73·7572·6520·3d26·6774··.····ensure·=&gt
 00041410:·3b20·2769·6e73·7461·6c6c·6564·272c·0a20··;·'installed',.·
 00041420:·207d·0a7d·0a3c·2f63·6f64·653e·3c2f·7072···}.}.</code></pr
 00041430:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class
 00041440:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes
 00041450:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle="
 00041460:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t
 00041470:·6172·6765·743d·2223·6964·6d31·3934·3622··arget="#idm1946"
 00041480:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro
 00041490:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria
 000414a0:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false
 000414b0:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat
 000414c0:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre
 000414d0:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati
 000414e0:·6f6e·2053·6865·6c6c·2073·6372·6970·7420··on·Shell·script·
 000414f0:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·
 00041500:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col
 00041510:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·
 00041520:·6964·3d22·6964·6d31·3934·3622·3e3c·7461··id="idm1946"><ta
 00041530:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table
 00041540:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t
 00041550:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta
 00041560:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><
 00041570:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit
00041560:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td00041580:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</
Max diff block lines reached; 66630/84736 bytes (78.63%) of diff not shown.
9.15 KB
html2text {}
    
Offset 531, 21 lines modifiedOffset 531, 14 lines modified
531 ··-·PCI-DSSv4-11.5.2531 ··-·PCI-DSSv4-11.5.2
532 ··-·enable_strategy532 ··-·enable_strategy
533 ··-·low_complexity533 ··-·low_complexity
534 ··-·low_disruption534 ··-·low_disruption
535 ··-·medium_severity535 ··-·medium_severity
536 ··-·no_reboot_needed536 ··-·no_reboot_needed
537 ··-·package_aide_installed537 ··-·package_aide_installed
538 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
539 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
540 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
541 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
542 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
543 package·--add=aide 
544 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8538 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
545 [[packages]]539 [[packages]]
546 name·=·"aide"540 name·=·"aide"
547 version·=·"*"541 version·=·"*"
548 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8542 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
549 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low543 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 570, 14 lines modifiedOffset 563, 21 lines modified
570 if·!·rpm·-q·--quiet·"aide"·;·then563 if·!·rpm·-q·--quiet·"aide"·;·then
571 ····yum·install·-y·"aide"564 ····yum·install·-y·"aide"
572 fi565 fi
  
573 else566 else
574 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'567 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
575 fi568 fi
 569 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 570 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 571 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 572 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 573 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 574 package·--add=aide
576 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*575 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
577 Run·the·following·command·to·generate·a·new·database:576 Run·the·following·command·to·generate·a·new·database:
578 $·sudo·/usr/sbin/aide·--init577 $·sudo·/usr/sbin/aide·--init
579 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:578 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
580 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz579 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
581 To·initiate·a·manual·check,·run·the·following·command:580 To·initiate·a·manual·check,·run·the·following·command:
582 $·sudo·/usr/sbin/aide·--check581 $·sudo·/usr/sbin/aide·--check
Offset 7384, 21 lines modifiedOffset 7384, 14 lines modified
7384 ··-·NIST-800-53-CM-6(a)7384 ··-·NIST-800-53-CM-6(a)
7385 ··-·enable_strategy7385 ··-·enable_strategy
7386 ··-·low_complexity7386 ··-·low_complexity
7387 ··-·low_disruption7387 ··-·low_disruption
7388 ··-·medium_severity7388 ··-·medium_severity
7389 ··-·no_reboot_needed7389 ··-·no_reboot_needed
7390 ··-·package_opensc_installed7390 ··-·package_opensc_installed
7391 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
7392 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
7393 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
7394 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
7395 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
7396 package·--add=opensc 
7397 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x87391 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
7398 [[packages]]7392 [[packages]]
7399 name·=·"opensc"7393 name·=·"opensc"
7400 version·=·"*"7394 version·=·"*"
7401 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x87395 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
7402 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low7396 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 7423, 14 lines modifiedOffset 7416, 21 lines modified
7423 if·!·rpm·-q·--quiet·"opensc"·;·then7416 if·!·rpm·-q·--quiet·"opensc"·;·then
7424 ····yum·install·-y·"opensc"7417 ····yum·install·-y·"opensc"
7425 fi7418 fi
  
7426 else7419 else
7427 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'7420 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
7428 fi7421 fi
 7422 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 7423 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 7424 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 7425 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 7426 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 7427 package·--add=opensc
7429 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·t\x8th\x8he\x8e·p\x8pc\x8cs\x8sc\x8c-\x8-l\x8li\x8it\x8te\x8e·p\x8pa\x8ac\x8ck\x8ka\x8ag\x8ge\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*7428 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·t\x8th\x8he\x8e·p\x8pc\x8cs\x8sc\x8c-\x8-l\x8li\x8it\x8te\x8e·p\x8pa\x8ac\x8ck\x8ka\x8ag\x8ge\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
7430 The·pcsc-lite·package·can·be·installed·with·the·following·command:7429 The·pcsc-lite·package·can·be·installed·with·the·following·command:
7431 $·sudo·yum·install·pcsc-lite7430 $·sudo·yum·install·pcsc-lite
7432 Rationale:··The·pcsc-lite·package·must·be·installed·if·it·is·to·be·available·for·multifactor·authentication·using·smartcards.7431 Rationale:··The·pcsc-lite·package·must·be·installed·if·it·is·to·be·available·for·multifactor·authentication·using·smartcards.
7433 Severity: ··medium7432 Severity: ··medium
7434 Rule·ID:····xccdf_org.ssgproject.content_rule_package_pcsc-lite_installed7433 Rule·ID:····xccdf_org.ssgproject.content_rule_package_pcsc-lite_installed
7435 ············_\x8d_\x8i_\x8s_\x8a···CCI-0040467434 ············_\x8d_\x8i_\x8s_\x8a···CCI-004046
Offset 7463, 21 lines modifiedOffset 7463, 14 lines modified
7463 ··-·NIST-800-53-CM-6(a)7463 ··-·NIST-800-53-CM-6(a)
7464 ··-·enable_strategy7464 ··-·enable_strategy
7465 ··-·low_complexity7465 ··-·low_complexity
7466 ··-·low_disruption7466 ··-·low_disruption
7467 ··-·medium_severity7467 ··-·medium_severity
7468 ··-·no_reboot_needed7468 ··-·no_reboot_needed
7469 ··-·package_pcsc-lite_installed7469 ··-·package_pcsc-lite_installed
7470 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
7471 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
7472 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
7473 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
7474 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
7475 package·--add=pcsc-lite 
7476 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x87470 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
7477 [[packages]]7471 [[packages]]
7478 name·=·"pcsc-lite"7472 name·=·"pcsc-lite"
7479 version·=·"*"7473 version·=·"*"
7480 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x87474 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
7481 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low7475 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 7502, 14 lines modifiedOffset 7495, 21 lines modified
7502 if·!·rpm·-q·--quiet·"pcsc-lite"·;·then7495 if·!·rpm·-q·--quiet·"pcsc-lite"·;·then
7503 ····yum·install·-y·"pcsc-lite"7496 ····yum·install·-y·"pcsc-lite"
7504 fi7497 fi
  
7505 else7498 else
7506 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'7499 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
7507 fi7500 fi
 7501 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 7502 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 7503 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 7504 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 7505 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 7506 package·--add=pcsc-lite
7508 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·t\x8th\x8he\x8e·p\x8pc\x8cs\x8sc\x8cd\x8d·S\x8Se\x8er\x8rv\x8vi\x8ic\x8ce\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*7507 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·t\x8th\x8he\x8e·p\x8pc\x8cs\x8sc\x8cd\x8d·S\x8Se\x8er\x8rv\x8vi\x8ic\x8ce\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
7509 The·pcscd·service·can·be·enabled·with·the·following·command:7508 The·pcscd·service·can·be·enabled·with·the·following·command:
7510 $·sudo·systemctl·enable·pcscd.service7509 $·sudo·systemctl·enable·pcscd.service
Max diff block lines reached; 4062/9344 bytes (43.47%) of diff not shown.
369 KB
./usr/share/doc/ssg-nondebian/ssg-rhv4-guide-rhvh-stig.html
    
Offset 17392, 142 lines modifiedOffset 17392, 142 lines modified
00043ef0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target00043ef0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
00043f00:·3d22·2369·646d·3139·3434·2220·7461·6269··="#idm1944"·tabi00043f00:·3d22·2369·646d·3139·3434·2220·7461·6269··="#idm1944"·tabi
00043f10:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b00043f10:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
00043f20:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa00043f20:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
00043f30:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit00043f30:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
00043f40:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·00043f40:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
00043f50:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!00043f50:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
00043f60:·223e·5265·6d65·6469·6174·696f·6e20·416e··">Remediation·An00043f60:·223e·5265·6d65·6469·6174·696f·6e20·4f53··">Remediation·OS
00043f70:·6163·6f6e·6461·2073·6e69·7070·6574·20e2··aconda·snippet·. 
00043f80:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c 
00043f90:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll00043f70:·4275·696c·6420·426c·7565·7072·696e·7420··Build·Blueprint·
 00043f80:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><
 00043f90:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
00043fa0:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i00043fa0:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
 00043fb0:·6c6c·6170·7365·2220·6964·3d22·6964·6d31··llapse"·id="idm1
 00043fc0:·3934·3422·3e3c·7072·653e·3c63·6f64·653e··944"><pre><code>
 00043fd0:·0a5b·5b70·6163·6b61·6765·735d·5d0a·6e61··.[[packages]].na
 00043fe0:·6d65·203d·2022·6169·6465·220a·7665·7273··me·=·"aide".vers
 00043ff0:·696f·6e20·3d20·222a·220a·3c2f·636f·6465··ion·=·"*".</code
00043fb0:·643d·2269·646d·3139·3434·223e·3c74·6162··d="idm1944"><tab 
00043fc0:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table· 
00043fd0:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta 
00043fe0:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab 
00043ff0:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t 
00044000:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity 
00044010:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t 
00044020:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D 
00044030:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th>< 
00044040:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
00044050:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:< 
00044060:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t 
00044070:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S 
00044080:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td 
00044090:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr 
000440a0:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c 
000440b0:·6f64·653e·0a70·6163·6b61·6765·202d·2d61··ode>.package·--a 
000440c0:·6464·3d61·6964·650a·3c2f·636f·6465·3e3c··dd=aide.</code>< 
000440d0:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl00044000:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a·
000440e0:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc00044010:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s
000440f0:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl00044020:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog
00044100:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat00044030:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d
00044110:·612d·7461·7267·6574·3d22·2369·646d·3139··a-target="#idm1900044040:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
00044120:·3435·2220·7461·6269·6e64·6578·3d22·3022··45"·tabindex="0"00044050:·3139·3435·2220·7461·6269·6e64·6578·3d22··1945"·tabindex="
00044130:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a00044060:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
00044140:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa00044070:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
00044150:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti00044080:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
00044160:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·00044090:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
00044170:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi000440a0:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
00044180:·6174·696f·6e20·4f53·4275·696c·6420·426c··ation·OSBuild·Bl 
00044190:·7565·7072·696e·7420·736e·6970·7065·7420··ueprint·snippet· 
000441a0:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div· 
000441b0:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col 
000441c0:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"· 
000441d0:·6964·3d22·6964·6d31·3934·3522·3e3c·7072··id="idm1945"><pr 
000441e0:·653e·3c63·6f64·653e·0a5b·5b70·6163·6b61··e><code>.[[packa 
000441f0:·6765·735d·5d0a·6e61·6d65·203d·2022·6169··ges]].name·=·"ai 
00044200:·6465·220a·7665·7273·696f·6e20·3d20·222a··de".version·=·"* 
00044210:·220a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··".</code></pre>< 
00044220:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b 
00044230:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"· 
00044240:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col 
00044250:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ 
00044260:·6574·3d22·2369·646d·3139·3436·2220·7461··et="#idm1946"·ta 
00044270:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role= 
00044280:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex 
00044290:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t 
000442a0:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t 
000442b0:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href=" 
000442c0:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation· 
000442d0:·5075·7070·6574·2073·6e69·7070·6574·20e2··Puppet·snippet·. 
000442e0:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c 
000442f0:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll 
00044300:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i 
00044310:·643d·2269·646d·3139·3436·223e·3c74·6162··d="idm1946"><tab000440b0:·6469·6174·696f·6e20·5075·7070·6574·2073··diation·Puppet·s
 000440c0:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b
 000440d0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
 000440e0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
 000440f0:·6c61·7073·6522·2069·643d·2269·646d·3139··lapse"·id="idm19
 00044100:·3435·223e·3c74·6162·6c65·2063·6c61·7373··45"><table·class
 00044110:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st
 00044120:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord
 00044130:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde
 00044140:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co
 00044150:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t
 00044160:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
 00044170:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio
 00044180:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</
 00044190:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 000441a0:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td>
 000441b0:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr><
 000441c0:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:
 000441d0:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<
 000441e0:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table
 000441f0:·3e3c·7072·653e·3c63·6f64·653e·696e·636c··><pre><code>incl
 00044200:·7564·6520·696e·7374·616c·6c5f·6169·6465··ude·install_aide
 00044210:·0a0a·636c·6173·7320·696e·7374·616c·6c5f··..class·install_
 00044220:·6169·6465·207b·0a20·2070·6163·6b61·6765··aide·{.··package
 00044230:·207b·2027·6169·6465·273a·0a20·2020·2065···{·'aide':.····e
 00044240:·6e73·7572·6520·3d26·6774·3b20·2769·6e73··nsure·=&gt;·'ins
 00044250:·7461·6c6c·6564·272c·0a20·207d·0a7d·0a3c··talled',.··}.}.<
 00044260:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di
00044320:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·00044270:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn·
00044330:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta 
00044340:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab 
00044350:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t 
00044360:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity 
00044370:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t 
00044380:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D 
00044390:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><00044280:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat
 00044290:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap
 000442a0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
 000442b0:·2223·6964·6d31·3934·3622·2074·6162·696e··"#idm1946"·tabin
 000442c0:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
 000442d0:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
 000442e0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
 000442f0:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
 00044300:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
 00044310:·3e52·656d·6564·6961·7469·6f6e·2053·6865··>Remediation·She
 00044320:·6c6c·2073·6372·6970·7420·e287·b23c·2f61··ll·script·...</a
 00044330:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
 00044340:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
 00044350:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
 00044360:·6d31·3934·3622·3e3c·7461·626c·6520·636c··m1946"><table·cl
 00044370:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table
 00044380:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b
 00044390:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co
 000443a0:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th
Max diff block lines reached; 318620/336864 bytes (94.58%) of diff not shown.
39.8 KB
html2text {}
    
Offset 713, 21 lines modifiedOffset 713, 14 lines modified
713 ··-·PCI-DSSv4-11.5.2713 ··-·PCI-DSSv4-11.5.2
714 ··-·enable_strategy714 ··-·enable_strategy
715 ··-·low_complexity715 ··-·low_complexity
716 ··-·low_disruption716 ··-·low_disruption
717 ··-·medium_severity717 ··-·medium_severity
718 ··-·no_reboot_needed718 ··-·no_reboot_needed
719 ··-·package_aide_installed719 ··-·package_aide_installed
720 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
721 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
722 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
723 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
724 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
725 package·--add=aide 
726 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8720 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
727 [[packages]]721 [[packages]]
728 name·=·"aide"722 name·=·"aide"
729 version·=·"*"723 version·=·"*"
730 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8724 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
731 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low725 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 752, 14 lines modifiedOffset 745, 21 lines modified
752 if·!·rpm·-q·--quiet·"aide"·;·then745 if·!·rpm·-q·--quiet·"aide"·;·then
753 ····yum·install·-y·"aide"746 ····yum·install·-y·"aide"
754 fi747 fi
  
755 else748 else
756 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'749 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
757 fi750 fi
 751 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 752 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 753 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 754 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 755 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 756 package·--add=aide
758 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*757 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
759 Run·the·following·command·to·generate·a·new·database:758 Run·the·following·command·to·generate·a·new·database:
760 $·sudo·/usr/sbin/aide·--init759 $·sudo·/usr/sbin/aide·--init
761 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:760 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
762 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz761 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
763 To·initiate·a·manual·check,·run·the·following·command:762 To·initiate·a·manual·check,·run·the·following·command:
764 $·sudo·/usr/sbin/aide·--check763 $·sudo·/usr/sbin/aide·--check
Offset 2282, 21 lines modifiedOffset 2282, 14 lines modified
2282 ··-·NIST-800-53-CM-7(b)2282 ··-·NIST-800-53-CM-7(b)
2283 ··-·disable_strategy2283 ··-·disable_strategy
2284 ··-·low_complexity2284 ··-·low_complexity
2285 ··-·low_disruption2285 ··-·low_disruption
2286 ··-·medium_severity2286 ··-·medium_severity
2287 ··-·no_reboot_needed2287 ··-·no_reboot_needed
2288 ··-·package_gdm_removed2288 ··-·package_gdm_removed
2289 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
2290 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
2291 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
2292 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
2293 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable 
  
2294 package·--remove=gdm 
2295 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x82289 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
2296 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low2290 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
2297 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low2291 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
2298 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false2292 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
2299 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable2293 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
2300 include·remove_gdm2294 include·remove_gdm
  
Offset 2322, 14 lines modifiedOffset 2315, 21 lines modified
2322 if·rpm·-q·--quiet·"gdm"·;·then2315 if·rpm·-q·--quiet·"gdm"·;·then
2323 yum·remove·-y·"gdm"2316 yum·remove·-y·"gdm"
2324 fi2317 fi
  
2325 else2318 else
2326 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'2319 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
2327 fi2320 fi
 2321 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 2322 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 2323 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 2324 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 2325 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
  
 2326 package·--remove=gdm
2328 Group  ·Sudo·  Group·contains·2·rules2327 Group  ·Sudo·  Group·contains·2·rules
2329 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Sudo,·which·stands·for·"su·'do'",·provides·the·ability·to·delegate·authority·to·certain·users,·groups·of·users,·or·system·administrators.·When·configured·for·system·users·and/or·groups,·Sudo·can·allow·a·user·or·group·to·execute·privileged·commands·that·normally·only·root·is·allowed·to·execute.2328 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Sudo,·which·stands·for·"su·'do'",·provides·the·ability·to·delegate·authority·to·certain·users,·groups·of·users,·or·system·administrators.·When·configured·for·system·users·and/or·groups,·Sudo·can·allow·a·user·or·group·to·execute·privileged·commands·that·normally·only·root·is·allowed·to·execute.
  
2330 For·more·information·on·Sudo·and·addition·Sudo·configuration·options,·see·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8w\x8w_\x8w\x8w_\x8w\x8w_\x8.\x8._\x8s\x8s_\x8u\x8u_\x8d\x8d_\x8o\x8o_\x8.\x8._\x8w\x8w_\x8s\x8s.2329 For·more·information·on·Sudo·and·addition·Sudo·configuration·options,·see·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8w\x8w_\x8w\x8w_\x8w\x8w_\x8.\x8._\x8s\x8s_\x8u\x8u_\x8d\x8d_\x8o\x8o_\x8.\x8._\x8w\x8w_\x8s\x8s.
2331 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·U\x8Us\x8se\x8er\x8rs\x8s·R\x8Re\x8e-\x8-A\x8Au\x8ut\x8th\x8he\x8en\x8nt\x8ti\x8ic\x8ca\x8at\x8te\x8e·f\x8fo\x8or\x8r·P\x8Pr\x8ri\x8iv\x8vi\x8il\x8le\x8eg\x8ge\x8e·E\x8Es\x8sc\x8ca\x8al\x8la\x8at\x8ti\x8io\x8on\x8n·-\x8-·s\x8su\x8ud\x8do\x8o·!\x8!a\x8au\x8ut\x8th\x8he\x8en\x8nt\x8ti\x8ic\x8ca\x8at\x8te\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*2330 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·U\x8Us\x8se\x8er\x8rs\x8s·R\x8Re\x8e-\x8-A\x8Au\x8ut\x8th\x8he\x8en\x8nt\x8ti\x8ic\x8ca\x8at\x8te\x8e·f\x8fo\x8or\x8r·P\x8Pr\x8ri\x8iv\x8vi\x8il\x8le\x8eg\x8ge\x8e·E\x8Es\x8sc\x8ca\x8al\x8la\x8at\x8ti\x8io\x8on\x8n·-\x8-·s\x8su\x8ud\x8do\x8o·!\x8!a\x8au\x8ut\x8th\x8he\x8en\x8nt\x8ti\x8ic\x8ca\x8at\x8te\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
2332 The·sudo·!authenticate·option,·when·specified,·allows·a·user·to·execute·commands·using·sudo·without·having·to·authenticate.·This·should·be·disabled·by·making·sure·that·the·!authenticate·option·does·not·exist·in·/etc/sudoers·configuration·file·or·any·sudo·configuration·snippets·in·/etc/sudoers.d/.2331 The·sudo·!authenticate·option,·when·specified,·allows·a·user·to·execute·commands·using·sudo·without·having·to·authenticate.·This·should·be·disabled·by·making·sure·that·the·!authenticate·option·does·not·exist·in·/etc/sudoers·configuration·file·or·any·sudo·configuration·snippets·in·/etc/sudoers.d/.
2333 ············Without·re-authentication,·users·may·access·resources·or·perform·tasks·for·which·they·do·not·have·authorization.2332 ············Without·re-authentication,·users·may·access·resources·or·perform·tasks·for·which·they·do·not·have·authorization.
Offset 11147, 21 lines modifiedOffset 11147, 14 lines modified
11147 ··-·NIST-800-53-CM-6(a)11147 ··-·NIST-800-53-CM-6(a)
11148 ··-·enable_strategy11148 ··-·enable_strategy
11149 ··-·low_complexity11149 ··-·low_complexity
11150 ··-·low_disruption11150 ··-·low_disruption
11151 ··-·medium_severity11151 ··-·medium_severity
11152 ··-·no_reboot_needed11152 ··-·no_reboot_needed
11153 ··-·package_tmux_installed11153 ··-·package_tmux_installed
11154 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
11155 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
11156 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
11157 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
11158 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
11159 package·--add=tmux 
11160 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x811154 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
11161 [[packages]]11155 [[packages]]
11162 name·=·"tmux"11156 name·=·"tmux"
11163 version·=·"*"11157 version·=·"*"
11164 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x811158 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
11165 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low11159 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 11186, 14 lines modifiedOffset 11179, 21 lines modified
11186 if·!·rpm·-q·--quiet·"tmux"·;·then11179 if·!·rpm·-q·--quiet·"tmux"·;·then
11187 ····yum·install·-y·"tmux"11180 ····yum·install·-y·"tmux"
11188 fi11181 fi
  
11189 else11182 else
11190 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'11183 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
11191 fi11184 fi
 11185 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 11186 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 11187 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 11188 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 11189 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 11190 package·--add=tmux
11192 Group  ·Hardware·Tokens·for·Authentication·  Group·contains·5·rules11191 Group  ·Hardware·Tokens·for·Authentication·  Group·contains·5·rules
11193 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·use·of·hardware·tokens·such·as·smart·cards·for·system·login·provides·stronger,·two-factor·authentication·than·using·a·username·and·password.·In·Red·Hat·Enterprise·Linux·servers·and·workstations,·hardware·token·login·is·not·enabled·by·default·and·must·be·enabled·in·the·system·settings.11192 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·use·of·hardware·tokens·such·as·smart·cards·for·system·login·provides·stronger,·two-factor·authentication·than·using·a·username·and·password.·In·Red·Hat·Enterprise·Linux·servers·and·workstations,·hardware·token·login·is·not·enabled·by·default·and·must·be·enabled·in·the·system·settings.
11194 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·t\x8th\x8he\x8e·o\x8op\x8pe\x8en\x8ns\x8sc\x8c·P\x8Pa\x8ac\x8ck\x8ka\x8ag\x8ge\x8e·F\x8Fo\x8or\x8r·M\x8Mu\x8ul\x8lt\x8ti\x8if\x8fa\x8ac\x8ct\x8to\x8or\x8r·A\x8Au\x8ut\x8th\x8he\x8en\x8nt\x8ti\x8ic\x8ca\x8at\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*11193 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·t\x8th\x8he\x8e·o\x8op\x8pe\x8en\x8ns\x8sc\x8c·P\x8Pa\x8ac\x8ck\x8ka\x8ag\x8ge\x8e·F\x8Fo\x8or\x8r·M\x8Mu\x8ul\x8lt\x8ti\x8if\x8fa\x8ac\x8ct\x8to\x8or\x8r·A\x8Au\x8ut\x8th\x8he\x8en\x8nt\x8ti\x8ic\x8ca\x8at\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
Max diff block lines reached; 34647/40752 bytes (85.02%) of diff not shown.
50.8 KB
./usr/share/doc/ssg-nondebian/ssg-rhv4-guide-rhvh-vpp.html
    
Offset 46595, 142 lines modifiedOffset 46595, 142 lines modified
000b6020:·612d·7461·7267·6574·3d22·2369·646d·3737··a-target="#idm77000b6020:·612d·7461·7267·6574·3d22·2369·646d·3737··a-target="#idm77
000b6030:·3832·2220·7461·6269·6e64·6578·3d22·3022··82"·tabindex="0"000b6030:·3832·2220·7461·6269·6e64·6578·3d22·3022··82"·tabindex="0"
000b6040:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a000b6040:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
000b6050:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa000b6050:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
000b6060:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti000b6060:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
000b6070:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·000b6070:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
000b6080:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi000b6080:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
 000b6090:·6174·696f·6e20·4f53·4275·696c·6420·426c··ation·OSBuild·Bl
 000b60a0:·7565·7072·696e·7420·736e·6970·7065·7420··ueprint·snippet·
 000b60b0:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·
 000b60c0:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col
 000b60d0:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·
 000b60e0:·6964·3d22·6964·6d37·3738·3222·3e3c·7072··id="idm7782"><pr
000b6090:·6174·696f·6e20·416e·6163·6f6e·6461·2073··ation·Anaconda·s 
000b60a0:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b 
000b60b0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa 
000b60c0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col 
000b60d0:·6c61·7073·6522·2069·643d·2269·646d·3737··lapse"·id="idm77 
000b60e0:·3832·223e·3c74·6162·6c65·2063·6c61·7373··82"><table·class 
000b60f0:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st 
000b6100:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord 
000b6110:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde 
000b6120:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co 
000b6130:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t 
000b6140:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr>< 
000b6150:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio 
000b6160:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</ 
000b6170:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
000b6180:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td> 
000b6190:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr>< 
000b61a0:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy: 
000b61b0:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable< 
000b61c0:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table 
000b61d0:·3e3c·7072·653e·3c63·6f64·653e·0a70·6163··><pre><code>.pac000b60f0:·653e·3c63·6f64·653e·0a5b·5b70·6163·6b61··e><code>.[[packa
000b61e0:·6b61·6765·202d·2d61·6464·3d6f·7065·6e73··kage·--add=opens000b6100:·6765·735d·5d0a·6e61·6d65·203d·2022·6f70··ges]].name·=·"op
 000b6110:·656e·7363·220a·7665·7273·696f·6e20·3d20··ensc".version·=·
000b61f0:·630a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··c.</code></pre><000b6120:·222a·220a·3c2f·636f·6465·3e3c·2f70·7265··"*".</code></pre
000b6200:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b000b6130:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class=
000b6210:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"·000b6140:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success
000b6220:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col000b6150:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c
000b6230:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ000b6160:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta
000b6240:·6574·3d22·2369·646d·3737·3833·2220·7461··et="#idm7783"·ta000b6170:·7267·6574·3d22·2369·646d·3737·3833·2220··rget="#idm7783"·
000b6250:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=000b6180:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol
000b6260:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex000b6190:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-
000b6270:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t000b61a0:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"
000b6280:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t000b61b0:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate
000b6290:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="000b61c0:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href
000b62a0:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·000b61d0:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio
000b62b0:·4f53·4275·696c·6420·426c·7565·7072·696e··OSBuild·Blueprin000b61e0:·6e20·5075·7070·6574·2073·6e69·7070·6574··n·Puppet·snippet
 000b61f0:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
 000b6200:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
 000b6210:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
 000b6220:·2069·643d·2269·646d·3737·3833·223e·3c74···id="idm7783"><t
 000b6230:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl
 000b6240:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·
 000b6250:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t
 000b6260:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">
 000b6270:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi
 000b6280:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<
 000b6290:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 000b62a0:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th
 000b62b0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
 000b62c0:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot
 000b62d0:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false<
 000b62e0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 000b62f0:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><
 000b6300:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></
 000b6310:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>
 000b6320:·3c63·6f64·653e·696e·636c·7564·6520·696e··<code>include·in
 000b6330:·7374·616c·6c5f·6f70·656e·7363·0a0a·636c··stall_opensc..cl
 000b6340:·6173·7320·696e·7374·616c·6c5f·6f70·656e··ass·install_open
 000b6350:·7363·207b·0a20·2070·6163·6b61·6765·207b··sc·{.··package·{
 000b6360:·2027·6f70·656e·7363·273a·0a20·2020·2065···'opensc':.····e
 000b6370:·6e73·7572·6520·3d26·6774·3b20·2769·6e73··nsure·=&gt;·'ins
 000b6380:·7461·6c6c·6564·272c·0a20·207d·0a7d·0a3c··talled',.··}.}.<
 000b6390:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di
 000b63a0:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn·
 000b63b0:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat
 000b63c0:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap
 000b63d0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
 000b63e0:·2223·6964·6d37·3738·3422·2074·6162·696e··"#idm7784"·tabin
 000b63f0:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
 000b6400:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
 000b6410:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
 000b6420:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
 000b6430:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
 000b6440:·3e52·656d·6564·6961·7469·6f6e·2053·6865··>Remediation·She
000b62c0:·7420·736e·6970·7065·7420·e287·b23c·2f61··t·snippet·...</a000b6450:·6c6c·2073·6372·6970·7420·e287·b23c·2f61··ll·script·...</a
000b62d0:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=000b6460:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
000b62e0:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·000b6470:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
000b62f0:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id000b6480:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
000b6300:·6d37·3738·3322·3e3c·7072·653e·3c63·6f64··m7783"><pre><cod 
000b6310:·653e·0a5b·5b70·6163·6b61·6765·735d·5d0a··e>.[[packages]]. 
000b6320:·6e61·6d65·203d·2022·6f70·656e·7363·220a··name·=·"opensc". 
000b6330:·7665·7273·696f·6e20·3d20·222a·220a·3c2f··version·=·"*".</ 
000b6340:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div 
000b6350:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b 
000b6360:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data 
000b6370:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps 
000b6380:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target=" 
000b6390:·2369·646d·3737·3834·2220·7461·6269·6e64··#idm7784"·tabind 
000b63a0:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but 
000b63b0:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand 
000b63c0:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title 
000b63d0:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re 
000b63e0:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!"> 
000b63f0:·5265·6d65·6469·6174·696f·6e20·5075·7070··Remediation·Pupp 
000b6400:·6574·2073·6e69·7070·6574·20e2·87b2·3c2f··et·snippet·...</ 
000b6410:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class 
000b6420:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse 
000b6430:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i 
000b6440:·646d·3737·3834·223e·3c74·6162·6c65·2063··dm7784"><table·c000b6490:·6d37·3738·3422·3e3c·7461·626c·6520·636c··m7784"><table·cl
 000b64a0:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table
000b6450:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl 
000b6460:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table- 
000b6470:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c000b64b0:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b
 000b64c0:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co
 000b64d0:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th
 000b64e0:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th
 000b64f0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
 000b6500:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup
 000b6510:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo
000b6480:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t 
000b6490:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t 
000b64a0:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></ 
000b64b0:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru 
000b64c0:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l 
Max diff block lines reached; 28346/46590 bytes (60.84%) of diff not shown.
5.21 KB
html2text {}
    
Offset 8767, 21 lines modifiedOffset 8767, 14 lines modified
8767 ··-·NIST-800-53-CM-6(a)8767 ··-·NIST-800-53-CM-6(a)
8768 ··-·enable_strategy8768 ··-·enable_strategy
8769 ··-·low_complexity8769 ··-·low_complexity
8770 ··-·low_disruption8770 ··-·low_disruption
8771 ··-·medium_severity8771 ··-·medium_severity
8772 ··-·no_reboot_needed8772 ··-·no_reboot_needed
8773 ··-·package_opensc_installed8773 ··-·package_opensc_installed
8774 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
8775 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
8776 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
8777 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
8778 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
8779 package·--add=opensc 
8780 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x88774 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
8781 [[packages]]8775 [[packages]]
8782 name·=·"opensc"8776 name·=·"opensc"
8783 version·=·"*"8777 version·=·"*"
8784 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x88778 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
8785 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low8779 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 8806, 14 lines modifiedOffset 8799, 21 lines modified
8806 if·!·rpm·-q·--quiet·"opensc"·;·then8799 if·!·rpm·-q·--quiet·"opensc"·;·then
8807 ····yum·install·-y·"opensc"8800 ····yum·install·-y·"opensc"
8808 fi8801 fi
  
8809 else8802 else
8810 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'8803 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
8811 fi8804 fi
 8805 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 8806 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 8807 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 8808 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 8809 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 8810 package·--add=opensc
8812 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·t\x8th\x8he\x8e·p\x8pc\x8cs\x8sc\x8c-\x8-l\x8li\x8it\x8te\x8e·p\x8pa\x8ac\x8ck\x8ka\x8ag\x8ge\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*8811 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·t\x8th\x8he\x8e·p\x8pc\x8cs\x8sc\x8c-\x8-l\x8li\x8it\x8te\x8e·p\x8pa\x8ac\x8ck\x8ka\x8ag\x8ge\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
8813 The·pcsc-lite·package·can·be·installed·with·the·following·command:8812 The·pcsc-lite·package·can·be·installed·with·the·following·command:
8814 $·sudo·yum·install·pcsc-lite8813 $·sudo·yum·install·pcsc-lite
8815 Rationale:··The·pcsc-lite·package·must·be·installed·if·it·is·to·be·available·for·multifactor·authentication·using·smartcards.8814 Rationale:··The·pcsc-lite·package·must·be·installed·if·it·is·to·be·available·for·multifactor·authentication·using·smartcards.
8816 Severity: ··medium8815 Severity: ··medium
8817 Rule·ID:····xccdf_org.ssgproject.content_rule_package_pcsc-lite_installed8816 Rule·ID:····xccdf_org.ssgproject.content_rule_package_pcsc-lite_installed
8818 ············_\x8d_\x8i_\x8s_\x8a···CCI-0040468817 ············_\x8d_\x8i_\x8s_\x8a···CCI-004046
Offset 8846, 21 lines modifiedOffset 8846, 14 lines modified
8846 ··-·NIST-800-53-CM-6(a)8846 ··-·NIST-800-53-CM-6(a)
8847 ··-·enable_strategy8847 ··-·enable_strategy
8848 ··-·low_complexity8848 ··-·low_complexity
8849 ··-·low_disruption8849 ··-·low_disruption
8850 ··-·medium_severity8850 ··-·medium_severity
8851 ··-·no_reboot_needed8851 ··-·no_reboot_needed
8852 ··-·package_pcsc-lite_installed8852 ··-·package_pcsc-lite_installed
8853 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
8854 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
8855 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
8856 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
8857 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
8858 package·--add=pcsc-lite 
8859 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x88853 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
8860 [[packages]]8854 [[packages]]
8861 name·=·"pcsc-lite"8855 name·=·"pcsc-lite"
8862 version·=·"*"8856 version·=·"*"
8863 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x88857 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
8864 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low8858 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Offset 8885, 14 lines modifiedOffset 8878, 21 lines modified
8885 if·!·rpm·-q·--quiet·"pcsc-lite"·;·then8878 if·!·rpm·-q·--quiet·"pcsc-lite"·;·then
8886 ····yum·install·-y·"pcsc-lite"8879 ····yum·install·-y·"pcsc-lite"
8887 fi8880 fi
  
8888 else8881 else
8889 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'8882 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
8890 fi8883 fi
 8884 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 8885 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 8886 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 8887 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 8888 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 8889 package·--add=pcsc-lite
8891 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·t\x8th\x8he\x8e·p\x8pc\x8cs\x8sc\x8cd\x8d·S\x8Se\x8er\x8rv\x8vi\x8ic\x8ce\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*8890 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·t\x8th\x8he\x8e·p\x8pc\x8cs\x8sc\x8cd\x8d·S\x8Se\x8er\x8rv\x8vi\x8ic\x8ce\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
8892 The·pcscd·service·can·be·enabled·with·the·following·command:8891 The·pcscd·service·can·be·enabled·with·the·following·command:
8893 $·sudo·systemctl·enable·pcscd.service8892 $·sudo·systemctl·enable·pcscd.service
8894 ············Using·an·authentication·device,·such·as·a·CAC·or·token·that·is·separate·from·the·information·system,·ensures·that·even·if·the·information·system·is·compromised,·that·compromise·will·not·affect·credentials·stored·on·the·authentication·device.8893 ············Using·an·authentication·device,·such·as·a·CAC·or·token·that·is·separate·from·the·information·system,·ensures·that·even·if·the·information·system·is·compromised,·that·compromise·will·not·affect·credentials·stored·on·the·authentication·device.
8895 Rationale:8894 Rationale:
8896 ············Multifactor·solutions·that·require·devices·separate·from·information·systems·gaining·access·include,·for·example,·hardware·tokens·providing·time-based·or·challenge-response·authenticators·and·smart·cards·such·as·the·U.S.·Government·Personal·Identity·Verification·card·and·the·DoD·Common·Access·Card.8895 ············Multifactor·solutions·that·require·devices·separate·from·information·systems·gaining·access·include,·for·example,·hardware·tokens·providing·time-based·or·challenge-response·authenticators·and·smart·cards·such·as·the·U.S.·Government·Personal·Identity·Verification·card·and·the·DoD·Common·Access·Card.
8897 Severity: ··medium8896 Severity: ··medium
Offset 52367, 39 lines modifiedOffset 52367, 39 lines modified
52367 ··-·medium_severity52367 ··-·medium_severity
52368 ··-·no_reboot_needed52368 ··-·no_reboot_needed
52369 ··-·service_auditd_enabled52369 ··-·service_auditd_enabled
52370 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x852370 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
52371 [customizations.services]52371 [customizations.services]
52372 enabled·=·["auditd"]52372 enabled·=·["auditd"]
52373 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
52374 --- 
52375 apiVersion:·machineconfiguration.openshift.io/v1 
52376 kind:·MachineConfig 
52377 spec: 
52378 ··config: 
52379 ····ignition: 
52380 ······version:·3.1.0 
52381 ····systemd: 
52382 ······units: 
52383 ······-·name:·auditd.service 
52384 ········enabled:·true 
52385 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x852373 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
52386 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low52374 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
52387 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low52375 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
52388 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false52376 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
52389 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable52377 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
52390 include·enable_auditd52378 include·enable_auditd
  
52391 class·enable_auditd·{52379 class·enable_auditd·{
52392 ··service·{'auditd':52380 ··service·{'auditd':
52393 ····enable·=>·true,52381 ····enable·=>·true,
52394 ····ensure·=>·'running',52382 ····ensure·=>·'running',
52395 ··}52383 ··}
52396 }52384 }
 52385 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 52386 ---
 52387 apiVersion:·machineconfiguration.openshift.io/v1
 52388 kind:·MachineConfig
 52389 spec:
 52390 ··config:
 52391 ····ignition:
Max diff block lines reached; 265/5313 bytes (4.99%) of diff not shown.
10.7 KB
./usr/share/doc/ssg-nondebian/ssg-sle12-guide-cis.html
    
Offset 165933, 73 lines modifiedOffset 165933, 73 lines modified
002882c0:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm002882c0:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
002882d0:·3339·3738·3622·2074·6162·696e·6465·783d··39786"·tabindex=002882d0:·3339·3738·3622·2074·6162·696e·6465·783d··39786"·tabindex=
002882e0:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button002882e0:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button
002882f0:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=002882f0:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=
00288300:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A00288300:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A
00288310:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea00288310:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea
00288320:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem00288320:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem
00288330:·6564·6961·7469·6f6e·2041·6e61·636f·6e64··ediation·Anacond 
00288340:·6120·736e·6970·7065·7420·e287·b23c·2f61··a·snippet·...</a00288330:·6564·6961·7469·6f6e·2053·6865·6c6c·2073··ediation·Shell·s
 00288340:·6372·6970·7420·e287·b23c·2f61·3e3c·6272··cript·...</a><br
00288350:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=00288350:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
00288360:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·00288360:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
00288370:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id00288370:·6170·7365·2220·6964·3d22·6964·6d33·3937··apse"·id="idm397
00288380:·6d33·3937·3836·223e·3c70·7265·3e3c·636f··m39786"><pre><co 
00288390:·6465·3e0a·7061·636b·6167·6520·2d2d·7265··de>.package·--re 
002883a0:·6d6f·7665·3d78·6f72·672d·7831·312d·7365··move=xorg-x11-se 
002883b0:·7276·6572·2d58·6f72·6720·2d2d·7265·6d6f··rver-Xorg·--remo00288380:·3836·223e·3c74·6162·6c65·2063·6c61·7373··86"><table·class
 00288390:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st
 002883a0:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord
 002883b0:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde
 002883c0:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co
 002883d0:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t
 002883e0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
 002883f0:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio
 00288400:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</
 00288410:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 00288420:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td>
 00288430:·7472·7565·3c2f·7464·3e3c·2f74·723e·3c74··true</td></tr><t
 00288440:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<
 00288450:·2f74·683e·3c74·643e·7265·7374·7269·6374··/th><td>restrict
 00288460:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl
 00288470:·653e·3c70·7265·3e3c·636f·6465·3e0a·0a23··e><pre><code>..#
 00288480:·2072·656d·6f76·6520·7061·636b·6167·6573···remove·packages
 00288490:·0a7a·7970·7065·7220·7265·6d6f·7665·202d··.zypper·remove·-
002883c0:·7665·3d78·6f72·672d·7831·312d·7365·7276··ve=xorg-x11-serv002884a0:·7920·2278·6f72·672d·7831·312d·7365·7276··y·"xorg-x11-serv
 002884b0:·6572·2d58·6f72·6722·0a7a·7970·7065·7220··er-Xorg".zypper·
 002884c0:·7265·6d6f·7665·202d·7920·2278·6f72·672d··remove·-y·"xorg-
 002884d0:·7831·312d·7365·7276·6572·2d75·7469·6c73··x11-server-utils
002883d0:·6572·2d63·6f6d·6d6f·6e20·2d2d·7265·6d6f··er-common·--remo 
002883e0:·7665·3d78·6f72·672d·7831·312d·7365·7276··ve=xorg-x11-serv 
002883f0:·6572·2d75·7469·6c73·202d·2d72·656d·6f76··er-utils·--remov 
00288400:·653d·786f·7267·2d78·3131·2d73·6572·7665··e=xorg-x11-serve 
00288410:·722d·5877·6179·6c61·6e64·0a3c·2f63·6f64··r-Xwayland.</cod 
00288420:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a 
00288430:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn- 
00288440:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to 
00288450:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"· 
00288460:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id 
00288470:·6d33·3937·3837·2220·7461·6269·6e64·6578··m39787"·tabindex 
00288480:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto 
00288490:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded 
002884a0:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title=" 
002884b0:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve 
002884c0:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re 
002884d0:·6d65·6469·6174·696f·6e20·5368·656c·6c20··mediation·Shell· 
002884e0:·7363·7269·7074·20e2·87b2·3c2f·613e·3c62··script·...</a><b 
002884f0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa 
00288500:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col 
00288510:·6c61·7073·6522·2069·643d·2269·646d·3339··lapse"·id="idm39 
00288520:·3738·3722·3e3c·7461·626c·6520·636c·6173··787"><table·clas 
00288530:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s 
00288540:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor 
00288550:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond 
00288560:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C 
00288570:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th>< 
00288580:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
00288590:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti 
002885a0:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low< 
002885b0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
002885c0:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td 
002885d0:·3e74·7275·653c·2f74·643e·3c2f·7472·3e3c··>true</td></tr>< 
002885e0:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy: 
002885f0:·3c2f·7468·3e3c·7464·3e72·6573·7472·6963··</th><td>restric 
00288600:·743c·2f74·643e·3c2f·7472·3e3c·2f74·6162··t</td></tr></tab 
00288610:·6c65·3e3c·7072·653e·3c63·6f64·653e·0a0a··le><pre><code>.. 
00288620:·2320·7265·6d6f·7665·2070·6163·6b61·6765··#·remove·package 
00288630:·730a·7a79·7070·6572·2072·656d·6f76·6520··s.zypper·remove·002884e0:·220a·7a79·7070·6572·2072·656d·6f76·6520··".zypper·remove·
00288640:·2d79·2022·786f·7267·2d78·3131·2d73·6572··-y·"xorg-x11-ser002884f0:·2d79·2022·786f·7267·2d78·3131·2d73·6572··-y·"xorg-x11-ser
00288650:·7665·722d·586f·7267·220a·7a79·7070·6572··ver-Xorg".zypper 
00288660:·2072·656d·6f76·6520·2d79·2022·786f·7267···remove·-y·"xorg 
00288670:·2d78·3131·2d73·6572·7665·722d·7574·696c··-x11-server-util 
00288680:·7322·0a7a·7970·7065·7220·7265·6d6f·7665··s".zypper·remove 
00288690:·202d·7920·2278·6f72·672d·7831·312d·7365···-y·"xorg-x11-se 
002886a0:·7276·6572·2d63·6f6d·6d6f·6e22·0a0a·7a79··rver-common"..zy 
002886b0:·7070·6572·2072·656d·6f76·6520·2d79·2022··pper·remove·-y·"00288500:·7665·722d·636f·6d6d·6f6e·220a·0a7a·7970··ver-common"..zyp
 00288510:·7065·7220·7265·6d6f·7665·202d·7920·2278··per·remove·-y·"x
 00288520:·6f72·672d·7831·312d·7365·7276·6572·2d58··org-x11-server-X
 00288530:·7761·796c·616e·6422·0a3c·2f63·6f64·653e··wayland".</code>
 00288540:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c
 00288550:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su
 00288560:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg
 00288570:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da
 00288580:·7461·2d74·6172·6765·743d·2223·6964·6d33··ta-target="#idm3
 00288590:·3937·3837·2220·7461·6269·6e64·6578·3d22··9787"·tabindex="
 002885a0:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
 002885b0:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
 002885c0:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
 002885d0:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
 002885e0:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
 002885f0:·6469·6174·696f·6e20·416e·6163·6f6e·6461··diation·Anaconda
 00288600:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>
 00288610:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="
 00288620:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c
 00288630:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm
 00288640:·3339·3738·3722·3e3c·7072·653e·3c63·6f64··39787"><pre><cod
 00288650:·653e·0a70·6163·6b61·6765·202d·2d72·656d··e>.package·--rem
 00288660:·6f76·653d·786f·7267·2d78·3131·2d73·6572··ove=xorg-x11-ser
 00288670:·7665·722d·586f·7267·202d·2d72·656d·6f76··ver-Xorg·--remov
002886c0:·786f·7267·2d78·3131·2d73·6572·7665·722d··xorg-x11-server-00288680:·653d·786f·7267·2d78·3131·2d73·6572·7665··e=xorg-x11-serve
 00288690:·722d·636f·6d6d·6f6e·202d·2d72·656d·6f76··r-common·--remov
 002886a0:·653d·786f·7267·2d78·3131·2d73·6572·7665··e=xorg-x11-serve
 002886b0:·722d·7574·696c·7320·2d2d·7265·6d6f·7665··r-utils·--remove
 002886c0:·3d78·6f72·672d·7831·312d·7365·7276·6572··=xorg-x11-server
002886d0:·5877·6179·6c61·6e64·220a·3c2f·636f·6465··Xwayland".</code002886d0:·2d58·7761·796c·616e·640a·3c2f·636f·6465··-Xwayland.</code
002886e0:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·2f64··></pre></div></d002886e0:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·2f64··></pre></div></d
002886f0:·6976·3e3c·2f74·643e·3c2f·7472·3e3c·2f74··iv></td></tr></t002886f0:·6976·3e3c·2f74·643e·3c2f·7472·3e3c·2f74··iv></td></tr></t
00288700:·626f·6479·3e3c·2f74·6162·6c65·3e3c·2f74··body></table></t00288700:·626f·6479·3e3c·2f74·6162·6c65·3e3c·2f74··body></table></t
00288710:·643e·3c2f·7472·3e3c·7472·2064·6174·612d··d></tr><tr·data-00288710:·643e·3c2f·7472·3e3c·7472·2064·6174·612d··d></tr><tr·data-
00288720:·7474·2d69·643d·2263·6869·6c64·7265·6e2d··tt-id="children-00288720:·7474·2d69·643d·2263·6869·6c64·7265·6e2d··tt-id="children-
00288730:·7863·6364·665f·6f72·672e·7373·6770·726f··xccdf_org.ssgpro00288730:·7863·6364·665f·6f72·672e·7373·6770·726f··xccdf_org.ssgpro
00288740:·6a65·6374·2e63·6f6e·7465·6e74·5f67·726f··ject.content_gro00288740:·6a65·6374·2e63·6f6e·7465·6e74·5f67·726f··ject.content_gro
1.71 KB
html2text {}
    
Offset 36192, 31 lines modifiedOffset 36192, 31 lines modified
36192 Severity: ···medium36192 Severity: ···medium
36193 Rule·ID:·····xccdf_org.ssgproject.content_rule_xwindows_remove_packages36193 Rule·ID:·····xccdf_org.ssgproject.content_rule_xwindows_remove_packages
36194 Identifiers:·CCE-92242-736194 Identifiers:·CCE-92242-7
36195 ·············_\x8d_\x8i_\x8s_\x8a···CCI-00036636195 ·············_\x8d_\x8i_\x8s_\x8a···CCI-000366
36196 References:··_\x8n_\x8i_\x8s_\x8t···CM-6(b)36196 References:··_\x8n_\x8i_\x8s_\x8t···CM-6(b)
36197 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000480-GPOS-0022736197 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000480-GPOS-00227
36198 ·············_\x8c_\x8i_\x8s····2.2.236198 ·············_\x8c_\x8i_\x8s····2.2.2
36199 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
36200 package·--remove=xorg-x11-server-Xorg·--remove=xorg-x11-server-common·--remove=xorg-x11-server-utils·-- 
36201 remove=xorg-x11-server-Xwayland 
36202 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x836199 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
36203 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low36200 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
36204 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low36201 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
36205 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true36202 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
36206 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict36203 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
  
  
36207 #·remove·packages36204 #·remove·packages
36208 zypper·remove·-y·"xorg-x11-server-Xorg"36205 zypper·remove·-y·"xorg-x11-server-Xorg"
36209 zypper·remove·-y·"xorg-x11-server-utils"36206 zypper·remove·-y·"xorg-x11-server-utils"
36210 zypper·remove·-y·"xorg-x11-server-common"36207 zypper·remove·-y·"xorg-x11-server-common"
  
36211 zypper·remove·-y·"xorg-x11-server-Xwayland"36208 zypper·remove·-y·"xorg-x11-server-Xwayland"
 36209 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 36210 package·--remove=xorg-x11-server-Xorg·--remove=xorg-x11-server-common·--remove=xorg-x11-server-utils·--
 36211 remove=xorg-x11-server-Xwayland
36212 Group  ·System·Accounting·with·auditd·  Group·contains·9·groups·and·58·rules36212 Group  ·System·Accounting·with·auditd·  Group·contains·9·groups·and·58·rules
36213 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·audit·service·provides·substantial·capabilities·for·recording·system·activities.·By·default,36213 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·audit·service·provides·substantial·capabilities·for·recording·system·activities.·By·default,
36214 the·service·audits·about·SELinux·AVC·denials·and·certain·types·of·security-relevant·events·such·as·system36214 the·service·audits·about·SELinux·AVC·denials·and·certain·types·of·security-relevant·events·such·as·system
36215 logins,·account·modifications,·and·authentication·events·performed·by·programs·such·as·sudo.·Under·its36215 logins,·account·modifications,·and·authentication·events·performed·by·programs·such·as·sudo.·Under·its
36216 default·configuration,·auditd·has·modest·disk·space·requirements,·and·should·not·noticeably·impact·system36216 default·configuration,·auditd·has·modest·disk·space·requirements,·and·should·not·noticeably·impact·system
36217 performance.36217 performance.
  
10.5 KB
./usr/share/doc/ssg-nondebian/ssg-sle12-guide-cis_server_l1.html
    
Offset 160127, 73 lines modifiedOffset 160127, 73 lines modified
002717e0:·6172·6765·743d·2223·6964·6d33·3937·3836··arget="#idm39786002717e0:·6172·6765·743d·2223·6964·6d33·3937·3836··arget="#idm39786
002717f0:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r002717f0:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r
00271800:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari00271800:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari
00271810:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals00271810:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals
00271820:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa00271820:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa
00271830:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr00271830:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr
00271840:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat00271840:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat
00271850:·696f·6e20·416e·6163·6f6e·6461·2073·6e69··ion·Anaconda·sni00271850:·696f·6e20·5368·656c·6c20·7363·7269·7074··ion·Shell·script
00271860:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>00271860:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
00271870:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane00271870:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
00271880:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla00271880:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
00271890:·7073·6522·2069·643d·2269·646d·3339·3738··pse"·id="idm397800271890:·2069·643d·2269·646d·3339·3738·3622·3e3c···id="idm39786"><
 002718a0:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab
 002718b0:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped
002718a0:·3622·3e3c·7072·653e·3c63·6f64·653e·0a70··6"><pre><code>.p 
002718b0:·6163·6b61·6765·202d·2d72·656d·6f76·653d··ackage·--remove= 
002718c0:·786f·7267·2d78·3131·2d73·6572·7665·722d··xorg-x11-server- 
002718d0:·586f·7267·202d·2d72·656d·6f76·653d·786f··Xorg·--remove=xo 
002718e0:·7267·2d78·3131·2d73·6572·7665·722d·636f··rg-x11-server-co 
002718f0:·6d6d·6f6e·202d·2d72·656d·6f76·653d·786f··mmon·--remove=xo 
00271900:·7267·2d78·3131·2d73·6572·7665·722d·7574··rg-x11-server-ut 
00271910:·696c·7320·2d2d·7265·6d6f·7665·3d78·6f72··ils·--remove=xor 
00271920:·672d·7831·312d·7365·7276·6572·2d58·7761··g-x11-server-Xwa 
00271930:·796c·616e·640a·3c2f·636f·6465·3e3c·2f70··yland.</code></p 
00271940:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas 
00271950:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe 
00271960:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle= 
00271970:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data- 
00271980:·7461·7267·6574·3d22·2369·646d·3339·3738··target="#idm3978 
00271990:·3722·2074·6162·696e·6465·783d·2230·2220··7"·tabindex="0"· 
002719a0:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar 
002719b0:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal 
002719c0:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ 
002719d0:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h 
002719e0:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia 
002719f0:·7469·6f6e·2053·6865·6c6c·2073·6372·6970··tion·Shell·scrip 
00271a00:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di 
00271a10:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c 
00271a20:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse 
00271a30:·2220·6964·3d22·6964·6d33·3937·3837·223e··"·id="idm39787"> 
00271a40:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta 
00271a50:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe 
00271a60:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered 
00271a70:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed002718c0:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·
 002718d0:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"
 002718e0:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex
 002718f0:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low
00271a80:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple 
00271a90:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo 
00271aa0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr>< 
00271ab0:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</ 
00271ac0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td>< 
00271ad0:·2f74·723e·3c74·723e·3c74·683e·5265·626f··/tr><tr><th>Rebo 
00271ae0:·6f74·3a3c·2f74·683e·3c74·643e·7472·7565··ot:</th><td>true 
00271af0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t00271900:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
00271b00:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th> 
00271b10:·3c74·643e·7265·7374·7269·6374·3c2f·7464··<td>restrict</td 
00271b20:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p 
00271b30:·7265·3e3c·636f·6465·3e0a·0a23·2072·656d··re><code>..#·rem 
00271b40:·6f76·6520·7061·636b·6167·6573·0a7a·7970··ove·packages.zyp00271910:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t
 00271920:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
 00271930:·7472·3e3c·7472·3e3c·7468·3e52·6562·6f6f··tr><tr><th>Reboo
 00271940:·743a·3c2f·7468·3e3c·7464·3e74·7275·653c··t:</th><td>true<
 00271950:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 00271960:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><
 00271970:·7464·3e72·6573·7472·6963·743c·2f74·643e··td>restrict</td>
 00271980:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr
 00271990:·653e·3c63·6f64·653e·0a0a·2320·7265·6d6f··e><code>..#·remo
 002719a0:·7665·2070·6163·6b61·6765·730a·7a79·7070··ve·packages.zypp
 002719b0:·6572·2072·656d·6f76·6520·2d79·2022·786f··er·remove·-y·"xo
 002719c0:·7267·2d78·3131·2d73·6572·7665·722d·586f··rg-x11-server-Xo
 002719d0:·7267·220a·7a79·7070·6572·2072·656d·6f76··rg".zypper·remov
 002719e0:·6520·2d79·2022·786f·7267·2d78·3131·2d73··e·-y·"xorg-x11-s
 002719f0:·6572·7665·722d·7574·696c·7322·0a7a·7970··erver-utils".zyp
00271b50:·7065·7220·7265·6d6f·7665·202d·7920·2278··per·remove·-y·"x00271a00:·7065·7220·7265·6d6f·7665·202d·7920·2278··per·remove·-y·"x
 00271a10:·6f72·672d·7831·312d·7365·7276·6572·2d63··org-x11-server-c
 00271a20:·6f6d·6d6f·6e22·0a0a·7a79·7070·6572·2072··ommon"..zypper·r
 00271a30:·656d·6f76·6520·2d79·2022·786f·7267·2d78··emove·-y·"xorg-x
 00271a40:·3131·2d73·6572·7665·722d·5877·6179·6c61··11-server-Xwayla
 00271a50:·6e64·220a·3c2f·636f·6465·3e3c·2f70·7265··nd".</code></pre
 00271a60:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class=
 00271a70:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success
 00271a80:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c
 00271a90:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta
 00271aa0:·7267·6574·3d22·2369·646d·3339·3738·3722··rget="#idm39787"
 00271ab0:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro
 00271ac0:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria
 00271ad0:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false
 00271ae0:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat
 00271af0:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre
 00271b00:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati
 00271b10:·6f6e·2041·6e61·636f·6e64·6120·736e·6970··on·Anaconda·snip
 00271b20:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br><
 00271b30:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
 00271b40:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap
 00271b50:·7365·2220·6964·3d22·6964·6d33·3937·3837··se"·id="idm39787
 00271b60:·223e·3c70·7265·3e3c·636f·6465·3e0a·7061··"><pre><code>.pa
 00271b70:·636b·6167·6520·2d2d·7265·6d6f·7665·3d78··ckage·--remove=x
00271b60:·6f72·672d·7831·312d·7365·7276·6572·2d58··org-x11-server-X00271b80:·6f72·672d·7831·312d·7365·7276·6572·2d58··org-x11-server-X
 00271b90:·6f72·6720·2d2d·7265·6d6f·7665·3d78·6f72··org·--remove=xor
 00271ba0:·672d·7831·312d·7365·7276·6572·2d63·6f6d··g-x11-server-com
 00271bb0:·6d6f·6e20·2d2d·7265·6d6f·7665·3d78·6f72··mon·--remove=xor
00271b70:·6f72·6722·0a7a·7970·7065·7220·7265·6d6f··org".zypper·remo 
00271b80:·7665·202d·7920·2278·6f72·672d·7831·312d··ve·-y·"xorg-x11- 
00271b90:·7365·7276·6572·2d75·7469·6c73·220a·7a79··server-utils".zy 
00271ba0:·7070·6572·2072·656d·6f76·6520·2d79·2022··pper·remove·-y·" 
00271bb0:·786f·7267·2d78·3131·2d73·6572·7665·722d··xorg-x11-server- 
00271bc0:·636f·6d6d·6f6e·220a·0a7a·7970·7065·7220··common"..zypper· 
00271bd0:·7265·6d6f·7665·202d·7920·2278·6f72·672d··remove·-y·"xorg- 
00271be0:·7831·312d·7365·7276·6572·2d58·7761·796c··x11-server-Xwayl00271bc0:·672d·7831·312d·7365·7276·6572·2d75·7469··g-x11-server-uti
 00271bd0:·6c73·202d·2d72·656d·6f76·653d·786f·7267··ls·--remove=xorg
 00271be0:·2d78·3131·2d73·6572·7665·722d·5877·6179··-x11-server-Xway
00271bf0:·616e·6422·0a3c·2f63·6f64·653e·3c2f·7072··and".</code></pr00271bf0:·6c61·6e64·0a3c·2f63·6f64·653e·3c2f·7072··land.</code></pr
00271c00:·653e·3c2f·6469·763e·3c2f·6469·763e·3c2f··e></div></div></00271c00:·653e·3c2f·6469·763e·3c2f·6469·763e·3c2f··e></div></div></
00271c10:·7464·3e3c·2f74·723e·3c2f·7462·6f64·793e··td></tr></tbody>00271c10:·7464·3e3c·2f74·723e·3c2f·7462·6f64·793e··td></tr></tbody>
00271c20:·3c2f·7461·626c·653e·3c2f·7464·3e3c·2f74··</table></td></t00271c20:·3c2f·7461·626c·653e·3c2f·7464·3e3c·2f74··</table></td></t
00271c30:·723e·3c2f·7462·6f64·793e·3c2f·7461·626c··r></tbody></tabl00271c30:·723e·3c2f·7462·6f64·793e·3c2f·7461·626c··r></tbody></tabl
00271c40:·653e·3c2f·6469·763e·3c64·6976·2069·643d··e></div><div·id=00271c40:·653e·3c2f·6469·763e·3c64·6976·2069·643d··e></div><div·id=
00271c50:·2272·6561·722d·6d61·7474·6572·223e·3c64··"rear-matter"><d00271c50:·2272·6561·722d·6d61·7474·6572·223e·3c64··"rear-matter"><d
00271c60:·6976·2063·6c61·7373·3d22·726f·7720·746f··iv·class="row·to00271c60:·6976·2063·6c61·7373·3d22·726f·7720·746f··iv·class="row·to
1.47 KB
html2text {}
    
Offset 34881, 28 lines modifiedOffset 34881, 28 lines modified
34881 Severity: ···medium34881 Severity: ···medium
34882 Rule·ID:·····xccdf_org.ssgproject.content_rule_xwindows_remove_packages34882 Rule·ID:·····xccdf_org.ssgproject.content_rule_xwindows_remove_packages
34883 Identifiers:·CCE-92242-734883 Identifiers:·CCE-92242-7
34884 ·············_\x8d_\x8i_\x8s_\x8a···CCI-00036634884 ·············_\x8d_\x8i_\x8s_\x8a···CCI-000366
34885 References:··_\x8n_\x8i_\x8s_\x8t···CM-6(b)34885 References:··_\x8n_\x8i_\x8s_\x8t···CM-6(b)
34886 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000480-GPOS-0022734886 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000480-GPOS-00227
34887 ·············_\x8c_\x8i_\x8s····2.2.234887 ·············_\x8c_\x8i_\x8s····2.2.2
34888 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
34889 package·--remove=xorg-x11-server-Xorg·--remove=xorg-x11-server-common·--remove=xorg-x11-server-utils·-- 
34890 remove=xorg-x11-server-Xwayland 
34891 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x834888 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
34892 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low34889 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
34893 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low34890 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
34894 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true34891 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
34895 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict34892 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
  
  
34896 #·remove·packages34893 #·remove·packages
34897 zypper·remove·-y·"xorg-x11-server-Xorg"34894 zypper·remove·-y·"xorg-x11-server-Xorg"
34898 zypper·remove·-y·"xorg-x11-server-utils"34895 zypper·remove·-y·"xorg-x11-server-utils"
34899 zypper·remove·-y·"xorg-x11-server-common"34896 zypper·remove·-y·"xorg-x11-server-common"
  
34900 zypper·remove·-y·"xorg-x11-server-Xwayland"34897 zypper·remove·-y·"xorg-x11-server-Xwayland"
 34898 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 34899 package·--remove=xorg-x11-server-Xorg·--remove=xorg-x11-server-common·--remove=xorg-x11-server-utils·--
 34900 remove=xorg-x11-server-Xwayland
34901 Red·Hat·and·Red·Hat·Enterprise·Linux·are·either·registered·trademarks·or34901 Red·Hat·and·Red·Hat·Enterprise·Linux·are·either·registered·trademarks·or
34902 trademarks·of·Red·Hat,·Inc.·in·the·United·States·and·other·countries.·All·other34902 trademarks·of·Red·Hat,·Inc.·in·the·United·States·and·other·countries.·All·other
34903 names·are·registered·trademarks·or·trademarks·of·their·respective·companies.34903 names·are·registered·trademarks·or·trademarks·of·their·respective·companies.
34904 Generated·using·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8C_\x8A_\x8P·1.4.234904 Generated·using·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8C_\x8A_\x8P·1.4.2
10.7 KB
./usr/share/doc/ssg-nondebian/ssg-sle15-guide-cis.html
    
Offset 174579, 73 lines modifiedOffset 174579, 73 lines modified
002a9f20:·2d74·6172·6765·743d·2223·6964·6d34·3235··-target="#idm425002a9f20:·2d74·6172·6765·743d·2223·6964·6d34·3235··-target="#idm425
002a9f30:·3638·2220·7461·6269·6e64·6578·3d22·3022··68"·tabindex="0"002a9f30:·3638·2220·7461·6269·6e64·6578·3d22·3022··68"·tabindex="0"
002a9f40:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a002a9f40:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
002a9f50:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa002a9f50:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
002a9f60:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti002a9f60:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
002a9f70:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·002a9f70:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
002a9f80:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi002a9f80:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
002a9f90:·6174·696f·6e20·416e·6163·6f6e·6461·2073··ation·Anaconda·s002a9f90:·6174·696f·6e20·5368·656c·6c20·7363·7269··ation·Shell·scri
002a9fa0:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b002a9fa0:·7074·20e2·87b2·3c2f·613e·3c62·723e·3c64··pt·...</a><br><d
002a9fb0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa002a9fb0:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-
002a9fc0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col002a9fc0:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps
002a9fd0:·6c61·7073·6522·2069·643d·2269·646d·3432··lapse"·id="idm42002a9fd0:·6522·2069·643d·2269·646d·3432·3536·3822··e"·id="idm42568"
002a9fe0:·3536·3822·3e3c·7072·653e·3c63·6f64·653e··568"><pre><code> 
002a9ff0:·0a70·6163·6b61·6765·202d·2d72·656d·6f76··.package·--remov 
002aa000:·653d·786f·7267·2d78·3131·2d73·6572·7665··e=xorg-x11-serve 
002aa010:·722d·586f·7267·202d·2d72·656d·6f76·653d··r-Xorg·--remove=002a9fe0:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t
 002a9ff0:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip
 002aa000:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere
 002aa010:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense
 002aa020:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl
 002aa030:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l
 002aa040:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
 002aa050:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:<
 002aa060:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
 002aa070:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb
 002aa080:·6f6f·743a·3c2f·7468·3e3c·7464·3e74·7275··oot:</th><td>tru
 002aa090:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr><
 002aa0a0:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th
 002aa0b0:·3e3c·7464·3e72·6573·7472·6963·743c·2f74··><td>restrict</t
 002aa0c0:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><
 002aa0d0:·7072·653e·3c63·6f64·653e·0a0a·2320·7265··pre><code>..#·re
 002aa0e0:·6d6f·7665·2070·6163·6b61·6765·730a·7a79··move·packages.zy
 002aa0f0:·7070·6572·2072·656d·6f76·6520·2d79·2022··pper·remove·-y·"
002aa020:·786f·7267·2d78·3131·2d73·6572·7665·722d··xorg-x11-server-002aa100:·786f·7267·2d78·3131·2d73·6572·7665·722d··xorg-x11-server-
 002aa110:·586f·7267·220a·7a79·7070·6572·2072·656d··Xorg".zypper·rem
 002aa120:·6f76·6520·2d79·2022·786f·7267·2d78·3131··ove·-y·"xorg-x11
 002aa130:·2d73·6572·7665·722d·7574·696c·7322·0a7a··-server-utils".z
002aa030:·636f·6d6d·6f6e·202d·2d72·656d·6f76·653d··common·--remove= 
002aa040:·786f·7267·2d78·3131·2d73·6572·7665·722d··xorg-x11-server- 
002aa050:·7574·696c·7320·2d2d·7265·6d6f·7665·3d78··utils·--remove=x 
002aa060:·6f72·672d·7831·312d·7365·7276·6572·2d58··org-x11-server-X 
002aa070:·7761·796c·616e·640a·3c2f·636f·6465·3e3c··wayland.</code>< 
002aa080:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl 
002aa090:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc 
002aa0a0:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl 
002aa0b0:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat 
002aa0c0:·612d·7461·7267·6574·3d22·2369·646d·3432··a-target="#idm42 
002aa0d0:·3536·3922·2074·6162·696e·6465·783d·2230··569"·tabindex="0 
002aa0e0:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"· 
002aa0f0:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f 
002aa100:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act 
002aa110:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal" 
002aa120:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed 
002aa130:·6961·7469·6f6e·2053·6865·6c6c·2073·6372··iation·Shell·scr 
002aa140:·6970·7420·e287·b23c·2f61·3e3c·6272·3e3c··ipt·...</a><br>< 
002aa150:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel 
002aa160:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap 
002aa170:·7365·2220·6964·3d22·6964·6d34·3235·3639··se"·id="idm42569 
002aa180:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class=" 
002aa190:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri 
002aa1a0:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border 
002aa1b0:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens 
002aa1c0:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp 
002aa1d0:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td> 
002aa1e0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr 
002aa1f0:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption: 
002aa200:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td 
002aa210:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re 
002aa220:·626f·6f74·3a3c·2f74·683e·3c74·643e·7472··boot:</th><td>tr 
002aa230:·7565·3c2f·7464·3e3c·2f74·723e·3c74·723e··ue</td></tr><tr> 
002aa240:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t 
002aa250:·683e·3c74·643e·7265·7374·7269·6374·3c2f··h><td>restrict</ 
002aa260:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table> 
002aa270:·3c70·7265·3e3c·636f·6465·3e0a·0a23·2072··<pre><code>..#·r 
002aa280:·656d·6f76·6520·7061·636b·6167·6573·0a7a··emove·packages.z 
002aa290:·7970·7065·7220·7265·6d6f·7665·202d·7920··ypper·remove·-y·002aa140:·7970·7065·7220·7265·6d6f·7665·202d·7920··ypper·remove·-y·
002aa2a0:·2278·6f72·672d·7831·312d·7365·7276·6572··"xorg-x11-server002aa150:·2278·6f72·672d·7831·312d·7365·7276·6572··"xorg-x11-server
002aa2b0:·2d58·6f72·6722·0a7a·7970·7065·7220·7265··-Xorg".zypper·re 
002aa2c0:·6d6f·7665·202d·7920·2278·6f72·672d·7831··move·-y·"xorg-x1 
002aa2d0:·312d·7365·7276·6572·2d75·7469·6c73·220a··1-server-utils". 
002aa2e0:·7a79·7070·6572·2072·656d·6f76·6520·2d79··zypper·remove·-y 
002aa2f0:·2022·786f·7267·2d78·3131·2d73·6572·7665···"xorg-x11-serve 
002aa300:·722d·636f·6d6d·6f6e·220a·0a7a·7970·7065··r-common"..zyppe 
002aa310:·7220·7265·6d6f·7665·202d·7920·2278·6f72··r·remove·-y·"xor002aa160:·2d63·6f6d·6d6f·6e22·0a0a·7a79·7070·6572··-common"..zypper
 002aa170:·2072·656d·6f76·6520·2d79·2022·786f·7267···remove·-y·"xorg
 002aa180:·2d78·3131·2d73·6572·7665·722d·5877·6179··-x11-server-Xway
 002aa190:·6c61·6e64·220a·3c2f·636f·6465·3e3c·2f70··land".</code></p
 002aa1a0:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas
 002aa1b0:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe
 002aa1c0:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle=
 002aa1d0:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data-
 002aa1e0:·7461·7267·6574·3d22·2369·646d·3432·3536··target="#idm4256
 002aa1f0:·3922·2074·6162·696e·6465·783d·2230·2220··9"·tabindex="0"·
 002aa200:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar
 002aa210:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal
 002aa220:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ
 002aa230:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h
 002aa240:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia
 002aa250:·7469·6f6e·2041·6e61·636f·6e64·6120·736e··tion·Anaconda·sn
 002aa260:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br
 002aa270:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
 002aa280:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
 002aa290:·6170·7365·2220·6964·3d22·6964·6d34·3235··apse"·id="idm425
 002aa2a0:·3639·223e·3c70·7265·3e3c·636f·6465·3e0a··69"><pre><code>.
 002aa2b0:·7061·636b·6167·6520·2d2d·7265·6d6f·7665··package·--remove
 002aa2c0:·3d78·6f72·672d·7831·312d·7365·7276·6572··=xorg-x11-server
 002aa2d0:·2d58·6f72·6720·2d2d·7265·6d6f·7665·3d78··-Xorg·--remove=x
002aa320:·672d·7831·312d·7365·7276·6572·2d58·7761··g-x11-server-Xwa002aa2e0:·6f72·672d·7831·312d·7365·7276·6572·2d63··org-x11-server-c
 002aa2f0:·6f6d·6d6f·6e20·2d2d·7265·6d6f·7665·3d78··ommon·--remove=x
 002aa300:·6f72·672d·7831·312d·7365·7276·6572·2d75··org-x11-server-u
 002aa310:·7469·6c73·202d·2d72·656d·6f76·653d·786f··tils·--remove=xo
 002aa320:·7267·2d78·3131·2d73·6572·7665·722d·5877··rg-x11-server-Xw
002aa330:·796c·616e·6422·0a3c·2f63·6f64·653e·3c2f··yland".</code></002aa330:·6179·6c61·6e64·0a3c·2f63·6f64·653e·3c2f··ayland.</code></
002aa340:·7072·653e·3c2f·6469·763e·3c2f·6469·763e··pre></div></div>002aa340:·7072·653e·3c2f·6469·763e·3c2f·6469·763e··pre></div></div>
002aa350:·3c2f·7464·3e3c·2f74·723e·3c2f·7462·6f64··</td></tr></tbod002aa350:·3c2f·7464·3e3c·2f74·723e·3c2f·7462·6f64··</td></tr></tbod
002aa360:·793e·3c2f·7461·626c·653e·3c2f·7464·3e3c··y></table></td><002aa360:·793e·3c2f·7461·626c·653e·3c2f·7464·3e3c··y></table></td><
002aa370:·2f74·723e·3c74·7220·6461·7461·2d74·742d··/tr><tr·data-tt-002aa370:·2f74·723e·3c74·7220·6461·7461·2d74·742d··/tr><tr·data-tt-
002aa380:·6964·3d22·6368·696c·6472·656e·2d78·6363··id="children-xcc002aa380:·6964·3d22·6368·696c·6472·656e·2d78·6363··id="children-xcc
002aa390:·6466·5f6f·7267·2e73·7367·7072·6f6a·6563··df_org.ssgprojec002aa390:·6466·5f6f·7267·2e73·7367·7072·6f6a·6563··df_org.ssgprojec
002aa3a0:·742e·636f·6e74·656e·745f·6772·6f75·705f··t.content_group_002aa3a0:·742e·636f·6e74·656e·745f·6772·6f75·705f··t.content_group_
1.71 KB
html2text {}
    
Offset 38123, 31 lines modifiedOffset 38123, 31 lines modified
38123 Severity: ···medium38123 Severity: ···medium
38124 Rule·ID:·····xccdf_org.ssgproject.content_rule_xwindows_remove_packages38124 Rule·ID:·····xccdf_org.ssgproject.content_rule_xwindows_remove_packages
38125 Identifiers:·CCE-91362-438125 Identifiers:·CCE-91362-4
38126 ·············_\x8d_\x8i_\x8s_\x8a···CCI-00036638126 ·············_\x8d_\x8i_\x8s_\x8a···CCI-000366
38127 References:··_\x8n_\x8i_\x8s_\x8t···CM-6(b)38127 References:··_\x8n_\x8i_\x8s_\x8t···CM-6(b)
38128 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000480-GPOS-0022738128 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000480-GPOS-00227
38129 ·············_\x8c_\x8i_\x8s····2.2.238129 ·············_\x8c_\x8i_\x8s····2.2.2
38130 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
38131 package·--remove=xorg-x11-server-Xorg·--remove=xorg-x11-server-common·--remove=xorg-x11-server-utils·-- 
38132 remove=xorg-x11-server-Xwayland 
38133 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x838130 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
38134 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low38131 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
38135 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low38132 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
38136 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true38133 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
38137 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict38134 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
  
  
38138 #·remove·packages38135 #·remove·packages
38139 zypper·remove·-y·"xorg-x11-server-Xorg"38136 zypper·remove·-y·"xorg-x11-server-Xorg"
38140 zypper·remove·-y·"xorg-x11-server-utils"38137 zypper·remove·-y·"xorg-x11-server-utils"
38141 zypper·remove·-y·"xorg-x11-server-common"38138 zypper·remove·-y·"xorg-x11-server-common"
  
38142 zypper·remove·-y·"xorg-x11-server-Xwayland"38139 zypper·remove·-y·"xorg-x11-server-Xwayland"
 38140 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 38141 package·--remove=xorg-x11-server-Xorg·--remove=xorg-x11-server-common·--remove=xorg-x11-server-utils·--
 38142 remove=xorg-x11-server-Xwayland
38143 Group  ·System·Accounting·with·auditd·  Group·contains·9·groups·and·58·rules38143 Group  ·System·Accounting·with·auditd·  Group·contains·9·groups·and·58·rules
38144 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·audit·service·provides·substantial·capabilities·for·recording·system·activities.·By·default,38144 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·audit·service·provides·substantial·capabilities·for·recording·system·activities.·By·default,
38145 the·service·audits·about·SELinux·AVC·denials·and·certain·types·of·security-relevant·events·such·as·system38145 the·service·audits·about·SELinux·AVC·denials·and·certain·types·of·security-relevant·events·such·as·system
38146 logins,·account·modifications,·and·authentication·events·performed·by·programs·such·as·sudo.·Under·its38146 logins,·account·modifications,·and·authentication·events·performed·by·programs·such·as·sudo.·Under·its
38147 default·configuration,·auditd·has·modest·disk·space·requirements,·and·should·not·noticeably·impact·system38147 default·configuration,·auditd·has·modest·disk·space·requirements,·and·should·not·noticeably·impact·system
38148 performance.38148 performance.
  
10.4 KB
./usr/share/doc/ssg-nondebian/ssg-sle15-guide-cis_server_l1.html
    
Offset 168295, 72 lines modifiedOffset 168295, 72 lines modified
00291660:·743d·2223·6964·6d34·3235·3638·2220·7461··t="#idm42568"·ta00291660:·743d·2223·6964·6d34·3235·3638·2220·7461··t="#idm42568"·ta
00291670:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=00291670:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
00291680:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex00291680:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
00291690:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t00291690:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
002916a0:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t002916a0:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
002916b0:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="002916b0:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
002916c0:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·002916c0:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
002916d0:·416e·6163·6f6e·6461·2073·6e69·7070·6574··Anaconda·snippet002916d0:·5368·656c·6c20·7363·7269·7074·20e2·87b2··Shell·script·...
002916e0:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div002916e0:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
002916f0:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co002916f0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
00291700:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"00291700:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
00291710:·2069·643d·2269·646d·3432·3536·3822·3e3c···id="idm42568"><00291710:·2269·646d·3432·3536·3822·3e3c·7461·626c··"idm42568"><tabl
 00291720:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t
 00291730:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab
 00291740:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl
 00291750:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr
 00291760:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:
 00291770:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
00291720:·7072·653e·3c63·6f64·653e·0a70·6163·6b61··pre><code>.packa 
00291730:·6765·202d·2d72·656d·6f76·653d·786f·7267··ge·--remove=xorg 
00291740:·2d78·3131·2d73·6572·7665·722d·586f·7267··-x11-server-Xorg 
00291750:·202d·2d72·656d·6f76·653d·786f·7267·2d78···--remove=xorg-x 
00291760:·3131·2d73·6572·7665·722d·636f·6d6d·6f6e··11-server-common 
00291770:·202d·2d72·656d·6f76·653d·786f·7267·2d78···--remove=xorg-x 
00291780:·3131·2d73·6572·7665·722d·7574·696c·7320··11-server-utils· 
00291790:·2d2d·7265·6d6f·7665·3d78·6f72·672d·7831··--remove=xorg-x1 
002917a0:·312d·7365·7276·6572·2d58·7761·796c·616e··1-server-Xwaylan 
002917b0:·640a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··d.</code></pre>< 
002917c0:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b 
002917d0:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"· 
002917e0:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col 
002917f0:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ 
00291800:·6574·3d22·2369·646d·3432·3536·3922·2074··et="#idm42569"·t 
00291810:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role 
00291820:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e 
00291830:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"· 
00291840:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate· 
00291850:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href= 
00291860:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation 
00291870:·2053·6865·6c6c·2073·6372·6970·7420·e287···Shell·script·.. 
00291880:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl 
00291890:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla 
002918a0:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id 
002918b0:·3d22·6964·6d34·3235·3639·223e·3c74·6162··="idm42569"><tab 
002918c0:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table· 
002918d0:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta 
002918e0:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab 
002918f0:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t 
00291900:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity 
00291910:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t 
00291920:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D 
00291930:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th>< 
00291940:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
00291950:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:< 
00291960:·2f74·683e·3c74·643e·7472·7565·3c2f·7464··/th><td>true</td 
00291970:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St00291780:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di
00291980:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td> 
00291990:·7265·7374·7269·6374·3c2f·7464·3e3c·2f74··restrict</td></t 
002919a0:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre>< 
002919b0:·636f·6465·3e0a·0a23·2072·656d·6f76·6520··code>..#·remove· 
002919c0:·7061·636b·6167·6573·0a7a·7970·7065·7220··packages.zypper·00291790:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t
 002917a0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
 002917b0:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</
 002917c0:·7468·3e3c·7464·3e74·7275·653c·2f74·643e··th><td>true</td>
 002917d0:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str
 002917e0:·6174·6567·793a·3c2f·7468·3e3c·7464·3e72··ategy:</th><td>r
 002917f0:·6573·7472·6963·743c·2f74·643e·3c2f·7472··estrict</td></tr
 00291800:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c
 00291810:·6f64·653e·0a0a·2320·7265·6d6f·7665·2070··ode>..#·remove·p
 00291820:·6163·6b61·6765·730a·7a79·7070·6572·2072··ackages.zypper·r
 00291830:·656d·6f76·6520·2d79·2022·786f·7267·2d78··emove·-y·"xorg-x
 00291840:·3131·2d73·6572·7665·722d·586f·7267·220a··11-server-Xorg".
 00291850:·7a79·7070·6572·2072·656d·6f76·6520·2d79··zypper·remove·-y
 00291860:·2022·786f·7267·2d78·3131·2d73·6572·7665···"xorg-x11-serve
 00291870:·722d·7574·696c·7322·0a7a·7970·7065·7220··r-utils".zypper·
002919d0:·7265·6d6f·7665·202d·7920·2278·6f72·672d··remove·-y·"xorg-00291880:·7265·6d6f·7665·202d·7920·2278·6f72·672d··remove·-y·"xorg-
 00291890:·7831·312d·7365·7276·6572·2d63·6f6d·6d6f··x11-server-commo
 002918a0:·6e22·0a0a·7a79·7070·6572·2072·656d·6f76··n"..zypper·remov
 002918b0:·6520·2d79·2022·786f·7267·2d78·3131·2d73··e·-y·"xorg-x11-s
 002918c0:·6572·7665·722d·5877·6179·6c61·6e64·220a··erver-Xwayland".
 002918d0:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d
 002918e0:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn
 002918f0:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da
 00291900:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla
 00291910:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
 00291920:·3d22·2369·646d·3432·3536·3922·2074·6162··="#idm42569"·tab
 00291930:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
 00291940:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
 00291950:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
 00291960:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
 00291970:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
 00291980:·2122·3e52·656d·6564·6961·7469·6f6e·2041··!">Remediation·A
 00291990:·6e61·636f·6e64·6120·736e·6970·7065·7420··naconda·snippet·
 002919a0:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·
 002919b0:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col
 002919c0:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·
 002919d0:·6964·3d22·6964·6d34·3235·3639·223e·3c70··id="idm42569"><p
 002919e0:·7265·3e3c·636f·6465·3e0a·7061·636b·6167··re><code>.packag
 002919f0:·6520·2d2d·7265·6d6f·7665·3d78·6f72·672d··e·--remove=xorg-
002919e0:·7831·312d·7365·7276·6572·2d58·6f72·6722··x11-server-Xorg"00291a00:·7831·312d·7365·7276·6572·2d58·6f72·6720··x11-server-Xorg·
 00291a10:·2d2d·7265·6d6f·7665·3d78·6f72·672d·7831··--remove=xorg-x1
 00291a20:·312d·7365·7276·6572·2d63·6f6d·6d6f·6e20··1-server-common·
 00291a30:·2d2d·7265·6d6f·7665·3d78·6f72·672d·7831··--remove=xorg-x1
 00291a40:·312d·7365·7276·6572·2d75·7469·6c73·202d··1-server-utils·-
 00291a50:·2d72·656d·6f76·653d·786f·7267·2d78·3131··-remove=xorg-x11
 00291a60:·2d73·6572·7665·722d·5877·6179·6c61·6e64··-server-Xwayland
002919f0:·0a7a·7970·7065·7220·7265·6d6f·7665·202d··.zypper·remove·- 
00291a00:·7920·2278·6f72·672d·7831·312d·7365·7276··y·"xorg-x11-serv 
00291a10:·6572·2d75·7469·6c73·220a·7a79·7070·6572··er-utils".zypper 
00291a20:·2072·656d·6f76·6520·2d79·2022·786f·7267···remove·-y·"xorg 
00291a30:·2d78·3131·2d73·6572·7665·722d·636f·6d6d··-x11-server-comm 
00291a40:·6f6e·220a·0a7a·7970·7065·7220·7265·6d6f··on"..zypper·remo 
00291a50:·7665·202d·7920·2278·6f72·672d·7831·312d··ve·-y·"xorg-x11- 
00291a60:·7365·7276·6572·2d58·7761·796c·616e·6422··server-Xwayland" 
00291a70:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></00291a70:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></
00291a80:·6469·763e·3c2f·6469·763e·3c2f·7464·3e3c··div></div></td><00291a80:·6469·763e·3c2f·6469·763e·3c2f·7464·3e3c··div></div></td><
00291a90:·2f74·723e·3c2f·7462·6f64·793e·3c2f·7461··/tr></tbody></ta00291a90:·2f74·723e·3c2f·7462·6f64·793e·3c2f·7461··/tr></tbody></ta
00291aa0:·626c·653e·3c2f·7464·3e3c·2f74·723e·3c2f··ble></td></tr></00291aa0:·626c·653e·3c2f·7464·3e3c·2f74·723e·3c2f··ble></td></tr></
00291ab0:·7462·6f64·793e·3c2f·7461·626c·653e·3c2f··tbody></table></00291ab0:·7462·6f64·793e·3c2f·7461·626c·653e·3c2f··tbody></table></
00291ac0:·6469·763e·3c64·6976·2069·643d·2272·6561··div><div·id="rea00291ac0:·6469·763e·3c64·6976·2069·643d·2272·6561··div><div·id="rea
00291ad0:·722d·6d61·7474·6572·223e·3c64·6976·2063··r-matter"><div·c00291ad0:·722d·6d61·7474·6572·223e·3c64·6976·2063··r-matter"><div·c
1.47 KB
html2text {}
    
Offset 36700, 28 lines modifiedOffset 36700, 28 lines modified
36700 Severity: ···medium36700 Severity: ···medium
36701 Rule·ID:·····xccdf_org.ssgproject.content_rule_xwindows_remove_packages36701 Rule·ID:·····xccdf_org.ssgproject.content_rule_xwindows_remove_packages
36702 Identifiers:·CCE-91362-436702 Identifiers:·CCE-91362-4
36703 ·············_\x8d_\x8i_\x8s_\x8a···CCI-00036636703 ·············_\x8d_\x8i_\x8s_\x8a···CCI-000366
36704 References:··_\x8n_\x8i_\x8s_\x8t···CM-6(b)36704 References:··_\x8n_\x8i_\x8s_\x8t···CM-6(b)
36705 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000480-GPOS-0022736705 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000480-GPOS-00227
36706 ·············_\x8c_\x8i_\x8s····2.2.236706 ·············_\x8c_\x8i_\x8s····2.2.2
36707 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
36708 package·--remove=xorg-x11-server-Xorg·--remove=xorg-x11-server-common·--remove=xorg-x11-server-utils·-- 
36709 remove=xorg-x11-server-Xwayland 
36710 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x836707 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
36711 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low36708 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
36712 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low36709 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
36713 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true36710 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
36714 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict36711 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
  
  
36715 #·remove·packages36712 #·remove·packages
36716 zypper·remove·-y·"xorg-x11-server-Xorg"36713 zypper·remove·-y·"xorg-x11-server-Xorg"
36717 zypper·remove·-y·"xorg-x11-server-utils"36714 zypper·remove·-y·"xorg-x11-server-utils"
36718 zypper·remove·-y·"xorg-x11-server-common"36715 zypper·remove·-y·"xorg-x11-server-common"
  
36719 zypper·remove·-y·"xorg-x11-server-Xwayland"36716 zypper·remove·-y·"xorg-x11-server-Xwayland"
 36717 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 36718 package·--remove=xorg-x11-server-Xorg·--remove=xorg-x11-server-common·--remove=xorg-x11-server-utils·--
 36719 remove=xorg-x11-server-Xwayland
36720 Red·Hat·and·Red·Hat·Enterprise·Linux·are·either·registered·trademarks·or36720 Red·Hat·and·Red·Hat·Enterprise·Linux·are·either·registered·trademarks·or
36721 trademarks·of·Red·Hat,·Inc.·in·the·United·States·and·other·countries.·All·other36721 trademarks·of·Red·Hat,·Inc.·in·the·United·States·and·other·countries.·All·other
36722 names·are·registered·trademarks·or·trademarks·of·their·respective·companies.36722 names·are·registered·trademarks·or·trademarks·of·their·respective·companies.
36723 Generated·using·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8C_\x8A_\x8P·1.4.236723 Generated·using·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8C_\x8A_\x8P·1.4.2
10.7 KB
./usr/share/doc/ssg-nondebian/ssg-slmicro5-guide-cis.html
    
Offset 149248, 73 lines modifiedOffset 149248, 73 lines modified
00246ff0:·6574·3d22·2369·646d·3234·3539·3322·2074··et="#idm24593"·t00246ff0:·6574·3d22·2369·646d·3234·3539·3322·2074··et="#idm24593"·t
00247000:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role00247000:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
00247010:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e00247010:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
00247020:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·00247020:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
00247030:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·00247030:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
00247040:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=00247040:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
00247050:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation00247050:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
00247060:·2041·6e61·636f·6e64·6120·736e·6970·7065···Anaconda·snippe00247060:·2053·6865·6c6c·2073·6372·6970·7420·e287···Shell·script·..
00247070:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di00247070:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl
00247080:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c00247080:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla
00247090:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse00247090:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id
002470a0:·2220·6964·3d22·6964·6d32·3435·3933·223e··"·id="idm24593">002470a0:·3d22·6964·6d32·3435·3933·223e·3c74·6162··="idm24593"><tab
 002470b0:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·
 002470c0:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta
 002470d0:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab
 002470e0:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t
 002470f0:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity
 00247100:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
002470b0:·3c70·7265·3e3c·636f·6465·3e0a·7061·636b··<pre><code>.pack 
002470c0:·6167·6520·2d2d·7265·6d6f·7665·3d78·6f72··age·--remove=xor 
002470d0:·672d·7831·312d·7365·7276·6572·2d58·6f72··g-x11-server-Xor 
002470e0:·6720·2d2d·7265·6d6f·7665·3d78·6f72·672d··g·--remove=xorg- 
002470f0:·7831·312d·7365·7276·6572·2d63·6f6d·6d6f··x11-server-commo 
00247100:·6e20·2d2d·7265·6d6f·7665·3d78·6f72·672d··n·--remove=xorg- 
00247110:·7831·312d·7365·7276·6572·2d75·7469·6c73··x11-server-utils 
00247120:·202d·2d72·656d·6f76·653d·786f·7267·2d78···--remove=xorg-x 
00247130:·3131·2d73·6572·7665·722d·5877·6179·6c61··11-server-Xwayla 
00247140:·6e64·0a3c·2f63·6f64·653e·3c2f·7072·653e··nd.</code></pre> 
00247150:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class=" 
00247160:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success" 
00247170:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co 
00247180:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar 
00247190:·6765·743d·2223·6964·6d32·3435·3934·2220··get="#idm24594"· 
002471a0:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol 
002471b0:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria- 
002471c0:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false" 
002471d0:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate 
002471e0:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href 
002471f0:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio 
00247200:·6e20·5368·656c·6c20·7363·7269·7074·20e2··n·Shell·script·. 
00247210:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c 
00247220:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll 
00247230:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i 
00247240:·643d·2269·646d·3234·3539·3422·3e3c·7461··d="idm24594"><ta 
00247250:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table 
00247260:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t 
00247270:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta 
00247280:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed">< 
00247290:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit 
002472a0:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</ 
002472b0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
002472c0:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th> 
002472d0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
002472e0:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot: 
002472f0:·3c2f·7468·3e3c·7464·3e74·7275·653c·2f74··</th><td>true</t 
00247300:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S00247110:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D
00247310:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td 
00247320:·3e72·6573·7472·6963·743c·2f74·643e·3c2f··>restrict</td></ 
00247330:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre> 
00247340:·3c63·6f64·653e·0a0a·2320·7265·6d6f·7665··<code>..#·remove 
00247350:·2070·6163·6b61·6765·730a·7a79·7070·6572···packages.zypper00247120:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><
 00247130:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
 00247140:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:<
 00247150:·2f74·683e·3c74·643e·7472·7565·3c2f·7464··/th><td>true</td
 00247160:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St
 00247170:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>
 00247180:·7265·7374·7269·6374·3c2f·7464·3e3c·2f74··restrict</td></t
 00247190:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><
 002471a0:·636f·6465·3e0a·0a23·2072·656d·6f76·6520··code>..#·remove·
 002471b0:·7061·636b·6167·6573·0a7a·7970·7065·7220··packages.zypper·
 002471c0:·7265·6d6f·7665·202d·7920·2278·6f72·672d··remove·-y·"xorg-
 002471d0:·7831·312d·7365·7276·6572·2d58·6f72·6722··x11-server-Xorg"
 002471e0:·0a7a·7970·7065·7220·7265·6d6f·7665·202d··.zypper·remove·-
 002471f0:·7920·2278·6f72·672d·7831·312d·7365·7276··y·"xorg-x11-serv
 00247200:·6572·2d75·7469·6c73·220a·7a79·7070·6572··er-utils".zypper
00247360:·2072·656d·6f76·6520·2d79·2022·786f·7267···remove·-y·"xorg00247210:·2072·656d·6f76·6520·2d79·2022·786f·7267···remove·-y·"xorg
 00247220:·2d78·3131·2d73·6572·7665·722d·636f·6d6d··-x11-server-comm
 00247230:·6f6e·220a·0a7a·7970·7065·7220·7265·6d6f··on"..zypper·remo
 00247240:·7665·202d·7920·2278·6f72·672d·7831·312d··ve·-y·"xorg-x11-
 00247250:·7365·7276·6572·2d58·7761·796c·616e·6422··server-Xwayland"
 00247260:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></
 00247270:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt
 00247280:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d
 00247290:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll
 002472a0:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
 002472b0:·743d·2223·6964·6d32·3435·3934·2220·7461··t="#idm24594"·ta
 002472c0:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
 002472d0:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
 002472e0:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
 002472f0:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
 00247300:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
 00247310:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
 00247320:·416e·6163·6f6e·6461·2073·6e69·7070·6574··Anaconda·snippet
 00247330:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
 00247340:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
 00247350:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
 00247360:·2069·643d·2269·646d·3234·3539·3422·3e3c···id="idm24594"><
 00247370:·7072·653e·3c63·6f64·653e·0a70·6163·6b61··pre><code>.packa
 00247380:·6765·202d·2d72·656d·6f76·653d·786f·7267··ge·--remove=xorg
00247370:·2d78·3131·2d73·6572·7665·722d·586f·7267··-x11-server-Xorg00247390:·2d78·3131·2d73·6572·7665·722d·586f·7267··-x11-server-Xorg
 002473a0:·202d·2d72·656d·6f76·653d·786f·7267·2d78···--remove=xorg-x
 002473b0:·3131·2d73·6572·7665·722d·636f·6d6d·6f6e··11-server-common
 002473c0:·202d·2d72·656d·6f76·653d·786f·7267·2d78···--remove=xorg-x
 002473d0:·3131·2d73·6572·7665·722d·7574·696c·7320··11-server-utils·
 002473e0:·2d2d·7265·6d6f·7665·3d78·6f72·672d·7831··--remove=xorg-x1
 002473f0:·312d·7365·7276·6572·2d58·7761·796c·616e··1-server-Xwaylan
00247380:·220a·7a79·7070·6572·2072·656d·6f76·6520··".zypper·remove· 
00247390:·2d79·2022·786f·7267·2d78·3131·2d73·6572··-y·"xorg-x11-ser 
002473a0:·7665·722d·7574·696c·7322·0a7a·7970·7065··ver-utils".zyppe 
002473b0:·7220·7265·6d6f·7665·202d·7920·2278·6f72··r·remove·-y·"xor 
002473c0:·672d·7831·312d·7365·7276·6572·2d63·6f6d··g-x11-server-com 
002473d0:·6d6f·6e22·0a0a·7a79·7070·6572·2072·656d··mon"..zypper·rem 
002473e0:·6f76·6520·2d79·2022·786f·7267·2d78·3131··ove·-y·"xorg-x11 
002473f0:·2d73·6572·7665·722d·5877·6179·6c61·6e64··-server-Xwayland 
00247400:·220a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··".</code></pre><00247400:·640a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··d.</code></pre><
00247410:·2f64·6976·3e3c·2f64·6976·3e3c·2f74·643e··/div></div></td>00247410:·2f64·6976·3e3c·2f64·6976·3e3c·2f74·643e··/div></div></td>
00247420:·3c2f·7472·3e3c·2f74·626f·6479·3e3c·2f74··</tr></tbody></t00247420:·3c2f·7472·3e3c·2f74·626f·6479·3e3c·2f74··</tr></tbody></t
00247430:·6162·6c65·3e3c·2f74·643e·3c2f·7472·3e3c··able></td></tr><00247430:·6162·6c65·3e3c·2f74·643e·3c2f·7472·3e3c··able></td></tr><
00247440:·7472·2064·6174·612d·7474·2d69·643d·2263··tr·data-tt-id="c00247440:·7472·2064·6174·612d·7474·2d69·643d·2263··tr·data-tt-id="c
00247450:·6869·6c64·7265·6e2d·7863·6364·665f·6f72··hildren-xccdf_or00247450:·6869·6c64·7265·6e2d·7863·6364·665f·6f72··hildren-xccdf_or
00247460:·672e·7373·6770·726f·6a65·6374·2e63·6f6e··g.ssgproject.con00247460:·672e·7373·6770·726f·6a65·6374·2e63·6f6e··g.ssgproject.con
00247470:·7465·6e74·5f67·726f·7570·5f61·7564·6974··tent_group_audit00247470:·7465·6e74·5f67·726f·7570·5f61·7564·6974··tent_group_audit
1.71 KB
html2text {}
    
Offset 31511, 31 lines modifiedOffset 31511, 31 lines modified
31511 Severity: ···medium31511 Severity: ···medium
31512 Rule·ID:·····xccdf_org.ssgproject.content_rule_xwindows_remove_packages31512 Rule·ID:·····xccdf_org.ssgproject.content_rule_xwindows_remove_packages
31513 Identifiers:·CCE-93873-831513 Identifiers:·CCE-93873-8
31514 ·············_\x8d_\x8i_\x8s_\x8a···CCI-00036631514 ·············_\x8d_\x8i_\x8s_\x8a···CCI-000366
31515 References:··_\x8n_\x8i_\x8s_\x8t···CM-6(b)31515 References:··_\x8n_\x8i_\x8s_\x8t···CM-6(b)
31516 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000480-GPOS-0022731516 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000480-GPOS-00227
31517 ·············_\x8c_\x8i_\x8s····2.2.231517 ·············_\x8c_\x8i_\x8s····2.2.2
31518 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
31519 package·--remove=xorg-x11-server-Xorg·--remove=xorg-x11-server-common·--remove=xorg-x11-server-utils·-- 
31520 remove=xorg-x11-server-Xwayland 
31521 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x831518 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
31522 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low31519 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
31523 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low31520 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
31524 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true31521 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
31525 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict31522 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
  
  
31526 #·remove·packages31523 #·remove·packages
31527 zypper·remove·-y·"xorg-x11-server-Xorg"31524 zypper·remove·-y·"xorg-x11-server-Xorg"
31528 zypper·remove·-y·"xorg-x11-server-utils"31525 zypper·remove·-y·"xorg-x11-server-utils"
31529 zypper·remove·-y·"xorg-x11-server-common"31526 zypper·remove·-y·"xorg-x11-server-common"
  
31530 zypper·remove·-y·"xorg-x11-server-Xwayland"31527 zypper·remove·-y·"xorg-x11-server-Xwayland"
 31528 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 31529 package·--remove=xorg-x11-server-Xorg·--remove=xorg-x11-server-common·--remove=xorg-x11-server-utils·--
 31530 remove=xorg-x11-server-Xwayland
31531 Group  ·System·Accounting·with·auditd·  Group·contains·9·groups·and·59·rules31531 Group  ·System·Accounting·with·auditd·  Group·contains·9·groups·and·59·rules
31532 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·audit·service·provides·substantial·capabilities·for·recording·system·activities.·By·default,31532 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·audit·service·provides·substantial·capabilities·for·recording·system·activities.·By·default,
31533 the·service·audits·about·SELinux·AVC·denials·and·certain·types·of·security-relevant·events·such·as·system31533 the·service·audits·about·SELinux·AVC·denials·and·certain·types·of·security-relevant·events·such·as·system
31534 logins,·account·modifications,·and·authentication·events·performed·by·programs·such·as·sudo.·Under·its31534 logins,·account·modifications,·and·authentication·events·performed·by·programs·such·as·sudo.·Under·its
31535 default·configuration,·auditd·has·modest·disk·space·requirements,·and·should·not·noticeably·impact·system31535 default·configuration,·auditd·has·modest·disk·space·requirements,·and·should·not·noticeably·impact·system
31536 performance.31536 performance.
  
10.8 KB
./usr/share/doc/ssg-nondebian/ssg-slmicro5-guide-cis_server_l1.html
    
Offset 143967, 73 lines modifiedOffset 143967, 73 lines modified
002325e0:·6574·3d22·2369·646d·3234·3539·3322·2074··et="#idm24593"·t002325e0:·6574·3d22·2369·646d·3234·3539·3322·2074··et="#idm24593"·t
002325f0:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role002325f0:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
00232600:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e00232600:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
00232610:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·00232610:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
00232620:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·00232620:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
00232630:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=00232630:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
00232640:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation00232640:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
00232650:·2041·6e61·636f·6e64·6120·736e·6970·7065···Anaconda·snippe00232650:·2053·6865·6c6c·2073·6372·6970·7420·e287···Shell·script·..
00232660:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di00232660:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl
00232670:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c00232670:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla
00232680:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse00232680:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id
00232690:·2220·6964·3d22·6964·6d32·3435·3933·223e··"·id="idm24593">00232690:·3d22·6964·6d32·3435·3933·223e·3c74·6162··="idm24593"><tab
 002326a0:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·
 002326b0:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta
 002326c0:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab
 002326d0:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t
 002326e0:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity
 002326f0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
002326a0:·3c70·7265·3e3c·636f·6465·3e0a·7061·636b··<pre><code>.pack 
002326b0:·6167·6520·2d2d·7265·6d6f·7665·3d78·6f72··age·--remove=xor 
002326c0:·672d·7831·312d·7365·7276·6572·2d58·6f72··g-x11-server-Xor 
002326d0:·6720·2d2d·7265·6d6f·7665·3d78·6f72·672d··g·--remove=xorg- 
002326e0:·7831·312d·7365·7276·6572·2d63·6f6d·6d6f··x11-server-commo 
002326f0:·6e20·2d2d·7265·6d6f·7665·3d78·6f72·672d··n·--remove=xorg- 
00232700:·7831·312d·7365·7276·6572·2d75·7469·6c73··x11-server-utils 
00232710:·202d·2d72·656d·6f76·653d·786f·7267·2d78···--remove=xorg-x 
00232720:·3131·2d73·6572·7665·722d·5877·6179·6c61··11-server-Xwayla 
00232730:·6e64·0a3c·2f63·6f64·653e·3c2f·7072·653e··nd.</code></pre> 
00232740:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class=" 
00232750:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success" 
00232760:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co 
00232770:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar 
00232780:·6765·743d·2223·6964·6d32·3435·3934·2220··get="#idm24594"· 
00232790:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol 
002327a0:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria- 
002327b0:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false" 
002327c0:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate 
002327d0:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href 
002327e0:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio 
002327f0:·6e20·5368·656c·6c20·7363·7269·7074·20e2··n·Shell·script·. 
00232800:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c 
00232810:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll 
00232820:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i 
00232830:·643d·2269·646d·3234·3539·3422·3e3c·7461··d="idm24594"><ta 
00232840:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table 
00232850:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t 
00232860:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta 
00232870:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed">< 
00232880:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit 
00232890:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</ 
002328a0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
002328b0:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th> 
002328c0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
002328d0:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot: 
002328e0:·3c2f·7468·3e3c·7464·3e74·7275·653c·2f74··</th><td>true</t 
002328f0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S00232700:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D
00232900:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td 
00232910:·3e72·6573·7472·6963·743c·2f74·643e·3c2f··>restrict</td></ 
00232920:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre> 
00232930:·3c63·6f64·653e·0a0a·2320·7265·6d6f·7665··<code>..#·remove 
00232940:·2070·6163·6b61·6765·730a·7a79·7070·6572···packages.zypper00232710:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><
 00232720:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
 00232730:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:<
 00232740:·2f74·683e·3c74·643e·7472·7565·3c2f·7464··/th><td>true</td
 00232750:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St
 00232760:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>
 00232770:·7265·7374·7269·6374·3c2f·7464·3e3c·2f74··restrict</td></t
 00232780:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><
 00232790:·636f·6465·3e0a·0a23·2072·656d·6f76·6520··code>..#·remove·
 002327a0:·7061·636b·6167·6573·0a7a·7970·7065·7220··packages.zypper·
 002327b0:·7265·6d6f·7665·202d·7920·2278·6f72·672d··remove·-y·"xorg-
 002327c0:·7831·312d·7365·7276·6572·2d58·6f72·6722··x11-server-Xorg"
 002327d0:·0a7a·7970·7065·7220·7265·6d6f·7665·202d··.zypper·remove·-
 002327e0:·7920·2278·6f72·672d·7831·312d·7365·7276··y·"xorg-x11-serv
 002327f0:·6572·2d75·7469·6c73·220a·7a79·7070·6572··er-utils".zypper
00232950:·2072·656d·6f76·6520·2d79·2022·786f·7267···remove·-y·"xorg00232800:·2072·656d·6f76·6520·2d79·2022·786f·7267···remove·-y·"xorg
 00232810:·2d78·3131·2d73·6572·7665·722d·636f·6d6d··-x11-server-comm
 00232820:·6f6e·220a·0a7a·7970·7065·7220·7265·6d6f··on"..zypper·remo
 00232830:·7665·202d·7920·2278·6f72·672d·7831·312d··ve·-y·"xorg-x11-
 00232840:·7365·7276·6572·2d58·7761·796c·616e·6422··server-Xwayland"
 00232850:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></
 00232860:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt
 00232870:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d
 00232880:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll
 00232890:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
 002328a0:·743d·2223·6964·6d32·3435·3934·2220·7461··t="#idm24594"·ta
 002328b0:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
 002328c0:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
 002328d0:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
 002328e0:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
 002328f0:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
 00232900:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
 00232910:·416e·6163·6f6e·6461·2073·6e69·7070·6574··Anaconda·snippet
 00232920:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
 00232930:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
 00232940:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
 00232950:·2069·643d·2269·646d·3234·3539·3422·3e3c···id="idm24594"><
 00232960:·7072·653e·3c63·6f64·653e·0a70·6163·6b61··pre><code>.packa
 00232970:·6765·202d·2d72·656d·6f76·653d·786f·7267··ge·--remove=xorg
00232960:·2d78·3131·2d73·6572·7665·722d·586f·7267··-x11-server-Xorg00232980:·2d78·3131·2d73·6572·7665·722d·586f·7267··-x11-server-Xorg
 00232990:·202d·2d72·656d·6f76·653d·786f·7267·2d78···--remove=xorg-x
 002329a0:·3131·2d73·6572·7665·722d·636f·6d6d·6f6e··11-server-common
 002329b0:·202d·2d72·656d·6f76·653d·786f·7267·2d78···--remove=xorg-x
 002329c0:·3131·2d73·6572·7665·722d·7574·696c·7320··11-server-utils·
 002329d0:·2d2d·7265·6d6f·7665·3d78·6f72·672d·7831··--remove=xorg-x1
 002329e0:·312d·7365·7276·6572·2d58·7761·796c·616e··1-server-Xwaylan
00232970:·220a·7a79·7070·6572·2072·656d·6f76·6520··".zypper·remove· 
00232980:·2d79·2022·786f·7267·2d78·3131·2d73·6572··-y·"xorg-x11-ser 
00232990:·7665·722d·7574·696c·7322·0a7a·7970·7065··ver-utils".zyppe 
002329a0:·7220·7265·6d6f·7665·202d·7920·2278·6f72··r·remove·-y·"xor 
002329b0:·672d·7831·312d·7365·7276·6572·2d63·6f6d··g-x11-server-com 
002329c0:·6d6f·6e22·0a0a·7a79·7070·6572·2072·656d··mon"..zypper·rem 
002329d0:·6f76·6520·2d79·2022·786f·7267·2d78·3131··ove·-y·"xorg-x11 
002329e0:·2d73·6572·7665·722d·5877·6179·6c61·6e64··-server-Xwayland 
002329f0:·220a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··".</code></pre><002329f0:·640a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··d.</code></pre><
00232a00:·2f64·6976·3e3c·2f64·6976·3e3c·2f74·643e··/div></div></td>00232a00:·2f64·6976·3e3c·2f64·6976·3e3c·2f74·643e··/div></div></td>
00232a10:·3c2f·7472·3e3c·2f74·626f·6479·3e3c·2f74··</tr></tbody></t00232a10:·3c2f·7472·3e3c·2f74·626f·6479·3e3c·2f74··</tr></tbody></t
00232a20:·6162·6c65·3e3c·2f74·643e·3c2f·7472·3e3c··able></td></tr><00232a20:·6162·6c65·3e3c·2f74·643e·3c2f·7472·3e3c··able></td></tr><
00232a30:·7472·2064·6174·612d·7474·2d69·643d·2263··tr·data-tt-id="c00232a30:·7472·2064·6174·612d·7474·2d69·643d·2263··tr·data-tt-id="c
00232a40:·6869·6c64·7265·6e2d·7863·6364·665f·6f72··hildren-xccdf_or00232a40:·6869·6c64·7265·6e2d·7863·6364·665f·6f72··hildren-xccdf_or
00232a50:·672e·7373·6770·726f·6a65·6374·2e63·6f6e··g.ssgproject.con00232a50:·672e·7373·6770·726f·6a65·6374·2e63·6f6e··g.ssgproject.con
00232a60:·7465·6e74·5f67·726f·7570·5f61·7564·6974··tent_group_audit00232a60:·7465·6e74·5f67·726f·7570·5f61·7564·6974··tent_group_audit
1.71 KB
html2text {}
    
Offset 30274, 31 lines modifiedOffset 30274, 31 lines modified
30274 Severity: ···medium30274 Severity: ···medium
30275 Rule·ID:·····xccdf_org.ssgproject.content_rule_xwindows_remove_packages30275 Rule·ID:·····xccdf_org.ssgproject.content_rule_xwindows_remove_packages
30276 Identifiers:·CCE-93873-830276 Identifiers:·CCE-93873-8
30277 ·············_\x8d_\x8i_\x8s_\x8a···CCI-00036630277 ·············_\x8d_\x8i_\x8s_\x8a···CCI-000366
30278 References:··_\x8n_\x8i_\x8s_\x8t···CM-6(b)30278 References:··_\x8n_\x8i_\x8s_\x8t···CM-6(b)
30279 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000480-GPOS-0022730279 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000480-GPOS-00227
30280 ·············_\x8c_\x8i_\x8s····2.2.230280 ·············_\x8c_\x8i_\x8s····2.2.2
30281 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
30282 package·--remove=xorg-x11-server-Xorg·--remove=xorg-x11-server-common·--remove=xorg-x11-server-utils·-- 
30283 remove=xorg-x11-server-Xwayland 
30284 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x830281 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
30285 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low30282 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
30286 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low30283 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
30287 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true30284 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
30288 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict30285 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
  
  
30289 #·remove·packages30286 #·remove·packages
30290 zypper·remove·-y·"xorg-x11-server-Xorg"30287 zypper·remove·-y·"xorg-x11-server-Xorg"
30291 zypper·remove·-y·"xorg-x11-server-utils"30288 zypper·remove·-y·"xorg-x11-server-utils"
30292 zypper·remove·-y·"xorg-x11-server-common"30289 zypper·remove·-y·"xorg-x11-server-common"
  
30293 zypper·remove·-y·"xorg-x11-server-Xwayland"30290 zypper·remove·-y·"xorg-x11-server-Xwayland"
 30291 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 30292 package·--remove=xorg-x11-server-Xorg·--remove=xorg-x11-server-common·--remove=xorg-x11-server-utils·--
 30293 remove=xorg-x11-server-Xwayland
30294 Group  ·System·Accounting·with·auditd·  Group·contains·1·group·and·2·rules30294 Group  ·System·Accounting·with·auditd·  Group·contains·1·group·and·2·rules
30295 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·audit·service·provides·substantial·capabilities·for·recording·system·activities.·By·default,30295 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·audit·service·provides·substantial·capabilities·for·recording·system·activities.·By·default,
30296 the·service·audits·about·SELinux·AVC·denials·and·certain·types·of·security-relevant·events·such·as·system30296 the·service·audits·about·SELinux·AVC·denials·and·certain·types·of·security-relevant·events·such·as·system
30297 logins,·account·modifications,·and·authentication·events·performed·by·programs·such·as·sudo.·Under·its30297 logins,·account·modifications,·and·authentication·events·performed·by·programs·such·as·sudo.·Under·its
30298 default·configuration,·auditd·has·modest·disk·space·requirements,·and·should·not·noticeably·impact·system30298 default·configuration,·auditd·has·modest·disk·space·requirements,·and·should·not·noticeably·impact·system
30299 performance.30299 performance.
  
3.58 MB
./usr/share/doc/ssg-nondebian/table-ol7-anssirefs.html
    
Offset 63, 274 lines modifiedOffset 63, 274 lines modified
000003e0:·2054·6974·6c65·3c2f·7468·3e0a·2020·2020···Title</th>.····000003e0:·2054·6974·6c65·3c2f·7468·3e0a·2020·2020···Title</th>.····
000003f0:·3c74·683e·4465·7363·7269·7074·696f·6e3c··<th>Description<000003f0:·3c74·683e·4465·7363·7269·7074·696f·6e3c··<th>Description<
00000400:·2f74·683e·0a20·2020·203c·7468·3e52·6174··/th>.····<th>Rat00000400:·2f74·683e·0a20·2020·203c·7468·3e52·6174··/th>.····<th>Rat
00000410:·696f·6e61·6c65·3c2f·7468·3e0a·2020·3c2f··ionale</th>.··</00000410:·696f·6e61·6c65·3c2f·7468·3e0a·2020·3c2f··ionale</th>.··</
00000420:·7468·6561·643e·0a20·203c·7462·6f64·793e··thead>.··<tbody>00000420:·7468·6561·643e·0a20·203c·7462·6f64·793e··thead>.··<tbody>
00000430:·0a20·203c·7472·3e0a·2020·2020·2020·3c74··.··<tr>.······<t00000430:·0a20·203c·7472·3e0a·2020·2020·2020·3c74··.··<tr>.······<t
00000440:·643e·5231·3c2f·7464·3e0a·2020·2020·2020··d>R1</td>.······00000440:·643e·5231·3c2f·7464·3e0a·2020·2020·2020··d>R1</td>.······
00000450:·3c74·643e·496e·7374·616c·6c20·7468·6520··<td>Install·the· 
00000460:·6472·6163·7574·2d66·6970·732d·6165·736e··dracut-fips-aesn 
00000470:·6920·5061·636b·6167·653c·2f74·643e·0a20··i·Package</td>.· 
00000480:·2020·2020·203c·7464·2078·6d6c·3a6c·616e·······<td·xml:lan00000450:·3c74·643e·5072·6566·6572·2074·6f20·7573··<td>Prefer·to·us
 00000460:·6520·6120·3634·2d62·6974·204f·7065·7261··e·a·64-bit·Opera
 00000470:·7469·6e67·2053·7973·7465·6d20·7768·656e··ting·System·when
 00000480:·2073·7570·706f·7274·6564·3c2f·7464·3e0a···supported</td>.
 00000490:·2020·2020·2020·3c74·6420·786d·6c3a·6c61········<td·xml:la
00000490:·673d·2265·6e2d·5553·223e·0a20·2020·2020··g="en-US">.·····000004a0:·6e67·3d22·656e·2d55·5322·3e0a·2020·2020··ng="en-US">.····
 000004b0:·2020·2020·5072·6566·6572·2069·6e73·7461······Prefer·insta
 000004c0:·6c6c·6174·696f·6e20·6f66·2036·342d·6269··llation·of·64-bi
 000004d0:·7420·6f70·6572·6174·696e·6720·7379·7374··t·operating·syst
 000004e0:·656d·7320·7768·656e·2074·6865·2043·5055··ems·when·the·CPU
 000004f0:·2073·7570·706f·7274·7320·6974·2e0a·2020···supports·it..··
000004a0:·2020·2054·6f20·656e·6162·6c65·2046·4950·····To·enable·FIP 
000004b0:·5320·6f6e·2073·7973·7465·6d20·7468·6174··S·on·system·that 
000004c0:·2073·7570·706f·7274·2074·6865·2041·6476···support·the·Adv 
000004d0:·616e·6365·6420·456e·6372·7970·7469·6f6e··anced·Encryption 
000004e0:·2053·7461·6e64·6172·6420·2841·4553·2920···Standard·(AES)· 
000004f0:·6f72·204e·6577·0a49·6e73·7472·7563·7469··or·New.Instructi 
00000500:·6f6e·7320·2841·4553·2d4e·4929·2065·6e67··ons·(AES-NI)·eng 
00000510:·696e·652c·2074·6865·2073·7973·7465·6d20··ine,·the·system· 
00000520:·7265·7175·6972·6573·2074·6861·7420·7468··requires·that·th 
00000530:·6520·3c74·743e·6472·6163·7574·2d66·6970··e·<tt>dracut-fip 
00000540:·732d·6165·736e·693c·2f74·743e·0a70·6163··s-aesni</tt>.pac 
00000550:·6b61·6765·2062·6520·696e·7374·616c·6c65··kage·be·installe 
00000560:·642e·0a54·6865·203c·636f·6465·3e64·7261··d..The·<code>dra 
00000570:·6375·742d·6669·7073·2d61·6573·6e69·3c2f··cut-fips-aesni</ 
00000580:·636f·6465·3e20·7061·636b·6167·6520·6361··code>·package·ca 
00000590:·6e20·6265·2069·6e73·7461·6c6c·6564·2077··n·be·installed·w 
000005a0:·6974·6820·7468·6520·666f·6c6c·6f77·696e··ith·the·followin 
000005b0:·6720·636f·6d6d·616e·643a·0a3c·7072·653e··g·command:.<pre> 
000005c0:·0a24·2073·7564·6f20·7975·6d20·696e·7374··.$·sudo·yum·inst 
000005d0:·616c·6c20·6472·6163·7574·2d66·6970·732d··all·dracut-fips- 
000005e0:·6165·736e·693c·2f70·7265·3e0a·2020·2020··aesni</pre>.···· 
000005f0:·2020·3c2f·7464·3e0a·2020·2020·2020·3c74····</td>.······<t00000500:·2020·2020·3c2f·7464·3e0a·2020·2020·2020······</td>.······
00000600:·6420·786d·6c3a·6c61·6e67·3d22·656e·2d55··d·xml:lang="en-U00000510:·3c74·6420·786d·6c3a·6c61·6e67·3d22·656e··<td·xml:lang="en
00000610:·5322·3e0a·2020·2020·2020·2020·5573·6520··S">.········Use·00000520:·2d55·5322·3e0a·2020·2020·2020·2020·5573··-US">.········Us
00000620:·6f66·2077·6561·6b20·6f72·2075·6e74·6573··of·weak·or·untes 
00000630:·7465·6420·656e·6372·7970·7469·6f6e·2061··ted·encryption·a 
00000640:·6c67·6f72·6974·686d·7320·756e·6465·726d··lgorithms·underm 
00000650:·696e·6573·2074·6865·2070·7572·706f·7365··ines·the·purpose 
00000660:·7320·6f66·2075·7469·6c69·7a69·6e67·2065··s·of·utilizing·e 
00000670:·6e63·7279·7074·696f·6e20·746f·0a70·726f··ncryption·to.pro 
00000680:·7465·6374·2064·6174·612e·2054·6865·206f··tect·data.·The·o 
00000690:·7065·7261·7469·6e67·2073·7973·7465·6d20··perating·system· 
000006a0:·6d75·7374·2069·6d70·6c65·6d65·6e74·2063··must·implement·c 
000006b0:·7279·7074·6f67·7261·7068·6963·206d·6f64··ryptographic·mod 
000006c0:·756c·6573·2061·6468·6572·696e·6720·746f··ules·adhering·to 
000006d0:·2074·6865·2068·6967·6865·720a·7374·616e···the·higher.stan 
000006e0:·6461·7264·7320·6170·7072·6f76·6564·2062··dards·approved·b 
000006f0:·7920·7468·6520·6665·6465·7261·6c20·676f··y·the·federal·go 
00000700:·7665·726e·6d65·6e74·2073·696e·6365·2074··vernment·since·t 
00000710:·6869·7320·7072·6f76·6964·6573·2061·7373··his·provides·ass 
00000720:·7572·616e·6365·2074·6865·7920·6861·7665··urance·they·have 
00000730:·2062·6565·6e20·7465·7374·6564·0a61·6e64···been·tested.and 
00000740:·2076·616c·6964·6174·6564·2e0a·2020·2020···validated..···· 
00000750:·2020·3c2f·7464·3e0a·2020·2020·3c2f·7472····</td>.····</tr00000530:·6520·6f66·2061·2036·342d·6269·7420·6f70··e·of·a·64-bit·op
 00000540:·6572·6174·696e·6720·7379·7374·656d·206f··erating·system·o
 00000550:·6666·6572·7320·6120·6665·7720·6164·7661··ffers·a·few·adva
 00000560:·6e74·6167·6573·2c20·6c69·6b65·2061·206c··ntages,·like·a·l
 00000570:·6172·6765·7220·6164·6472·6573·7320·7370··arger·address·sp
 00000580:·6163·6520·7261·6e67·6520·666f·720a·4164··ace·range·for.Ad
 00000590:·6472·6573·7320·5370·6163·6520·4c61·796f··dress·Space·Layo
 000005a0:·7574·2052·616e·646f·6d69·7a61·7469·6f6e··ut·Randomization
 000005b0:·2028·4153·4c52·2920·616e·6420·7379·7374···(ASLR)·and·syst
 000005c0:·656d·6174·6963·2070·7265·7365·6e63·6520··ematic·presence·
 000005d0:·6f66·204e·6f20·6558·6563·7574·6520·616e··of·No·eXecute·an
 000005e0:·6420·4578·6563·7574·6520·4469·7361·626c··d·Execute·Disabl
 000005f0:·6520·284e·582f·5844·2920·7072·6f74·6563··e·(NX/XD)·protec
 00000600:·7469·6f6e·2062·6974·732e·0a20·2020·2020··tion·bits..·····
 00000610:·203c·2f74·643e·0a20·2020·203c·2f74·723e···</td>.····</tr>
 00000620:·0a20·2020·203c·7472·3e0a·2020·2020·2020··.····<tr>.······
 00000630:·3c74·643e·5231·3c2f·7464·3e0a·2020·2020··<td>R1</td>.····
 00000640:·2020·3c74·643e·496e·7374·616c·6c20·5041····<td>Install·PA
 00000650:·4520·4b65·726e·656c·206f·6e20·5375·7070··E·Kernel·on·Supp
 00000660:·6f72·7465·6420·3332·2d62·6974·2078·3836··orted·32-bit·x86
 00000670:·2053·7973·7465·6d73·3c2f·7464·3e0a·2020···Systems</td>.··
 00000680:·2020·2020·3c74·6420·786d·6c3a·6c61·6e67······<td·xml:lang
 00000690:·3d22·656e·2d55·5322·3e0a·2020·2020·2020··="en-US">.······
 000006a0:·2020·5379·7374·656d·7320·7468·6174·2061····Systems·that·a
 000006b0:·7265·2075·7369·6e67·2074·6865·2036·342d··re·using·the·64-
 000006c0:·6269·7420·7838·3620·6b65·726e·656c·2070··bit·x86·kernel·p
 000006d0:·6163·6b61·6765·0a64·6f20·6e6f·7420·6e65··ackage.do·not·ne
 000006e0:·6564·2074·6f20·696e·7374·616c·6c20·7468··ed·to·install·th
 000006f0:·6520·6b65·726e·656c·2d50·4145·2070·6163··e·kernel-PAE·pac
 00000700:·6b61·6765·2062·6563·6175·7365·2074·6865··kage·because·the
 00000710:·2036·342d·6269·740a·7838·3620·6b65·726e···64-bit.x86·kern
 00000720:·656c·2061·6c72·6561·6479·2069·6e63·6c75··el·already·inclu
 00000730:·6465·7320·7468·6973·2073·7570·706f·7274··des·this·support
 00000740:·2e20·486f·7765·7665·722c·2069·6620·7468··.·However,·if·th
 00000750:·6520·7379·7374·656d·2069·730a·3332·2d62··e·system·is.32-b
 00000760:·6974·2061·6e64·2061·6c73·6f20·7375·7070··it·and·also·supp
 00000770:·6f72·7473·2074·6865·2050·4145·2061·6e64··orts·the·PAE·and
 00000780:·204e·5820·6665·6174·7572·6573·2061·730a···NX·features·as.
 00000790:·6465·7465·726d·696e·6564·2069·6e20·7468··determined·in·th
 000007a0:·6520·7072·6576·696f·7573·2073·6563·7469··e·previous·secti
 000007b0:·6f6e·2c20·7468·6520·6b65·726e·656c·2d50··on,·the·kernel-P
 000007c0:·4145·2070·6163·6b61·6765·2073·686f·756c··AE·package·shoul
 000007d0:·640a·6265·2069·6e73·7461·6c6c·6564·2074··d.be·installed·t
 000007e0:·6f20·656e·6162·6c65·2058·4420·6f72·204e··o·enable·XD·or·N
 000007f0:·5820·7375·7070·6f72·742e·0a54·6865·203c··X·support..The·<
 00000800:·636f·6465·3e6b·6572·6e65·6c2d·5041·453c··code>kernel-PAE<
 00000810:·2f63·6f64·653e·2070·6163·6b61·6765·2063··/code>·package·c
 00000820:·616e·2062·6520·696e·7374·616c·6c65·6420··an·be·installed·
 00000830:·7769·7468·2074·6865·2066·6f6c·6c6f·7769··with·the·followi
 00000840:·6e67·2063·6f6d·6d61·6e64·3a0a·3c70·7265··ng·command:.<pre
 00000850:·3e0a·2420·7375·646f·2079·756d·2069·6e73··>.$·sudo·yum·ins
 00000860:·7461·6c6c·206b·6572·6e65·6c2d·5041·453c··tall·kernel-PAE<
 00000870:·2f70·7265·3e0a·5468·6520·696e·7374·616c··/pre>.The·instal
 00000880:·6c61·7469·6f6e·2070·726f·6365·7373·2073··lation·process·s
 00000890:·686f·756c·6420·616c·736f·2068·6176·6520··hould·also·have·
 000008a0:·636f·6e66·6967·7572·6564·2074·6865·0a62··configured·the.b
 000008b0:·6f6f·746c·6f61·6465·7220·746f·206c·6f61··ootloader·to·loa
 000008c0:·6420·7468·6520·6e65·7720·6b65·726e·656c··d·the·new·kernel
 000008d0:·2061·7420·626f·6f74·2e20·5665·7269·6679···at·boot.·Verify
 000008e0:·2074·6869·7320·6166·7465·7220·7265·626f···this·after·rebo
 000008f0:·6f74·0a61·6e64·206d·6f64·6966·7920·3c74··ot.and·modify·<t
 00000900:·743e·2f65·7463·2f64·6566·6175·6c74·2f67··t>/etc/default/g
 00000910:·7275·623c·2f74·743e·2069·6620·6e65·6365··rub</tt>·if·nece
Max diff block lines reached; 3030619/3067073 bytes (98.81%) of diff not shown.
674 KB
html2text {}
    
Offset 1, 38 lines modifiedOffset 1, 13 lines modified
  
  
1 Rules·with·ANSSI·Reference·in·Guide·to·the·Secure·Configuration·of·Oracle·Linux1 Rules·with·ANSSI·Reference·in·Guide·to·the·Secure·Configuration·of·Oracle·Linux
2 72 7
  
  
3 ···········································································Use·of·weak·or·untested·encryption 
4 ······························To·enable·FIPS·on·system·that·support·the····algorithms·undermines·the·purposes·of 
5 ······························Advanced·Encryption·Standard·(AES)·or·New····utilizing·encryption·to·protect·data. 
6 ····Install·the·dracut-fips-··Instructions·(AES-NI)·engine,·the·system·····The·operating·system·must·implement 
7 R1··aesni·Package·············requires·that·the·dracut-fips-aesni·package··cryptographic·modules·adhering·to·the 
8 ······························be·installed.·The·dracut-fips-aesni·package··higher·standards·approved·by·the 
9 ······························can·be·installed·with·the·following·command:·federal·government·since·this·provides 
10 ······························$·sudo·yum·install·dracut-fips-aesni·········assurance·they·have·been·tested·and 
11 ···········································································validated. 
12 ······························The·SMAP·is·used·to·prevent·the·supervisor 
13 ······························mode·from·unintentionally·reading/writing 
14 ······························into·memory·pages·in·the·user·space,·it·is 
15 ······························enabled·by·default·since·Linux·kernel·3.7. 
16 ······························But·it·could·be·disabled·through·kernel·boot 
17 ······························parameters.·Ensure·that·Supervisor·Mode 
18 ······························Access·Prevention·(SMAP)·is·not·disabled·by··Disabling·SMAP·can·facilitate 
19 R1··Ensure·SMAP·is·not········the·nosmap·boot·paramenter·option.·Check·····exploitation·of·vulnerabilities·caused 
20 ····disabled·during·boot······that·the·line································by·unintended·access·and·manipulation 
21 ······························GRUB_CMDLINE_LINUX="..."·····················of·data·in·the·user·space. 
22 ······························within·/etc/default/grub·doesn't·contain·the 
23 ······························argument·nosmap.·Run·the·following·command 
24 ······························to·update·command·line·for·already·installed 
25 ······························kernels: 
26 ······························#·grubby·--update-kernel=ALL·--remove- 
27 ······························args="nosmap" 
28 ···········································································Use·of·a·64-bit·operating·system3 ···········································································Use·of·a·64-bit·operating·system
29 ···········································································offers·a·few·advantages,·like·a·larger4 ···········································································offers·a·few·advantages,·like·a·larger
30 ····Prefer·to·use·a·64-bit····Prefer·installation·of·64-bit·operating······address·space·range·for·Address·Space5 ····Prefer·to·use·a·64-bit····Prefer·installation·of·64-bit·operating······address·space·range·for·Address·Space
31 R1··Operating·System·when·····systems·when·the·CPU·supports·it.············Layout·Randomization·(ASLR)·and6 R1··Operating·System·when·····systems·when·the·CPU·supports·it.············Layout·Randomization·(ASLR)·and
32 ····supported······························································systematic·presence·of·No·eXecute·and7 ····supported······························································systematic·presence·of·No·eXecute·and
33 ···········································································Execute·Disable·(NX/XD)·protection8 ···········································································Execute·Disable·(NX/XD)·protection
34 ···········································································bits.9 ···········································································bits.
Offset 62, 14 lines modifiedOffset 37, 39 lines modified
62 ······························GRUB_CMDLINE_LINUX="..."·····················kernel·to·unintentionally·execute·code37 ······························GRUB_CMDLINE_LINUX="..."·····················kernel·to·unintentionally·execute·code
63 ······························within·/etc/default/grub·doesn't·contain·the·in·less·privileged·memory·space.38 ······························within·/etc/default/grub·doesn't·contain·the·in·less·privileged·memory·space.
64 ······························argument·nosmep.·Run·the·following·command39 ······························argument·nosmep.·Run·the·following·command
65 ······························to·update·command·line·for·already·installed40 ······························to·update·command·line·for·already·installed
66 ······························kernels:41 ······························kernels:
67 ······························#·grubby·--update-kernel=ALL·--remove-42 ······························#·grubby·--update-kernel=ALL·--remove-
68 ······························args="nosmep"43 ······························args="nosmep"
 44 ······························The·SMAP·is·used·to·prevent·the·supervisor
 45 ······························mode·from·unintentionally·reading/writing
 46 ······························into·memory·pages·in·the·user·space,·it·is
 47 ······························enabled·by·default·since·Linux·kernel·3.7.
 48 ······························But·it·could·be·disabled·through·kernel·boot
 49 ······························parameters.·Ensure·that·Supervisor·Mode
 50 ······························Access·Prevention·(SMAP)·is·not·disabled·by··Disabling·SMAP·can·facilitate
 51 R1··Ensure·SMAP·is·not········the·nosmap·boot·paramenter·option.·Check·····exploitation·of·vulnerabilities·caused
 52 ····disabled·during·boot······that·the·line································by·unintended·access·and·manipulation
 53 ······························GRUB_CMDLINE_LINUX="..."·····················of·data·in·the·user·space.
 54 ······························within·/etc/default/grub·doesn't·contain·the
 55 ······························argument·nosmap.·Run·the·following·command
 56 ······························to·update·command·line·for·already·installed
 57 ······························kernels:
 58 ······························#·grubby·--update-kernel=ALL·--remove-
 59 ······························args="nosmap"
 60 ···········································································Use·of·weak·or·untested·encryption
 61 ······························To·enable·FIPS·on·system·that·support·the····algorithms·undermines·the·purposes·of
 62 ······························Advanced·Encryption·Standard·(AES)·or·New····utilizing·encryption·to·protect·data.
 63 ····Install·the·dracut-fips-··Instructions·(AES-NI)·engine,·the·system·····The·operating·system·must·implement
 64 R1··aesni·Package·············requires·that·the·dracut-fips-aesni·package··cryptographic·modules·adhering·to·the
 65 ······························be·installed.·The·dracut-fips-aesni·package··higher·standards·approved·by·the
 66 ······························can·be·installed·with·the·following·command:·federal·government·since·this·provides
 67 ······························$·sudo·yum·install·dracut-fips-aesni·········assurance·they·have·been·tested·and
 68 ···········································································validated.
69 ······························The·grub2·boot·loader·should·have·a69 ······························The·grub2·boot·loader·should·have·a
70 ······························superuser·account·and·password·protection70 ······························superuser·account·and·password·protection
71 ······························enabled·to·protect·boot-time·settings.·······Password·protection·on·the·boot·loader71 ······························enabled·to·protect·boot-time·settings.·······Password·protection·on·the·boot·loader
72 ···········································································configuration·ensures·users·with72 ···········································································configuration·ensures·users·with
73 ····Set·Boot·Loader·Password··Since·plaintext·passwords·are·a·security·····physical·access·cannot·trivially·alter73 ····Set·Boot·Loader·Password··Since·plaintext·passwords·are·a·security·····physical·access·cannot·trivially·alter
74 R5··in·grub2··················risk,·generate·a·hash·for·the·password·by····important·bootloader·settings.·These74 R5··in·grub2··················risk,·generate·a·hash·for·the·password·by····important·bootloader·settings.·These
75 ······························running·the·following·command:···············include·which·kernel·to·use,·and75 ······························running·the·following·command:···············include·which·kernel·to·use,·and
Offset 99, 77 lines modifiedOffset 99, 141 lines modified
99 ······························systems.·Modify·the·line·within·/etc/········hardware·devices.99 ······························systems.·Modify·the·line·within·/etc/········hardware·devices.
100 ······························default/grub·as·shown·below:100 ······························default/grub·as·shown·below:
101 ······························GRUB_CMDLINE_LINUX="...·iommu=force·..."101 ······························GRUB_CMDLINE_LINUX="...·iommu=force·..."
102 ······························Run·the·following·command·to·update·command102 ······························Run·the·following·command·to·update·command
103 ······························line·for·already·installed·kernels:103 ······························line·for·already·installed·kernels:
104 ······························#·grubby·--update-kernel=ALL·--104 ······························#·grubby·--update-kernel=ALL·--
105 ······························args="iommu=force"105 ······························args="iommu=force"
106 ······························Microarchitectural·Data·Sampling·(MDS)·is·a 
107 ······························hardware·vulnerability·which·allows 
108 ······························unprivileged·speculative·access·to·data 
109 ······························which·is·available·in·various·CPU·internal 
110 ······························buffers.·When·performing·store,·load,·L1 
111 ······························refill·operations,·processors·write·data 
112 ······························into·temporary·microarchitectural·structures 
113 ······························(buffers),·and·the·data·in·the·buffer·can·be 
114 ······························forwarded·to·load·operations·as·an 
115 ······························optimization.·Under·certain·conditions,·data 
116 ······························unrelated·to·the·load·operations·can·be 
117 ······························speculatively·forwarded·from·the·buffers·to 
118 ······························a·disclosure·gadget·which·allows·in·turn·to 
119 ······························infer·the·value·via·a·cache·side·channel 
120 ······························attack.·Select·the·appropriate·mitigation·by106 ······························The·kernel·may·merge·similar·slabs·together
 107 ······························to·reduce·overhead·and·increase·cache
 108 ······························hotness·of·objects.·Disabling·merging·of
 109 ······························slabs·keeps·the·slabs·separate·and·reduces
 110 ······························the·risk·of·kernel·heap·overflows
 111 ······························overwriting·objects·in·merged·caches.·To·····Disabling·the·merge·of·slabs·of
 112 ······························disable·merging·of·slabs·in·the·Kernel·add···similar·sizes·prevents·the·kernel·from
 113 ······························the·argument·slab_nomerge=yes·to·the·default·merging·a·seemingly·useless·but
 114 ······························GRUB·2·command·line·for·the·Linux·operating··vulnerable·slab·with·a·useful·and
 115 ······························system.·To·ensure·that·slab_nomerge=yes·is···valuable·slab.·This·increase·the·risk
 116 R8··Disable·merging·of·slabs··added·as·a·kernel·command·line·argument·to···that·a·heap·overflow·could·overwrite
 117 ····with·similar·size·········newly·installed·kernels,·add·················objects·from·merged·caches,·with
 118 ······························slab_nomerge=yes·to·the·default·Grub2········unmerged·caches·the·heap·overflow
 119 ······························command·line·for·Linux·operating·systems.····would·only·affect·the·objects·in·the
 120 ······························Modify·the·line·within·/etc/default/grub·as··same·cache.·Overall,·this·reduces·the
 121 ······························shown·below:·································kernel·attack·surface·area·by
 122 ······························GRUB_CMDLINE_LINUX="...·slab_nomerge=yes·····isolating·slabs·from·each·other.
 123 ······························..."
 124 ······························Run·the·following·command·to·update·command
 125 ······························line·for·already·installed·kernels:
 126 ······························#·grubby·--update-kernel=ALL·--
 127 ······························args="slab_nomerge=yes"
 128 ······························To·enable·Kernel·page-table·isolation,·add
121 ······························adding·the·argument·mds=full·to·the·default129 ······························the·argument·pti=on·to·the·default·GRUB·2
122 ····Configure·················GRUB·2·command·line·for·the·Linux·operating··The·MDS·vulnerability·allows·an 
123 R8··Microarchitectural·Data···system.·To·ensure·that·mds=full·is·added·as··attacker·to·sample·data·from·internal 
124 ····Sampling·mitigation·······a·kernel·command·line·argument·to·newly······CPU·buffers.130 ······························command·line·for·the·Linux·operating·system.
Max diff block lines reached; 674674/690189 bytes (97.75%) of diff not shown.
1.22 MB
./usr/share/doc/ssg-nondebian/table-ol7-cuirefs.html
Ordering differences only
    
Offset 40, 45 lines modifiedOffset 40, 53 lines modified
40 ····<th>Mapping</th>40 ····<th>Mapping</th>
41 ····<th>Rule·Title</th>41 ····<th>Rule·Title</th>
42 ····<th>Description</th>42 ····<th>Description</th>
43 ····<th>Rationale</th>43 ····<th>Rationale</th>
44 ··</thead>44 ··</thead>
45 ··<tbody>45 ··<tbody>
46 ··<tr>46 ··<tr>
47 ······<td>3.1.1</td>47 ······<td>3.1.1<br/>3.1.5</td>
48 ······<td>Disable·GDM·Guest·Login</td>48 ······<td>Disable·SSH·Access·via·Empty·Passwords</td>
49 ······<td·xml:lang="en-US">49 ······<td·xml:lang="en-US">
50 ········The·GNOME·Display·Manager·(GDM)·can·allow·users·to·login·without·credentials 
51 which·can·be·useful·for·public·kiosk·scenarios.·Allowing·users·to·login·without·credentials 
52 or·"guest"·account·access·has·inherent·security·risks·and·should·be·disabled.·To·do·disable 
53 timed·logins·or·guest·account·access,·set·the·<tt>TimedLoginEnable</tt>·to·<tt>false</tt>·in 
54 the·<tt>[daemon]</tt>·section·in·<tt>/etc/gdm/custom.conf</tt>.·For·example: 
55 <pre>[daemon] 
56 TimedLoginEnable=false</pre>50 ········Disallow·SSH·login·with·empty·passwords.
 51 The·default·SSH·configuration·disables·logins·with·empty·passwords.·The·appropriate
 52 configuration·is·used·if·no·value·is·set·for·<tt>PermitEmptyPasswords</tt>.
 53 <br·/>
 54 To·explicitly·disallow·SSH·login·from·accounts·with·empty·passwords,
 55 add·or·correct·the·following·line·in
  
  
 56 <tt>/etc/ssh/sshd_config</tt>:
  
 57 <br·/>
 58 <pre>PermitEmptyPasswords·no</pre>
 59 Any·accounts·with·empty·passwords·should·be·disabled·immediately,·and·PAM·configuration
 60 should·prevent·users·from·being·able·to·assign·themselves·empty·passwords.
57 ······</td>61 ······</td>
58 ······<td·xml:lang="en-US">62 ······<td·xml:lang="en-US">
59 ········Failure·to·restrict·system·access·to·authenticated·users·negatively·impacts·operating 
60 system·security.63 ········Configuring·this·setting·for·the·SSH·daemon·provides·additional·assurance
 64 that·remote·login·via·SSH·will·require·a·password,·even·in·the·event·of
 65 misconfiguration·elsewhere.
61 ······</td>66 ······</td>
62 ····</tr>67 ····</tr>
63 ····<tr>68 ····<tr>
64 ······<td>3.1.1<br/>3.1.5</td>69 ······<td>3.1.1</td>
65 ······<td>Restrict·Virtual·Console·Root·Logins</td>70 ······<td>Disable·GDM·Automatic·Login</td>
66 ······<td·xml:lang="en-US">71 ······<td·xml:lang="en-US">
67 ········To·restrict·root·logins·through·the·(deprecated)·virtual·console·devices, 
68 ensure·lines·of·this·form·do·not·appear·in·<tt>/etc/securetty</tt>: 
69 <pre>vc/1 
70 vc/2 
71 vc/3 
72 vc/4</pre>72 ········The·GNOME·Display·Manager·(GDM)·can·allow·users·to·automatically·login·without
 73 user·interaction·or·credentials.·User·should·always·be·required·to·authenticate·themselves
 74 to·the·system·that·they·are·authorized·to·use.·To·disable·user·ability·to·automatically
 75 login·to·the·system,·set·the·<tt>AutomaticLoginEnable</tt>·to·<tt>false</tt>·in·the
 76 <tt>[daemon]</tt>·section·in·<tt>/etc/gdm/custom.conf</tt>.·For·example:
 77 <pre>[daemon]
 78 AutomaticLoginEnable=false</pre>
73 ······</td>79 ······</td>
74 ······<td·xml:lang="en-US">80 ······<td·xml:lang="en-US">
 81 ········Failure·to·restrict·system·access·to·authenticated·users·negatively·impacts·operating
 82 system·security.
75 ········Preventing·direct·root·login·to·virtual·console·devices 
76 helps·ensure·accountability·for·actions·taken·on·the·system 
77 using·the·root·account. 
78 ······</td>83 ······</td>
79 ····</tr>84 ····</tr>
80 ····<tr>85 ····<tr>
81 ······<td>3.1.1<br/>3.1.5</td>86 ······<td>3.1.1<br/>3.1.5</td>
82 ······<td>Disable·SSH·Root·Login</td>87 ······<td>Disable·SSH·Root·Login</td>
83 ······<td·xml:lang="en-US">88 ······<td·xml:lang="en-US">
84 ········The·root·user·should·never·be·allowed·to·login·to·a89 ········The·root·user·should·never·be·allowed·to·login·to·a
Offset 95, 23 lines modifiedOffset 103, 43 lines modified
95 security·is·gained·by·extending·the·policy·of·not·logging·directly·on·as·root.103 security·is·gained·by·extending·the·policy·of·not·logging·directly·on·as·root.
96 In·addition,·logging·in·with·a·user-specific·account·provides·individual104 In·addition,·logging·in·with·a·user-specific·account·provides·individual
97 accountability·of·actions·performed·on·the·system·and·also·helps·to·minimize105 accountability·of·actions·performed·on·the·system·and·also·helps·to·minimize
98 direct·attack·attempts·on·root's·password.106 direct·attack·attempts·on·root's·password.
99 ······</td>107 ······</td>
100 ····</tr>108 ····</tr>
101 ····<tr>109 ····<tr>
 110 ······<td>3.1.1<br/>3.1.5</td>
 111 ······<td>Prevent·Login·to·Accounts·With·Empty·Password</td>
 112 ······<td·xml:lang="en-US">
 113 ········If·an·account·is·configured·for·password·authentication
 114 but·does·not·have·an·assigned·password,·it·may·be·possible·to·log
 115 into·the·account·without·authentication.·Remove·any·instances·of·the
 116 <tt>nullok</tt>·in
  
 117 <tt>/etc/pam.d/system-auth</tt>·and
 118 <tt>/etc/pam.d/password-auth</tt>
  
 119 to·prevent·logins·with·empty·passwords.
 120 ······</td>
 121 ······<td·xml:lang="en-US">
 122 ········If·an·account·has·an·empty·password,·anyone·could·log·in·and
 123 run·commands·with·the·privileges·of·that·account.·Accounts·with
 124 empty·passwords·should·never·be·used·in·operational·environments.
 125 ······</td>
 126 ····</tr>
 127 ····<tr>
102 ······<td>3.1.1<br/>3.4.5</td>128 ······<td>3.1.1<br/>3.4.5</td>
103 ······<td>Require·Authentication·for·Single·User·Mode</td>129 ······<td>Require·Authentication·for·Emergency·Systemd·Target</td>
104 ······<td·xml:lang="en-US">130 ······<td·xml:lang="en-US">
105 ········Single-user·mode·is·intended·as·a·system·recovery131 ········Emergency·mode·is·intended·as·a·system·recovery
106 method,·providing·a·single·user·root·access·to·the·system·by132 method,·providing·a·single·user·root·access·to·the·system
107 providing·a·boot·option·at·startup.133 during·a·failed·boot·sequence.
108 <br·/><br·/>134 <br·/><br·/>
109 By·default,·single-user·mode·is·protected·by·requiring·a·password·and·is·set135 By·default,·Emergency·mode·is·protected·by·requiring·a·password·and·is·set
110 in·<tt>/usr/lib/systemd/system/rescue.service</tt>.136 in·<tt>/usr/lib/systemd/system/emergency.service</tt>.
111 ······</td>137 ······</td>
112 ······<td·xml:lang="en-US">138 ······<td·xml:lang="en-US">
113 ········This·prevents·attackers·with·physical·access·from·trivially·bypassing·security139 ········This·prevents·attackers·with·physical·access·from·trivially·bypassing·security
114 on·the·machine·and·gaining·root·access.·Such·accesses·are·further·prevented140 on·the·machine·and·gaining·root·access.·Such·accesses·are·further·prevented
115 by·configuring·the·bootloader·password.141 by·configuring·the·bootloader·password.
116 ······</td>142 ······</td>
117 ····</tr>143 ····</tr>
Offset 127, 45 lines modifiedOffset 155, 71 lines modified
127 ······<td·xml:lang="en-US">155 ······<td·xml:lang="en-US">
128 ········Preventing·direct·root·login·to·serial·port·interfaces156 ········Preventing·direct·root·login·to·serial·port·interfaces
129 helps·ensure·accountability·for·actions·taken·on·the·systems157 helps·ensure·accountability·for·actions·taken·on·the·systems
130 using·the·root·account.158 using·the·root·account.
131 ······</td>159 ······</td>
132 ····</tr>160 ····</tr>
133 ····<tr>161 ····<tr>
134 ······<td>3.1.1<br/>3.4.5</td>162 ······<td>3.1.1<br/>3.1.6</td>
135 ······<td>Require·Authentication·for·Emergency·Systemd·Target</td>163 ······<td>Direct·root·Logins·Not·Allowed</td>
136 ······<td·xml:lang="en-US">164 ······<td·xml:lang="en-US">
137 ········Emergency·mode·is·intended·as·a·system·recovery 
138 method,·providing·a·single·user·root·access·to·the·system 
139 during·a·failed·boot·sequence. 
140 <br·/><br·/> 
Max diff block lines reached; 456802/463660 bytes (98.52%) of diff not shown.
800 KB
html2text {}
    
Offset 1, 31 lines modifiedOffset 1, 35 lines modified
  
  
1 Rules·with·NIST-800-171·Reference·in·Guide·to·the·Secure·Configuration·of1 Rules·with·NIST-800-171·Reference·in·Guide·to·the·Secure·Configuration·of
2 Oracle·Linux·72 Oracle·Linux·7
  
  
 3 ·······································Disallow·SSH·login·with·empty·passwords.·The·default
 4 ·······································SSH·configuration·disables·logins·with·empty···········Configuring·this
 5 ·······································passwords.·The·appropriate·configuration·is·used·if·no·setting·for·the·SSH
 6 ·······································value·is·set·for·PermitEmptyPasswords.·················daemon·provides
 7 ·······································To·explicitly·disallow·SSH·login·from·accounts·with····additional·assurance
 8 3.1.1···Disable·SSH·Access·via·Empty···empty·passwords,·add·or·correct·the·following·line·in··that·remote·login
 9 3.1.5···Passwords······················/etc/ssh/sshd_config:··································via·SSH·will·require
 10 ·······································PermitEmptyPasswords·no································a·password,·even·in
 11 ·······································Any·accounts·with·empty·passwords·should·be·disabled···the·event·of
 12 ·······································immediately,·and·PAM·configuration·should·prevent······misconfiguration
 13 ·······································users·from·being·able·to·assign·themselves·empty·······elsewhere.
 14 ·······································passwords.
3 ·······································The·GNOME·Display·Manager·(GDM)·can·allow·users·to15 ·······································The·GNOME·Display·Manager·(GDM)·can·allow·users·to
4 ·······································login·without·credentials·which·can·be·useful·for 
5 ·······································public·kiosk·scenarios.·Allowing·users·to·login········Failure·to·restrict 
6 ·······································without·credentials·or·"guest"·account·access·has······system·access·to 
7 3.1.1···Disable·GDM·Guest·Login········inherent·security·risks·and·should·be·disabled.·To·do··authenticated·users 
8 ·······································disable·timed·logins·or·guest·account·access,·set·the··negatively·impacts16 ·······································automatically·login·without·user·interaction·or
 17 ·······································credentials.·User·should·always·be·required·to·········Failure·to·restrict
 18 ·······································authenticate·themselves·to·the·system·that·they·are····system·access·to
 19 3.1.1···Disable·GDM·Automatic·Login····authorized·to·use.·To·disable·user·ability·to··········authenticated·users
 20 ·······································automatically·login·to·the·system,·set·the·············negatively·impacts
9 ·······································TimedLoginEnable·to·false·in·the·[daemon]·section·in·/·operating·system21 ·······································AutomaticLoginEnable·to·false·in·the·[daemon]·section··operating·system
10 ·······································etc/gdm/custom.conf.·For·example:······················security.22 ·······································in·/etc/gdm/custom.conf.·For·example:··················security.
11 ·······································[daemon]23 ·······································[daemon]
12 ·······································TimedLoginEnable=false24 ·······································AutomaticLoginEnable=false
13 ·······································To·restrict·root·logins·through·the·(deprecated)·······Preventing·direct 
14 ·······································virtual·console·devices,·ensure·lines·of·this·form·do··root·login·to 
15 ·······································not·appear·in·/etc/securetty:··························virtual·console 
16 3.1.1···Restrict·Virtual·Console·Root··vc/1···················································devices·helps·ensure 
17 3.1.5···Logins·························vc/2···················································accountability·for 
18 ·······································vc/3···················································actions·taken·on·the 
19 ·······································vc/4···················································system·using·the 
20 ······························································································root·account. 
21 ······························································································Even·though·the25 ······························································································Even·though·the
22 ······························································································communications26 ······························································································communications
23 ······························································································channel·may·be27 ······························································································channel·may·be
24 ······························································································encrypted,·an28 ······························································································encrypted,·an
25 ······························································································additional·layer·of29 ······························································································additional·layer·of
26 ······························································································security·is·gained30 ······························································································security·is·gained
27 ······························································································by·extending·the31 ······························································································by·extending·the
Offset 39, 54 lines modifiedOffset 43, 80 lines modified
39 ······························································································accountability·of43 ······························································································accountability·of
40 ······························································································actions·performed·on44 ······························································································actions·performed·on
41 ······························································································the·system·and·also45 ······························································································the·system·and·also
42 ······························································································helps·to·minimize46 ······························································································helps·to·minimize
43 ······························································································direct·attack47 ······························································································direct·attack
44 ······························································································attempts·on·root's48 ······························································································attempts·on·root's
45 ······························································································password.49 ······························································································password.
 50 ······························································································If·an·account·has·an
 51 ······························································································empty·password,
 52 ·······································If·an·account·is·configured·for·password···············anyone·could·log·in
 53 ·······································authentication·but·does·not·have·an·assigned·password,·and·run·commands
 54 3.1.1···Prevent·Login·to·Accounts·With·it·may·be·possible·to·log·into·the·account·without·····with·the·privileges
 55 3.1.5···Empty·Password·················authentication.·Remove·any·instances·of·the·nullok·in··of·that·account.
 56 ·······································/etc/pam.d/system-auth·and·/etc/pam.d/password-auth·to·Accounts·with·empty
 57 ·······································prevent·logins·with·empty·passwords.···················passwords·should
 58 ······························································································never·be·used·in
 59 ······························································································operational
 60 ······························································································environments.
46 ······························································································This·prevents61 ······························································································This·prevents
47 ······························································································attackers·with62 ······························································································attackers·with
48 ·······································Single-user·mode·is·intended·as·a·system·recovery······physical·access·from63 ·······································Emergency·mode·is·intended·as·a·system·recovery········physical·access·from
49 ·······································method,·providing·a·single·user·root·access·to·the·····trivially·bypassing64 ·······································method,·providing·a·single·user·root·access·to·the·····trivially·bypassing
50 3.1.1···Require·Authentication·for·····system·by·providing·a·boot·option·at·startup.··········security·on·the65 3.1.1···Require·Authentication·for·····system·during·a·failed·boot·sequence.··················security·on·the
51 3.4.5···Single·User·Mode······································································machine·and·gaining66 3.4.5···Emergency·Systemd·Target······························································machine·and·gaining
52 ·······································By·default,·single-user·mode·is·protected·by·requiring·root·access.·Such67 ·······································By·default,·Emergency·mode·is·protected·by·requiring·a·root·access.·Such
53 ·······································a·password·and·is·set·in·/usr/lib/systemd/system/······accesses·are·further68 ·······································password·and·is·set·in·/usr/lib/systemd/system/········accesses·are·further
54 ·······································rescue.service.········································prevented·by69 ·······································emergency.service.·····································prevented·by
55 ······························································································configuring·the70 ······························································································configuring·the
56 ······························································································bootloader·password.71 ······························································································bootloader·password.
57 ······························································································Preventing·direct72 ······························································································Preventing·direct
58 ······························································································root·login·to·serial73 ······························································································root·login·to·serial
59 ·······································To·restrict·root·logins·on·serial·ports,·ensure·lines··port·interfaces74 ·······································To·restrict·root·logins·on·serial·ports,·ensure·lines··port·interfaces
60 3.1.1···Restrict·Serial·Port·Root······of·this·form·do·not·appear·in·/etc/securetty:··········helps·ensure75 3.1.1···Restrict·Serial·Port·Root······of·this·form·do·not·appear·in·/etc/securetty:··········helps·ensure
61 3.1.5···Logins·························ttyS0··················································accountability·for76 3.1.5···Logins·························ttyS0··················································accountability·for
62 ·······································ttyS1··················································actions·taken·on·the77 ·······································ttyS1··················································actions·taken·on·the
63 ······························································································systems·using·the78 ······························································································systems·using·the
64 ······························································································root·account.79 ······························································································root·account.
 80 ·······································To·further·limit·access·to·the·root·account,
 81 ·······································administrators·can·disable·root·logins·at·the·console··Disabling·direct
 82 ·······································by·editing·the·/etc/securetty·file.·This·file·lists····root·logins·ensures
 83 ·······································all·devices·the·root·user·is·allowed·to·login·to.·If···proper
 84 ·······································the·file·does·not·exist·at·all,·the·root·user·can······accountability·and
 85 ·······································login·through·any·communication·device·on·the·system,··multifactor
 86 ·······································whether·via·the·console·or·via·a·raw·network···········authentication·to
 87 3.1.1··································interface.·This·is·dangerous·as·user·can·login·to·the··privileged·accounts.
 88 3.1.6···Direct·root·Logins·Not·Allowed·system·as·root·via·Telnet,·which·sends·the·password·in·Users·will·first
 89 ·······································plain·text·over·the·network.·By·default,·Oracle·Linux··login,·then·escalate
 90 ·······································7's·/etc/securetty·file·only·allows·the·root·user·to···to·privileged·(root)
 91 ·······································login·at·the·console·physically·attached·to·the········access·via·su·/
 92 ·······································system.·To·prevent·root·from·logging·in,·remove·the····sudo.·This·is
 93 ·······································contents·of·this·file.·To·prevent·direct·root·logins,··required·for·FISMA
 94 ·······································remove·the·contents·of·this·file·by·typing·the·········Low·and·FISMA
 95 ·······································following·command:·····································Moderate·systems.
 96 ·······································$·sudo·echo·>·/etc/securetty
 97 ·······································To·restrict·root·logins·through·the·(deprecated)·······Preventing·direct
 98 ·······································virtual·console·devices,·ensure·lines·of·this·form·do··root·login·to
 99 ·······································not·appear·in·/etc/securetty:··························virtual·console
 100 3.1.1···Restrict·Virtual·Console·Root··vc/1···················································devices·helps·ensure
 101 3.1.5···Logins·························vc/2···················································accountability·for
 102 ·······································vc/3···················································actions·taken·on·the
 103 ·······································vc/4···················································system·using·the
 104 ······························································································root·account.
65 ······························································································This·prevents105 ······························································································This·prevents
66 ······························································································attackers·with106 ······························································································attackers·with
67 ·······································Emergency·mode·is·intended·as·a·system·recovery········physical·access·from107 ·······································Single-user·mode·is·intended·as·a·system·recovery······physical·access·from
68 ·······································method,·providing·a·single·user·root·access·to·the·····trivially·bypassing108 ·······································method,·providing·a·single·user·root·access·to·the·····trivially·bypassing
69 3.1.1···Require·Authentication·for·····system·during·a·failed·boot·sequence.··················security·on·the109 3.1.1···Require·Authentication·for·····system·by·providing·a·boot·option·at·startup.··········security·on·the
70 3.4.5···Emergency·Systemd·Target······························································machine·and·gaining110 3.4.5···Single·User·Mode······································································machine·and·gaining
71 ·······································By·default,·Emergency·mode·is·protected·by·requiring·a·root·access.·Such111 ·······································By·default,·single-user·mode·is·protected·by·requiring·root·access.·Such
72 ·······································password·and·is·set·in·/usr/lib/systemd/system/········accesses·are·further112 ·······································a·password·and·is·set·in·/usr/lib/systemd/system/······accesses·are·further
73 ·······································emergency.service.·····································prevented·by113 ·······································rescue.service.········································prevented·by
74 ······························································································configuring·the114 ······························································································configuring·the
75 ······························································································bootloader·password.115 ······························································································bootloader·password.
76 ·······································The·GNOME·Display·Manager·(GDM)·can·allow·users·to 
77 ·······································automatically·login·without·user·interaction·or 
78 ·······································credentials.·User·should·always·be·required·to·········Failure·to·restrict 
79 ·······································authenticate·themselves·to·the·system·that·they·are····system·access·to 
80 3.1.1···Disable·GDM·Automatic·Login····authorized·to·use.·To·disable·user·ability·to··········authenticated·users 
81 ·······································automatically·login·to·the·system,·set·the·············negatively·impacts 
Max diff block lines reached; 803696/819151 bytes (98.11%) of diff not shown.
3.49 KB
./usr/share/doc/ssg-nondebian/table-ol7-nistrefs-stig.html
    
Offset 8559, 18 lines modifiedOffset 8559, 18 lines modified
000216e0:·616e·6420·7573·6520·7468·6520·696e·666f··and·use·the·info000216e0:·616e·6420·7573·6520·7468·6520·696e·666f··and·use·the·info
000216f0:·726d·6174·696f·6e20·746f·2070·6f74·656e··rmation·to·poten000216f0:·726d·6174·696f·6e20·746f·2070·6f74·656e··rmation·to·poten
00021700:·7469·616c·6c79·2063·6f6d·7072·6f6d·6973··tially·compromis00021700:·7469·616c·6c79·2063·6f6d·7072·6f6d·6973··tially·compromis
00021710:·6520·7468·6520·696e·7465·6772·6974·7920··e·the·integrity·00021710:·6520·7468·6520·696e·7465·6772·6974·7920··e·the·integrity·
00021720:·6f66·2074·6865·2073·7973·7465·6d20·616e··of·the·system·an00021720:·6f66·2074·6865·2073·7973·7465·6d20·616e··of·the·system·an
00021730:·640a·6e65·7477·6f72·6b28·7329·2e0a·2020··d.network(s)..··00021730:·640a·6e65·7477·6f72·6b28·7329·2e0a·2020··d.network(s)..··
00021740:·3c2f·7464·3e0a·2020·3c74·643e·7661·725f··</td>.··<td>var_00021740:·3c2f·7464·3e0a·2020·3c74·643e·7661·725f··</td>.··<td>var_
00021750:·736e·6d70·645f·7277·5f73·7472·696e·673d··snmpd_rw_string=00021750:·736e·6d70·645f·726f·5f73·7472·696e·673d··snmpd_ro_string=
00021760:·6368·616e·6765·6d65·7277·3c62·722f·3e76··changemerw<br/>v00021760:·6368·616e·6765·6d65·726f·3c62·722f·3e76··changemero<br/>v
00021770:·6172·5f73·6e6d·7064·5f72·6f5f·7374·7269··ar_snmpd_ro_stri00021770:·6172·5f73·6e6d·7064·5f72·775f·7374·7269··ar_snmpd_rw_stri
00021780:·6e67·3d63·6861·6e67·656d·6572·6f3c·2f74··ng=changemero</t00021780:·6e67·3d63·6861·6e67·656d·6572·773c·2f74··ng=changemerw</t
00021790:·643e·0a3c·2f74·723e·0a3c·7472·3e0a·2020··d>.</tr>.<tr>.··00021790:·643e·0a3c·2f74·723e·0a3c·7472·3e0a·2020··d>.</tr>.<tr>.··
000217a0:·3c74·643e·5343·2d35·3c2f·7464·3e0a·2020··<td>SC-5</td>.··000217a0:·3c74·643e·5343·2d35·3c2f·7464·3e0a·2020··<td>SC-5</td>.··
000217b0:·3c74·643e·4e2f·413c·2f74·643e·0a20·203c··<td>N/A</td>.··<000217b0:·3c74·643e·4e2f·413c·2f74·643e·0a20·203c··<td>N/A</td>.··<
000217c0:·7464·3e43·6f6e·6669·6775·7265·204b·6572··td>Configure·Ker000217c0:·7464·3e43·6f6e·6669·6775·7265·204b·6572··td>Configure·Ker
000217d0:·6e65·6c20·746f·2052·6174·6520·4c69·6d69··nel·to·Rate·Limi000217d0:·6e65·6c20·746f·2052·6174·6520·4c69·6d69··nel·to·Rate·Limi
000217e0:·7420·5365·6e64·696e·6720·6f66·2044·7570··t·Sending·of·Dup000217e0:·7420·5365·6e64·696e·6720·6f66·2044·7570··t·Sending·of·Dup
000217f0:·6c69·6361·7465·2054·4350·2041·636b·6e6f··licate·TCP·Ackno000217f0:·6c69·6361·7465·2054·4350·2041·636b·6e6f··licate·TCP·Ackno
1.87 KB
html2text {}
    
Offset 2919, 16 lines modifiedOffset 2919, 16 lines modified
2919 ··············································································network·management2919 ··············································································network·management
2920 ··············································································protocol·(SNMP)2920 ··············································································protocol·(SNMP)
2921 ··············································································community·strings2921 ··············································································community·strings
2922 ··············································································must·be·changed·to2922 ··············································································must·be·changed·to
2923 ··································Edit·/etc/snmp/snmpd.conf,·remove·or·change·maintain·security.2923 ··································Edit·/etc/snmp/snmpd.conf,·remove·or·change·maintain·security.
2924 ··································the·default·community·strings·of·public·and·If·the·service·is2924 ··································the·default·community·strings·of·public·and·If·the·service·is
2925 ··································private.·This·profile·configures·new·read-··running·with·the2925 ··································private.·This·profile·configures·new·read-··running·with·the
2926 ········N/·Ensure·Default·SNMP····only·community·string·to·changemero·and·····default·············var_snmpd_rw_string=changemerw2926 ········N/·Ensure·Default·SNMP····only·community·string·to·changemero·and·····default·············var_snmpd_ro_string=changemero
2927 IA-5(e)·A··Password·Is·Not·Used···read-write·community·string·to·changemerw.··authenticators,·····var_snmpd_ro_string=changemero2927 IA-5(e)·A··Password·Is·Not·Used···read-write·community·string·to·changemerw.··authenticators,·····var_snmpd_rw_string=changemerw
2928 ··································Once·the·default·community·strings·have·····then·anyone·can2928 ··································Once·the·default·community·strings·have·····then·anyone·can
2929 ··································been·changed,·restart·the·SNMP·service:·····gather·data·about2929 ··································been·changed,·restart·the·SNMP·service:·····gather·data·about
2930 ··································$·sudo·systemctl·restart·snmpd··············the·system·and·the2930 ··································$·sudo·systemctl·restart·snmpd··············the·system·and·the
2931 ··············································································network·and·use·the2931 ··············································································network·and·use·the
2932 ··············································································information·to2932 ··············································································information·to
2933 ··············································································potentially2933 ··············································································potentially
2934 ··············································································compromise·the2934 ··············································································compromise·the
9.78 MB
./usr/share/doc/ssg-nondebian/table-ol7-nistrefs.html
    
Offset 66, 15745 lines modifiedOffset 66, 15745 lines modified
00000410:·0a20·2020·203c·7468·3e52·6174·696f·6e61··.····<th>Rationa00000410:·0a20·2020·203c·7468·3e52·6174·696f·6e61··.····<th>Rationa
00000420:·6c65·3c2f·7468·3e0a·2020·3c2f·7468·6561··le</th>.··</thea00000420:·6c65·3c2f·7468·3e0a·2020·3c2f·7468·6561··le</th>.··</thea
00000430:·643e·0a20·203c·7462·6f64·793e·0a20·203c··d>.··<tbody>.··<00000430:·643e·0a20·203c·7462·6f64·793e·0a20·203c··d>.··<tbody>.··<
00000440:·7472·3e0a·2020·2020·2020·3c74·643e·4155··tr>.······<td>AU00000440:·7472·3e0a·2020·2020·2020·3c74·643e·4155··tr>.······<td>AU
00000450:·2d32·2861·293c·2f74·643e·0a20·2020·2020··-2(a)</td>.·····00000450:·2d32·2861·293c·2f74·643e·0a20·2020·2020··-2(a)</td>.·····
00000460:·203c·7464·3e43·6f6e·6669·6775·7265·2061···<td>Configure·a00000460:·203c·7464·3e43·6f6e·6669·6775·7265·2061···<td>Configure·a
Diff chunk too large, falling back to line-by-line diff (1453 lines added, 1453 lines removed)
00000470:·7564·6974·696e·6720·6f66·2073·7563·6365··uditing·of·succe00000470:·7564·6974·696e·6720·6f66·2073·7563·6365··uditing·of·succe
00000480:·7373·6675·6c20·6669·6c65·2063·7265·6174··ssful·file·creat00000480:·7373·6675·6c20·6669·6c65·2061·6363·6573··ssful·file·acces
00000490:·696f·6e73·2028·4141·7263·6836·3429·3c2f··ions·(AArch64)</00000490:·7365·7320·2870·7063·3634·6c65·293c·2f74··ses·(ppc64le)</t
000004a0:·7464·3e0a·2020·2020·2020·3c74·6420·786d··td>.······<td·xm000004a0:·643e·0a20·2020·2020·203c·7464·2078·6d6c··d>.······<td·xml
000004b0:·6c3a·6c61·6e67·3d22·656e·2d55·5322·3e0a··l:lang="en-US">.000004b0:·3a6c·616e·673d·2265·6e2d·5553·223e·0a20··:lang="en-US">.·
000004c0:·2020·2020·2020·2020·456e·7375·7265·2074··········Ensure·t000004c0:·2020·2020·2020·2045·6e73·7572·6520·7468·········Ensure·th
000004d0:·6861·7420·7375·6363·6573·7366·756c·2061··hat·successful·a000004d0:·6174·2073·7563·6365·7373·6675·6c20·6174··at·successful·at
000004e0:·7474·656d·7074·7320·746f·2063·7265·6174··ttempts·to·creat000004e0:·7465·6d70·7473·2074·6f20·6163·6365·7373··tempts·to·access
000004f0:·6520·6120·6669·6c65·2061·7265·2061·7564··e·a·file·are·aud000004f0:·2061·2066·696c·6520·6172·6520·6175·6469···a·file·are·audi
00000500:·6974·6564·2e0a·0a54·6865·2066·6f6c·6c6f··ited...The·follo00000500:·7465·642e·0a0a·5468·6520·666f·6c6c·6f77··ted...The·follow
00000510:·7769·6e67·2072·756c·6573·2063·6f6e·6669··wing·rules·confi00000510:·696e·6720·7275·6c65·7320·636f·6e66·6967··ing·rules·config
00000520:·6775·7265·2061·7564·6974·2061·7320·6465··gure·audit·as·de00000520:·7572·6520·6175·6469·7420·6173·2064·6573··ure·audit·as·des
00000530:·7363·7269·6265·6420·6162·6f76·653a·0a3c··scribed·above:.<00000530:·6372·6962·6564·2061·626f·7665·3a0a·3c70··cribed·above:.<p
00000540:·7072·653e·2323·2053·7563·6365·7373·6675··pre>##·Successfu00000540:·7265·3e23·2320·5375·6363·6573·7366·756c··re>##·Successful
00000550:·6c20·6669·6c65·2063·7265·6174·696f·6e20··l·file·creation·00000550:·2066·696c·6520·6163·6365·7373·2028·616e···file·access·(an
00000560:·286f·7065·6e20·7769·7468·204f·5f43·5245··(open·with·O_CRE00000560:·7920·6f74·6865·7220·6f70·656e·7329·2054··y·other·opens)·T
00000570:·4154·290a·2d61·2061·6c77·6179·732c·6578··AT).-a·always,ex00000570:·6869·7320·6861·7320·746f·2067·6f20·6c61··his·has·to·go·la
00000580:·6974·202d·4620·6172·6368·3d62·3332·202d··it·-F·arch=b32·-00000580:·7374·2e0a·2323·2054·6865·7365·206e·6578··st..##·These·nex
00000590:·5320·6f70·656e·6174·2c6f·7065·6e5f·6279··S·openat,open_by00000590:·7420·7477·6f20·6172·6520·6c69·6b65·6c79··t·two·are·likely
000005a0:·5f68·616e·646c·655f·6174·202d·4620·6132··_handle_at·-F·a2000005a0:·2074·6f20·7265·7375·6c74·2069·6e20·6120···to·result·in·a·
000005b0:·2661·6d70·3b30·3130·3020·2d46·2073·7563··&amp;0100·-F·suc000005b0:·7768·6f6c·6520·6c6f·7420·6f66·2065·7665··whole·lot·of·eve
000005c0:·6365·7373·3d31·202d·4620·6175·6964·3e3d··cess=1·-F·auid>=000005c0:·6e74·730a·2d61·2061·6c77·6179·732c·6578··nts.-a·always,ex
000005d0:·3130·3030·202d·4620·6175·6964·213d·756e··1000·-F·auid!=un000005d0:·6974·202d·4620·6172·6368·3d62·3634·202d··it·-F·arch=b64·-
000005e0:·7365·7420·2d46·206b·6579·3d73·7563·6365··set·-F·key=succe000005e0:·5320·6f70·656e·2c6f·7065·6e61·742c·6f70··S·open,openat,op
000005f0:·7373·6675·6c2d·6372·6561·7465·0a2d·6120··ssful-create.-a·000005f0:·656e·6174·322c·6f70·656e·5f62·795f·6861··enat2,open_by_ha
00000600:·616c·7761·7973·2c65·7869·7420·2d46·2061··always,exit·-F·a00000600:·6e64·6c65·5f61·7420·2d46·2073·7563·6365··ndle_at·-F·succe
00000610:·7263·683d·6236·3420·2d53·206f·7065·6e61··rch=b64·-S·opena00000610:·7373·3d31·202d·4620·6175·6964·3e3d·3130··ss=1·-F·auid>=10
00000620:·742c·6f70·656e·5f62·795f·6861·6e64·6c65··t,open_by_handle00000620:·3030·202d·4620·6175·6964·213d·756e·7365··00·-F·auid!=unse
00000630:·5f61·7420·2d46·2061·3226·616d·703b·3031··_at·-F·a2&amp;0100000630:·7420·2d46·206b·6579·3d73·7563·6365·7373··t·-F·key=success
00000640:·3030·202d·4620·7375·6363·6573·733d·3120··00·-F·success=1·00000640:·6675·6c2d·6163·6365·7373·2020·2020·3c2f··ful-access····</
00000650:·2d46·2061·7569·643e·3d31·3030·3020·2d46··-F·auid>=1000·-F00000650:·7072·653e·0a0a·4c6f·6164·206e·6577·2041··pre>..Load·new·A
00000660:·2061·7569·6421·3d75·6e73·6574·202d·4620···auid!=unset·-F·00000660:·7564·6974·2072·756c·6573·2069·6e74·6f20··udit·rules·into·
00000670:·6b65·793d·7375·6363·6573·7366·756c·2d63··key=successful-c00000670:·6b65·726e·656c·2062·7920·7275·6e6e·696e··kernel·by·runnin
00000680:·7265·6174·650a·2d61·2061·6c77·6179·732c··reate.-a·always,00000680:·673a·0a3c·7072·653e·6175·6765·6e72·756c··g:.<pre>augenrul
00000690:·6578·6974·202d·4620·6172·6368·3d62·3332··exit·-F·arch=b3200000690:·6573·202d·2d6c·6f61·643c·2f70·7265·3e0a··es·--load</pre>.
000006a0:·202d·5320·6f70·656e·202d·4620·6131·2661···-S·open·-F·a1&a000006a0:·0a4e·6f74·653a·2054·6869·7320·7275·6c65··.Note:·This·rule
000006b0:·6d70·3b30·3130·3020·2d46·2073·7563·6365··mp;0100·-F·succe000006b0:·2075·7365·7320·6120·7370·6563·6961·6c20···uses·a·special·
000006c0:·7373·3d31·202d·4620·6175·6964·3e3d·3130··ss=1·-F·auid>=10000006c0:·7365·7420·6f66·2041·7564·6974·2072·756c··set·of·Audit·rul
000006d0:·3030·202d·4620·6175·6964·213d·756e·7365··00·-F·auid!=unse000006d0:·6573·2074·6f20·636f·6d70·6c79·2077·6974··es·to·comply·wit
000006e0:·7420·2d46·206b·6579·3d73·7563·6365·7373··t·-F·key=success000006e0:·6820·4f53·5050·2034·2e32·2e31·2e20·596f··h·OSPP·4.2.1.·Yo
000006f0:·6675·6c2d·6372·6561·7465·0a2d·6120·616c··ful-create.-a·al000006f0:·7520·6d61·7920·7265·7573·6520·7468·6973··u·may·reuse·this
00000700:·7761·7973·2c65·7869·7420·2d46·2061·7263··ways,exit·-F·arc00000700:·2072·756c·6520·696e·2064·6966·6665·7265···rule·in·differe
00000710:·683d·6233·3220·2d53·2063·7265·6174·202d··h=b32·-S·creat·-00000710:·6e74·2070·726f·6669·6c65·732e·2049·6620··nt·profiles.·If·
00000720:·4620·7375·6363·6573·733d·3120·2d46·2061··F·success=1·-F·a00000720:·796f·7520·6465·6369·6465·2074·6f20·646f··you·decide·to·do
00000730:·7569·643e·3d31·3030·3020·2d46·2061·7569··uid>=1000·-F·aui00000730:·2073·6f2c·2069·7420·6973·2072·6563·6f6d···so,·it·is·recom
00000740:·6421·3d75·6e73·6574·202d·4620·6b65·793d··d!=unset·-F·key=00000740:·6d65·6e64·6564·2074·6861·7420·796f·7520··mended·that·you·
00000750:·7375·6363·6573·7366·756c·2d63·7265·6174··successful-creat00000750:·696e·7370·6563·7420·636f·6e74·656e·7473··inspect·contents
00000760:·6520·2020·203c·2f70·7265·3e0a·0a4c·6f61··e····</pre>..Loa00000760:·206f·6620·7468·6520·6669·6c65·2063·6c6f···of·the·file·clo
00000770:·6420·6e65·7720·4175·6469·7420·7275·6c65··d·new·Audit·rule00000770:·7365·6c79·2061·6e64·206d·616b·6520·7375··sely·and·make·su
00000780:·7320·696e·746f·206b·6572·6e65·6c20·6279··s·into·kernel·by00000780:·7265·2074·6861·7420·7468·6579·2061·7265··re·that·they·are
00000790:·2072·756e·6e69·6e67·3a0a·3c70·7265·3e61···running:.<pre>a00000790:·2061·6c6c·6967·6e65·6420·7769·7468·2079···alligned·with·y
000007a0:·7567·656e·7275·6c65·7320·2d2d·6c6f·6164··ugenrules·--load000007a0:·6f75·7220·6e65·6564·732e·0a20·2020·2020··our·needs..·····
000007b0:·3c2f·7072·653e·0a0a·4e6f·7465·3a20·5468··</pre>..Note:·Th000007b0:·203c·2f74·643e·0a20·2020·2020·203c·7464···</td>.······<td
000007c0:·6973·2072·756c·6520·7573·6573·2061·2073··is·rule·uses·a·s000007c0:·2078·6d6c·3a6c·616e·673d·2265·6e2d·5553···xml:lang="en-US
000007d0:·7065·6369·616c·2073·6574·206f·6620·4175··pecial·set·of·Au000007d0:·223e·0a20·2020·2020·2020·2041·7564·6974··">.········Audit
000007e0:·6469·7420·7275·6c65·7320·746f·2063·6f6d··dit·rules·to·com000007e0:·696e·6720·6f66·2073·7563·6365·7373·6675··ing·of·successfu
000007f0:·706c·7920·7769·7468·204f·5350·5020·342e··ply·with·OSPP·4.000007f0:·6c20·6174·7465·6d70·7473·2074·6f20·6163··l·attempts·to·ac
00000800:·322e·312e·2059·6f75·206d·6179·2072·6575··2.1.·You·may·reu00000800:·6365·7373·2061·2066·696c·6520·6865·6c70··cess·a·file·help
00000810:·7365·2074·6869·7320·7275·6c65·2069·6e20··se·this·rule·in·00000810:·7320·696e·2069·6e76·6573·7469·6761·7469··s·in·investigati
00000820:·6469·6666·6572·656e·7420·7072·6f66·696c··different·profil00000820:·6f6e·206f·6620·6163·7469·7669·7469·6573··on·of·activities
00000830:·6573·2e20·4966·2079·6f75·2064·6563·6964··es.·If·you·decid00000830:·2070·6572·666f·726d·6564·206f·6e20·7468···performed·on·th
00000840:·6520·746f·2064·6f20·736f·2c20·6974·2069··e·to·do·so,·it·i00000840:·6520·7379·7374·656d·2e0a·2020·2020·2020··e·system..······
00000850:·7320·7265·636f·6d6d·656e·6465·6420·7468··s·recommended·th00000850:·3c2f·7464·3e0a·2020·2020·3c2f·7472·3e0a··</td>.····</tr>.
00000860:·6174·2079·6f75·2069·6e73·7065·6374·2063··at·you·inspect·c00000860:·2020·2020·3c74·723e·0a20·2020·2020·203c······<tr>.······<
00000870:·6f6e·7465·6e74·7320·6f66·2074·6865·2066··ontents·of·the·f00000870:·7464·3e41·552d·3228·6429·3c62·722f·3e41··td>AU-2(d)<br/>A
00000880:·696c·6520·636c·6f73·656c·7920·616e·6420··ile·closely·and·00000880:·552d·3132·2863·293c·6272·2f3e·4143·2d36··U-12(c)<br/>AC-6
00000890:·6d61·6b65·2073·7572·6520·7468·6174·2074··make·sure·that·t00000890:·2839·293c·6272·2f3e·434d·2d36·2861·293c··(9)<br/>CM-6(a)<
000008a0:·6865·7920·6172·6520·616c·6c69·676e·6564··hey·are·alligned000008a0:·2f74·643e·0a20·2020·2020·203c·7464·3e45··/td>.······<td>E
000008b0:·2077·6974·6820·796f·7572·206e·6565·6473···with·your·needs000008b0:·6e73·7572·6520·6175·6469·7464·2043·6f6c··nsure·auditd·Col
000008c0:·2e0a·2020·2020·2020·3c2f·7464·3e0a·2020··..······</td>.··000008c0:·6c65·6374·7320·496e·666f·726d·6174·696f··lects·Informatio
000008d0:·2020·2020·3c74·6420·786d·6c3a·6c61·6e67······<td·xml:lang000008d0:·6e20·6f6e·204b·6572·6e65·6c20·4d6f·6475··n·on·Kernel·Modu
000008e0:·3d22·656e·2d55·5322·3e0a·2020·2020·2020··="en-US">.······000008e0:·6c65·2055·6e6c·6f61·6469·6e67·202d·2064··le·Unloading·-·d
000008f0:·2020·4175·6469·7469·6e67·206f·6620·7375····Auditing·of·su000008f0:·656c·6574·655f·6d6f·6475·6c65·3c2f·7464··elete_module</td
00000900:·6363·6573·7366·756c·2061·7474·656d·7074··ccessful·attempt00000900:·3e0a·2020·2020·2020·3c74·6420·786d·6c3a··>.······<td·xml:
00000910:·7320·746f·2063·7265·6174·6520·6120·6669··s·to·create·a·fi00000910:·6c61·6e67·3d22·656e·2d55·5322·3e0a·2020··lang="en-US">.··
00000920:·6c65·2068·656c·7073·2069·6e20·696e·7665··le·helps·in·inve00000920:·2020·2020·2020·546f·2063·6170·7475·7265········To·capture
00000930:·7374·6967·6174·696f·6e20·6f66·2061·6374··stigation·of·act00000930:·206b·6572·6e65·6c20·6d6f·6475·6c65·2075···kernel·module·u
00000940:·696f·6e73·2077·6869·6368·2068·6170·7065··ions·which·happe00000940:·6e6c·6f61·6469·6e67·2065·7665·6e74·732c··nloading·events,
00000950:·6e65·6420·6f6e·2074·6865·2073·7973·7465··ned·on·the·syste00000950:·2075·7365·2066·6f6c·6c6f·7769·6e67·206c···use·following·l
00000960:·6d2e·0a20·2020·2020·203c·2f74·643e·0a20··m..······</td>.·00000960:·696e·652c·2073·6574·7469·6e67·2041·5243··ine,·setting·ARC
00000970:·2020·203c·2f74·723e·0a20·2020·203c·7472·····</tr>.····<tr00000970:·4820·746f·0a65·6974·6865·7220·6233·3220··H·to.either·b32·
00000980:·3e0a·2020·2020·2020·3c74·643e·4155·2d32··>.······<td>AU-200000980:·666f·7220·3332·2d62·6974·2073·7973·7465··for·32-bit·syste
00000990:·2861·293c·2f74·643e·0a20·2020·2020·203c··(a)</td>.······<00000990:·6d2c·206f·7220·6861·7669·6e67·2074·776f··m,·or·having·two
000009a0:·7464·3e43·6f6e·6669·6775·7265·2061·7564··td>Configure·aud000009a0:·206c·696e·6573·2066·6f72·2062·6f74·6820···lines·for·both·
000009b0:·6974·696e·6720·6f66·2075·6e73·7563·6365··iting·of·unsucce000009b0:·6233·3220·616e·6420·6236·3420·696e·2063··b32·and·b64·in·c
000009c0:·7373·6675·6c20·6669·6c65·2063·7265·6174··ssful·file·creat000009c0:·6173·6520·796f·7572·2073·7973·7465·6d20··ase·your·system·
000009d0:·696f·6e73·3c2f·7464·3e0a·2020·2020·2020··ions</td>.······000009d0:·6973·2036·342d·6269·743a·0a0a·3c70·7265··is·64-bit:..<pre
000009e0:·3c74·6420·786d·6c3a·6c61·6e67·3d22·656e··<td·xml:lang="en000009e0:·3e2d·6120·616c·7761·7973·2c65·7869·7420··>-a·always,exit·
000009f0:·2d55·5322·3e0a·2020·2020·2020·2020·456e··-US">.········En000009f0:·2d46·2061·7263·683d·3c69·3e41·5243·483c··-F·arch=<i>ARCH<
00000a00:·7375·7265·2074·6861·7420·756e·7375·6363··sure·that·unsucc00000a00:·2f69·3e20·2d53·2064·656c·6574·655f·6d6f··/i>·-S·delete_mo
00000a10:·6573·7366·756c·2061·7474·656d·7074·7320··essful·attempts·00000a10:·6475·6c65·202d·4620·6175·6964·3e3d·3130··dule·-F·auid>=10
00000a20:·746f·2063·7265·6174·6520·6120·6669·6c65··to·create·a·file00000a20:·3030·202d·4620·6175·6964·213d·756e·7365··00·-F·auid!=unse
00000a30:·2061·7265·2061·7564·6974·6564·2e0a·0a54···are·audited...T00000a30:·7420·2d46·206b·6579·3d6d·6f64·756c·6573··t·-F·key=modules
00000a40:·6865·2066·6f6c·6c6f·7769·6e67·2072·756c··he·following·rul00000a40:·3c2f·7072·653e·0a0a·0a50·6c61·6365·2074··</pre>...Place·t
00000a50:·6573·2063·6f6e·6669·6775·7265·2061·7564··es·configure·aud00000a50:·6f20·6164·6420·7468·6520·6c69·6e65·2064··o·add·the·line·d
00000a60:·6974·2061·7320·6465·7363·7269·6265·6420··it·as·described·00000a60:·6570·656e·6473·206f·6e20·6120·7761·7920··epends·on·a·way·
00000a70:·6162·6f76·653a·0a3c·7072·653e·2323·2055··above:.<pre>##·U00000a70:·3c74·743e·6175·6469·7464·3c2f·7474·3e20··<tt>auditd</tt>·
00000a80:·6e73·7563·6365·7373·6675·6c20·6669·6c65··nsuccessful·file00000a80:·6461·656d·6f6e·2069·7320·636f·6e66·6967··daemon·is·config
00000a90:·2063·7265·6174·696f·6e20·286f·7065·6e20···creation·(open·00000a90:·7572·6564·2e20·4966·2069·7420·6973·2063··ured.·If·it·is·c
00000aa0:·7769·7468·204f·5f43·5245·4154·290a·2d61··with·O_CREAT).-a00000aa0:·6f6e·6669·6775·7265·640a·746f·2075·7365··onfigured.to·use
00000ab0:·2061·6c77·6179·732c·6578·6974·202d·4620···always,exit·-F·00000ab0:·2074·6865·203c·7474·3e61·7567·656e·7275···the·<tt>augenru
00000ac0:·6172·6368·3d62·3332·202d·5320·6f70·656e··arch=b32·-S·open00000ac0:·6c65·733c·2f74·743e·2070·726f·6772·616d··les</tt>·program
00000ad0:·6174·2c6f·7065·6e5f·6279·5f68·616e·646c··at,open_by_handl00000ad0:·2028·7468·6520·6465·6661·756c·7429·2c20···(the·default),·
00000ae0:·655f·6174·202d·4620·6132·2661·6d70·3b30··e_at·-F·a2&amp;000000ae0:·6164·6420·7468·6520·6c69·6e65·2074·6f20··add·the·line·to·
00000af0:·3130·3020·2d46·2065·7869·743d·2d45·4143··100·-F·exit=-EAC00000af0:·6120·6669·6c65·2077·6974·6820·7375·6666··a·file·with·suff
00000b00:·4345·5320·2d46·2061·7569·6426·6774·3b3d··CES·-F·auid&gt;=00000b00:·6978·0a3c·7474·3e2e·7275·6c65·733c·2f74··ix.<tt>.rules</t
00000b10:·3130·3030·202d·4620·6175·6964·213d·756e··1000·-F·auid!=un00000b10:·743e·2069·6e20·7468·6520·6469·7265·6374··t>·in·the·direct
00000b20:·7365·7420·2d46·206b·6579·3d75·6e73·7563··set·-F·key=unsuc00000b20:·6f72·7920·3c74·743e·2f65·7463·2f61·7564··ory·<tt>/etc/aud
00000b30:·6365·7373·6675·6c2d·6372·6561·7465·0a2d··cessful-create.-00000b30:·6974·2f72·756c·6573·2e64·3c2f·7474·3e2e··it/rules.d</tt>.
00000b40:·6120·616c·7761·7973·2c65·7869·7420·2d46··a·always,exit·-F00000b40:·0a0a·4966·2074·6865·203c·7474·3e61·7564··..If·the·<tt>aud
00000b50:·2061·7263·683d·6236·3420·2d53·206f·7065···arch=b64·-S·ope00000b50:·6974·643c·2f74·743e·2064·6165·6d6f·6e20··itd</tt>·daemon·
00000b60:·6e61·742c·6f70·656e·5f62·795f·6861·6e64··nat,open_by_hand00000b60:·6973·2063·6f6e·6669·6775·7265·6420·746f··is·configured·to
00000b70:·6c65·5f61·7420·2d46·2061·3226·616d·703b··le_at·-F·a2&amp;00000b70:·2075·7365·2074·6865·203c·7474·3e61·7564···use·the·<tt>aud
00000b80:·3031·3030·202d·4620·6578·6974·3d2d·4541··0100·-F·exit=-EA00000b80:·6974·6374·6c3c·2f74·743e·2075·7469·6c69··itctl</tt>·utili
00000b90:·4343·4553·202d·4620·6175·6964·2667·743b··CCES·-F·auid&gt;00000b90:·7479·2c0a·6164·6420·7468·6520·6c69·6e65··ty,.add·the·line
00000ba0:·3d31·3030·3020·2d46·2061·7569·6421·3d75··=1000·-F·auid!=u00000ba0:·2074·6f20·6669·6c65·203c·7474·3e2f·6574···to·file·<tt>/et
00000bb0:·6e73·6574·202d·4620·6b65·793d·756e·7375··nset·-F·key=unsu00000bb0:·632f·6175·6469·742f·6175·6469·742e·7275··c/audit/audit.ru
00000bc0:·6363·6573·7366·756c·2d63·7265·6174·650a··ccessful-create.00000bc0:·6c65·733c·2f74·743e·2e0a·2020·2020·2020··les</tt>..······
00000bd0:·2d61·2061·6c77·6179·732c·6578·6974·202d··-a·always,exit·-00000bd0:·3c2f·7464·3e0a·2020·2020·2020·3c74·6420··</td>.······<td·
00000be0:·4620·6172·6368·3d62·3332·202d·5320·6f70··F·arch=b32·-S·op00000be0:·786d·6c3a·6c61·6e67·3d22·656e·2d55·5322··xml:lang="en-US"
Max diff block lines reached; 7325985/7527077 bytes (97.33%) of diff not shown.
2.6 MB
html2text {}
    
Offset 1, 30 lines modifiedOffset 1, 97 lines modified
  
  
1 Rules·with·NIST-800-53·Reference·in·Guide·to·the·Secure·Configuration·of·Oracle1 Rules·with·NIST-800-53·Reference·in·Guide·to·the·Secure·Configuration·of·Oracle
2 Linux·72 Linux·7
  
  
3 ·······························Ensure·that·successful·attempts·to·create·a·file·are·audited.·The·following·rules3 ·······························Ensure·that·successful·attempts·to·access·a·file·are·audited.·The·following·rules
4 ·······························configure·audit·as·described·above:4 ·······························configure·audit·as·described·above:
5 ·······························##·Successful·file·creation·(open·with·O_CREAT) 
6 ·······························-a·always,exit·-F·arch=b32·-S·openat,open_by_handle_at·-F·a2&0100·-F·success=1·- 
7 ·······························F·auid>=1000·-F·auid!=unset·-F·key=successful-create5 ·······························##·Successful·file·access·(any·other·opens)·This·has·to·go·last.
 6 ·······························##·These·next·two·are·likely·to·result·in·a·whole·lot·of·events··························Auditing·of·successful
 7 ········Configure·auditing·of··-a·always,exit·-F·arch=b64·-S·open,openat,openat2,open_by_handle_at·-F·success=1·-·······attempts·to·access·a
 8 AU-2(a)·successful·file········F·auid>=1000·-F·auid!=unset·-F·key=successful-access·····································file·helps·in
 9 ········accesses·(ppc64le)·····Load·new·Audit·rules·into·kernel·by·running:·············································investigation·of
 10 ·······························augenrules·--load········································································activities·performed·on
 11 ·······························Note:·This·rule·uses·a·special·set·of·Audit·rules·to·comply·with·OSPP·4.2.1.·You·may·····the·system.
 12 ·······························reuse·this·rule·in·different·profiles.·If·you·decide·to·do·so,·it·is·recommended·that
 13 ·······························you·inspect·contents·of·the·file·closely·and·make·sure·that·they·are·alligned·with·your
 14 ·······························needs.
 15 ························································································································The·removal·of·kernel
 16 ························································································································modules·can·be·used·to
 17 ·······························To·capture·kernel·module·unloading·events,·use·following·line,·setting·ARCH·to·either····alter·the·behavior·of
 18 AU-2(d)························b32·for·32-bit·system,·or·having·two·lines·for·both·b32·and·b64·in·case·your·system·is···the·kernel·and
 19 AU-12···Ensure·auditd·Collects·64-bit:··················································································potentially·introduce
 20 (c)·····Information·on·Kernel··-a·always,exit·-F·arch=ARCH·-S·delete_module·-F·auid>=1000·-F·auid!=unset·-F·key=modules·malicious·code·into
 21 AC-6(9)·Module·Unloading·-·····Place·to·add·the·line·depends·on·a·way·auditd·daemon·is·configured.·If·it·is·configured··kernel·space.·It·is
 22 CM-6(a)·delete_module··········to·use·the·augenrules·program·(the·default),·add·the·line·to·a·file·with·suffix·.rules···important·to·have·an
 23 ·······························in·the·directory·/etc/audit/rules.d.·If·the·auditd·daemon·is·configured·to·use·the·······audit·trail·of·modules
 24 ·······························auditctl·utility,·add·the·line·to·file·/etc/audit/audit.rules.···························that·have·been
 25 ························································································································introduced·into·the
 26 ························································································································kernel.
 27 ·······························Ensure·that·successful·attempts·to·access·a·file·are·audited.·The·following·rules
 28 ·······························configure·audit·as·described·above:
 29 ·······························##·Successful·file·access·(any·other·opens)·This·has·to·go·last.
 30 ·······························##·These·next·two·are·likely·to·result·in·a·whole·lot·of·events
8 ·······························-a·always,exit·-F·arch=b64·-S·openat,open_by_handle_at·-F·a2&0100·-F·success=1·-·········Auditing·of·successful31 ·······························-a·always,exit·-F·arch=b32·-S·open,openat,openat2,open_by_handle_at·-F·success=1·-·······Auditing·of·successful
9 ·······························F·auid>=1000·-F·auid!=unset·-F·key=successful-create·····································attempts·to·create·a32 ········Configure·auditing·of··F·auid>=1000·-F·auid!=unset·-F·key=successful-access·····································attempts·to·access·a
10 ········Configure·auditing·of··-a·always,exit·-F·arch=b32·-S·open·-F·a1&0100·-F·success=1·-F·auid>=1000·-F·auid!=unset··file·helps·in 
11 AU-2(a)·successful·file········-F·key=successful-create·································································investigation·of 
12 ········creations·(AArch64)····-a·always,exit·-F·arch=b32·-S·creat·-F·success=1·-F·auid>=1000·-F·auid!=unset·-··········actions·which·happened33 AU-2(a)·successful·file········-a·always,exit·-F·arch=b64·-S·openat,openat2,open_by_handle_at·-F·success=1·-············file·helps·in
 34 ········accesses·(AArch64)·····F·auid>=1000·-F·auid!=unset·-F·key=successful-access·····································investigation·of
 35 ·······························Load·new·Audit·rules·into·kernel·by·running:·············································activities·performed·on
13 ·······························F·key=successful-create··································································on·the·system.36 ·······························augenrules·--load········································································the·system.
14 ·······························Load·new·Audit·rules·into·kernel·by·running: 
15 ·······························augenrules·--load 
16 ·······························Note:·This·rule·uses·a·special·set·of·Audit·rules·to·comply·with·OSPP·4.2.1.·You·may37 ·······························Note:·This·rule·uses·a·special·set·of·Audit·rules·to·comply·with·OSPP·4.2.1.·You·may
17 ·······························reuse·this·rule·in·different·profiles.·If·you·decide·to·do·so,·it·is·recommended·that38 ·······························reuse·this·rule·in·different·profiles.·If·you·decide·to·do·so,·it·is·recommended·that
18 ·······························you·inspect·contents·of·the·file·closely·and·make·sure·that·they·are·alligned·with·your39 ·······························you·inspect·contents·of·the·file·closely·and·make·sure·that·they·are·alligned·with·your
19 ·······························needs.40 ·······························needs.
 41 ························································································································Misuse·of·privileged
 42 ························································································································functions,·either
 43 ························································································································intentionally·or
 44 ························································································································unintentionally·by
 45 ························································································································authorized·users,·or·by
 46 ························································································································unauthorized·external
 47 ························································································································entities·that·have
 48 ························································································································compromised·system
 49 ························································································································accounts,·is·a·serious
 50 ························································································································and·ongoing·concern·and
 51 ·······························At·a·minimum,·the·audit·system·should·collect·the·execution·of·privileged·commands·for···can·have·significant
 52 ·······························all·users·and·root.·If·the·auditd·daemon·is·configured·to·use·the·augenrules·program·to··adverse·impacts·on
 53 ·······························read·audit·rules·during·daemon·startup·(the·default),·add·a·line·of·the·following·form···organizations.·Auditing
 54 AU-2(d)·Ensure·auditd·Collects·to·a·file·with·suffix·.rules·in·the·directory·/etc/audit/rules.d:························the·use·of·privileged
 55 AU-12···Information·on·the·Use·-a·always,exit·-F·path=/usr/sbin/postdrop·-F·perm=x·-F·auid>=1000·-F·auid!=unset·-·······functions·is·one·way·to
 56 (c)·····of·Privileged·Commands·F·key=privileged·········································································detect·such·misuse·and
 57 AC-6(9)·-·postdrop·············If·the·auditd·daemon·is·configured·to·use·the·auditctl·utility·to·read·audit·rules·······identify·the·risk·from
 58 CM-6(a)························during·daemon·startup,·add·a·line·of·the·following·form·to·/etc/audit/audit.rules:·······insider·and·advanced
 59 ·······························-a·always,exit·-F·path=/usr/sbin/postdrop·-F·perm=x·-F·auid>=1000·-F·auid!=unset·-·······persistent·threats.
 60 ·······························F·key=privileged
 61 ························································································································Privileged·programs·are
 62 ························································································································subject·to·escalation-
 63 ························································································································of-privilege·attacks,
 64 ························································································································which·attempt·to
 65 ························································································································subvert·their·normal
 66 ························································································································role·of·providing·some
 67 ························································································································necessary·but·limited
 68 ························································································································capability.·As·such,
 69 ························································································································motivation·exists·to
 70 ························································································································monitor·these·programs
 71 ························································································································for·unusual·activity.
 72 ·······························The·audit·system·should·collect·unsuccessful·file·deletion·attempts·for·all·users·and
 73 ·······························root.·If·the·auditd·daemon·is·configured·to·use·the·augenrules·program·to·read·audit
 74 ·······························rules·during·daemon·startup·(the·default),·add·the·following·lines·to·a·file·with·suffix
 75 ·······························.rules·in·the·directory·/etc/audit/rules.d.·If·the·auditd·daemon·is·configured·to·use····Unsuccessful·attempts
 76 ·······························the·auditctl·utility·to·read·audit·rules·during·daemon·startup,·add·the·following·lines··to·delete·files·could
 77 AU-2(d)························to·/etc/audit/audit.rules·file.··························································be·an·indicator·of
 78 AU-12···Record·Unsuccessful····-a·always,exit·-F·arch=b32·-S·unlink·-F·exit=-EACCES·-F·auid>=1000·-F·auid!=unset·-······malicious·activity·on·a
 79 (c)·····Delete·Attempts·to·····F·key=unsuccessful-delete································································system.·Auditing·these
 80 CM-6(a)·Files·-·unlink·········-a·always,exit·-F·arch=b32·-S·unlink·-F·exit=-EPERM·-F·auid>=1000·-F·auid!=unset·-·······events·could·serve·as
 81 ·······························F·key=unsuccessful-delete································································evidence·of·potential
 82 ·······························If·the·system·is·64·bit·then·also·add·the·following·lines:·······························system·compromise.
 83 ·······························-a·always,exit·-F·arch=b64·-S·unlink·-F·exit=-EACCES·-F·auid>=1000·-F·auid!=unset·-
 84 ·······························F·key=unsuccessful-delete
 85 ·······························-a·always,exit·-F·arch=b64·-S·unlink·-F·exit=-EPERM·-F·auid>=1000·-F·auid!=unset·-
 86 ·······························F·key=unsuccessful-delete
20 ·······························Ensure·that·unsuccessful·attempts·to·create·a·file·are·audited.·The·following·rules87 ·······························Ensure·that·unsuccessful·attempts·to·create·a·file·are·audited.·The·following·rules
21 ·······························configure·audit·as·described·above:88 ·······························configure·audit·as·described·above:
22 ·······························##·Unsuccessful·file·creation·(open·with·O_CREAT)89 ·······························##·Unsuccessful·file·creation·(open·with·O_CREAT)
23 ·······························-a·always,exit·-F·arch=b32·-S·openat,open_by_handle_at·-F·a2&0100·-F·exit=-EACCES·-90 ·······························-a·always,exit·-F·arch=b32·-S·openat,open_by_handle_at·-F·a2&0100·-F·exit=-EACCES·-
24 ·······························F·auid>=1000·-F·auid!=unset·-F·key=unsuccessful-create91 ·······························F·auid>=1000·-F·auid!=unset·-F·key=unsuccessful-create
25 ·······························-a·always,exit·-F·arch=b64·-S·openat,open_by_handle_at·-F·a2&0100·-F·exit=-EACCES·-92 ·······························-a·always,exit·-F·arch=b64·-S·openat,open_by_handle_at·-F·a2&0100·-F·exit=-EACCES·-
26 ·······························F·auid>=1000·-F·auid!=unset·-F·key=unsuccessful-create93 ·······························F·auid>=1000·-F·auid!=unset·-F·key=unsuccessful-create
Offset 50, 321 lines modifiedOffset 117, 114 lines modified
50 ·······························F·key=unsuccessful-create117 ·······························F·key=unsuccessful-create
51 ·······························Load·new·Audit·rules·into·kernel·by·running:118 ·······························Load·new·Audit·rules·into·kernel·by·running:
52 ·······························augenrules·--load119 ·······························augenrules·--load
53 ·······························Note:·This·rule·uses·a·special·set·of·Audit·rules·to·comply·with·OSPP·4.2.1.·You·may120 ·······························Note:·This·rule·uses·a·special·set·of·Audit·rules·to·comply·with·OSPP·4.2.1.·You·may
54 ·······························reuse·this·rule·in·different·profiles.·If·you·decide·to·do·so,·it·is·recommended·that121 ·······························reuse·this·rule·in·different·profiles.·If·you·decide·to·do·so,·it·is·recommended·that
55 ·······························you·inspect·contents·of·the·file·closely·and·make·sure·that·they·are·alligned·with·your122 ·······························you·inspect·contents·of·the·file·closely·and·make·sure·that·they·are·alligned·with·your
56 ·······························needs.123 ·······························needs.
 124 ·······························Configure·kernel·to·prevent·modification·of·login·UIDs·once·they·are·set.·Changing·login·If·modification·of
 125 ·······························UIDs·while·this·configuration·is·enforced·requires·special·capabilities·which·are·not····login·UIDs·is·not
 126 ········Configure·immutable····available·to·unprivileged·users.·The·following·rules·configure·audit·as·described·above:·prevented,·they·can·be
 127 AU-2(a)·Audit·login·UIDs·······##·Make·the·loginuid·immutable.·This·prevents·tampering·with·the·auid.···················changed·by·unprivileged
 128 ·······························--loginuid-immutable·····································································users·and·make·auditing
 129 ·······························Load·new·Audit·rules·into·kernel·by·running:·············································complicated·or
 130 ·······························augenrules·--load········································································impossible.
57 ························································································································Arbitrary·changes·to 
58 ·······························If·the·auditd·daemon·is·configured·to·use·the·augenrules·program·to·read·audit·rules·····the·system·time·can·be 
59 ·······························during·daemon·startup·(the·default),·add·the·following·line·to·a·file·with·suffix·.rules·used·to·obfuscate 
60 AU-2(d)························in·the·directory·/etc/audit/rules.d:·····················································nefarious·activities·in 
61 AU-12···Record·Attempts·to·····-w·/etc/localtime·-p·wa·-k·audit_time_rules··············································log·files,·as·well·as 
62 (c)·····Alter·the·localtime····If·the·auditd·daemon·is·configured·to·use·the·auditctl·utility·to·read·audit·rules·······to·confuse·network 
63 AC-6(9)·File···················during·daemon·startup,·add·the·following·line·to·/etc/audit/audit.rules·file:············services·that·are 
64 CM-6(a)························-w·/etc/localtime·-p·wa·-k·audit_time_rules··············································highly·dependent·upon 
65 ·······························The·-k·option·allows·for·the·specification·of·a·key·in·string·form·that·can·be·used·for··an·accurate·system·time 
Max diff block lines reached; 2708637/2725040 bytes (99.40%) of diff not shown.
616 KB
./usr/share/doc/ssg-nondebian/table-ol7-ospprefs.html
Ordering differences only
    
Offset 99, 24 lines modifiedOffset 99, 23 lines modified
99 memory·ouf·of·that·node.·The·<tt>page_alloc.shuffle=1</tt>·kernel·command99 memory·ouf·of·that·node.·The·<tt>page_alloc.shuffle=1</tt>·kernel·command
100 line·parameter·then·forces·this·functionality·irrespectively·of·memory·cache100 line·parameter·then·forces·this·functionality·irrespectively·of·memory·cache
101 architecture.101 architecture.
102 ······</td>102 ······</td>
103 ····</tr>103 ····</tr>
104 ····<tr>104 ····<tr>
105 ······<td>AVA_VAN.1</td>105 ······<td>AVA_VAN.1</td>
106 ······<td>Configure·kernel·to·zero·out·memory·before·allocation</td>106 ······<td>Configure·kernel·to·zero·out·memory·before·allocation·in·zIPL</td>
107 ······<td·xml:lang="en-US">107 ······<td·xml:lang="en-US">
 108 ········To·ensure·that·the·kernel·is·configured·to·zero·out·memory·before
 109 allocation,·check·that·all·boot·entries·in
 110 <tt>/boot/loader/entries/*.conf</tt>·have·<tt>init_on_alloc=1</tt>
 111 included·in·its·options.<br·/>
  
 112 To·ensure·that·new·kernels·and·boot·entries·continue·to·zero·out·memory
 113 before·allocation,·add·<tt>init_on_alloc=1</tt>·to·<tt>/etc/kernel/cmdline</tt>.
108 ········To·configure·the·kernel·to·zero·out·memory·before·allocating·it,·add·the 
109 <tt>init_on_alloc=1</tt>·argument·to·the·default·GRUB·2·command·line. 
110 To·ensure·that·<tt>init_on_alloc=1</tt>·is·added·as·a·kernel·command·line 
111 argument·to·newly·installed·kernels,·add·<tt>init_on_alloc=1</tt>·to·the 
112 default·Grub2·command·line·for·Linux·operating·systems.·Modify·the·line·within 
113 <tt>/etc/default/grub</tt>·as·shown·below: 
114 <pre>GRUB_CMDLINE_LINUX="...·init_on_alloc=1·..."</pre> 
115 Run·the·following·command·to·update·command·line·for·already·installed·kernels:<pre>#·grubby·--update-kernel=ALL·--args="init_on_alloc=1"</pre> 
116 ······</td>114 ······</td>
117 ······<td·xml:lang="en-US">115 ······<td·xml:lang="en-US">
118 ········When·the·kernel·configuration·option·<tt>init_on_alloc</tt>·is·enabled,116 ········When·the·kernel·configuration·option·<tt>init_on_alloc</tt>·is·enabled,
119 all·page·allocator·and·slab·allocator·memory·will·be·zeroed·when·allocated,117 all·page·allocator·and·slab·allocator·memory·will·be·zeroed·when·allocated,
120 eliminating·many·kinds·of·"uninitialized·heap·memory"·flaws,·effectively118 eliminating·many·kinds·of·"uninitialized·heap·memory"·flaws,·effectively
121 preventing·data·leaks.119 preventing·data·leaks.
122 ······</td>120 ······</td>
Offset 145, 39 lines modifiedOffset 144, 48 lines modified
145 memory·ouf·of·that·node.·The·<tt>page_alloc.shuffle=1</tt>·kernel·command144 memory·ouf·of·that·node.·The·<tt>page_alloc.shuffle=1</tt>·kernel·command
146 line·parameter·then·forces·this·functionality·irrespectively·of·memory·cache145 line·parameter·then·forces·this·functionality·irrespectively·of·memory·cache
147 architecture.146 architecture.
148 ······</td>147 ······</td>
149 ····</tr>148 ····</tr>
150 ····<tr>149 ····<tr>
151 ······<td>AVA_VAN.1</td>150 ······<td>AVA_VAN.1</td>
152 ······<td>Configure·kernel·to·zero·out·memory·before·allocation·in·zIPL</td>151 ······<td>Configure·kernel·to·zero·out·memory·before·allocation</td>
153 ······<td·xml:lang="en-US">152 ······<td·xml:lang="en-US">
154 ········To·ensure·that·the·kernel·is·configured·to·zero·out·memory·before 
155 allocation,·check·that·all·boot·entries·in 
156 <tt>/boot/loader/entries/*.conf</tt>·have·<tt>init_on_alloc=1</tt> 
157 included·in·its·options.<br·/> 
  
158 To·ensure·that·new·kernels·and·boot·entries·continue·to·zero·out·memory 
159 before·allocation,·add·<tt>init_on_alloc=1</tt>·to·<tt>/etc/kernel/cmdline</tt>.153 ········To·configure·the·kernel·to·zero·out·memory·before·allocating·it,·add·the
 154 <tt>init_on_alloc=1</tt>·argument·to·the·default·GRUB·2·command·line.
 155 To·ensure·that·<tt>init_on_alloc=1</tt>·is·added·as·a·kernel·command·line
 156 argument·to·newly·installed·kernels,·add·<tt>init_on_alloc=1</tt>·to·the
 157 default·Grub2·command·line·for·Linux·operating·systems.·Modify·the·line·within
 158 <tt>/etc/default/grub</tt>·as·shown·below:
 159 <pre>GRUB_CMDLINE_LINUX="...·init_on_alloc=1·..."</pre>
 160 Run·the·following·command·to·update·command·line·for·already·installed·kernels:<pre>#·grubby·--update-kernel=ALL·--args="init_on_alloc=1"</pre>
160 ······</td>161 ······</td>
161 ······<td·xml:lang="en-US">162 ······<td·xml:lang="en-US">
162 ········When·the·kernel·configuration·option·<tt>init_on_alloc</tt>·is·enabled,163 ········When·the·kernel·configuration·option·<tt>init_on_alloc</tt>·is·enabled,
163 all·page·allocator·and·slab·allocator·memory·will·be·zeroed·when·allocated,164 all·page·allocator·and·slab·allocator·memory·will·be·zeroed·when·allocated,
164 eliminating·many·kinds·of·"uninitialized·heap·memory"·flaws,·effectively165 eliminating·many·kinds·of·"uninitialized·heap·memory"·flaws,·effectively
165 preventing·data·leaks.166 preventing·data·leaks.
166 ······</td>167 ······</td>
167 ····</tr>168 ····</tr>
168 ····<tr>169 ····<tr>
169 ······<td>FAU_GEN.1</td>170 ······<td>FAU_GEN.1</td>
170 ······<td>Ensure·the·audit·Subsystem·is·Installed</td>171 ······<td>Enable·Auditing·to·Start·Prior·to·the·Audit·Daemon·in·zIPL</td>
171 ······<td·xml:lang="en-US">172 ······<td·xml:lang="en-US">
172 ········The·audit·package·should·be·installed.173 ········To·ensure·all·processes·can·be·audited,·even·those·which·start·prior·to·the·audit·daemon,
 174 check·that·all·boot·entries·in·<tt>/boot/loader/entries/*.conf</tt>·have·<tt>audit=1</tt>
 175 included·in·its·options.<br·/>
  
 176 To·ensure·that·new·kernels·and·boot·entries·continue·to·enable·audit,
 177 add·<tt>audit=1</tt>·to·<tt>/etc/kernel/cmdline</tt>.
173 ······</td>178 ······</td>
174 ······<td·xml:lang="en-US">179 ······<td·xml:lang="en-US">
175 ········The·auditd·service·is·an·access·monitoring·and·accounting·daemon,·watching·system·calls·to·audit·any·access,·in·comparison·with·potential·local·access·control·policy·such·as·SELinux·policy.180 ········Each·process·on·the·system·carries·an·"auditable"·flag·which·indicates·whether
 181 its·activities·can·be·audited.·Although·<tt>auditd</tt>·takes·care·of·enabling
 182 this·for·all·processes·which·launch·after·it·does,·adding·the·kernel·argument
 183 ensures·it·is·set·for·every·process·during·boot.
176 ······</td>184 ······</td>
177 ····</tr>185 ····</tr>
178 ····<tr>186 ····<tr>
179 ······<td>FAU_GEN.1</td>187 ······<td>FAU_GEN.1</td>
180 ······<td>Configure·auditd·flush·priority</td>188 ······<td>Configure·auditd·flush·priority</td>
181 ······<td·xml:lang="en-US">189 ······<td·xml:lang="en-US">
182 ········The·<tt>auditd</tt>·service·can·be·configured·to190 ········The·<tt>auditd</tt>·service·can·be·configured·to
Offset 190, 28 lines modifiedOffset 198, 14 lines modified
190 ········Audit·data·should·be·synchronously·written·to·disk·to·ensure198 ········Audit·data·should·be·synchronously·written·to·disk·to·ensure
191 log·integrity.·These·parameters·assure·that·all·audit·event·data·is·fully199 log·integrity.·These·parameters·assure·that·all·audit·event·data·is·fully
192 synchronized·with·the·log·files·on·the·disk.200 synchronized·with·the·log·files·on·the·disk.
193 ······</td>201 ······</td>
194 ····</tr>202 ····</tr>
195 ····<tr>203 ····<tr>
196 ······<td>FAU_GEN.1</td>204 ······<td>FAU_GEN.1</td>
197 ······<td>Set·number·of·records·to·cause·an·explicit·flush·to·audit·logs</td> 
198 ······<td·xml:lang="en-US"> 
199 ········To·configure·Audit·daemon·to·issue·an·explicit·flush·to·disk·command 
200 after·writing·<abbr·title="$var_auditd_freq"><tt>50</tt></abbr>·records,·set·<tt>freq</tt>·to·<tt><abbr·title="$var_auditd_freq"><tt>50</tt></abbr></tt> 
201 in·<tt>/etc/audit/auditd.conf</tt>. 
202 ······</td> 
203 ······<td·xml:lang="en-US"> 
204 ········If·option·<tt>freq</tt>·isn't·set·to·<tt><sub·idref="var_auditd_freq"·/></tt>,·the·flush·to·disk 
205 may·happen·after·higher·number·of·records,·increasing·the·danger 
206 of·audit·loss. 
207 ······</td> 
208 ····</tr> 
209 ····<tr> 
210 ······<td>FAU_GEN.1</td> 
211 ······<td>Disable·SSH·Root·Login</td>205 ······<td>Disable·SSH·Root·Login</td>
212 ······<td·xml:lang="en-US">206 ······<td·xml:lang="en-US">
213 ········The·root·user·should·never·be·allowed·to·login·to·a207 ········The·root·user·should·never·be·allowed·to·login·to·a
214 system·directly·over·a·network.208 system·directly·over·a·network.
215 To·disable·root·login·via·SSH,·add·or·correct·the·following·line·in209 To·disable·root·login·via·SSH,·add·or·correct·the·following·line·in
  
  
Offset 225, 31 lines modifiedOffset 219, 52 lines modified
225 In·addition,·logging·in·with·a·user-specific·account·provides·individual219 In·addition,·logging·in·with·a·user-specific·account·provides·individual
226 accountability·of·actions·performed·on·the·system·and·also·helps·to·minimize220 accountability·of·actions·performed·on·the·system·and·also·helps·to·minimize
227 direct·attack·attempts·on·root's·password.221 direct·attack·attempts·on·root's·password.
228 ······</td>222 ······</td>
229 ····</tr>223 ····</tr>
230 ····<tr>224 ····<tr>
231 ······<td>FAU_GEN.1</td>225 ······<td>FAU_GEN.1</td>
232 ······<td>Enable·Auditing·for·Processes·Which·Start·Prior·to·the·Audit·Daemon</td>226 ······<td>Configure·basic·parameters·of·Audit·system</td>
233 ······<td·xml:lang="en-US">227 ······<td·xml:lang="en-US">
234 ········To·ensure·all·processes·can·be·audited,·even·those·which·start 
235 prior·to·the·audit·daemon,·add·the·argument·<tt>audit=1</tt>·to·the·default 
Max diff block lines reached; 226222/233992 bytes (96.68%) of diff not shown.
387 KB
html2text {}
    
Offset 59, 22 lines modifiedOffset 59, 22 lines modified
59 ·························································································································applications·allocating59 ·························································································································applications·allocating
60 ·························································································································memory·ouf·of·that·node.·The60 ·························································································································memory·ouf·of·that·node.·The
61 ·························································································································page_alloc.shuffle=1·kernel61 ·························································································································page_alloc.shuffle=1·kernel
62 ·························································································································command·line·parameter·then62 ·························································································································command·line·parameter·then
63 ·························································································································forces·this·functionality63 ·························································································································forces·this·functionality
64 ·························································································································irrespectively·of·memory64 ·························································································································irrespectively·of·memory
65 ·························································································································cache·architecture.65 ·························································································································cache·architecture.
66 ································To·configure·the·kernel·to·zero·out·memory·before·allocating·it,·add·the·init_on_alloc=1·When·the·kernel·configuration 
67 ································argument·to·the·default·GRUB·2·command·line.·To·ensure·that·init_on_alloc=1·is·added·as··option·init_on_alloc·is 
68 ·················Configure······a·kernel·command·line·argument·to·newly·installed·kernels,·add·init_on_alloc=1·to·the····enabled,·all·page·allocator 
69 ·················kernel·to·zero·default·Grub2·command·line·for·Linux·operating·systems.·Modify·the·line·within·/etc/·····and·slab·allocator·memory66 ·························································································································When·the·kernel·configuration
 67 ·················Configure·······························································································option·init_on_alloc·is
 68 ·················kernel·to·zero·To·ensure·that·the·kernel·is·configured·to·zero·out·memory·before·allocation,·check·that·enabled,·all·page·allocator
 69 ·················out·memory·····all·boot·entries·in·/boot/loader/entries/*.conf·have·init_on_alloc=1·included·in·its·····and·slab·allocator·memory
70 AVA_VAN.1········out·memory·····default/grub·as·shown·below:·····························································will·be·zeroed·when70 AVA_VAN.1········before·········options.·················································································will·be·zeroed·when
71 ·················before·········GRUB_CMDLINE_LINUX="...·init_on_alloc=1·..."·············································allocated,·eliminating·many 
72 ·················allocation·····Run·the·following·command·to·update·command·line·for·already·installed·kernels:··········kinds·of·"uninitialized·heap 
73 ································#·grubby·--update-kernel=ALL·--args="init_on_alloc=1"····································memory"·flaws,·effectively71 ·················allocation·in··To·ensure·that·new·kernels·and·boot·entries·continue·to·zero·out·memory·before···········allocated,·eliminating·many
 72 ·················zIPL···········allocation,·add·init_on_alloc=1·to·/etc/kernel/cmdline.··································kinds·of·"uninitialized·heap
 73 ·························································································································memory"·flaws,·effectively
74 ·························································································································preventing·data·leaks.74 ·························································································································preventing·data·leaks.
75 ·························································································································The75 ·························································································································The
76 ·························································································································CONFIG_SHUFFLE_PAGE_ALLOCATOR76 ·························································································································CONFIG_SHUFFLE_PAGE_ALLOCATOR
77 ·························································································································config·option·is·primarily77 ·························································································································config·option·is·primarily
78 ·························································································································focused·on·improving·the78 ·························································································································focused·on·improving·the
79 ·························································································································average·utilization·of·a79 ·························································································································average·utilization·of·a
80 ·························································································································direct-mapped·memory-side-80 ·························································································································direct-mapped·memory-side-
Offset 93, 68 lines modifiedOffset 93, 78 lines modified
93 ·························································································································applications·allocating93 ·························································································································applications·allocating
94 ·························································································································memory·ouf·of·that·node.·The94 ·························································································································memory·ouf·of·that·node.·The
95 ·························································································································page_alloc.shuffle=1·kernel95 ·························································································································page_alloc.shuffle=1·kernel
96 ·························································································································command·line·parameter·then96 ·························································································································command·line·parameter·then
97 ·························································································································forces·this·functionality97 ·························································································································forces·this·functionality
98 ·························································································································irrespectively·of·memory98 ·························································································································irrespectively·of·memory
99 ·························································································································cache·architecture.99 ·························································································································cache·architecture.
100 ·························································································································When·the·kernel·configuration 
101 ·················Configure·······························································································option·init_on_alloc·is 
102 ·················kernel·to·zero·To·ensure·that·the·kernel·is·configured·to·zero·out·memory·before·allocation,·check·that·enabled,·all·page·allocator 
103 ·················out·memory·····all·boot·entries·in·/boot/loader/entries/*.conf·have·init_on_alloc=1·included·in·its·····and·slab·allocator·memory100 ································To·configure·the·kernel·to·zero·out·memory·before·allocating·it,·add·the·init_on_alloc=1·When·the·kernel·configuration
 101 ································argument·to·the·default·GRUB·2·command·line.·To·ensure·that·init_on_alloc=1·is·added·as··option·init_on_alloc·is
 102 ·················Configure······a·kernel·command·line·argument·to·newly·installed·kernels,·add·init_on_alloc=1·to·the····enabled,·all·page·allocator
 103 ·················kernel·to·zero·default·Grub2·command·line·for·Linux·operating·systems.·Modify·the·line·within·/etc/·····and·slab·allocator·memory
104 AVA_VAN.1········before·········options.·················································································will·be·zeroed·when104 AVA_VAN.1········out·memory·····default/grub·as·shown·below:·····························································will·be·zeroed·when
105 ·················allocation·in··To·ensure·that·new·kernels·and·boot·entries·continue·to·zero·out·memory·before···········allocated,·eliminating·many 
106 ·················zIPL···········allocation,·add·init_on_alloc=1·to·/etc/kernel/cmdline.··································kinds·of·"uninitialized·heap 
107 ·························································································································memory"·flaws,·effectively105 ·················before·········GRUB_CMDLINE_LINUX="...·init_on_alloc=1·..."·············································allocated,·eliminating·many
 106 ·················allocation·····Run·the·following·command·to·update·command·line·for·already·installed·kernels:··········kinds·of·"uninitialized·heap
 107 ································#·grubby·--update-kernel=ALL·--args="init_on_alloc=1"····································memory"·flaws,·effectively
108 ·························································································································preventing·data·leaks.108 ·························································································································preventing·data·leaks.
109 ·························································································································The·auditd·service·is·an 
110 ·························································································································access·monitoring·and109 ·························································································································Each·process·on·the·system
111 ·················Ensure·the······························································································accounting·daemon,·watching 
112 FAU_GEN.1········audit··········The·audit·package·should·be·installed.···················································system·calls·to·audit·any 
113 ·················Subsystem·is····························································································access,·in·comparison·with 
114 ·················Installed·······························································································potential·local·access110 ·························································································································carries·an·"auditable"·flag
 111 ·························································································································which·indicates·whether·its
 112 ·················Enable·········To·ensure·all·processes·can·be·audited,·even·those·which·start·prior·to·the·audit········activities·can·be·audited.
 113 ·················Auditing·to····daemon,·check·that·all·boot·entries·in·/boot/loader/entries/*.conf·have·audit=1·included·Although·auditd·takes·care·of
 114 FAU_GEN.1········Start·Prior·to·in·its·options.··········································································enabling·this·for·all
 115 ·················the·Audit······To·ensure·that·new·kernels·and·boot·entries·continue·to·enable·audit,·add·audit=1·to·/···processes·which·launch·after
 116 ·················Daemon·in·zIPL·etc/kernel/cmdline.······································································it·does,·adding·the·kernel
115 ·························································································································control·policy·such·as117 ·························································································································argument·ensures·it·is·set
 118 ·························································································································for·every·process·during
116 ·························································································································SELinux·policy.119 ·························································································································boot.
117 ·························································································································Audit·data·should·be120 ·························································································································Audit·data·should·be
118 ································The·auditd·service·can·be·configured·to·synchronously·write·audit·event·data·to·disk.····synchronously·written·to·disk121 ································The·auditd·service·can·be·configured·to·synchronously·write·audit·event·data·to·disk.····synchronously·written·to·disk
119 ·················Configure······Add·or·correct·the·following·line·in·/etc/audit/auditd.conf·to·ensure·that·audit·event···to·ensure·log·integrity.122 ·················Configure······Add·or·correct·the·following·line·in·/etc/audit/auditd.conf·to·ensure·that·audit·event···to·ensure·log·integrity.
120 FAU_GEN.1········auditd·flush···data·is·fully·synchronized·with·the·log·files·on·the·disk:·······························These·parameters·assure·that123 FAU_GEN.1········auditd·flush···data·is·fully·synchronized·with·the·log·files·on·the·disk:·······························These·parameters·assure·that
121 ·················priority·······flush·=·data·············································································all·audit·event·data·is·fully124 ·················priority·······flush·=·data·············································································all·audit·event·data·is·fully
122 ·························································································································synchronized·with·the·log125 ·························································································································synchronized·with·the·log
123 ·························································································································files·on·the·disk.126 ·························································································································files·on·the·disk.
124 ·················Set·number·of···························································································If·option·freq·isn't·set·to·, 
125 ·················records·to·····To·configure·Audit·daemon·to·issue·an·explicit·flush·to·disk·command·after·writing·50····the·flush·to·disk·may·happen 
126 FAU_GEN.1········cause·an·······records,·set·freq·to·50·in·/etc/audit/auditd.conf.·······································after·higher·number·of 
127 ·················explicit·flush··························································································records,·increasing·the 
128 ·················to·audit·logs···························································································danger·of·audit·loss. 
129 ·························································································································Even·though·the127 ·························································································································Even·though·the
130 ·························································································································communications·channel·may·be128 ·························································································································communications·channel·may·be
131 ·························································································································encrypted,·an·additional129 ·························································································································encrypted,·an·additional
132 ·························································································································layer·of·security·is·gained130 ·························································································································layer·of·security·is·gained
133 ·························································································································by·extending·the·policy·of131 ·························································································································by·extending·the·policy·of
134 ································The·root·user·should·never·be·allowed·to·login·to·a·system·directly·over·a·network.·To···not·logging·directly·on·as132 ································The·root·user·should·never·be·allowed·to·login·to·a·system·directly·over·a·network.·To···not·logging·directly·on·as
135 FAU_GEN.1········Disable·SSH····disable·root·login·via·SSH,·add·or·correct·the·following·line·in·/etc/ssh/sshd_config:···root.·In·addition,·logging·in133 FAU_GEN.1········Disable·SSH····disable·root·login·via·SSH,·add·or·correct·the·following·line·in·/etc/ssh/sshd_config:···root.·In·addition,·logging·in
136 ·················Root·Login·····PermitRootLogin·no·······································································with·a·user-specific·account134 ·················Root·Login·····PermitRootLogin·no·······································································with·a·user-specific·account
137 ·························································································································provides·individual135 ·························································································································provides·individual
138 ·························································································································accountability·of·actions136 ·························································································································accountability·of·actions
139 ·························································································································performed·on·the·system·and137 ·························································································································performed·on·the·system·and
140 ·························································································································also·helps·to·minimize·direct138 ·························································································································also·helps·to·minimize·direct
141 ·························································································································attack·attempts·on·root's139 ·························································································································attack·attempts·on·root's
142 ·························································································································password.140 ·························································································································password.
 141 ································Perform·basic·configuration·of·Audit·system.·Make·sure·that·any·previously·defined·rules
 142 ································are·cleared,·the·auditing·system·is·configured·to·handle·sudden·bursts·of·events,·and·in
 143 ································cases·of·failure,·messages·are·configured·to·be·directed·to·system·log.·The·following
 144 ································rules·configure·audit·as·described·above:
 145 ································##·First·rule·-·delete·all
 146 ································-D·······················································································Without·basic·configurations,
143 ·························································································································Each·process·on·the·system 
144 ································To·ensure·all·processes·can·be·audited,·even·those·which·start·prior·to·the·audit········carries·an·"auditable"·flag 
145 ·················Enable·········daemon,·add·the·argument·audit=1·to·the·default·GRUB·2·command·line·for·the·Linux········which·indicates·whether·its 
146 ·················Auditing·for···operating·system.·To·ensure·that·audit=1·is·added·as·a·kernel·command·line·argument·to···activities·can·be·audited. 
147 ·················Processes······newly·installed·kernels,·add·audit=1·to·the·default·Grub2·command·line·for·Linux·········Although·auditd·takes·care·of 
148 FAU_GEN.1········Which·Start····operating·systems.·Modify·the·line·within·/etc/default/grub·as·shown·below:··············enabling·this·for·all 
149 ·················Prior·to·the···GRUB_CMDLINE_LINUX="...·audit=1·..."·····················································processes·which·launch·after 
150 ·················Audit·Daemon···Run·the·following·command·to·update·command·line·for·already·installed·kernels:··········it·does,·adding·the·kernel 
151 ································#·grubby·--update-kernel=ALL·--args="audit=1"············································argument·ensures·it·is·set 
152 ·························································································································for·every·process·during 
153 ·························································································································boot.147 ·························································································································audit·may·not·perform·as
 148 ·················Configure······##·Increase·the·buffers·to·survive·stress·events.········································expected.·It·may·not·be·able
 149 FAU_GEN.1········basic··········##·Make·this·bigger·for·busy·systems·····················································to·correctly·handle·events
 150 ·················parameters·of··-b·8192··················································································under·stressful·conditions,
 151 ·················Audit·system····························································································or·log·events·in·case·of
 152 ································##·This·determine·how·long·to·wait·in·burst·of·events····································failure.
 153 ································--backlog_wait_time·60000
  
 154 ································##·Set·failure·mode·to·syslog
 155 ································-f·1
 156 ································Load·new·Audit·rules·into·kernel·by·running:
 157 ································augenrules·--load
 158 ·················Set·number·of···························································································If·option·freq·isn't·set·to·,
 159 ·················records·to·····To·configure·Audit·daemon·to·issue·an·explicit·flush·to·disk·command·after·writing·50····the·flush·to·disk·may·happen
 160 FAU_GEN.1········cause·an·······records,·set·freq·to·50·in·/etc/audit/auditd.conf.·······································after·higher·number·of
 161 ·················explicit·flush··························································································records,·increasing·the
 162 ·················to·audit·logs···························································································danger·of·audit·loss.
154 ·························································································································Without·establishing·what163 ·························································································································Without·establishing·what
155 ·························································································································type·of·events·occurred,·it164 ·························································································································type·of·events·occurred,·it
156 ·························································································································would·be·difficult·to165 ·························································································································would·be·difficult·to
157 ·························································································································establish,·correlate,·and166 ·························································································································establish,·correlate,·and
Max diff block lines reached; 377151/396694 bytes (95.07%) of diff not shown.
789 KB
./usr/share/doc/ssg-nondebian/table-ol7-pcidssrefs.html
Ordering differences only
    
Offset 73, 28 lines modifiedOffset 73, 14 lines modified
73 is·the·only·place·that·loopback·network·traffic·should·be·seen,73 is·the·only·place·that·loopback·network·traffic·should·be·seen,
74 all·other·interfaces·should·ignore·traffic·on·this·network·as·an74 all·other·interfaces·should·ignore·traffic·on·this·network·as·an
75 anti-spoofing·measure.75 anti-spoofing·measure.
76 ······</td>76 ······</td>
77 ····</tr>77 ····</tr>
78 ····<tr>78 ····<tr>
79 ······<td>Req-1.3.1<br/>Req-1.3.2</td>79 ······<td>Req-1.3.1<br/>Req-1.3.2</td>
80 ······<td>Disable·Kernel·Parameter·for·IP·Forwarding·on·IPv4·Interfaces</td> 
81 ······<td·xml:lang="en-US"> 
82 ········To·set·the·runtime·status·of·the·<code>net.ipv4.ip_forward</code>·kernel·parameter,·run·the·following·command:·<pre>$·sudo·sysctl·-w·net.ipv4.ip_forward=0</pre> 
83 To·make·sure·that·the·setting·is·persistent,·add·the·following·line·to·a·file·in·the·directory·<tt>/etc/sysctl.d</tt>:·<pre>net.ipv4.ip_forward·=·0</pre> 
84 ······</td> 
85 ······<td·xml:lang="en-US"> 
86 ········Routing·protocol·daemons·are·typically·used·on·routers·to·exchange 
87 network·topology·information·with·other·routers.·If·this·capability·is·used·when 
88 not·required,·system·network·information·may·be·unnecessarily·transmitted·across 
89 the·network. 
90 ······</td> 
91 ····</tr> 
92 ····<tr> 
93 ······<td>Req-1.3.1<br/>Req-1.3.2</td> 
94 ······<td>Ensure·IPv6·is·disabled·through·kernel·boot·parameter</td>80 ······<td>Ensure·IPv6·is·disabled·through·kernel·boot·parameter</td>
95 ······<td·xml:lang="en-US">81 ······<td·xml:lang="en-US">
96 ········To·disable·IPv6·protocol·support·in·the·Linux·kernel,82 ········To·disable·IPv6·protocol·support·in·the·Linux·kernel,
97 add·the·argument·<tt>ipv6.disable=1</tt>·to·the·default83 add·the·argument·<tt>ipv6.disable=1</tt>·to·the·default
98 GRUB2·command·line·for·the·Linux·operating·system.84 GRUB2·command·line·for·the·Linux·operating·system.
99 To·ensure·that·<tt>ipv6.disable=1</tt>·is·added·as·a·kernel·command·line85 To·ensure·that·<tt>ipv6.disable=1</tt>·is·added·as·a·kernel·command·line
100 argument·to·newly·installed·kernels,·add·<tt>ipv6.disable=1</tt>·to·the86 argument·to·newly·installed·kernels,·add·<tt>ipv6.disable=1</tt>·to·the
Offset 105, 14 lines modifiedOffset 91, 28 lines modified
105 ······</td>91 ······</td>
106 ······<td·xml:lang="en-US">92 ······<td·xml:lang="en-US">
107 ········Any·unnecessary·network·stacks,·including·IPv6,·should·be·disabled·to·reduce93 ········Any·unnecessary·network·stacks,·including·IPv6,·should·be·disabled·to·reduce
108 the·vulnerability·to·exploitation.94 the·vulnerability·to·exploitation.
109 ······</td>95 ······</td>
110 ····</tr>96 ····</tr>
111 ····<tr>97 ····<tr>
 98 ······<td>Req-1.3.1<br/>Req-1.3.2</td>
 99 ······<td>Disable·Kernel·Parameter·for·IP·Forwarding·on·IPv4·Interfaces</td>
 100 ······<td·xml:lang="en-US">
 101 ········To·set·the·runtime·status·of·the·<code>net.ipv4.ip_forward</code>·kernel·parameter,·run·the·following·command:·<pre>$·sudo·sysctl·-w·net.ipv4.ip_forward=0</pre>
 102 To·make·sure·that·the·setting·is·persistent,·add·the·following·line·to·a·file·in·the·directory·<tt>/etc/sysctl.d</tt>:·<pre>net.ipv4.ip_forward·=·0</pre>
 103 ······</td>
 104 ······<td·xml:lang="en-US">
 105 ········Routing·protocol·daemons·are·typically·used·on·routers·to·exchange
 106 network·topology·information·with·other·routers.·If·this·capability·is·used·when
 107 not·required,·system·network·information·may·be·unnecessarily·transmitted·across
 108 the·network.
 109 ······</td>
 110 ····</tr>
 111 ····<tr>
112 ······<td>Req-1.3.3</td>112 ······<td>Req-1.3.3</td>
113 ······<td>Deactivate·Wireless·Network·Interfaces</td>113 ······<td>Deactivate·Wireless·Network·Interfaces</td>
114 ······<td·xml:lang="en-US">114 ······<td·xml:lang="en-US">
115 ········Deactivating·wireless·network·interfaces·should·prevent·normal·usage·of·the·wireless115 ········Deactivating·wireless·network·interfaces·should·prevent·normal·usage·of·the·wireless
116 capability.116 capability.
117 <br·/><br·/>117 <br·/><br·/>
  
Offset 246, 41 lines modifiedOffset 246, 25 lines modified
246 ······<td·xml:lang="en-US">246 ······<td·xml:lang="en-US">
247 ········Disabling·DCCP·protects247 ········Disabling·DCCP·protects
248 the·system·against·exploitation·of·any·flaws·in·its·implementation.248 the·system·against·exploitation·of·any·flaws·in·its·implementation.
249 ······</td>249 ······</td>
250 ····</tr>250 ····</tr>
251 ····<tr>251 ····<tr>
252 ······<td>Req-1.4.3</td>252 ······<td>Req-1.4.3</td>
 253 ······<td>Enable·Kernel·Parameter·to·Ignore·ICMP·Broadcast·Echo·Requests·on·IPv4·Interfaces</td>
253 ······<td>Disable·Kernel·Parameter·for·Accepting·ICMP·Redirects·by·Default·on·IPv4·Interfaces</td> 
254 ······<td·xml:lang="en-US"> 
255 ········To·set·the·runtime·status·of·the·<code>net.ipv4.conf.default.accept_redirects</code>·kernel·parameter,·run·the·following·command:·<pre>$·sudo·sysctl·-w·net.ipv4.conf.default.accept_redirects=0</pre> 
256 To·make·sure·that·the·setting·is·persistent,·add·the·following·line·to·a·file·in·the·directory·<tt>/etc/sysctl.d</tt>:·<pre>net.ipv4.conf.default.accept_redirects·=·0</pre> 
257 ······</td> 
258 ······<td·xml:lang="en-US"> 
259 ········ICMP·redirect·messages·are·used·by·routers·to·inform·hosts·that·a·more 
260 direct·route·exists·for·a·particular·destination.·These·messages·modify·the 
261 host's·route·table·and·are·unauthenticated.·An·illicit·ICMP·redirect 
262 message·could·result·in·a·man-in-the-middle·attack. 
263 <br·/>This·feature·of·the·IPv4·protocol·has·few·legitimate·uses.·It·should 
264 be·disabled·unless·absolutely·required. 
265 ······</td> 
266 ····</tr> 
267 ····<tr> 
268 ······<td>Req-1.4.3</td> 
269 ······<td>Enable·Kernel·Parameter·to·Use·Reverse·Path·Filtering·on·all·IPv4·Interfaces</td> 
270 ······<td·xml:lang="en-US">254 ······<td·xml:lang="en-US">
271 ········To·set·the·runtime·status·of·the·<code>net.ipv4.conf.all.rp_filter</code>·kernel·parameter,·run·the·following·command:·<pre>$·sudo·sysctl·-w·net.ipv4.conf.all.rp_filter=1</pre>255 ········To·set·the·runtime·status·of·the·<code>net.ipv4.icmp_echo_ignore_broadcasts</code>·kernel·parameter,·run·the·following·command:·<pre>$·sudo·sysctl·-w·net.ipv4.icmp_echo_ignore_broadcasts=1</pre>
272 To·make·sure·that·the·setting·is·persistent,·add·the·following·line·to·a·file·in·the·directory·<tt>/etc/sysctl.d</tt>:·<pre>net.ipv4.conf.all.rp_filter·=·1</pre>256 To·make·sure·that·the·setting·is·persistent,·add·the·following·line·to·a·file·in·the·directory·<tt>/etc/sysctl.d</tt>:·<pre>net.ipv4.icmp_echo_ignore_broadcasts·=·1</pre>
273 ······</td>257 ······</td>
274 ······<td·xml:lang="en-US">258 ······<td·xml:lang="en-US">
275 ········Enabling·reverse·path·filtering·drops·packets·with·source·addresses 
276 that·should·not·have·been·able·to·be·received·on·the·interface·they·were 
277 received·on.·It·should·not·be·used·on·systems·which·are·routers·for 
278 complicated·networks,·but·is·helpful·for·end·hosts·and·routers·serving·small 
279 networks.259 ········Responding·to·broadcast·(ICMP)·echoes·facilitates·network·mapping
 260 and·provides·a·vector·for·amplification·attacks.
 261 <br·/>
 262 Ignoring·ICMP·echo·requests·(pings)·sent·to·broadcast·or·multicast
 263 addresses·makes·the·system·slightly·more·difficult·to·enumerate·on·the·network.
280 ······</td>264 ······</td>
281 ····</tr>265 ····</tr>
282 ····<tr>266 ····<tr>
283 ······<td>Req-1.4.3</td>267 ······<td>Req-1.4.3</td>
284 ······<td>Disable·Kernel·Parameter·for·Accepting·Source-Routed·Packets·on·IPv6·Interfaces·by·Default</td>268 ······<td>Disable·Kernel·Parameter·for·Accepting·Source-Routed·Packets·on·IPv6·Interfaces·by·Default</td>
285 ······<td·xml:lang="en-US">269 ······<td·xml:lang="en-US">
286 ········To·set·the·runtime·status·of·the·<code>net.ipv6.conf.default.accept_source_route</code>·kernel·parameter,·run·the·following·command:·<pre>$·sudo·sysctl·-w·net.ipv6.conf.default.accept_source_route=0</pre>270 ········To·set·the·runtime·status·of·the·<code>net.ipv6.conf.default.accept_source_route</code>·kernel·parameter,·run·the·following·command:·<pre>$·sudo·sysctl·-w·net.ipv6.conf.default.accept_source_route=0</pre>
Offset 295, 37 lines modifiedOffset 279, 41 lines modified
  
295 Accepting·source-routed·packets·in·the·IPv6·protocol·has·few·legitimate279 Accepting·source-routed·packets·in·the·IPv6·protocol·has·few·legitimate
296 uses.·It·should·be·disabled·unless·it·is·absolutely·required.280 uses.·It·should·be·disabled·unless·it·is·absolutely·required.
297 ······</td>281 ······</td>
298 ····</tr>282 ····</tr>
299 ····<tr>283 ····<tr>
300 ······<td>Req-1.4.3</td>284 ······<td>Req-1.4.3</td>
301 ······<td>Enable·Kernel·Parameter·to·Ignore·Bogus·ICMP·Error·Responses·on·IPv4·Interfaces</td>285 ······<td>Disable·Kernel·Parameter·for·Accepting·ICMP·Redirects·by·Default·on·IPv4·Interfaces</td>
302 ······<td·xml:lang="en-US">286 ······<td·xml:lang="en-US">
303 ········To·set·the·runtime·status·of·the·<code>net.ipv4.icmp_ignore_bogus_error_responses</code>·kernel·parameter,·run·the·following·command:·<pre>$·sudo·sysctl·-w·net.ipv4.icmp_ignore_bogus_error_responses=1</pre>287 ········To·set·the·runtime·status·of·the·<code>net.ipv4.conf.default.accept_redirects</code>·kernel·parameter,·run·the·following·command:·<pre>$·sudo·sysctl·-w·net.ipv4.conf.default.accept_redirects=0</pre>
304 To·make·sure·that·the·setting·is·persistent,·add·the·following·line·to·a·file·in·the·directory·<tt>/etc/sysctl.d</tt>:·<pre>net.ipv4.icmp_ignore_bogus_error_responses·=·1</pre>288 To·make·sure·that·the·setting·is·persistent,·add·the·following·line·to·a·file·in·the·directory·<tt>/etc/sysctl.d</tt>:·<pre>net.ipv4.conf.default.accept_redirects·=·0</pre>
305 ······</td>289 ······</td>
306 ······<td·xml:lang="en-US">290 ······<td·xml:lang="en-US">
307 ········Ignoring·bogus·ICMP·error·responses·reduces 
308 log·size,·although·some·activity·would·not·be·logged.291 ········ICMP·redirect·messages·are·used·by·routers·to·inform·hosts·that·a·more
 292 direct·route·exists·for·a·particular·destination.·These·messages·modify·the
 293 host's·route·table·and·are·unauthenticated.·An·illicit·ICMP·redirect
 294 message·could·result·in·a·man-in-the-middle·attack.
 295 <br·/>This·feature·of·the·IPv4·protocol·has·few·legitimate·uses.·It·should
 296 be·disabled·unless·absolutely·required.
309 ······</td>297 ······</td>
310 ····</tr>298 ····</tr>
Max diff block lines reached; 300724/308460 bytes (97.49%) of diff not shown.
488 KB
html2text {}
    
Offset 34, 14 lines modifiedOffset 34, 26 lines modified
34 ····················································································network·traffic34 ····················································································network·traffic
35 ····················································································should·be·seen,·all35 ····················································································should·be·seen,·all
36 ····················································································other·interfaces36 ····················································································other·interfaces
37 ····················································································should·ignore37 ····················································································should·ignore
38 ····················································································traffic·on·this38 ····················································································traffic·on·this
39 ····················································································network·as·an·anti-39 ····················································································network·as·an·anti-
40 ····················································································spoofing·measure.40 ····················································································spoofing·measure.
 41 ·····························To·disable·IPv6·protocol·support·in·the·Linux·kernel,
 42 ·····························add·the·argument·ipv6.disable=1·to·the·default·GRUB2
 43 ·····························command·line·for·the·Linux·operating·system.·To·ensure·Any·unnecessary
 44 ·····························that·ipv6.disable=1·is·added·as·a·kernel·command·line··network·stacks,
 45 Req-·····Ensure·IPv6·is······argument·to·newly·installed·kernels,·add···············including·IPv6,
 46 1.3.1····disabled·through····ipv6.disable=1·to·the·default·Grub2·command·line·for···should·be·disabled
 47 Req-·····kernel·boot·········Linux·operating·systems.·Modify·the·line·within·/etc/··to·reduce·the
 48 1.3.2····parameter···········default/grub·as·shown·below:···························vulnerability·to
 49 ·····························GRUB_CMDLINE_LINUX="...·ipv6.disable=1·..."············exploitation.
 50 ·····························Run·the·following·command·to·update·command·line·for
 51 ·····························already·installed·kernels:
 52 ·····························#·grubby·--update-kernel=ALL·--args="ipv6.disable=1"
41 ····················································································Routing·protocol53 ····················································································Routing·protocol
42 ····················································································daemons·are54 ····················································································daemons·are
43 ····················································································typically·used·on55 ····················································································typically·used·on
44 ····················································································routers·to·exchange56 ····················································································routers·to·exchange
45 ·····························To·set·the·runtime·status·of·the·net.ipv4.ip_forward···network·topology57 ·····························To·set·the·runtime·status·of·the·net.ipv4.ip_forward···network·topology
46 Req-·····Disable·Kernel······kernel·parameter,·run·the·following·command:···········information·with58 Req-·····Disable·Kernel······kernel·parameter,·run·the·following·command:···········information·with
47 1.3.1····Parameter·for·IP····$·sudo·sysctl·-w·net.ipv4.ip_forward=0·················other·routers.·If59 1.3.1····Parameter·for·IP····$·sudo·sysctl·-w·net.ipv4.ip_forward=0·················other·routers.·If
Offset 49, 26 lines modifiedOffset 61, 14 lines modified
49 1.3.2····Interfaces··········following·line·to·a·file·in·the·directory·/etc/········used·when·not61 1.3.2····Interfaces··········following·line·to·a·file·in·the·directory·/etc/········used·when·not
50 ·····························sysctl.d:··············································required,·system62 ·····························sysctl.d:··············································required,·system
51 ·····························net.ipv4.ip_forward·=·0································network·information63 ·····························net.ipv4.ip_forward·=·0································network·information
52 ····················································································may·be64 ····················································································may·be
53 ····················································································unnecessarily65 ····················································································unnecessarily
54 ····················································································transmitted·across66 ····················································································transmitted·across
55 ····················································································the·network.67 ····················································································the·network.
56 ·····························To·disable·IPv6·protocol·support·in·the·Linux·kernel, 
57 ·····························add·the·argument·ipv6.disable=1·to·the·default·GRUB2 
58 ·····························command·line·for·the·Linux·operating·system.·To·ensure·Any·unnecessary 
59 ·····························that·ipv6.disable=1·is·added·as·a·kernel·command·line··network·stacks, 
60 Req-·····Ensure·IPv6·is······argument·to·newly·installed·kernels,·add···············including·IPv6, 
61 1.3.1····disabled·through····ipv6.disable=1·to·the·default·Grub2·command·line·for···should·be·disabled 
62 Req-·····kernel·boot·········Linux·operating·systems.·Modify·the·line·within·/etc/··to·reduce·the 
63 1.3.2····parameter···········default/grub·as·shown·below:···························vulnerability·to 
64 ·····························GRUB_CMDLINE_LINUX="...·ipv6.disable=1·..."············exploitation. 
65 ·····························Run·the·following·command·to·update·command·line·for 
66 ·····························already·installed·kernels: 
67 ·····························#·grubby·--update-kernel=ALL·--args="ipv6.disable=1" 
68 ····················································································The·use·of·wireless68 ····················································································The·use·of·wireless
69 ····················································································networking·can69 ····················································································networking·can
70 ····················································································introduce·many70 ····················································································introduce·many
71 ····················································································different·attack71 ····················································································different·attack
72 ····················································································vectors·into·the72 ····················································································vectors·into·the
73 ····················································································organization's73 ····················································································organization's
74 ····················································································network.·Common74 ····················································································network.·Common
Offset 187, 14 lines modifiedOffset 187, 61 lines modified
187 Req-·····Disable·DCCP········being·loaded,·add·the·following·line·to·the·file·/etc/·against187 Req-·····Disable·DCCP········being·loaded,·add·the·following·line·to·the·file·/etc/·against
188 1.4.2····Support·············modprobe.d/dccp.conf:··································exploitation·of·any188 1.4.2····Support·············modprobe.d/dccp.conf:··································exploitation·of·any
189 ·····························install·dccp·/bin/false································flaws·in·its189 ·····························install·dccp·/bin/false································flaws·in·its
190 ·····························To·configure·the·system·to·prevent·the·dccp·from·being·implementation.190 ·····························To·configure·the·system·to·prevent·the·dccp·from·being·implementation.
191 ·····························used,·add·the·following·line·to·file·/etc/modprobe.d/191 ·····························used,·add·the·following·line·to·file·/etc/modprobe.d/
192 ·····························dccp.conf:192 ·····························dccp.conf:
193 ·····························blacklist·dccp193 ·····························blacklist·dccp
 194 ····················································································Responding·to
 195 ····················································································broadcast·(ICMP)
 196 ····················································································echoes·facilitates
 197 ·····························To·set·the·runtime·status·of·the·······················network·mapping·and
 198 ·····························net.ipv4.icmp_echo_ignore_broadcasts·kernel·parameter,·provides·a·vector
 199 ·········Enable·Kernel·······run·the·following·command:·····························for·amplification
 200 ·········Parameter·to·Ignore·$·sudo·sysctl·-········································attacks.
 201 Req-·····ICMP·Broadcast·Echo·w·net.ipv4.icmp_echo_ignore_broadcasts=1···············Ignoring·ICMP·echo
 202 1.4.3····Requests·on·IPv4····To·make·sure·that·the·setting·is·persistent,·add·the···requests·(pings)
 203 ·········Interfaces··········following·line·to·a·file·in·the·directory·/etc/········sent·to·broadcast
 204 ·····························sysctl.d:··············································or·multicast
 205 ·····························net.ipv4.icmp_echo_ignore_broadcasts·=·1···············addresses·makes·the
 206 ····················································································system·slightly
 207 ····················································································more·difficult·to
 208 ····················································································enumerate·on·the
 209 ····················································································network.
 210 ····················································································Source-routed
 211 ····················································································packets·allow·the
 212 ····················································································source·of·the
 213 ····················································································packet·to·suggest
 214 ····················································································routers·forward·the
 215 ····················································································packet·along·a
 216 ····················································································different·path·than
 217 ····················································································configured·on·the
 218 ····················································································router,·which·can
 219 ····················································································be·used·to·bypass
 220 ····················································································network·security
 221 ·····························To·set·the·runtime·status·of·the·······················measures.·This
 222 ·········Disable·Kernel······net.ipv6.conf.default.accept_source_route·kernel·······requirement·applies
 223 ·········Parameter·for·······parameter,·run·the·following·command:··················only·to·the
 224 Req-·····Accepting·Source-···$·sudo·sysctl·-········································forwarding·of
 225 1.4.3····Routed·Packets·on···w·net.ipv6.conf.default.accept_source_route=0··········source-routerd
 226 ·········IPv6·Interfaces·by··To·make·sure·that·the·setting·is·persistent,·add·the···traffic,·such·as
 227 ·········Default·············following·line·to·a·file·in·the·directory·/etc/········when·IPv6
 228 ·····························sysctl.d:··············································forwarding·is
 229 ·····························net.ipv6.conf.default.accept_source_route·=·0··········enabled·and·the
 230 ····················································································system·is
 231 ····················································································functioning·as·a
 232 ····················································································router.·Accepting
 233 ····················································································source-routed
 234 ····················································································packets·in·the·IPv6
 235 ····················································································protocol·has·few
 236 ····················································································legitimate·uses.·It
 237 ····················································································should·be·disabled
 238 ····················································································unless·it·is
 239 ····················································································absolutely
 240 ····················································································required.
194 ····················································································ICMP·redirect241 ····················································································ICMP·redirect
195 ····················································································messages·are·used242 ····················································································messages·are·used
196 ····················································································by·routers·to243 ····················································································by·routers·to
197 ····················································································inform·hosts·that·a244 ····················································································inform·hosts·that·a
198 ····················································································more·direct·route245 ····················································································more·direct·route
199 ····················································································exists·for·a246 ····················································································exists·for·a
200 ····················································································particular247 ····················································································particular
Offset 229, 110 lines modifiedOffset 276, 63 lines modified
229 ·····························sysctl.d:··············································are·routers·for276 ·····························sysctl.d:··············································are·routers·for
230 ·····························net.ipv4.conf.all.rp_filter·=·1························complicated277 ·····························net.ipv4.conf.all.rp_filter·=·1························complicated
231 ····················································································networks,·but·is278 ····················································································networks,·but·is
232 ····················································································helpful·for·end279 ····················································································helpful·for·end
233 ····················································································hosts·and·routers280 ····················································································hosts·and·routers
234 ····················································································serving·small281 ····················································································serving·small
235 ····················································································networks.282 ····················································································networks.
236 ····················································································Source-routed 
237 ····················································································packets·allow·the 
238 ····················································································source·of·the 
239 ····················································································packet·to·suggest 
Max diff block lines reached; 481715/499191 bytes (96.50%) of diff not shown.
3.61 MB
./usr/share/doc/ssg-nondebian/table-ol8-anssirefs.html
    
Offset 63, 274 lines modifiedOffset 63, 274 lines modified
000003e0:·2054·6974·6c65·3c2f·7468·3e0a·2020·2020···Title</th>.····000003e0:·2054·6974·6c65·3c2f·7468·3e0a·2020·2020···Title</th>.····
000003f0:·3c74·683e·4465·7363·7269·7074·696f·6e3c··<th>Description<000003f0:·3c74·683e·4465·7363·7269·7074·696f·6e3c··<th>Description<
00000400:·2f74·683e·0a20·2020·203c·7468·3e52·6174··/th>.····<th>Rat00000400:·2f74·683e·0a20·2020·203c·7468·3e52·6174··/th>.····<th>Rat
00000410:·696f·6e61·6c65·3c2f·7468·3e0a·2020·3c2f··ionale</th>.··</00000410:·696f·6e61·6c65·3c2f·7468·3e0a·2020·3c2f··ionale</th>.··</
00000420:·7468·6561·643e·0a20·203c·7462·6f64·793e··thead>.··<tbody>00000420:·7468·6561·643e·0a20·203c·7462·6f64·793e··thead>.··<tbody>
00000430:·0a20·203c·7472·3e0a·2020·2020·2020·3c74··.··<tr>.······<t00000430:·0a20·203c·7472·3e0a·2020·2020·2020·3c74··.··<tr>.······<t
00000440:·643e·5231·3c2f·7464·3e0a·2020·2020·2020··d>R1</td>.······00000440:·643e·5231·3c2f·7464·3e0a·2020·2020·2020··d>R1</td>.······
00000450:·3c74·643e·496e·7374·616c·6c20·7468·6520··<td>Install·the· 
00000460:·6472·6163·7574·2d66·6970·732d·6165·736e··dracut-fips-aesn 
00000470:·6920·5061·636b·6167·653c·2f74·643e·0a20··i·Package</td>.· 
00000480:·2020·2020·203c·7464·2078·6d6c·3a6c·616e·······<td·xml:lan00000450:·3c74·643e·5072·6566·6572·2074·6f20·7573··<td>Prefer·to·us
 00000460:·6520·6120·3634·2d62·6974·204f·7065·7261··e·a·64-bit·Opera
 00000470:·7469·6e67·2053·7973·7465·6d20·7768·656e··ting·System·when
 00000480:·2073·7570·706f·7274·6564·3c2f·7464·3e0a···supported</td>.
 00000490:·2020·2020·2020·3c74·6420·786d·6c3a·6c61········<td·xml:la
00000490:·673d·2265·6e2d·5553·223e·0a20·2020·2020··g="en-US">.·····000004a0:·6e67·3d22·656e·2d55·5322·3e0a·2020·2020··ng="en-US">.····
 000004b0:·2020·2020·5072·6566·6572·2069·6e73·7461······Prefer·insta
 000004c0:·6c6c·6174·696f·6e20·6f66·2036·342d·6269··llation·of·64-bi
 000004d0:·7420·6f70·6572·6174·696e·6720·7379·7374··t·operating·syst
 000004e0:·656d·7320·7768·656e·2074·6865·2043·5055··ems·when·the·CPU
 000004f0:·2073·7570·706f·7274·7320·6974·2e0a·2020···supports·it..··
000004a0:·2020·2054·6f20·656e·6162·6c65·2046·4950·····To·enable·FIP 
000004b0:·5320·6f6e·2073·7973·7465·6d20·7468·6174··S·on·system·that 
000004c0:·2073·7570·706f·7274·2074·6865·2041·6476···support·the·Adv 
000004d0:·616e·6365·6420·456e·6372·7970·7469·6f6e··anced·Encryption 
000004e0:·2053·7461·6e64·6172·6420·2841·4553·2920···Standard·(AES)· 
000004f0:·6f72·204e·6577·0a49·6e73·7472·7563·7469··or·New.Instructi 
00000500:·6f6e·7320·2841·4553·2d4e·4929·2065·6e67··ons·(AES-NI)·eng 
00000510:·696e·652c·2074·6865·2073·7973·7465·6d20··ine,·the·system· 
00000520:·7265·7175·6972·6573·2074·6861·7420·7468··requires·that·th 
00000530:·6520·3c74·743e·6472·6163·7574·2d66·6970··e·<tt>dracut-fip 
00000540:·732d·6165·736e·693c·2f74·743e·0a70·6163··s-aesni</tt>.pac 
00000550:·6b61·6765·2062·6520·696e·7374·616c·6c65··kage·be·installe 
00000560:·642e·0a54·6865·203c·636f·6465·3e64·7261··d..The·<code>dra 
00000570:·6375·742d·6669·7073·2d61·6573·6e69·3c2f··cut-fips-aesni</ 
00000580:·636f·6465·3e20·7061·636b·6167·6520·6361··code>·package·ca 
00000590:·6e20·6265·2069·6e73·7461·6c6c·6564·2077··n·be·installed·w 
000005a0:·6974·6820·7468·6520·666f·6c6c·6f77·696e··ith·the·followin 
000005b0:·6720·636f·6d6d·616e·643a·0a3c·7072·653e··g·command:.<pre> 
000005c0:·0a24·2073·7564·6f20·7975·6d20·696e·7374··.$·sudo·yum·inst 
000005d0:·616c·6c20·6472·6163·7574·2d66·6970·732d··all·dracut-fips- 
000005e0:·6165·736e·693c·2f70·7265·3e0a·2020·2020··aesni</pre>.···· 
000005f0:·2020·3c2f·7464·3e0a·2020·2020·2020·3c74····</td>.······<t00000500:·2020·2020·3c2f·7464·3e0a·2020·2020·2020······</td>.······
00000600:·6420·786d·6c3a·6c61·6e67·3d22·656e·2d55··d·xml:lang="en-U00000510:·3c74·6420·786d·6c3a·6c61·6e67·3d22·656e··<td·xml:lang="en
00000610:·5322·3e0a·2020·2020·2020·2020·5573·6520··S">.········Use·00000520:·2d55·5322·3e0a·2020·2020·2020·2020·5573··-US">.········Us
00000620:·6f66·2077·6561·6b20·6f72·2075·6e74·6573··of·weak·or·untes 
00000630:·7465·6420·656e·6372·7970·7469·6f6e·2061··ted·encryption·a 
00000640:·6c67·6f72·6974·686d·7320·756e·6465·726d··lgorithms·underm 
00000650:·696e·6573·2074·6865·2070·7572·706f·7365··ines·the·purpose 
00000660:·7320·6f66·2075·7469·6c69·7a69·6e67·2065··s·of·utilizing·e 
00000670:·6e63·7279·7074·696f·6e20·746f·0a70·726f··ncryption·to.pro 
00000680:·7465·6374·2064·6174·612e·2054·6865·206f··tect·data.·The·o 
00000690:·7065·7261·7469·6e67·2073·7973·7465·6d20··perating·system· 
000006a0:·6d75·7374·2069·6d70·6c65·6d65·6e74·2063··must·implement·c 
000006b0:·7279·7074·6f67·7261·7068·6963·206d·6f64··ryptographic·mod 
000006c0:·756c·6573·2061·6468·6572·696e·6720·746f··ules·adhering·to 
000006d0:·2074·6865·2068·6967·6865·720a·7374·616e···the·higher.stan 
000006e0:·6461·7264·7320·6170·7072·6f76·6564·2062··dards·approved·b 
000006f0:·7920·7468·6520·6665·6465·7261·6c20·676f··y·the·federal·go 
00000700:·7665·726e·6d65·6e74·2073·696e·6365·2074··vernment·since·t 
00000710:·6869·7320·7072·6f76·6964·6573·2061·7373··his·provides·ass 
00000720:·7572·616e·6365·2074·6865·7920·6861·7665··urance·they·have 
00000730:·2062·6565·6e20·7465·7374·6564·0a61·6e64···been·tested.and 
00000740:·2076·616c·6964·6174·6564·2e0a·2020·2020···validated..···· 
00000750:·2020·3c2f·7464·3e0a·2020·2020·3c2f·7472····</td>.····</tr00000530:·6520·6f66·2061·2036·342d·6269·7420·6f70··e·of·a·64-bit·op
 00000540:·6572·6174·696e·6720·7379·7374·656d·206f··erating·system·o
 00000550:·6666·6572·7320·6120·6665·7720·6164·7661··ffers·a·few·adva
 00000560:·6e74·6167·6573·2c20·6c69·6b65·2061·206c··ntages,·like·a·l
 00000570:·6172·6765·7220·6164·6472·6573·7320·7370··arger·address·sp
 00000580:·6163·6520·7261·6e67·6520·666f·720a·4164··ace·range·for.Ad
 00000590:·6472·6573·7320·5370·6163·6520·4c61·796f··dress·Space·Layo
 000005a0:·7574·2052·616e·646f·6d69·7a61·7469·6f6e··ut·Randomization
 000005b0:·2028·4153·4c52·2920·616e·6420·7379·7374···(ASLR)·and·syst
 000005c0:·656d·6174·6963·2070·7265·7365·6e63·6520··ematic·presence·
 000005d0:·6f66·204e·6f20·6558·6563·7574·6520·616e··of·No·eXecute·an
 000005e0:·6420·4578·6563·7574·6520·4469·7361·626c··d·Execute·Disabl
 000005f0:·6520·284e·582f·5844·2920·7072·6f74·6563··e·(NX/XD)·protec
 00000600:·7469·6f6e·2062·6974·732e·0a20·2020·2020··tion·bits..·····
 00000610:·203c·2f74·643e·0a20·2020·203c·2f74·723e···</td>.····</tr>
 00000620:·0a20·2020·203c·7472·3e0a·2020·2020·2020··.····<tr>.······
 00000630:·3c74·643e·5231·3c2f·7464·3e0a·2020·2020··<td>R1</td>.····
 00000640:·2020·3c74·643e·496e·7374·616c·6c20·5041····<td>Install·PA
 00000650:·4520·4b65·726e·656c·206f·6e20·5375·7070··E·Kernel·on·Supp
 00000660:·6f72·7465·6420·3332·2d62·6974·2078·3836··orted·32-bit·x86
 00000670:·2053·7973·7465·6d73·3c2f·7464·3e0a·2020···Systems</td>.··
 00000680:·2020·2020·3c74·6420·786d·6c3a·6c61·6e67······<td·xml:lang
 00000690:·3d22·656e·2d55·5322·3e0a·2020·2020·2020··="en-US">.······
 000006a0:·2020·5379·7374·656d·7320·7468·6174·2061····Systems·that·a
 000006b0:·7265·2075·7369·6e67·2074·6865·2036·342d··re·using·the·64-
 000006c0:·6269·7420·7838·3620·6b65·726e·656c·2070··bit·x86·kernel·p
 000006d0:·6163·6b61·6765·0a64·6f20·6e6f·7420·6e65··ackage.do·not·ne
 000006e0:·6564·2074·6f20·696e·7374·616c·6c20·7468··ed·to·install·th
 000006f0:·6520·6b65·726e·656c·2d50·4145·2070·6163··e·kernel-PAE·pac
 00000700:·6b61·6765·2062·6563·6175·7365·2074·6865··kage·because·the
 00000710:·2036·342d·6269·740a·7838·3620·6b65·726e···64-bit.x86·kern
 00000720:·656c·2061·6c72·6561·6479·2069·6e63·6c75··el·already·inclu
 00000730:·6465·7320·7468·6973·2073·7570·706f·7274··des·this·support
 00000740:·2e20·486f·7765·7665·722c·2069·6620·7468··.·However,·if·th
 00000750:·6520·7379·7374·656d·2069·730a·3332·2d62··e·system·is.32-b
 00000760:·6974·2061·6e64·2061·6c73·6f20·7375·7070··it·and·also·supp
 00000770:·6f72·7473·2074·6865·2050·4145·2061·6e64··orts·the·PAE·and
 00000780:·204e·5820·6665·6174·7572·6573·2061·730a···NX·features·as.
 00000790:·6465·7465·726d·696e·6564·2069·6e20·7468··determined·in·th
 000007a0:·6520·7072·6576·696f·7573·2073·6563·7469··e·previous·secti
 000007b0:·6f6e·2c20·7468·6520·6b65·726e·656c·2d50··on,·the·kernel-P
 000007c0:·4145·2070·6163·6b61·6765·2073·686f·756c··AE·package·shoul
 000007d0:·640a·6265·2069·6e73·7461·6c6c·6564·2074··d.be·installed·t
 000007e0:·6f20·656e·6162·6c65·2058·4420·6f72·204e··o·enable·XD·or·N
 000007f0:·5820·7375·7070·6f72·742e·0a54·6865·203c··X·support..The·<
 00000800:·636f·6465·3e6b·6572·6e65·6c2d·5041·453c··code>kernel-PAE<
 00000810:·2f63·6f64·653e·2070·6163·6b61·6765·2063··/code>·package·c
 00000820:·616e·2062·6520·696e·7374·616c·6c65·6420··an·be·installed·
 00000830:·7769·7468·2074·6865·2066·6f6c·6c6f·7769··with·the·followi
 00000840:·6e67·2063·6f6d·6d61·6e64·3a0a·3c70·7265··ng·command:.<pre
 00000850:·3e0a·2420·7375·646f·2079·756d·2069·6e73··>.$·sudo·yum·ins
 00000860:·7461·6c6c·206b·6572·6e65·6c2d·5041·453c··tall·kernel-PAE<
 00000870:·2f70·7265·3e0a·5468·6520·696e·7374·616c··/pre>.The·instal
 00000880:·6c61·7469·6f6e·2070·726f·6365·7373·2073··lation·process·s
 00000890:·686f·756c·6420·616c·736f·2068·6176·6520··hould·also·have·
 000008a0:·636f·6e66·6967·7572·6564·2074·6865·0a62··configured·the.b
 000008b0:·6f6f·746c·6f61·6465·7220·746f·206c·6f61··ootloader·to·loa
 000008c0:·6420·7468·6520·6e65·7720·6b65·726e·656c··d·the·new·kernel
 000008d0:·2061·7420·626f·6f74·2e20·5665·7269·6679···at·boot.·Verify
 000008e0:·2074·6869·7320·6166·7465·7220·7265·626f···this·after·rebo
 000008f0:·6f74·0a61·6e64·206d·6f64·6966·7920·3c74··ot.and·modify·<t
 00000900:·743e·2f65·7463·2f64·6566·6175·6c74·2f67··t>/etc/default/g
 00000910:·7275·623c·2f74·743e·2069·6620·6e65·6365··rub</tt>·if·nece
Max diff block lines reached; 3052279/3088733 bytes (98.82%) of diff not shown.
678 KB
html2text {}
    
Offset 1, 38 lines modifiedOffset 1, 13 lines modified
  
  
1 Rules·with·ANSSI·Reference·in·Guide·to·the·Secure·Configuration·of·Oracle·Linux1 Rules·with·ANSSI·Reference·in·Guide·to·the·Secure·Configuration·of·Oracle·Linux
2 82 8
  
  
3 ···········································································Use·of·weak·or·untested·encryption 
4 ······························To·enable·FIPS·on·system·that·support·the····algorithms·undermines·the·purposes·of 
5 ······························Advanced·Encryption·Standard·(AES)·or·New····utilizing·encryption·to·protect·data. 
6 ····Install·the·dracut-fips-··Instructions·(AES-NI)·engine,·the·system·····The·operating·system·must·implement 
7 R1··aesni·Package·············requires·that·the·dracut-fips-aesni·package··cryptographic·modules·adhering·to·the 
8 ······························be·installed.·The·dracut-fips-aesni·package··higher·standards·approved·by·the 
9 ······························can·be·installed·with·the·following·command:·federal·government·since·this·provides 
10 ······························$·sudo·yum·install·dracut-fips-aesni·········assurance·they·have·been·tested·and 
11 ···········································································validated. 
12 ······························The·SMAP·is·used·to·prevent·the·supervisor 
13 ······························mode·from·unintentionally·reading/writing 
14 ······························into·memory·pages·in·the·user·space,·it·is 
15 ······························enabled·by·default·since·Linux·kernel·3.7. 
16 ······························But·it·could·be·disabled·through·kernel·boot 
17 ······························parameters.·Ensure·that·Supervisor·Mode 
18 ······························Access·Prevention·(SMAP)·is·not·disabled·by··Disabling·SMAP·can·facilitate 
19 R1··Ensure·SMAP·is·not········the·nosmap·boot·paramenter·option.·Check·····exploitation·of·vulnerabilities·caused 
20 ····disabled·during·boot······that·the·line································by·unintended·access·and·manipulation 
21 ······························GRUB_CMDLINE_LINUX="..."·····················of·data·in·the·user·space. 
22 ······························within·/etc/default/grub·doesn't·contain·the 
23 ······························argument·nosmap.·Run·the·following·command 
24 ······························to·update·command·line·for·already·installed 
25 ······························kernels: 
26 ······························#·grubby·--update-kernel=ALL·--remove- 
27 ······························args="nosmap" 
28 ···········································································Use·of·a·64-bit·operating·system3 ···········································································Use·of·a·64-bit·operating·system
29 ···········································································offers·a·few·advantages,·like·a·larger4 ···········································································offers·a·few·advantages,·like·a·larger
30 ····Prefer·to·use·a·64-bit····Prefer·installation·of·64-bit·operating······address·space·range·for·Address·Space5 ····Prefer·to·use·a·64-bit····Prefer·installation·of·64-bit·operating······address·space·range·for·Address·Space
31 R1··Operating·System·when·····systems·when·the·CPU·supports·it.············Layout·Randomization·(ASLR)·and6 R1··Operating·System·when·····systems·when·the·CPU·supports·it.············Layout·Randomization·(ASLR)·and
32 ····supported······························································systematic·presence·of·No·eXecute·and7 ····supported······························································systematic·presence·of·No·eXecute·and
33 ···········································································Execute·Disable·(NX/XD)·protection8 ···········································································Execute·Disable·(NX/XD)·protection
34 ···········································································bits.9 ···········································································bits.
Offset 62, 14 lines modifiedOffset 37, 39 lines modified
62 ······························GRUB_CMDLINE_LINUX="..."·····················kernel·to·unintentionally·execute·code37 ······························GRUB_CMDLINE_LINUX="..."·····················kernel·to·unintentionally·execute·code
63 ······························within·/etc/default/grub·doesn't·contain·the·in·less·privileged·memory·space.38 ······························within·/etc/default/grub·doesn't·contain·the·in·less·privileged·memory·space.
64 ······························argument·nosmep.·Run·the·following·command39 ······························argument·nosmep.·Run·the·following·command
65 ······························to·update·command·line·for·already·installed40 ······························to·update·command·line·for·already·installed
66 ······························kernels:41 ······························kernels:
67 ······························#·grubby·--update-kernel=ALL·--remove-42 ······························#·grubby·--update-kernel=ALL·--remove-
68 ······························args="nosmep"43 ······························args="nosmep"
 44 ······························The·SMAP·is·used·to·prevent·the·supervisor
 45 ······························mode·from·unintentionally·reading/writing
 46 ······························into·memory·pages·in·the·user·space,·it·is
 47 ······························enabled·by·default·since·Linux·kernel·3.7.
 48 ······························But·it·could·be·disabled·through·kernel·boot
 49 ······························parameters.·Ensure·that·Supervisor·Mode
 50 ······························Access·Prevention·(SMAP)·is·not·disabled·by··Disabling·SMAP·can·facilitate
 51 R1··Ensure·SMAP·is·not········the·nosmap·boot·paramenter·option.·Check·····exploitation·of·vulnerabilities·caused
 52 ····disabled·during·boot······that·the·line································by·unintended·access·and·manipulation
 53 ······························GRUB_CMDLINE_LINUX="..."·····················of·data·in·the·user·space.
 54 ······························within·/etc/default/grub·doesn't·contain·the
 55 ······························argument·nosmap.·Run·the·following·command
 56 ······························to·update·command·line·for·already·installed
 57 ······························kernels:
 58 ······························#·grubby·--update-kernel=ALL·--remove-
 59 ······························args="nosmap"
 60 ···········································································Use·of·weak·or·untested·encryption
 61 ······························To·enable·FIPS·on·system·that·support·the····algorithms·undermines·the·purposes·of
 62 ······························Advanced·Encryption·Standard·(AES)·or·New····utilizing·encryption·to·protect·data.
 63 ····Install·the·dracut-fips-··Instructions·(AES-NI)·engine,·the·system·····The·operating·system·must·implement
 64 R1··aesni·Package·············requires·that·the·dracut-fips-aesni·package··cryptographic·modules·adhering·to·the
 65 ······························be·installed.·The·dracut-fips-aesni·package··higher·standards·approved·by·the
 66 ······························can·be·installed·with·the·following·command:·federal·government·since·this·provides
 67 ······························$·sudo·yum·install·dracut-fips-aesni·········assurance·they·have·been·tested·and
 68 ···········································································validated.
69 ······························The·grub2·boot·loader·should·have·a69 ······························The·grub2·boot·loader·should·have·a
70 ······························superuser·account·and·password·protection70 ······························superuser·account·and·password·protection
71 ······························enabled·to·protect·boot-time·settings.·······Password·protection·on·the·boot·loader71 ······························enabled·to·protect·boot-time·settings.·······Password·protection·on·the·boot·loader
72 ···········································································configuration·ensures·users·with72 ···········································································configuration·ensures·users·with
73 ····Set·Boot·Loader·Password··Since·plaintext·passwords·are·a·security·····physical·access·cannot·trivially·alter73 ····Set·Boot·Loader·Password··Since·plaintext·passwords·are·a·security·····physical·access·cannot·trivially·alter
74 R5··in·grub2··················risk,·generate·a·hash·for·the·password·by····important·bootloader·settings.·These74 R5··in·grub2··················risk,·generate·a·hash·for·the·password·by····important·bootloader·settings.·These
75 ······························running·the·following·command:···············include·which·kernel·to·use,·and75 ······························running·the·following·command:···············include·which·kernel·to·use,·and
Offset 99, 77 lines modifiedOffset 99, 141 lines modified
99 ······························systems.·Modify·the·line·within·/etc/········hardware·devices.99 ······························systems.·Modify·the·line·within·/etc/········hardware·devices.
100 ······························default/grub·as·shown·below:100 ······························default/grub·as·shown·below:
101 ······························GRUB_CMDLINE_LINUX="...·iommu=force·..."101 ······························GRUB_CMDLINE_LINUX="...·iommu=force·..."
102 ······························Run·the·following·command·to·update·command102 ······························Run·the·following·command·to·update·command
103 ······························line·for·already·installed·kernels:103 ······························line·for·already·installed·kernels:
104 ······························#·grubby·--update-kernel=ALL·--104 ······························#·grubby·--update-kernel=ALL·--
105 ······························args="iommu=force"105 ······························args="iommu=force"
106 ······························Microarchitectural·Data·Sampling·(MDS)·is·a 
107 ······························hardware·vulnerability·which·allows 
108 ······························unprivileged·speculative·access·to·data 
109 ······························which·is·available·in·various·CPU·internal 
110 ······························buffers.·When·performing·store,·load,·L1 
111 ······························refill·operations,·processors·write·data 
112 ······························into·temporary·microarchitectural·structures 
113 ······························(buffers),·and·the·data·in·the·buffer·can·be 
114 ······························forwarded·to·load·operations·as·an 
115 ······························optimization.·Under·certain·conditions,·data 
116 ······························unrelated·to·the·load·operations·can·be 
117 ······························speculatively·forwarded·from·the·buffers·to 
118 ······························a·disclosure·gadget·which·allows·in·turn·to 
119 ······························infer·the·value·via·a·cache·side·channel 
120 ······························attack.·Select·the·appropriate·mitigation·by106 ······························The·kernel·may·merge·similar·slabs·together
 107 ······························to·reduce·overhead·and·increase·cache
 108 ······························hotness·of·objects.·Disabling·merging·of
 109 ······························slabs·keeps·the·slabs·separate·and·reduces
 110 ······························the·risk·of·kernel·heap·overflows
 111 ······························overwriting·objects·in·merged·caches.·To·····Disabling·the·merge·of·slabs·of
 112 ······························disable·merging·of·slabs·in·the·Kernel·add···similar·sizes·prevents·the·kernel·from
 113 ······························the·argument·slab_nomerge=yes·to·the·default·merging·a·seemingly·useless·but
 114 ······························GRUB·2·command·line·for·the·Linux·operating··vulnerable·slab·with·a·useful·and
 115 ······························system.·To·ensure·that·slab_nomerge=yes·is···valuable·slab.·This·increase·the·risk
 116 R8··Disable·merging·of·slabs··added·as·a·kernel·command·line·argument·to···that·a·heap·overflow·could·overwrite
 117 ····with·similar·size·········newly·installed·kernels,·add·················objects·from·merged·caches,·with
 118 ······························slab_nomerge=yes·to·the·default·Grub2········unmerged·caches·the·heap·overflow
 119 ······························command·line·for·Linux·operating·systems.····would·only·affect·the·objects·in·the
 120 ······························Modify·the·line·within·/etc/default/grub·as··same·cache.·Overall,·this·reduces·the
 121 ······························shown·below:·································kernel·attack·surface·area·by
 122 ······························GRUB_CMDLINE_LINUX="...·slab_nomerge=yes·····isolating·slabs·from·each·other.
 123 ······························..."
 124 ······························Run·the·following·command·to·update·command
 125 ······························line·for·already·installed·kernels:
 126 ······························#·grubby·--update-kernel=ALL·--
 127 ······························args="slab_nomerge=yes"
 128 ······························To·enable·Kernel·page-table·isolation,·add
121 ······························adding·the·argument·mds=full·to·the·default129 ······························the·argument·pti=on·to·the·default·GRUB·2
122 ····Configure·················GRUB·2·command·line·for·the·Linux·operating··The·MDS·vulnerability·allows·an 
123 R8··Microarchitectural·Data···system.·To·ensure·that·mds=full·is·added·as··attacker·to·sample·data·from·internal 
124 ····Sampling·mitigation·······a·kernel·command·line·argument·to·newly······CPU·buffers.130 ······························command·line·for·the·Linux·operating·system.
Max diff block lines reached; 678992/694507 bytes (97.77%) of diff not shown.
1.22 MB
./usr/share/doc/ssg-nondebian/table-ol8-cuirefs.html
Ordering differences only
    
Offset 40, 45 lines modifiedOffset 40, 53 lines modified
40 ····<th>Mapping</th>40 ····<th>Mapping</th>
41 ····<th>Rule·Title</th>41 ····<th>Rule·Title</th>
42 ····<th>Description</th>42 ····<th>Description</th>
43 ····<th>Rationale</th>43 ····<th>Rationale</th>
44 ··</thead>44 ··</thead>
45 ··<tbody>45 ··<tbody>
46 ··<tr>46 ··<tr>
47 ······<td>3.1.1</td>47 ······<td>3.1.1<br/>3.1.5</td>
48 ······<td>Disable·GDM·Guest·Login</td>48 ······<td>Disable·SSH·Access·via·Empty·Passwords</td>
49 ······<td·xml:lang="en-US">49 ······<td·xml:lang="en-US">
50 ········The·GNOME·Display·Manager·(GDM)·can·allow·users·to·login·without·credentials 
51 which·can·be·useful·for·public·kiosk·scenarios.·Allowing·users·to·login·without·credentials 
52 or·"guest"·account·access·has·inherent·security·risks·and·should·be·disabled.·To·do·disable 
53 timed·logins·or·guest·account·access,·set·the·<tt>TimedLoginEnable</tt>·to·<tt>false</tt>·in 
54 the·<tt>[daemon]</tt>·section·in·<tt>/etc/gdm/custom.conf</tt>.·For·example: 
55 <pre>[daemon] 
56 TimedLoginEnable=false</pre>50 ········Disallow·SSH·login·with·empty·passwords.
 51 The·default·SSH·configuration·disables·logins·with·empty·passwords.·The·appropriate
 52 configuration·is·used·if·no·value·is·set·for·<tt>PermitEmptyPasswords</tt>.
 53 <br·/>
 54 To·explicitly·disallow·SSH·login·from·accounts·with·empty·passwords,
 55 add·or·correct·the·following·line·in
  
  
 56 <tt>/etc/ssh/sshd_config</tt>:
  
 57 <br·/>
 58 <pre>PermitEmptyPasswords·no</pre>
 59 Any·accounts·with·empty·passwords·should·be·disabled·immediately,·and·PAM·configuration
 60 should·prevent·users·from·being·able·to·assign·themselves·empty·passwords.
57 ······</td>61 ······</td>
58 ······<td·xml:lang="en-US">62 ······<td·xml:lang="en-US">
59 ········Failure·to·restrict·system·access·to·authenticated·users·negatively·impacts·operating 
60 system·security.63 ········Configuring·this·setting·for·the·SSH·daemon·provides·additional·assurance
 64 that·remote·login·via·SSH·will·require·a·password,·even·in·the·event·of
 65 misconfiguration·elsewhere.
61 ······</td>66 ······</td>
62 ····</tr>67 ····</tr>
63 ····<tr>68 ····<tr>
64 ······<td>3.1.1<br/>3.1.5</td>69 ······<td>3.1.1</td>
65 ······<td>Restrict·Virtual·Console·Root·Logins</td>70 ······<td>Disable·GDM·Automatic·Login</td>
66 ······<td·xml:lang="en-US">71 ······<td·xml:lang="en-US">
67 ········To·restrict·root·logins·through·the·(deprecated)·virtual·console·devices, 
68 ensure·lines·of·this·form·do·not·appear·in·<tt>/etc/securetty</tt>: 
69 <pre>vc/1 
70 vc/2 
71 vc/3 
72 vc/4</pre>72 ········The·GNOME·Display·Manager·(GDM)·can·allow·users·to·automatically·login·without
 73 user·interaction·or·credentials.·User·should·always·be·required·to·authenticate·themselves
 74 to·the·system·that·they·are·authorized·to·use.·To·disable·user·ability·to·automatically
 75 login·to·the·system,·set·the·<tt>AutomaticLoginEnable</tt>·to·<tt>false</tt>·in·the
 76 <tt>[daemon]</tt>·section·in·<tt>/etc/gdm/custom.conf</tt>.·For·example:
 77 <pre>[daemon]
 78 AutomaticLoginEnable=false</pre>
73 ······</td>79 ······</td>
74 ······<td·xml:lang="en-US">80 ······<td·xml:lang="en-US">
 81 ········Failure·to·restrict·system·access·to·authenticated·users·negatively·impacts·operating
 82 system·security.
75 ········Preventing·direct·root·login·to·virtual·console·devices 
76 helps·ensure·accountability·for·actions·taken·on·the·system 
77 using·the·root·account. 
78 ······</td>83 ······</td>
79 ····</tr>84 ····</tr>
80 ····<tr>85 ····<tr>
81 ······<td>3.1.1<br/>3.1.5</td>86 ······<td>3.1.1<br/>3.1.5</td>
82 ······<td>Disable·SSH·Root·Login</td>87 ······<td>Disable·SSH·Root·Login</td>
83 ······<td·xml:lang="en-US">88 ······<td·xml:lang="en-US">
84 ········The·root·user·should·never·be·allowed·to·login·to·a89 ········The·root·user·should·never·be·allowed·to·login·to·a
Offset 95, 23 lines modifiedOffset 103, 43 lines modified
95 security·is·gained·by·extending·the·policy·of·not·logging·directly·on·as·root.103 security·is·gained·by·extending·the·policy·of·not·logging·directly·on·as·root.
96 In·addition,·logging·in·with·a·user-specific·account·provides·individual104 In·addition,·logging·in·with·a·user-specific·account·provides·individual
97 accountability·of·actions·performed·on·the·system·and·also·helps·to·minimize105 accountability·of·actions·performed·on·the·system·and·also·helps·to·minimize
98 direct·attack·attempts·on·root's·password.106 direct·attack·attempts·on·root's·password.
99 ······</td>107 ······</td>
100 ····</tr>108 ····</tr>
101 ····<tr>109 ····<tr>
 110 ······<td>3.1.1<br/>3.1.5</td>
 111 ······<td>Prevent·Login·to·Accounts·With·Empty·Password</td>
 112 ······<td·xml:lang="en-US">
 113 ········If·an·account·is·configured·for·password·authentication
 114 but·does·not·have·an·assigned·password,·it·may·be·possible·to·log
 115 into·the·account·without·authentication.·Remove·any·instances·of·the
 116 <tt>nullok</tt>·in
  
 117 <tt>/etc/pam.d/system-auth</tt>·and
 118 <tt>/etc/pam.d/password-auth</tt>
  
 119 to·prevent·logins·with·empty·passwords.
 120 ······</td>
 121 ······<td·xml:lang="en-US">
 122 ········If·an·account·has·an·empty·password,·anyone·could·log·in·and
 123 run·commands·with·the·privileges·of·that·account.·Accounts·with
 124 empty·passwords·should·never·be·used·in·operational·environments.
 125 ······</td>
 126 ····</tr>
 127 ····<tr>
102 ······<td>3.1.1<br/>3.4.5</td>128 ······<td>3.1.1<br/>3.4.5</td>
103 ······<td>Require·Authentication·for·Single·User·Mode</td>129 ······<td>Require·Authentication·for·Emergency·Systemd·Target</td>
104 ······<td·xml:lang="en-US">130 ······<td·xml:lang="en-US">
105 ········Single-user·mode·is·intended·as·a·system·recovery131 ········Emergency·mode·is·intended·as·a·system·recovery
106 method,·providing·a·single·user·root·access·to·the·system·by132 method,·providing·a·single·user·root·access·to·the·system
107 providing·a·boot·option·at·startup.133 during·a·failed·boot·sequence.
108 <br·/><br·/>134 <br·/><br·/>
109 By·default,·single-user·mode·is·protected·by·requiring·a·password·and·is·set135 By·default,·Emergency·mode·is·protected·by·requiring·a·password·and·is·set
110 in·<tt>/usr/lib/systemd/system/rescue.service</tt>.136 in·<tt>/usr/lib/systemd/system/emergency.service</tt>.
111 ······</td>137 ······</td>
112 ······<td·xml:lang="en-US">138 ······<td·xml:lang="en-US">
113 ········This·prevents·attackers·with·physical·access·from·trivially·bypassing·security139 ········This·prevents·attackers·with·physical·access·from·trivially·bypassing·security
114 on·the·machine·and·gaining·root·access.·Such·accesses·are·further·prevented140 on·the·machine·and·gaining·root·access.·Such·accesses·are·further·prevented
115 by·configuring·the·bootloader·password.141 by·configuring·the·bootloader·password.
116 ······</td>142 ······</td>
117 ····</tr>143 ····</tr>
Offset 127, 45 lines modifiedOffset 155, 71 lines modified
127 ······<td·xml:lang="en-US">155 ······<td·xml:lang="en-US">
128 ········Preventing·direct·root·login·to·serial·port·interfaces156 ········Preventing·direct·root·login·to·serial·port·interfaces
129 helps·ensure·accountability·for·actions·taken·on·the·systems157 helps·ensure·accountability·for·actions·taken·on·the·systems
130 using·the·root·account.158 using·the·root·account.
131 ······</td>159 ······</td>
132 ····</tr>160 ····</tr>
133 ····<tr>161 ····<tr>
134 ······<td>3.1.1<br/>3.4.5</td>162 ······<td>3.1.1<br/>3.1.6</td>
135 ······<td>Require·Authentication·for·Emergency·Systemd·Target</td>163 ······<td>Direct·root·Logins·Not·Allowed</td>
136 ······<td·xml:lang="en-US">164 ······<td·xml:lang="en-US">
137 ········Emergency·mode·is·intended·as·a·system·recovery 
138 method,·providing·a·single·user·root·access·to·the·system 
139 during·a·failed·boot·sequence. 
140 <br·/><br·/> 
Max diff block lines reached; 454272/461130 bytes (98.51%) of diff not shown.
797 KB
html2text {}
    
Offset 1, 31 lines modifiedOffset 1, 35 lines modified
  
  
1 Rules·with·NIST-800-171·Reference·in·Guide·to·the·Secure·Configuration·of1 Rules·with·NIST-800-171·Reference·in·Guide·to·the·Secure·Configuration·of
2 Oracle·Linux·82 Oracle·Linux·8
  
  
 3 ·······································Disallow·SSH·login·with·empty·passwords.·The·default
 4 ·······································SSH·configuration·disables·logins·with·empty···········Configuring·this
 5 ·······································passwords.·The·appropriate·configuration·is·used·if·no·setting·for·the·SSH
 6 ·······································value·is·set·for·PermitEmptyPasswords.·················daemon·provides
 7 ·······································To·explicitly·disallow·SSH·login·from·accounts·with····additional·assurance
 8 3.1.1···Disable·SSH·Access·via·Empty···empty·passwords,·add·or·correct·the·following·line·in··that·remote·login
 9 3.1.5···Passwords······················/etc/ssh/sshd_config:··································via·SSH·will·require
 10 ·······································PermitEmptyPasswords·no································a·password,·even·in
 11 ·······································Any·accounts·with·empty·passwords·should·be·disabled···the·event·of
 12 ·······································immediately,·and·PAM·configuration·should·prevent······misconfiguration
 13 ·······································users·from·being·able·to·assign·themselves·empty·······elsewhere.
 14 ·······································passwords.
3 ·······································The·GNOME·Display·Manager·(GDM)·can·allow·users·to15 ·······································The·GNOME·Display·Manager·(GDM)·can·allow·users·to
4 ·······································login·without·credentials·which·can·be·useful·for 
5 ·······································public·kiosk·scenarios.·Allowing·users·to·login········Failure·to·restrict 
6 ·······································without·credentials·or·"guest"·account·access·has······system·access·to 
7 3.1.1···Disable·GDM·Guest·Login········inherent·security·risks·and·should·be·disabled.·To·do··authenticated·users 
8 ·······································disable·timed·logins·or·guest·account·access,·set·the··negatively·impacts16 ·······································automatically·login·without·user·interaction·or
 17 ·······································credentials.·User·should·always·be·required·to·········Failure·to·restrict
 18 ·······································authenticate·themselves·to·the·system·that·they·are····system·access·to
 19 3.1.1···Disable·GDM·Automatic·Login····authorized·to·use.·To·disable·user·ability·to··········authenticated·users
 20 ·······································automatically·login·to·the·system,·set·the·············negatively·impacts
9 ·······································TimedLoginEnable·to·false·in·the·[daemon]·section·in·/·operating·system21 ·······································AutomaticLoginEnable·to·false·in·the·[daemon]·section··operating·system
10 ·······································etc/gdm/custom.conf.·For·example:······················security.22 ·······································in·/etc/gdm/custom.conf.·For·example:··················security.
11 ·······································[daemon]23 ·······································[daemon]
12 ·······································TimedLoginEnable=false24 ·······································AutomaticLoginEnable=false
13 ·······································To·restrict·root·logins·through·the·(deprecated)·······Preventing·direct 
14 ·······································virtual·console·devices,·ensure·lines·of·this·form·do··root·login·to 
15 ·······································not·appear·in·/etc/securetty:··························virtual·console 
16 3.1.1···Restrict·Virtual·Console·Root··vc/1···················································devices·helps·ensure 
17 3.1.5···Logins·························vc/2···················································accountability·for 
18 ·······································vc/3···················································actions·taken·on·the 
19 ·······································vc/4···················································system·using·the 
20 ······························································································root·account. 
21 ······························································································Even·though·the25 ······························································································Even·though·the
22 ······························································································communications26 ······························································································communications
23 ······························································································channel·may·be27 ······························································································channel·may·be
24 ······························································································encrypted,·an28 ······························································································encrypted,·an
25 ······························································································additional·layer·of29 ······························································································additional·layer·of
26 ······························································································security·is·gained30 ······························································································security·is·gained
27 ······························································································by·extending·the31 ······························································································by·extending·the
Offset 39, 54 lines modifiedOffset 43, 80 lines modified
39 ······························································································accountability·of43 ······························································································accountability·of
40 ······························································································actions·performed·on44 ······························································································actions·performed·on
41 ······························································································the·system·and·also45 ······························································································the·system·and·also
42 ······························································································helps·to·minimize46 ······························································································helps·to·minimize
43 ······························································································direct·attack47 ······························································································direct·attack
44 ······························································································attempts·on·root's48 ······························································································attempts·on·root's
45 ······························································································password.49 ······························································································password.
 50 ······························································································If·an·account·has·an
 51 ······························································································empty·password,
 52 ·······································If·an·account·is·configured·for·password···············anyone·could·log·in
 53 ·······································authentication·but·does·not·have·an·assigned·password,·and·run·commands
 54 3.1.1···Prevent·Login·to·Accounts·With·it·may·be·possible·to·log·into·the·account·without·····with·the·privileges
 55 3.1.5···Empty·Password·················authentication.·Remove·any·instances·of·the·nullok·in··of·that·account.
 56 ·······································/etc/pam.d/system-auth·and·/etc/pam.d/password-auth·to·Accounts·with·empty
 57 ·······································prevent·logins·with·empty·passwords.···················passwords·should
 58 ······························································································never·be·used·in
 59 ······························································································operational
 60 ······························································································environments.
46 ······························································································This·prevents61 ······························································································This·prevents
47 ······························································································attackers·with62 ······························································································attackers·with
48 ·······································Single-user·mode·is·intended·as·a·system·recovery······physical·access·from63 ·······································Emergency·mode·is·intended·as·a·system·recovery········physical·access·from
49 ·······································method,·providing·a·single·user·root·access·to·the·····trivially·bypassing64 ·······································method,·providing·a·single·user·root·access·to·the·····trivially·bypassing
50 3.1.1···Require·Authentication·for·····system·by·providing·a·boot·option·at·startup.··········security·on·the65 3.1.1···Require·Authentication·for·····system·during·a·failed·boot·sequence.··················security·on·the
51 3.4.5···Single·User·Mode······································································machine·and·gaining66 3.4.5···Emergency·Systemd·Target······························································machine·and·gaining
52 ·······································By·default,·single-user·mode·is·protected·by·requiring·root·access.·Such67 ·······································By·default,·Emergency·mode·is·protected·by·requiring·a·root·access.·Such
53 ·······································a·password·and·is·set·in·/usr/lib/systemd/system/······accesses·are·further68 ·······································password·and·is·set·in·/usr/lib/systemd/system/········accesses·are·further
54 ·······································rescue.service.········································prevented·by69 ·······································emergency.service.·····································prevented·by
55 ······························································································configuring·the70 ······························································································configuring·the
56 ······························································································bootloader·password.71 ······························································································bootloader·password.
57 ······························································································Preventing·direct72 ······························································································Preventing·direct
58 ······························································································root·login·to·serial73 ······························································································root·login·to·serial
59 ·······································To·restrict·root·logins·on·serial·ports,·ensure·lines··port·interfaces74 ·······································To·restrict·root·logins·on·serial·ports,·ensure·lines··port·interfaces
60 3.1.1···Restrict·Serial·Port·Root······of·this·form·do·not·appear·in·/etc/securetty:··········helps·ensure75 3.1.1···Restrict·Serial·Port·Root······of·this·form·do·not·appear·in·/etc/securetty:··········helps·ensure
61 3.1.5···Logins·························ttyS0··················································accountability·for76 3.1.5···Logins·························ttyS0··················································accountability·for
62 ·······································ttyS1··················································actions·taken·on·the77 ·······································ttyS1··················································actions·taken·on·the
63 ······························································································systems·using·the78 ······························································································systems·using·the
64 ······························································································root·account.79 ······························································································root·account.
 80 ·······································To·further·limit·access·to·the·root·account,
 81 ·······································administrators·can·disable·root·logins·at·the·console··Disabling·direct
 82 ·······································by·editing·the·/etc/securetty·file.·This·file·lists····root·logins·ensures
 83 ·······································all·devices·the·root·user·is·allowed·to·login·to.·If···proper
 84 ·······································the·file·does·not·exist·at·all,·the·root·user·can······accountability·and
 85 ·······································login·through·any·communication·device·on·the·system,··multifactor
 86 ·······································whether·via·the·console·or·via·a·raw·network···········authentication·to
 87 3.1.1··································interface.·This·is·dangerous·as·user·can·login·to·the··privileged·accounts.
 88 3.1.6···Direct·root·Logins·Not·Allowed·system·as·root·via·Telnet,·which·sends·the·password·in·Users·will·first
 89 ·······································plain·text·over·the·network.·By·default,·Oracle·Linux··login,·then·escalate
 90 ·······································8's·/etc/securetty·file·only·allows·the·root·user·to···to·privileged·(root)
 91 ·······································login·at·the·console·physically·attached·to·the········access·via·su·/
 92 ·······································system.·To·prevent·root·from·logging·in,·remove·the····sudo.·This·is
 93 ·······································contents·of·this·file.·To·prevent·direct·root·logins,··required·for·FISMA
 94 ·······································remove·the·contents·of·this·file·by·typing·the·········Low·and·FISMA
 95 ·······································following·command:·····································Moderate·systems.
 96 ·······································$·sudo·echo·>·/etc/securetty
 97 ·······································To·restrict·root·logins·through·the·(deprecated)·······Preventing·direct
 98 ·······································virtual·console·devices,·ensure·lines·of·this·form·do··root·login·to
 99 ·······································not·appear·in·/etc/securetty:··························virtual·console
 100 3.1.1···Restrict·Virtual·Console·Root··vc/1···················································devices·helps·ensure
 101 3.1.5···Logins·························vc/2···················································accountability·for
 102 ·······································vc/3···················································actions·taken·on·the
 103 ·······································vc/4···················································system·using·the
 104 ······························································································root·account.
65 ······························································································This·prevents105 ······························································································This·prevents
66 ······························································································attackers·with106 ······························································································attackers·with
67 ·······································Emergency·mode·is·intended·as·a·system·recovery········physical·access·from107 ·······································Single-user·mode·is·intended·as·a·system·recovery······physical·access·from
68 ·······································method,·providing·a·single·user·root·access·to·the·····trivially·bypassing108 ·······································method,·providing·a·single·user·root·access·to·the·····trivially·bypassing
69 3.1.1···Require·Authentication·for·····system·during·a·failed·boot·sequence.··················security·on·the109 3.1.1···Require·Authentication·for·····system·by·providing·a·boot·option·at·startup.··········security·on·the
70 3.4.5···Emergency·Systemd·Target······························································machine·and·gaining110 3.4.5···Single·User·Mode······································································machine·and·gaining
71 ·······································By·default,·Emergency·mode·is·protected·by·requiring·a·root·access.·Such111 ·······································By·default,·single-user·mode·is·protected·by·requiring·root·access.·Such
72 ·······································password·and·is·set·in·/usr/lib/systemd/system/········accesses·are·further112 ·······································a·password·and·is·set·in·/usr/lib/systemd/system/······accesses·are·further
73 ·······································emergency.service.·····································prevented·by113 ·······································rescue.service.········································prevented·by
74 ······························································································configuring·the114 ······························································································configuring·the
75 ······························································································bootloader·password.115 ······························································································bootloader·password.
76 ·······································The·GNOME·Display·Manager·(GDM)·can·allow·users·to 
77 ·······································automatically·login·without·user·interaction·or 
78 ·······································credentials.·User·should·always·be·required·to·········Failure·to·restrict 
79 ·······································authenticate·themselves·to·the·system·that·they·are····system·access·to 
80 3.1.1···Disable·GDM·Automatic·Login····authorized·to·use.·To·disable·user·ability·to··········authenticated·users 
81 ·······································automatically·login·to·the·system,·set·the·············negatively·impacts 
Max diff block lines reached; 800596/816051 bytes (98.11%) of diff not shown.
6.32 KB
./usr/share/doc/ssg-nondebian/table-ol8-nistrefs-ospp.html
    
Offset 4070, 15 lines modifiedOffset 4070, 15 lines modified
4070 <tt>RekeyLimit</tt>.4070 <tt>RekeyLimit</tt>.
4071 ··</td>4071 ··</td>
4072 ··<td·xml:lang="en-US">4072 ··<td·xml:lang="en-US">
4073 By·decreasing·the·limit·based·on·the·amount·of·data·and·enabling4073 By·decreasing·the·limit·based·on·the·amount·of·data·and·enabling
4074 time-based·limit,·effects·of·potential·attacks·against4074 time-based·limit,·effects·of·potential·attacks·against
4075 encryption·keys·are·limited.4075 encryption·keys·are·limited.
4076 ··</td>4076 ··</td>
4077 ··<td>var_ssh_client_rekey_limit_time=1hour<br/>var_ssh_client_rekey_limit_size=1G</td>4077 ··<td>var_ssh_client_rekey_limit_size=1G<br/>var_ssh_client_rekey_limit_time=1hour</td>
4078 </tr>4078 </tr>
4079 <tr>4079 <tr>
4080 ··<td></td>4080 ··<td></td>
4081 ··<td>N/A</td>4081 ··<td>N/A</td>
4082 ··<td>SSH·client·uses·strong·entropy·to·seed·(for·CSH·like·shells)</td>4082 ··<td>SSH·client·uses·strong·entropy·to·seed·(for·CSH·like·shells)</td>
4083 ··<td·xml:lang="en-US">4083 ··<td·xml:lang="en-US">
4084 To·set·up·SSH·client·to·use·entropy·from·a·high-quality·source,·make·sure4084 To·set·up·SSH·client·to·use·entropy·from·a·high-quality·source,·make·sure
Offset 4133, 15 lines modifiedOffset 4133, 15 lines modified
4133 <pre>RekeyLimit·<tt>1G</tt>·<tt>1hour</tt></pre>4133 <pre>RekeyLimit·<tt>1G</tt>·<tt>1hour</tt></pre>
4134 ··</td>4134 ··</td>
4135 ··<td·xml:lang="en-US">4135 ··<td·xml:lang="en-US">
4136 By·decreasing·the·limit·based·on·the·amount·of·data·and·enabling4136 By·decreasing·the·limit·based·on·the·amount·of·data·and·enabling
4137 time-based·limit,·effects·of·potential·attacks·against4137 time-based·limit,·effects·of·potential·attacks·against
4138 encryption·keys·are·limited.4138 encryption·keys·are·limited.
4139 ··</td>4139 ··</td>
4140 ··<td>var_rekey_limit_time=1hour<br/>var_rekey_limit_size=1G</td>4140 ··<td>var_rekey_limit_size=1G<br/>var_rekey_limit_time=1hour</td>
4141 </tr>4141 </tr>
4142 <tr>4142 <tr>
4143 ··<td></td>4143 ··<td></td>
4144 ··<td>N/A</td>4144 ··<td>N/A</td>
4145 ··<td>SSH·server·uses·strong·entropy·to·seed</td>4145 ··<td>SSH·server·uses·strong·entropy·to·seed</td>
4146 ··<td·xml:lang="en-US">4146 ··<td·xml:lang="en-US">
4147 To·set·up·SSH·server·to·use·entropy·from·a·high-quality·source,·edit·the·<tt>/etc/sysconfig/sshd</tt>·file.4147 To·set·up·SSH·server·to·use·entropy·from·a·high-quality·source,·edit·the·<tt>/etc/sysconfig/sshd</tt>·file.
4.98 KB
html2text {}
    
Offset 3341, 16 lines modifiedOffset 3341, 16 lines modified
3341 ··················································································································options,·which·can3341 ··················································································································options,·which·can
3342 ··················································································································help·protect3342 ··················································································································help·protect
3343 ··················································································································programs·which·use3343 ··················································································································programs·which·use
3344 ··················································································································it.3344 ··················································································································it.
3345 ·························The·RekeyLimit·parameter·specifies·how·often·the·session·key·is·renegotiated,·both·in····By·decreasing·the3345 ·························The·RekeyLimit·parameter·specifies·how·often·the·session·key·is·renegotiated,·both·in····By·decreasing·the
3346 ·························terms·of·amount·of·data·that·may·be·transmitted·and·the·time·elapsed.·To·decrease·the····limit·based·on·the3346 ·························terms·of·amount·of·data·that·may·be·transmitted·and·the·time·elapsed.·To·decrease·the····limit·based·on·the
3347 ········Configure········default·limits,·put·line·RekeyLimit·1G·1hour·to·file·/etc/ssh/ssh_config.d/02-rekey-·····amount·of·data·and3347 ········Configure········default·limits,·put·line·RekeyLimit·1G·1hour·to·file·/etc/ssh/ssh_config.d/02-rekey-·····amount·of·data·and
3348 ·····N/·session··········limit.conf.·Make·sure·that·there·is·no·other·RekeyLimit·configuration·preceding·the······enabling·time-based·var_ssh_client_rekey_limit_time=1hour3348 ·····N/·session··········limit.conf.·Make·sure·that·there·is·no·other·RekeyLimit·configuration·preceding·the······enabling·time-based·var_ssh_client_rekey_limit_size=1G
3349 ·····A··renegotiation····include·directive·in·the·main·config·file·/etc/ssh/ssh_config.·Check·also·other·files·in·limit,·effects·of···var_ssh_client_rekey_limit_size=1G3349 ·····A··renegotiation····include·directive·in·the·main·config·file·/etc/ssh/ssh_config.·Check·also·other·files·in·limit,·effects·of···var_ssh_client_rekey_limit_time=1hour
3350 ········for·SSH·client···/etc/ssh/ssh_config.d·directory.·Files·are·processed·according·to·lexicographical·order··potential·attacks3350 ········for·SSH·client···/etc/ssh/ssh_config.d·directory.·Files·are·processed·according·to·lexicographical·order··potential·attacks
3351 ·························of·file·names.·Make·sure·that·there·is·no·file·processed·before·02-rekey-limit.conf······against·encryption3351 ·························of·file·names.·Make·sure·that·there·is·no·file·processed·before·02-rekey-limit.conf······against·encryption
3352 ·························containing·definition·of·RekeyLimit.·····················································keys·are·limited.3352 ·························containing·definition·of·RekeyLimit.·····················································keys·are·limited.
3353 ··················································································································Some·SSH3353 ··················································································································Some·SSH
3354 ··················································································································implementations·use3354 ··················································································································implementations·use
3355 ··················································································································the·openssl·library3355 ··················································································································the·openssl·library
3356 ··················································································································for·entropy,·which3356 ··················································································································for·entropy,·which
Offset 3401, 16 lines modifiedOffset 3401, 16 lines modified
3401 ··················································································································generator·used·by3401 ··················································································································generator·used·by
3402 ··················································································································SSH·would·be·known3402 ··················································································································SSH·would·be·known
3403 ··················································································································to·potential3403 ··················································································································to·potential
3404 ··················································································································attackers.3404 ··················································································································attackers.
3405 ··················································································································By·decreasing·the3405 ··················································································································By·decreasing·the
3406 ·························The·RekeyLimit·parameter·specifies·how·often·the·session·key·of·the·is·renegotiated,·····limit·based·on·the3406 ·························The·RekeyLimit·parameter·specifies·how·often·the·session·key·of·the·is·renegotiated,·····limit·based·on·the
3407 ········Force·frequent···both·in·terms·of·amount·of·data·that·may·be·transmitted·and·the·time·elapsed.············amount·of·data·and3407 ········Force·frequent···both·in·terms·of·amount·of·data·that·may·be·transmitted·and·the·time·elapsed.············amount·of·data·and
3408 ·····N/·session·key······To·decrease·the·default·limits,·add·or·correct·the·following·line·in·/etc/ssh/···········enabling·time-based·var_rekey_limit_time=1hour3408 ·····N/·session·key······To·decrease·the·default·limits,·add·or·correct·the·following·line·in·/etc/ssh/···········enabling·time-based·var_rekey_limit_size=1G
3409 ·····A··renegotiation····sshd_config:·············································································limit,·effects·of···var_rekey_limit_size=1G3409 ·····A··renegotiation····sshd_config:·············································································limit,·effects·of···var_rekey_limit_time=1hour
3410 ·························RekeyLimit·1G·1hour······································································potential·attacks3410 ·························RekeyLimit·1G·1hour······································································potential·attacks
3411 ··················································································································against·encryption3411 ··················································································································against·encryption
3412 ··················································································································keys·are·limited.3412 ··················································································································keys·are·limited.
3413 ··················································································································SSH·implementation3413 ··················································································································SSH·implementation
3414 ··················································································································in·Oracle·Linux·83414 ··················································································································in·Oracle·Linux·8
3415 ··················································································································uses·the·openssl3415 ··················································································································uses·the·openssl
3416 ··················································································································library,·which3416 ··················································································································library,·which
3.49 KB
./usr/share/doc/ssg-nondebian/table-ol8-nistrefs-stig.html
    
Offset 24427, 17 lines modifiedOffset 24427, 17 lines modified
0005f6a0:·6e67·0a74·696d·652d·6261·7365·6420·6c69··ng.time-based·li0005f6a0:·6e67·0a74·696d·652d·6261·7365·6420·6c69··ng.time-based·li
0005f6b0:·6d69·742c·2065·6666·6563·7473·206f·6620··mit,·effects·of·0005f6b0:·6d69·742c·2065·6666·6563·7473·206f·6620··mit,·effects·of·
0005f6c0:·706f·7465·6e74·6961·6c20·6174·7461·636b··potential·attack0005f6c0:·706f·7465·6e74·6961·6c20·6174·7461·636b··potential·attack
0005f6d0:·7320·6167·6169·6e73·740a·656e·6372·7970··s·against.encryp0005f6d0:·7320·6167·6169·6e73·740a·656e·6372·7970··s·against.encryp
0005f6e0:·7469·6f6e·206b·6579·7320·6172·6520·6c69··tion·keys·are·li0005f6e0:·7469·6f6e·206b·6579·7320·6172·6520·6c69··tion·keys·are·li
0005f6f0:·6d69·7465·642e·0a20·203c·2f74·643e·0a20··mited..··</td>.·0005f6f0:·6d69·7465·642e·0a20·203c·2f74·643e·0a20··mited..··</td>.·
0005f700:·203c·7464·3e76·6172·5f72·656b·6579·5f6c···<td>var_rekey_l0005f700:·203c·7464·3e76·6172·5f72·656b·6579·5f6c···<td>var_rekey_l
 0005f710:·696d·6974·5f73·697a·653d·3147·3c62·722f··imit_size=1G<br/
 0005f720:·3e76·6172·5f72·656b·6579·5f6c·696d·6974··>var_rekey_limit
0005f710:·696d·6974·5f74·696d·653d·3168·6f75·723c··imit_time=1hour<0005f730:·5f74·696d·653d·3168·6f75·723c·2f74·643e··_time=1hour</td>
0005f720:·6272·2f3e·7661·725f·7265·6b65·795f·6c69··br/>var_rekey_li 
0005f730:·6d69·745f·7369·7a65·3d31·473c·2f74·643e··mit_size=1G</td> 
0005f740:·0a3c·2f74·723e·0a3c·7472·3e0a·2020·3c74··.</tr>.<tr>.··<t0005f740:·0a3c·2f74·723e·0a3c·7472·3e0a·2020·3c74··.</tr>.<tr>.··<t
0005f750:·643e·3c2f·7464·3e0a·2020·3c74·643e·4e2f··d></td>.··<td>N/0005f750:·643e·3c2f·7464·3e0a·2020·3c74·643e·4e2f··d></td>.··<td>N/
0005f760:·413c·2f74·643e·0a20·203c·7464·3e53·5348··A</td>.··<td>SSH0005f760:·413c·2f74·643e·0a20·203c·7464·3e53·5348··A</td>.··<td>SSH
0005f770:·2073·6572·7665·7220·7573·6573·2073·7472···server·uses·str0005f770:·2073·6572·7665·7220·7573·6573·2073·7472···server·uses·str
0005f780:·6f6e·6720·656e·7472·6f70·7920·746f·2073··ong·entropy·to·s0005f780:·6f6e·6720·656e·7472·6f70·7920·746f·2073··ong·entropy·to·s
0005f790:·6565·643c·2f74·643e·0a20·203c·7464·2078··eed</td>.··<td·x0005f790:·6565·643c·2f74·643e·0a20·203c·7464·2078··eed</td>.··<td·x
0005f7a0:·6d6c·3a6c·616e·673d·2265·6e2d·5553·223e··ml:lang="en-US">0005f7a0:·6d6c·3a6c·616e·673d·2265·6e2d·5553·223e··ml:lang="en-US">
2.0 KB
html2text {}
    
Offset 7774, 16 lines modifiedOffset 7774, 16 lines modified
7774 ·································private·key.··········································system·where·the7774 ·································private·key.··········································system·where·the
7775 ·······················································································associated·public7775 ·······················································································associated·public
7776 ·······················································································key·has·been7776 ·······················································································key·has·been
7777 ·······················································································installed.7777 ·······················································································installed.
7778 ·································The·RekeyLimit·parameter·specifies·how·often·the······By·decreasing·the7778 ·································The·RekeyLimit·parameter·specifies·how·often·the······By·decreasing·the
7779 ·································session·key·of·the·is·renegotiated,·both·in·terms·of··limit·based·on·the7779 ·································session·key·of·the·is·renegotiated,·both·in·terms·of··limit·based·on·the
7780 ···········Force·frequent········amount·of·data·that·may·be·transmitted·and·the·time···amount·of·data·and7780 ···········Force·frequent········amount·of·data·that·may·be·transmitted·and·the·time···amount·of·data·and
7781 ········N/·session·key···········elapsed.··············································enabling·time-based·var_rekey_limit_time=1hour7781 ········N/·session·key···········elapsed.··············································enabling·time-based·var_rekey_limit_size=1G
7782 ········A··renegotiation·········To·decrease·the·default·limits,·add·or·correct·the····limit,·effects·of···var_rekey_limit_size=1G7782 ········A··renegotiation·········To·decrease·the·default·limits,·add·or·correct·the····limit,·effects·of···var_rekey_limit_time=1hour
7783 ·································following·line·in·/etc/ssh/sshd_config:···············potential·attacks7783 ·································following·line·in·/etc/ssh/sshd_config:···············potential·attacks
7784 ·································RekeyLimit·1G·1hour···································against·encryption7784 ·································RekeyLimit·1G·1hour···································against·encryption
7785 ·······················································································keys·are·limited.7785 ·······················································································keys·are·limited.
7786 ·······················································································SSH·implementation7786 ·······················································································SSH·implementation
7787 ·······················································································in·Oracle·Linux·87787 ·······················································································in·Oracle·Linux·8
7788 ·······················································································uses·the·openssl7788 ·······················································································uses·the·openssl
7789 ·······················································································library,·which7789 ·······················································································library,·which
9.77 MB
./usr/share/doc/ssg-nondebian/table-ol8-nistrefs.html
    
Offset 66, 15742 lines modifiedOffset 66, 15742 lines modified
00000410:·0a20·2020·203c·7468·3e52·6174·696f·6e61··.····<th>Rationa00000410:·0a20·2020·203c·7468·3e52·6174·696f·6e61··.····<th>Rationa
00000420:·6c65·3c2f·7468·3e0a·2020·3c2f·7468·6561··le</th>.··</thea00000420:·6c65·3c2f·7468·3e0a·2020·3c2f·7468·6561··le</th>.··</thea
00000430:·643e·0a20·203c·7462·6f64·793e·0a20·203c··d>.··<tbody>.··<00000430:·643e·0a20·203c·7462·6f64·793e·0a20·203c··d>.··<tbody>.··<
00000440:·7472·3e0a·2020·2020·2020·3c74·643e·4155··tr>.······<td>AU00000440:·7472·3e0a·2020·2020·2020·3c74·643e·4155··tr>.······<td>AU
00000450:·2d32·2861·293c·2f74·643e·0a20·2020·2020··-2(a)</td>.·····00000450:·2d32·2861·293c·2f74·643e·0a20·2020·2020··-2(a)</td>.·····
00000460:·203c·7464·3e43·6f6e·6669·6775·7265·2061···<td>Configure·a00000460:·203c·7464·3e43·6f6e·6669·6775·7265·2061···<td>Configure·a
Diff chunk too large, falling back to line-by-line diff (1453 lines added, 1453 lines removed)
00000470:·7564·6974·696e·6720·6f66·2073·7563·6365··uditing·of·succe00000470:·7564·6974·696e·6720·6f66·2073·7563·6365··uditing·of·succe
00000480:·7373·6675·6c20·6669·6c65·2063·7265·6174··ssful·file·creat00000480:·7373·6675·6c20·6669·6c65·2061·6363·6573··ssful·file·acces
00000490:·696f·6e73·2028·4141·7263·6836·3429·3c2f··ions·(AArch64)</00000490:·7365·7320·2870·7063·3634·6c65·293c·2f74··ses·(ppc64le)</t
000004a0:·7464·3e0a·2020·2020·2020·3c74·6420·786d··td>.······<td·xm000004a0:·643e·0a20·2020·2020·203c·7464·2078·6d6c··d>.······<td·xml
000004b0:·6c3a·6c61·6e67·3d22·656e·2d55·5322·3e0a··l:lang="en-US">.000004b0:·3a6c·616e·673d·2265·6e2d·5553·223e·0a20··:lang="en-US">.·
000004c0:·2020·2020·2020·2020·456e·7375·7265·2074··········Ensure·t000004c0:·2020·2020·2020·2045·6e73·7572·6520·7468·········Ensure·th
000004d0:·6861·7420·7375·6363·6573·7366·756c·2061··hat·successful·a000004d0:·6174·2073·7563·6365·7373·6675·6c20·6174··at·successful·at
000004e0:·7474·656d·7074·7320·746f·2063·7265·6174··ttempts·to·creat000004e0:·7465·6d70·7473·2074·6f20·6163·6365·7373··tempts·to·access
000004f0:·6520·6120·6669·6c65·2061·7265·2061·7564··e·a·file·are·aud000004f0:·2061·2066·696c·6520·6172·6520·6175·6469···a·file·are·audi
00000500:·6974·6564·2e0a·0a54·6865·2066·6f6c·6c6f··ited...The·follo00000500:·7465·642e·0a0a·5468·6520·666f·6c6c·6f77··ted...The·follow
00000510:·7769·6e67·2072·756c·6573·2063·6f6e·6669··wing·rules·confi00000510:·696e·6720·7275·6c65·7320·636f·6e66·6967··ing·rules·config
00000520:·6775·7265·2061·7564·6974·2061·7320·6465··gure·audit·as·de00000520:·7572·6520·6175·6469·7420·6173·2064·6573··ure·audit·as·des
00000530:·7363·7269·6265·6420·6162·6f76·653a·0a3c··scribed·above:.<00000530:·6372·6962·6564·2061·626f·7665·3a0a·3c70··cribed·above:.<p
00000540:·7072·653e·2323·2053·7563·6365·7373·6675··pre>##·Successfu00000540:·7265·3e23·2320·5375·6363·6573·7366·756c··re>##·Successful
00000550:·6c20·6669·6c65·2063·7265·6174·696f·6e20··l·file·creation·00000550:·2066·696c·6520·6163·6365·7373·2028·616e···file·access·(an
00000560:·286f·7065·6e20·7769·7468·204f·5f43·5245··(open·with·O_CRE00000560:·7920·6f74·6865·7220·6f70·656e·7329·2054··y·other·opens)·T
00000570:·4154·290a·2d61·2061·6c77·6179·732c·6578··AT).-a·always,ex00000570:·6869·7320·6861·7320·746f·2067·6f20·6c61··his·has·to·go·la
00000580:·6974·202d·4620·6172·6368·3d62·3332·202d··it·-F·arch=b32·-00000580:·7374·2e0a·2323·2054·6865·7365·206e·6578··st..##·These·nex
00000590:·5320·6f70·656e·6174·2c6f·7065·6e5f·6279··S·openat,open_by00000590:·7420·7477·6f20·6172·6520·6c69·6b65·6c79··t·two·are·likely
000005a0:·5f68·616e·646c·655f·6174·202d·4620·6132··_handle_at·-F·a2000005a0:·2074·6f20·7265·7375·6c74·2069·6e20·6120···to·result·in·a·
000005b0:·2661·6d70·3b30·3130·3020·2d46·2073·7563··&amp;0100·-F·suc000005b0:·7768·6f6c·6520·6c6f·7420·6f66·2065·7665··whole·lot·of·eve
000005c0:·6365·7373·3d31·202d·4620·6175·6964·3e3d··cess=1·-F·auid>=000005c0:·6e74·730a·2d61·2061·6c77·6179·732c·6578··nts.-a·always,ex
000005d0:·3130·3030·202d·4620·6175·6964·213d·756e··1000·-F·auid!=un000005d0:·6974·202d·4620·6172·6368·3d62·3634·202d··it·-F·arch=b64·-
000005e0:·7365·7420·2d46·206b·6579·3d73·7563·6365··set·-F·key=succe000005e0:·5320·6f70·656e·2c6f·7065·6e61·742c·6f70··S·open,openat,op
000005f0:·7373·6675·6c2d·6372·6561·7465·0a2d·6120··ssful-create.-a·000005f0:·656e·6174·322c·6f70·656e·5f62·795f·6861··enat2,open_by_ha
00000600:·616c·7761·7973·2c65·7869·7420·2d46·2061··always,exit·-F·a00000600:·6e64·6c65·5f61·7420·2d46·2073·7563·6365··ndle_at·-F·succe
00000610:·7263·683d·6236·3420·2d53·206f·7065·6e61··rch=b64·-S·opena00000610:·7373·3d31·202d·4620·6175·6964·3e3d·3130··ss=1·-F·auid>=10
00000620:·742c·6f70·656e·5f62·795f·6861·6e64·6c65··t,open_by_handle00000620:·3030·202d·4620·6175·6964·213d·756e·7365··00·-F·auid!=unse
00000630:·5f61·7420·2d46·2061·3226·616d·703b·3031··_at·-F·a2&amp;0100000630:·7420·2d46·206b·6579·3d73·7563·6365·7373··t·-F·key=success
00000640:·3030·202d·4620·7375·6363·6573·733d·3120··00·-F·success=1·00000640:·6675·6c2d·6163·6365·7373·2020·2020·3c2f··ful-access····</
00000650:·2d46·2061·7569·643e·3d31·3030·3020·2d46··-F·auid>=1000·-F00000650:·7072·653e·0a0a·4c6f·6164·206e·6577·2041··pre>..Load·new·A
00000660:·2061·7569·6421·3d75·6e73·6574·202d·4620···auid!=unset·-F·00000660:·7564·6974·2072·756c·6573·2069·6e74·6f20··udit·rules·into·
00000670:·6b65·793d·7375·6363·6573·7366·756c·2d63··key=successful-c00000670:·6b65·726e·656c·2062·7920·7275·6e6e·696e··kernel·by·runnin
00000680:·7265·6174·650a·2d61·2061·6c77·6179·732c··reate.-a·always,00000680:·673a·0a3c·7072·653e·6175·6765·6e72·756c··g:.<pre>augenrul
00000690:·6578·6974·202d·4620·6172·6368·3d62·3332··exit·-F·arch=b3200000690:·6573·202d·2d6c·6f61·643c·2f70·7265·3e0a··es·--load</pre>.
000006a0:·202d·5320·6f70·656e·202d·4620·6131·2661···-S·open·-F·a1&a000006a0:·0a4e·6f74·653a·2054·6869·7320·7275·6c65··.Note:·This·rule
000006b0:·6d70·3b30·3130·3020·2d46·2073·7563·6365··mp;0100·-F·succe000006b0:·2075·7365·7320·6120·7370·6563·6961·6c20···uses·a·special·
000006c0:·7373·3d31·202d·4620·6175·6964·3e3d·3130··ss=1·-F·auid>=10000006c0:·7365·7420·6f66·2041·7564·6974·2072·756c··set·of·Audit·rul
000006d0:·3030·202d·4620·6175·6964·213d·756e·7365··00·-F·auid!=unse000006d0:·6573·2074·6f20·636f·6d70·6c79·2077·6974··es·to·comply·wit
000006e0:·7420·2d46·206b·6579·3d73·7563·6365·7373··t·-F·key=success000006e0:·6820·4f53·5050·2034·2e32·2e31·2e20·596f··h·OSPP·4.2.1.·Yo
000006f0:·6675·6c2d·6372·6561·7465·0a2d·6120·616c··ful-create.-a·al000006f0:·7520·6d61·7920·7265·7573·6520·7468·6973··u·may·reuse·this
00000700:·7761·7973·2c65·7869·7420·2d46·2061·7263··ways,exit·-F·arc00000700:·2072·756c·6520·696e·2064·6966·6665·7265···rule·in·differe
00000710:·683d·6233·3220·2d53·2063·7265·6174·202d··h=b32·-S·creat·-00000710:·6e74·2070·726f·6669·6c65·732e·2049·6620··nt·profiles.·If·
00000720:·4620·7375·6363·6573·733d·3120·2d46·2061··F·success=1·-F·a00000720:·796f·7520·6465·6369·6465·2074·6f20·646f··you·decide·to·do
00000730:·7569·643e·3d31·3030·3020·2d46·2061·7569··uid>=1000·-F·aui00000730:·2073·6f2c·2069·7420·6973·2072·6563·6f6d···so,·it·is·recom
00000740:·6421·3d75·6e73·6574·202d·4620·6b65·793d··d!=unset·-F·key=00000740:·6d65·6e64·6564·2074·6861·7420·796f·7520··mended·that·you·
00000750:·7375·6363·6573·7366·756c·2d63·7265·6174··successful-creat00000750:·696e·7370·6563·7420·636f·6e74·656e·7473··inspect·contents
00000760:·6520·2020·203c·2f70·7265·3e0a·0a4c·6f61··e····</pre>..Loa00000760:·206f·6620·7468·6520·6669·6c65·2063·6c6f···of·the·file·clo
00000770:·6420·6e65·7720·4175·6469·7420·7275·6c65··d·new·Audit·rule00000770:·7365·6c79·2061·6e64·206d·616b·6520·7375··sely·and·make·su
00000780:·7320·696e·746f·206b·6572·6e65·6c20·6279··s·into·kernel·by00000780:·7265·2074·6861·7420·7468·6579·2061·7265··re·that·they·are
00000790:·2072·756e·6e69·6e67·3a0a·3c70·7265·3e61···running:.<pre>a00000790:·2061·6c6c·6967·6e65·6420·7769·7468·2079···alligned·with·y
000007a0:·7567·656e·7275·6c65·7320·2d2d·6c6f·6164··ugenrules·--load000007a0:·6f75·7220·6e65·6564·732e·0a20·2020·2020··our·needs..·····
000007b0:·3c2f·7072·653e·0a0a·4e6f·7465·3a20·5468··</pre>..Note:·Th000007b0:·203c·2f74·643e·0a20·2020·2020·203c·7464···</td>.······<td
000007c0:·6973·2072·756c·6520·7573·6573·2061·2073··is·rule·uses·a·s000007c0:·2078·6d6c·3a6c·616e·673d·2265·6e2d·5553···xml:lang="en-US
000007d0:·7065·6369·616c·2073·6574·206f·6620·4175··pecial·set·of·Au000007d0:·223e·0a20·2020·2020·2020·2041·7564·6974··">.········Audit
000007e0:·6469·7420·7275·6c65·7320·746f·2063·6f6d··dit·rules·to·com000007e0:·696e·6720·6f66·2073·7563·6365·7373·6675··ing·of·successfu
000007f0:·706c·7920·7769·7468·204f·5350·5020·342e··ply·with·OSPP·4.000007f0:·6c20·6174·7465·6d70·7473·2074·6f20·6163··l·attempts·to·ac
00000800:·322e·312e·2059·6f75·206d·6179·2072·6575··2.1.·You·may·reu00000800:·6365·7373·2061·2066·696c·6520·6865·6c70··cess·a·file·help
00000810:·7365·2074·6869·7320·7275·6c65·2069·6e20··se·this·rule·in·00000810:·7320·696e·2069·6e76·6573·7469·6761·7469··s·in·investigati
00000820:·6469·6666·6572·656e·7420·7072·6f66·696c··different·profil00000820:·6f6e·206f·6620·6163·7469·7669·7469·6573··on·of·activities
00000830:·6573·2e20·4966·2079·6f75·2064·6563·6964··es.·If·you·decid00000830:·2070·6572·666f·726d·6564·206f·6e20·7468···performed·on·th
00000840:·6520·746f·2064·6f20·736f·2c20·6974·2069··e·to·do·so,·it·i00000840:·6520·7379·7374·656d·2e0a·2020·2020·2020··e·system..······
00000850:·7320·7265·636f·6d6d·656e·6465·6420·7468··s·recommended·th00000850:·3c2f·7464·3e0a·2020·2020·3c2f·7472·3e0a··</td>.····</tr>.
00000860:·6174·2079·6f75·2069·6e73·7065·6374·2063··at·you·inspect·c00000860:·2020·2020·3c74·723e·0a20·2020·2020·203c······<tr>.······<
00000870:·6f6e·7465·6e74·7320·6f66·2074·6865·2066··ontents·of·the·f00000870:·7464·3e41·552d·3228·6429·3c62·722f·3e41··td>AU-2(d)<br/>A
00000880:·696c·6520·636c·6f73·656c·7920·616e·6420··ile·closely·and·00000880:·552d·3132·2863·293c·6272·2f3e·4143·2d36··U-12(c)<br/>AC-6
00000890:·6d61·6b65·2073·7572·6520·7468·6174·2074··make·sure·that·t00000890:·2839·293c·6272·2f3e·434d·2d36·2861·293c··(9)<br/>CM-6(a)<
000008a0:·6865·7920·6172·6520·616c·6c69·676e·6564··hey·are·alligned000008a0:·2f74·643e·0a20·2020·2020·203c·7464·3e45··/td>.······<td>E
000008b0:·2077·6974·6820·796f·7572·206e·6565·6473···with·your·needs000008b0:·6e73·7572·6520·6175·6469·7464·2043·6f6c··nsure·auditd·Col
000008c0:·2e0a·2020·2020·2020·3c2f·7464·3e0a·2020··..······</td>.··000008c0:·6c65·6374·7320·496e·666f·726d·6174·696f··lects·Informatio
000008d0:·2020·2020·3c74·6420·786d·6c3a·6c61·6e67······<td·xml:lang000008d0:·6e20·6f6e·204b·6572·6e65·6c20·4d6f·6475··n·on·Kernel·Modu
000008e0:·3d22·656e·2d55·5322·3e0a·2020·2020·2020··="en-US">.······000008e0:·6c65·2055·6e6c·6f61·6469·6e67·202d·2064··le·Unloading·-·d
000008f0:·2020·4175·6469·7469·6e67·206f·6620·7375····Auditing·of·su000008f0:·656c·6574·655f·6d6f·6475·6c65·3c2f·7464··elete_module</td
00000900:·6363·6573·7366·756c·2061·7474·656d·7074··ccessful·attempt00000900:·3e0a·2020·2020·2020·3c74·6420·786d·6c3a··>.······<td·xml:
00000910:·7320·746f·2063·7265·6174·6520·6120·6669··s·to·create·a·fi00000910:·6c61·6e67·3d22·656e·2d55·5322·3e0a·2020··lang="en-US">.··
00000920:·6c65·2068·656c·7073·2069·6e20·696e·7665··le·helps·in·inve00000920:·2020·2020·2020·546f·2063·6170·7475·7265········To·capture
00000930:·7374·6967·6174·696f·6e20·6f66·2061·6374··stigation·of·act00000930:·206b·6572·6e65·6c20·6d6f·6475·6c65·2075···kernel·module·u
00000940:·696f·6e73·2077·6869·6368·2068·6170·7065··ions·which·happe00000940:·6e6c·6f61·6469·6e67·2065·7665·6e74·732c··nloading·events,
00000950:·6e65·6420·6f6e·2074·6865·2073·7973·7465··ned·on·the·syste00000950:·2075·7365·2066·6f6c·6c6f·7769·6e67·206c···use·following·l
00000960:·6d2e·0a20·2020·2020·203c·2f74·643e·0a20··m..······</td>.·00000960:·696e·652c·2073·6574·7469·6e67·2041·5243··ine,·setting·ARC
00000970:·2020·203c·2f74·723e·0a20·2020·203c·7472·····</tr>.····<tr00000970:·4820·746f·0a65·6974·6865·7220·6233·3220··H·to.either·b32·
00000980:·3e0a·2020·2020·2020·3c74·643e·4155·2d32··>.······<td>AU-200000980:·666f·7220·3332·2d62·6974·2073·7973·7465··for·32-bit·syste
00000990:·2861·293c·2f74·643e·0a20·2020·2020·203c··(a)</td>.······<00000990:·6d2c·206f·7220·6861·7669·6e67·2074·776f··m,·or·having·two
000009a0:·7464·3e43·6f6e·6669·6775·7265·2061·7564··td>Configure·aud000009a0:·206c·696e·6573·2066·6f72·2062·6f74·6820···lines·for·both·
000009b0:·6974·696e·6720·6f66·2075·6e73·7563·6365··iting·of·unsucce000009b0:·6233·3220·616e·6420·6236·3420·696e·2063··b32·and·b64·in·c
000009c0:·7373·6675·6c20·6669·6c65·2063·7265·6174··ssful·file·creat000009c0:·6173·6520·796f·7572·2073·7973·7465·6d20··ase·your·system·
000009d0:·696f·6e73·3c2f·7464·3e0a·2020·2020·2020··ions</td>.······000009d0:·6973·2036·342d·6269·743a·0a0a·3c70·7265··is·64-bit:..<pre
000009e0:·3c74·6420·786d·6c3a·6c61·6e67·3d22·656e··<td·xml:lang="en000009e0:·3e2d·6120·616c·7761·7973·2c65·7869·7420··>-a·always,exit·
000009f0:·2d55·5322·3e0a·2020·2020·2020·2020·456e··-US">.········En000009f0:·2d46·2061·7263·683d·3c69·3e41·5243·483c··-F·arch=<i>ARCH<
00000a00:·7375·7265·2074·6861·7420·756e·7375·6363··sure·that·unsucc00000a00:·2f69·3e20·2d53·2064·656c·6574·655f·6d6f··/i>·-S·delete_mo
00000a10:·6573·7366·756c·2061·7474·656d·7074·7320··essful·attempts·00000a10:·6475·6c65·202d·4620·6175·6964·3e3d·3130··dule·-F·auid>=10
00000a20:·746f·2063·7265·6174·6520·6120·6669·6c65··to·create·a·file00000a20:·3030·202d·4620·6175·6964·213d·756e·7365··00·-F·auid!=unse
00000a30:·2061·7265·2061·7564·6974·6564·2e0a·0a54···are·audited...T00000a30:·7420·2d46·206b·6579·3d6d·6f64·756c·6573··t·-F·key=modules
00000a40:·6865·2066·6f6c·6c6f·7769·6e67·2072·756c··he·following·rul00000a40:·3c2f·7072·653e·0a0a·0a50·6c61·6365·2074··</pre>...Place·t
00000a50:·6573·2063·6f6e·6669·6775·7265·2061·7564··es·configure·aud00000a50:·6f20·6164·6420·7468·6520·6c69·6e65·2064··o·add·the·line·d
00000a60:·6974·2061·7320·6465·7363·7269·6265·6420··it·as·described·00000a60:·6570·656e·6473·206f·6e20·6120·7761·7920··epends·on·a·way·
00000a70:·6162·6f76·653a·0a3c·7072·653e·2323·2055··above:.<pre>##·U00000a70:·3c74·743e·6175·6469·7464·3c2f·7474·3e20··<tt>auditd</tt>·
00000a80:·6e73·7563·6365·7373·6675·6c20·6669·6c65··nsuccessful·file00000a80:·6461·656d·6f6e·2069·7320·636f·6e66·6967··daemon·is·config
00000a90:·2063·7265·6174·696f·6e20·286f·7065·6e20···creation·(open·00000a90:·7572·6564·2e20·4966·2069·7420·6973·2063··ured.·If·it·is·c
00000aa0:·7769·7468·204f·5f43·5245·4154·290a·2d61··with·O_CREAT).-a00000aa0:·6f6e·6669·6775·7265·640a·746f·2075·7365··onfigured.to·use
00000ab0:·2061·6c77·6179·732c·6578·6974·202d·4620···always,exit·-F·00000ab0:·2074·6865·203c·7474·3e61·7567·656e·7275···the·<tt>augenru
00000ac0:·6172·6368·3d62·3332·202d·5320·6f70·656e··arch=b32·-S·open00000ac0:·6c65·733c·2f74·743e·2070·726f·6772·616d··les</tt>·program
00000ad0:·6174·2c6f·7065·6e5f·6279·5f68·616e·646c··at,open_by_handl00000ad0:·2028·7468·6520·6465·6661·756c·7429·2c20···(the·default),·
00000ae0:·655f·6174·202d·4620·6132·2661·6d70·3b30··e_at·-F·a2&amp;000000ae0:·6164·6420·7468·6520·6c69·6e65·2074·6f20··add·the·line·to·
00000af0:·3130·3020·2d46·2065·7869·743d·2d45·4143··100·-F·exit=-EAC00000af0:·6120·6669·6c65·2077·6974·6820·7375·6666··a·file·with·suff
00000b00:·4345·5320·2d46·2061·7569·6426·6774·3b3d··CES·-F·auid&gt;=00000b00:·6978·0a3c·7474·3e2e·7275·6c65·733c·2f74··ix.<tt>.rules</t
00000b10:·3130·3030·202d·4620·6175·6964·213d·756e··1000·-F·auid!=un00000b10:·743e·2069·6e20·7468·6520·6469·7265·6374··t>·in·the·direct
00000b20:·7365·7420·2d46·206b·6579·3d75·6e73·7563··set·-F·key=unsuc00000b20:·6f72·7920·3c74·743e·2f65·7463·2f61·7564··ory·<tt>/etc/aud
00000b30:·6365·7373·6675·6c2d·6372·6561·7465·0a2d··cessful-create.-00000b30:·6974·2f72·756c·6573·2e64·3c2f·7474·3e2e··it/rules.d</tt>.
00000b40:·6120·616c·7761·7973·2c65·7869·7420·2d46··a·always,exit·-F00000b40:·0a0a·4966·2074·6865·203c·7474·3e61·7564··..If·the·<tt>aud
00000b50:·2061·7263·683d·6236·3420·2d53·206f·7065···arch=b64·-S·ope00000b50:·6974·643c·2f74·743e·2064·6165·6d6f·6e20··itd</tt>·daemon·
00000b60:·6e61·742c·6f70·656e·5f62·795f·6861·6e64··nat,open_by_hand00000b60:·6973·2063·6f6e·6669·6775·7265·6420·746f··is·configured·to
00000b70:·6c65·5f61·7420·2d46·2061·3226·616d·703b··le_at·-F·a2&amp;00000b70:·2075·7365·2074·6865·203c·7474·3e61·7564···use·the·<tt>aud
00000b80:·3031·3030·202d·4620·6578·6974·3d2d·4541··0100·-F·exit=-EA00000b80:·6974·6374·6c3c·2f74·743e·2075·7469·6c69··itctl</tt>·utili
00000b90:·4343·4553·202d·4620·6175·6964·2667·743b··CCES·-F·auid&gt;00000b90:·7479·2c0a·6164·6420·7468·6520·6c69·6e65··ty,.add·the·line
00000ba0:·3d31·3030·3020·2d46·2061·7569·6421·3d75··=1000·-F·auid!=u00000ba0:·2074·6f20·6669·6c65·203c·7474·3e2f·6574···to·file·<tt>/et
00000bb0:·6e73·6574·202d·4620·6b65·793d·756e·7375··nset·-F·key=unsu00000bb0:·632f·6175·6469·742f·6175·6469·742e·7275··c/audit/audit.ru
00000bc0:·6363·6573·7366·756c·2d63·7265·6174·650a··ccessful-create.00000bc0:·6c65·733c·2f74·743e·2e0a·2020·2020·2020··les</tt>..······
00000bd0:·2d61·2061·6c77·6179·732c·6578·6974·202d··-a·always,exit·-00000bd0:·3c2f·7464·3e0a·2020·2020·2020·3c74·6420··</td>.······<td·
00000be0:·4620·6172·6368·3d62·3332·202d·5320·6f70··F·arch=b32·-S·op00000be0:·786d·6c3a·6c61·6e67·3d22·656e·2d55·5322··xml:lang="en-US"
Max diff block lines reached; 7320120/7521212 bytes (97.33%) of diff not shown.
2.6 MB
html2text {}
    
Offset 1, 30 lines modifiedOffset 1, 97 lines modified
  
  
1 Rules·with·NIST-800-53·Reference·in·Guide·to·the·Secure·Configuration·of·Oracle1 Rules·with·NIST-800-53·Reference·in·Guide·to·the·Secure·Configuration·of·Oracle
2 Linux·82 Linux·8
  
  
3 ·······························Ensure·that·successful·attempts·to·create·a·file·are·audited.·The·following·rules3 ·······························Ensure·that·successful·attempts·to·access·a·file·are·audited.·The·following·rules
4 ·······························configure·audit·as·described·above:4 ·······························configure·audit·as·described·above:
5 ·······························##·Successful·file·creation·(open·with·O_CREAT) 
6 ·······························-a·always,exit·-F·arch=b32·-S·openat,open_by_handle_at·-F·a2&0100·-F·success=1·- 
7 ·······························F·auid>=1000·-F·auid!=unset·-F·key=successful-create5 ·······························##·Successful·file·access·(any·other·opens)·This·has·to·go·last.
 6 ·······························##·These·next·two·are·likely·to·result·in·a·whole·lot·of·events··························Auditing·of·successful
 7 ········Configure·auditing·of··-a·always,exit·-F·arch=b64·-S·open,openat,openat2,open_by_handle_at·-F·success=1·-·······attempts·to·access·a
 8 AU-2(a)·successful·file········F·auid>=1000·-F·auid!=unset·-F·key=successful-access·····································file·helps·in
 9 ········accesses·(ppc64le)·····Load·new·Audit·rules·into·kernel·by·running:·············································investigation·of
 10 ·······························augenrules·--load········································································activities·performed·on
 11 ·······························Note:·This·rule·uses·a·special·set·of·Audit·rules·to·comply·with·OSPP·4.2.1.·You·may·····the·system.
 12 ·······························reuse·this·rule·in·different·profiles.·If·you·decide·to·do·so,·it·is·recommended·that
 13 ·······························you·inspect·contents·of·the·file·closely·and·make·sure·that·they·are·alligned·with·your
 14 ·······························needs.
 15 ························································································································The·removal·of·kernel
 16 ························································································································modules·can·be·used·to
 17 ·······························To·capture·kernel·module·unloading·events,·use·following·line,·setting·ARCH·to·either····alter·the·behavior·of
 18 AU-2(d)························b32·for·32-bit·system,·or·having·two·lines·for·both·b32·and·b64·in·case·your·system·is···the·kernel·and
 19 AU-12···Ensure·auditd·Collects·64-bit:··················································································potentially·introduce
 20 (c)·····Information·on·Kernel··-a·always,exit·-F·arch=ARCH·-S·delete_module·-F·auid>=1000·-F·auid!=unset·-F·key=modules·malicious·code·into
 21 AC-6(9)·Module·Unloading·-·····Place·to·add·the·line·depends·on·a·way·auditd·daemon·is·configured.·If·it·is·configured··kernel·space.·It·is
 22 CM-6(a)·delete_module··········to·use·the·augenrules·program·(the·default),·add·the·line·to·a·file·with·suffix·.rules···important·to·have·an
 23 ·······························in·the·directory·/etc/audit/rules.d.·If·the·auditd·daemon·is·configured·to·use·the·······audit·trail·of·modules
 24 ·······························auditctl·utility,·add·the·line·to·file·/etc/audit/audit.rules.···························that·have·been
 25 ························································································································introduced·into·the
 26 ························································································································kernel.
 27 ·······························Ensure·that·successful·attempts·to·access·a·file·are·audited.·The·following·rules
 28 ·······························configure·audit·as·described·above:
 29 ·······························##·Successful·file·access·(any·other·opens)·This·has·to·go·last.
 30 ·······························##·These·next·two·are·likely·to·result·in·a·whole·lot·of·events
8 ·······························-a·always,exit·-F·arch=b64·-S·openat,open_by_handle_at·-F·a2&0100·-F·success=1·-·········Auditing·of·successful31 ·······························-a·always,exit·-F·arch=b32·-S·open,openat,openat2,open_by_handle_at·-F·success=1·-·······Auditing·of·successful
9 ·······························F·auid>=1000·-F·auid!=unset·-F·key=successful-create·····································attempts·to·create·a32 ········Configure·auditing·of··F·auid>=1000·-F·auid!=unset·-F·key=successful-access·····································attempts·to·access·a
10 ········Configure·auditing·of··-a·always,exit·-F·arch=b32·-S·open·-F·a1&0100·-F·success=1·-F·auid>=1000·-F·auid!=unset··file·helps·in 
11 AU-2(a)·successful·file········-F·key=successful-create·································································investigation·of 
12 ········creations·(AArch64)····-a·always,exit·-F·arch=b32·-S·creat·-F·success=1·-F·auid>=1000·-F·auid!=unset·-··········actions·which·happened33 AU-2(a)·successful·file········-a·always,exit·-F·arch=b64·-S·openat,openat2,open_by_handle_at·-F·success=1·-············file·helps·in
 34 ········accesses·(AArch64)·····F·auid>=1000·-F·auid!=unset·-F·key=successful-access·····································investigation·of
 35 ·······························Load·new·Audit·rules·into·kernel·by·running:·············································activities·performed·on
13 ·······························F·key=successful-create··································································on·the·system.36 ·······························augenrules·--load········································································the·system.
14 ·······························Load·new·Audit·rules·into·kernel·by·running: 
15 ·······························augenrules·--load 
16 ·······························Note:·This·rule·uses·a·special·set·of·Audit·rules·to·comply·with·OSPP·4.2.1.·You·may37 ·······························Note:·This·rule·uses·a·special·set·of·Audit·rules·to·comply·with·OSPP·4.2.1.·You·may
17 ·······························reuse·this·rule·in·different·profiles.·If·you·decide·to·do·so,·it·is·recommended·that38 ·······························reuse·this·rule·in·different·profiles.·If·you·decide·to·do·so,·it·is·recommended·that
18 ·······························you·inspect·contents·of·the·file·closely·and·make·sure·that·they·are·alligned·with·your39 ·······························you·inspect·contents·of·the·file·closely·and·make·sure·that·they·are·alligned·with·your
19 ·······························needs.40 ·······························needs.
 41 ························································································································Misuse·of·privileged
 42 ························································································································functions,·either
 43 ························································································································intentionally·or
 44 ························································································································unintentionally·by
 45 ························································································································authorized·users,·or·by
 46 ························································································································unauthorized·external
 47 ························································································································entities·that·have
 48 ························································································································compromised·system
 49 ························································································································accounts,·is·a·serious
 50 ························································································································and·ongoing·concern·and
 51 ·······························At·a·minimum,·the·audit·system·should·collect·the·execution·of·privileged·commands·for···can·have·significant
 52 ·······························all·users·and·root.·If·the·auditd·daemon·is·configured·to·use·the·augenrules·program·to··adverse·impacts·on
 53 ·······························read·audit·rules·during·daemon·startup·(the·default),·add·a·line·of·the·following·form···organizations.·Auditing
 54 AU-2(d)·Ensure·auditd·Collects·to·a·file·with·suffix·.rules·in·the·directory·/etc/audit/rules.d:························the·use·of·privileged
 55 AU-12···Information·on·the·Use·-a·always,exit·-F·path=/usr/sbin/postdrop·-F·perm=x·-F·auid>=1000·-F·auid!=unset·-·······functions·is·one·way·to
 56 (c)·····of·Privileged·Commands·F·key=privileged·········································································detect·such·misuse·and
 57 AC-6(9)·-·postdrop·············If·the·auditd·daemon·is·configured·to·use·the·auditctl·utility·to·read·audit·rules·······identify·the·risk·from
 58 CM-6(a)························during·daemon·startup,·add·a·line·of·the·following·form·to·/etc/audit/audit.rules:·······insider·and·advanced
 59 ·······························-a·always,exit·-F·path=/usr/sbin/postdrop·-F·perm=x·-F·auid>=1000·-F·auid!=unset·-·······persistent·threats.
 60 ·······························F·key=privileged
 61 ························································································································Privileged·programs·are
 62 ························································································································subject·to·escalation-
 63 ························································································································of-privilege·attacks,
 64 ························································································································which·attempt·to
 65 ························································································································subvert·their·normal
 66 ························································································································role·of·providing·some
 67 ························································································································necessary·but·limited
 68 ························································································································capability.·As·such,
 69 ························································································································motivation·exists·to
 70 ························································································································monitor·these·programs
 71 ························································································································for·unusual·activity.
 72 ·······························The·audit·system·should·collect·unsuccessful·file·deletion·attempts·for·all·users·and
 73 ·······························root.·If·the·auditd·daemon·is·configured·to·use·the·augenrules·program·to·read·audit
 74 ·······························rules·during·daemon·startup·(the·default),·add·the·following·lines·to·a·file·with·suffix
 75 ·······························.rules·in·the·directory·/etc/audit/rules.d.·If·the·auditd·daemon·is·configured·to·use····Unsuccessful·attempts
 76 ·······························the·auditctl·utility·to·read·audit·rules·during·daemon·startup,·add·the·following·lines··to·delete·files·could
 77 AU-2(d)························to·/etc/audit/audit.rules·file.··························································be·an·indicator·of
 78 AU-12···Record·Unsuccessful····-a·always,exit·-F·arch=b32·-S·unlink·-F·exit=-EACCES·-F·auid>=1000·-F·auid!=unset·-······malicious·activity·on·a
 79 (c)·····Delete·Attempts·to·····F·key=unsuccessful-delete································································system.·Auditing·these
 80 CM-6(a)·Files·-·unlink·········-a·always,exit·-F·arch=b32·-S·unlink·-F·exit=-EPERM·-F·auid>=1000·-F·auid!=unset·-·······events·could·serve·as
 81 ·······························F·key=unsuccessful-delete································································evidence·of·potential
 82 ·······························If·the·system·is·64·bit·then·also·add·the·following·lines:·······························system·compromise.
 83 ·······························-a·always,exit·-F·arch=b64·-S·unlink·-F·exit=-EACCES·-F·auid>=1000·-F·auid!=unset·-
 84 ·······························F·key=unsuccessful-delete
 85 ·······························-a·always,exit·-F·arch=b64·-S·unlink·-F·exit=-EPERM·-F·auid>=1000·-F·auid!=unset·-
 86 ·······························F·key=unsuccessful-delete
20 ·······························Ensure·that·unsuccessful·attempts·to·create·a·file·are·audited.·The·following·rules87 ·······························Ensure·that·unsuccessful·attempts·to·create·a·file·are·audited.·The·following·rules
21 ·······························configure·audit·as·described·above:88 ·······························configure·audit·as·described·above:
22 ·······························##·Unsuccessful·file·creation·(open·with·O_CREAT)89 ·······························##·Unsuccessful·file·creation·(open·with·O_CREAT)
23 ·······························-a·always,exit·-F·arch=b32·-S·openat,open_by_handle_at·-F·a2&0100·-F·exit=-EACCES·-90 ·······························-a·always,exit·-F·arch=b32·-S·openat,open_by_handle_at·-F·a2&0100·-F·exit=-EACCES·-
24 ·······························F·auid>=1000·-F·auid!=unset·-F·key=unsuccessful-create91 ·······························F·auid>=1000·-F·auid!=unset·-F·key=unsuccessful-create
25 ·······························-a·always,exit·-F·arch=b64·-S·openat,open_by_handle_at·-F·a2&0100·-F·exit=-EACCES·-92 ·······························-a·always,exit·-F·arch=b64·-S·openat,open_by_handle_at·-F·a2&0100·-F·exit=-EACCES·-
26 ·······························F·auid>=1000·-F·auid!=unset·-F·key=unsuccessful-create93 ·······························F·auid>=1000·-F·auid!=unset·-F·key=unsuccessful-create
Offset 50, 321 lines modifiedOffset 117, 114 lines modified
50 ·······························F·key=unsuccessful-create117 ·······························F·key=unsuccessful-create
51 ·······························Load·new·Audit·rules·into·kernel·by·running:118 ·······························Load·new·Audit·rules·into·kernel·by·running:
52 ·······························augenrules·--load119 ·······························augenrules·--load
53 ·······························Note:·This·rule·uses·a·special·set·of·Audit·rules·to·comply·with·OSPP·4.2.1.·You·may120 ·······························Note:·This·rule·uses·a·special·set·of·Audit·rules·to·comply·with·OSPP·4.2.1.·You·may
54 ·······························reuse·this·rule·in·different·profiles.·If·you·decide·to·do·so,·it·is·recommended·that121 ·······························reuse·this·rule·in·different·profiles.·If·you·decide·to·do·so,·it·is·recommended·that
55 ·······························you·inspect·contents·of·the·file·closely·and·make·sure·that·they·are·alligned·with·your122 ·······························you·inspect·contents·of·the·file·closely·and·make·sure·that·they·are·alligned·with·your
56 ·······························needs.123 ·······························needs.
 124 ·······························Configure·kernel·to·prevent·modification·of·login·UIDs·once·they·are·set.·Changing·login·If·modification·of
 125 ·······························UIDs·while·this·configuration·is·enforced·requires·special·capabilities·which·are·not····login·UIDs·is·not
 126 ········Configure·immutable····available·to·unprivileged·users.·The·following·rules·configure·audit·as·described·above:·prevented,·they·can·be
 127 AU-2(a)·Audit·login·UIDs·······##·Make·the·loginuid·immutable.·This·prevents·tampering·with·the·auid.···················changed·by·unprivileged
 128 ·······························--loginuid-immutable·····································································users·and·make·auditing
 129 ·······························Load·new·Audit·rules·into·kernel·by·running:·············································complicated·or
 130 ·······························augenrules·--load········································································impossible.
57 ························································································································Arbitrary·changes·to 
58 ·······························If·the·auditd·daemon·is·configured·to·use·the·augenrules·program·to·read·audit·rules·····the·system·time·can·be 
59 ·······························during·daemon·startup·(the·default),·add·the·following·line·to·a·file·with·suffix·.rules·used·to·obfuscate 
60 AU-2(d)························in·the·directory·/etc/audit/rules.d:·····················································nefarious·activities·in 
61 AU-12···Record·Attempts·to·····-w·/etc/localtime·-p·wa·-k·audit_time_rules··············································log·files,·as·well·as 
62 (c)·····Alter·the·localtime····If·the·auditd·daemon·is·configured·to·use·the·auditctl·utility·to·read·audit·rules·······to·confuse·network 
63 AC-6(9)·File···················during·daemon·startup,·add·the·following·line·to·/etc/audit/audit.rules·file:············services·that·are 
64 CM-6(a)························-w·/etc/localtime·-p·wa·-k·audit_time_rules··············································highly·dependent·upon 
65 ·······························The·-k·option·allows·for·the·specification·of·a·key·in·string·form·that·can·be·used·for··an·accurate·system·time 
Max diff block lines reached; 2707017/2723420 bytes (99.40%) of diff not shown.
790 KB
./usr/share/doc/ssg-nondebian/table-ol8-pcidssrefs.html
Ordering differences only
    
Offset 73, 28 lines modifiedOffset 73, 14 lines modified
73 is·the·only·place·that·loopback·network·traffic·should·be·seen,73 is·the·only·place·that·loopback·network·traffic·should·be·seen,
74 all·other·interfaces·should·ignore·traffic·on·this·network·as·an74 all·other·interfaces·should·ignore·traffic·on·this·network·as·an
75 anti-spoofing·measure.75 anti-spoofing·measure.
76 ······</td>76 ······</td>
77 ····</tr>77 ····</tr>
78 ····<tr>78 ····<tr>
79 ······<td>Req-1.3.1<br/>Req-1.3.2</td>79 ······<td>Req-1.3.1<br/>Req-1.3.2</td>
80 ······<td>Disable·Kernel·Parameter·for·IP·Forwarding·on·IPv4·Interfaces</td> 
81 ······<td·xml:lang="en-US"> 
82 ········To·set·the·runtime·status·of·the·<code>net.ipv4.ip_forward</code>·kernel·parameter,·run·the·following·command:·<pre>$·sudo·sysctl·-w·net.ipv4.ip_forward=0</pre> 
83 To·make·sure·that·the·setting·is·persistent,·add·the·following·line·to·a·file·in·the·directory·<tt>/etc/sysctl.d</tt>:·<pre>net.ipv4.ip_forward·=·0</pre> 
84 ······</td> 
85 ······<td·xml:lang="en-US"> 
86 ········Routing·protocol·daemons·are·typically·used·on·routers·to·exchange 
87 network·topology·information·with·other·routers.·If·this·capability·is·used·when 
88 not·required,·system·network·information·may·be·unnecessarily·transmitted·across 
89 the·network. 
90 ······</td> 
91 ····</tr> 
92 ····<tr> 
93 ······<td>Req-1.3.1<br/>Req-1.3.2</td> 
94 ······<td>Ensure·IPv6·is·disabled·through·kernel·boot·parameter</td>80 ······<td>Ensure·IPv6·is·disabled·through·kernel·boot·parameter</td>
95 ······<td·xml:lang="en-US">81 ······<td·xml:lang="en-US">
96 ········To·disable·IPv6·protocol·support·in·the·Linux·kernel,82 ········To·disable·IPv6·protocol·support·in·the·Linux·kernel,
97 add·the·argument·<tt>ipv6.disable=1</tt>·to·the·default83 add·the·argument·<tt>ipv6.disable=1</tt>·to·the·default
98 GRUB2·command·line·for·the·Linux·operating·system.84 GRUB2·command·line·for·the·Linux·operating·system.
99 To·ensure·that·<tt>ipv6.disable=1</tt>·is·added·as·a·kernel·command·line85 To·ensure·that·<tt>ipv6.disable=1</tt>·is·added·as·a·kernel·command·line
100 argument·to·newly·installed·kernels,·add·<tt>ipv6.disable=1</tt>·to·the86 argument·to·newly·installed·kernels,·add·<tt>ipv6.disable=1</tt>·to·the
Offset 105, 14 lines modifiedOffset 91, 28 lines modified
105 ······</td>91 ······</td>
106 ······<td·xml:lang="en-US">92 ······<td·xml:lang="en-US">
107 ········Any·unnecessary·network·stacks,·including·IPv6,·should·be·disabled·to·reduce93 ········Any·unnecessary·network·stacks,·including·IPv6,·should·be·disabled·to·reduce
108 the·vulnerability·to·exploitation.94 the·vulnerability·to·exploitation.
109 ······</td>95 ······</td>
110 ····</tr>96 ····</tr>
111 ····<tr>97 ····<tr>
 98 ······<td>Req-1.3.1<br/>Req-1.3.2</td>
 99 ······<td>Disable·Kernel·Parameter·for·IP·Forwarding·on·IPv4·Interfaces</td>
 100 ······<td·xml:lang="en-US">
 101 ········To·set·the·runtime·status·of·the·<code>net.ipv4.ip_forward</code>·kernel·parameter,·run·the·following·command:·<pre>$·sudo·sysctl·-w·net.ipv4.ip_forward=0</pre>
 102 To·make·sure·that·the·setting·is·persistent,·add·the·following·line·to·a·file·in·the·directory·<tt>/etc/sysctl.d</tt>:·<pre>net.ipv4.ip_forward·=·0</pre>
 103 ······</td>
 104 ······<td·xml:lang="en-US">
 105 ········Routing·protocol·daemons·are·typically·used·on·routers·to·exchange
 106 network·topology·information·with·other·routers.·If·this·capability·is·used·when
 107 not·required,·system·network·information·may·be·unnecessarily·transmitted·across
 108 the·network.
 109 ······</td>
 110 ····</tr>
 111 ····<tr>
112 ······<td>Req-1.3.3</td>112 ······<td>Req-1.3.3</td>
113 ······<td>Deactivate·Wireless·Network·Interfaces</td>113 ······<td>Deactivate·Wireless·Network·Interfaces</td>
114 ······<td·xml:lang="en-US">114 ······<td·xml:lang="en-US">
115 ········Deactivating·wireless·network·interfaces·should·prevent·normal·usage·of·the·wireless115 ········Deactivating·wireless·network·interfaces·should·prevent·normal·usage·of·the·wireless
116 capability.116 capability.
117 <br·/><br·/>117 <br·/><br·/>
  
Offset 246, 41 lines modifiedOffset 246, 25 lines modified
246 ······<td·xml:lang="en-US">246 ······<td·xml:lang="en-US">
247 ········Disabling·DCCP·protects247 ········Disabling·DCCP·protects
248 the·system·against·exploitation·of·any·flaws·in·its·implementation.248 the·system·against·exploitation·of·any·flaws·in·its·implementation.
249 ······</td>249 ······</td>
250 ····</tr>250 ····</tr>
251 ····<tr>251 ····<tr>
252 ······<td>Req-1.4.3</td>252 ······<td>Req-1.4.3</td>
 253 ······<td>Enable·Kernel·Parameter·to·Ignore·ICMP·Broadcast·Echo·Requests·on·IPv4·Interfaces</td>
253 ······<td>Disable·Kernel·Parameter·for·Accepting·ICMP·Redirects·by·Default·on·IPv4·Interfaces</td> 
254 ······<td·xml:lang="en-US"> 
255 ········To·set·the·runtime·status·of·the·<code>net.ipv4.conf.default.accept_redirects</code>·kernel·parameter,·run·the·following·command:·<pre>$·sudo·sysctl·-w·net.ipv4.conf.default.accept_redirects=0</pre> 
256 To·make·sure·that·the·setting·is·persistent,·add·the·following·line·to·a·file·in·the·directory·<tt>/etc/sysctl.d</tt>:·<pre>net.ipv4.conf.default.accept_redirects·=·0</pre> 
257 ······</td> 
258 ······<td·xml:lang="en-US"> 
259 ········ICMP·redirect·messages·are·used·by·routers·to·inform·hosts·that·a·more 
260 direct·route·exists·for·a·particular·destination.·These·messages·modify·the 
261 host's·route·table·and·are·unauthenticated.·An·illicit·ICMP·redirect 
262 message·could·result·in·a·man-in-the-middle·attack. 
263 <br·/>This·feature·of·the·IPv4·protocol·has·few·legitimate·uses.·It·should 
264 be·disabled·unless·absolutely·required. 
265 ······</td> 
266 ····</tr> 
267 ····<tr> 
268 ······<td>Req-1.4.3</td> 
269 ······<td>Enable·Kernel·Parameter·to·Use·Reverse·Path·Filtering·on·all·IPv4·Interfaces</td> 
270 ······<td·xml:lang="en-US">254 ······<td·xml:lang="en-US">
271 ········To·set·the·runtime·status·of·the·<code>net.ipv4.conf.all.rp_filter</code>·kernel·parameter,·run·the·following·command:·<pre>$·sudo·sysctl·-w·net.ipv4.conf.all.rp_filter=1</pre>255 ········To·set·the·runtime·status·of·the·<code>net.ipv4.icmp_echo_ignore_broadcasts</code>·kernel·parameter,·run·the·following·command:·<pre>$·sudo·sysctl·-w·net.ipv4.icmp_echo_ignore_broadcasts=1</pre>
272 To·make·sure·that·the·setting·is·persistent,·add·the·following·line·to·a·file·in·the·directory·<tt>/etc/sysctl.d</tt>:·<pre>net.ipv4.conf.all.rp_filter·=·1</pre>256 To·make·sure·that·the·setting·is·persistent,·add·the·following·line·to·a·file·in·the·directory·<tt>/etc/sysctl.d</tt>:·<pre>net.ipv4.icmp_echo_ignore_broadcasts·=·1</pre>
273 ······</td>257 ······</td>
274 ······<td·xml:lang="en-US">258 ······<td·xml:lang="en-US">
275 ········Enabling·reverse·path·filtering·drops·packets·with·source·addresses 
276 that·should·not·have·been·able·to·be·received·on·the·interface·they·were 
277 received·on.·It·should·not·be·used·on·systems·which·are·routers·for 
278 complicated·networks,·but·is·helpful·for·end·hosts·and·routers·serving·small 
279 networks.259 ········Responding·to·broadcast·(ICMP)·echoes·facilitates·network·mapping
 260 and·provides·a·vector·for·amplification·attacks.
 261 <br·/>
 262 Ignoring·ICMP·echo·requests·(pings)·sent·to·broadcast·or·multicast
 263 addresses·makes·the·system·slightly·more·difficult·to·enumerate·on·the·network.
280 ······</td>264 ······</td>
281 ····</tr>265 ····</tr>
282 ····<tr>266 ····<tr>
283 ······<td>Req-1.4.3</td>267 ······<td>Req-1.4.3</td>
284 ······<td>Disable·Kernel·Parameter·for·Accepting·Source-Routed·Packets·on·IPv6·Interfaces·by·Default</td>268 ······<td>Disable·Kernel·Parameter·for·Accepting·Source-Routed·Packets·on·IPv6·Interfaces·by·Default</td>
285 ······<td·xml:lang="en-US">269 ······<td·xml:lang="en-US">
286 ········To·set·the·runtime·status·of·the·<code>net.ipv6.conf.default.accept_source_route</code>·kernel·parameter,·run·the·following·command:·<pre>$·sudo·sysctl·-w·net.ipv6.conf.default.accept_source_route=0</pre>270 ········To·set·the·runtime·status·of·the·<code>net.ipv6.conf.default.accept_source_route</code>·kernel·parameter,·run·the·following·command:·<pre>$·sudo·sysctl·-w·net.ipv6.conf.default.accept_source_route=0</pre>
Offset 295, 37 lines modifiedOffset 279, 41 lines modified
  
295 Accepting·source-routed·packets·in·the·IPv6·protocol·has·few·legitimate279 Accepting·source-routed·packets·in·the·IPv6·protocol·has·few·legitimate
296 uses.·It·should·be·disabled·unless·it·is·absolutely·required.280 uses.·It·should·be·disabled·unless·it·is·absolutely·required.
297 ······</td>281 ······</td>
298 ····</tr>282 ····</tr>
299 ····<tr>283 ····<tr>
300 ······<td>Req-1.4.3</td>284 ······<td>Req-1.4.3</td>
301 ······<td>Enable·Kernel·Parameter·to·Ignore·Bogus·ICMP·Error·Responses·on·IPv4·Interfaces</td>285 ······<td>Disable·Kernel·Parameter·for·Accepting·ICMP·Redirects·by·Default·on·IPv4·Interfaces</td>
302 ······<td·xml:lang="en-US">286 ······<td·xml:lang="en-US">
303 ········To·set·the·runtime·status·of·the·<code>net.ipv4.icmp_ignore_bogus_error_responses</code>·kernel·parameter,·run·the·following·command:·<pre>$·sudo·sysctl·-w·net.ipv4.icmp_ignore_bogus_error_responses=1</pre>287 ········To·set·the·runtime·status·of·the·<code>net.ipv4.conf.default.accept_redirects</code>·kernel·parameter,·run·the·following·command:·<pre>$·sudo·sysctl·-w·net.ipv4.conf.default.accept_redirects=0</pre>
304 To·make·sure·that·the·setting·is·persistent,·add·the·following·line·to·a·file·in·the·directory·<tt>/etc/sysctl.d</tt>:·<pre>net.ipv4.icmp_ignore_bogus_error_responses·=·1</pre>288 To·make·sure·that·the·setting·is·persistent,·add·the·following·line·to·a·file·in·the·directory·<tt>/etc/sysctl.d</tt>:·<pre>net.ipv4.conf.default.accept_redirects·=·0</pre>
305 ······</td>289 ······</td>
306 ······<td·xml:lang="en-US">290 ······<td·xml:lang="en-US">
307 ········Ignoring·bogus·ICMP·error·responses·reduces 
308 log·size,·although·some·activity·would·not·be·logged.291 ········ICMP·redirect·messages·are·used·by·routers·to·inform·hosts·that·a·more
 292 direct·route·exists·for·a·particular·destination.·These·messages·modify·the
 293 host's·route·table·and·are·unauthenticated.·An·illicit·ICMP·redirect
 294 message·could·result·in·a·man-in-the-middle·attack.
 295 <br·/>This·feature·of·the·IPv4·protocol·has·few·legitimate·uses.·It·should
 296 be·disabled·unless·absolutely·required.
309 ······</td>297 ······</td>
310 ····</tr>298 ····</tr>
Max diff block lines reached; 300562/308298 bytes (97.49%) of diff not shown.
488 KB
html2text {}
    
Offset 34, 14 lines modifiedOffset 34, 26 lines modified
34 ····················································································network·traffic34 ····················································································network·traffic
35 ····················································································should·be·seen,·all35 ····················································································should·be·seen,·all
36 ····················································································other·interfaces36 ····················································································other·interfaces
37 ····················································································should·ignore37 ····················································································should·ignore
38 ····················································································traffic·on·this38 ····················································································traffic·on·this
39 ····················································································network·as·an·anti-39 ····················································································network·as·an·anti-
40 ····················································································spoofing·measure.40 ····················································································spoofing·measure.
 41 ·····························To·disable·IPv6·protocol·support·in·the·Linux·kernel,
 42 ·····························add·the·argument·ipv6.disable=1·to·the·default·GRUB2
 43 ·····························command·line·for·the·Linux·operating·system.·To·ensure·Any·unnecessary
 44 ·····························that·ipv6.disable=1·is·added·as·a·kernel·command·line··network·stacks,
 45 Req-·····Ensure·IPv6·is······argument·to·newly·installed·kernels,·add···············including·IPv6,
 46 1.3.1····disabled·through····ipv6.disable=1·to·the·default·Grub2·command·line·for···should·be·disabled
 47 Req-·····kernel·boot·········Linux·operating·systems.·Modify·the·line·within·/etc/··to·reduce·the
 48 1.3.2····parameter···········default/grub·as·shown·below:···························vulnerability·to
 49 ·····························GRUB_CMDLINE_LINUX="...·ipv6.disable=1·..."············exploitation.
 50 ·····························Run·the·following·command·to·update·command·line·for
 51 ·····························already·installed·kernels:
 52 ·····························#·grubby·--update-kernel=ALL·--args="ipv6.disable=1"
41 ····················································································Routing·protocol53 ····················································································Routing·protocol
42 ····················································································daemons·are54 ····················································································daemons·are
43 ····················································································typically·used·on55 ····················································································typically·used·on
44 ····················································································routers·to·exchange56 ····················································································routers·to·exchange
45 ·····························To·set·the·runtime·status·of·the·net.ipv4.ip_forward···network·topology57 ·····························To·set·the·runtime·status·of·the·net.ipv4.ip_forward···network·topology
46 Req-·····Disable·Kernel······kernel·parameter,·run·the·following·command:···········information·with58 Req-·····Disable·Kernel······kernel·parameter,·run·the·following·command:···········information·with
47 1.3.1····Parameter·for·IP····$·sudo·sysctl·-w·net.ipv4.ip_forward=0·················other·routers.·If59 1.3.1····Parameter·for·IP····$·sudo·sysctl·-w·net.ipv4.ip_forward=0·················other·routers.·If
Offset 49, 26 lines modifiedOffset 61, 14 lines modified
49 1.3.2····Interfaces··········following·line·to·a·file·in·the·directory·/etc/········used·when·not61 1.3.2····Interfaces··········following·line·to·a·file·in·the·directory·/etc/········used·when·not
50 ·····························sysctl.d:··············································required,·system62 ·····························sysctl.d:··············································required,·system
51 ·····························net.ipv4.ip_forward·=·0································network·information63 ·····························net.ipv4.ip_forward·=·0································network·information
52 ····················································································may·be64 ····················································································may·be
53 ····················································································unnecessarily65 ····················································································unnecessarily
54 ····················································································transmitted·across66 ····················································································transmitted·across
55 ····················································································the·network.67 ····················································································the·network.
56 ·····························To·disable·IPv6·protocol·support·in·the·Linux·kernel, 
57 ·····························add·the·argument·ipv6.disable=1·to·the·default·GRUB2 
58 ·····························command·line·for·the·Linux·operating·system.·To·ensure·Any·unnecessary 
59 ·····························that·ipv6.disable=1·is·added·as·a·kernel·command·line··network·stacks, 
60 Req-·····Ensure·IPv6·is······argument·to·newly·installed·kernels,·add···············including·IPv6, 
61 1.3.1····disabled·through····ipv6.disable=1·to·the·default·Grub2·command·line·for···should·be·disabled 
62 Req-·····kernel·boot·········Linux·operating·systems.·Modify·the·line·within·/etc/··to·reduce·the 
63 1.3.2····parameter···········default/grub·as·shown·below:···························vulnerability·to 
64 ·····························GRUB_CMDLINE_LINUX="...·ipv6.disable=1·..."············exploitation. 
65 ·····························Run·the·following·command·to·update·command·line·for 
66 ·····························already·installed·kernels: 
67 ·····························#·grubby·--update-kernel=ALL·--args="ipv6.disable=1" 
68 ····················································································The·use·of·wireless68 ····················································································The·use·of·wireless
69 ····················································································networking·can69 ····················································································networking·can
70 ····················································································introduce·many70 ····················································································introduce·many
71 ····················································································different·attack71 ····················································································different·attack
72 ····················································································vectors·into·the72 ····················································································vectors·into·the
73 ····················································································organization's73 ····················································································organization's
74 ····················································································network.·Common74 ····················································································network.·Common
Offset 187, 14 lines modifiedOffset 187, 61 lines modified
187 Req-·····Disable·DCCP········being·loaded,·add·the·following·line·to·the·file·/etc/·against187 Req-·····Disable·DCCP········being·loaded,·add·the·following·line·to·the·file·/etc/·against
188 1.4.2····Support·············modprobe.d/dccp.conf:··································exploitation·of·any188 1.4.2····Support·············modprobe.d/dccp.conf:··································exploitation·of·any
189 ·····························install·dccp·/bin/false································flaws·in·its189 ·····························install·dccp·/bin/false································flaws·in·its
190 ·····························To·configure·the·system·to·prevent·the·dccp·from·being·implementation.190 ·····························To·configure·the·system·to·prevent·the·dccp·from·being·implementation.
191 ·····························used,·add·the·following·line·to·file·/etc/modprobe.d/191 ·····························used,·add·the·following·line·to·file·/etc/modprobe.d/
192 ·····························dccp.conf:192 ·····························dccp.conf:
193 ·····························blacklist·dccp193 ·····························blacklist·dccp
 194 ····················································································Responding·to
 195 ····················································································broadcast·(ICMP)
 196 ····················································································echoes·facilitates
 197 ·····························To·set·the·runtime·status·of·the·······················network·mapping·and
 198 ·····························net.ipv4.icmp_echo_ignore_broadcasts·kernel·parameter,·provides·a·vector
 199 ·········Enable·Kernel·······run·the·following·command:·····························for·amplification
 200 ·········Parameter·to·Ignore·$·sudo·sysctl·-········································attacks.
 201 Req-·····ICMP·Broadcast·Echo·w·net.ipv4.icmp_echo_ignore_broadcasts=1···············Ignoring·ICMP·echo
 202 1.4.3····Requests·on·IPv4····To·make·sure·that·the·setting·is·persistent,·add·the···requests·(pings)
 203 ·········Interfaces··········following·line·to·a·file·in·the·directory·/etc/········sent·to·broadcast
 204 ·····························sysctl.d:··············································or·multicast
 205 ·····························net.ipv4.icmp_echo_ignore_broadcasts·=·1···············addresses·makes·the
 206 ····················································································system·slightly
 207 ····················································································more·difficult·to
 208 ····················································································enumerate·on·the
 209 ····················································································network.
 210 ····················································································Source-routed
 211 ····················································································packets·allow·the
 212 ····················································································source·of·the
 213 ····················································································packet·to·suggest
 214 ····················································································routers·forward·the
 215 ····················································································packet·along·a
 216 ····················································································different·path·than
 217 ····················································································configured·on·the
 218 ····················································································router,·which·can
 219 ····················································································be·used·to·bypass
 220 ····················································································network·security
 221 ·····························To·set·the·runtime·status·of·the·······················measures.·This
 222 ·········Disable·Kernel······net.ipv6.conf.default.accept_source_route·kernel·······requirement·applies
 223 ·········Parameter·for·······parameter,·run·the·following·command:··················only·to·the
 224 Req-·····Accepting·Source-···$·sudo·sysctl·-········································forwarding·of
 225 1.4.3····Routed·Packets·on···w·net.ipv6.conf.default.accept_source_route=0··········source-routerd
 226 ·········IPv6·Interfaces·by··To·make·sure·that·the·setting·is·persistent,·add·the···traffic,·such·as
 227 ·········Default·············following·line·to·a·file·in·the·directory·/etc/········when·IPv6
 228 ·····························sysctl.d:··············································forwarding·is
 229 ·····························net.ipv6.conf.default.accept_source_route·=·0··········enabled·and·the
 230 ····················································································system·is
 231 ····················································································functioning·as·a
 232 ····················································································router.·Accepting
 233 ····················································································source-routed
 234 ····················································································packets·in·the·IPv6
 235 ····················································································protocol·has·few
 236 ····················································································legitimate·uses.·It
 237 ····················································································should·be·disabled
 238 ····················································································unless·it·is
 239 ····················································································absolutely
 240 ····················································································required.
194 ····················································································ICMP·redirect241 ····················································································ICMP·redirect
195 ····················································································messages·are·used242 ····················································································messages·are·used
196 ····················································································by·routers·to243 ····················································································by·routers·to
197 ····················································································inform·hosts·that·a244 ····················································································inform·hosts·that·a
198 ····················································································more·direct·route245 ····················································································more·direct·route
199 ····················································································exists·for·a246 ····················································································exists·for·a
200 ····················································································particular247 ····················································································particular
Offset 229, 110 lines modifiedOffset 276, 63 lines modified
229 ·····························sysctl.d:··············································are·routers·for276 ·····························sysctl.d:··············································are·routers·for
230 ·····························net.ipv4.conf.all.rp_filter·=·1························complicated277 ·····························net.ipv4.conf.all.rp_filter·=·1························complicated
231 ····················································································networks,·but·is278 ····················································································networks,·but·is
232 ····················································································helpful·for·end279 ····················································································helpful·for·end
233 ····················································································hosts·and·routers280 ····················································································hosts·and·routers
234 ····················································································serving·small281 ····················································································serving·small
235 ····················································································networks.282 ····················································································networks.
236 ····················································································Source-routed 
237 ····················································································packets·allow·the 
238 ····················································································source·of·the 
239 ····················································································packet·to·suggest 
Max diff block lines reached; 482652/500128 bytes (96.51%) of diff not shown.
17.4 MB
./usr/share/doc/ssg-nondebian/table-rhcos4-nistrefs.html
    
Offset 69, 15697 lines modifiedOffset 69, 15697 lines modified
00000440:·6174·696f·6e61·6c65·3c2f·7468·3e0a·2020··ationale</th>.··00000440:·6174·696f·6e61·6c65·3c2f·7468·3e0a·2020··ationale</th>.··
00000450:·3c2f·7468·6561·643e·0a20·203c·7462·6f64··</thead>.··<tbod00000450:·3c2f·7468·6561·643e·0a20·203c·7462·6f64··</thead>.··<tbod
00000460:·793e·0a20·203c·7472·3e0a·2020·2020·2020··y>.··<tr>.······00000460:·793e·0a20·203c·7472·3e0a·2020·2020·2020··y>.··<tr>.······
00000470:·3c74·643e·4155·2d32·2861·293c·2f74·643e··<td>AU-2(a)</td>00000470:·3c74·643e·4155·2d32·2861·293c·2f74·643e··<td>AU-2(a)</td>
00000480:·0a20·2020·2020·203c·7464·3e43·6f6e·6669··.······<td>Confi00000480:·0a20·2020·2020·203c·7464·3e43·6f6e·6669··.······<td>Confi
00000490:·6775·7265·2061·7564·6974·696e·6720·6f66··gure·auditing·of00000490:·6775·7265·2061·7564·6974·696e·6720·6f66··gure·auditing·of
Diff chunk too large, falling back to line-by-line diff (5962 lines added, 5962 lines removed)
000004a0:·2073·7563·6365·7373·6675·6c20·6669·6c65···successful·file000004a0:·2073·7563·6365·7373·6675·6c20·6669·6c65···successful·file
000004b0:·2063·7265·6174·696f·6e73·2028·4141·7263···creations·(AArc000004b0:·2061·6363·6573·7365·7320·2870·7063·3634···accesses·(ppc64
000004c0:·6836·3429·3c2f·7464·3e0a·2020·2020·2020··h64)</td>.······000004c0:·6c65·293c·2f74·643e·0a20·2020·2020·203c··le)</td>.······<
000004d0:·3c74·6420·786d·6c3a·6c61·6e67·3d22·656e··<td·xml:lang="en000004d0:·7464·2078·6d6c·3a6c·616e·673d·2265·6e2d··td·xml:lang="en-
000004e0:·2d55·5322·3e0a·2020·2020·2020·2020·456e··-US">.········En000004e0:·5553·223e·0a20·2020·2020·2020·2045·6e73··US">.········Ens
000004f0:·7375·7265·2074·6861·7420·7375·6363·6573··sure·that·succes000004f0:·7572·6520·7468·6174·2073·7563·6365·7373··ure·that·success
00000500:·7366·756c·2061·7474·656d·7074·7320·746f··sful·attempts·to00000500:·6675·6c20·6174·7465·6d70·7473·2074·6f20··ful·attempts·to·
00000510:·2063·7265·6174·6520·6120·6669·6c65·2061···create·a·file·a00000510:·6163·6365·7373·2061·2066·696c·6520·6172··access·a·file·ar
00000520:·7265·2061·7564·6974·6564·2e0a·0a54·6865··re·audited...The00000520:·6520·6175·6469·7465·642e·0a0a·5468·6520··e·audited...The·
00000530:·2066·6f6c·6c6f·7769·6e67·2072·756c·6573···following·rules00000530:·666f·6c6c·6f77·696e·6720·7275·6c65·7320··following·rules·
00000540:·2063·6f6e·6669·6775·7265·2061·7564·6974···configure·audit00000540:·636f·6e66·6967·7572·6520·6175·6469·7420··configure·audit·
00000550:·2061·7320·6465·7363·7269·6265·6420·6162···as·described·ab00000550:·6173·2064·6573·6372·6962·6564·2061·626f··as·described·abo
00000560:·6f76·653a·0a3c·7072·653e·2323·2053·7563··ove:.<pre>##·Suc00000560:·7665·3a0a·3c70·7265·3e23·2320·5375·6363··ve:.<pre>##·Succ
00000570:·6365·7373·6675·6c20·6669·6c65·2063·7265··cessful·file·cre00000570:·6573·7366·756c·2066·696c·6520·6163·6365··essful·file·acce
00000580:·6174·696f·6e20·286f·7065·6e20·7769·7468··ation·(open·with00000580:·7373·2028·616e·7920·6f74·6865·7220·6f70··ss·(any·other·op
00000590:·204f·5f43·5245·4154·290a·2d61·2061·6c77···O_CREAT).-a·alw00000590:·656e·7329·2054·6869·7320·6861·7320·746f··ens)·This·has·to
000005a0:·6179·732c·6578·6974·202d·4620·6172·6368··ays,exit·-F·arch000005a0:·2067·6f20·6c61·7374·2e0a·2323·2054·6865···go·last..##·The
000005b0:·3d62·3332·202d·5320·6f70·656e·6174·2c6f··=b32·-S·openat,o000005b0:·7365·206e·6578·7420·7477·6f20·6172·6520··se·next·two·are·
000005c0:·7065·6e5f·6279·5f68·616e·646c·655f·6174··pen_by_handle_at000005c0:·6c69·6b65·6c79·2074·6f20·7265·7375·6c74··likely·to·result
000005d0:·202d·4620·6132·2661·6d70·3b30·3130·3020···-F·a2&amp;0100·000005d0:·2069·6e20·6120·7768·6f6c·6520·6c6f·7420···in·a·whole·lot·
000005e0:·2d46·2073·7563·6365·7373·3d31·202d·4620··-F·success=1·-F·000005e0:·6f66·2065·7665·6e74·730a·2d61·2061·6c77··of·events.-a·alw
000005f0:·6175·6964·3e3d·3130·3030·202d·4620·6175··auid>=1000·-F·au000005f0:·6179·732c·6578·6974·202d·4620·6172·6368··ays,exit·-F·arch
00000600:·6964·213d·756e·7365·7420·2d46·206b·6579··id!=unset·-F·key00000600:·3d62·3634·202d·5320·6f70·656e·2c6f·7065··=b64·-S·open,ope
00000610:·3d73·7563·6365·7373·6675·6c2d·6372·6561··=successful-crea00000610:·6e61·742c·6f70·656e·6174·322c·6f70·656e··nat,openat2,open
00000620:·7465·0a2d·6120·616c·7761·7973·2c65·7869··te.-a·always,exi00000620:·5f62·795f·6861·6e64·6c65·5f61·7420·2d46··_by_handle_at·-F
00000630:·7420·2d46·2061·7263·683d·6236·3420·2d53··t·-F·arch=b64·-S00000630:·2073·7563·6365·7373·3d31·202d·4620·6175···success=1·-F·au
00000640:·206f·7065·6e61·742c·6f70·656e·5f62·795f···openat,open_by_00000640:·6964·3e3d·3130·3030·202d·4620·6175·6964··id>=1000·-F·auid
00000650:·6861·6e64·6c65·5f61·7420·2d46·2061·3226··handle_at·-F·a2&00000650:·213d·756e·7365·7420·2d46·206b·6579·3d73··!=unset·-F·key=s
00000660:·616d·703b·3031·3030·202d·4620·7375·6363··amp;0100·-F·succ00000660:·7563·6365·7373·6675·6c2d·6163·6365·7373··uccessful-access
00000670:·6573·733d·3120·2d46·2061·7569·643e·3d31··ess=1·-F·auid>=100000670:·2020·2020·3c2f·7072·653e·0a0a·4c6f·6164······</pre>..Load
00000680:·3030·3020·2d46·2061·7569·6421·3d75·6e73··000·-F·auid!=uns00000680:·206e·6577·2041·7564·6974·2072·756c·6573···new·Audit·rules
00000690:·6574·202d·4620·6b65·793d·7375·6363·6573··et·-F·key=succes00000690:·2069·6e74·6f20·6b65·726e·656c·2062·7920···into·kernel·by·
000006a0:·7366·756c·2d63·7265·6174·650a·2d61·2061··sful-create.-a·a000006a0:·7275·6e6e·696e·673a·0a3c·7072·653e·6175··running:.<pre>au
000006b0:·6c77·6179·732c·6578·6974·202d·4620·6172··lways,exit·-F·ar000006b0:·6765·6e72·756c·6573·202d·2d6c·6f61·643c··genrules·--load<
000006c0:·6368·3d62·3332·202d·5320·6f70·656e·202d··ch=b32·-S·open·-000006c0:·2f70·7265·3e0a·0a4e·6f74·653a·2054·6869··/pre>..Note:·Thi
000006d0:·4620·6131·2661·6d70·3b30·3130·3020·2d46··F·a1&amp;0100·-F000006d0:·7320·7275·6c65·2075·7365·7320·6120·7370··s·rule·uses·a·sp
000006e0:·2073·7563·6365·7373·3d31·202d·4620·6175···success=1·-F·au000006e0:·6563·6961·6c20·7365·7420·6f66·2041·7564··ecial·set·of·Aud
000006f0:·6964·3e3d·3130·3030·202d·4620·6175·6964··id>=1000·-F·auid000006f0:·6974·2072·756c·6573·2074·6f20·636f·6d70··it·rules·to·comp
00000700:·213d·756e·7365·7420·2d46·206b·6579·3d73··!=unset·-F·key=s00000700:·6c79·2077·6974·6820·4f53·5050·2034·2e32··ly·with·OSPP·4.2
00000710:·7563·6365·7373·6675·6c2d·6372·6561·7465··uccessful-create00000710:·2e31·2e20·596f·7520·6d61·7920·7265·7573··.1.·You·may·reus
00000720:·0a2d·6120·616c·7761·7973·2c65·7869·7420··.-a·always,exit·00000720:·6520·7468·6973·2072·756c·6520·696e·2064··e·this·rule·in·d
00000730:·2d46·2061·7263·683d·6233·3220·2d53·2063··-F·arch=b32·-S·c00000730:·6966·6665·7265·6e74·2070·726f·6669·6c65··ifferent·profile
00000740:·7265·6174·202d·4620·7375·6363·6573·733d··reat·-F·success=00000740:·732e·2049·6620·796f·7520·6465·6369·6465··s.·If·you·decide
00000750:·3120·2d46·2061·7569·643e·3d31·3030·3020··1·-F·auid>=1000·00000750:·2074·6f20·646f·2073·6f2c·2069·7420·6973···to·do·so,·it·is
00000760:·2d46·2061·7569·6421·3d75·6e73·6574·202d··-F·auid!=unset·-00000760:·2072·6563·6f6d·6d65·6e64·6564·2074·6861···recommended·tha
00000770:·4620·6b65·793d·7375·6363·6573·7366·756c··F·key=successful00000770:·7420·796f·7520·696e·7370·6563·7420·636f··t·you·inspect·co
00000780:·2d63·7265·6174·6520·2020·203c·2f70·7265··-create····</pre00000780:·6e74·656e·7473·206f·6620·7468·6520·6669··ntents·of·the·fi
00000790:·3e0a·0a4c·6f61·6420·6e65·7720·4175·6469··>..Load·new·Audi00000790:·6c65·2063·6c6f·7365·6c79·2061·6e64·206d··le·closely·and·m
000007a0:·7420·7275·6c65·7320·696e·746f·206b·6572··t·rules·into·ker000007a0:·616b·6520·7375·7265·2074·6861·7420·7468··ake·sure·that·th
000007b0:·6e65·6c20·6279·2072·756e·6e69·6e67·3a0a··nel·by·running:.000007b0:·6579·2061·7265·2061·6c6c·6967·6e65·6420··ey·are·alligned·
000007c0:·3c70·7265·3e61·7567·656e·7275·6c65·7320··<pre>augenrules·000007c0:·7769·7468·2079·6f75·7220·6e65·6564·732e··with·your·needs.
000007d0:·2d2d·6c6f·6164·3c2f·7072·653e·0a0a·4e6f··--load</pre>..No000007d0:·0a20·2020·2020·203c·2f74·643e·0a20·2020··.······</td>.···
000007e0:·7465·3a20·5468·6973·2072·756c·6520·7573··te:·This·rule·us000007e0:·2020·203c·7464·2078·6d6c·3a6c·616e·673d·····<td·xml:lang=
000007f0:·6573·2061·2073·7065·6369·616c·2073·6574··es·a·special·set000007f0:·2265·6e2d·5553·223e·0a20·2020·2020·2020··"en-US">.·······
00000800:·206f·6620·4175·6469·7420·7275·6c65·7320···of·Audit·rules·00000800:·2041·7564·6974·696e·6720·6f66·2073·7563···Auditing·of·suc
00000810:·746f·2063·6f6d·706c·7920·7769·7468·204f··to·comply·with·O00000810:·6365·7373·6675·6c20·6174·7465·6d70·7473··cessful·attempts
00000820:·5350·5020·342e·322e·312e·2059·6f75·206d··SPP·4.2.1.·You·m00000820:·2074·6f20·6163·6365·7373·2061·2066·696c···to·access·a·fil
00000830:·6179·2072·6575·7365·2074·6869·7320·7275··ay·reuse·this·ru00000830:·6520·6865·6c70·7320·696e·2069·6e76·6573··e·helps·in·inves
00000840:·6c65·2069·6e20·6469·6666·6572·656e·7420··le·in·different·00000840:·7469·6761·7469·6f6e·206f·6620·6163·7469··tigation·of·acti
00000850:·7072·6f66·696c·6573·2e20·4966·2079·6f75··profiles.·If·you00000850:·7669·7469·6573·2070·6572·666f·726d·6564··vities·performed
00000860:·2064·6563·6964·6520·746f·2064·6f20·736f···decide·to·do·so00000860:·206f·6e20·7468·6520·7379·7374·656d·2e0a···on·the·system..
00000870:·2c20·6974·2069·7320·7265·636f·6d6d·656e··,·it·is·recommen00000870:·2020·2020·2020·3c2f·7464·3e0a·2020·2020········</td>.····
00000880:·6465·6420·7468·6174·2079·6f75·2069·6e73··ded·that·you·ins00000880:·3c2f·7472·3e0a·2020·2020·3c74·723e·0a20··</tr>.····<tr>.·
00000890:·7065·6374·2063·6f6e·7465·6e74·7320·6f66··pect·contents·of00000890:·2020·2020·203c·7464·3e41·552d·3228·6429·······<td>AU-2(d)
000008a0:·2074·6865·2066·696c·6520·636c·6f73·656c···the·file·closel000008a0:·3c62·722f·3e41·552d·3132·2863·293c·6272··<br/>AU-12(c)<br
000008b0:·7920·616e·6420·6d61·6b65·2073·7572·6520··y·and·make·sure·000008b0:·2f3e·4143·2d36·2839·293c·6272·2f3e·434d··/>AC-6(9)<br/>CM
000008c0:·7468·6174·2074·6865·7920·6172·6520·616c··that·they·are·al000008c0:·2d36·2861·293c·2f74·643e·0a20·2020·2020··-6(a)</td>.·····
000008d0:·6c69·676e·6564·2077·6974·6820·796f·7572··ligned·with·your000008d0:·203c·7464·3e45·6e73·7572·6520·6175·6469···<td>Ensure·audi
000008e0:·206e·6565·6473·2e0a·2020·2020·2020·3c2f···needs..······</000008e0:·7464·2043·6f6c·6c65·6374·7320·496e·666f··td·Collects·Info
000008f0:·7464·3e0a·2020·2020·2020·3c74·6420·786d··td>.······<td·xm000008f0:·726d·6174·696f·6e20·6f6e·204b·6572·6e65··rmation·on·Kerne
00000900:·6c3a·6c61·6e67·3d22·656e·2d55·5322·3e0a··l:lang="en-US">.00000900:·6c20·4d6f·6475·6c65·2055·6e6c·6f61·6469··l·Module·Unloadi
00000910:·2020·2020·2020·2020·4175·6469·7469·6e67··········Auditing00000910:·6e67·202d·2064·656c·6574·655f·6d6f·6475··ng·-·delete_modu
00000920:·206f·6620·7375·6363·6573·7366·756c·2061···of·successful·a00000920:·6c65·3c2f·7464·3e0a·2020·2020·2020·3c74··le</td>.······<t
00000930:·7474·656d·7074·7320·746f·2063·7265·6174··ttempts·to·creat00000930:·6420·786d·6c3a·6c61·6e67·3d22·656e·2d55··d·xml:lang="en-U
00000940:·6520·6120·6669·6c65·2068·656c·7073·2069··e·a·file·helps·i00000940:·5322·3e0a·2020·2020·2020·2020·546f·2063··S">.········To·c
00000950:·6e20·696e·7665·7374·6967·6174·696f·6e20··n·investigation·00000950:·6170·7475·7265·206b·6572·6e65·6c20·6d6f··apture·kernel·mo
00000960:·6f66·2061·6374·696f·6e73·2077·6869·6368··of·actions·which00000960:·6475·6c65·2075·6e6c·6f61·6469·6e67·2065··dule·unloading·e
00000970:·2068·6170·7065·6e65·6420·6f6e·2074·6865···happened·on·the00000970:·7665·6e74·732c·2075·7365·2066·6f6c·6c6f··vents,·use·follo
00000980:·2073·7973·7465·6d2e·0a20·2020·2020·203c···system..······<00000980:·7769·6e67·206c·696e·652c·2073·6574·7469··wing·line,·setti
00000990:·2f74·643e·0a20·2020·203c·2f74·723e·0a20··/td>.····</tr>.·00000990:·6e67·2041·5243·4820·746f·0a65·6974·6865··ng·ARCH·to.eithe
000009a0:·2020·203c·7472·3e0a·2020·2020·2020·3c74·····<tr>.······<t000009a0:·7220·6233·3220·666f·7220·3332·2d62·6974··r·b32·for·32-bit
000009b0:·643e·4155·2d32·2861·293c·2f74·643e·0a20··d>AU-2(a)</td>.·000009b0:·2073·7973·7465·6d2c·206f·7220·6861·7669···system,·or·havi
000009c0:·2020·2020·203c·7464·3e43·6f6e·6669·6775·······<td>Configu000009c0:·6e67·2074·776f·206c·696e·6573·2066·6f72··ng·two·lines·for
000009d0:·7265·2061·7564·6974·696e·6720·6f66·2075··re·auditing·of·u000009d0:·2062·6f74·6820·6233·3220·616e·6420·6236···both·b32·and·b6
000009e0:·6e73·7563·6365·7373·6675·6c20·6669·6c65··nsuccessful·file000009e0:·3420·696e·2063·6173·6520·796f·7572·2073··4·in·case·your·s
000009f0:·2063·7265·6174·696f·6e73·3c2f·7464·3e0a···creations</td>.000009f0:·7973·7465·6d20·6973·2036·342d·6269·743a··ystem·is·64-bit:
00000a00:·2020·2020·2020·3c74·6420·786d·6c3a·6c61········<td·xml:la00000a00:·0a0a·3c70·7265·3e2d·6120·616c·7761·7973··..<pre>-a·always
00000a10:·6e67·3d22·656e·2d55·5322·3e0a·2020·2020··ng="en-US">.····00000a10:·2c65·7869·7420·2d46·2061·7263·683d·3c69··,exit·-F·arch=<i
00000a20:·2020·2020·456e·7375·7265·2074·6861·7420······Ensure·that·00000a20:·3e41·5243·483c·2f69·3e20·2d53·2064·656c··>ARCH</i>·-S·del
00000a30:·756e·7375·6363·6573·7366·756c·2061·7474··unsuccessful·att00000a30:·6574·655f·6d6f·6475·6c65·202d·4620·6b65··ete_module·-F·ke
00000a40:·656d·7074·7320·746f·2063·7265·6174·6520··empts·to·create·00000a40:·793d·6d6f·6475·6c65·733c·2f70·7265·3e0a··y=modules</pre>.
00000a50:·6120·6669·6c65·2061·7265·2061·7564·6974··a·file·are·audit00000a50:·0a0a·506c·6163·6520·746f·2061·6464·2074··..Place·to·add·t
00000a60:·6564·2e0a·0a54·6865·2066·6f6c·6c6f·7769··ed...The·followi00000a60:·6865·206c·696e·6520·6465·7065·6e64·7320··he·line·depends·
00000a70:·6e67·2072·756c·6573·2063·6f6e·6669·6775··ng·rules·configu00000a70:·6f6e·2061·2077·6179·203c·7474·3e61·7564··on·a·way·<tt>aud
00000a80:·7265·2061·7564·6974·2061·7320·6465·7363··re·audit·as·desc00000a80:·6974·643c·2f74·743e·2064·6165·6d6f·6e20··itd</tt>·daemon·
00000a90:·7269·6265·6420·6162·6f76·653a·0a3c·7072··ribed·above:.<pr00000a90:·6973·2063·6f6e·6669·6775·7265·642e·2049··is·configured.·I
00000aa0:·653e·2323·2055·6e73·7563·6365·7373·6675··e>##·Unsuccessfu00000aa0:·6620·6974·2069·7320·636f·6e66·6967·7572··f·it·is·configur
00000ab0:·6c20·6669·6c65·2063·7265·6174·696f·6e20··l·file·creation·00000ab0:·6564·0a74·6f20·7573·6520·7468·6520·3c74··ed.to·use·the·<t
00000ac0:·286f·7065·6e20·7769·7468·204f·5f43·5245··(open·with·O_CRE00000ac0:·743e·6175·6765·6e72·756c·6573·3c2f·7474··t>augenrules</tt
00000ad0:·4154·290a·2d61·2061·6c77·6179·732c·6578··AT).-a·always,ex00000ad0:·3e20·7072·6f67·7261·6d20·2874·6865·2064··>·program·(the·d
00000ae0:·6974·202d·4620·6172·6368·3d62·3332·202d··it·-F·arch=b32·-00000ae0:·6566·6175·6c74·292c·2061·6464·2074·6865··efault),·add·the
00000af0:·5320·6f70·656e·6174·2c6f·7065·6e5f·6279··S·openat,open_by00000af0:·206c·696e·6520·746f·2061·2066·696c·6520···line·to·a·file·
00000b00:·5f68·616e·646c·655f·6174·202d·4620·6132··_handle_at·-F·a200000b00:·7769·7468·2073·7566·6669·780a·3c74·743e··with·suffix.<tt>
00000b10:·2661·6d70·3b30·3130·3020·2d46·2065·7869··&amp;0100·-F·exi00000b10:·2e72·756c·6573·3c2f·7474·3e20·696e·2074··.rules</tt>·in·t
00000b20:·743d·2d45·4143·4345·5320·2d46·2061·7569··t=-EACCES·-F·aui00000b20:·6865·2064·6972·6563·746f·7279·203c·7474··he·directory·<tt
00000b30:·6426·6774·3b3d·3130·3030·202d·4620·6175··d&gt;=1000·-F·au00000b30:·3e2f·6574·632f·6175·6469·742f·7275·6c65··>/etc/audit/rule
00000b40:·6964·213d·756e·7365·7420·2d46·206b·6579··id!=unset·-F·key00000b40:·732e·643c·2f74·743e·2e0a·0a49·6620·7468··s.d</tt>...If·th
00000b50:·3d75·6e73·7563·6365·7373·6675·6c2d·6372··=unsuccessful-cr00000b50:·6520·3c74·743e·6175·6469·7464·3c2f·7474··e·<tt>auditd</tt
00000b60:·6561·7465·0a2d·6120·616c·7761·7973·2c65··eate.-a·always,e00000b60:·3e20·6461·656d·6f6e·2069·7320·636f·6e66··>·daemon·is·conf
00000b70:·7869·7420·2d46·2061·7263·683d·6236·3420··xit·-F·arch=b64·00000b70:·6967·7572·6564·2074·6f20·7573·6520·7468··igured·to·use·th
00000b80:·2d53·206f·7065·6e61·742c·6f70·656e·5f62··-S·openat,open_b00000b80:·6520·3c74·743e·6175·6469·7463·746c·3c2f··e·<tt>auditctl</
00000b90:·795f·6861·6e64·6c65·5f61·7420·2d46·2061··y_handle_at·-F·a00000b90:·7474·3e20·7574·696c·6974·792c·0a61·6464··tt>·utility,.add
00000ba0:·3226·616d·703b·3031·3030·202d·4620·6578··2&amp;0100·-F·ex00000ba0:·2074·6865·206c·696e·6520·746f·2066·696c···the·line·to·fil
00000bb0:·6974·3d2d·4541·4343·4553·202d·4620·6175··it=-EACCES·-F·au00000bb0:·6520·3c74·743e·2f65·7463·2f61·7564·6974··e·<tt>/etc/audit
00000bc0:·6964·2667·743b·3d31·3030·3020·2d46·2061··id&gt;=1000·-F·a00000bc0:·2f61·7564·6974·2e72·756c·6573·3c2f·7474··/audit.rules</tt
00000bd0:·7569·6421·3d75·6e73·6574·202d·4620·6b65··uid!=unset·-F·ke00000bd0:·3e2e·0a20·2020·2020·203c·2f74·643e·0a20··>..······</td>.·
00000be0:·793d·756e·7375·6363·6573·7366·756c·2d63··y=unsuccessful-c00000be0:·2020·2020·203c·7464·2078·6d6c·3a6c·616e·······<td·xml:lan
00000bf0:·7265·6174·650a·2d61·2061·6c77·6179·732c··reate.-a·always,00000bf0:·673d·2265·6e2d·5553·223e·0a20·2020·2020··g="en-US">.·····
00000c00:·6578·6974·202d·4620·6172·6368·3d62·3332··exit·-F·arch=b3200000c00:·2020·2054·6865·2072·656d·6f76·616c·206f·····The·removal·o
00000c10:·202d·5320·6f70·656e·202d·4620·6131·2661···-S·open·-F·a1&a00000c10:·6620·6b65·726e·656c·206d·6f64·756c·6573··f·kernel·modules
Max diff block lines reached; 7108432/7931766 bytes (89.62%) of diff not shown.
9.87 MB
html2text {}
Max HTML report size reached
3.61 MB
./usr/share/doc/ssg-nondebian/table-rhel8-anssirefs.html
    
Offset 64, 274 lines modifiedOffset 64, 274 lines modified
000003f0:·3c74·683e·5275·6c65·2054·6974·6c65·3c2f··<th>Rule·Title</000003f0:·3c74·683e·5275·6c65·2054·6974·6c65·3c2f··<th>Rule·Title</
00000400:·7468·3e0a·2020·2020·3c74·683e·4465·7363··th>.····<th>Desc00000400:·7468·3e0a·2020·2020·3c74·683e·4465·7363··th>.····<th>Desc
00000410:·7269·7074·696f·6e3c·2f74·683e·0a20·2020··ription</th>.···00000410:·7269·7074·696f·6e3c·2f74·683e·0a20·2020··ription</th>.···
00000420:·203c·7468·3e52·6174·696f·6e61·6c65·3c2f···<th>Rationale</00000420:·203c·7468·3e52·6174·696f·6e61·6c65·3c2f···<th>Rationale</
00000430:·7468·3e0a·2020·3c2f·7468·6561·643e·0a20··th>.··</thead>.·00000430:·7468·3e0a·2020·3c2f·7468·6561·643e·0a20··th>.··</thead>.·
00000440:·203c·7462·6f64·793e·0a20·203c·7472·3e0a···<tbody>.··<tr>.00000440:·203c·7462·6f64·793e·0a20·203c·7472·3e0a···<tbody>.··<tr>.
00000450:·2020·2020·2020·3c74·643e·5231·3c2f·7464········<td>R1</td00000450:·2020·2020·2020·3c74·643e·5231·3c2f·7464········<td>R1</td
00000460:·3e0a·2020·2020·2020·3c74·643e·496e·7374··>.······<td>Inst00000460:·3e0a·2020·2020·2020·3c74·643e·5072·6566··>.······<td>Pref
 00000470:·6572·2074·6f20·7573·6520·6120·3634·2d62··er·to·use·a·64-b
 00000480:·6974·204f·7065·7261·7469·6e67·2053·7973··it·Operating·Sys
00000470:·616c·6c20·7468·6520·6472·6163·7574·2d66··all·the·dracut-f 
00000480:·6970·732d·6165·736e·6920·5061·636b·6167··ips-aesni·Packag 
00000490:·653c·2f74·643e·0a20·2020·2020·203c·7464··e</td>.······<td 
000004a0:·2078·6d6c·3a6c·616e·673d·2265·6e2d·5553···xml:lang="en-US 
000004b0:·223e·0a20·2020·2020·2020·2054·6f20·656e··">.········To·en 
000004c0:·6162·6c65·2046·4950·5320·6f6e·2073·7973··able·FIPS·on·sys 
000004d0:·7465·6d20·7468·6174·2073·7570·706f·7274··tem·that·support00000490:·7465·6d20·7768·656e·2073·7570·706f·7274··tem·when·support
000004e0:·2074·6865·2041·6476·616e·6365·6420·456e···the·Advanced·En 
000004f0:·6372·7970·7469·6f6e·2053·7461·6e64·6172··cryption·Standar 
00000500:·6420·2841·4553·2920·6f72·204e·6577·0a49··d·(AES)·or·New.I 
00000510:·6e73·7472·7563·7469·6f6e·7320·2841·4553··nstructions·(AES 
00000520:·2d4e·4929·2065·6e67·696e·652c·2074·6865··-NI)·engine,·the 
00000530:·2073·7973·7465·6d20·7265·7175·6972·6573···system·requires 
00000540:·2074·6861·7420·7468·6520·3c74·743e·6472···that·the·<tt>dr 
00000550:·6163·7574·2d66·6970·732d·6165·736e·693c··acut-fips-aesni< 
00000560:·2f74·743e·0a70·6163·6b61·6765·2062·6520··/tt>.package·be· 
00000570:·696e·7374·616c·6c65·642e·0a54·6865·203c··installed..The·< 
00000580:·636f·6465·3e64·7261·6375·742d·6669·7073··code>dracut-fips 
00000590:·2d61·6573·6e69·3c2f·636f·6465·3e20·7061··-aesni</code>·pa 
000005a0:·636b·6167·6520·6361·6e20·6265·2069·6e73··ckage·can·be·ins 
000005b0:·7461·6c6c·6564·2077·6974·6820·7468·6520··talled·with·the· 
000005c0:·666f·6c6c·6f77·696e·6720·636f·6d6d·616e··following·comman 
000005d0:·643a·0a3c·7072·653e·0a24·2073·7564·6f20··d:.<pre>.$·sudo· 
000005e0:·7975·6d20·696e·7374·616c·6c20·6472·6163··yum·install·drac 
000005f0:·7574·2d66·6970·732d·6165·736e·693c·2f70··ut-fips-aesni</p 
00000600:·7265·3e0a·2020·2020·2020·3c2f·7464·3e0a··re>.······</td>. 
00000610:·2020·2020·2020·3c74·6420·786d·6c3a·6c61········<td·xml:la 
00000620:·6e67·3d22·656e·2d55·5322·3e0a·2020·2020··ng="en-US">.···· 
00000630:·2020·2020·5573·6520·6f66·2077·6561·6b20······Use·of·weak· 
00000640:·6f72·2075·6e74·6573·7465·6420·656e·6372··or·untested·encr 
00000650:·7970·7469·6f6e·2061·6c67·6f72·6974·686d··yption·algorithm 
00000660:·7320·756e·6465·726d·696e·6573·2074·6865··s·undermines·the 
00000670:·2070·7572·706f·7365·7320·6f66·2075·7469···purposes·of·uti 
00000680:·6c69·7a69·6e67·2065·6e63·7279·7074·696f··lizing·encryptio 
00000690:·6e20·746f·0a70·726f·7465·6374·2064·6174··n·to.protect·dat 
000006a0:·612e·2054·6865·206f·7065·7261·7469·6e67··a.·The·operating 
000006b0:·2073·7973·7465·6d20·6d75·7374·2069·6d70···system·must·imp 
000006c0:·6c65·6d65·6e74·2063·7279·7074·6f67·7261··lement·cryptogra 
000006d0:·7068·6963·206d·6f64·756c·6573·2061·6468··phic·modules·adh 
000006e0:·6572·696e·6720·746f·2074·6865·2068·6967··ering·to·the·hig 
000006f0:·6865·720a·7374·616e·6461·7264·7320·6170··her.standards·ap 
00000700:·7072·6f76·6564·2062·7920·7468·6520·6665··proved·by·the·fe 
00000710:·6465·7261·6c20·676f·7665·726e·6d65·6e74··deral·government 
00000720:·2073·696e·6365·2074·6869·7320·7072·6f76···since·this·prov 
00000730:·6964·6573·2061·7373·7572·616e·6365·2074··ides·assurance·t 
00000740:·6865·7920·6861·7665·2062·6565·6e20·7465··hey·have·been·te 
00000750:·7374·6564·0a61·6e64·2076·616c·6964·6174··sted.and·validat 
00000760:·6564·2e0a·2020·2020·2020·3c2f·7464·3e0a··ed..······</td>. 
00000770:·2020·2020·3c2f·7472·3e0a·2020·2020·3c74······</tr>.····<t 
00000780:·723e·0a20·2020·2020·203c·7464·3e52·313c··r>.······<td>R1< 
00000790:·2f74·643e·0a20·2020·2020·203c·7464·3e45··/td>.······<td>E 
000007a0:·6e73·7572·6520·534d·4150·2069·7320·6e6f··nsure·SMAP·is·no 
000007b0:·7420·6469·7361·626c·6564·2064·7572·696e··t·disabled·durin 
000007c0:·6720·626f·6f74·3c2f·7464·3e0a·2020·2020··g·boot</td>.···· 
000007d0:·2020·3c74·6420·786d·6c3a·6c61·6e67·3d22····<td·xml:lang=" 
000007e0:·656e·2d55·5322·3e0a·2020·2020·2020·2020··en-US">.········ 
000007f0:·5468·6520·534d·4150·2069·7320·7573·6564··The·SMAP·is·used 
00000800:·2074·6f20·7072·6576·656e·7420·7468·6520···to·prevent·the· 
00000810:·7375·7065·7276·6973·6f72·206d·6f64·6520··supervisor·mode· 
00000820:·6672·6f6d·2075·6e69·6e74·656e·7469·6f6e··from·unintention 
00000830:·616c·6c79·2072·6561·6469·6e67·2f77·7269··ally·reading/wri 
00000840:·7469·6e67·2069·6e74·6f0a·6d65·6d6f·7279··ting·into.memory 
00000850:·2070·6167·6573·2069·6e20·7468·6520·7573···pages·in·the·us 
00000860:·6572·2073·7061·6365·2c20·6974·2069·7320··er·space,·it·is· 
00000870:·656e·6162·6c65·6420·6279·2064·6566·6175··enabled·by·defau 
00000880:·6c74·2073·696e·6365·204c·696e·7578·206b··lt·since·Linux·k 
00000890:·6572·6e65·6c20·332e·372e·0a42·7574·2069··ernel·3.7..But·i 
000008a0:·7420·636f·756c·6420·6265·2064·6973·6162··t·could·be·disab 
000008b0:·6c65·6420·7468·726f·7567·6820·6b65·726e··led·through·kern 
000008c0:·656c·2062·6f6f·7420·7061·7261·6d65·7465··el·boot·paramete 
000008d0:·7273·2e0a·0a45·6e73·7572·6520·7468·6174··rs...Ensure·that 
000008e0:·2053·7570·6572·7669·736f·7220·4d6f·6465···Supervisor·Mode 
000008f0:·2041·6363·6573·7320·5072·6576·656e·7469···Access·Preventi 
00000900:·6f6e·2028·534d·4150·2920·6973·206e·6f74··on·(SMAP)·is·not 
00000910:·2064·6973·6162·6c65·6420·6279·0a74·6865···disabled·by.the 
00000920:·203c·7474·3e6e·6f73·6d61·703c·2f74·743e···<tt>nosmap</tt> 
00000930:·2062·6f6f·7420·7061·7261·6d65·6e74·6572···boot·paramenter 
00000940:·206f·7074·696f·6e2e·0a0a·4368·6563·6b20···option...Check· 
00000950:·7468·6174·2074·6865·206c·696e·6520·3c70··that·the·line·<p 
00000960:·7265·3e47·5255·425f·434d·444c·494e·455f··re>GRUB_CMDLINE_ 
00000970:·4c49·4e55·583d·222e·2e2e·223c·2f70·7265··LINUX="..."</pre 
00000980:·3e20·7769·7468·696e·203c·7474·3e2f·6574··>·within·<tt>/et 
00000990:·632f·6465·6661·756c·742f·6772·7562·3c2f··c/default/grub</ 
000009a0:·7474·3e0a·646f·6573·6e27·7420·636f·6e74··tt>.doesn't·cont 
000009b0:·6169·6e20·7468·6520·6172·6775·6d65·6e74··ain·the·argument 
000009c0:·203c·7474·3e6e·6f73·6d61·703c·2f74·743e···<tt>nosmap</tt> 
000009d0:·2e0a·5275·6e20·7468·6520·666f·6c6c·6f77··..Run·the·follow 
000009e0:·696e·6720·636f·6d6d·616e·6420·746f·2075··ing·command·to·u 
000009f0:·7064·6174·6520·636f·6d6d·616e·6420·6c69··pdate·command·li 
00000a00:·6e65·2066·6f72·2061·6c72·6561·6479·2069··ne·for·already·i 
00000a10:·6e73·7461·6c6c·6564·206b·6572·6e65·6c73··nstalled·kernels 
00000a20:·3a0a·3c70·7265·3e23·2067·7275·6262·7920··:.<pre>#·grubby· 
00000a30:·2d2d·7570·6461·7465·2d6b·6572·6e65·6c3d··--update-kernel= 
00000a40:·414c·4c20·2d2d·7265·6d6f·7665·2d61·7267··ALL·--remove-arg 
00000a50:·733d·226e·6f73·6d61·7022·3c2f·7072·653e··s="nosmap"</pre> 
00000a60:·0a20·2020·2020·203c·2f74·643e·0a20·2020··.······</td>.··· 
00000a70:·2020·203c·7464·2078·6d6c·3a6c·616e·673d·····<td·xml:lang= 
00000a80:·2265·6e2d·5553·223e·0a20·2020·2020·2020··"en-US">.······· 
00000a90:·2044·6973·6162·6c69·6e67·2053·4d41·5020···Disabling·SMAP· 
00000aa0:·6361·6e20·6661·6369·6c69·7461·7465·2065··can·facilitate·e 
00000ab0:·7870·6c6f·6974·6174·696f·6e20·6f66·2076··xploitation·of·v 
00000ac0:·756c·6e65·7261·6269·6c69·7469·6573·2063··ulnerabilities·c 
00000ad0:·6175·7365·6420·6279·2075·6e69·6e74·656e··aused·by·uninten 
00000ae0:·6465·6420·6163·6365·7373·2061·6e64·0a6d··ded·access·and.m 
00000af0:·616e·6970·756c·6174·696f·6e20·6f66·2064··anipulation·of·d 
00000b00:·6174·6120·696e·2074·6865·2075·7365·7220··ata·in·the·user· 
00000b10:·7370·6163·652e·0a20·2020·2020·203c·2f74··space..······</t 
00000b20:·643e·0a20·2020·203c·2f74·723e·0a20·2020··d>.····</tr>.··· 
00000b30:·203c·7472·3e0a·2020·2020·2020·3c74·643e···<tr>.······<td> 
00000b40:·5231·3c2f·7464·3e0a·2020·2020·2020·3c74··R1</td>.······<t000004a0:·6564·3c2f·7464·3e0a·2020·2020·2020·3c74··ed</td>.······<t
00000b50:·643e·5072·6566·6572·2074·6f20·7573·6520··d>Prefer·to·use· 
00000b60:·6120·3634·2d62·6974·204f·7065·7261·7469··a·64-bit·Operati 
00000b70:·6e67·2053·7973·7465·6d20·7768·656e·2073··ng·System·when·s 
00000b80:·7570·706f·7274·6564·3c2f·7464·3e0a·2020··upported</td>.·· 
00000b90:·2020·2020·3c74·6420·786d·6c3a·6c61·6e67······<td·xml:lang 
00000ba0:·3d22·656e·2d55·5322·3e0a·2020·2020·2020··="en-US">.······ 
00000bb0:·2020·5072·6566·6572·2069·6e73·7461·6c6c····Prefer·install 
Max diff block lines reached; 3053869/3090323 bytes (98.82%) of diff not shown.
678 KB
html2text {}
    
Offset 1, 38 lines modifiedOffset 1, 13 lines modified
  
  
1 Rules·with·ANSSI·Reference·in·Guide·to·the·Secure·Configuration·of·Red·Hat1 Rules·with·ANSSI·Reference·in·Guide·to·the·Secure·Configuration·of·Red·Hat
2 Enterprise·Linux·82 Enterprise·Linux·8
  
  
3 ···········································································Use·of·weak·or·untested·encryption 
4 ······························To·enable·FIPS·on·system·that·support·the····algorithms·undermines·the·purposes·of 
5 ······························Advanced·Encryption·Standard·(AES)·or·New····utilizing·encryption·to·protect·data. 
6 ····Install·the·dracut-fips-··Instructions·(AES-NI)·engine,·the·system·····The·operating·system·must·implement 
7 R1··aesni·Package·············requires·that·the·dracut-fips-aesni·package··cryptographic·modules·adhering·to·the 
8 ······························be·installed.·The·dracut-fips-aesni·package··higher·standards·approved·by·the 
9 ······························can·be·installed·with·the·following·command:·federal·government·since·this·provides 
10 ······························$·sudo·yum·install·dracut-fips-aesni·········assurance·they·have·been·tested·and 
11 ···········································································validated. 
12 ······························The·SMAP·is·used·to·prevent·the·supervisor 
13 ······························mode·from·unintentionally·reading/writing 
14 ······························into·memory·pages·in·the·user·space,·it·is 
15 ······························enabled·by·default·since·Linux·kernel·3.7. 
16 ······························But·it·could·be·disabled·through·kernel·boot 
17 ······························parameters.·Ensure·that·Supervisor·Mode 
18 ······························Access·Prevention·(SMAP)·is·not·disabled·by··Disabling·SMAP·can·facilitate 
19 R1··Ensure·SMAP·is·not········the·nosmap·boot·paramenter·option.·Check·····exploitation·of·vulnerabilities·caused 
20 ····disabled·during·boot······that·the·line································by·unintended·access·and·manipulation 
21 ······························GRUB_CMDLINE_LINUX="..."·····················of·data·in·the·user·space. 
22 ······························within·/etc/default/grub·doesn't·contain·the 
23 ······························argument·nosmap.·Run·the·following·command 
24 ······························to·update·command·line·for·already·installed 
25 ······························kernels: 
26 ······························#·grubby·--update-kernel=ALL·--remove- 
27 ······························args="nosmap" 
28 ···········································································Use·of·a·64-bit·operating·system3 ···········································································Use·of·a·64-bit·operating·system
29 ···········································································offers·a·few·advantages,·like·a·larger4 ···········································································offers·a·few·advantages,·like·a·larger
30 ····Prefer·to·use·a·64-bit····Prefer·installation·of·64-bit·operating······address·space·range·for·Address·Space5 ····Prefer·to·use·a·64-bit····Prefer·installation·of·64-bit·operating······address·space·range·for·Address·Space
31 R1··Operating·System·when·····systems·when·the·CPU·supports·it.············Layout·Randomization·(ASLR)·and6 R1··Operating·System·when·····systems·when·the·CPU·supports·it.············Layout·Randomization·(ASLR)·and
32 ····supported······························································systematic·presence·of·No·eXecute·and7 ····supported······························································systematic·presence·of·No·eXecute·and
33 ···········································································Execute·Disable·(NX/XD)·protection8 ···········································································Execute·Disable·(NX/XD)·protection
34 ···········································································bits.9 ···········································································bits.
Offset 62, 14 lines modifiedOffset 37, 39 lines modified
62 ······························GRUB_CMDLINE_LINUX="..."·····················kernel·to·unintentionally·execute·code37 ······························GRUB_CMDLINE_LINUX="..."·····················kernel·to·unintentionally·execute·code
63 ······························within·/etc/default/grub·doesn't·contain·the·in·less·privileged·memory·space.38 ······························within·/etc/default/grub·doesn't·contain·the·in·less·privileged·memory·space.
64 ······························argument·nosmep.·Run·the·following·command39 ······························argument·nosmep.·Run·the·following·command
65 ······························to·update·command·line·for·already·installed40 ······························to·update·command·line·for·already·installed
66 ······························kernels:41 ······························kernels:
67 ······························#·grubby·--update-kernel=ALL·--remove-42 ······························#·grubby·--update-kernel=ALL·--remove-
68 ······························args="nosmep"43 ······························args="nosmep"
 44 ······························The·SMAP·is·used·to·prevent·the·supervisor
 45 ······························mode·from·unintentionally·reading/writing
 46 ······························into·memory·pages·in·the·user·space,·it·is
 47 ······························enabled·by·default·since·Linux·kernel·3.7.
 48 ······························But·it·could·be·disabled·through·kernel·boot
 49 ······························parameters.·Ensure·that·Supervisor·Mode
 50 ······························Access·Prevention·(SMAP)·is·not·disabled·by··Disabling·SMAP·can·facilitate
 51 R1··Ensure·SMAP·is·not········the·nosmap·boot·paramenter·option.·Check·····exploitation·of·vulnerabilities·caused
 52 ····disabled·during·boot······that·the·line································by·unintended·access·and·manipulation
 53 ······························GRUB_CMDLINE_LINUX="..."·····················of·data·in·the·user·space.
 54 ······························within·/etc/default/grub·doesn't·contain·the
 55 ······························argument·nosmap.·Run·the·following·command
 56 ······························to·update·command·line·for·already·installed
 57 ······························kernels:
 58 ······························#·grubby·--update-kernel=ALL·--remove-
 59 ······························args="nosmap"
 60 ···········································································Use·of·weak·or·untested·encryption
 61 ······························To·enable·FIPS·on·system·that·support·the····algorithms·undermines·the·purposes·of
 62 ······························Advanced·Encryption·Standard·(AES)·or·New····utilizing·encryption·to·protect·data.
 63 ····Install·the·dracut-fips-··Instructions·(AES-NI)·engine,·the·system·····The·operating·system·must·implement
 64 R1··aesni·Package·············requires·that·the·dracut-fips-aesni·package··cryptographic·modules·adhering·to·the
 65 ······························be·installed.·The·dracut-fips-aesni·package··higher·standards·approved·by·the
 66 ······························can·be·installed·with·the·following·command:·federal·government·since·this·provides
 67 ······························$·sudo·yum·install·dracut-fips-aesni·········assurance·they·have·been·tested·and
 68 ···········································································validated.
69 ······························The·grub2·boot·loader·should·have·a69 ······························The·grub2·boot·loader·should·have·a
70 ······························superuser·account·and·password·protection70 ······························superuser·account·and·password·protection
71 ······························enabled·to·protect·boot-time·settings.·······Password·protection·on·the·boot·loader71 ······························enabled·to·protect·boot-time·settings.·······Password·protection·on·the·boot·loader
72 ···········································································configuration·ensures·users·with72 ···········································································configuration·ensures·users·with
73 ····Set·Boot·Loader·Password··Since·plaintext·passwords·are·a·security·····physical·access·cannot·trivially·alter73 ····Set·Boot·Loader·Password··Since·plaintext·passwords·are·a·security·····physical·access·cannot·trivially·alter
74 R5··in·grub2··················risk,·generate·a·hash·for·the·password·by····important·bootloader·settings.·These74 R5··in·grub2··················risk,·generate·a·hash·for·the·password·by····important·bootloader·settings.·These
75 ······························running·the·following·command:···············include·which·kernel·to·use,·and75 ······························running·the·following·command:···············include·which·kernel·to·use,·and
Offset 99, 77 lines modifiedOffset 99, 141 lines modified
99 ······························systems.·Modify·the·line·within·/etc/········hardware·devices.99 ······························systems.·Modify·the·line·within·/etc/········hardware·devices.
100 ······························default/grub·as·shown·below:100 ······························default/grub·as·shown·below:
101 ······························GRUB_CMDLINE_LINUX="...·iommu=force·..."101 ······························GRUB_CMDLINE_LINUX="...·iommu=force·..."
102 ······························Run·the·following·command·to·update·command102 ······························Run·the·following·command·to·update·command
103 ······························line·for·already·installed·kernels:103 ······························line·for·already·installed·kernels:
104 ······························#·grubby·--update-kernel=ALL·--104 ······························#·grubby·--update-kernel=ALL·--
105 ······························args="iommu=force"105 ······························args="iommu=force"
106 ······························Microarchitectural·Data·Sampling·(MDS)·is·a 
107 ······························hardware·vulnerability·which·allows 
108 ······························unprivileged·speculative·access·to·data 
109 ······························which·is·available·in·various·CPU·internal 
110 ······························buffers.·When·performing·store,·load,·L1 
111 ······························refill·operations,·processors·write·data 
112 ······························into·temporary·microarchitectural·structures 
113 ······························(buffers),·and·the·data·in·the·buffer·can·be 
114 ······························forwarded·to·load·operations·as·an 
115 ······························optimization.·Under·certain·conditions,·data 
116 ······························unrelated·to·the·load·operations·can·be 
117 ······························speculatively·forwarded·from·the·buffers·to 
118 ······························a·disclosure·gadget·which·allows·in·turn·to 
119 ······························infer·the·value·via·a·cache·side·channel 
120 ······························attack.·Select·the·appropriate·mitigation·by106 ······························The·kernel·may·merge·similar·slabs·together
 107 ······························to·reduce·overhead·and·increase·cache
 108 ······························hotness·of·objects.·Disabling·merging·of
 109 ······························slabs·keeps·the·slabs·separate·and·reduces
 110 ······························the·risk·of·kernel·heap·overflows
 111 ······························overwriting·objects·in·merged·caches.·To·····Disabling·the·merge·of·slabs·of
 112 ······························disable·merging·of·slabs·in·the·Kernel·add···similar·sizes·prevents·the·kernel·from
 113 ······························the·argument·slab_nomerge=yes·to·the·default·merging·a·seemingly·useless·but
 114 ······························GRUB·2·command·line·for·the·Linux·operating··vulnerable·slab·with·a·useful·and
 115 ······························system.·To·ensure·that·slab_nomerge=yes·is···valuable·slab.·This·increase·the·risk
 116 R8··Disable·merging·of·slabs··added·as·a·kernel·command·line·argument·to···that·a·heap·overflow·could·overwrite
 117 ····with·similar·size·········newly·installed·kernels,·add·················objects·from·merged·caches,·with
 118 ······························slab_nomerge=yes·to·the·default·Grub2········unmerged·caches·the·heap·overflow
 119 ······························command·line·for·Linux·operating·systems.····would·only·affect·the·objects·in·the
 120 ······························Modify·the·line·within·/etc/default/grub·as··same·cache.·Overall,·this·reduces·the
 121 ······························shown·below:·································kernel·attack·surface·area·by
 122 ······························GRUB_CMDLINE_LINUX="...·slab_nomerge=yes·····isolating·slabs·from·each·other.
 123 ······························..."
 124 ······························Run·the·following·command·to·update·command
 125 ······························line·for·already·installed·kernels:
 126 ······························#·grubby·--update-kernel=ALL·--
 127 ······························args="slab_nomerge=yes"
 128 ······························To·enable·Kernel·page-table·isolation,·add
121 ······························adding·the·argument·mds=full·to·the·default129 ······························the·argument·pti=on·to·the·default·GRUB·2
122 ····Configure·················GRUB·2·command·line·for·the·Linux·operating··The·MDS·vulnerability·allows·an 
123 R8··Microarchitectural·Data···system.·To·ensure·that·mds=full·is·added·as··attacker·to·sample·data·from·internal 
124 ····Sampling·mitigation·······a·kernel·command·line·argument·to·newly······CPU·buffers.130 ······························command·line·for·the·Linux·operating·system.
Max diff block lines reached; 679003/694530 bytes (97.76%) of diff not shown.
1.36 MB
./usr/share/doc/ssg-nondebian/table-rhel8-cisrefs.html
    
Offset 1846, 461 lines modifiedOffset 1846, 461 lines modified
00007350:·652d·7573·6572·206d·6f64·652e·0a20·2020··e-user·mode..···00007350:·652d·7573·6572·206d·6f64·652e·0a20·2020··e-user·mode..···
00007360:·2020·203c·2f74·643e·0a20·2020·203c·2f74·····</td>.····</t00007360:·2020·203c·2f74·643e·0a20·2020·203c·2f74·····</td>.····</t
00007370:·723e·0a20·2020·203c·7472·3e0a·2020·2020··r>.····<tr>.····00007370:·723e·0a20·2020·203c·7472·3e0a·2020·2020··r>.····<tr>.····
00007380:·2020·3c74·643e·312e·332e·323c·2f74·643e····<td>1.3.2</td>00007380:·2020·3c74·643e·312e·332e·323c·2f74·643e····<td>1.3.2</td>
00007390:·0a20·2020·2020·203c·7464·3e56·6572·6966··.······<td>Verif00007390:·0a20·2020·2020·203c·7464·3e56·6572·6966··.······<td>Verif
000073a0:·7920·7468·6520·5545·4649·2042·6f6f·7420··y·the·UEFI·Boot·000073a0:·7920·7468·6520·5545·4649·2042·6f6f·7420··y·the·UEFI·Boot·
Diff chunk too large, falling back to line-by-line diff (447 lines added, 447 lines removed)
000073b0:·4c6f·6164·6572·2067·7275·622e·6366·6720··Loader·grub.cfg·000073b0:·4c6f·6164·6572·2067·7275·622e·6366·6720··Loader·grub.cfg·
000073c0:·4772·6f75·7020·4f77·6e65·7273·6869·703c··Group·Ownership<000073c0:·5573·6572·204f·776e·6572·7368·6970·3c2f··User·Ownership</
000073d0:·2f74·643e·0a20·2020·2020·203c·7464·2078··/td>.······<td·x000073d0:·7464·3e0a·2020·2020·2020·3c74·6420·786d··td>.······<td·xm
000073e0:·6d6c·3a6c·616e·673d·2265·6e2d·5553·223e··ml:lang="en-US">000073e0:·6c3a·6c61·6e67·3d22·656e·2d55·5322·3e0a··l:lang="en-US">.
000073f0:·0a20·2020·2020·2020·2054·6865·2066·696c··.········The·fil000073f0:·2020·2020·2020·2020·5468·6520·6669·6c65··········The·file
00007400:·6520·3c74·743e·2f62·6f6f·742f·6566·692f··e·<tt>/boot/efi/00007400:·203c·7474·3e2f·626f·6f74·2f65·6669·2f45···<tt>/boot/efi/E
00007410:·4546·492f·7265·6468·6174·2f67·7275·622e··EFI/redhat/grub.00007410:·4649·2f72·6564·6861·742f·6772·7562·2e63··FI/redhat/grub.c
00007420:·6366·673c·2f74·743e·2073·686f·756c·640a··cfg</tt>·should.00007420:·6667·3c2f·7474·3e20·7368·6f75·6c64·0a62··fg</tt>·should.b
00007430:·6265·2067·726f·7570·2d6f·776e·6564·2062··be·group-owned·b00007430:·6520·6f77·6e65·6420·6279·2074·6865·203c··e·owned·by·the·<
00007440:·7920·7468·6520·3c74·743e·726f·6f74·3c2f··y·the·<tt>root</00007440:·7474·3e72·6f6f·743c·2f74·743e·2075·7365··tt>root</tt>·use
00007450:·7474·3e20·6772·6f75·7020·746f·2070·7265··tt>·group·to·pre00007450:·7220·746f·2070·7265·7665·6e74·2064·6573··r·to·prevent·des
00007460:·7665·6e74·0a64·6573·7472·7563·7469·6f6e··vent.destruction00007460:·7472·7563·7469·6f6e·0a6f·7220·6d6f·6469··truction.or·modi
00007470:·206f·7220·6d6f·6469·6669·6361·7469·6f6e···or·modification00007470:·6669·6361·7469·6f6e·206f·6620·7468·6520··fication·of·the·
00007480:·206f·6620·7468·6520·6669·6c65·2e0a·0a54···of·the·file...T00007480:·6669·6c65·2e0a·0a54·6f20·7072·6f70·6572··file...To·proper
00007490:·6f20·7072·6f70·6572·6c79·2073·6574·2074··o·properly·set·t00007490:·6c79·2073·6574·2074·6865·206f·776e·6572··ly·set·the·owner
000074a0:·6865·2067·726f·7570·206f·776e·6572·206f··he·group·owner·o000074a0:·206f·6620·3c63·6f64·653e·2f62·6f6f·742f···of·<code>/boot/
000074b0:·6620·3c63·6f64·653e·2f62·6f6f·742f·6566··f·<code>/boot/ef000074b0:·6566·692f·4546·492f·7265·6468·6174·2f67··efi/EFI/redhat/g
000074c0:·692f·4546·492f·7265·6468·6174·2f67·7275··i/EFI/redhat/gru000074c0:·7275·622e·6366·673c·2f63·6f64·653e·2c20··rub.cfg</code>,·
000074d0:·622e·6366·673c·2f63·6f64·653e·2c20·7275··b.cfg</code>,·ru000074d0:·7275·6e20·7468·6520·636f·6d6d·616e·643a··run·the·command:
000074e0:·6e20·7468·6520·636f·6d6d·616e·643a·0a3c··n·the·command:.<000074e0:·0a3c·7072·653e·2420·7375·646f·2063·686f··.<pre>$·sudo·cho
000074f0:·7072·653e·2420·7375·646f·2063·6867·7270··pre>$·sudo·chgrp000074f0:·776e·2072·6f6f·7420·2f62·6f6f·742f·6566··wn·root·/boot/ef
00007500:·2072·6f6f·7420·2f62·6f6f·742f·6566·692f···root·/boot/efi/00007500:·692f·4546·492f·7265·6468·6174·2f67·7275··i/EFI/redhat/gru
00007510:·4546·492f·7265·6468·6174·2f67·7275·622e··EFI/redhat/grub.00007510:·622e·6366·6720·3c2f·7072·653e·0a20·2020··b.cfg·</pre>.···
00007520:·6366·673c·2f70·7265·3e0a·2020·2020·2020··cfg</pre>.······00007520:·2020·203c·2f74·643e·0a20·2020·2020·203c·····</td>.······<
00007530:·3c2f·7464·3e0a·2020·2020·2020·3c74·6420··</td>.······<td·00007530:·7464·2078·6d6c·3a6c·616e·673d·2265·6e2d··td·xml:lang="en-
00007540:·786d·6c3a·6c61·6e67·3d22·656e·2d55·5322··xml:lang="en-US"00007540:·5553·223e·0a20·2020·2020·2020·204f·6e6c··US">.········Onl
00007550:·3e0a·2020·2020·2020·2020·5468·6520·3c74··>.········The·<t00007550:·7920·726f·6f74·2073·686f·756c·6420·6265··y·root·should·be
00007560:·743e·726f·6f74·3c2f·7474·3e20·6772·6f75··t>root</tt>·grou00007560:·2061·626c·6520·746f·206d·6f64·6966·7920···able·to·modify·
00007570:·7020·6973·2061·2068·6967·686c·792d·7072··p·is·a·highly-pr00007570:·696d·706f·7274·616e·7420·626f·6f74·2070··important·boot·p
00007580:·6976·696c·6567·6564·2067·726f·7570·2e20··ivileged·group.·00007580:·6172·616d·6574·6572·732e·0a20·2020·2020··arameters..·····
00007590:·4675·7274·6865·726d·6f72·652c·2074·6865··Furthermore,·the00007590:·203c·2f74·643e·0a20·2020·203c·2f74·723e···</td>.····</tr>
000075a0:·2067·726f·7570·2d6f·776e·6572·206f·6620···group-owner·of·000075a0:·0a20·2020·203c·7472·3e0a·2020·2020·2020··.····<tr>.······
000075b0:·7468·6973·0a66·696c·6520·7368·6f75·6c64··this.file·should000075b0:·3c74·643e·312e·332e·323c·2f74·643e·0a20··<td>1.3.2</td>.·
000075c0:·206e·6f74·2068·6176·6520·616e·7920·6163···not·have·any·ac000075c0:·2020·2020·203c·7464·3e56·6572·6966·7920·······<td>Verify·
000075d0:·6365·7373·2070·7269·7669·6c65·6765·7320··cess·privileges·000075d0:·2f62·6f6f·742f·6772·7562·322f·6772·7562··/boot/grub2/grub
000075e0:·616e·7977·6179·2e0a·2020·2020·2020·3c2f··anyway..······</000075e0:·2e63·6667·2055·7365·7220·4f77·6e65·7273··.cfg·User·Owners
000075f0:·7464·3e0a·2020·2020·3c2f·7472·3e0a·2020··td>.····</tr>.··000075f0:·6869·703c·2f74·643e·0a20·2020·2020·203c··hip</td>.······<
00007600:·2020·3c74·723e·0a20·2020·2020·203c·7464····<tr>.······<td00007600:·7464·2078·6d6c·3a6c·616e·673d·2265·6e2d··td·xml:lang="en-
00007610:·3e31·2e33·2e32·3c2f·7464·3e0a·2020·2020··>1.3.2</td>.····00007610:·5553·223e·0a20·2020·2020·2020·2054·6865··US">.········The
00007620:·2020·3c74·643e·5665·7269·6679·202f·626f····<td>Verify·/bo00007620:·2066·696c·6520·3c74·743e·2f62·6f6f·742f···file·<tt>/boot/
00007630:·6f74·2f67·7275·6232·2f75·7365·722e·6366··ot/grub2/user.cf00007630:·6772·7562·322f·6772·7562·2e63·6667·3c2f··grub2/grub.cfg</
00007640:·6720·5573·6572·204f·776e·6572·7368·6970··g·User·Ownership00007640:·7474·3e20·7368·6f75·6c64·0a62·6520·6f77··tt>·should.be·ow
00007650:·3c2f·7464·3e0a·2020·2020·2020·3c74·6420··</td>.······<td·00007650:·6e65·6420·6279·2074·6865·203c·7474·3e72··ned·by·the·<tt>r
00007660:·786d·6c3a·6c61·6e67·3d22·656e·2d55·5322··xml:lang="en-US"00007660:·6f6f·743c·2f74·743e·2075·7365·7220·746f··oot</tt>·user·to
00007670:·3e0a·2020·2020·2020·2020·5468·6520·6669··>.········The·fi00007670:·2070·7265·7665·6e74·2064·6573·7472·7563···prevent·destruc
00007680:·6c65·203c·7474·3e2f·626f·6f74·2f67·7275··le·<tt>/boot/gru00007680:·7469·6f6e·0a6f·7220·6d6f·6469·6669·6361··tion.or·modifica
00007690:·6232·2f75·7365·722e·6366·673c·2f74·743e··b2/user.cfg</tt>00007690:·7469·6f6e·206f·6620·7468·6520·6669·6c65··tion·of·the·file
000076a0:·2073·686f·756c·6420·6265·206f·776e·6564···should·be·owned000076a0:·2e0a·0a54·6f20·7072·6f70·6572·6c79·2073··...To·properly·s
000076b0:·2062·7920·7468·6520·3c74·743e·726f·6f74···by·the·<tt>root000076b0:·6574·2074·6865·206f·776e·6572·206f·6620··et·the·owner·of·
000076c0:·3c2f·7474·3e0a·7573·6572·2074·6f20·7072··</tt>.user·to·pr000076c0:·3c63·6f64·653e·2f62·6f6f·742f·6772·7562··<code>/boot/grub
000076d0:·6576·656e·7420·7265·6164·696e·6720·6f72··event·reading·or000076d0:·322f·6772·7562·2e63·6667·3c2f·636f·6465··2/grub.cfg</code
000076e0:·206d·6f64·6966·6963·6174·696f·6e20·6f66···modification·of000076e0:·3e2c·2072·756e·2074·6865·2063·6f6d·6d61··>,·run·the·comma
000076f0:·2074·6865·2066·696c·652e·0a0a·546f·2070···the·file...To·p000076f0:·6e64·3a0a·3c70·7265·3e24·2073·7564·6f20··nd:.<pre>$·sudo·
00007700:·726f·7065·726c·7920·7365·7420·7468·6520··roperly·set·the·00007700:·6368·6f77·6e20·726f·6f74·202f·626f·6f74··chown·root·/boot
00007710:·6f77·6e65·7220·6f66·203c·636f·6465·3e2f··owner·of·<code>/00007710:·2f67·7275·6232·2f67·7275·622e·6366·6720··/grub2/grub.cfg·
00007720:·626f·6f74·2f67·7275·6232·2f75·7365·722e··boot/grub2/user.00007720:·3c2f·7072·653e·0a20·2020·2020·203c·2f74··</pre>.······</t
00007730:·6366·673c·2f63·6f64·653e·2c20·7275·6e20··cfg</code>,·run·00007730:·643e·0a20·2020·2020·203c·7464·2078·6d6c··d>.······<td·xml
00007740:·7468·6520·636f·6d6d·616e·643a·0a3c·7072··the·command:.<pr00007740:·3a6c·616e·673d·2265·6e2d·5553·223e·0a20··:lang="en-US">.·
00007750:·653e·2420·7375·646f·2063·686f·776e·2072··e>$·sudo·chown·r00007750:·2020·2020·2020·204f·6e6c·7920·726f·6f74·········Only·root
00007760:·6f6f·7420·2f62·6f6f·742f·6772·7562·322f··oot·/boot/grub2/00007760:·2073·686f·756c·6420·6265·2061·626c·6520···should·be·able·
00007770:·7573·6572·2e63·6667·203c·2f70·7265·3e0a··user.cfg·</pre>.00007770:·746f·206d·6f64·6966·7920·696d·706f·7274··to·modify·import
00007780:·2020·2020·2020·3c2f·7464·3e0a·2020·2020········</td>.····00007780:·616e·7420·626f·6f74·2070·6172·616d·6574··ant·boot·paramet
00007790:·2020·3c74·6420·786d·6c3a·6c61·6e67·3d22····<td·xml:lang="00007790:·6572·732e·0a20·2020·2020·203c·2f74·643e··ers..······</td>
000077a0:·656e·2d55·5322·3e0a·2020·2020·2020·2020··en-US">.········000077a0:·0a20·2020·203c·2f74·723e·0a20·2020·203c··.····</tr>.····<
000077b0:·4f6e·6c79·2072·6f6f·7420·7368·6f75·6c64··Only·root·should000077b0:·7472·3e0a·2020·2020·2020·3c74·643e·312e··tr>.······<td>1.
000077c0:·2062·6520·6162·6c65·2074·6f20·6d6f·6469···be·able·to·modi000077c0:·332e·323c·2f74·643e·0a20·2020·2020·203c··3.2</td>.······<
000077d0:·6679·2069·6d70·6f72·7461·6e74·2062·6f6f··fy·important·boo000077d0:·7464·3e56·6572·6966·7920·2f62·6f6f·742f··td>Verify·/boot/
000077e0:·7420·7061·7261·6d65·7465·7273·2e20·416c··t·parameters.·Al000077e0:·6566·692f·4546·492f·7265·6468·6174·2f75··efi/EFI/redhat/u
000077f0:·736f·2c20·6e6f·6e2d·726f·6f74·2075·7365··so,·non-root·use000077f0:·7365·722e·6366·6720·5573·6572·204f·776e··ser.cfg·User·Own
00007800:·7273·2077·686f·2072·6561·640a·7468·6520··rs·who·read.the·00007800:·6572·7368·6970·3c2f·7464·3e0a·2020·2020··ership</td>.····
00007810:·626f·6f74·2070·6172·616d·6574·6572·7320··boot·parameters·00007810:·2020·3c74·6420·786d·6c3a·6c61·6e67·3d22····<td·xml:lang="
00007820:·6d61·7920·6265·2061·626c·6520·746f·2069··may·be·able·to·i00007820:·656e·2d55·5322·3e0a·2020·2020·2020·2020··en-US">.········
00007830:·6465·6e74·6966·7920·7765·616b·6e65·7373··dentify·weakness00007830:·5468·6520·6669·6c65·203c·7474·3e2f·626f··The·file·<tt>/bo
00007840:·6573·2069·6e20·7365·6375·7269·7479·2075··es·in·security·u00007840:·6f74·2f65·6669·2f45·4649·2f72·6564·6861··ot/efi/EFI/redha
00007850:·706f·6e20·626f·6f74·2061·6e64·2062·6520··pon·boot·and·be·00007850:·742f·7573·6572·2e63·6667·3c2f·7474·3e20··t/user.cfg</tt>·
00007860:·6162·6c65·2074·6f0a·6578·706c·6f69·7420··able·to.exploit·00007860:·7368·6f75·6c64·2062·6520·6f77·6e65·6420··should·be·owned·
00007870:·7468·656d·2e0a·2020·2020·2020·3c2f·7464··them..······</td00007870:·6279·2074·6865·203c·7474·3e72·6f6f·743c··by·the·<tt>root<
00007880:·3e0a·2020·2020·3c2f·7472·3e0a·2020·2020··>.····</tr>.····00007880:·2f74·743e·0a75·7365·7220·746f·2070·7265··/tt>.user·to·pre
00007890:·3c74·723e·0a20·2020·2020·203c·7464·3e31··<tr>.······<td>100007890:·7665·6e74·2072·6561·6469·6e67·206f·7220··vent·reading·or·
000078a0:·2e33·2e32·3c2f·7464·3e0a·2020·2020·2020··.3.2</td>.······000078a0:·6d6f·6469·6669·6361·7469·6f6e·206f·6620··modification·of·
000078b0:·3c74·643e·5665·7269·6679·2074·6865·2055··<td>Verify·the·U000078b0:·7468·6520·6669·6c65·2e0a·0a54·6f20·7072··the·file...To·pr
000078c0:·4546·4920·426f·6f74·204c·6f61·6465·7220··EFI·Boot·Loader·000078c0:·6f70·6572·6c79·2073·6574·2074·6865·206f··operly·set·the·o
000078d0:·6772·7562·2e63·6667·2050·6572·6d69·7373··grub.cfg·Permiss000078d0:·776e·6572·206f·6620·3c63·6f64·653e·2f62··wner·of·<code>/b
000078e0:·696f·6e73·3c2f·7464·3e0a·2020·2020·2020··ions</td>.······000078e0:·6f6f·742f·6566·692f·4546·492f·7265·6468··oot/efi/EFI/redh
000078f0:·3c74·6420·786d·6c3a·6c61·6e67·3d22·656e··<td·xml:lang="en000078f0:·6174·2f75·7365·722e·6366·673c·2f63·6f64··at/user.cfg</cod
00007900:·2d55·5322·3e0a·2020·2020·2020·2020·4669··-US">.········Fi00007900:·653e·2c20·7275·6e20·7468·6520·636f·6d6d··e>,·run·the·comm
00007910:·6c65·2070·6572·6d69·7373·696f·6e73·2066··le·permissions·f00007910:·616e·643a·0a3c·7072·653e·2420·7375·646f··and:.<pre>$·sudo
00007920:·6f72·203c·7474·3e2f·626f·6f74·2f65·6669··or·<tt>/boot/efi00007920:·2063·686f·776e·2072·6f6f·7420·2f62·6f6f···chown·root·/boo
00007930:·2f45·4649·2f72·6564·6861·742f·6772·7562··/EFI/redhat/grub00007930:·742f·6566·692f·4546·492f·7265·6468·6174··t/efi/EFI/redhat
00007940:·2e63·6667·3c2f·7474·3e20·7368·6f75·6c64··.cfg</tt>·should00007940:·2f75·7365·722e·6366·6720·3c2f·7072·653e··/user.cfg·</pre>
00007950:·2062·6520·7365·7420·746f·2037·3030·2e0a···be·set·to·700..00007950:·0a20·2020·2020·203c·2f74·643e·0a20·2020··.······</td>.···
00007960:·0a54·6f20·7072·6f70·6572·6c79·2073·6574··.To·properly·set00007960:·2020·203c·7464·2078·6d6c·3a6c·616e·673d·····<td·xml:lang=
00007970:·2074·6865·2070·6572·6d69·7373·696f·6e73···the·permissions00007970:·2265·6e2d·5553·223e·0a20·2020·2020·2020··"en-US">.·······
00007980:·206f·6620·3c63·6f64·653e·2f62·6f6f·742f···of·<code>/boot/00007980:·204f·6e6c·7920·726f·6f74·2073·686f·756c···Only·root·shoul
00007990:·6566·692f·4546·492f·7265·6468·6174·2f67··efi/EFI/redhat/g00007990:·6420·6265·2061·626c·6520·746f·206d·6f64··d·be·able·to·mod
000079a0:·7275·622e·6366·673c·2f63·6f64·653e·2c20··rub.cfg</code>,·000079a0:·6966·7920·696d·706f·7274·616e·7420·626f··ify·important·bo
000079b0:·7275·6e20·7468·6520·636f·6d6d·616e·643a··run·the·command:000079b0:·6f74·2070·6172·616d·6574·6572·732e·2041··ot·parameters.·A
000079c0:·0a3c·7072·653e·2420·7375·646f·2063·686d··.<pre>$·sudo·chm000079c0:·6c73·6f2c·206e·6f6e·2d72·6f6f·7420·7573··lso,·non-root·us
000079d0:·6f64·2037·3030·202f·626f·6f74·2f65·6669··od·700·/boot/efi000079d0:·6572·7320·7768·6f20·7265·6164·0a74·6865··ers·who·read.the
000079e0:·2f45·4649·2f72·6564·6861·742f·6772·7562··/EFI/redhat/grub000079e0:·2062·6f6f·7420·7061·7261·6d65·7465·7273···boot·parameters
000079f0:·2e63·6667·3c2f·7072·653e·0a20·2020·2020··.cfg</pre>.·····000079f0:·206d·6179·2062·6520·6162·6c65·2074·6f20···may·be·able·to·
00007a00:·203c·2f74·643e·0a20·2020·2020·203c·7464···</td>.······<td00007a00:·6964·656e·7469·6679·2077·6561·6b6e·6573··identify·weaknes
00007a10:·2078·6d6c·3a6c·616e·673d·2265·6e2d·5553···xml:lang="en-US00007a10:·7365·7320·696e·2073·6563·7572·6974·7920··ses·in·security·
00007a20:·223e·0a20·2020·2020·2020·2050·726f·7065··">.········Prope00007a20:·7570·6f6e·2062·6f6f·7420·616e·6420·6265··upon·boot·and·be
00007a30:·7220·7065·726d·6973·7369·6f6e·7320·656e··r·permissions·en00007a30:·2061·626c·6520·746f·0a65·7870·6c6f·6974···able·to.exploit
00007a40:·7375·7265·2074·6861·7420·6f6e·6c79·2074··sure·that·only·t00007a40:·2074·6865·6d2e·0a20·2020·2020·203c·2f74···them..······</t
00007a50:·6865·2072·6f6f·7420·7573·6572·2063·616e··he·root·user·can00007a50:·643e·0a20·2020·203c·2f74·723e·0a20·2020··d>.····</tr>.···
00007a60:·206d·6f64·6966·7920·696d·706f·7274·616e···modify·importan00007a60:·203c·7472·3e0a·2020·2020·2020·3c74·643e···<tr>.······<td>
00007a70:·7420·626f·6f74·0a70·6172·616d·6574·6572··t·boot.parameter00007a70:·312e·332e·323c·2f74·643e·0a20·2020·2020··1.3.2</td>.·····
00007a80:·732e·0a20·2020·2020·203c·2f74·643e·0a20··s..······</td>.·00007a80:·203c·7464·3e56·6572·6966·7920·2f62·6f6f···<td>Verify·/boo
00007a90:·2020·203c·2f74·723e·0a20·2020·203c·7472·····</tr>.····<tr00007a90:·742f·6566·692f·4546·492f·7265·6468·6174··t/efi/EFI/redhat
00007aa0:·3e0a·2020·2020·2020·3c74·643e·312e·332e··>.······<td>1.3.00007aa0:·2f75·7365·722e·6366·6720·4772·6f75·7020··/user.cfg·Group·
00007ab0:·323c·2f74·643e·0a20·2020·2020·203c·7464··2</td>.······<td00007ab0:·4f77·6e65·7273·6869·703c·2f74·643e·0a20··Ownership</td>.·
00007ac0:·3e56·6572·6966·7920·2f62·6f6f·742f·6772··>Verify·/boot/gr00007ac0:·2020·2020·203c·7464·2078·6d6c·3a6c·616e·······<td·xml:lan
00007ad0:·7562·322f·6772·7562·2e63·6667·2047·726f··ub2/grub.cfg·Gro00007ad0:·673d·2265·6e2d·5553·223e·0a20·2020·2020··g="en-US">.·····
00007ae0:·7570·204f·776e·6572·7368·6970·3c2f·7464··up·Ownership</td00007ae0:·2020·2054·6865·2066·696c·6520·3c74·743e·····The·file·<tt>
00007af0:·3e0a·2020·2020·2020·3c74·6420·786d·6c3a··>.······<td·xml:00007af0:·2f62·6f6f·742f·6566·692f·4546·492f·7265··/boot/efi/EFI/re
00007b00:·6c61·6e67·3d22·656e·2d55·5322·3e0a·2020··lang="en-US">.··00007b00:·6468·6174·2f75·7365·722e·6366·673c·2f74··dhat/user.cfg</t
00007b10:·2020·2020·2020·5468·6520·6669·6c65·203c········The·file·<00007b10:·743e·2073·686f·756c·6420·6265·2067·726f··t>·should·be·gro
00007b20:·7474·3e2f·626f·6f74·2f67·7275·6232·2f67··tt>/boot/grub2/g00007b20:·7570·2d6f·776e·6564·2062·7920·7468·650a··up-owned·by·the.
Max diff block lines reached; 1031711/1093975 bytes (94.31%) of diff not shown.
327 KB
html2text {}
    
Offset 461, 55 lines modifiedOffset 461, 24 lines modified
461 1.3.1·············Set·the·UEFI·Boot···Since·plaintext·passwords·are·a·security·risk,·········cannot·trivially461 1.3.1·············Set·the·UEFI·Boot···Since·plaintext·passwords·are·a·security·risk,·········cannot·trivially
462 ··················Loader·Password·····generate·a·hash·for·the·password·by·running·the········alter·important462 ··················Loader·Password·····generate·a·hash·for·the·password·by·running·the········alter·important
463 ······································following·command:·····································bootloader·settings.463 ······································following·command:·····································bootloader·settings.
464 ······································#·grub2-setpassword····································These·include·which464 ······································#·grub2-setpassword····································These·include·which
465 ······································When·prompted,·enter·the·password·that·was·selected.···kernel·to·use,·and465 ······································When·prompted,·enter·the·password·that·was·selected.···kernel·to·use,·and
466 ·····························································································whether·to·enter466 ·····························································································whether·to·enter
467 ·····························································································single-user·mode.467 ·····························································································single-user·mode.
468 ······································The·file·/boot/efi/EFI/redhat/grub.cfg·should·be·······The·root·group·is·a 
469 ··················Verify·the·UEFI·····group-owned·by·the·root·group·to·prevent·destruction···highly-privileged 
470 ··················Boot·Loader·········or·modification·of·the·file.·To·properly·set·the·group·group.·Furthermore, 
471 1.3.2·············grub.cfg·Group······owner·of·/boot/efi/EFI/redhat/grub.cfg,·run·the········the·group-owner·of 
472 ··················Ownership···········command:···············································this·file·should·not 
473 ······································$·sudo·chgrp·root·/boot/efi/EFI/redhat/grub.cfg········have·any·access 
474 ·····························································································privileges·anyway. 
475 ·····························································································Only·root·should·be 
476 ·····························································································able·to·modify 
477 ·····························································································important·boot 
478 ······································The·file·/boot/grub2/user.cfg·should·be·owned·by·the···parameters.·Also, 
479 ··················Verify·/boot/grub2/·root·user·to·prevent·reading·or·modification·of·the····non-root·users·who 
480 1.3.2·············user.cfg·User·······file.·To·properly·set·the·owner·of·/boot/grub2/········read·the·boot 
481 ··················Ownership···········user.cfg,·run·the·command:·····························parameters·may·be 
482 ······································$·sudo·chown·root·/boot/grub2/user.cfg·················able·to·identify 
483 ·····························································································weaknesses·in 
484 ·····························································································security·upon·boot 
485 ·····························································································and·be·able·to 
486 ·····························································································exploit·them. 
487 ··················Verify·the·UEFI·····File·permissions·for·/boot/efi/EFI/redhat/grub.cfg·····Proper·permissions 
488 ··················Boot·Loader·········should·be·set·to·700.·To·properly·set·the·permissions··ensure·that·only·the 
489 1.3.2·············grub.cfg············of·/boot/efi/EFI/redhat/grub.cfg,·run·the·command:·····root·user·can·modify 
490 ··················Permissions·········$·sudo·chmod·700·/boot/efi/EFI/redhat/grub.cfg·········important·boot 
491 ·····························································································parameters. 
492 ·····························································································The·root·group·is·a 
493 ······································The·file·/boot/grub2/grub.cfg·should·be·group-owned·by·highly-privileged 
494 ··················Verify·/boot/grub2/·the·root·group·to·prevent·destruction·or·modification··group.·Furthermore, 
495 1.3.2·············grub.cfg·Group······of·the·file.·To·properly·set·the·group·owner·of·/boot/·the·group-owner·of 
496 ··················Ownership···········grub2/grub.cfg,·run·the·command:·······················this·file·should·not 
497 ······································$·sudo·chgrp·root·/boot/grub2/grub.cfg·················have·any·access 
498 ·····························································································privileges·anyway. 
499 ······································File·permissions·for·/boot/efi/EFI/redhat/user.cfg·····Proper·permissions 
500 ··················Verify·/boot/efi/···should·be·set·to·600.·To·properly·set·the·permissions··ensure·that·only·the 
501 1.3.2·············EFI/redhat/user.cfg·of·/boot/efi/EFI/redhat/user.cfg,·run·the·command:·····root·user·can·read 
502 ··················Permissions·········$·sudo·chmod·600·/boot/efi/EFI/redhat/user.cfg·········or·modify·important 
503 ·····························································································boot·parameters. 
504 ··················Verify·the·UEFI·····The·file·/boot/efi/EFI/redhat/grub.cfg·should·be·owned·Only·root·should·be468 ··················Verify·the·UEFI·····The·file·/boot/efi/EFI/redhat/grub.cfg·should·be·owned·Only·root·should·be
505 ··················Boot·Loader·········by·the·root·user·to·prevent·destruction·or·············able·to·modify469 ··················Boot·Loader·········by·the·root·user·to·prevent·destruction·or·············able·to·modify
506 1.3.2·············grub.cfg·User·······modification·of·the·file.·To·properly·set·the·owner·of·important·boot470 1.3.2·············grub.cfg·User·······modification·of·the·file.·To·properly·set·the·owner·of·important·boot
507 ··················Ownership···········/boot/efi/EFI/redhat/grub.cfg,·run·the·command:········parameters.471 ··················Ownership···········/boot/efi/EFI/redhat/grub.cfg,·run·the·command:········parameters.
508 ······································$·sudo·chown·root·/boot/efi/EFI/redhat/grub.cfg472 ······································$·sudo·chown·root·/boot/efi/EFI/redhat/grub.cfg
 473 ······································The·file·/boot/grub2/grub.cfg·should·be·owned·by·the···Only·root·should·be
 474 ··················Verify·/boot/grub2/·root·user·to·prevent·destruction·or·modification·of····able·to·modify
 475 1.3.2·············grub.cfg·User·······the·file.·To·properly·set·the·owner·of·/boot/grub2/····important·boot
 476 ··················Ownership···········grub.cfg,·run·the·command:·····························parameters.
 477 ······································$·sudo·chown·root·/boot/grub2/grub.cfg
509 ·····························································································Only·root·should·be478 ·····························································································Only·root·should·be
510 ·····························································································able·to·modify479 ·····························································································able·to·modify
511 ·····························································································important·boot480 ·····························································································important·boot
512 ······································The·file·/boot/efi/EFI/redhat/user.cfg·should·be·owned·parameters.·Also,481 ······································The·file·/boot/efi/EFI/redhat/user.cfg·should·be·owned·parameters.·Also,
513 ··················Verify·/boot/efi/···by·the·root·user·to·prevent·reading·or·modification·of·non-root·users·who482 ··················Verify·/boot/efi/···by·the·root·user·to·prevent·reading·or·modification·of·non-root·users·who
514 1.3.2·············EFI/redhat/user.cfg·the·file.·To·properly·set·the·owner·of·/boot/efi/EFI/··read·the·boot483 1.3.2·············EFI/redhat/user.cfg·the·file.·To·properly·set·the·owner·of·/boot/efi/EFI/··read·the·boot
515 ··················User·Ownership······redhat/user.cfg,·run·the·command:······················parameters·may·be484 ··················User·Ownership······redhat/user.cfg,·run·the·command:······················parameters·may·be
Offset 529, 29 lines modifiedOffset 498, 24 lines modified
529 ··················Group·Ownership·····command:···············································read·the·boot498 ··················Group·Ownership·····command:···············································read·the·boot
530 ······································$·sudo·chgrp·root·/boot/efi/EFI/redhat/user.cfg········parameters·may·be499 ······································$·sudo·chgrp·root·/boot/efi/EFI/redhat/user.cfg········parameters·may·be
531 ·····························································································able·to·identify500 ·····························································································able·to·identify
532 ·····························································································weaknesses·in501 ·····························································································weaknesses·in
533 ·····························································································security·upon·boot502 ·····························································································security·upon·boot
534 ·····························································································and·be·able·to503 ·····························································································and·be·able·to
535 ·····························································································exploit·them.504 ·····························································································exploit·them.
536 ······································The·file·/boot/grub2/grub.cfg·should·be·owned·by·the···Only·root·should·be 
537 ··················Verify·/boot/grub2/·root·user·to·prevent·destruction·or·modification·of····able·to·modify 
538 1.3.2·············grub.cfg·User·······the·file.·To·properly·set·the·owner·of·/boot/grub2/····important·boot 
539 ··················Ownership···········grub.cfg,·run·the·command:·····························parameters. 
540 ······································$·sudo·chown·root·/boot/grub2/grub.cfg505 ··················Verify·the·UEFI·····File·permissions·for·/boot/efi/EFI/redhat/grub.cfg·····Proper·permissions
 506 ··················Boot·Loader·········should·be·set·to·700.·To·properly·set·the·permissions··ensure·that·only·the
 507 1.3.2·············grub.cfg············of·/boot/efi/EFI/redhat/grub.cfg,·run·the·command:·····root·user·can·modify
 508 ··················Permissions·········$·sudo·chmod·700·/boot/efi/EFI/redhat/grub.cfg·········important·boot
 509 ·····························································································parameters.
541 ······································File·permissions·for·/boot/grub2/grub.cfg·should·be····Proper·permissions510 ······································File·permissions·for·/boot/grub2/grub.cfg·should·be····Proper·permissions
542 ··················Verify·/boot/grub2/·set·to·600.·To·properly·set·the·permissions·of·/boot/··ensure·that·only·the511 ··················Verify·/boot/grub2/·set·to·600.·To·properly·set·the·permissions·of·/boot/··ensure·that·only·the
543 1.3.2·············grub.cfg············grub2/grub.cfg,·run·the·command:·······················root·user·can·modify512 1.3.2·············grub.cfg············grub2/grub.cfg,·run·the·command:·······················root·user·can·modify
544 ··················Permissions·········$·sudo·chmod·600·/boot/grub2/grub.cfg··················important·boot513 ··················Permissions·········$·sudo·chmod·600·/boot/grub2/grub.cfg··················important·boot
545 ·····························································································parameters.514 ·····························································································parameters.
546 ······································File·permissions·for·/boot/grub2/user.cfg·should·be····Proper·permissions 
547 ··················Verify·/boot/grub2/·set·to·600.·To·properly·set·the·permissions·of·/boot/··ensure·that·only·the 
548 1.3.2·············user.cfg············grub2/user.cfg,·run·the·command:·······················root·user·can·read 
549 ··················Permissions·········$·sudo·chmod·600·/boot/grub2/user.cfg··················or·modify·important 
550 ·····························································································boot·parameters. 
551 ·····························································································The·root·group·is·a515 ·····························································································The·root·group·is·a
552 ·····························································································highly-privileged516 ·····························································································highly-privileged
553 ·····························································································group.·Furthermore,517 ·····························································································group.·Furthermore,
554 ·····························································································the·group-owner·of518 ·····························································································the·group-owner·of
555 ·····························································································this·file·should·not519 ·····························································································this·file·should·not
556 ······································The·file·/boot/grub2/user.cfg·should·be·group-owned·by·have·any·access520 ······································The·file·/boot/grub2/user.cfg·should·be·group-owned·by·have·any·access
557 ··················Verify·/boot/grub2/·the·root·group·to·prevent·reading·or·modification·of···privileges·anyway.521 ··················Verify·/boot/grub2/·the·root·group·to·prevent·reading·or·modification·of···privileges·anyway.
Offset 559, 14 lines modifiedOffset 523, 50 lines modified
559 ··················Ownership···········grub2/user.cfg,·run·the·command:·······················read·the·boot523 ··················Ownership···········grub2/user.cfg,·run·the·command:·······················read·the·boot
560 ······································$·sudo·chgrp·root·/boot/grub2/user.cfg·················parameters·may·be524 ······································$·sudo·chgrp·root·/boot/grub2/user.cfg·················parameters·may·be
561 ·····························································································able·to·identify525 ·····························································································able·to·identify
562 ·····························································································weaknesses·in526 ·····························································································weaknesses·in
563 ·····························································································security·upon·boot527 ·····························································································security·upon·boot
564 ·····························································································and·be·able·to528 ·····························································································and·be·able·to
565 ·····························································································exploit·them.529 ·····························································································exploit·them.
 530 ······································The·file·/boot/efi/EFI/redhat/grub.cfg·should·be·······The·root·group·is·a
 531 ··················Verify·the·UEFI·····group-owned·by·the·root·group·to·prevent·destruction···highly-privileged
 532 ··················Boot·Loader·········or·modification·of·the·file.·To·properly·set·the·group·group.·Furthermore,
 533 1.3.2·············grub.cfg·Group······owner·of·/boot/efi/EFI/redhat/grub.cfg,·run·the········the·group-owner·of
 534 ··················Ownership···········command:···············································this·file·should·not
 535 ······································$·sudo·chgrp·root·/boot/efi/EFI/redhat/grub.cfg········have·any·access
 536 ·····························································································privileges·anyway.
 537 ·····························································································Only·root·should·be
 538 ·····························································································able·to·modify
 539 ·····························································································important·boot
 540 ······································The·file·/boot/grub2/user.cfg·should·be·owned·by·the···parameters.·Also,
 541 ··················Verify·/boot/grub2/·root·user·to·prevent·reading·or·modification·of·the····non-root·users·who
 542 1.3.2·············user.cfg·User·······file.·To·properly·set·the·owner·of·/boot/grub2/········read·the·boot
 543 ··················Ownership···········user.cfg,·run·the·command:·····························parameters·may·be
 544 ······································$·sudo·chown·root·/boot/grub2/user.cfg·················able·to·identify
 545 ·····························································································weaknesses·in
 546 ·····························································································security·upon·boot
 547 ·····························································································and·be·able·to
 548 ·····························································································exploit·them.
 549 ······································File·permissions·for·/boot/grub2/user.cfg·should·be····Proper·permissions
 550 ··················Verify·/boot/grub2/·set·to·600.·To·properly·set·the·permissions·of·/boot/··ensure·that·only·the
 551 1.3.2·············user.cfg············grub2/user.cfg,·run·the·command:·······················root·user·can·read
 552 ··················Permissions·········$·sudo·chmod·600·/boot/grub2/user.cfg··················or·modify·important
 553 ·····························································································boot·parameters.
 554 ······································File·permissions·for·/boot/efi/EFI/redhat/user.cfg·····Proper·permissions
Max diff block lines reached; 319071/334455 bytes (95.40%) of diff not shown.
1.22 MB
./usr/share/doc/ssg-nondebian/table-rhel8-cuirefs.html
Ordering differences only
    
Offset 40, 45 lines modifiedOffset 40, 53 lines modified
40 ····<th>Mapping</th>40 ····<th>Mapping</th>
41 ····<th>Rule·Title</th>41 ····<th>Rule·Title</th>
42 ····<th>Description</th>42 ····<th>Description</th>
43 ····<th>Rationale</th>43 ····<th>Rationale</th>
44 ··</thead>44 ··</thead>
45 ··<tbody>45 ··<tbody>
46 ··<tr>46 ··<tr>
47 ······<td>3.1.1</td>47 ······<td>3.1.1<br/>3.1.5</td>
48 ······<td>Disable·GDM·Guest·Login</td>48 ······<td>Disable·SSH·Access·via·Empty·Passwords</td>
49 ······<td·xml:lang="en-US">49 ······<td·xml:lang="en-US">
50 ········The·GNOME·Display·Manager·(GDM)·can·allow·users·to·login·without·credentials 
51 which·can·be·useful·for·public·kiosk·scenarios.·Allowing·users·to·login·without·credentials 
52 or·"guest"·account·access·has·inherent·security·risks·and·should·be·disabled.·To·do·disable 
53 timed·logins·or·guest·account·access,·set·the·<tt>TimedLoginEnable</tt>·to·<tt>false</tt>·in 
54 the·<tt>[daemon]</tt>·section·in·<tt>/etc/gdm/custom.conf</tt>.·For·example: 
55 <pre>[daemon] 
56 TimedLoginEnable=false</pre>50 ········Disallow·SSH·login·with·empty·passwords.
 51 The·default·SSH·configuration·disables·logins·with·empty·passwords.·The·appropriate
 52 configuration·is·used·if·no·value·is·set·for·<tt>PermitEmptyPasswords</tt>.
 53 <br·/>
 54 To·explicitly·disallow·SSH·login·from·accounts·with·empty·passwords,
 55 add·or·correct·the·following·line·in
  
  
 56 <tt>/etc/ssh/sshd_config</tt>:
  
 57 <br·/>
 58 <pre>PermitEmptyPasswords·no</pre>
 59 Any·accounts·with·empty·passwords·should·be·disabled·immediately,·and·PAM·configuration
 60 should·prevent·users·from·being·able·to·assign·themselves·empty·passwords.
57 ······</td>61 ······</td>
58 ······<td·xml:lang="en-US">62 ······<td·xml:lang="en-US">
59 ········Failure·to·restrict·system·access·to·authenticated·users·negatively·impacts·operating 
60 system·security.63 ········Configuring·this·setting·for·the·SSH·daemon·provides·additional·assurance
 64 that·remote·login·via·SSH·will·require·a·password,·even·in·the·event·of
 65 misconfiguration·elsewhere.
61 ······</td>66 ······</td>
62 ····</tr>67 ····</tr>
63 ····<tr>68 ····<tr>
64 ······<td>3.1.1<br/>3.1.5</td>69 ······<td>3.1.1</td>
65 ······<td>Restrict·Virtual·Console·Root·Logins</td>70 ······<td>Disable·GDM·Automatic·Login</td>
66 ······<td·xml:lang="en-US">71 ······<td·xml:lang="en-US">
67 ········To·restrict·root·logins·through·the·(deprecated)·virtual·console·devices, 
68 ensure·lines·of·this·form·do·not·appear·in·<tt>/etc/securetty</tt>: 
69 <pre>vc/1 
70 vc/2 
71 vc/3 
72 vc/4</pre>72 ········The·GNOME·Display·Manager·(GDM)·can·allow·users·to·automatically·login·without
 73 user·interaction·or·credentials.·User·should·always·be·required·to·authenticate·themselves
 74 to·the·system·that·they·are·authorized·to·use.·To·disable·user·ability·to·automatically
 75 login·to·the·system,·set·the·<tt>AutomaticLoginEnable</tt>·to·<tt>false</tt>·in·the
 76 <tt>[daemon]</tt>·section·in·<tt>/etc/gdm/custom.conf</tt>.·For·example:
 77 <pre>[daemon]
 78 AutomaticLoginEnable=false</pre>
73 ······</td>79 ······</td>
74 ······<td·xml:lang="en-US">80 ······<td·xml:lang="en-US">
 81 ········Failure·to·restrict·system·access·to·authenticated·users·negatively·impacts·operating
 82 system·security.
75 ········Preventing·direct·root·login·to·virtual·console·devices 
76 helps·ensure·accountability·for·actions·taken·on·the·system 
77 using·the·root·account. 
78 ······</td>83 ······</td>
79 ····</tr>84 ····</tr>
80 ····<tr>85 ····<tr>
81 ······<td>3.1.1<br/>3.1.5</td>86 ······<td>3.1.1<br/>3.1.5</td>
82 ······<td>Disable·SSH·Root·Login</td>87 ······<td>Disable·SSH·Root·Login</td>
83 ······<td·xml:lang="en-US">88 ······<td·xml:lang="en-US">
84 ········The·root·user·should·never·be·allowed·to·login·to·a89 ········The·root·user·should·never·be·allowed·to·login·to·a
Offset 95, 23 lines modifiedOffset 103, 43 lines modified
95 security·is·gained·by·extending·the·policy·of·not·logging·directly·on·as·root.103 security·is·gained·by·extending·the·policy·of·not·logging·directly·on·as·root.
96 In·addition,·logging·in·with·a·user-specific·account·provides·individual104 In·addition,·logging·in·with·a·user-specific·account·provides·individual
97 accountability·of·actions·performed·on·the·system·and·also·helps·to·minimize105 accountability·of·actions·performed·on·the·system·and·also·helps·to·minimize
98 direct·attack·attempts·on·root's·password.106 direct·attack·attempts·on·root's·password.
99 ······</td>107 ······</td>
100 ····</tr>108 ····</tr>
101 ····<tr>109 ····<tr>
 110 ······<td>3.1.1<br/>3.1.5</td>
 111 ······<td>Prevent·Login·to·Accounts·With·Empty·Password</td>
 112 ······<td·xml:lang="en-US">
 113 ········If·an·account·is·configured·for·password·authentication
 114 but·does·not·have·an·assigned·password,·it·may·be·possible·to·log
 115 into·the·account·without·authentication.·Remove·any·instances·of·the
 116 <tt>nullok</tt>·in
  
 117 <tt>/etc/pam.d/system-auth</tt>·and
 118 <tt>/etc/pam.d/password-auth</tt>
  
 119 to·prevent·logins·with·empty·passwords.
 120 ······</td>
 121 ······<td·xml:lang="en-US">
 122 ········If·an·account·has·an·empty·password,·anyone·could·log·in·and
 123 run·commands·with·the·privileges·of·that·account.·Accounts·with
 124 empty·passwords·should·never·be·used·in·operational·environments.
 125 ······</td>
 126 ····</tr>
 127 ····<tr>
102 ······<td>3.1.1<br/>3.4.5</td>128 ······<td>3.1.1<br/>3.4.5</td>
103 ······<td>Require·Authentication·for·Single·User·Mode</td>129 ······<td>Require·Authentication·for·Emergency·Systemd·Target</td>
104 ······<td·xml:lang="en-US">130 ······<td·xml:lang="en-US">
105 ········Single-user·mode·is·intended·as·a·system·recovery131 ········Emergency·mode·is·intended·as·a·system·recovery
106 method,·providing·a·single·user·root·access·to·the·system·by132 method,·providing·a·single·user·root·access·to·the·system
107 providing·a·boot·option·at·startup.133 during·a·failed·boot·sequence.
108 <br·/><br·/>134 <br·/><br·/>
109 By·default,·single-user·mode·is·protected·by·requiring·a·password·and·is·set135 By·default,·Emergency·mode·is·protected·by·requiring·a·password·and·is·set
110 in·<tt>/usr/lib/systemd/system/rescue.service</tt>.136 in·<tt>/usr/lib/systemd/system/emergency.service</tt>.
111 ······</td>137 ······</td>
112 ······<td·xml:lang="en-US">138 ······<td·xml:lang="en-US">
113 ········This·prevents·attackers·with·physical·access·from·trivially·bypassing·security139 ········This·prevents·attackers·with·physical·access·from·trivially·bypassing·security
114 on·the·machine·and·gaining·root·access.·Such·accesses·are·further·prevented140 on·the·machine·and·gaining·root·access.·Such·accesses·are·further·prevented
115 by·configuring·the·bootloader·password.141 by·configuring·the·bootloader·password.
116 ······</td>142 ······</td>
117 ····</tr>143 ····</tr>
Offset 127, 45 lines modifiedOffset 155, 71 lines modified
127 ······<td·xml:lang="en-US">155 ······<td·xml:lang="en-US">
128 ········Preventing·direct·root·login·to·serial·port·interfaces156 ········Preventing·direct·root·login·to·serial·port·interfaces
129 helps·ensure·accountability·for·actions·taken·on·the·systems157 helps·ensure·accountability·for·actions·taken·on·the·systems
130 using·the·root·account.158 using·the·root·account.
131 ······</td>159 ······</td>
132 ····</tr>160 ····</tr>
133 ····<tr>161 ····<tr>
134 ······<td>3.1.1<br/>3.4.5</td>162 ······<td>3.1.1<br/>3.1.6</td>
135 ······<td>Require·Authentication·for·Emergency·Systemd·Target</td>163 ······<td>Direct·root·Logins·Not·Allowed</td>
136 ······<td·xml:lang="en-US">164 ······<td·xml:lang="en-US">
137 ········Emergency·mode·is·intended·as·a·system·recovery 
138 method,·providing·a·single·user·root·access·to·the·system 
139 during·a·failed·boot·sequence. 
140 <br·/><br·/> 
Max diff block lines reached; 455194/462064 bytes (98.51%) of diff not shown.
798 KB
html2text {}
    
Offset 1, 31 lines modifiedOffset 1, 35 lines modified
  
  
1 Rules·with·NIST-800-171·Reference·in·Guide·to·the·Secure·Configuration·of·Red1 Rules·with·NIST-800-171·Reference·in·Guide·to·the·Secure·Configuration·of·Red
2 Hat·Enterprise·Linux·82 Hat·Enterprise·Linux·8
  
  
 3 ·······································Disallow·SSH·login·with·empty·passwords.·The·default
 4 ·······································SSH·configuration·disables·logins·with·empty···········Configuring·this
 5 ·······································passwords.·The·appropriate·configuration·is·used·if·no·setting·for·the·SSH
 6 ·······································value·is·set·for·PermitEmptyPasswords.·················daemon·provides
 7 ·······································To·explicitly·disallow·SSH·login·from·accounts·with····additional·assurance
 8 3.1.1···Disable·SSH·Access·via·Empty···empty·passwords,·add·or·correct·the·following·line·in··that·remote·login
 9 3.1.5···Passwords······················/etc/ssh/sshd_config:··································via·SSH·will·require
 10 ·······································PermitEmptyPasswords·no································a·password,·even·in
 11 ·······································Any·accounts·with·empty·passwords·should·be·disabled···the·event·of
 12 ·······································immediately,·and·PAM·configuration·should·prevent······misconfiguration
 13 ·······································users·from·being·able·to·assign·themselves·empty·······elsewhere.
 14 ·······································passwords.
3 ·······································The·GNOME·Display·Manager·(GDM)·can·allow·users·to15 ·······································The·GNOME·Display·Manager·(GDM)·can·allow·users·to
4 ·······································login·without·credentials·which·can·be·useful·for 
5 ·······································public·kiosk·scenarios.·Allowing·users·to·login········Failure·to·restrict 
6 ·······································without·credentials·or·"guest"·account·access·has······system·access·to 
7 3.1.1···Disable·GDM·Guest·Login········inherent·security·risks·and·should·be·disabled.·To·do··authenticated·users 
8 ·······································disable·timed·logins·or·guest·account·access,·set·the··negatively·impacts16 ·······································automatically·login·without·user·interaction·or
 17 ·······································credentials.·User·should·always·be·required·to·········Failure·to·restrict
 18 ·······································authenticate·themselves·to·the·system·that·they·are····system·access·to
 19 3.1.1···Disable·GDM·Automatic·Login····authorized·to·use.·To·disable·user·ability·to··········authenticated·users
 20 ·······································automatically·login·to·the·system,·set·the·············negatively·impacts
9 ·······································TimedLoginEnable·to·false·in·the·[daemon]·section·in·/·operating·system21 ·······································AutomaticLoginEnable·to·false·in·the·[daemon]·section··operating·system
10 ·······································etc/gdm/custom.conf.·For·example:······················security.22 ·······································in·/etc/gdm/custom.conf.·For·example:··················security.
11 ·······································[daemon]23 ·······································[daemon]
12 ·······································TimedLoginEnable=false24 ·······································AutomaticLoginEnable=false
13 ·······································To·restrict·root·logins·through·the·(deprecated)·······Preventing·direct 
14 ·······································virtual·console·devices,·ensure·lines·of·this·form·do··root·login·to 
15 ·······································not·appear·in·/etc/securetty:··························virtual·console 
16 3.1.1···Restrict·Virtual·Console·Root··vc/1···················································devices·helps·ensure 
17 3.1.5···Logins·························vc/2···················································accountability·for 
18 ·······································vc/3···················································actions·taken·on·the 
19 ·······································vc/4···················································system·using·the 
20 ······························································································root·account. 
21 ······························································································Even·though·the25 ······························································································Even·though·the
22 ······························································································communications26 ······························································································communications
23 ······························································································channel·may·be27 ······························································································channel·may·be
24 ······························································································encrypted,·an28 ······························································································encrypted,·an
25 ······························································································additional·layer·of29 ······························································································additional·layer·of
26 ······························································································security·is·gained30 ······························································································security·is·gained
27 ······························································································by·extending·the31 ······························································································by·extending·the
Offset 39, 54 lines modifiedOffset 43, 80 lines modified
39 ······························································································accountability·of43 ······························································································accountability·of
40 ······························································································actions·performed·on44 ······························································································actions·performed·on
41 ······························································································the·system·and·also45 ······························································································the·system·and·also
42 ······························································································helps·to·minimize46 ······························································································helps·to·minimize
43 ······························································································direct·attack47 ······························································································direct·attack
44 ······························································································attempts·on·root's48 ······························································································attempts·on·root's
45 ······························································································password.49 ······························································································password.
 50 ······························································································If·an·account·has·an
 51 ······························································································empty·password,
 52 ·······································If·an·account·is·configured·for·password···············anyone·could·log·in
 53 ·······································authentication·but·does·not·have·an·assigned·password,·and·run·commands
 54 3.1.1···Prevent·Login·to·Accounts·With·it·may·be·possible·to·log·into·the·account·without·····with·the·privileges
 55 3.1.5···Empty·Password·················authentication.·Remove·any·instances·of·the·nullok·in··of·that·account.
 56 ·······································/etc/pam.d/system-auth·and·/etc/pam.d/password-auth·to·Accounts·with·empty
 57 ·······································prevent·logins·with·empty·passwords.···················passwords·should
 58 ······························································································never·be·used·in
 59 ······························································································operational
 60 ······························································································environments.
46 ······························································································This·prevents61 ······························································································This·prevents
47 ······························································································attackers·with62 ······························································································attackers·with
48 ·······································Single-user·mode·is·intended·as·a·system·recovery······physical·access·from63 ·······································Emergency·mode·is·intended·as·a·system·recovery········physical·access·from
49 ·······································method,·providing·a·single·user·root·access·to·the·····trivially·bypassing64 ·······································method,·providing·a·single·user·root·access·to·the·····trivially·bypassing
50 3.1.1···Require·Authentication·for·····system·by·providing·a·boot·option·at·startup.··········security·on·the65 3.1.1···Require·Authentication·for·····system·during·a·failed·boot·sequence.··················security·on·the
51 3.4.5···Single·User·Mode······································································machine·and·gaining66 3.4.5···Emergency·Systemd·Target······························································machine·and·gaining
52 ·······································By·default,·single-user·mode·is·protected·by·requiring·root·access.·Such67 ·······································By·default,·Emergency·mode·is·protected·by·requiring·a·root·access.·Such
53 ·······································a·password·and·is·set·in·/usr/lib/systemd/system/······accesses·are·further68 ·······································password·and·is·set·in·/usr/lib/systemd/system/········accesses·are·further
54 ·······································rescue.service.········································prevented·by69 ·······································emergency.service.·····································prevented·by
55 ······························································································configuring·the70 ······························································································configuring·the
56 ······························································································bootloader·password.71 ······························································································bootloader·password.
57 ······························································································Preventing·direct72 ······························································································Preventing·direct
58 ······························································································root·login·to·serial73 ······························································································root·login·to·serial
59 ·······································To·restrict·root·logins·on·serial·ports,·ensure·lines··port·interfaces74 ·······································To·restrict·root·logins·on·serial·ports,·ensure·lines··port·interfaces
60 3.1.1···Restrict·Serial·Port·Root······of·this·form·do·not·appear·in·/etc/securetty:··········helps·ensure75 3.1.1···Restrict·Serial·Port·Root······of·this·form·do·not·appear·in·/etc/securetty:··········helps·ensure
61 3.1.5···Logins·························ttyS0··················································accountability·for76 3.1.5···Logins·························ttyS0··················································accountability·for
62 ·······································ttyS1··················································actions·taken·on·the77 ·······································ttyS1··················································actions·taken·on·the
63 ······························································································systems·using·the78 ······························································································systems·using·the
64 ······························································································root·account.79 ······························································································root·account.
 80 ·······································To·further·limit·access·to·the·root·account,
 81 ·······································administrators·can·disable·root·logins·at·the·console··Disabling·direct
 82 ·······································by·editing·the·/etc/securetty·file.·This·file·lists····root·logins·ensures
 83 ·······································all·devices·the·root·user·is·allowed·to·login·to.·If···proper
 84 ·······································the·file·does·not·exist·at·all,·the·root·user·can······accountability·and
 85 ·······································login·through·any·communication·device·on·the·system,··multifactor
 86 ·······································whether·via·the·console·or·via·a·raw·network···········authentication·to
 87 3.1.1··································interface.·This·is·dangerous·as·user·can·login·to·the··privileged·accounts.
 88 3.1.6···Direct·root·Logins·Not·Allowed·system·as·root·via·Telnet,·which·sends·the·password·in·Users·will·first
 89 ·······································plain·text·over·the·network.·By·default,·Red·Hat·······login,·then·escalate
 90 ·······································Enterprise·Linux·8's·/etc/securetty·file·only·allows···to·privileged·(root)
 91 ·······································the·root·user·to·login·at·the·console·physically·······access·via·su·/
 92 ·······································attached·to·the·system.·To·prevent·root·from·logging···sudo.·This·is
 93 ·······································in,·remove·the·contents·of·this·file.·To·prevent·······required·for·FISMA
 94 ·······································direct·root·logins,·remove·the·contents·of·this·file···Low·and·FISMA
 95 ·······································by·typing·the·following·command:·······················Moderate·systems.
 96 ·······································$·sudo·echo·>·/etc/securetty
 97 ·······································To·restrict·root·logins·through·the·(deprecated)·······Preventing·direct
 98 ·······································virtual·console·devices,·ensure·lines·of·this·form·do··root·login·to
 99 ·······································not·appear·in·/etc/securetty:··························virtual·console
 100 3.1.1···Restrict·Virtual·Console·Root··vc/1···················································devices·helps·ensure
 101 3.1.5···Logins·························vc/2···················································accountability·for
 102 ·······································vc/3···················································actions·taken·on·the
 103 ·······································vc/4···················································system·using·the
 104 ······························································································root·account.
65 ······························································································This·prevents105 ······························································································This·prevents
66 ······························································································attackers·with106 ······························································································attackers·with
67 ·······································Emergency·mode·is·intended·as·a·system·recovery········physical·access·from107 ·······································Single-user·mode·is·intended·as·a·system·recovery······physical·access·from
68 ·······································method,·providing·a·single·user·root·access·to·the·····trivially·bypassing108 ·······································method,·providing·a·single·user·root·access·to·the·····trivially·bypassing
69 3.1.1···Require·Authentication·for·····system·during·a·failed·boot·sequence.··················security·on·the109 3.1.1···Require·Authentication·for·····system·by·providing·a·boot·option·at·startup.··········security·on·the
70 3.4.5···Emergency·Systemd·Target······························································machine·and·gaining110 3.4.5···Single·User·Mode······································································machine·and·gaining
71 ·······································By·default,·Emergency·mode·is·protected·by·requiring·a·root·access.·Such111 ·······································By·default,·single-user·mode·is·protected·by·requiring·root·access.·Such
72 ·······································password·and·is·set·in·/usr/lib/systemd/system/········accesses·are·further112 ·······································a·password·and·is·set·in·/usr/lib/systemd/system/······accesses·are·further
73 ·······································emergency.service.·····································prevented·by113 ·······································rescue.service.········································prevented·by
74 ······························································································configuring·the114 ······························································································configuring·the
75 ······························································································bootloader·password.115 ······························································································bootloader·password.
76 ·······································The·GNOME·Display·Manager·(GDM)·can·allow·users·to 
77 ·······································automatically·login·without·user·interaction·or 
78 ·······································credentials.·User·should·always·be·required·to·········Failure·to·restrict 
79 ·······································authenticate·themselves·to·the·system·that·they·are····system·access·to 
80 3.1.1···Disable·GDM·Automatic·Login····authorized·to·use.·To·disable·user·ability·to··········authenticated·users 
81 ·······································automatically·login·to·the·system,·set·the·············negatively·impacts 
Max diff block lines reached; 801604/817071 bytes (98.11%) of diff not shown.
3.56 KB
./usr/share/doc/ssg-nondebian/table-rhel8-nistrefs-stig.html
    
Offset 24277, 17 lines modifiedOffset 24277, 17 lines modified
0005ed40:·696e·670a·7469·6d65·2d62·6173·6564·206c··ing.time-based·l0005ed40:·696e·670a·7469·6d65·2d62·6173·6564·206c··ing.time-based·l
0005ed50:·696d·6974·2c20·6566·6665·6374·7320·6f66··imit,·effects·of0005ed50:·696d·6974·2c20·6566·6665·6374·7320·6f66··imit,·effects·of
0005ed60:·2070·6f74·656e·7469·616c·2061·7474·6163···potential·attac0005ed60:·2070·6f74·656e·7469·616c·2061·7474·6163···potential·attac
0005ed70:·6b73·2061·6761·696e·7374·0a65·6e63·7279··ks·against.encry0005ed70:·6b73·2061·6761·696e·7374·0a65·6e63·7279··ks·against.encry
0005ed80:·7074·696f·6e20·6b65·7973·2061·7265·206c··ption·keys·are·l0005ed80:·7074·696f·6e20·6b65·7973·2061·7265·206c··ption·keys·are·l
0005ed90:·696d·6974·6564·2e0a·2020·3c2f·7464·3e0a··imited..··</td>.0005ed90:·696d·6974·6564·2e0a·2020·3c2f·7464·3e0a··imited..··</td>.
0005eda0:·2020·3c74·643e·7661·725f·7265·6b65·795f····<td>var_rekey_0005eda0:·2020·3c74·643e·7661·725f·7265·6b65·795f····<td>var_rekey_
0005edb0:·6c69·6d69·745f·7469·6d65·3d31·686f·7572··limit_time=1hour0005edb0:·6c69·6d69·745f·7369·7a65·3d31·473c·6272··limit_size=1G<br
0005edc0:·3c62·722f·3e76·6172·5f72·656b·6579·5f6c··<br/>var_rekey_l 
0005edd0:·696d·6974·5f73·697a·653d·3147·3c2f·7464··imit_size=1G</td0005edc0:·2f3e·7661·725f·7265·6b65·795f·6c69·6d69··/>var_rekey_limi
 0005edd0:·745f·7469·6d65·3d31·686f·7572·3c2f·7464··t_time=1hour</td
0005ede0:·3e0a·3c2f·7472·3e0a·3c74·723e·0a20·203c··>.</tr>.<tr>.··<0005ede0:·3e0a·3c2f·7472·3e0a·3c74·723e·0a20·203c··>.</tr>.<tr>.··<
0005edf0:·7464·3e3c·2f74·643e·0a20·203c·7464·3e43··td></td>.··<td>C0005edf0:·7464·3e3c·2f74·643e·0a20·203c·7464·3e43··td></td>.··<td>C
0005ee00:·4345·2d38·3234·3632·2d33·3c2f·7464·3e0a··CE-82462-3</td>.0005ee00:·4345·2d38·3234·3632·2d33·3c2f·7464·3e0a··CE-82462-3</td>.
0005ee10:·2020·3c74·643e·5353·4820·7365·7276·6572····<td>SSH·server0005ee10:·2020·3c74·643e·5353·4820·7365·7276·6572····<td>SSH·server
0005ee20:·2075·7365·7320·7374·726f·6e67·2065·6e74···uses·strong·ent0005ee20:·2075·7365·7320·7374·726f·6e67·2065·6e74···uses·strong·ent
0005ee30:·726f·7079·2074·6f20·7365·6564·3c2f·7464··ropy·to·seed</td0005ee30:·726f·7079·2074·6f20·7365·6564·3c2f·7464··ropy·to·seed</td
0005ee40:·3e0a·2020·3c74·6420·786d·6c3a·6c61·6e67··>.··<td·xml:lang0005ee40:·3e0a·2020·3c74·6420·786d·6c3a·6c61·6e67··>.··<td·xml:lang
2.07 KB
html2text {}
    
Offset 7644, 16 lines modifiedOffset 7644, 16 lines modified
7644 ·····································corresponding·private·key.····························system·where·the7644 ·····································corresponding·private·key.····························system·where·the
7645 ···························································································associated·public7645 ···························································································associated·public
7646 ···························································································key·has·been7646 ···························································································key·has·been
7647 ···························································································installed.7647 ···························································································installed.
7648 ·····································The·RekeyLimit·parameter·specifies·how·often·the······By·decreasing·the7648 ·····································The·RekeyLimit·parameter·specifies·how·often·the······By·decreasing·the
7649 ·····································session·key·of·the·is·renegotiated,·both·in·terms·of··limit·based·on·the7649 ·····································session·key·of·the·is·renegotiated,·both·in·terms·of··limit·based·on·the
7650 ········CCE-···Force·frequent········amount·of·data·that·may·be·transmitted·and·the·time···amount·of·data·and7650 ········CCE-···Force·frequent········amount·of·data·that·may·be·transmitted·and·the·time···amount·of·data·and
7651 ········82177-·session·key···········elapsed.··············································enabling·time-based·var_rekey_limit_time=1hour7651 ········82177-·session·key···········elapsed.··············································enabling·time-based·var_rekey_limit_size=1G
7652 ········7······renegotiation·········To·decrease·the·default·limits,·add·or·correct·the····limit,·effects·of···var_rekey_limit_size=1G7652 ········7······renegotiation·········To·decrease·the·default·limits,·add·or·correct·the····limit,·effects·of···var_rekey_limit_time=1hour
7653 ·····································following·line·in·/etc/ssh/sshd_config:···············potential·attacks7653 ·····································following·line·in·/etc/ssh/sshd_config:···············potential·attacks
7654 ·····································RekeyLimit·1G·1hour···································against·encryption7654 ·····································RekeyLimit·1G·1hour···································against·encryption
7655 ···························································································keys·are·limited.7655 ···························································································keys·are·limited.
7656 ···························································································SSH·implementation7656 ···························································································SSH·implementation
7657 ···························································································in·Red·Hat7657 ···························································································in·Red·Hat
7658 ···························································································Enterprise·Linux·87658 ···························································································Enterprise·Linux·8
7659 ···························································································uses·the·openssl7659 ···························································································uses·the·openssl
9.78 MB
./usr/share/doc/ssg-nondebian/table-rhel8-nistrefs.html
    
Offset 68, 15744 lines modifiedOffset 68, 15744 lines modified
00000430:·3e52·6174·696f·6e61·6c65·3c2f·7468·3e0a··>Rationale</th>.00000430:·3e52·6174·696f·6e61·6c65·3c2f·7468·3e0a··>Rationale</th>.
00000440:·2020·3c2f·7468·6561·643e·0a20·203c·7462····</thead>.··<tb00000440:·2020·3c2f·7468·6561·643e·0a20·203c·7462····</thead>.··<tb
00000450:·6f64·793e·0a20·203c·7472·3e0a·2020·2020··ody>.··<tr>.····00000450:·6f64·793e·0a20·203c·7472·3e0a·2020·2020··ody>.··<tr>.····
00000460:·2020·3c74·643e·4155·2d32·2861·293c·2f74····<td>AU-2(a)</t00000460:·2020·3c74·643e·4155·2d32·2861·293c·2f74····<td>AU-2(a)</t
00000470:·643e·0a20·2020·2020·203c·7464·3e43·6f6e··d>.······<td>Con00000470:·643e·0a20·2020·2020·203c·7464·3e43·6f6e··d>.······<td>Con
00000480:·6669·6775·7265·2061·7564·6974·696e·6720··figure·auditing·00000480:·6669·6775·7265·2061·7564·6974·696e·6720··figure·auditing·
Diff chunk too large, falling back to line-by-line diff (1453 lines added, 1453 lines removed)
00000490:·6f66·2073·7563·6365·7373·6675·6c20·6669··of·successful·fi00000490:·6f66·2073·7563·6365·7373·6675·6c20·6669··of·successful·fi
000004a0:·6c65·2063·7265·6174·696f·6e73·2028·4141··le·creations·(AA000004a0:·6c65·2061·6363·6573·7365·7320·2870·7063··le·accesses·(ppc
000004b0:·7263·6836·3429·3c2f·7464·3e0a·2020·2020··rch64)</td>.····000004b0:·3634·6c65·293c·2f74·643e·0a20·2020·2020··64le)</td>.·····
000004c0:·2020·3c74·6420·786d·6c3a·6c61·6e67·3d22····<td·xml:lang="000004c0:·203c·7464·2078·6d6c·3a6c·616e·673d·2265···<td·xml:lang="e
000004d0:·656e·2d55·5322·3e0a·2020·2020·2020·2020··en-US">.········000004d0:·6e2d·5553·223e·0a20·2020·2020·2020·2045··n-US">.········E
000004e0:·456e·7375·7265·2074·6861·7420·7375·6363··Ensure·that·succ000004e0:·6e73·7572·6520·7468·6174·2073·7563·6365··nsure·that·succe
000004f0:·6573·7366·756c·2061·7474·656d·7074·7320··essful·attempts·000004f0:·7373·6675·6c20·6174·7465·6d70·7473·2074··ssful·attempts·t
00000500:·746f·2063·7265·6174·6520·6120·6669·6c65··to·create·a·file00000500:·6f20·6163·6365·7373·2061·2066·696c·6520··o·access·a·file·
00000510:·2061·7265·2061·7564·6974·6564·2e0a·0a54···are·audited...T00000510:·6172·6520·6175·6469·7465·642e·0a0a·5468··are·audited...Th
00000520:·6865·2066·6f6c·6c6f·7769·6e67·2072·756c··he·following·rul00000520:·6520·666f·6c6c·6f77·696e·6720·7275·6c65··e·following·rule
00000530:·6573·2063·6f6e·6669·6775·7265·2061·7564··es·configure·aud00000530:·7320·636f·6e66·6967·7572·6520·6175·6469··s·configure·audi
00000540:·6974·2061·7320·6465·7363·7269·6265·6420··it·as·described·00000540:·7420·6173·2064·6573·6372·6962·6564·2061··t·as·described·a
00000550:·6162·6f76·653a·0a3c·7072·653e·2323·2053··above:.<pre>##·S00000550:·626f·7665·3a0a·3c70·7265·3e23·2320·5375··bove:.<pre>##·Su
00000560:·7563·6365·7373·6675·6c20·6669·6c65·2063··uccessful·file·c00000560:·6363·6573·7366·756c·2066·696c·6520·6163··ccessful·file·ac
00000570:·7265·6174·696f·6e20·286f·7065·6e20·7769··reation·(open·wi00000570:·6365·7373·2028·616e·7920·6f74·6865·7220··cess·(any·other·
00000580:·7468·204f·5f43·5245·4154·290a·2d61·2061··th·O_CREAT).-a·a00000580:·6f70·656e·7329·2054·6869·7320·6861·7320··opens)·This·has·
00000590:·6c77·6179·732c·6578·6974·202d·4620·6172··lways,exit·-F·ar00000590:·746f·2067·6f20·6c61·7374·2e0a·2323·2054··to·go·last..##·T
000005a0:·6368·3d62·3332·202d·5320·6f70·656e·6174··ch=b32·-S·openat000005a0:·6865·7365·206e·6578·7420·7477·6f20·6172··hese·next·two·ar
000005b0:·2c6f·7065·6e5f·6279·5f68·616e·646c·655f··,open_by_handle_000005b0:·6520·6c69·6b65·6c79·2074·6f20·7265·7375··e·likely·to·resu
000005c0:·6174·202d·4620·6132·2661·6d70·3b30·3130··at·-F·a2&amp;010000005c0:·6c74·2069·6e20·6120·7768·6f6c·6520·6c6f··lt·in·a·whole·lo
000005d0:·3020·2d46·2073·7563·6365·7373·3d31·202d··0·-F·success=1·-000005d0:·7420·6f66·2065·7665·6e74·730a·2d61·2061··t·of·events.-a·a
000005e0:·4620·6175·6964·3e3d·3130·3030·202d·4620··F·auid>=1000·-F·000005e0:·6c77·6179·732c·6578·6974·202d·4620·6172··lways,exit·-F·ar
000005f0:·6175·6964·213d·756e·7365·7420·2d46·206b··auid!=unset·-F·k000005f0:·6368·3d62·3634·202d·5320·6f70·656e·2c6f··ch=b64·-S·open,o
00000600:·6579·3d73·7563·6365·7373·6675·6c2d·6372··ey=successful-cr00000600:·7065·6e61·742c·6f70·656e·6174·322c·6f70··penat,openat2,op
00000610:·6561·7465·0a2d·6120·616c·7761·7973·2c65··eate.-a·always,e00000610:·656e·5f62·795f·6861·6e64·6c65·5f61·7420··en_by_handle_at·
00000620:·7869·7420·2d46·2061·7263·683d·6236·3420··xit·-F·arch=b64·00000620:·2d46·2073·7563·6365·7373·3d31·202d·4620··-F·success=1·-F·
00000630:·2d53·206f·7065·6e61·742c·6f70·656e·5f62··-S·openat,open_b00000630:·6175·6964·3e3d·3130·3030·202d·4620·6175··auid>=1000·-F·au
00000640:·795f·6861·6e64·6c65·5f61·7420·2d46·2061··y_handle_at·-F·a00000640:·6964·213d·756e·7365·7420·2d46·206b·6579··id!=unset·-F·key
00000650:·3226·616d·703b·3031·3030·202d·4620·7375··2&amp;0100·-F·su00000650:·3d73·7563·6365·7373·6675·6c2d·6163·6365··=successful-acce
00000660:·6363·6573·733d·3120·2d46·2061·7569·643e··ccess=1·-F·auid>00000660:·7373·2020·2020·3c2f·7072·653e·0a0a·4c6f··ss····</pre>..Lo
00000670:·3d31·3030·3020·2d46·2061·7569·6421·3d75··=1000·-F·auid!=u00000670:·6164·206e·6577·2041·7564·6974·2072·756c··ad·new·Audit·rul
00000680:·6e73·6574·202d·4620·6b65·793d·7375·6363··nset·-F·key=succ00000680:·6573·2069·6e74·6f20·6b65·726e·656c·2062··es·into·kernel·b
00000690:·6573·7366·756c·2d63·7265·6174·650a·2d61··essful-create.-a00000690:·7920·7275·6e6e·696e·673a·0a3c·7072·653e··y·running:.<pre>
000006a0:·2061·6c77·6179·732c·6578·6974·202d·4620···always,exit·-F·000006a0:·6175·6765·6e72·756c·6573·202d·2d6c·6f61··augenrules·--loa
000006b0:·6172·6368·3d62·3332·202d·5320·6f70·656e··arch=b32·-S·open000006b0:·643c·2f70·7265·3e0a·0a4e·6f74·653a·2054··d</pre>..Note:·T
000006c0:·202d·4620·6131·2661·6d70·3b30·3130·3020···-F·a1&amp;0100·000006c0:·6869·7320·7275·6c65·2075·7365·7320·6120··his·rule·uses·a·
000006d0:·2d46·2073·7563·6365·7373·3d31·202d·4620··-F·success=1·-F·000006d0:·7370·6563·6961·6c20·7365·7420·6f66·2041··special·set·of·A
000006e0:·6175·6964·3e3d·3130·3030·202d·4620·6175··auid>=1000·-F·au000006e0:·7564·6974·2072·756c·6573·2074·6f20·636f··udit·rules·to·co
000006f0:·6964·213d·756e·7365·7420·2d46·206b·6579··id!=unset·-F·key000006f0:·6d70·6c79·2077·6974·6820·4f53·5050·2034··mply·with·OSPP·4
00000700:·3d73·7563·6365·7373·6675·6c2d·6372·6561··=successful-crea00000700:·2e32·2e31·2e20·596f·7520·6d61·7920·7265··.2.1.·You·may·re
00000710:·7465·0a2d·6120·616c·7761·7973·2c65·7869··te.-a·always,exi00000710:·7573·6520·7468·6973·2072·756c·6520·696e··use·this·rule·in
00000720:·7420·2d46·2061·7263·683d·6233·3220·2d53··t·-F·arch=b32·-S00000720:·2064·6966·6665·7265·6e74·2070·726f·6669···different·profi
00000730:·2063·7265·6174·202d·4620·7375·6363·6573···creat·-F·succes00000730:·6c65·732e·2049·6620·796f·7520·6465·6369··les.·If·you·deci
00000740:·733d·3120·2d46·2061·7569·643e·3d31·3030··s=1·-F·auid>=10000000740:·6465·2074·6f20·646f·2073·6f2c·2069·7420··de·to·do·so,·it·
00000750:·3020·2d46·2061·7569·6421·3d75·6e73·6574··0·-F·auid!=unset00000750:·6973·2072·6563·6f6d·6d65·6e64·6564·2074··is·recommended·t
00000760:·202d·4620·6b65·793d·7375·6363·6573·7366···-F·key=successf00000760:·6861·7420·796f·7520·696e·7370·6563·7420··hat·you·inspect·
00000770:·756c·2d63·7265·6174·6520·2020·203c·2f70··ul-create····</p00000770:·636f·6e74·656e·7473·206f·6620·7468·6520··contents·of·the·
00000780:·7265·3e0a·0a4c·6f61·6420·6e65·7720·4175··re>..Load·new·Au00000780:·6669·6c65·2063·6c6f·7365·6c79·2061·6e64··file·closely·and
00000790:·6469·7420·7275·6c65·7320·696e·746f·206b··dit·rules·into·k00000790:·206d·616b·6520·7375·7265·2074·6861·7420···make·sure·that·
000007a0:·6572·6e65·6c20·6279·2072·756e·6e69·6e67··ernel·by·running000007a0:·7468·6579·2061·7265·2061·6c6c·6967·6e65··they·are·alligne
000007b0:·3a0a·3c70·7265·3e61·7567·656e·7275·6c65··:.<pre>augenrule000007b0:·6420·7769·7468·2079·6f75·7220·6e65·6564··d·with·your·need
000007c0:·7320·2d2d·6c6f·6164·3c2f·7072·653e·0a0a··s·--load</pre>..000007c0:·732e·0a20·2020·2020·203c·2f74·643e·0a20··s..······</td>.·
000007d0:·4e6f·7465·3a20·5468·6973·2072·756c·6520··Note:·This·rule·000007d0:·2020·2020·203c·7464·2078·6d6c·3a6c·616e·······<td·xml:lan
000007e0:·7573·6573·2061·2073·7065·6369·616c·2073··uses·a·special·s000007e0:·673d·2265·6e2d·5553·223e·0a20·2020·2020··g="en-US">.·····
000007f0:·6574·206f·6620·4175·6469·7420·7275·6c65··et·of·Audit·rule000007f0:·2020·2041·7564·6974·696e·6720·6f66·2073·····Auditing·of·s
00000800:·7320·746f·2063·6f6d·706c·7920·7769·7468··s·to·comply·with00000800:·7563·6365·7373·6675·6c20·6174·7465·6d70··uccessful·attemp
00000810:·204f·5350·5020·342e·322e·312e·2059·6f75···OSPP·4.2.1.·You00000810:·7473·2074·6f20·6163·6365·7373·2061·2066··ts·to·access·a·f
00000820:·206d·6179·2072·6575·7365·2074·6869·7320···may·reuse·this·00000820:·696c·6520·6865·6c70·7320·696e·2069·6e76··ile·helps·in·inv
00000830:·7275·6c65·2069·6e20·6469·6666·6572·656e··rule·in·differen00000830:·6573·7469·6761·7469·6f6e·206f·6620·6163··estigation·of·ac
00000840:·7420·7072·6f66·696c·6573·2e20·4966·2079··t·profiles.·If·y00000840:·7469·7669·7469·6573·2070·6572·666f·726d··tivities·perform
00000850:·6f75·2064·6563·6964·6520·746f·2064·6f20··ou·decide·to·do·00000850:·6564·206f·6e20·7468·6520·7379·7374·656d··ed·on·the·system
00000860:·736f·2c20·6974·2069·7320·7265·636f·6d6d··so,·it·is·recomm00000860:·2e0a·2020·2020·2020·3c2f·7464·3e0a·2020··..······</td>.··
00000870:·656e·6465·6420·7468·6174·2079·6f75·2069··ended·that·you·i00000870:·2020·3c2f·7472·3e0a·2020·2020·3c74·723e····</tr>.····<tr>
00000880:·6e73·7065·6374·2063·6f6e·7465·6e74·7320··nspect·contents·00000880:·0a20·2020·2020·203c·7464·3e41·552d·3228··.······<td>AU-2(
00000890:·6f66·2074·6865·2066·696c·6520·636c·6f73··of·the·file·clos00000890:·6429·3c62·722f·3e41·552d·3132·2863·293c··d)<br/>AU-12(c)<
000008a0:·656c·7920·616e·6420·6d61·6b65·2073·7572··ely·and·make·sur000008a0:·6272·2f3e·4143·2d36·2839·293c·6272·2f3e··br/>AC-6(9)<br/>
000008b0:·6520·7468·6174·2074·6865·7920·6172·6520··e·that·they·are·000008b0:·434d·2d36·2861·293c·2f74·643e·0a20·2020··CM-6(a)</td>.···
000008c0:·616c·6c69·676e·6564·2077·6974·6820·796f··alligned·with·yo000008c0:·2020·203c·7464·3e45·6e73·7572·6520·6175·····<td>Ensure·au
000008d0:·7572·206e·6565·6473·2e0a·2020·2020·2020··ur·needs..······000008d0:·6469·7464·2043·6f6c·6c65·6374·7320·496e··ditd·Collects·In
000008e0:·3c2f·7464·3e0a·2020·2020·2020·3c74·6420··</td>.······<td·000008e0:·666f·726d·6174·696f·6e20·6f6e·204b·6572··formation·on·Ker
000008f0:·786d·6c3a·6c61·6e67·3d22·656e·2d55·5322··xml:lang="en-US"000008f0:·6e65·6c20·4d6f·6475·6c65·2055·6e6c·6f61··nel·Module·Unloa
00000900:·3e0a·2020·2020·2020·2020·4175·6469·7469··>.········Auditi00000900:·6469·6e67·202d·2064·656c·6574·655f·6d6f··ding·-·delete_mo
00000910:·6e67·206f·6620·7375·6363·6573·7366·756c··ng·of·successful00000910:·6475·6c65·3c2f·7464·3e0a·2020·2020·2020··dule</td>.······
00000920:·2061·7474·656d·7074·7320·746f·2063·7265···attempts·to·cre00000920:·3c74·6420·786d·6c3a·6c61·6e67·3d22·656e··<td·xml:lang="en
00000930:·6174·6520·6120·6669·6c65·2068·656c·7073··ate·a·file·helps00000930:·2d55·5322·3e0a·2020·2020·2020·2020·546f··-US">.········To
00000940:·2069·6e20·696e·7665·7374·6967·6174·696f···in·investigatio00000940:·2063·6170·7475·7265·206b·6572·6e65·6c20···capture·kernel·
00000950:·6e20·6f66·2061·6374·696f·6e73·2077·6869··n·of·actions·whi00000950:·6d6f·6475·6c65·2075·6e6c·6f61·6469·6e67··module·unloading
00000960:·6368·2068·6170·7065·6e65·6420·6f6e·2074··ch·happened·on·t00000960:·2065·7665·6e74·732c·2075·7365·2066·6f6c···events,·use·fol
00000970:·6865·2073·7973·7465·6d2e·0a20·2020·2020··he·system..·····00000970:·6c6f·7769·6e67·206c·696e·652c·2073·6574··lowing·line,·set
00000980:·203c·2f74·643e·0a20·2020·203c·2f74·723e···</td>.····</tr>00000980:·7469·6e67·2041·5243·4820·746f·0a65·6974··ting·ARCH·to.eit
00000990:·0a20·2020·203c·7472·3e0a·2020·2020·2020··.····<tr>.······00000990:·6865·7220·6233·3220·666f·7220·3332·2d62··her·b32·for·32-b
000009a0:·3c74·643e·4155·2d32·2861·293c·2f74·643e··<td>AU-2(a)</td>000009a0:·6974·2073·7973·7465·6d2c·206f·7220·6861··it·system,·or·ha
000009b0:·0a20·2020·2020·203c·7464·3e43·6f6e·6669··.······<td>Confi000009b0:·7669·6e67·2074·776f·206c·696e·6573·2066··ving·two·lines·f
000009c0:·6775·7265·2061·7564·6974·696e·6720·6f66··gure·auditing·of000009c0:·6f72·2062·6f74·6820·6233·3220·616e·6420··or·both·b32·and·
000009d0:·2075·6e73·7563·6365·7373·6675·6c20·6669···unsuccessful·fi000009d0:·6236·3420·696e·2063·6173·6520·796f·7572··b64·in·case·your
000009e0:·6c65·2063·7265·6174·696f·6e73·3c2f·7464··le·creations</td000009e0:·2073·7973·7465·6d20·6973·2036·342d·6269···system·is·64-bi
000009f0:·3e0a·2020·2020·2020·3c74·6420·786d·6c3a··>.······<td·xml:000009f0:·743a·0a0a·3c70·7265·3e2d·6120·616c·7761··t:..<pre>-a·alwa
00000a00:·6c61·6e67·3d22·656e·2d55·5322·3e0a·2020··lang="en-US">.··00000a00:·7973·2c65·7869·7420·2d46·2061·7263·683d··ys,exit·-F·arch=
00000a10:·2020·2020·2020·456e·7375·7265·2074·6861········Ensure·tha00000a10:·3c69·3e41·5243·483c·2f69·3e20·2d53·2064··<i>ARCH</i>·-S·d
00000a20:·7420·756e·7375·6363·6573·7366·756c·2061··t·unsuccessful·a00000a20:·656c·6574·655f·6d6f·6475·6c65·202d·4620··elete_module·-F·
00000a30:·7474·656d·7074·7320·746f·2063·7265·6174··ttempts·to·creat00000a30:·6175·6964·3e3d·3130·3030·202d·4620·6175··auid>=1000·-F·au
00000a40:·6520·6120·6669·6c65·2061·7265·2061·7564··e·a·file·are·aud00000a40:·6964·213d·756e·7365·7420·2d46·206b·6579··id!=unset·-F·key
00000a50:·6974·6564·2e0a·0a54·6865·2066·6f6c·6c6f··ited...The·follo00000a50:·3d6d·6f64·756c·6573·3c2f·7072·653e·0a0a··=modules</pre>..
00000a60:·7769·6e67·2072·756c·6573·2063·6f6e·6669··wing·rules·confi00000a60:·0a50·6c61·6365·2074·6f20·6164·6420·7468··.Place·to·add·th
00000a70:·6775·7265·2061·7564·6974·2061·7320·6465··gure·audit·as·de00000a70:·6520·6c69·6e65·2064·6570·656e·6473·206f··e·line·depends·o
00000a80:·7363·7269·6265·6420·6162·6f76·653a·0a3c··scribed·above:.<00000a80:·6e20·6120·7761·7920·3c74·743e·6175·6469··n·a·way·<tt>audi
00000a90:·7072·653e·2323·2055·6e73·7563·6365·7373··pre>##·Unsuccess00000a90:·7464·3c2f·7474·3e20·6461·656d·6f6e·2069··td</tt>·daemon·i
00000aa0:·6675·6c20·6669·6c65·2063·7265·6174·696f··ful·file·creatio00000aa0:·7320·636f·6e66·6967·7572·6564·2e20·4966··s·configured.·If
00000ab0:·6e20·286f·7065·6e20·7769·7468·204f·5f43··n·(open·with·O_C00000ab0:·2069·7420·6973·2063·6f6e·6669·6775·7265···it·is·configure
00000ac0:·5245·4154·290a·2d61·2061·6c77·6179·732c··REAT).-a·always,00000ac0:·640a·746f·2075·7365·2074·6865·203c·7474··d.to·use·the·<tt
00000ad0:·6578·6974·202d·4620·6172·6368·3d62·3332··exit·-F·arch=b3200000ad0:·3e61·7567·656e·7275·6c65·733c·2f74·743e··>augenrules</tt>
00000ae0:·202d·5320·6f70·656e·6174·2c6f·7065·6e5f···-S·openat,open_00000ae0:·2070·726f·6772·616d·2028·7468·6520·6465···program·(the·de
00000af0:·6279·5f68·616e·646c·655f·6174·202d·4620··by_handle_at·-F·00000af0:·6661·756c·7429·2c20·6164·6420·7468·6520··fault),·add·the·
00000b00:·6132·2661·6d70·3b30·3130·3020·2d46·2065··a2&amp;0100·-F·e00000b00:·6c69·6e65·2074·6f20·6120·6669·6c65·2077··line·to·a·file·w
00000b10:·7869·743d·2d45·4143·4345·5320·2d46·2061··xit=-EACCES·-F·a00000b10:·6974·6820·7375·6666·6978·0a3c·7474·3e2e··ith·suffix.<tt>.
00000b20:·7569·6426·6774·3b3d·3130·3030·202d·4620··uid&gt;=1000·-F·00000b20:·7275·6c65·733c·2f74·743e·2069·6e20·7468··rules</tt>·in·th
00000b30:·6175·6964·213d·756e·7365·7420·2d46·206b··auid!=unset·-F·k00000b30:·6520·6469·7265·6374·6f72·7920·3c74·743e··e·directory·<tt>
00000b40:·6579·3d75·6e73·7563·6365·7373·6675·6c2d··ey=unsuccessful-00000b40:·2f65·7463·2f61·7564·6974·2f72·756c·6573··/etc/audit/rules
00000b50:·6372·6561·7465·0a2d·6120·616c·7761·7973··create.-a·always00000b50:·2e64·3c2f·7474·3e2e·0a0a·4966·2074·6865··.d</tt>...If·the
00000b60:·2c65·7869·7420·2d46·2061·7263·683d·6236··,exit·-F·arch=b600000b60:·203c·7474·3e61·7564·6974·643c·2f74·743e···<tt>auditd</tt>
00000b70:·3420·2d53·206f·7065·6e61·742c·6f70·656e··4·-S·openat,open00000b70:·2064·6165·6d6f·6e20·6973·2063·6f6e·6669···daemon·is·confi
00000b80:·5f62·795f·6861·6e64·6c65·5f61·7420·2d46··_by_handle_at·-F00000b80:·6775·7265·6420·746f·2075·7365·2074·6865··gured·to·use·the
00000b90:·2061·3226·616d·703b·3031·3030·202d·4620···a2&amp;0100·-F·00000b90:·203c·7474·3e61·7564·6974·6374·6c3c·2f74···<tt>auditctl</t
00000ba0:·6578·6974·3d2d·4541·4343·4553·202d·4620··exit=-EACCES·-F·00000ba0:·743e·2075·7469·6c69·7479·2c0a·6164·6420··t>·utility,.add·
00000bb0:·6175·6964·2667·743b·3d31·3030·3020·2d46··auid&gt;=1000·-F00000bb0:·7468·6520·6c69·6e65·2074·6f20·6669·6c65··the·line·to·file
00000bc0:·2061·7569·6421·3d75·6e73·6574·202d·4620···auid!=unset·-F·00000bc0:·203c·7474·3e2f·6574·632f·6175·6469·742f···<tt>/etc/audit/
00000bd0:·6b65·793d·756e·7375·6363·6573·7366·756c··key=unsuccessful00000bd0:·6175·6469·742e·7275·6c65·733c·2f74·743e··audit.rules</tt>
00000be0:·2d63·7265·6174·650a·2d61·2061·6c77·6179··-create.-a·alway00000be0:·2e0a·2020·2020·2020·3c2f·7464·3e0a·2020··..······</td>.··
00000bf0:·732c·6578·6974·202d·4620·6172·6368·3d62··s,exit·-F·arch=b00000bf0:·2020·2020·3c74·6420·786d·6c3a·6c61·6e67······<td·xml:lang
00000c00:·3332·202d·5320·6f70·656e·202d·4620·6131··32·-S·open·-F·a100000c00:·3d22·656e·2d55·5322·3e0a·2020·2020·2020··="en-US">.······
Max diff block lines reached; 7328745/7529837 bytes (97.33%) of diff not shown.
2.6 MB
html2text {}
    
Offset 1, 30 lines modifiedOffset 1, 97 lines modified
  
  
1 Rules·with·NIST-800-53·Reference·in·Guide·to·the·Secure·Configuration·of·Red1 Rules·with·NIST-800-53·Reference·in·Guide·to·the·Secure·Configuration·of·Red
2 Hat·Enterprise·Linux·82 Hat·Enterprise·Linux·8
  
  
3 ·······························Ensure·that·successful·attempts·to·create·a·file·are·audited.·The·following·rules3 ·······························Ensure·that·successful·attempts·to·access·a·file·are·audited.·The·following·rules
4 ·······························configure·audit·as·described·above:4 ·······························configure·audit·as·described·above:
5 ·······························##·Successful·file·creation·(open·with·O_CREAT) 
6 ·······························-a·always,exit·-F·arch=b32·-S·openat,open_by_handle_at·-F·a2&0100·-F·success=1·- 
7 ·······························F·auid>=1000·-F·auid!=unset·-F·key=successful-create5 ·······························##·Successful·file·access·(any·other·opens)·This·has·to·go·last.
 6 ·······························##·These·next·two·are·likely·to·result·in·a·whole·lot·of·events··························Auditing·of·successful
 7 ········Configure·auditing·of··-a·always,exit·-F·arch=b64·-S·open,openat,openat2,open_by_handle_at·-F·success=1·-·······attempts·to·access·a
 8 AU-2(a)·successful·file········F·auid>=1000·-F·auid!=unset·-F·key=successful-access·····································file·helps·in
 9 ········accesses·(ppc64le)·····Load·new·Audit·rules·into·kernel·by·running:·············································investigation·of
 10 ·······························augenrules·--load········································································activities·performed·on
 11 ·······························Note:·This·rule·uses·a·special·set·of·Audit·rules·to·comply·with·OSPP·4.2.1.·You·may·····the·system.
 12 ·······························reuse·this·rule·in·different·profiles.·If·you·decide·to·do·so,·it·is·recommended·that
 13 ·······························you·inspect·contents·of·the·file·closely·and·make·sure·that·they·are·alligned·with·your
 14 ·······························needs.
 15 ························································································································The·removal·of·kernel
 16 ························································································································modules·can·be·used·to
 17 ·······························To·capture·kernel·module·unloading·events,·use·following·line,·setting·ARCH·to·either····alter·the·behavior·of
 18 AU-2(d)························b32·for·32-bit·system,·or·having·two·lines·for·both·b32·and·b64·in·case·your·system·is···the·kernel·and
 19 AU-12···Ensure·auditd·Collects·64-bit:··················································································potentially·introduce
 20 (c)·····Information·on·Kernel··-a·always,exit·-F·arch=ARCH·-S·delete_module·-F·auid>=1000·-F·auid!=unset·-F·key=modules·malicious·code·into
 21 AC-6(9)·Module·Unloading·-·····Place·to·add·the·line·depends·on·a·way·auditd·daemon·is·configured.·If·it·is·configured··kernel·space.·It·is
 22 CM-6(a)·delete_module··········to·use·the·augenrules·program·(the·default),·add·the·line·to·a·file·with·suffix·.rules···important·to·have·an
 23 ·······························in·the·directory·/etc/audit/rules.d.·If·the·auditd·daemon·is·configured·to·use·the·······audit·trail·of·modules
 24 ·······························auditctl·utility,·add·the·line·to·file·/etc/audit/audit.rules.···························that·have·been
 25 ························································································································introduced·into·the
 26 ························································································································kernel.
 27 ·······························Ensure·that·successful·attempts·to·access·a·file·are·audited.·The·following·rules
 28 ·······························configure·audit·as·described·above:
 29 ·······························##·Successful·file·access·(any·other·opens)·This·has·to·go·last.
 30 ·······························##·These·next·two·are·likely·to·result·in·a·whole·lot·of·events
8 ·······························-a·always,exit·-F·arch=b64·-S·openat,open_by_handle_at·-F·a2&0100·-F·success=1·-·········Auditing·of·successful31 ·······························-a·always,exit·-F·arch=b32·-S·open,openat,openat2,open_by_handle_at·-F·success=1·-·······Auditing·of·successful
9 ·······························F·auid>=1000·-F·auid!=unset·-F·key=successful-create·····································attempts·to·create·a32 ········Configure·auditing·of··F·auid>=1000·-F·auid!=unset·-F·key=successful-access·····································attempts·to·access·a
10 ········Configure·auditing·of··-a·always,exit·-F·arch=b32·-S·open·-F·a1&0100·-F·success=1·-F·auid>=1000·-F·auid!=unset··file·helps·in 
11 AU-2(a)·successful·file········-F·key=successful-create·································································investigation·of 
12 ········creations·(AArch64)····-a·always,exit·-F·arch=b32·-S·creat·-F·success=1·-F·auid>=1000·-F·auid!=unset·-··········actions·which·happened33 AU-2(a)·successful·file········-a·always,exit·-F·arch=b64·-S·openat,openat2,open_by_handle_at·-F·success=1·-············file·helps·in
 34 ········accesses·(AArch64)·····F·auid>=1000·-F·auid!=unset·-F·key=successful-access·····································investigation·of
 35 ·······························Load·new·Audit·rules·into·kernel·by·running:·············································activities·performed·on
13 ·······························F·key=successful-create··································································on·the·system.36 ·······························augenrules·--load········································································the·system.
14 ·······························Load·new·Audit·rules·into·kernel·by·running: 
15 ·······························augenrules·--load 
16 ·······························Note:·This·rule·uses·a·special·set·of·Audit·rules·to·comply·with·OSPP·4.2.1.·You·may37 ·······························Note:·This·rule·uses·a·special·set·of·Audit·rules·to·comply·with·OSPP·4.2.1.·You·may
17 ·······························reuse·this·rule·in·different·profiles.·If·you·decide·to·do·so,·it·is·recommended·that38 ·······························reuse·this·rule·in·different·profiles.·If·you·decide·to·do·so,·it·is·recommended·that
18 ·······························you·inspect·contents·of·the·file·closely·and·make·sure·that·they·are·alligned·with·your39 ·······························you·inspect·contents·of·the·file·closely·and·make·sure·that·they·are·alligned·with·your
19 ·······························needs.40 ·······························needs.
 41 ························································································································Misuse·of·privileged
 42 ························································································································functions,·either
 43 ························································································································intentionally·or
 44 ························································································································unintentionally·by
 45 ························································································································authorized·users,·or·by
 46 ························································································································unauthorized·external
 47 ························································································································entities·that·have
 48 ························································································································compromised·system
 49 ························································································································accounts,·is·a·serious
 50 ························································································································and·ongoing·concern·and
 51 ·······························At·a·minimum,·the·audit·system·should·collect·the·execution·of·privileged·commands·for···can·have·significant
 52 ·······························all·users·and·root.·If·the·auditd·daemon·is·configured·to·use·the·augenrules·program·to··adverse·impacts·on
 53 ·······························read·audit·rules·during·daemon·startup·(the·default),·add·a·line·of·the·following·form···organizations.·Auditing
 54 AU-2(d)·Ensure·auditd·Collects·to·a·file·with·suffix·.rules·in·the·directory·/etc/audit/rules.d:························the·use·of·privileged
 55 AU-12···Information·on·the·Use·-a·always,exit·-F·path=/usr/sbin/postdrop·-F·perm=x·-F·auid>=1000·-F·auid!=unset·-·······functions·is·one·way·to
 56 (c)·····of·Privileged·Commands·F·key=privileged·········································································detect·such·misuse·and
 57 AC-6(9)·-·postdrop·············If·the·auditd·daemon·is·configured·to·use·the·auditctl·utility·to·read·audit·rules·······identify·the·risk·from
 58 CM-6(a)························during·daemon·startup,·add·a·line·of·the·following·form·to·/etc/audit/audit.rules:·······insider·and·advanced
 59 ·······························-a·always,exit·-F·path=/usr/sbin/postdrop·-F·perm=x·-F·auid>=1000·-F·auid!=unset·-·······persistent·threats.
 60 ·······························F·key=privileged
 61 ························································································································Privileged·programs·are
 62 ························································································································subject·to·escalation-
 63 ························································································································of-privilege·attacks,
 64 ························································································································which·attempt·to
 65 ························································································································subvert·their·normal
 66 ························································································································role·of·providing·some
 67 ························································································································necessary·but·limited
 68 ························································································································capability.·As·such,
 69 ························································································································motivation·exists·to
 70 ························································································································monitor·these·programs
 71 ························································································································for·unusual·activity.
 72 ·······························The·audit·system·should·collect·unsuccessful·file·deletion·attempts·for·all·users·and
 73 ·······························root.·If·the·auditd·daemon·is·configured·to·use·the·augenrules·program·to·read·audit
 74 ·······························rules·during·daemon·startup·(the·default),·add·the·following·lines·to·a·file·with·suffix
 75 ·······························.rules·in·the·directory·/etc/audit/rules.d.·If·the·auditd·daemon·is·configured·to·use····Unsuccessful·attempts
 76 ·······························the·auditctl·utility·to·read·audit·rules·during·daemon·startup,·add·the·following·lines··to·delete·files·could
 77 AU-2(d)························to·/etc/audit/audit.rules·file.··························································be·an·indicator·of
 78 AU-12···Record·Unsuccessful····-a·always,exit·-F·arch=b32·-S·unlink·-F·exit=-EACCES·-F·auid>=1000·-F·auid!=unset·-······malicious·activity·on·a
 79 (c)·····Delete·Attempts·to·····F·key=unsuccessful-delete································································system.·Auditing·these
 80 CM-6(a)·Files·-·unlink·········-a·always,exit·-F·arch=b32·-S·unlink·-F·exit=-EPERM·-F·auid>=1000·-F·auid!=unset·-·······events·could·serve·as
 81 ·······························F·key=unsuccessful-delete································································evidence·of·potential
 82 ·······························If·the·system·is·64·bit·then·also·add·the·following·lines:·······························system·compromise.
 83 ·······························-a·always,exit·-F·arch=b64·-S·unlink·-F·exit=-EACCES·-F·auid>=1000·-F·auid!=unset·-
 84 ·······························F·key=unsuccessful-delete
 85 ·······························-a·always,exit·-F·arch=b64·-S·unlink·-F·exit=-EPERM·-F·auid>=1000·-F·auid!=unset·-
 86 ·······························F·key=unsuccessful-delete
20 ·······························Ensure·that·unsuccessful·attempts·to·create·a·file·are·audited.·The·following·rules87 ·······························Ensure·that·unsuccessful·attempts·to·create·a·file·are·audited.·The·following·rules
21 ·······························configure·audit·as·described·above:88 ·······························configure·audit·as·described·above:
22 ·······························##·Unsuccessful·file·creation·(open·with·O_CREAT)89 ·······························##·Unsuccessful·file·creation·(open·with·O_CREAT)
23 ·······························-a·always,exit·-F·arch=b32·-S·openat,open_by_handle_at·-F·a2&0100·-F·exit=-EACCES·-90 ·······························-a·always,exit·-F·arch=b32·-S·openat,open_by_handle_at·-F·a2&0100·-F·exit=-EACCES·-
24 ·······························F·auid>=1000·-F·auid!=unset·-F·key=unsuccessful-create91 ·······························F·auid>=1000·-F·auid!=unset·-F·key=unsuccessful-create
25 ·······························-a·always,exit·-F·arch=b64·-S·openat,open_by_handle_at·-F·a2&0100·-F·exit=-EACCES·-92 ·······························-a·always,exit·-F·arch=b64·-S·openat,open_by_handle_at·-F·a2&0100·-F·exit=-EACCES·-
26 ·······························F·auid>=1000·-F·auid!=unset·-F·key=unsuccessful-create93 ·······························F·auid>=1000·-F·auid!=unset·-F·key=unsuccessful-create
Offset 50, 321 lines modifiedOffset 117, 114 lines modified
50 ·······························F·key=unsuccessful-create117 ·······························F·key=unsuccessful-create
51 ·······························Load·new·Audit·rules·into·kernel·by·running:118 ·······························Load·new·Audit·rules·into·kernel·by·running:
52 ·······························augenrules·--load119 ·······························augenrules·--load
53 ·······························Note:·This·rule·uses·a·special·set·of·Audit·rules·to·comply·with·OSPP·4.2.1.·You·may120 ·······························Note:·This·rule·uses·a·special·set·of·Audit·rules·to·comply·with·OSPP·4.2.1.·You·may
54 ·······························reuse·this·rule·in·different·profiles.·If·you·decide·to·do·so,·it·is·recommended·that121 ·······························reuse·this·rule·in·different·profiles.·If·you·decide·to·do·so,·it·is·recommended·that
55 ·······························you·inspect·contents·of·the·file·closely·and·make·sure·that·they·are·alligned·with·your122 ·······························you·inspect·contents·of·the·file·closely·and·make·sure·that·they·are·alligned·with·your
56 ·······························needs.123 ·······························needs.
 124 ·······························Configure·kernel·to·prevent·modification·of·login·UIDs·once·they·are·set.·Changing·login·If·modification·of
 125 ·······························UIDs·while·this·configuration·is·enforced·requires·special·capabilities·which·are·not····login·UIDs·is·not
 126 ········Configure·immutable····available·to·unprivileged·users.·The·following·rules·configure·audit·as·described·above:·prevented,·they·can·be
 127 AU-2(a)·Audit·login·UIDs·······##·Make·the·loginuid·immutable.·This·prevents·tampering·with·the·auid.···················changed·by·unprivileged
 128 ·······························--loginuid-immutable·····································································users·and·make·auditing
 129 ·······························Load·new·Audit·rules·into·kernel·by·running:·············································complicated·or
 130 ·······························augenrules·--load········································································impossible.
57 ························································································································Arbitrary·changes·to 
58 ·······························If·the·auditd·daemon·is·configured·to·use·the·augenrules·program·to·read·audit·rules·····the·system·time·can·be 
59 ·······························during·daemon·startup·(the·default),·add·the·following·line·to·a·file·with·suffix·.rules·used·to·obfuscate 
60 AU-2(d)························in·the·directory·/etc/audit/rules.d:·····················································nefarious·activities·in 
61 AU-12···Record·Attempts·to·····-w·/etc/localtime·-p·wa·-k·audit_time_rules··············································log·files,·as·well·as 
62 (c)·····Alter·the·localtime····If·the·auditd·daemon·is·configured·to·use·the·auditctl·utility·to·read·audit·rules·······to·confuse·network 
63 AC-6(9)·File···················during·daemon·startup,·add·the·following·line·to·/etc/audit/audit.rules·file:············services·that·are 
64 CM-6(a)························-w·/etc/localtime·-p·wa·-k·audit_time_rules··············································highly·dependent·upon 
65 ·······························The·-k·option·allows·for·the·specification·of·a·key·in·string·form·that·can·be·used·for··an·accurate·system·time 
Max diff block lines reached; 2710152/2726567 bytes (99.40%) of diff not shown.
789 KB
./usr/share/doc/ssg-nondebian/table-rhel8-pcidssrefs.html
Ordering differences only
    
Offset 73, 28 lines modifiedOffset 73, 14 lines modified
73 is·the·only·place·that·loopback·network·traffic·should·be·seen,73 is·the·only·place·that·loopback·network·traffic·should·be·seen,
74 all·other·interfaces·should·ignore·traffic·on·this·network·as·an74 all·other·interfaces·should·ignore·traffic·on·this·network·as·an
75 anti-spoofing·measure.75 anti-spoofing·measure.
76 ······</td>76 ······</td>
77 ····</tr>77 ····</tr>
78 ····<tr>78 ····<tr>
79 ······<td>Req-1.3.1<br/>Req-1.3.2</td>79 ······<td>Req-1.3.1<br/>Req-1.3.2</td>
80 ······<td>Disable·Kernel·Parameter·for·IP·Forwarding·on·IPv4·Interfaces</td> 
81 ······<td·xml:lang="en-US"> 
82 ········To·set·the·runtime·status·of·the·<code>net.ipv4.ip_forward</code>·kernel·parameter,·run·the·following·command:·<pre>$·sudo·sysctl·-w·net.ipv4.ip_forward=0</pre> 
83 To·make·sure·that·the·setting·is·persistent,·add·the·following·line·to·a·file·in·the·directory·<tt>/etc/sysctl.d</tt>:·<pre>net.ipv4.ip_forward·=·0</pre> 
84 ······</td> 
85 ······<td·xml:lang="en-US"> 
86 ········Routing·protocol·daemons·are·typically·used·on·routers·to·exchange 
87 network·topology·information·with·other·routers.·If·this·capability·is·used·when 
88 not·required,·system·network·information·may·be·unnecessarily·transmitted·across 
89 the·network. 
90 ······</td> 
91 ····</tr> 
92 ····<tr> 
93 ······<td>Req-1.3.1<br/>Req-1.3.2</td> 
94 ······<td>Ensure·IPv6·is·disabled·through·kernel·boot·parameter</td>80 ······<td>Ensure·IPv6·is·disabled·through·kernel·boot·parameter</td>
95 ······<td·xml:lang="en-US">81 ······<td·xml:lang="en-US">
96 ········To·disable·IPv6·protocol·support·in·the·Linux·kernel,82 ········To·disable·IPv6·protocol·support·in·the·Linux·kernel,
97 add·the·argument·<tt>ipv6.disable=1</tt>·to·the·default83 add·the·argument·<tt>ipv6.disable=1</tt>·to·the·default
98 GRUB2·command·line·for·the·Linux·operating·system.84 GRUB2·command·line·for·the·Linux·operating·system.
99 To·ensure·that·<tt>ipv6.disable=1</tt>·is·added·as·a·kernel·command·line85 To·ensure·that·<tt>ipv6.disable=1</tt>·is·added·as·a·kernel·command·line
100 argument·to·newly·installed·kernels,·add·<tt>ipv6.disable=1</tt>·to·the86 argument·to·newly·installed·kernels,·add·<tt>ipv6.disable=1</tt>·to·the
Offset 105, 14 lines modifiedOffset 91, 28 lines modified
105 ······</td>91 ······</td>
106 ······<td·xml:lang="en-US">92 ······<td·xml:lang="en-US">
107 ········Any·unnecessary·network·stacks,·including·IPv6,·should·be·disabled·to·reduce93 ········Any·unnecessary·network·stacks,·including·IPv6,·should·be·disabled·to·reduce
108 the·vulnerability·to·exploitation.94 the·vulnerability·to·exploitation.
109 ······</td>95 ······</td>
110 ····</tr>96 ····</tr>
111 ····<tr>97 ····<tr>
 98 ······<td>Req-1.3.1<br/>Req-1.3.2</td>
 99 ······<td>Disable·Kernel·Parameter·for·IP·Forwarding·on·IPv4·Interfaces</td>
 100 ······<td·xml:lang="en-US">
 101 ········To·set·the·runtime·status·of·the·<code>net.ipv4.ip_forward</code>·kernel·parameter,·run·the·following·command:·<pre>$·sudo·sysctl·-w·net.ipv4.ip_forward=0</pre>
 102 To·make·sure·that·the·setting·is·persistent,·add·the·following·line·to·a·file·in·the·directory·<tt>/etc/sysctl.d</tt>:·<pre>net.ipv4.ip_forward·=·0</pre>
 103 ······</td>
 104 ······<td·xml:lang="en-US">
 105 ········Routing·protocol·daemons·are·typically·used·on·routers·to·exchange
 106 network·topology·information·with·other·routers.·If·this·capability·is·used·when
 107 not·required,·system·network·information·may·be·unnecessarily·transmitted·across
 108 the·network.
 109 ······</td>
 110 ····</tr>
 111 ····<tr>
112 ······<td>Req-1.3.3</td>112 ······<td>Req-1.3.3</td>
113 ······<td>Deactivate·Wireless·Network·Interfaces</td>113 ······<td>Deactivate·Wireless·Network·Interfaces</td>
114 ······<td·xml:lang="en-US">114 ······<td·xml:lang="en-US">
115 ········Deactivating·wireless·network·interfaces·should·prevent·normal·usage·of·the·wireless115 ········Deactivating·wireless·network·interfaces·should·prevent·normal·usage·of·the·wireless
116 capability.116 capability.
117 <br·/><br·/>117 <br·/><br·/>
  
Offset 246, 41 lines modifiedOffset 246, 25 lines modified
246 ······<td·xml:lang="en-US">246 ······<td·xml:lang="en-US">
247 ········Disabling·DCCP·protects247 ········Disabling·DCCP·protects
248 the·system·against·exploitation·of·any·flaws·in·its·implementation.248 the·system·against·exploitation·of·any·flaws·in·its·implementation.
249 ······</td>249 ······</td>
250 ····</tr>250 ····</tr>
251 ····<tr>251 ····<tr>
252 ······<td>Req-1.4.3</td>252 ······<td>Req-1.4.3</td>
 253 ······<td>Enable·Kernel·Parameter·to·Ignore·ICMP·Broadcast·Echo·Requests·on·IPv4·Interfaces</td>
253 ······<td>Disable·Kernel·Parameter·for·Accepting·ICMP·Redirects·by·Default·on·IPv4·Interfaces</td> 
254 ······<td·xml:lang="en-US"> 
255 ········To·set·the·runtime·status·of·the·<code>net.ipv4.conf.default.accept_redirects</code>·kernel·parameter,·run·the·following·command:·<pre>$·sudo·sysctl·-w·net.ipv4.conf.default.accept_redirects=0</pre> 
256 To·make·sure·that·the·setting·is·persistent,·add·the·following·line·to·a·file·in·the·directory·<tt>/etc/sysctl.d</tt>:·<pre>net.ipv4.conf.default.accept_redirects·=·0</pre> 
257 ······</td> 
258 ······<td·xml:lang="en-US"> 
259 ········ICMP·redirect·messages·are·used·by·routers·to·inform·hosts·that·a·more 
260 direct·route·exists·for·a·particular·destination.·These·messages·modify·the 
261 host's·route·table·and·are·unauthenticated.·An·illicit·ICMP·redirect 
262 message·could·result·in·a·man-in-the-middle·attack. 
263 <br·/>This·feature·of·the·IPv4·protocol·has·few·legitimate·uses.·It·should 
264 be·disabled·unless·absolutely·required. 
265 ······</td> 
266 ····</tr> 
267 ····<tr> 
268 ······<td>Req-1.4.3</td> 
269 ······<td>Enable·Kernel·Parameter·to·Use·Reverse·Path·Filtering·on·all·IPv4·Interfaces</td> 
270 ······<td·xml:lang="en-US">254 ······<td·xml:lang="en-US">
271 ········To·set·the·runtime·status·of·the·<code>net.ipv4.conf.all.rp_filter</code>·kernel·parameter,·run·the·following·command:·<pre>$·sudo·sysctl·-w·net.ipv4.conf.all.rp_filter=1</pre>255 ········To·set·the·runtime·status·of·the·<code>net.ipv4.icmp_echo_ignore_broadcasts</code>·kernel·parameter,·run·the·following·command:·<pre>$·sudo·sysctl·-w·net.ipv4.icmp_echo_ignore_broadcasts=1</pre>
272 To·make·sure·that·the·setting·is·persistent,·add·the·following·line·to·a·file·in·the·directory·<tt>/etc/sysctl.d</tt>:·<pre>net.ipv4.conf.all.rp_filter·=·1</pre>256 To·make·sure·that·the·setting·is·persistent,·add·the·following·line·to·a·file·in·the·directory·<tt>/etc/sysctl.d</tt>:·<pre>net.ipv4.icmp_echo_ignore_broadcasts·=·1</pre>
273 ······</td>257 ······</td>
274 ······<td·xml:lang="en-US">258 ······<td·xml:lang="en-US">
275 ········Enabling·reverse·path·filtering·drops·packets·with·source·addresses 
276 that·should·not·have·been·able·to·be·received·on·the·interface·they·were 
277 received·on.·It·should·not·be·used·on·systems·which·are·routers·for 
278 complicated·networks,·but·is·helpful·for·end·hosts·and·routers·serving·small 
279 networks.259 ········Responding·to·broadcast·(ICMP)·echoes·facilitates·network·mapping
 260 and·provides·a·vector·for·amplification·attacks.
 261 <br·/>
 262 Ignoring·ICMP·echo·requests·(pings)·sent·to·broadcast·or·multicast
 263 addresses·makes·the·system·slightly·more·difficult·to·enumerate·on·the·network.
280 ······</td>264 ······</td>
281 ····</tr>265 ····</tr>
282 ····<tr>266 ····<tr>
283 ······<td>Req-1.4.3</td>267 ······<td>Req-1.4.3</td>
284 ······<td>Disable·Kernel·Parameter·for·Accepting·Source-Routed·Packets·on·IPv6·Interfaces·by·Default</td>268 ······<td>Disable·Kernel·Parameter·for·Accepting·Source-Routed·Packets·on·IPv6·Interfaces·by·Default</td>
285 ······<td·xml:lang="en-US">269 ······<td·xml:lang="en-US">
286 ········To·set·the·runtime·status·of·the·<code>net.ipv6.conf.default.accept_source_route</code>·kernel·parameter,·run·the·following·command:·<pre>$·sudo·sysctl·-w·net.ipv6.conf.default.accept_source_route=0</pre>270 ········To·set·the·runtime·status·of·the·<code>net.ipv6.conf.default.accept_source_route</code>·kernel·parameter,·run·the·following·command:·<pre>$·sudo·sysctl·-w·net.ipv6.conf.default.accept_source_route=0</pre>
Offset 295, 37 lines modifiedOffset 279, 41 lines modified
  
295 Accepting·source-routed·packets·in·the·IPv6·protocol·has·few·legitimate279 Accepting·source-routed·packets·in·the·IPv6·protocol·has·few·legitimate
296 uses.·It·should·be·disabled·unless·it·is·absolutely·required.280 uses.·It·should·be·disabled·unless·it·is·absolutely·required.
297 ······</td>281 ······</td>
298 ····</tr>282 ····</tr>
299 ····<tr>283 ····<tr>
300 ······<td>Req-1.4.3</td>284 ······<td>Req-1.4.3</td>
301 ······<td>Enable·Kernel·Parameter·to·Ignore·Bogus·ICMP·Error·Responses·on·IPv4·Interfaces</td>285 ······<td>Disable·Kernel·Parameter·for·Accepting·ICMP·Redirects·by·Default·on·IPv4·Interfaces</td>
302 ······<td·xml:lang="en-US">286 ······<td·xml:lang="en-US">
303 ········To·set·the·runtime·status·of·the·<code>net.ipv4.icmp_ignore_bogus_error_responses</code>·kernel·parameter,·run·the·following·command:·<pre>$·sudo·sysctl·-w·net.ipv4.icmp_ignore_bogus_error_responses=1</pre>287 ········To·set·the·runtime·status·of·the·<code>net.ipv4.conf.default.accept_redirects</code>·kernel·parameter,·run·the·following·command:·<pre>$·sudo·sysctl·-w·net.ipv4.conf.default.accept_redirects=0</pre>
304 To·make·sure·that·the·setting·is·persistent,·add·the·following·line·to·a·file·in·the·directory·<tt>/etc/sysctl.d</tt>:·<pre>net.ipv4.icmp_ignore_bogus_error_responses·=·1</pre>288 To·make·sure·that·the·setting·is·persistent,·add·the·following·line·to·a·file·in·the·directory·<tt>/etc/sysctl.d</tt>:·<pre>net.ipv4.conf.default.accept_redirects·=·0</pre>
305 ······</td>289 ······</td>
306 ······<td·xml:lang="en-US">290 ······<td·xml:lang="en-US">
307 ········Ignoring·bogus·ICMP·error·responses·reduces 
308 log·size,·although·some·activity·would·not·be·logged.291 ········ICMP·redirect·messages·are·used·by·routers·to·inform·hosts·that·a·more
 292 direct·route·exists·for·a·particular·destination.·These·messages·modify·the
 293 host's·route·table·and·are·unauthenticated.·An·illicit·ICMP·redirect
 294 message·could·result·in·a·man-in-the-middle·attack.
 295 <br·/>This·feature·of·the·IPv4·protocol·has·few·legitimate·uses.·It·should
 296 be·disabled·unless·absolutely·required.
309 ······</td>297 ······</td>
310 ····</tr>298 ····</tr>
Max diff block lines reached; 299943/307679 bytes (97.49%) of diff not shown.
488 KB
html2text {}
    
Offset 34, 14 lines modifiedOffset 34, 26 lines modified
34 ····················································································network·traffic34 ····················································································network·traffic
35 ····················································································should·be·seen,·all35 ····················································································should·be·seen,·all
36 ····················································································other·interfaces36 ····················································································other·interfaces
37 ····················································································should·ignore37 ····················································································should·ignore
38 ····················································································traffic·on·this38 ····················································································traffic·on·this
39 ····················································································network·as·an·anti-39 ····················································································network·as·an·anti-
40 ····················································································spoofing·measure.40 ····················································································spoofing·measure.
 41 ·····························To·disable·IPv6·protocol·support·in·the·Linux·kernel,
 42 ·····························add·the·argument·ipv6.disable=1·to·the·default·GRUB2
 43 ·····························command·line·for·the·Linux·operating·system.·To·ensure·Any·unnecessary
 44 ·····························that·ipv6.disable=1·is·added·as·a·kernel·command·line··network·stacks,
 45 Req-·····Ensure·IPv6·is······argument·to·newly·installed·kernels,·add···············including·IPv6,
 46 1.3.1····disabled·through····ipv6.disable=1·to·the·default·Grub2·command·line·for···should·be·disabled
 47 Req-·····kernel·boot·········Linux·operating·systems.·Modify·the·line·within·/etc/··to·reduce·the
 48 1.3.2····parameter···········default/grub·as·shown·below:···························vulnerability·to
 49 ·····························GRUB_CMDLINE_LINUX="...·ipv6.disable=1·..."············exploitation.
 50 ·····························Run·the·following·command·to·update·command·line·for
 51 ·····························already·installed·kernels:
 52 ·····························#·grubby·--update-kernel=ALL·--args="ipv6.disable=1"
41 ····················································································Routing·protocol53 ····················································································Routing·protocol
42 ····················································································daemons·are54 ····················································································daemons·are
43 ····················································································typically·used·on55 ····················································································typically·used·on
44 ····················································································routers·to·exchange56 ····················································································routers·to·exchange
45 ·····························To·set·the·runtime·status·of·the·net.ipv4.ip_forward···network·topology57 ·····························To·set·the·runtime·status·of·the·net.ipv4.ip_forward···network·topology
46 Req-·····Disable·Kernel······kernel·parameter,·run·the·following·command:···········information·with58 Req-·····Disable·Kernel······kernel·parameter,·run·the·following·command:···········information·with
47 1.3.1····Parameter·for·IP····$·sudo·sysctl·-w·net.ipv4.ip_forward=0·················other·routers.·If59 1.3.1····Parameter·for·IP····$·sudo·sysctl·-w·net.ipv4.ip_forward=0·················other·routers.·If
Offset 49, 26 lines modifiedOffset 61, 14 lines modified
49 1.3.2····Interfaces··········following·line·to·a·file·in·the·directory·/etc/········used·when·not61 1.3.2····Interfaces··········following·line·to·a·file·in·the·directory·/etc/········used·when·not
50 ·····························sysctl.d:··············································required,·system62 ·····························sysctl.d:··············································required,·system
51 ·····························net.ipv4.ip_forward·=·0································network·information63 ·····························net.ipv4.ip_forward·=·0································network·information
52 ····················································································may·be64 ····················································································may·be
53 ····················································································unnecessarily65 ····················································································unnecessarily
54 ····················································································transmitted·across66 ····················································································transmitted·across
55 ····················································································the·network.67 ····················································································the·network.
56 ·····························To·disable·IPv6·protocol·support·in·the·Linux·kernel, 
57 ·····························add·the·argument·ipv6.disable=1·to·the·default·GRUB2 
58 ·····························command·line·for·the·Linux·operating·system.·To·ensure·Any·unnecessary 
59 ·····························that·ipv6.disable=1·is·added·as·a·kernel·command·line··network·stacks, 
60 Req-·····Ensure·IPv6·is······argument·to·newly·installed·kernels,·add···············including·IPv6, 
61 1.3.1····disabled·through····ipv6.disable=1·to·the·default·Grub2·command·line·for···should·be·disabled 
62 Req-·····kernel·boot·········Linux·operating·systems.·Modify·the·line·within·/etc/··to·reduce·the 
63 1.3.2····parameter···········default/grub·as·shown·below:···························vulnerability·to 
64 ·····························GRUB_CMDLINE_LINUX="...·ipv6.disable=1·..."············exploitation. 
65 ·····························Run·the·following·command·to·update·command·line·for 
66 ·····························already·installed·kernels: 
67 ·····························#·grubby·--update-kernel=ALL·--args="ipv6.disable=1" 
68 ····················································································The·use·of·wireless68 ····················································································The·use·of·wireless
69 ····················································································networking·can69 ····················································································networking·can
70 ····················································································introduce·many70 ····················································································introduce·many
71 ····················································································different·attack71 ····················································································different·attack
72 ····················································································vectors·into·the72 ····················································································vectors·into·the
73 ····················································································organization's73 ····················································································organization's
74 ····················································································network.·Common74 ····················································································network.·Common
Offset 187, 14 lines modifiedOffset 187, 61 lines modified
187 Req-·····Disable·DCCP········being·loaded,·add·the·following·line·to·the·file·/etc/·against187 Req-·····Disable·DCCP········being·loaded,·add·the·following·line·to·the·file·/etc/·against
188 1.4.2····Support·············modprobe.d/dccp.conf:··································exploitation·of·any188 1.4.2····Support·············modprobe.d/dccp.conf:··································exploitation·of·any
189 ·····························install·dccp·/bin/false································flaws·in·its189 ·····························install·dccp·/bin/false································flaws·in·its
190 ·····························To·configure·the·system·to·prevent·the·dccp·from·being·implementation.190 ·····························To·configure·the·system·to·prevent·the·dccp·from·being·implementation.
191 ·····························used,·add·the·following·line·to·file·/etc/modprobe.d/191 ·····························used,·add·the·following·line·to·file·/etc/modprobe.d/
192 ·····························dccp.conf:192 ·····························dccp.conf:
193 ·····························blacklist·dccp193 ·····························blacklist·dccp
 194 ····················································································Responding·to
 195 ····················································································broadcast·(ICMP)
 196 ····················································································echoes·facilitates
 197 ·····························To·set·the·runtime·status·of·the·······················network·mapping·and
 198 ·····························net.ipv4.icmp_echo_ignore_broadcasts·kernel·parameter,·provides·a·vector
 199 ·········Enable·Kernel·······run·the·following·command:·····························for·amplification
 200 ·········Parameter·to·Ignore·$·sudo·sysctl·-········································attacks.
 201 Req-·····ICMP·Broadcast·Echo·w·net.ipv4.icmp_echo_ignore_broadcasts=1···············Ignoring·ICMP·echo
 202 1.4.3····Requests·on·IPv4····To·make·sure·that·the·setting·is·persistent,·add·the···requests·(pings)
 203 ·········Interfaces··········following·line·to·a·file·in·the·directory·/etc/········sent·to·broadcast
 204 ·····························sysctl.d:··············································or·multicast
 205 ·····························net.ipv4.icmp_echo_ignore_broadcasts·=·1···············addresses·makes·the
 206 ····················································································system·slightly
 207 ····················································································more·difficult·to
 208 ····················································································enumerate·on·the
 209 ····················································································network.
 210 ····················································································Source-routed
 211 ····················································································packets·allow·the
 212 ····················································································source·of·the
 213 ····················································································packet·to·suggest
 214 ····················································································routers·forward·the
 215 ····················································································packet·along·a
 216 ····················································································different·path·than
 217 ····················································································configured·on·the
 218 ····················································································router,·which·can
 219 ····················································································be·used·to·bypass
 220 ····················································································network·security
 221 ·····························To·set·the·runtime·status·of·the·······················measures.·This
 222 ·········Disable·Kernel······net.ipv6.conf.default.accept_source_route·kernel·······requirement·applies
 223 ·········Parameter·for·······parameter,·run·the·following·command:··················only·to·the
 224 Req-·····Accepting·Source-···$·sudo·sysctl·-········································forwarding·of
 225 1.4.3····Routed·Packets·on···w·net.ipv6.conf.default.accept_source_route=0··········source-routerd
 226 ·········IPv6·Interfaces·by··To·make·sure·that·the·setting·is·persistent,·add·the···traffic,·such·as
 227 ·········Default·············following·line·to·a·file·in·the·directory·/etc/········when·IPv6
 228 ·····························sysctl.d:··············································forwarding·is
 229 ·····························net.ipv6.conf.default.accept_source_route·=·0··········enabled·and·the
 230 ····················································································system·is
 231 ····················································································functioning·as·a
 232 ····················································································router.·Accepting
 233 ····················································································source-routed
 234 ····················································································packets·in·the·IPv6
 235 ····················································································protocol·has·few
 236 ····················································································legitimate·uses.·It
 237 ····················································································should·be·disabled
 238 ····················································································unless·it·is
 239 ····················································································absolutely
 240 ····················································································required.
194 ····················································································ICMP·redirect241 ····················································································ICMP·redirect
195 ····················································································messages·are·used242 ····················································································messages·are·used
196 ····················································································by·routers·to243 ····················································································by·routers·to
197 ····················································································inform·hosts·that·a244 ····················································································inform·hosts·that·a
198 ····················································································more·direct·route245 ····················································································more·direct·route
199 ····················································································exists·for·a246 ····················································································exists·for·a
200 ····················································································particular247 ····················································································particular
Offset 229, 110 lines modifiedOffset 276, 63 lines modified
229 ·····························sysctl.d:··············································are·routers·for276 ·····························sysctl.d:··············································are·routers·for
230 ·····························net.ipv4.conf.all.rp_filter·=·1························complicated277 ·····························net.ipv4.conf.all.rp_filter·=·1························complicated
231 ····················································································networks,·but·is278 ····················································································networks,·but·is
232 ····················································································helpful·for·end279 ····················································································helpful·for·end
233 ····················································································hosts·and·routers280 ····················································································hosts·and·routers
234 ····················································································serving·small281 ····················································································serving·small
235 ····················································································networks.282 ····················································································networks.
236 ····················································································Source-routed 
237 ····················································································packets·allow·the 
238 ····················································································source·of·the 
239 ····················································································packet·to·suggest 
Max diff block lines reached; 482589/500065 bytes (96.51%) of diff not shown.
885 B
./usr/share/scap-security-guide/ansible/cs10-playbook-stig.yml
    
Offset 43, 15 lines modifiedOffset 43, 15 lines modified
43 ····var_accounts_passwords_pam_faillock_dir:·!!str·/var/log/faillock43 ····var_accounts_passwords_pam_faillock_dir:·!!str·/var/log/faillock
44 ····var_accounts_passwords_pam_faillock_fail_interval:·!!str·90044 ····var_accounts_passwords_pam_faillock_fail_interval:·!!str·900
45 ····var_accounts_passwords_pam_faillock_unlock_time:·!!str·045 ····var_accounts_passwords_pam_faillock_unlock_time:·!!str·0
46 ····var_password_pam_dcredit:·!!str·-146 ····var_password_pam_dcredit:·!!str·-1
47 ····var_password_pam_dictcheck:·!!str·147 ····var_password_pam_dictcheck:·!!str·1
48 ····var_password_pam_difok:·!!str·848 ····var_password_pam_difok:·!!str·8
49 ····var_password_pam_lcredit:·!!str·-149 ····var_password_pam_lcredit:·!!str·-1
50 ····var_password_pam_maxclassrepeat:·!!str·350 ····var_password_pam_maxclassrepeat:·!!str·4
51 ····var_password_pam_maxrepeat:·!!str·351 ····var_password_pam_maxrepeat:·!!str·3
52 ····var_password_pam_minclass:·!!str·452 ····var_password_pam_minclass:·!!str·4
53 ····var_password_pam_minlen:·!!str·1553 ····var_password_pam_minlen:·!!str·15
54 ····var_password_pam_ocredit:·!!str·-154 ····var_password_pam_ocredit:·!!str·-1
55 ····var_password_pam_retry:·!!str·355 ····var_password_pam_retry:·!!str·3
56 ····var_password_pam_ucredit:·!!str·-156 ····var_password_pam_ucredit:·!!str·-1
57 ····var_password_hashing_algorithm_pam:·!!str·yescrypt57 ····var_password_hashing_algorithm_pam:·!!str·yescrypt
893 B
./usr/share/scap-security-guide/ansible/cs10-playbook-stig_gui.yml
    
Offset 43, 15 lines modifiedOffset 43, 15 lines modified
43 ····var_accounts_passwords_pam_faillock_dir:·!!str·/var/log/faillock43 ····var_accounts_passwords_pam_faillock_dir:·!!str·/var/log/faillock
44 ····var_accounts_passwords_pam_faillock_fail_interval:·!!str·90044 ····var_accounts_passwords_pam_faillock_fail_interval:·!!str·900
45 ····var_accounts_passwords_pam_faillock_unlock_time:·!!str·045 ····var_accounts_passwords_pam_faillock_unlock_time:·!!str·0
46 ····var_password_pam_dcredit:·!!str·-146 ····var_password_pam_dcredit:·!!str·-1
47 ····var_password_pam_dictcheck:·!!str·147 ····var_password_pam_dictcheck:·!!str·1
48 ····var_password_pam_difok:·!!str·848 ····var_password_pam_difok:·!!str·8
49 ····var_password_pam_lcredit:·!!str·-149 ····var_password_pam_lcredit:·!!str·-1
50 ····var_password_pam_maxclassrepeat:·!!str·350 ····var_password_pam_maxclassrepeat:·!!str·4
51 ····var_password_pam_maxrepeat:·!!str·351 ····var_password_pam_maxrepeat:·!!str·3
52 ····var_password_pam_minclass:·!!str·452 ····var_password_pam_minclass:·!!str·4
53 ····var_password_pam_minlen:·!!str·1553 ····var_password_pam_minlen:·!!str·15
54 ····var_password_pam_ocredit:·!!str·-154 ····var_password_pam_ocredit:·!!str·-1
55 ····var_password_pam_retry:·!!str·355 ····var_password_pam_retry:·!!str·3
56 ····var_password_pam_ucredit:·!!str·-156 ····var_password_pam_ucredit:·!!str·-1
57 ····var_password_hashing_algorithm_pam:·!!str·yescrypt57 ····var_password_hashing_algorithm_pam:·!!str·yescrypt
885 B
./usr/share/scap-security-guide/ansible/ol10-playbook-stig.yml
    
Offset 41, 15 lines modifiedOffset 41, 15 lines modified
41 ····var_accounts_passwords_pam_faillock_dir:·!!str·/var/log/faillock41 ····var_accounts_passwords_pam_faillock_dir:·!!str·/var/log/faillock
42 ····var_accounts_passwords_pam_faillock_fail_interval:·!!str·90042 ····var_accounts_passwords_pam_faillock_fail_interval:·!!str·900
43 ····var_accounts_passwords_pam_faillock_unlock_time:·!!str·043 ····var_accounts_passwords_pam_faillock_unlock_time:·!!str·0
44 ····var_password_pam_dcredit:·!!str·-144 ····var_password_pam_dcredit:·!!str·-1
45 ····var_password_pam_dictcheck:·!!str·145 ····var_password_pam_dictcheck:·!!str·1
46 ····var_password_pam_difok:·!!str·846 ····var_password_pam_difok:·!!str·8
47 ····var_password_pam_lcredit:·!!str·-147 ····var_password_pam_lcredit:·!!str·-1
48 ····var_password_pam_maxclassrepeat:·!!str·348 ····var_password_pam_maxclassrepeat:·!!str·4
49 ····var_password_pam_maxrepeat:·!!str·349 ····var_password_pam_maxrepeat:·!!str·3
50 ····var_password_pam_minclass:·!!str·450 ····var_password_pam_minclass:·!!str·4
51 ····var_password_pam_minlen:·!!str·1551 ····var_password_pam_minlen:·!!str·15
52 ····var_password_pam_ocredit:·!!str·-152 ····var_password_pam_ocredit:·!!str·-1
53 ····var_password_pam_retry:·!!str·353 ····var_password_pam_retry:·!!str·3
54 ····var_password_pam_ucredit:·!!str·-154 ····var_password_pam_ucredit:·!!str·-1
55 ····var_password_hashing_algorithm_pam:·!!str·yescrypt55 ····var_password_hashing_algorithm_pam:·!!str·yescrypt
893 B
./usr/share/scap-security-guide/ansible/ol10-playbook-stig_gui.yml
    
Offset 41, 15 lines modifiedOffset 41, 15 lines modified
41 ····var_accounts_passwords_pam_faillock_dir:·!!str·/var/log/faillock41 ····var_accounts_passwords_pam_faillock_dir:·!!str·/var/log/faillock
42 ····var_accounts_passwords_pam_faillock_fail_interval:·!!str·90042 ····var_accounts_passwords_pam_faillock_fail_interval:·!!str·900
43 ····var_accounts_passwords_pam_faillock_unlock_time:·!!str·043 ····var_accounts_passwords_pam_faillock_unlock_time:·!!str·0
44 ····var_password_pam_dcredit:·!!str·-144 ····var_password_pam_dcredit:·!!str·-1
45 ····var_password_pam_dictcheck:·!!str·145 ····var_password_pam_dictcheck:·!!str·1
46 ····var_password_pam_difok:·!!str·846 ····var_password_pam_difok:·!!str·8
47 ····var_password_pam_lcredit:·!!str·-147 ····var_password_pam_lcredit:·!!str·-1
48 ····var_password_pam_maxclassrepeat:·!!str·348 ····var_password_pam_maxclassrepeat:·!!str·4
49 ····var_password_pam_maxrepeat:·!!str·349 ····var_password_pam_maxrepeat:·!!str·3
50 ····var_password_pam_minclass:·!!str·450 ····var_password_pam_minclass:·!!str·4
51 ····var_password_pam_minlen:·!!str·1551 ····var_password_pam_minlen:·!!str·15
52 ····var_password_pam_ocredit:·!!str·-152 ····var_password_pam_ocredit:·!!str·-1
53 ····var_password_pam_retry:·!!str·353 ····var_password_pam_retry:·!!str·3
54 ····var_password_pam_ucredit:·!!str·-154 ····var_password_pam_ucredit:·!!str·-1
55 ····var_password_hashing_algorithm_pam:·!!str·yescrypt55 ····var_password_hashing_algorithm_pam:·!!str·yescrypt
889 B
./usr/share/scap-security-guide/ansible/rhel10-playbook-stig.yml
    
Offset 43, 15 lines modifiedOffset 43, 15 lines modified
43 ····var_accounts_passwords_pam_faillock_dir:·!!str·/var/log/faillock43 ····var_accounts_passwords_pam_faillock_dir:·!!str·/var/log/faillock
44 ····var_accounts_passwords_pam_faillock_fail_interval:·!!str·90044 ····var_accounts_passwords_pam_faillock_fail_interval:·!!str·900
45 ····var_accounts_passwords_pam_faillock_unlock_time:·!!str·045 ····var_accounts_passwords_pam_faillock_unlock_time:·!!str·0
46 ····var_password_pam_dcredit:·!!str·-146 ····var_password_pam_dcredit:·!!str·-1
47 ····var_password_pam_dictcheck:·!!str·147 ····var_password_pam_dictcheck:·!!str·1
48 ····var_password_pam_difok:·!!str·848 ····var_password_pam_difok:·!!str·8
49 ····var_password_pam_lcredit:·!!str·-149 ····var_password_pam_lcredit:·!!str·-1
50 ····var_password_pam_maxclassrepeat:·!!str·350 ····var_password_pam_maxclassrepeat:·!!str·4
51 ····var_password_pam_maxrepeat:·!!str·351 ····var_password_pam_maxrepeat:·!!str·3
52 ····var_password_pam_minclass:·!!str·452 ····var_password_pam_minclass:·!!str·4
53 ····var_password_pam_minlen:·!!str·1553 ····var_password_pam_minlen:·!!str·15
54 ····var_password_pam_ocredit:·!!str·-154 ····var_password_pam_ocredit:·!!str·-1
55 ····var_password_pam_retry:·!!str·355 ····var_password_pam_retry:·!!str·3
56 ····var_password_pam_ucredit:·!!str·-156 ····var_password_pam_ucredit:·!!str·-1
57 ····var_password_hashing_algorithm_pam:·!!str·yescrypt57 ····var_password_hashing_algorithm_pam:·!!str·yescrypt
897 B
./usr/share/scap-security-guide/ansible/rhel10-playbook-stig_gui.yml
    
Offset 43, 15 lines modifiedOffset 43, 15 lines modified
43 ····var_accounts_passwords_pam_faillock_dir:·!!str·/var/log/faillock43 ····var_accounts_passwords_pam_faillock_dir:·!!str·/var/log/faillock
44 ····var_accounts_passwords_pam_faillock_fail_interval:·!!str·90044 ····var_accounts_passwords_pam_faillock_fail_interval:·!!str·900
45 ····var_accounts_passwords_pam_faillock_unlock_time:·!!str·045 ····var_accounts_passwords_pam_faillock_unlock_time:·!!str·0
46 ····var_password_pam_dcredit:·!!str·-146 ····var_password_pam_dcredit:·!!str·-1
47 ····var_password_pam_dictcheck:·!!str·147 ····var_password_pam_dictcheck:·!!str·1
48 ····var_password_pam_difok:·!!str·848 ····var_password_pam_difok:·!!str·8
49 ····var_password_pam_lcredit:·!!str·-149 ····var_password_pam_lcredit:·!!str·-1
50 ····var_password_pam_maxclassrepeat:·!!str·350 ····var_password_pam_maxclassrepeat:·!!str·4
51 ····var_password_pam_maxrepeat:·!!str·351 ····var_password_pam_maxrepeat:·!!str·3
52 ····var_password_pam_minclass:·!!str·452 ····var_password_pam_minclass:·!!str·4
53 ····var_password_pam_minlen:·!!str·1553 ····var_password_pam_minlen:·!!str·15
54 ····var_password_pam_ocredit:·!!str·-154 ····var_password_pam_ocredit:·!!str·-1
55 ····var_password_pam_retry:·!!str·355 ····var_password_pam_retry:·!!str·3
56 ····var_password_pam_ucredit:·!!str·-156 ····var_password_pam_ucredit:·!!str·-1
57 ····var_password_hashing_algorithm_pam:·!!str·yescrypt57 ····var_password_hashing_algorithm_pam:·!!str·yescrypt
1.31 KB
./usr/share/scap-security-guide/tailoring/ol8_stig_delta_tailoring.xml
1.18 KB
./usr/share/scap-security-guide/tailoring/ol8_stig_delta_tailoring.xml
    
Offset 1, 10 lines modifiedOffset 1, 10 lines modified
1 <?xml·version="1.0"·encoding="utf-8"?>1 <?xml·version="1.0"·encoding="utf-8"?>
2 <xccdf-1.2:Tailoring·xmlns:xccdf-1.2="http://checklists.nist.gov/xccdf/1.2"·id="xccdf_content-disa-delta_tailoring_default">2 <xccdf-1.2:Tailoring·xmlns:xccdf-1.2="http://checklists.nist.gov/xccdf/1.2"·id="xccdf_content-disa-delta_tailoring_default">
3 ··<xccdf-1.2:version·time="2025-02-28T20:08:00">1</xccdf-1.2:version>3 ··<xccdf-1.2:version·time="2025-03-01T22:08:00">1</xccdf-1.2:version>
4 ··<xccdf-1.2:Profile·id="xccdf_org.ssgproject.content_profile_stig_delta_tailoring"·extends="xccdf_org.ssgproject.content_profile_stig">4 ··<xccdf-1.2:Profile·id="xccdf_org.ssgproject.content_profile_stig_delta_tailoring"·extends="xccdf_org.ssgproject.content_profile_stig">
5 ····<xccdf-1.2:title·override="true">DISA·STIG·for·Oracle·Linux·8</xccdf-1.2:title>5 ····<xccdf-1.2:title·override="true">DISA·STIG·for·Oracle·Linux·8</xccdf-1.2:title>
6 ····<xccdf-1.2:description·override="true">This·profile·contains·configuration·checks·that·align·to·the6 ····<xccdf-1.2:description·override="true">This·profile·contains·configuration·checks·that·align·to·the
7 DISA·STIG·for·Oracle·Linux·8·V2R3.</xccdf-1.2:description>7 DISA·STIG·for·Oracle·Linux·8·V2R3.</xccdf-1.2:description>
8 ····<xccdf-1.2:select·idref="xccdf_org.ssgproject.content_rule_accounts_have_homedir_login_defs"·selected="false"/>8 ····<xccdf-1.2:select·idref="xccdf_org.ssgproject.content_rule_accounts_have_homedir_login_defs"·selected="false"/>
9 ····<xccdf-1.2:select·idref="xccdf_org.ssgproject.content_rule_accounts_logon_fail_delay"·selected="false"/>9 ····<xccdf-1.2:select·idref="xccdf_org.ssgproject.content_rule_accounts_logon_fail_delay"·selected="false"/>
10 ····<xccdf-1.2:select·idref="xccdf_org.ssgproject.content_rule_accounts_max_concurrent_login_sessions"·selected="false"/>10 ····<xccdf-1.2:select·idref="xccdf_org.ssgproject.content_rule_accounts_max_concurrent_login_sessions"·selected="false"/>
1.12 KB
./usr/share/scap-security-guide/tailoring/rhel8_stig_delta_tailoring.xml
999 B
./usr/share/scap-security-guide/tailoring/rhel8_stig_delta_tailoring.xml
    
Offset 1, 10 lines modifiedOffset 1, 10 lines modified
1 <?xml·version="1.0"·encoding="utf-8"?>1 <?xml·version="1.0"·encoding="utf-8"?>
2 <xccdf-1.2:Tailoring·xmlns:xccdf-1.2="http://checklists.nist.gov/xccdf/1.2"·id="xccdf_content-disa-delta_tailoring_default">2 <xccdf-1.2:Tailoring·xmlns:xccdf-1.2="http://checklists.nist.gov/xccdf/1.2"·id="xccdf_content-disa-delta_tailoring_default">
3 ··<xccdf-1.2:version·time="2025-02-28T20:08:00">1</xccdf-1.2:version>3 ··<xccdf-1.2:version·time="2025-03-01T22:08:00">1</xccdf-1.2:version>
4 ··<xccdf-1.2:Profile·id="xccdf_org.ssgproject.content_profile_stig_delta_tailoring"·extends="xccdf_org.ssgproject.content_profile_stig">4 ··<xccdf-1.2:Profile·id="xccdf_org.ssgproject.content_profile_stig_delta_tailoring"·extends="xccdf_org.ssgproject.content_profile_stig">
5 ····<xccdf-1.2:title·override="true">DISA·STIG·for·Red·Hat·Enterprise·Linux·8</xccdf-1.2:title>5 ····<xccdf-1.2:title·override="true">DISA·STIG·for·Red·Hat·Enterprise·Linux·8</xccdf-1.2:title>
6 ····<xccdf-1.2:description·override="true">This·profile·contains·configuration·checks·that·align·to·the6 ····<xccdf-1.2:description·override="true">This·profile·contains·configuration·checks·that·align·to·the
7 DISA·STIG·for·Red·Hat·Enterprise·Linux·8·V2R2.7 DISA·STIG·for·Red·Hat·Enterprise·Linux·8·V2R2.
  
8 In·addition·to·being·applicable·to·Red·Hat·Enterprise·Linux·8,·this8 In·addition·to·being·applicable·to·Red·Hat·Enterprise·Linux·8,·this
9 configuration·baseline·is·applicable·to·the·operating·system·tier·of9 configuration·baseline·is·applicable·to·the·operating·system·tier·of
1.12 KB
./usr/share/scap-security-guide/tailoring/rhel9_stig_delta_tailoring.xml
999 B
./usr/share/scap-security-guide/tailoring/rhel9_stig_delta_tailoring.xml
    
Offset 1, 10 lines modifiedOffset 1, 10 lines modified
1 <?xml·version="1.0"·encoding="utf-8"?>1 <?xml·version="1.0"·encoding="utf-8"?>
2 <xccdf-1.2:Tailoring·xmlns:xccdf-1.2="http://checklists.nist.gov/xccdf/1.2"·id="xccdf_content-disa-delta_tailoring_default">2 <xccdf-1.2:Tailoring·xmlns:xccdf-1.2="http://checklists.nist.gov/xccdf/1.2"·id="xccdf_content-disa-delta_tailoring_default">
3 ··<xccdf-1.2:version·time="2025-02-28T20:08:00">1</xccdf-1.2:version>3 ··<xccdf-1.2:version·time="2025-03-01T22:08:00">1</xccdf-1.2:version>
4 ··<xccdf-1.2:Profile·id="xccdf_org.ssgproject.content_profile_stig_delta_tailoring"·extends="xccdf_org.ssgproject.content_profile_stig">4 ··<xccdf-1.2:Profile·id="xccdf_org.ssgproject.content_profile_stig_delta_tailoring"·extends="xccdf_org.ssgproject.content_profile_stig">
5 ····<xccdf-1.2:title·override="true">DISA·STIG·for·Red·Hat·Enterprise·Linux·9</xccdf-1.2:title>5 ····<xccdf-1.2:title·override="true">DISA·STIG·for·Red·Hat·Enterprise·Linux·9</xccdf-1.2:title>
6 ····<xccdf-1.2:description·override="true">This·profile·contains·configuration·checks·that·align·to·the6 ····<xccdf-1.2:description·override="true">This·profile·contains·configuration·checks·that·align·to·the
7 DISA·STIG·for·Red·Hat·Enterprise·Linux·9·V2R3.7 DISA·STIG·for·Red·Hat·Enterprise·Linux·9·V2R3.
  
8 In·addition·to·being·applicable·to·Red·Hat·Enterprise·Linux·9,·this8 In·addition·to·being·applicable·to·Red·Hat·Enterprise·Linux·9,·this
9 configuration·baseline·is·applicable·to·the·operating·system·tier·of9 configuration·baseline·is·applicable·to·the·operating·system·tier·of
857 KB
./usr/share/xml/scap/ssg/content/ssg-al2023-ds.xml
857 KB
./usr/share/xml/scap/ssg/content/ssg-al2023-ds.xml
    
Offset 19, 23 lines modifiedOffset 19, 23 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-al2023-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-al2023-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-al2023-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-al2023-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-al2023-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-al2023-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-al2023-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-al2023-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-al2023-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-al2023-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-al2023-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-al2023-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-al2023-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-al2023-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:amazon:amazon_linux:2023">28 ······<cpe-dict:cpe-item·name="cpe:/o:amazon:amazon_linux:2023">
29 ········<cpe-dict:title·xml:lang="en-us">Amazon·Linux·2023</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Amazon·Linux·2023</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml">oval:ssg-installed_OS_is_al2023:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml">oval:ssg-installed_OS_is_al2023:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ····</cpe-dict:cpe-list>32 ····</cpe-dict:cpe-list>
33 ··</ds:component>33 ··</ds:component>
34 ··<ds:component·id="scap_org.open-scap_comp_ssg-al2023-xccdf.xml"·timestamp="2025-02-28T20:08:00">34 ··<ds:component·id="scap_org.open-scap_comp_ssg-al2023-xccdf.xml"·timestamp="2025-03-01T22:08:00">
35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_AL-2023"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_AL-2023"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Amazon·Linux·2023</xccdf-1.2:title>37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Amazon·Linux·2023</xccdf-1.2:title>
38 ······<xccdf-1.2:description>38 ······<xccdf-1.2:description>
39 ········This·guide·presents·a·catalog·of·security-relevant39 ········This·guide·presents·a·catalog·of·security-relevant
40 configuration·settings·for·Amazon·Linux·2023.·It·is·a·rendering·of40 configuration·settings·for·Amazon·Linux·2023.·It·is·a·rendering·of
41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 105, 185 lines modifiedOffset 105, 185 lines modified
105 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>105 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
106 ······<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>106 ······<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
107 ······<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>107 ······<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
108 ······<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>108 ······<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
109 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>109 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
110 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>110 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
111 ······<cpe-lang:platform-specification>111 ······<cpe-lang:platform-specification>
112 ········<cpe-lang:platform·id="not_bootc"> 
113 ··········<cpe-lang:logical-test·operator="AND"·negate="true"> 
114 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-bootc:def:1"/> 
115 ··········</cpe-lang:logical-test> 
116 ········</cpe-lang:platform> 
117 ········<cpe-lang:platform·id="package_pam"> 
118 ··········<cpe-lang:logical-test·operator="AND"·negate="false"> 
119 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/> 
120 ··········</cpe-lang:logical-test> 
121 ········</cpe-lang:platform> 
122 ········<cpe-lang:platform·id="mount_tmp">112 ········<cpe-lang:platform·id="mount_var-tmp">
123 ··········<cpe-lang:logical-test·operator="AND"·negate="false">113 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
124 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_tmp:def:1"/>114 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-tmp:def:1"/>
125 ··········</cpe-lang:logical-test>115 ··········</cpe-lang:logical-test>
126 ········</cpe-lang:platform>116 ········</cpe-lang:platform>
127 ········<cpe-lang:platform·id="package_firewalld_and_package_nftables_and_system_with_kernel">117 ········<cpe-lang:platform·id="ipv6_enabled">
128 ··········<cpe-lang:logical-test·operator="AND"·negate="false">118 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
129 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/> 
130 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>119 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-ipv6_enabled:def:1"/>
131 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
132 ··········</cpe-lang:logical-test>120 ··········</cpe-lang:logical-test>
133 ········</cpe-lang:platform>121 ········</cpe-lang:platform>
134 ········<cpe-lang:platform·id="mount_var-log">122 ········<cpe-lang:platform·id="package_rsyslog">
135 ··········<cpe-lang:logical-test·operator="AND"·negate="false">123 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
136 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-log:def:1"/>124 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>
137 ··········</cpe-lang:logical-test>125 ··········</cpe-lang:logical-test>
138 ········</cpe-lang:platform>126 ········</cpe-lang:platform>
139 ········<cpe-lang:platform·id="package_bash">127 ········<cpe-lang:platform·id="package_bash">
140 ··········<cpe-lang:logical-test·operator="AND"·negate="false">128 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
141 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>129 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>
142 ··········</cpe-lang:logical-test>130 ··········</cpe-lang:logical-test>
143 ········</cpe-lang:platform>131 ········</cpe-lang:platform>
144 ········<cpe-lang:platform·id="grub2">132 ········<cpe-lang:platform·id="package_chrony">
145 ··········<cpe-lang:logical-test·operator="AND"·negate="false">133 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
146 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>134 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
147 ··········</cpe-lang:logical-test>135 ··········</cpe-lang:logical-test>
148 ········</cpe-lang:platform>136 ········</cpe-lang:platform>
149 ········<cpe-lang:platform·id="package_rsyslog">137 ········<cpe-lang:platform·id="package_firewalld">
150 ··········<cpe-lang:logical-test·operator="AND"·negate="false">138 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
151 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>139 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>
152 ··········</cpe-lang:logical-test>140 ··········</cpe-lang:logical-test>
153 ········</cpe-lang:platform>141 ········</cpe-lang:platform>
154 ········<cpe-lang:platform·id="package_systemd">142 ········<cpe-lang:platform·id="package_rsh-server">
155 ··········<cpe-lang:logical-test·operator="AND"·negate="false">143 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
156 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>144 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-package_rsh-server:def:1"/>
157 ··········</cpe-lang:logical-test>145 ··········</cpe-lang:logical-test>
158 ········</cpe-lang:platform>146 ········</cpe-lang:platform>
159 ········<cpe-lang:platform·id="mount_var">147 ········<cpe-lang:platform·id="package_systemd">
160 ··········<cpe-lang:logical-test·operator="AND"·negate="false">148 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
161 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var:def:1"/>149 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>
162 ··········</cpe-lang:logical-test>150 ··········</cpe-lang:logical-test>
163 ········</cpe-lang:platform>151 ········</cpe-lang:platform>
164 ········<cpe-lang:platform·id="service_disabled_iptables_and_service_disabled_ufw_and_system_with_kernel">152 ········<cpe-lang:platform·id="not_bootc_and_not_container">
165 ··········<cpe-lang:logical-test·operator="AND"·negate="false">153 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 154 ············<cpe-lang:logical-test·operator="AND"·negate="true">
166 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_iptables:def:1"/> 
167 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_ufw:def:1"/> 
168 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>155 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-bootc:def:1"/>
 156 ············</cpe-lang:logical-test>
 157 ············<cpe-lang:logical-test·operator="AND"·negate="true">
 158 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_container:def:1"/>
 159 ············</cpe-lang:logical-test>
169 ··········</cpe-lang:logical-test>160 ··········</cpe-lang:logical-test>
170 ········</cpe-lang:platform>161 ········</cpe-lang:platform>
171 ········<cpe-lang:platform·id="package_firewalld">162 ········<cpe-lang:platform·id="mount_tmp">
172 ··········<cpe-lang:logical-test·operator="AND"·negate="false">163 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
173 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>164 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_tmp:def:1"/>
174 ··········</cpe-lang:logical-test>165 ··········</cpe-lang:logical-test>
175 ········</cpe-lang:platform>166 ········</cpe-lang:platform>
176 ········<cpe-lang:platform·id="non-uefi">167 ········<cpe-lang:platform·id="package_nftables">
177 ··········<cpe-lang:logical-test·operator="AND"·negate="false">168 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
178 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_non_uefi:def:1"/>169 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
179 ··········</cpe-lang:logical-test>170 ··········</cpe-lang:logical-test>
180 ········</cpe-lang:platform>171 ········</cpe-lang:platform>
181 ········<cpe-lang:platform·id="mount_var-log-audit">172 ········<cpe-lang:platform·id="package_pam">
182 ··········<cpe-lang:logical-test·operator="AND"·negate="false">173 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
183 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-log-audit:def:1"/>174 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>
184 ··········</cpe-lang:logical-test>175 ··········</cpe-lang:logical-test>
185 ········</cpe-lang:platform>176 ········</cpe-lang:platform>
186 ········<cpe-lang:platform·id="package_postfix">177 ········<cpe-lang:platform·id="service_disabled_iptables_and_service_disabled_ufw_and_system_with_kernel">
187 ··········<cpe-lang:logical-test·operator="AND"·negate="false">178 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 179 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_iptables:def:1"/>
188 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-package_postfix:def:1"/>180 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_ufw:def:1"/>
 181 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
189 ··········</cpe-lang:logical-test>182 ··········</cpe-lang:logical-test>
190 ········</cpe-lang:platform>183 ········</cpe-lang:platform>
191 ········<cpe-lang:platform·id="package_audit">184 ········<cpe-lang:platform·id="package_sudo">
192 ··········<cpe-lang:logical-test·operator="AND"·negate="false">185 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
193 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-package_audit:def:1"/>186 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-package_sudo:def:1"/>
194 ··········</cpe-lang:logical-test>187 ··········</cpe-lang:logical-test>
195 ········</cpe-lang:platform>188 ········</cpe-lang:platform>
196 ········<cpe-lang:platform·id="package_snmpd_and_system_with_kernel">189 ········<cpe-lang:platform·id="package_firewalld_and_package_nftables_and_system_with_kernel">
197 ··········<cpe-lang:logical-test·operator="AND"·negate="false">190 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 191 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>
198 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-package_snmpd:def:1"/>192 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
199 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>193 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
Max diff block lines reached; 863251/877286 bytes (98.40%) of diff not shown.
719 KB
./usr/share/xml/scap/ssg/content/ssg-al2023-ocil.xml
719 KB
./usr/share/xml/scap/ssg/content/ssg-al2023-ocil.xml
Ordering differences only
    
Offset 3, 3055 lines modifiedOffset 3, 3055 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-set_nftables_table_ocil:questionnaire:1"> 
11 ······<ocil:title>Ensure·a·Table·Exists·for·Nftables</ocil:title> 
12 ······<ocil:actions> 
13 ········<ocil:test_action_ref>ocil:ssg-set_nftables_table_action:testaction:1</ocil:test_action_ref> 
14 ······</ocil:actions> 
15 ····</ocil:questionnaire> 
16 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_fsetxattr_ocil:questionnaire:1"> 
17 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·fsetxattr</ocil:title> 
18 ······<ocil:actions> 
19 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_fsetxattr_action:testaction:1</ocil:test_action_ref> 
20 ······</ocil:actions> 
21 ····</ocil:questionnaire> 
22 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_group_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_backup_etc_group_ocil:questionnaire:1">
23 ······<ocil:title>Verify·Permissions·on·group·File</ocil:title>11 ······<ocil:title>Verify·Permissions·on·Backup·group·File</ocil:title>
24 ······<ocil:actions>12 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-file_permissions_etc_group_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-file_permissions_backup_etc_group_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>14 ······</ocil:actions>
27 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-configure_crypto_policy_ocil:questionnaire:1"> 
29 ······<ocil:title>Configure·System·Cryptography·Policy</ocil:title>16 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_send_redirects_ocil:questionnaire:1">
 17 ······<ocil:title>Disable·Kernel·Parameter·for·Sending·ICMP·Redirects·on·all·IPv4·Interfaces</ocil:title>
30 ······<ocil:actions>18 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-configure_crypto_policy_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_send_redirects_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>20 ······</ocil:actions>
33 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-group_unique_id_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_usergroup_modification_group_ocil:questionnaire:1">
35 ······<ocil:title>Ensure·All·Groups·on·the·System·Have·Unique·Group·ID</ocil:title>23 ······<ocil:title>Record·Events·that·Modify·User/Group·Information·-·/etc/group</ocil:title>
36 ······<ocil:actions>24 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-group_unique_id_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-audit_rules_usergroup_modification_group_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>26 ······</ocil:actions>
39 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_fchown_ocil:questionnaire:1"> 
41 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·fchown</ocil:title>28 ····<ocil:questionnaire·id="ocil:ssg-package_rsyslog_installed_ocil:questionnaire:1">
 29 ······<ocil:title>Ensure·rsyslog·is·Installed</ocil:title>
42 ······<ocil:actions>30 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_fchown_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-package_rsyslog_installed_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>32 ······</ocil:actions>
45 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-aide_build_database_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-package_dnsmasq_removed_ocil:questionnaire:1">
47 ······<ocil:title>Build·and·Test·AIDE·Database</ocil:title>35 ······<ocil:title>Uninstall·dnsmasq·Package</ocil:title>
48 ······<ocil:actions>36 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-aide_build_database_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-package_dnsmasq_removed_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>38 ······</ocil:actions>
51 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-partition_for_var_log_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-partition_for_var_log_audit_ocil:questionnaire:1">
53 ······<ocil:title>Ensure·/var/log·Located·On·Separate·Partition</ocil:title>41 ······<ocil:title>Ensure·/var/log/audit·Located·On·Separate·Partition</ocil:title>
54 ······<ocil:actions>42 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-partition_for_var_log_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-partition_for_var_log_audit_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>44 ······</ocil:actions>
57 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-file_owner_user_cfg_ocil:questionnaire:1"> 
59 ······<ocil:title>Verify·/boot/grub2/user.cfg·User·Ownership</ocil:title>46 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_accept_source_route_ocil:questionnaire:1">
 47 ······<ocil:title>Disable·Kernel·Parameter·for·Accepting·Source-Routed·Packets·on·all·IPv4·Interfaces</ocil:title>
60 ······<ocil:actions>48 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-file_owner_user_cfg_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_accept_source_route_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>50 ······</ocil:actions>
63 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-accounts_user_dot_group_ownership_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_execution_chacl_ocil:questionnaire:1">
65 ······<ocil:title>User·Initialization·Files·Must·Be·Group-Owned·By·The·Primary·Group</ocil:title>53 ······<ocil:title>Record·Any·Attempts·to·Run·chacl</ocil:title>
66 ······<ocil:actions>54 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-accounts_user_dot_group_ownership_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-audit_rules_execution_chacl_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>56 ······</ocil:actions>
69 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-package_firewalld_installed_ocil:questionnaire:1"> 
71 ······<ocil:title>Install·firewalld·Package</ocil:title>58 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_file_deletion_events_rename_ocil:questionnaire:1">
 59 ······<ocil:title>Ensure·auditd·Collects·File·Deletion·Events·by·User·-·rename</ocil:title>
72 ······<ocil:actions>60 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-package_firewalld_installed_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-audit_rules_file_deletion_events_rename_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>62 ······</ocil:actions>
75 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-gid_passwd_group_same_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-aide_check_audit_tools_ocil:questionnaire:1">
77 ······<ocil:title>All·GIDs·referenced·in·/etc/passwd·must·be·defined·in·/etc/group</ocil:title>65 ······<ocil:title>Configure·AIDE·to·Verify·the·Audit·Tools</ocil:title>
78 ······<ocil:actions>66 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-gid_passwd_group_same_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-aide_check_audit_tools_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>68 ······</ocil:actions>
81 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-accounts_user_interactive_home_directory_exists_ocil:questionnaire:1"> 
83 ······<ocil:title>All·Interactive·Users·Home·Directories·Must·Exist</ocil:title>70 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_kernel_module_loading_create_ocil:questionnaire:1">
 71 ······<ocil:title>Ensure·auditd·Collects·Information·on·Kernel·Module·Unloading·-·create_module</ocil:title>
84 ······<ocil:actions>72 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-accounts_user_interactive_home_directory_exists_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-audit_rules_kernel_module_loading_create_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>74 ······</ocil:actions>
87 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_fchmod_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_sshd_config_ocil:questionnaire:1">
89 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·fchmod</ocil:title>77 ······<ocil:title>Verify·Permissions·on·SSH·Server·config·file</ocil:title>
90 ······<ocil:actions>78 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_fchmod_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-file_permissions_sshd_config_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>80 ······</ocil:actions>
93 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_root_login_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_log_martians_ocil:questionnaire:1">
95 ······<ocil:title>Disable·SSH·Root·Login</ocil:title>83 ······<ocil:title>Enable·Kernel·Paremeter·to·Log·Martian·Packets·on·all·IPv4·Interfaces·by·Default</ocil:title>
96 ······<ocil:actions>84 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_root_login_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_log_martians_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>86 ······</ocil:actions>
99 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_set_max_life_existing_ocil:questionnaire:1"> 
101 ······<ocil:title>Set·Existing·Passwords·Maximum·Age</ocil:title>88 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_open_ocil:questionnaire:1">
 89 ······<ocil:title>Record·Unsuccessful·Access·Attempts·to·Files·-·open</ocil:title>
102 ······<ocil:actions>90 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-accounts_password_set_max_life_existing_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_open_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>92 ······</ocil:actions>
105 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-accounts_user_dot_user_ownership_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_x11_forwarding_ocil:questionnaire:1">
107 ······<ocil:title>User·Initialization·Files·Must·Be·Owned·By·the·Primary·User</ocil:title>95 ······<ocil:title>Disable·X11·Forwarding</ocil:title>
108 ······<ocil:actions>96 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-accounts_user_dot_user_ownership_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_x11_forwarding_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>98 ······</ocil:actions>
111 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-kernel_module_sctp_disabled_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-package_sudo_installed_ocil:questionnaire:1">
113 ······<ocil:title>Disable·SCTP·Support</ocil:title>101 ······<ocil:title>Install·sudo·Package</ocil:title>
114 ······<ocil:actions>102 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-kernel_module_sctp_disabled_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-package_sudo_installed_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>104 ······</ocil:actions>
117 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_accept_redirects_ocil:questionnaire:1"> 
119 ······<ocil:title>Disable·Kernel·Parameter·for·Accepting·ICMP·Redirects·by·Default·on·IPv4·Interfaces</ocil:title>106 ····<ocil:questionnaire·id="ocil:ssg-mount_option_tmp_nosuid_ocil:questionnaire:1">
 107 ······<ocil:title>Add·nosuid·Option·to·/tmp</ocil:title>
120 ······<ocil:actions>108 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_accept_redirects_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-mount_option_tmp_nosuid_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>110 ······</ocil:actions>
Max diff block lines reached; 723723/735799 bytes (98.36%) of diff not shown.
99.4 KB
./usr/share/xml/scap/ssg/content/ssg-al2023-xccdf.xml
99.3 KB
./usr/share/xml/scap/ssg/content/ssg-al2023-xccdf.xml
Ordering differences only
    
Offset 72, 185 lines modifiedOffset 72, 185 lines modified
72 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>72 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
73 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>73 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
74 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>74 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
75 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>75 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
77 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>77 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
78 ··<cpe-lang:platform-specification>78 ··<cpe-lang:platform-specification>
79 ····<cpe-lang:platform·id="not_bootc"> 
80 ······<cpe-lang:logical-test·operator="AND"·negate="true"> 
81 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-bootc:def:1"/> 
82 ······</cpe-lang:logical-test> 
83 ····</cpe-lang:platform> 
84 ····<cpe-lang:platform·id="package_pam"> 
85 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
86 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/> 
87 ······</cpe-lang:logical-test> 
88 ····</cpe-lang:platform> 
89 ····<cpe-lang:platform·id="mount_tmp">79 ····<cpe-lang:platform·id="mount_var-tmp">
90 ······<cpe-lang:logical-test·operator="AND"·negate="false">80 ······<cpe-lang:logical-test·operator="AND"·negate="false">
91 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_tmp:def:1"/>81 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-tmp:def:1"/>
92 ······</cpe-lang:logical-test>82 ······</cpe-lang:logical-test>
93 ····</cpe-lang:platform>83 ····</cpe-lang:platform>
94 ····<cpe-lang:platform·id="package_firewalld_and_package_nftables_and_system_with_kernel">84 ····<cpe-lang:platform·id="ipv6_enabled">
95 ······<cpe-lang:logical-test·operator="AND"·negate="false">85 ······<cpe-lang:logical-test·operator="AND"·negate="false">
96 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/> 
97 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>86 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-ipv6_enabled:def:1"/>
98 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
99 ······</cpe-lang:logical-test>87 ······</cpe-lang:logical-test>
100 ····</cpe-lang:platform>88 ····</cpe-lang:platform>
101 ····<cpe-lang:platform·id="mount_var-log">89 ····<cpe-lang:platform·id="package_rsyslog">
102 ······<cpe-lang:logical-test·operator="AND"·negate="false">90 ······<cpe-lang:logical-test·operator="AND"·negate="false">
103 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-log:def:1"/>91 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>
104 ······</cpe-lang:logical-test>92 ······</cpe-lang:logical-test>
105 ····</cpe-lang:platform>93 ····</cpe-lang:platform>
106 ····<cpe-lang:platform·id="package_bash">94 ····<cpe-lang:platform·id="package_bash">
107 ······<cpe-lang:logical-test·operator="AND"·negate="false">95 ······<cpe-lang:logical-test·operator="AND"·negate="false">
108 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>96 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>
109 ······</cpe-lang:logical-test>97 ······</cpe-lang:logical-test>
110 ····</cpe-lang:platform>98 ····</cpe-lang:platform>
111 ····<cpe-lang:platform·id="grub2">99 ····<cpe-lang:platform·id="package_chrony">
112 ······<cpe-lang:logical-test·operator="AND"·negate="false">100 ······<cpe-lang:logical-test·operator="AND"·negate="false">
113 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>101 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
114 ······</cpe-lang:logical-test>102 ······</cpe-lang:logical-test>
115 ····</cpe-lang:platform>103 ····</cpe-lang:platform>
116 ····<cpe-lang:platform·id="package_rsyslog">104 ····<cpe-lang:platform·id="package_firewalld">
117 ······<cpe-lang:logical-test·operator="AND"·negate="false">105 ······<cpe-lang:logical-test·operator="AND"·negate="false">
118 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>106 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>
119 ······</cpe-lang:logical-test>107 ······</cpe-lang:logical-test>
120 ····</cpe-lang:platform>108 ····</cpe-lang:platform>
121 ····<cpe-lang:platform·id="package_systemd">109 ····<cpe-lang:platform·id="package_rsh-server">
122 ······<cpe-lang:logical-test·operator="AND"·negate="false">110 ······<cpe-lang:logical-test·operator="AND"·negate="false">
123 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>111 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-package_rsh-server:def:1"/>
124 ······</cpe-lang:logical-test>112 ······</cpe-lang:logical-test>
125 ····</cpe-lang:platform>113 ····</cpe-lang:platform>
126 ····<cpe-lang:platform·id="mount_var">114 ····<cpe-lang:platform·id="package_systemd">
127 ······<cpe-lang:logical-test·operator="AND"·negate="false">115 ······<cpe-lang:logical-test·operator="AND"·negate="false">
128 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var:def:1"/>116 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>
129 ······</cpe-lang:logical-test>117 ······</cpe-lang:logical-test>
130 ····</cpe-lang:platform>118 ····</cpe-lang:platform>
131 ····<cpe-lang:platform·id="service_disabled_iptables_and_service_disabled_ufw_and_system_with_kernel">119 ····<cpe-lang:platform·id="not_bootc_and_not_container">
132 ······<cpe-lang:logical-test·operator="AND"·negate="false">120 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 121 ········<cpe-lang:logical-test·operator="AND"·negate="true">
133 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_iptables:def:1"/> 
134 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_ufw:def:1"/> 
135 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>122 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-bootc:def:1"/>
 123 ········</cpe-lang:logical-test>
 124 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 125 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_container:def:1"/>
 126 ········</cpe-lang:logical-test>
136 ······</cpe-lang:logical-test>127 ······</cpe-lang:logical-test>
137 ····</cpe-lang:platform>128 ····</cpe-lang:platform>
138 ····<cpe-lang:platform·id="package_firewalld">129 ····<cpe-lang:platform·id="mount_tmp">
139 ······<cpe-lang:logical-test·operator="AND"·negate="false">130 ······<cpe-lang:logical-test·operator="AND"·negate="false">
140 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>131 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_tmp:def:1"/>
141 ······</cpe-lang:logical-test>132 ······</cpe-lang:logical-test>
142 ····</cpe-lang:platform>133 ····</cpe-lang:platform>
143 ····<cpe-lang:platform·id="non-uefi">134 ····<cpe-lang:platform·id="package_nftables">
144 ······<cpe-lang:logical-test·operator="AND"·negate="false">135 ······<cpe-lang:logical-test·operator="AND"·negate="false">
145 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_non_uefi:def:1"/>136 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
146 ······</cpe-lang:logical-test>137 ······</cpe-lang:logical-test>
147 ····</cpe-lang:platform>138 ····</cpe-lang:platform>
148 ····<cpe-lang:platform·id="mount_var-log-audit">139 ····<cpe-lang:platform·id="package_pam">
149 ······<cpe-lang:logical-test·operator="AND"·negate="false">140 ······<cpe-lang:logical-test·operator="AND"·negate="false">
150 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-log-audit:def:1"/>141 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>
151 ······</cpe-lang:logical-test>142 ······</cpe-lang:logical-test>
152 ····</cpe-lang:platform>143 ····</cpe-lang:platform>
153 ····<cpe-lang:platform·id="package_postfix">144 ····<cpe-lang:platform·id="service_disabled_iptables_and_service_disabled_ufw_and_system_with_kernel">
154 ······<cpe-lang:logical-test·operator="AND"·negate="false">145 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 146 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_iptables:def:1"/>
155 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-package_postfix:def:1"/>147 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_ufw:def:1"/>
 148 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
156 ······</cpe-lang:logical-test>149 ······</cpe-lang:logical-test>
157 ····</cpe-lang:platform>150 ····</cpe-lang:platform>
158 ····<cpe-lang:platform·id="package_audit">151 ····<cpe-lang:platform·id="package_sudo">
159 ······<cpe-lang:logical-test·operator="AND"·negate="false">152 ······<cpe-lang:logical-test·operator="AND"·negate="false">
160 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-package_audit:def:1"/>153 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-package_sudo:def:1"/>
161 ······</cpe-lang:logical-test>154 ······</cpe-lang:logical-test>
162 ····</cpe-lang:platform>155 ····</cpe-lang:platform>
163 ····<cpe-lang:platform·id="package_snmpd_and_system_with_kernel">156 ····<cpe-lang:platform·id="package_firewalld_and_package_nftables_and_system_with_kernel">
164 ······<cpe-lang:logical-test·operator="AND"·negate="false">157 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 158 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>
165 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-package_snmpd:def:1"/>159 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
166 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>160 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
167 ······</cpe-lang:logical-test>161 ······</cpe-lang:logical-test>
168 ····</cpe-lang:platform>162 ····</cpe-lang:platform>
169 ····<cpe-lang:platform·id="package_sudo">163 ····<cpe-lang:platform·id="mount_var-log-audit">
170 ······<cpe-lang:logical-test·operator="AND"·negate="false">164 ······<cpe-lang:logical-test·operator="AND"·negate="false">
171 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-package_sudo:def:1"/>165 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-log-audit:def:1"/>
172 ······</cpe-lang:logical-test>166 ······</cpe-lang:logical-test>
173 ····</cpe-lang:platform>167 ····</cpe-lang:platform>
174 ····<cpe-lang:platform·id="package_nftables">168 ····<cpe-lang:platform·id="system_with_kernel">
175 ······<cpe-lang:logical-test·operator="AND"·negate="false">169 ······<cpe-lang:logical-test·operator="AND"·negate="false">
176 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>170 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
177 ······</cpe-lang:logical-test>171 ······</cpe-lang:logical-test>
178 ····</cpe-lang:platform>172 ····</cpe-lang:platform>
179 ····<cpe-lang:platform·id="not_aarch64_arch_and_not_s390x_arch">173 ····<cpe-lang:platform·id="not_aarch64_arch_and_not_s390x_arch">
180 ······<cpe-lang:logical-test·operator="AND"·negate="false">174 ······<cpe-lang:logical-test·operator="AND"·negate="false">
181 ········<cpe-lang:logical-test·operator="AND"·negate="true">175 ········<cpe-lang:logical-test·operator="AND"·negate="true">
182 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>176 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
183 ········</cpe-lang:logical-test>177 ········</cpe-lang:logical-test>
184 ········<cpe-lang:logical-test·operator="AND"·negate="true">178 ········<cpe-lang:logical-test·operator="AND"·negate="true">
185 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_s390x:def:1"/>179 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_s390x:def:1"/>
186 ········</cpe-lang:logical-test>180 ········</cpe-lang:logical-test>
187 ······</cpe-lang:logical-test>181 ······</cpe-lang:logical-test>
188 ····</cpe-lang:platform>182 ····</cpe-lang:platform>
189 ····<cpe-lang:platform·id="not_aarch64_arch">183 ····<cpe-lang:platform·id="mount_var">
190 ······<cpe-lang:logical-test·operator="AND"·negate="true">184 ······<cpe-lang:logical-test·operator="AND"·negate="false">
Max diff block lines reached; 87649/101599 bytes (86.27%) of diff not shown.
928 KB
./usr/share/xml/scap/ssg/content/ssg-alinux2-ds.xml
928 KB
./usr/share/xml/scap/ssg/content/ssg-alinux2-ds.xml
    
Offset 19, 23 lines modifiedOffset 19, 23 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-alinux2-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-alinux2-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-alinux2-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-alinux2-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-alinux2-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-alinux2-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-alinux2-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-alinux2-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-alinux2-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-alinux2-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-alinux2-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-alinux2-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-alinux2-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-alinux2-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:alinux:alibaba_cloud_linux:2">28 ······<cpe-dict:cpe-item·name="cpe:/o:alinux:alibaba_cloud_linux:2">
29 ········<cpe-dict:title·xml:lang="en-us">Alibaba·Cloud·Linux·2</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Alibaba·Cloud·Linux·2</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml">oval:ssg-installed_OS_is_alinux2:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml">oval:ssg-installed_OS_is_alinux2:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ····</cpe-dict:cpe-list>32 ····</cpe-dict:cpe-list>
33 ··</ds:component>33 ··</ds:component>
34 ··<ds:component·id="scap_org.open-scap_comp_ssg-alinux2-xccdf.xml"·timestamp="2025-02-28T20:08:00">34 ··<ds:component·id="scap_org.open-scap_comp_ssg-alinux2-xccdf.xml"·timestamp="2025-03-01T22:08:00">
35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_ALINUX-2"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_ALINUX-2"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Alibaba·Cloud·Linux·2</xccdf-1.2:title>37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Alibaba·Cloud·Linux·2</xccdf-1.2:title>
38 ······<xccdf-1.2:description>38 ······<xccdf-1.2:description>
39 ········This·guide·presents·a·catalog·of·security-relevant39 ········This·guide·presents·a·catalog·of·security-relevant
40 configuration·settings·for·Alibaba·Cloud·Linux·2.·It·is·a·rendering·of40 configuration·settings·for·Alibaba·Cloud·Linux·2.·It·is·a·rendering·of
41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 104, 105 lines modifiedOffset 104, 109 lines modified
104 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>104 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
105 ······<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>105 ······<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
106 ······<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>106 ······<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
107 ······<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>107 ······<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
108 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>108 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
109 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>109 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
110 ······<cpe-lang:platform-specification>110 ······<cpe-lang:platform-specification>
111 ········<cpe-lang:platform·id="not_bootc"> 
112 ··········<cpe-lang:logical-test·operator="AND"·negate="true"> 
113 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-bootc:def:1"/> 
114 ··········</cpe-lang:logical-test> 
115 ········</cpe-lang:platform> 
116 ········<cpe-lang:platform·id="machine"> 
117 ··········<cpe-lang:logical-test·operator="AND"·negate="false"> 
118 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/> 
119 ··········</cpe-lang:logical-test> 
120 ········</cpe-lang:platform> 
121 ········<cpe-lang:platform·id="package_pam"> 
122 ··········<cpe-lang:logical-test·operator="AND"·negate="false"> 
123 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/> 
124 ··········</cpe-lang:logical-test> 
125 ········</cpe-lang:platform> 
126 ········<cpe-lang:platform·id="package_autofs_and_system_with_kernel">111 ········<cpe-lang:platform·id="package_autofs_and_system_with_kernel">
127 ··········<cpe-lang:logical-test·operator="AND"·negate="false">112 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
128 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>113 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>
129 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>114 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
130 ··········</cpe-lang:logical-test>115 ··········</cpe-lang:logical-test>
131 ········</cpe-lang:platform>116 ········</cpe-lang:platform>
132 ········<cpe-lang:platform·id="package_iptables">117 ········<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">
133 ··········<cpe-lang:logical-test·operator="AND"·negate="false">118 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 119 ············<cpe-lang:logical-test·operator="AND"·negate="true">
 120 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
 121 ············</cpe-lang:logical-test>
 122 ············<cpe-lang:logical-test·operator="AND"·negate="true">
 123 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
 124 ············</cpe-lang:logical-test>
134 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>125 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
135 ··········</cpe-lang:logical-test>126 ··········</cpe-lang:logical-test>
136 ········</cpe-lang:platform>127 ········</cpe-lang:platform>
137 ········<cpe-lang:platform·id="grub2">128 ········<cpe-lang:platform·id="ipv6_enabled">
138 ··········<cpe-lang:logical-test·operator="AND"·negate="false">129 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 130 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-ipv6_enabled:def:1"/>
 131 ··········</cpe-lang:logical-test>
 132 ········</cpe-lang:platform>
 133 ········<cpe-lang:platform·id="package_gdm">
 134 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
139 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>135 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_gdm:def:1"/>
140 ··········</cpe-lang:logical-test>136 ··········</cpe-lang:logical-test>
141 ········</cpe-lang:platform>137 ········</cpe-lang:platform>
142 ········<cpe-lang:platform·id="package_rsyslog">138 ········<cpe-lang:platform·id="package_rsyslog">
143 ··········<cpe-lang:logical-test·operator="AND"·negate="false">139 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
144 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>140 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>
145 ··········</cpe-lang:logical-test>141 ··········</cpe-lang:logical-test>
146 ········</cpe-lang:platform>142 ········</cpe-lang:platform>
147 ········<cpe-lang:platform·id="package_yum">143 ········<cpe-lang:platform·id="package_chrony_or_package_ntp">
148 ··········<cpe-lang:logical-test·operator="AND"·negate="false">144 ··········<cpe-lang:logical-test·operator="OR"·negate="false">
 145 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
149 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_yum:def:1"/>146 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_ntp:def:1"/>
150 ··········</cpe-lang:logical-test>147 ··········</cpe-lang:logical-test>
151 ········</cpe-lang:platform>148 ········</cpe-lang:platform>
152 ········<cpe-lang:platform·id="package_systemd">149 ········<cpe-lang:platform·id="package_logrotate">
153 ··········<cpe-lang:logical-test·operator="AND"·negate="false">150 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
154 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>151 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_logrotate:def:1"/>
155 ··········</cpe-lang:logical-test>152 ··········</cpe-lang:logical-test>
156 ········</cpe-lang:platform>153 ········</cpe-lang:platform>
157 ········<cpe-lang:platform·id="package_avahi_and_system_with_kernel">154 ········<cpe-lang:platform·id="package_chrony">
158 ··········<cpe-lang:logical-test·operator="AND"·negate="false">155 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
159 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_avahi:def:1"/>156 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
160 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
161 ··········</cpe-lang:logical-test>157 ··········</cpe-lang:logical-test>
162 ········</cpe-lang:platform>158 ········</cpe-lang:platform>
163 ········<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">159 ········<cpe-lang:platform·id="package_ufw_and_system_with_kernel">
164 ··········<cpe-lang:logical-test·operator="AND"·negate="false">160 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
165 ············<cpe-lang:logical-test·operator="AND"·negate="true"> 
166 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/> 
167 ············</cpe-lang:logical-test> 
168 ············<cpe-lang:logical-test·operator="AND"·negate="true"> 
169 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>161 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
170 ············</cpe-lang:logical-test> 
171 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>162 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
172 ··········</cpe-lang:logical-test>163 ··········</cpe-lang:logical-test>
173 ········</cpe-lang:platform>164 ········</cpe-lang:platform>
174 ········<cpe-lang:platform·id="package_firewalld">165 ········<cpe-lang:platform·id="package_firewalld">
175 ··········<cpe-lang:logical-test·operator="AND"·negate="false">166 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
176 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>167 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>
177 ··········</cpe-lang:logical-test>168 ··········</cpe-lang:logical-test>
178 ········</cpe-lang:platform>169 ········</cpe-lang:platform>
179 ········<cpe-lang:platform·id="non-uefi">170 ········<cpe-lang:platform·id="package_systemd">
180 ··········<cpe-lang:logical-test·operator="AND"·negate="false">171 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
181 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_non_uefi:def:1"/>172 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>
182 ··········</cpe-lang:logical-test>173 ··········</cpe-lang:logical-test>
183 ········</cpe-lang:platform>174 ········</cpe-lang:platform>
184 ········<cpe-lang:platform·id="package_postfix">175 ········<cpe-lang:platform·id="not_bootc_and_not_container">
185 ··········<cpe-lang:logical-test·operator="AND"·negate="false">176 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 177 ············<cpe-lang:logical-test·operator="AND"·negate="true">
186 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_postfix:def:1"/>178 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-bootc:def:1"/>
 179 ············</cpe-lang:logical-test>
 180 ············<cpe-lang:logical-test·operator="AND"·negate="true">
 181 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_container:def:1"/>
 182 ············</cpe-lang:logical-test>
187 ··········</cpe-lang:logical-test>183 ··········</cpe-lang:logical-test>
188 ········</cpe-lang:platform>184 ········</cpe-lang:platform>
189 ········<cpe-lang:platform·id="package_audit">185 ········<cpe-lang:platform·id="package_iptables_and_service_disabled_firewalld_and_system_with_kernel">
Max diff block lines reached; 937458/949930 bytes (98.69%) of diff not shown.
860 KB
./usr/share/xml/scap/ssg/content/ssg-alinux2-ocil.xml
859 KB
./usr/share/xml/scap/ssg/content/ssg-alinux2-ocil.xml
Ordering differences only
    
Offset 3, 2935 lines modifiedOffset 3, 2935 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_file_deletion_events_rmdir_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_disk_full_action_stig_ocil:questionnaire:1">
11 ······<ocil:title>Ensure·auditd·Collects·File·Deletion·Events·by·User·-·rmdir</ocil:title>11 ······<ocil:title>Configure·auditd·Disk·Full·Action·when·Disk·Space·Is·Full</ocil:title>
12 ······<ocil:actions>12 ······<ocil:actions>
13 ········<ocil:test_action_ref>ocil:ssg-audit_rules_file_deletion_events_rmdir_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-auditd_data_disk_full_action_stig_action:testaction:1</ocil:test_action_ref>
14 ······</ocil:actions>14 ······</ocil:actions>
15 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
16 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_passwd_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-sshd_set_keepalive_ocil:questionnaire:1">
17 ······<ocil:title>Verify·Group·Who·Owns·passwd·File</ocil:title>17 ······<ocil:title>Set·SSH·Client·Alive·Count·Max</ocil:title>
18 ······<ocil:actions>18 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_passwd_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-sshd_set_keepalive_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>20 ······</ocil:actions>
21 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-file_ownership_library_dirs_ocil:questionnaire:1"> 
23 ······<ocil:title>Verify·that·Shared·Library·Files·Have·Root·Ownership</ocil:title>22 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_default_mmap_min_addr_ocil:questionnaire:1">
 23 ······<ocil:title>Configure·Low·Address·Space·To·Protect·From·User·Allocation</ocil:title>
24 ······<ocil:actions>24 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-file_ownership_library_dirs_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-kernel_config_default_mmap_min_addr_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>26 ······</ocil:actions>
27 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_ocredit_ocil:questionnaire:1"> 
29 ······<ocil:title>Ensure·PAM·Enforces·Password·Requirements·-·Minimum·Special·Characters</ocil:title>28 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_lremovexattr_ocil:questionnaire:1">
 29 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·lremovexattr</ocil:title>
30 ······<ocil:actions>30 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-accounts_password_pam_ocredit_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_lremovexattr_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>32 ······</ocil:actions>
33 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_shared_media_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_arp_filter_ocil:questionnaire:1">
35 ······<ocil:title>Configure·Sending·and·Accepting·Shared·Media·Redirects·for·All·IPv4·Interfaces</ocil:title>35 ······<ocil:title>Configure·ARP·filtering·for·All·IPv4·Interfaces</ocil:title>
36 ······<ocil:actions>36 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_shared_media_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_arp_filter_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>38 ······</ocil:actions>
39 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-file_owner_etc_group_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_user_known_hosts_ocil:questionnaire:1">
41 ······<ocil:title>Verify·User·Who·Owns·group·File</ocil:title>41 ······<ocil:title>Disable·SSH·Support·for·User·Known·Hosts</ocil:title>
42 ······<ocil:actions>42 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-file_owner_etc_group_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_user_known_hosts_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>44 ······</ocil:actions>
45 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-audit_privileged_commands_shutdown_ocil:questionnaire:1">46 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_backup_etc_shadow_ocil:questionnaire:1">
47 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·shutdown</ocil:title>47 ······<ocil:title>Verify·User·Who·Owns·Backup·shadow·File</ocil:title>
48 ······<ocil:actions>48 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-audit_privileged_commands_shutdown_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_backup_etc_shadow_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>50 ······</ocil:actions>
51 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_mac_modification_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-rsyslog_files_ownership_ocil:questionnaire:1">
53 ······<ocil:title>Record·Events·that·Modify·the·System's·Mandatory·Access·Controls</ocil:title>53 ······<ocil:title>Ensure·Log·Files·Are·Owned·By·Appropriate·User</ocil:title>
54 ······<ocil:actions>54 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-audit_rules_mac_modification_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-rsyslog_files_ownership_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>56 ······</ocil:actions>
57 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_randomize_memory_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-account_unique_id_ocil:questionnaire:1">
59 ······<ocil:title>Randomize·the·kernel·memory·sections</ocil:title>59 ······<ocil:title>Ensure·All·Accounts·on·the·System·Have·Unique·User·IDs</ocil:title>
60 ······<ocil:actions>60 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-kernel_config_randomize_memory_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-account_unique_id_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>62 ······</ocil:actions>
63 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_cron_daily_ocil:questionnaire:1"> 
65 ······<ocil:title>Verify·Permissions·on·cron.daily</ocil:title>64 ····<ocil:questionnaire·id="ocil:ssg-service_ntpdate_disabled_ocil:questionnaire:1">
 65 ······<ocil:title>Disable·ntpdate·Service·(ntpdate)</ocil:title>
66 ······<ocil:actions>66 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-file_permissions_cron_daily_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-service_ntpdate_disabled_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>68 ······</ocil:actions>
69 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-file_owner_cron_d_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-file_at_deny_not_exist_ocil:questionnaire:1">
71 ······<ocil:title>Verify·Owner·on·cron.d</ocil:title>71 ······<ocil:title>Ensure·that·/etc/at.deny·does·not·exist</ocil:title>
72 ······<ocil:actions>72 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-file_owner_cron_d_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-file_at_deny_not_exist_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>74 ······</ocil:actions>
75 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_backup_etc_group_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-auditd_local_events_ocil:questionnaire:1">
77 ······<ocil:title>Verify·Group·Who·Owns·Backup·group·File</ocil:title>77 ······<ocil:title>Include·Local·Events·in·Audit·Logs</ocil:title>
78 ······<ocil:actions>78 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_backup_etc_group_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-auditd_local_events_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>80 ······</ocil:actions>
81 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-grub2_spectre_v2_argument_ocil:questionnaire:1"> 
83 ······<ocil:title>Enforce·Spectre·v2·mitigation</ocil:title>82 ····<ocil:questionnaire·id="ocil:ssg-auditd_audispd_syslog_plugin_activated_ocil:questionnaire:1">
 83 ······<ocil:title>Configure·auditd·to·use·audispd's·syslog·plugin</ocil:title>
84 ······<ocil:actions>84 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-grub2_spectre_v2_argument_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-auditd_audispd_syslog_plugin_activated_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>86 ······</ocil:actions>
87 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_crontab_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_cron_monthly_ocil:questionnaire:1">
89 ······<ocil:title>Verify·Group·Who·Owns·Crontab</ocil:title>89 ······<ocil:title>Verify·Permissions·on·cron.monthly</ocil:title>
90 ······<ocil:actions>90 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_crontab_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-file_permissions_cron_monthly_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>92 ······</ocil:actions>
93 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-dir_permissions_binary_dirs_ocil:questionnaire:1"> 
95 ······<ocil:title>Verify·that·System·Executable·Directories·Have·Restrictive·Permissions</ocil:title>94 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_pwhistory_remember_system_auth_ocil:questionnaire:1">
 95 ······<ocil:title>Limit·Password·Reuse:·system-auth</ocil:title>
96 ······<ocil:actions>96 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-dir_permissions_binary_dirs_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-accounts_password_pam_pwhistory_remember_system_auth_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>98 ······</ocil:actions>
99 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-chronyd_run_as_chrony_user_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-file_ownership_sshd_pub_key_ocil:questionnaire:1">
101 ······<ocil:title>Ensure·that·chronyd·is·running·under·chrony·user·account</ocil:title>101 ······<ocil:title>Verify·Ownership·on·SSH·Server·Public·*.pub·Key·Files</ocil:title>
102 ······<ocil:actions>102 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-chronyd_run_as_chrony_user_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-file_ownership_sshd_pub_key_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>104 ······</ocil:actions>
105 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_home_dirs_ocil:questionnaire:1">106 ····<ocil:questionnaire·id="ocil:ssg-service_rsyncd_disabled_ocil:questionnaire:1">
107 ······<ocil:title>Ensure·that·User·Home·Directories·are·not·Group-Writable·or·World-Readable</ocil:title>107 ······<ocil:title>Ensure·rsyncd·service·is·disabled</ocil:title>
108 ······<ocil:actions>108 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-file_permissions_home_dirs_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-service_rsyncd_disabled_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>110 ······</ocil:actions>
111 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-service_chronyd_or_ntpd_enabled_ocil:questionnaire:1"> 
113 ······<ocil:title>Enable·the·NTP·Daemon</ocil:title>112 ····<ocil:questionnaire·id="ocil:ssg-accounts_max_concurrent_login_sessions_ocil:questionnaire:1">
 113 ······<ocil:title>Limit·the·Number·of·Concurrent·Login·Sessions·Allowed·Per·User</ocil:title>
114 ······<ocil:actions>114 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-service_chronyd_or_ntpd_enabled_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-accounts_max_concurrent_login_sessions_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>116 ······</ocil:actions>
117 ····</ocil:questionnaire>117 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_module_sig_key_ocil:questionnaire:1"> 
119 ······<ocil:title>Specify·module·signing·key·to·use</ocil:title>118 ····<ocil:questionnaire·id="ocil:ssg-package_openldap-clients_removed_ocil:questionnaire:1">
 119 ······<ocil:title>Ensure·LDAP·client·is·not·installed</ocil:title>
120 ······<ocil:actions>120 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-kernel_config_module_sig_key_action:testaction:1</ocil:test_action_ref>121 ········<ocil:test_action_ref>ocil:ssg-package_openldap-clients_removed_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>122 ······</ocil:actions>
Max diff block lines reached; 867429/879910 bytes (98.58%) of diff not shown.
25.8 KB
./usr/share/xml/scap/ssg/content/ssg-alinux2-xccdf.xml
25.7 KB
./usr/share/xml/scap/ssg/content/ssg-alinux2-xccdf.xml
Ordering differences only
    
Offset 71, 105 lines modifiedOffset 71, 109 lines modified
71 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>71 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
72 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>72 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
73 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>73 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
74 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>74 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
75 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>75 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
77 ··<cpe-lang:platform-specification>77 ··<cpe-lang:platform-specification>
78 ····<cpe-lang:platform·id="not_bootc"> 
79 ······<cpe-lang:logical-test·operator="AND"·negate="true"> 
80 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-bootc:def:1"/> 
81 ······</cpe-lang:logical-test> 
82 ····</cpe-lang:platform> 
83 ····<cpe-lang:platform·id="machine"> 
84 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
85 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/> 
86 ······</cpe-lang:logical-test> 
87 ····</cpe-lang:platform> 
88 ····<cpe-lang:platform·id="package_pam"> 
89 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
90 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/> 
91 ······</cpe-lang:logical-test> 
92 ····</cpe-lang:platform> 
93 ····<cpe-lang:platform·id="package_autofs_and_system_with_kernel">78 ····<cpe-lang:platform·id="package_autofs_and_system_with_kernel">
94 ······<cpe-lang:logical-test·operator="AND"·negate="false">79 ······<cpe-lang:logical-test·operator="AND"·negate="false">
95 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>80 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>
96 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>81 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
97 ······</cpe-lang:logical-test>82 ······</cpe-lang:logical-test>
98 ····</cpe-lang:platform>83 ····</cpe-lang:platform>
99 ····<cpe-lang:platform·id="package_iptables">84 ····<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">
100 ······<cpe-lang:logical-test·operator="AND"·negate="false">85 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 86 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 87 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
 88 ········</cpe-lang:logical-test>
 89 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 90 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
 91 ········</cpe-lang:logical-test>
101 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>92 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
102 ······</cpe-lang:logical-test>93 ······</cpe-lang:logical-test>
103 ····</cpe-lang:platform>94 ····</cpe-lang:platform>
104 ····<cpe-lang:platform·id="grub2">95 ····<cpe-lang:platform·id="ipv6_enabled">
105 ······<cpe-lang:logical-test·operator="AND"·negate="false">96 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 97 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-ipv6_enabled:def:1"/>
 98 ······</cpe-lang:logical-test>
 99 ····</cpe-lang:platform>
 100 ····<cpe-lang:platform·id="package_gdm">
 101 ······<cpe-lang:logical-test·operator="AND"·negate="false">
106 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>102 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_gdm:def:1"/>
107 ······</cpe-lang:logical-test>103 ······</cpe-lang:logical-test>
108 ····</cpe-lang:platform>104 ····</cpe-lang:platform>
109 ····<cpe-lang:platform·id="package_rsyslog">105 ····<cpe-lang:platform·id="package_rsyslog">
110 ······<cpe-lang:logical-test·operator="AND"·negate="false">106 ······<cpe-lang:logical-test·operator="AND"·negate="false">
111 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>107 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>
112 ······</cpe-lang:logical-test>108 ······</cpe-lang:logical-test>
113 ····</cpe-lang:platform>109 ····</cpe-lang:platform>
114 ····<cpe-lang:platform·id="package_yum">110 ····<cpe-lang:platform·id="package_chrony_or_package_ntp">
115 ······<cpe-lang:logical-test·operator="AND"·negate="false">111 ······<cpe-lang:logical-test·operator="OR"·negate="false">
 112 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
116 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_yum:def:1"/>113 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_ntp:def:1"/>
117 ······</cpe-lang:logical-test>114 ······</cpe-lang:logical-test>
118 ····</cpe-lang:platform>115 ····</cpe-lang:platform>
119 ····<cpe-lang:platform·id="package_systemd">116 ····<cpe-lang:platform·id="package_logrotate">
120 ······<cpe-lang:logical-test·operator="AND"·negate="false">117 ······<cpe-lang:logical-test·operator="AND"·negate="false">
121 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>118 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_logrotate:def:1"/>
122 ······</cpe-lang:logical-test>119 ······</cpe-lang:logical-test>
123 ····</cpe-lang:platform>120 ····</cpe-lang:platform>
124 ····<cpe-lang:platform·id="package_avahi_and_system_with_kernel">121 ····<cpe-lang:platform·id="package_chrony">
125 ······<cpe-lang:logical-test·operator="AND"·negate="false">122 ······<cpe-lang:logical-test·operator="AND"·negate="false">
126 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_avahi:def:1"/>123 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
127 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
128 ······</cpe-lang:logical-test>124 ······</cpe-lang:logical-test>
129 ····</cpe-lang:platform>125 ····</cpe-lang:platform>
130 ····<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">126 ····<cpe-lang:platform·id="package_ufw_and_system_with_kernel">
131 ······<cpe-lang:logical-test·operator="AND"·negate="false">127 ······<cpe-lang:logical-test·operator="AND"·negate="false">
132 ········<cpe-lang:logical-test·operator="AND"·negate="true"> 
133 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/> 
134 ········</cpe-lang:logical-test> 
135 ········<cpe-lang:logical-test·operator="AND"·negate="true"> 
136 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>128 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
137 ········</cpe-lang:logical-test> 
138 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>129 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
139 ······</cpe-lang:logical-test>130 ······</cpe-lang:logical-test>
140 ····</cpe-lang:platform>131 ····</cpe-lang:platform>
141 ····<cpe-lang:platform·id="package_firewalld">132 ····<cpe-lang:platform·id="package_firewalld">
142 ······<cpe-lang:logical-test·operator="AND"·negate="false">133 ······<cpe-lang:logical-test·operator="AND"·negate="false">
143 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>134 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>
144 ······</cpe-lang:logical-test>135 ······</cpe-lang:logical-test>
145 ····</cpe-lang:platform>136 ····</cpe-lang:platform>
146 ····<cpe-lang:platform·id="non-uefi">137 ····<cpe-lang:platform·id="package_systemd">
147 ······<cpe-lang:logical-test·operator="AND"·negate="false">138 ······<cpe-lang:logical-test·operator="AND"·negate="false">
148 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_non_uefi:def:1"/>139 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>
149 ······</cpe-lang:logical-test>140 ······</cpe-lang:logical-test>
150 ····</cpe-lang:platform>141 ····</cpe-lang:platform>
151 ····<cpe-lang:platform·id="package_postfix">142 ····<cpe-lang:platform·id="not_bootc_and_not_container">
152 ······<cpe-lang:logical-test·operator="AND"·negate="false">143 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 144 ········<cpe-lang:logical-test·operator="AND"·negate="true">
153 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_postfix:def:1"/>145 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-bootc:def:1"/>
 146 ········</cpe-lang:logical-test>
 147 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 148 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_container:def:1"/>
 149 ········</cpe-lang:logical-test>
154 ······</cpe-lang:logical-test>150 ······</cpe-lang:logical-test>
155 ····</cpe-lang:platform>151 ····</cpe-lang:platform>
156 ····<cpe-lang:platform·id="package_audit">152 ····<cpe-lang:platform·id="package_iptables_and_service_disabled_firewalld_and_system_with_kernel">
157 ······<cpe-lang:logical-test·operator="AND"·negate="false">153 ······<cpe-lang:logical-test·operator="AND"·negate="false">
158 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_audit:def:1"/>154 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
 155 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_firewalld:def:1"/>
 156 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
159 ······</cpe-lang:logical-test>157 ······</cpe-lang:logical-test>
160 ····</cpe-lang:platform>158 ····</cpe-lang:platform>
 159 ····<cpe-lang:platform·id="aarch64_arch_or_x86_64_arch">
 160 ······<cpe-lang:logical-test·operator="OR"·negate="false">
 161 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
 162 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/>
 163 ······</cpe-lang:logical-test>
 164 ····</cpe-lang:platform>
161 ····<cpe-lang:platform·id="package_logrotate">165 ····<cpe-lang:platform·id="package_pam">
162 ······<cpe-lang:logical-test·operator="AND"·negate="false">166 ······<cpe-lang:logical-test·operator="AND"·negate="false">
163 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_logrotate:def:1"/>167 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>
164 ······</cpe-lang:logical-test>168 ······</cpe-lang:logical-test>
165 ····</cpe-lang:platform>169 ····</cpe-lang:platform>
166 ····<cpe-lang:platform·id="package_ntp">170 ····<cpe-lang:platform·id="machine">
167 ······<cpe-lang:logical-test·operator="AND"·negate="false">171 ······<cpe-lang:logical-test·operator="AND"·negate="false">
168 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_ntp:def:1"/>172 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
169 ······</cpe-lang:logical-test>173 ······</cpe-lang:logical-test>
170 ····</cpe-lang:platform>174 ····</cpe-lang:platform>
171 ····<cpe-lang:platform·id="not_rhcos4-rhel9_and_service_disabled_nftables_and_service_disabled_ufw_and_system_with_kernel">175 ····<cpe-lang:platform·id="not_rhcos4-rhel9_and_service_disabled_nftables_and_service_disabled_ufw_and_system_with_kernel">
172 ······<cpe-lang:logical-test·operator="AND"·negate="false">176 ······<cpe-lang:logical-test·operator="AND"·negate="false">
Max diff block lines reached; 13637/26164 bytes (52.12%) of diff not shown.
923 KB
./usr/share/xml/scap/ssg/content/ssg-alinux3-ds.xml
923 KB
./usr/share/xml/scap/ssg/content/ssg-alinux3-ds.xml
    
Offset 19, 23 lines modifiedOffset 19, 23 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-alinux3-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-alinux3-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-alinux3-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-alinux3-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-alinux3-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-alinux3-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-alinux3-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-alinux3-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-alinux3-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-alinux3-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-alinux3-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-alinux3-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-alinux3-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-alinux3-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:alinux:alibaba_cloud_linux:3">28 ······<cpe-dict:cpe-item·name="cpe:/o:alinux:alibaba_cloud_linux:3">
29 ········<cpe-dict:title·xml:lang="en-us">Alibaba·Cloud·Linux·3</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Alibaba·Cloud·Linux·3</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml">oval:ssg-installed_OS_is_alinux3:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml">oval:ssg-installed_OS_is_alinux3:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ····</cpe-dict:cpe-list>32 ····</cpe-dict:cpe-list>
33 ··</ds:component>33 ··</ds:component>
34 ··<ds:component·id="scap_org.open-scap_comp_ssg-alinux3-xccdf.xml"·timestamp="2025-02-28T20:08:00">34 ··<ds:component·id="scap_org.open-scap_comp_ssg-alinux3-xccdf.xml"·timestamp="2025-03-01T22:08:00">
35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_ALINUX-3"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_ALINUX-3"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Alibaba·Cloud·Linux·3</xccdf-1.2:title>37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Alibaba·Cloud·Linux·3</xccdf-1.2:title>
38 ······<xccdf-1.2:description>38 ······<xccdf-1.2:description>
39 ········This·guide·presents·a·catalog·of·security-relevant39 ········This·guide·presents·a·catalog·of·security-relevant
40 configuration·settings·for·Alibaba·Cloud·Linux·3.·It·is·a·rendering·of40 configuration·settings·for·Alibaba·Cloud·Linux·3.·It·is·a·rendering·of
41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 104, 219 lines modifiedOffset 104, 219 lines modified
104 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>104 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
105 ······<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>105 ······<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
106 ······<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>106 ······<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
107 ······<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>107 ······<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
108 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>108 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
109 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>109 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
110 ······<cpe-lang:platform-specification>110 ······<cpe-lang:platform-specification>
 111 ········<cpe-lang:platform·id="package_autofs_and_system_with_kernel">
111 ········<cpe-lang:platform·id="not_bootc"> 
112 ··········<cpe-lang:logical-test·operator="AND"·negate="true"> 
113 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-bootc:def:1"/> 
114 ··········</cpe-lang:logical-test> 
115 ········</cpe-lang:platform> 
116 ········<cpe-lang:platform·id="machine"> 
117 ··········<cpe-lang:logical-test·operator="AND"·negate="false">112 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 113 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>
118 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>114 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
119 ··········</cpe-lang:logical-test>115 ··········</cpe-lang:logical-test>
120 ········</cpe-lang:platform>116 ········</cpe-lang:platform>
121 ········<cpe-lang:platform·id="package_pam">117 ········<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">
122 ··········<cpe-lang:logical-test·operator="AND"·negate="false">118 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 119 ············<cpe-lang:logical-test·operator="AND"·negate="true">
 120 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
 121 ············</cpe-lang:logical-test>
 122 ············<cpe-lang:logical-test·operator="AND"·negate="true">
 123 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
 124 ············</cpe-lang:logical-test>
123 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>125 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
124 ··········</cpe-lang:logical-test>126 ··········</cpe-lang:logical-test>
125 ········</cpe-lang:platform>127 ········</cpe-lang:platform>
126 ········<cpe-lang:platform·id="package_autofs_and_system_with_kernel">128 ········<cpe-lang:platform·id="ipv6_enabled">
127 ··········<cpe-lang:logical-test·operator="AND"·negate="false">129 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
128 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>130 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-ipv6_enabled:def:1"/>
129 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
130 ··········</cpe-lang:logical-test>131 ··········</cpe-lang:logical-test>
131 ········</cpe-lang:platform>132 ········</cpe-lang:platform>
132 ········<cpe-lang:platform·id="package_firewalld_and_package_nftables_and_system_with_kernel">133 ········<cpe-lang:platform·id="package_gdm">
133 ··········<cpe-lang:logical-test·operator="AND"·negate="false">134 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
134 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>135 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_gdm:def:1"/>
135 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/> 
136 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
137 ··········</cpe-lang:logical-test>136 ··········</cpe-lang:logical-test>
138 ········</cpe-lang:platform>137 ········</cpe-lang:platform>
139 ········<cpe-lang:platform·id="package_iptables">138 ········<cpe-lang:platform·id="package_rsyslog">
140 ··········<cpe-lang:logical-test·operator="AND"·negate="false">139 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
141 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>140 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>
142 ··········</cpe-lang:logical-test>141 ··········</cpe-lang:logical-test>
143 ········</cpe-lang:platform>142 ········</cpe-lang:platform>
144 ········<cpe-lang:platform·id="grub2">143 ········<cpe-lang:platform·id="package_logrotate">
145 ··········<cpe-lang:logical-test·operator="AND"·negate="false">144 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
146 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>145 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_logrotate:def:1"/>
147 ··········</cpe-lang:logical-test>146 ··········</cpe-lang:logical-test>
148 ········</cpe-lang:platform>147 ········</cpe-lang:platform>
149 ········<cpe-lang:platform·id="wifi-iface">148 ········<cpe-lang:platform·id="package_chrony">
150 ··········<cpe-lang:logical-test·operator="AND"·negate="false">149 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
151 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_wifi_interface:def:1"/>150 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
152 ··········</cpe-lang:logical-test>151 ··········</cpe-lang:logical-test>
153 ········</cpe-lang:platform>152 ········</cpe-lang:platform>
154 ········<cpe-lang:platform·id="package_rsyslog">153 ········<cpe-lang:platform·id="package_ufw_and_system_with_kernel">
155 ··········<cpe-lang:logical-test·operator="AND"·negate="false">154 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
156 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>155 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
 156 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
157 ··········</cpe-lang:logical-test>157 ··········</cpe-lang:logical-test>
158 ········</cpe-lang:platform>158 ········</cpe-lang:platform>
159 ········<cpe-lang:platform·id="package_yum">159 ········<cpe-lang:platform·id="package_firewalld">
160 ··········<cpe-lang:logical-test·operator="AND"·negate="false">160 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
161 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_yum:def:1"/>161 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>
162 ··········</cpe-lang:logical-test>162 ··········</cpe-lang:logical-test>
163 ········</cpe-lang:platform>163 ········</cpe-lang:platform>
164 ········<cpe-lang:platform·id="package_systemd">164 ········<cpe-lang:platform·id="package_systemd">
165 ··········<cpe-lang:logical-test·operator="AND"·negate="false">165 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
166 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>166 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>
167 ··········</cpe-lang:logical-test>167 ··········</cpe-lang:logical-test>
168 ········</cpe-lang:platform>168 ········</cpe-lang:platform>
 169 ········<cpe-lang:platform·id="not_bootc_and_not_container">
169 ········<cpe-lang:platform·id="package_avahi_and_system_with_kernel"> 
170 ··········<cpe-lang:logical-test·operator="AND"·negate="false"> 
171 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_avahi:def:1"/> 
172 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
173 ··········</cpe-lang:logical-test> 
174 ········</cpe-lang:platform> 
175 ········<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables"> 
176 ··········<cpe-lang:logical-test·operator="AND"·negate="false">170 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
177 ············<cpe-lang:logical-test·operator="AND"·negate="true">171 ············<cpe-lang:logical-test·operator="AND"·negate="true">
178 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>172 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-bootc:def:1"/>
179 ············</cpe-lang:logical-test>173 ············</cpe-lang:logical-test>
180 ············<cpe-lang:logical-test·operator="AND"·negate="true">174 ············<cpe-lang:logical-test·operator="AND"·negate="true">
181 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>175 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_container:def:1"/>
182 ············</cpe-lang:logical-test>176 ············</cpe-lang:logical-test>
183 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/> 
184 ··········</cpe-lang:logical-test> 
185 ········</cpe-lang:platform> 
186 ········<cpe-lang:platform·id="package_firewalld"> 
187 ··········<cpe-lang:logical-test·operator="AND"·negate="false"> 
188 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/> 
189 ··········</cpe-lang:logical-test>177 ··········</cpe-lang:logical-test>
190 ········</cpe-lang:platform>178 ········</cpe-lang:platform>
191 ········<cpe-lang:platform·id="non-uefi">179 ········<cpe-lang:platform·id="package_iptables_and_service_disabled_firewalld_and_system_with_kernel">
192 ··········<cpe-lang:logical-test·operator="AND"·negate="false">180 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 181 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
 182 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_firewalld:def:1"/>
193 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_non_uefi:def:1"/>183 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
194 ··········</cpe-lang:logical-test>184 ··········</cpe-lang:logical-test>
Max diff block lines reached; 931651/945313 bytes (98.55%) of diff not shown.
854 KB
./usr/share/xml/scap/ssg/content/ssg-alinux3-ocil.xml
854 KB
./usr/share/xml/scap/ssg/content/ssg-alinux3-ocil.xml
Ordering differences only
    
Offset 3, 4387 lines modifiedOffset 3, 4387 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-file_owner_etc_passwd_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_x11_forwarding_ocil:questionnaire:1">
11 ······<ocil:title>Verify·User·Who·Owns·passwd·File</ocil:title>11 ······<ocil:title>Disable·X11·Forwarding</ocil:title>
12 ······<ocil:actions>12 ······<ocil:actions>
13 ········<ocil:test_action_ref>ocil:ssg-file_owner_etc_passwd_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_x11_forwarding_action:testaction:1</ocil:test_action_ref>
14 ······</ocil:actions>14 ······</ocil:actions>
15 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
16 ····<ocil:questionnaire·id="ocil:ssg-grub2_l1tf_argument_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-kernel_module_uvcvideo_disabled_ocil:questionnaire:1">
17 ······<ocil:title>Configure·L1·Terminal·Fault·mitigations</ocil:title>17 ······<ocil:title>Disable·the·uvcvideo·module</ocil:title>
18 ······<ocil:actions>18 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-grub2_l1tf_argument_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-kernel_module_uvcvideo_disabled_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>20 ······</ocil:actions>
21 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_acpi_custom_method_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-auditd_log_format_ocil:questionnaire:1">
23 ······<ocil:title>Do·not·allow·ACPI·methods·to·be·inserted/replaced·at·run·time</ocil:title>23 ······<ocil:title>Resolve·information·before·writing·to·audit·logs</ocil:title>
24 ······<ocil:actions>24 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-kernel_config_acpi_custom_method_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-auditd_log_format_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>26 ······</ocil:actions>
27 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-sudo_remove_no_authenticate_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_hibernation_ocil:questionnaire:1">
29 ······<ocil:title>Ensure·Users·Re-Authenticate·for·Privilege·Escalation·-·sudo·!authenticate</ocil:title>29 ······<ocil:title>Disable·hibernation</ocil:title>
30 ······<ocil:actions>30 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-sudo_remove_no_authenticate_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-kernel_config_hibernation_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>32 ······</ocil:actions>
33 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_usergroup_modification_passwd_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-package_audit_installed_ocil:questionnaire:1">
35 ······<ocil:title>Record·Events·that·Modify·User/Group·Information·-·/etc/passwd</ocil:title>35 ······<ocil:title>Ensure·the·audit·Subsystem·is·Installed</ocil:title>
36 ······<ocil:actions>36 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-audit_rules_usergroup_modification_passwd_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-package_audit_installed_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>38 ······</ocil:actions>
39 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_pwhistory_remember_system_auth_ocil:questionnaire:1"> 
41 ······<ocil:title>Limit·Password·Reuse:·system-auth</ocil:title>40 ····<ocil:questionnaire·id="ocil:ssg-package_firewalld_installed_ocil:questionnaire:1">
 41 ······<ocil:title>Install·firewalld·Package</ocil:title>
42 ······<ocil:actions>42 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-accounts_password_pam_pwhistory_remember_system_auth_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-package_firewalld_installed_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>44 ······</ocil:actions>
45 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_usergroup_modification_ocil:questionnaire:1">46 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_lremovexattr_ocil:questionnaire:1">
47 ······<ocil:title>Record·Events·that·Modify·User/Group·Information</ocil:title>47 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·lremovexattr</ocil:title>
48 ······<ocil:actions>48 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-audit_rules_usergroup_modification_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_lremovexattr_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>50 ······</ocil:actions>
51 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-file_owner_cron_weekly_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-service_ufw_enabled_ocil:questionnaire:1">
53 ······<ocil:title>Verify·Owner·on·cron.weekly</ocil:title>53 ······<ocil:title>Verify·ufw·Enabled</ocil:title>
54 ······<ocil:actions>54 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-file_owner_cron_weekly_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-service_ufw_enabled_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>56 ······</ocil:actions>
57 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-file_groupownership_audit_configuration_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_cron_monthly_ocil:questionnaire:1">
59 ······<ocil:title>Audit·Configuration·Files·Must·Be·Owned·By·Group·root</ocil:title>59 ······<ocil:title>Verify·Group·Who·Owns·cron.monthly</ocil:title>
60 ······<ocil:actions>60 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-file_groupownership_audit_configuration_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_cron_monthly_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>62 ······</ocil:actions>
63 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_fremovexattr_ocil:questionnaire:1"> 
65 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·fremovexattr</ocil:title>64 ····<ocil:questionnaire·id="ocil:ssg-service_rsyncd_disabled_ocil:questionnaire:1">
 65 ······<ocil:title>Ensure·rsyncd·service·is·disabled</ocil:title>
66 ······<ocil:actions>66 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_fremovexattr_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-service_rsyncd_disabled_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>68 ······</ocil:actions>
69 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_ungroupowned_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_chown_ocil:questionnaire:1">
71 ······<ocil:title>Ensure·All·Files·Are·Owned·by·a·Group</ocil:title>71 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·chown</ocil:title>
72 ······<ocil:actions>72 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-file_permissions_ungroupowned_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_chown_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>74 ······</ocil:actions>
75 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_security_writable_hooks_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-sysctl_kernel_kptr_restrict_ocil:questionnaire:1">
77 ······<ocil:title>Disable·mutable·hooks</ocil:title>77 ······<ocil:title>Restrict·Exposed·Kernel·Pointer·Addresses·Access</ocil:title>
78 ······<ocil:actions>78 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-kernel_config_security_writable_hooks_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-sysctl_kernel_kptr_restrict_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>80 ······</ocil:actions>
81 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_crontab_ocil:questionnaire:1"> 
83 ······<ocil:title>Verify·Group·Who·Owns·Crontab</ocil:title>82 ····<ocil:questionnaire·id="ocil:ssg-sshd_set_max_auth_tries_ocil:questionnaire:1">
 83 ······<ocil:title>Set·SSH·authentication·attempt·limit</ocil:title>
84 ······<ocil:actions>84 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_crontab_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-sshd_set_max_auth_tries_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>86 ······</ocil:actions>
87 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_openat_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-auditd_overflow_action_ocil:questionnaire:1">
89 ······<ocil:title>Record·Unsuccessful·Access·Attempts·to·Files·-·openat</ocil:title>89 ······<ocil:title>Appropriate·Action·Must·be·Setup·When·the·Internal·Audit·Event·Queue·is·Full</ocil:title>
90 ······<ocil:actions>90 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_openat_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-auditd_overflow_action_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>92 ······</ocil:actions>
93 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-package_xinetd_removed_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-sshd_enable_pam_ocil:questionnaire:1">
95 ······<ocil:title>Uninstall·xinetd·Package</ocil:title>95 ······<ocil:title>Enable·PAM</ocil:title>
96 ······<ocil:actions>96 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-package_xinetd_removed_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-sshd_enable_pam_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>98 ······</ocil:actions>
99 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-auditd_audispd_syslog_plugin_activated_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-sshd_set_idle_timeout_ocil:questionnaire:1">
101 ······<ocil:title>Configure·auditd·to·use·audispd's·syslog·plugin</ocil:title>101 ······<ocil:title>Set·SSH·Client·Alive·Interval</ocil:title>
102 ······<ocil:actions>102 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-auditd_audispd_syslog_plugin_activated_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-sshd_set_idle_timeout_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>104 ······</ocil:actions>
105 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-kernel_module_ipv6_option_disabled_ocil:questionnaire:1">106 ····<ocil:questionnaire·id="ocil:ssg-file_owner_cron_monthly_ocil:questionnaire:1">
107 ······<ocil:title>Disable·IPv6·Networking·Support·Automatic·Loading</ocil:title>107 ······<ocil:title>Verify·Owner·on·cron.monthly</ocil:title>
108 ······<ocil:actions>108 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-kernel_module_ipv6_option_disabled_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-file_owner_cron_monthly_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>110 ······</ocil:actions>
111 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_chmod_ocil:questionnaire:1"> 
113 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·chmod</ocil:title>112 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_devkmem_ocil:questionnaire:1">
 113 ······<ocil:title>Disable·/dev/kmem·virtual·device·support</ocil:title>
114 ······<ocil:actions>114 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_chmod_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-kernel_config_devkmem_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>116 ······</ocil:actions>
117 ····</ocil:questionnaire>117 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-package_telnet_removed_ocil:questionnaire:1"> 
119 ······<ocil:title>Remove·telnet·Clients</ocil:title>118 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_disk_error_action_stig_ocil:questionnaire:1">
 119 ······<ocil:title>Configure·auditd·Disk·Error·Action·on·Disk·Error</ocil:title>
120 ······<ocil:actions>120 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-package_telnet_removed_action:testaction:1</ocil:test_action_ref>121 ········<ocil:test_action_ref>ocil:ssg-auditd_data_disk_error_action_stig_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>122 ······</ocil:actions>
123 ····</ocil:questionnaire>123 ····</ocil:questionnaire>
124 ····<ocil:questionnaire·id="ocil:ssg-package_postfix_installed_ocil:questionnaire:1"> 
Max diff block lines reached; 861934/874639 bytes (98.55%) of diff not shown.
25.7 KB
./usr/share/xml/scap/ssg/content/ssg-alinux3-xccdf.xml
25.6 KB
./usr/share/xml/scap/ssg/content/ssg-alinux3-xccdf.xml
Ordering differences only
    
Offset 71, 219 lines modifiedOffset 71, 219 lines modified
71 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>71 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
72 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>72 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
73 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>73 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
74 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>74 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
75 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>75 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
77 ··<cpe-lang:platform-specification>77 ··<cpe-lang:platform-specification>
 78 ····<cpe-lang:platform·id="package_autofs_and_system_with_kernel">
78 ····<cpe-lang:platform·id="not_bootc"> 
79 ······<cpe-lang:logical-test·operator="AND"·negate="true"> 
80 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-bootc:def:1"/> 
81 ······</cpe-lang:logical-test> 
82 ····</cpe-lang:platform> 
83 ····<cpe-lang:platform·id="machine"> 
84 ······<cpe-lang:logical-test·operator="AND"·negate="false">79 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 80 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>
85 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>81 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
86 ······</cpe-lang:logical-test>82 ······</cpe-lang:logical-test>
87 ····</cpe-lang:platform>83 ····</cpe-lang:platform>
88 ····<cpe-lang:platform·id="package_pam">84 ····<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">
89 ······<cpe-lang:logical-test·operator="AND"·negate="false">85 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 86 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 87 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
 88 ········</cpe-lang:logical-test>
 89 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 90 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
 91 ········</cpe-lang:logical-test>
90 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>92 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
91 ······</cpe-lang:logical-test>93 ······</cpe-lang:logical-test>
92 ····</cpe-lang:platform>94 ····</cpe-lang:platform>
93 ····<cpe-lang:platform·id="package_autofs_and_system_with_kernel">95 ····<cpe-lang:platform·id="ipv6_enabled">
94 ······<cpe-lang:logical-test·operator="AND"·negate="false">96 ······<cpe-lang:logical-test·operator="AND"·negate="false">
95 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>97 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-ipv6_enabled:def:1"/>
96 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
97 ······</cpe-lang:logical-test>98 ······</cpe-lang:logical-test>
98 ····</cpe-lang:platform>99 ····</cpe-lang:platform>
99 ····<cpe-lang:platform·id="package_firewalld_and_package_nftables_and_system_with_kernel">100 ····<cpe-lang:platform·id="package_gdm">
100 ······<cpe-lang:logical-test·operator="AND"·negate="false">101 ······<cpe-lang:logical-test·operator="AND"·negate="false">
101 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>102 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_gdm:def:1"/>
102 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/> 
103 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
104 ······</cpe-lang:logical-test>103 ······</cpe-lang:logical-test>
105 ····</cpe-lang:platform>104 ····</cpe-lang:platform>
106 ····<cpe-lang:platform·id="package_iptables">105 ····<cpe-lang:platform·id="package_rsyslog">
107 ······<cpe-lang:logical-test·operator="AND"·negate="false">106 ······<cpe-lang:logical-test·operator="AND"·negate="false">
108 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>107 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>
109 ······</cpe-lang:logical-test>108 ······</cpe-lang:logical-test>
110 ····</cpe-lang:platform>109 ····</cpe-lang:platform>
111 ····<cpe-lang:platform·id="grub2">110 ····<cpe-lang:platform·id="package_logrotate">
112 ······<cpe-lang:logical-test·operator="AND"·negate="false">111 ······<cpe-lang:logical-test·operator="AND"·negate="false">
113 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>112 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_logrotate:def:1"/>
114 ······</cpe-lang:logical-test>113 ······</cpe-lang:logical-test>
115 ····</cpe-lang:platform>114 ····</cpe-lang:platform>
116 ····<cpe-lang:platform·id="wifi-iface">115 ····<cpe-lang:platform·id="package_chrony">
117 ······<cpe-lang:logical-test·operator="AND"·negate="false">116 ······<cpe-lang:logical-test·operator="AND"·negate="false">
118 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_wifi_interface:def:1"/>117 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
119 ······</cpe-lang:logical-test>118 ······</cpe-lang:logical-test>
120 ····</cpe-lang:platform>119 ····</cpe-lang:platform>
121 ····<cpe-lang:platform·id="package_rsyslog">120 ····<cpe-lang:platform·id="package_ufw_and_system_with_kernel">
122 ······<cpe-lang:logical-test·operator="AND"·negate="false">121 ······<cpe-lang:logical-test·operator="AND"·negate="false">
123 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>122 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
 123 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
124 ······</cpe-lang:logical-test>124 ······</cpe-lang:logical-test>
125 ····</cpe-lang:platform>125 ····</cpe-lang:platform>
126 ····<cpe-lang:platform·id="package_yum">126 ····<cpe-lang:platform·id="package_firewalld">
127 ······<cpe-lang:logical-test·operator="AND"·negate="false">127 ······<cpe-lang:logical-test·operator="AND"·negate="false">
128 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_yum:def:1"/>128 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>
129 ······</cpe-lang:logical-test>129 ······</cpe-lang:logical-test>
130 ····</cpe-lang:platform>130 ····</cpe-lang:platform>
131 ····<cpe-lang:platform·id="package_systemd">131 ····<cpe-lang:platform·id="package_systemd">
132 ······<cpe-lang:logical-test·operator="AND"·negate="false">132 ······<cpe-lang:logical-test·operator="AND"·negate="false">
133 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>133 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>
134 ······</cpe-lang:logical-test>134 ······</cpe-lang:logical-test>
135 ····</cpe-lang:platform>135 ····</cpe-lang:platform>
 136 ····<cpe-lang:platform·id="not_bootc_and_not_container">
136 ····<cpe-lang:platform·id="package_avahi_and_system_with_kernel"> 
137 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
138 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_avahi:def:1"/> 
139 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
140 ······</cpe-lang:logical-test> 
141 ····</cpe-lang:platform> 
142 ····<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables"> 
143 ······<cpe-lang:logical-test·operator="AND"·negate="false">137 ······<cpe-lang:logical-test·operator="AND"·negate="false">
144 ········<cpe-lang:logical-test·operator="AND"·negate="true">138 ········<cpe-lang:logical-test·operator="AND"·negate="true">
145 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>139 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-bootc:def:1"/>
146 ········</cpe-lang:logical-test>140 ········</cpe-lang:logical-test>
147 ········<cpe-lang:logical-test·operator="AND"·negate="true">141 ········<cpe-lang:logical-test·operator="AND"·negate="true">
148 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>142 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_container:def:1"/>
149 ········</cpe-lang:logical-test>143 ········</cpe-lang:logical-test>
150 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/> 
151 ······</cpe-lang:logical-test> 
152 ····</cpe-lang:platform> 
153 ····<cpe-lang:platform·id="package_firewalld"> 
154 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
155 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/> 
156 ······</cpe-lang:logical-test>144 ······</cpe-lang:logical-test>
157 ····</cpe-lang:platform>145 ····</cpe-lang:platform>
158 ····<cpe-lang:platform·id="non-uefi">146 ····<cpe-lang:platform·id="package_iptables_and_service_disabled_firewalld_and_system_with_kernel">
159 ······<cpe-lang:logical-test·operator="AND"·negate="false">147 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 148 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
 149 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_firewalld:def:1"/>
160 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_non_uefi:def:1"/>150 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
161 ······</cpe-lang:logical-test>151 ······</cpe-lang:logical-test>
162 ····</cpe-lang:platform>152 ····</cpe-lang:platform>
163 ····<cpe-lang:platform·id="package_postfix">153 ····<cpe-lang:platform·id="aarch64_arch_or_x86_64_arch">
164 ······<cpe-lang:logical-test·operator="AND"·negate="false">154 ······<cpe-lang:logical-test·operator="OR"·negate="false">
 155 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
165 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_postfix:def:1"/>156 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/>
166 ······</cpe-lang:logical-test>157 ······</cpe-lang:logical-test>
167 ····</cpe-lang:platform>158 ····</cpe-lang:platform>
168 ····<cpe-lang:platform·id="package_audit">159 ····<cpe-lang:platform·id="package_pam">
169 ······<cpe-lang:logical-test·operator="AND"·negate="false">160 ······<cpe-lang:logical-test·operator="AND"·negate="false">
170 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_audit:def:1"/>161 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>
171 ······</cpe-lang:logical-test>162 ······</cpe-lang:logical-test>
172 ····</cpe-lang:platform>163 ····</cpe-lang:platform>
173 ····<cpe-lang:platform·id="package_logrotate">164 ····<cpe-lang:platform·id="machine">
174 ······<cpe-lang:logical-test·operator="AND"·negate="false">165 ······<cpe-lang:logical-test·operator="AND"·negate="false">
175 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_logrotate:def:1"/>166 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
176 ······</cpe-lang:logical-test>167 ······</cpe-lang:logical-test>
177 ····</cpe-lang:platform>168 ····</cpe-lang:platform>
178 ····<cpe-lang:platform·id="package_sudo">169 ····<cpe-lang:platform·id="package_sudo">
179 ······<cpe-lang:logical-test·operator="AND"·negate="false">170 ······<cpe-lang:logical-test·operator="AND"·negate="false">
180 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_sudo:def:1"/>171 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_sudo:def:1"/>
181 ······</cpe-lang:logical-test>172 ······</cpe-lang:logical-test>
182 ····</cpe-lang:platform>173 ····</cpe-lang:platform>
 174 ····<cpe-lang:platform·id="package_firewalld_and_package_nftables_and_system_with_kernel">
183 ····<cpe-lang:platform·id="aarch64_arch_or_x86_64_arch"> 
Max diff block lines reached; 12046/26118 bytes (46.12%) of diff not shown.
1.15 MB
./usr/share/xml/scap/ssg/content/ssg-almalinux9-ds.xml
1.15 MB
./usr/share/xml/scap/ssg/content/ssg-almalinux9-ds.xml
    
Offset 21, 23 lines modifiedOffset 21, 23 lines modified
21 ····<ds:checks>21 ····<ds:checks>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-almalinux9-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-almalinux9-oval.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-almalinux9-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-almalinux9-oval.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-almalinux9-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-almalinux9-ocil.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-almalinux9-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-almalinux9-ocil.xml"/>
24 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-almalinux9-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-almalinux9-cpe-oval.xml"/>24 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-almalinux9-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-almalinux9-cpe-oval.xml"/>
25 ······<ds:component-ref·id="scap_org.open-scap_cref_oval-org.almalinux.alsa-9.xml.bz2"·xlink:href="https://security.almalinux.org/oval/org.almalinux.alsa-9.xml.bz2"/>25 ······<ds:component-ref·id="scap_org.open-scap_cref_oval-org.almalinux.alsa-9.xml.bz2"·xlink:href="https://security.almalinux.org/oval/org.almalinux.alsa-9.xml.bz2"/>
26 ····</ds:checks>26 ····</ds:checks>
27 ··</ds:data-stream>27 ··</ds:data-stream>
28 ··<ds:component·id="scap_org.open-scap_comp_ssg-almalinux9-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">28 ··<ds:component·id="scap_org.open-scap_comp_ssg-almalinux9-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
29 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">29 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
30 ······<cpe-dict:cpe-item·name="cpe:/o:almalinux:almalinux:9">30 ······<cpe-dict:cpe-item·name="cpe:/o:almalinux:almalinux:9">
31 ········<cpe-dict:title·xml:lang="en-us">AlmaLinux·OS·9</cpe-dict:title>31 ········<cpe-dict:title·xml:lang="en-us">AlmaLinux·OS·9</cpe-dict:title>
32 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml">oval:ssg-installed_OS_is_almalinux9:def:1</cpe-dict:check>32 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml">oval:ssg-installed_OS_is_almalinux9:def:1</cpe-dict:check>
33 ······</cpe-dict:cpe-item>33 ······</cpe-dict:cpe-item>
34 ····</cpe-dict:cpe-list>34 ····</cpe-dict:cpe-list>
35 ··</ds:component>35 ··</ds:component>
36 ··<ds:component·id="scap_org.open-scap_comp_ssg-almalinux9-xccdf.xml"·timestamp="2025-02-28T20:08:00">36 ··<ds:component·id="scap_org.open-scap_comp_ssg-almalinux9-xccdf.xml"·timestamp="2025-03-01T22:08:00">
37 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_ALMALINUX-9"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">37 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_ALMALINUX-9"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
38 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>38 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
39 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·AlmaLinux·OS·9</xccdf-1.2:title>39 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·AlmaLinux·OS·9</xccdf-1.2:title>
40 ······<xccdf-1.2:description>40 ······<xccdf-1.2:description>
41 ········This·guide·presents·a·catalog·of·security-relevant41 ········This·guide·presents·a·catalog·of·security-relevant
42 configuration·settings·for·AlmaLinux·OS·9.·It·is·a·rendering·of42 configuration·settings·for·AlmaLinux·OS·9.·It·is·a·rendering·of
43 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)43 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 107, 252 lines modifiedOffset 107, 252 lines modified
107 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>107 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
108 ······<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>108 ······<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
109 ······<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>109 ······<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
110 ······<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>110 ······<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
111 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>111 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
112 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>112 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
113 ······<cpe-lang:platform-specification>113 ······<cpe-lang:platform-specification>
114 ········<cpe-lang:platform·id="package_libuser">114 ········<cpe-lang:platform·id="not_aarch64_arch_and_not_ppc64le_arch_and_system_with_kernel">
115 ··········<cpe-lang:logical-test·operator="AND"·negate="false">115 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
116 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-package_libuser:def:1"/> 
117 ··········</cpe-lang:logical-test> 
118 ········</cpe-lang:platform> 
119 ········<cpe-lang:platform·id="not_bootc"> 
120 ··········<cpe-lang:logical-test·operator="AND"·negate="true">116 ············<cpe-lang:logical-test·operator="AND"·negate="true">
 117 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
 118 ············</cpe-lang:logical-test>
 119 ············<cpe-lang:logical-test·operator="AND"·negate="true">
 120 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_ppc64le:def:1"/>
 121 ············</cpe-lang:logical-test>
121 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-bootc:def:1"/>122 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
122 ··········</cpe-lang:logical-test>123 ··········</cpe-lang:logical-test>
123 ········</cpe-lang:platform>124 ········</cpe-lang:platform>
124 ········<cpe-lang:platform·id="machine">125 ········<cpe-lang:platform·id="package_polkit">
125 ··········<cpe-lang:logical-test·operator="AND"·negate="false">126 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
126 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>127 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-package_polkit:def:1"/>
127 ··········</cpe-lang:logical-test>128 ··········</cpe-lang:logical-test>
128 ········</cpe-lang:platform>129 ········</cpe-lang:platform>
129 ········<cpe-lang:platform·id="package_pam">130 ········<cpe-lang:platform·id="mount_var-tmp">
130 ··········<cpe-lang:logical-test·operator="AND"·negate="false">131 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
131 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>132 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-tmp:def:1"/>
132 ··········</cpe-lang:logical-test>133 ··········</cpe-lang:logical-test>
133 ········</cpe-lang:platform>134 ········</cpe-lang:platform>
134 ········<cpe-lang:platform·id="package_autofs_and_system_with_kernel">135 ········<cpe-lang:platform·id="package_autofs_and_system_with_kernel">
135 ··········<cpe-lang:logical-test·operator="AND"·negate="false">136 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
136 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>137 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>
137 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>138 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
138 ··········</cpe-lang:logical-test>139 ··········</cpe-lang:logical-test>
139 ········</cpe-lang:platform>140 ········</cpe-lang:platform>
140 ········<cpe-lang:platform·id="mount_tmp">141 ········<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">
141 ··········<cpe-lang:logical-test·operator="AND"·negate="false">142 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 143 ············<cpe-lang:logical-test·operator="AND"·negate="true">
 144 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
 145 ············</cpe-lang:logical-test>
 146 ············<cpe-lang:logical-test·operator="AND"·negate="true">
142 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_tmp:def:1"/>147 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
 148 ············</cpe-lang:logical-test>
 149 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
143 ··········</cpe-lang:logical-test>150 ··········</cpe-lang:logical-test>
144 ········</cpe-lang:platform>151 ········</cpe-lang:platform>
145 ········<cpe-lang:platform·id="package_firewalld_and_package_nftables_and_system_with_kernel">152 ········<cpe-lang:platform·id="ipv6_enabled">
146 ··········<cpe-lang:logical-test·operator="AND"·negate="false">153 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
147 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/> 
148 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>154 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-ipv6_enabled:def:1"/>
149 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
150 ··········</cpe-lang:logical-test>155 ··········</cpe-lang:logical-test>
151 ········</cpe-lang:platform>156 ········</cpe-lang:platform>
152 ········<cpe-lang:platform·id="mount_var-log">157 ········<cpe-lang:platform·id="package_gdm">
153 ··········<cpe-lang:logical-test·operator="AND"·negate="false">158 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
154 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-log:def:1"/>159 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-package_gdm:def:1"/>
155 ··········</cpe-lang:logical-test>160 ··········</cpe-lang:logical-test>
156 ········</cpe-lang:platform>161 ········</cpe-lang:platform>
157 ········<cpe-lang:platform·id="uefi">162 ········<cpe-lang:platform·id="package_rsyslog">
158 ··········<cpe-lang:logical-test·operator="AND"·negate="false">163 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
159 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>164 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>
160 ··········</cpe-lang:logical-test>165 ··········</cpe-lang:logical-test>
161 ········</cpe-lang:platform>166 ········</cpe-lang:platform>
162 ········<cpe-lang:platform·id="package_bash">167 ········<cpe-lang:platform·id="package_bash">
163 ··········<cpe-lang:logical-test·operator="AND"·negate="false">168 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
164 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>169 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>
165 ··········</cpe-lang:logical-test>170 ··········</cpe-lang:logical-test>
166 ········</cpe-lang:platform>171 ········</cpe-lang:platform>
167 ········<cpe-lang:platform·id="package_telnet-server_and_system_with_kernel">172 ········<cpe-lang:platform·id="uefi">
168 ··········<cpe-lang:logical-test·operator="AND"·negate="false">173 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
169 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-package_telnet-server:def:1"/> 
170 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>174 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>
171 ··········</cpe-lang:logical-test>175 ··········</cpe-lang:logical-test>
172 ········</cpe-lang:platform>176 ········</cpe-lang:platform>
173 ········<cpe-lang:platform·id="grub2">177 ········<cpe-lang:platform·id="package_logrotate">
174 ··········<cpe-lang:logical-test·operator="AND"·negate="false">178 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
175 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>179 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-package_logrotate:def:1"/>
176 ··········</cpe-lang:logical-test>180 ··········</cpe-lang:logical-test>
177 ········</cpe-lang:platform>181 ········</cpe-lang:platform>
178 ········<cpe-lang:platform·id="wifi-iface">182 ········<cpe-lang:platform·id="package_chrony">
179 ··········<cpe-lang:logical-test·operator="AND"·negate="false">183 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
180 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_wifi_interface:def:1"/>184 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
181 ··········</cpe-lang:logical-test>185 ··········</cpe-lang:logical-test>
182 ········</cpe-lang:platform>186 ········</cpe-lang:platform>
183 ········<cpe-lang:platform·id="package_rsyslog">187 ········<cpe-lang:platform·id="package_firewalld">
184 ··········<cpe-lang:logical-test·operator="AND"·negate="false">188 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 189 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>
 190 ··········</cpe-lang:logical-test>
 191 ········</cpe-lang:platform>
 192 ········<cpe-lang:platform·id="package_rsh-server">
 193 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
185 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>194 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-package_rsh-server:def:1"/>
186 ··········</cpe-lang:logical-test>195 ··········</cpe-lang:logical-test>
187 ········</cpe-lang:platform>196 ········</cpe-lang:platform>
188 ········<cpe-lang:platform·id="package_systemd">197 ········<cpe-lang:platform·id="package_systemd">
189 ··········<cpe-lang:logical-test·operator="AND"·negate="false">198 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
190 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>199 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>
191 ··········</cpe-lang:logical-test>200 ··········</cpe-lang:logical-test>
192 ········</cpe-lang:platform>201 ········</cpe-lang:platform>
193 ········<cpe-lang:platform·id="package_avahi_and_system_with_kernel">202 ········<cpe-lang:platform·id="not_bootc_and_not_container">
Max diff block lines reached; 1190939/1204501 bytes (98.87%) of diff not shown.
996 KB
./usr/share/xml/scap/ssg/content/ssg-almalinux9-ocil.xml
996 KB
./usr/share/xml/scap/ssg/content/ssg-almalinux9-ocil.xml
Ordering differences only
    
Offset 3, 6844 lines modifiedOffset 3, 6924 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_passwd_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-file_owner_etc_group_ocil:questionnaire:1">
11 ······<ocil:title>Verify·Permissions·on·passwd·File</ocil:title>11 ······<ocil:title>Verify·User·Who·Owns·group·File</ocil:title>
12 ······<ocil:actions>12 ······<ocil:actions>
13 ········<ocil:test_action_ref>ocil:ssg-file_permissions_etc_passwd_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-file_owner_etc_group_action:testaction:1</ocil:test_action_ref>
14 ······</ocil:actions>14 ······</ocil:actions>
15 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
16 ····<ocil:questionnaire·id="ocil:ssg-mount_option_var_log_nodev_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-xwindows_runlevel_target_ocil:questionnaire:1">
17 ······<ocil:title>Add·nodev·Option·to·/var/log</ocil:title>17 ······<ocil:title>Disable·Graphical·Environment·Startup·By·Setting·Default·Target</ocil:title>
18 ······<ocil:actions>18 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-mount_option_var_log_nodev_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-xwindows_runlevel_target_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>20 ······</ocil:actions>
21 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_space_left_action_ocil:questionnaire:1"> 
23 ······<ocil:title>Configure·auditd·space_left·Action·on·Low·Disk·Space</ocil:title>22 ····<ocil:questionnaire·id="ocil:ssg-account_password_pam_faillock_password_auth_ocil:questionnaire:1">
 23 ······<ocil:title>Configure·the·Use·of·the·pam_faillock.so·Module·in·the·/etc/pam.d/password-auth·File.</ocil:title>
24 ······<ocil:actions>24 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-auditd_data_retention_space_left_action_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-account_password_pam_faillock_password_auth_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>26 ······</ocil:actions>
27 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-file_owner_etc_motd_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_shadow_ocil:questionnaire:1">
29 ······<ocil:title>Verify·ownership·of·Message·of·the·Day·Banner</ocil:title>29 ······<ocil:title>Verify·Group·Who·Owns·shadow·File</ocil:title>
30 ······<ocil:actions>30 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-file_owner_etc_motd_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_shadow_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>32 ······</ocil:actions>
33 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-dconf_gnome_disable_autorun_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-journald_compress_ocil:questionnaire:1">
35 ······<ocil:title>Disable·GNOME3·Automount·running</ocil:title>35 ······<ocil:title>Ensure·journald·is·configured·to·compress·large·log·files</ocil:title>
36 ······<ocil:actions>36 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-dconf_gnome_disable_autorun_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-journald_compress_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>38 ······</ocil:actions>
39 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_minclass_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-package_xinetd_removed_ocil:questionnaire:1">
41 ······<ocil:title>Ensure·PAM·Enforces·Password·Requirements·-·Minimum·Different·Categories</ocil:title>41 ······<ocil:title>Uninstall·xinetd·Package</ocil:title>
42 ······<ocil:actions>42 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-accounts_password_pam_minclass_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-package_xinetd_removed_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>44 ······</ocil:actions>
45 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-service_systemd-journald_enabled_ocil:questionnaire:1">46 ····<ocil:questionnaire·id="ocil:ssg-package_ypbind_removed_ocil:questionnaire:1">
47 ······<ocil:title>Enable·systemd-journald·Service</ocil:title>47 ······<ocil:title>Remove·NIS·Client</ocil:title>
48 ······<ocil:actions>48 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-service_systemd-journald_enabled_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-package_ypbind_removed_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>50 ······</ocil:actions>
51 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_secure_redirects_ocil:questionnaire:1"> 
53 ······<ocil:title>Configure·Kernel·Parameter·for·Accepting·Secure·Redirects·By·Default</ocil:title>52 ····<ocil:questionnaire·id="ocil:ssg-dconf_gnome_screensaver_lock_enabled_ocil:questionnaire:1">
 53 ······<ocil:title>Enable·GNOME3·Screensaver·Lock·After·Idle·Period</ocil:title>
54 ······<ocil:actions>54 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_secure_redirects_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-dconf_gnome_screensaver_lock_enabled_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>56 ······</ocil:actions>
57 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-sshd_allow_only_protocol2_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-sshd_enable_strictmodes_ocil:questionnaire:1">
59 ······<ocil:title>Allow·Only·SSH·Protocol·2</ocil:title>59 ······<ocil:title>Enable·Use·of·Strict·Mode·Checking</ocil:title>
60 ······<ocil:actions>60 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-sshd_allow_only_protocol2_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-sshd_enable_strictmodes_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>62 ······</ocil:actions>
63 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-sysctl_kernel_exec_shield_ocil:questionnaire:1"> 
65 ······<ocil:title>Enable·ExecShield·via·sysctl</ocil:title>64 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_passwd_ocil:questionnaire:1">
 65 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·passwd</ocil:title>
66 ······<ocil:actions>66 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-sysctl_kernel_exec_shield_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_passwd_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>68 ······</ocil:actions>
69 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_fchownat_ocil:questionnaire:1"> 
71 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·fchownat</ocil:title>70 ····<ocil:questionnaire·id="ocil:ssg-account_password_pam_faillock_system_auth_ocil:questionnaire:1">
 71 ······<ocil:title>Configure·the·Use·of·the·pam_faillock.so·Module·in·the·/etc/pam.d/system-auth·File.</ocil:title>
72 ······<ocil:actions>72 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_fchownat_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-account_password_pam_faillock_system_auth_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>74 ······</ocil:actions>
75 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-sysctl_kernel_randomize_va_space_ocil:questionnaire:1"> 
77 ······<ocil:title>Enable·Randomized·Layout·of·Virtual·Address·Space</ocil:title>76 ····<ocil:questionnaire·id="ocil:ssg-package_tftp-server_removed_ocil:questionnaire:1">
 77 ······<ocil:title>Uninstall·tftp-server·Package</ocil:title>
78 ······<ocil:actions>78 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-sysctl_kernel_randomize_va_space_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-package_tftp-server_removed_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>80 ······</ocil:actions>
81 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_time_stime_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_rhosts_ocil:questionnaire:1">
83 ······<ocil:title>Record·Attempts·to·Alter·Time·Through·stime</ocil:title>83 ······<ocil:title>Disable·SSH·Support·for·.rhosts·Files</ocil:title>
84 ······<ocil:actions>84 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-audit_rules_time_stime_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_rhosts_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>86 ······</ocil:actions>
87 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-securetty_root_login_console_only_ocil:questionnaire:1"> 
89 ······<ocil:title>Restrict·Virtual·Console·Root·Logins</ocil:title>88 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_send_redirects_ocil:questionnaire:1">
 89 ······<ocil:title>Disable·Kernel·Parameter·for·Sending·ICMP·Redirects·on·all·IPv4·Interfaces·by·Default</ocil:title>
90 ······<ocil:actions>90 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-securetty_root_login_console_only_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_send_redirects_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>92 ······</ocil:actions>
93 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_fchmodat_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-coredump_disable_backtraces_ocil:questionnaire:1">
95 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·fchmodat</ocil:title>95 ······<ocil:title>Disable·core·dump·backtraces</ocil:title>
96 ······<ocil:actions>96 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_fchmodat_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-coredump_disable_backtraces_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>98 ······</ocil:actions>
99 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_cron_d_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-rsyslog_files_permissions_ocil:questionnaire:1">
101 ······<ocil:title>Verify·Group·Who·Owns·cron.d</ocil:title>101 ······<ocil:title>Ensure·System·Log·Files·Have·Correct·Permissions</ocil:title>
102 ······<ocil:actions>102 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_cron_d_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-rsyslog_files_permissions_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>104 ······</ocil:actions>
105 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-dconf_gnome_screensaver_idle_activation_enabled_ocil:questionnaire:1">106 ····<ocil:questionnaire·id="ocil:ssg-service_firewalld_enabled_ocil:questionnaire:1">
107 ······<ocil:title>Enable·GNOME3·Screensaver·Idle·Activation</ocil:title>107 ······<ocil:title>Verify·firewalld·Enabled</ocil:title>
108 ······<ocil:actions>108 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-dconf_gnome_screensaver_idle_activation_enabled_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-service_firewalld_enabled_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>110 ······</ocil:actions>
111 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-partition_for_var_log_audit_ocil:questionnaire:1"> 
113 ······<ocil:title>Ensure·/var/log/audit·Located·On·Separate·Partition</ocil:title>112 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_last_change_is_in_past_ocil:questionnaire:1">
 113 ······<ocil:title>Ensure·all·users·last·password·change·date·is·in·the·past</ocil:title>
114 ······<ocil:actions>114 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-partition_for_var_log_audit_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-accounts_password_last_change_is_in_past_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>116 ······</ocil:actions>
117 ····</ocil:questionnaire>117 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-mount_option_var_nosuid_ocil:questionnaire:1">118 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_empty_passwords_ocil:questionnaire:1">
119 ······<ocil:title>Add·nosuid·Option·to·/var</ocil:title>119 ······<ocil:title>Disable·SSH·Access·via·Empty·Passwords</ocil:title>
120 ······<ocil:actions>120 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-mount_option_var_nosuid_action:testaction:1</ocil:test_action_ref>121 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_empty_passwords_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>122 ······</ocil:actions>
Max diff block lines reached; 1007415/1019918 bytes (98.77%) of diff not shown.
129 KB
./usr/share/xml/scap/ssg/content/ssg-almalinux9-xccdf.xml
129 KB
./usr/share/xml/scap/ssg/content/ssg-almalinux9-xccdf.xml
Ordering differences only
    
Offset 72, 252 lines modifiedOffset 72, 252 lines modified
72 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>72 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
73 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>73 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
74 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>74 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
75 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>75 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
77 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>77 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
78 ··<cpe-lang:platform-specification>78 ··<cpe-lang:platform-specification>
79 ····<cpe-lang:platform·id="package_libuser">79 ····<cpe-lang:platform·id="not_aarch64_arch_and_not_ppc64le_arch_and_system_with_kernel">
80 ······<cpe-lang:logical-test·operator="AND"·negate="false">80 ······<cpe-lang:logical-test·operator="AND"·negate="false">
81 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-package_libuser:def:1"/> 
82 ······</cpe-lang:logical-test> 
83 ····</cpe-lang:platform> 
84 ····<cpe-lang:platform·id="not_bootc"> 
85 ······<cpe-lang:logical-test·operator="AND"·negate="true">81 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 82 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
 83 ········</cpe-lang:logical-test>
 84 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 85 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_ppc64le:def:1"/>
 86 ········</cpe-lang:logical-test>
86 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-bootc:def:1"/>87 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
87 ······</cpe-lang:logical-test>88 ······</cpe-lang:logical-test>
88 ····</cpe-lang:platform>89 ····</cpe-lang:platform>
89 ····<cpe-lang:platform·id="machine">90 ····<cpe-lang:platform·id="package_polkit">
90 ······<cpe-lang:logical-test·operator="AND"·negate="false">91 ······<cpe-lang:logical-test·operator="AND"·negate="false">
91 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>92 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-package_polkit:def:1"/>
92 ······</cpe-lang:logical-test>93 ······</cpe-lang:logical-test>
93 ····</cpe-lang:platform>94 ····</cpe-lang:platform>
94 ····<cpe-lang:platform·id="package_pam">95 ····<cpe-lang:platform·id="mount_var-tmp">
95 ······<cpe-lang:logical-test·operator="AND"·negate="false">96 ······<cpe-lang:logical-test·operator="AND"·negate="false">
96 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>97 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-tmp:def:1"/>
97 ······</cpe-lang:logical-test>98 ······</cpe-lang:logical-test>
98 ····</cpe-lang:platform>99 ····</cpe-lang:platform>
99 ····<cpe-lang:platform·id="package_autofs_and_system_with_kernel">100 ····<cpe-lang:platform·id="package_autofs_and_system_with_kernel">
100 ······<cpe-lang:logical-test·operator="AND"·negate="false">101 ······<cpe-lang:logical-test·operator="AND"·negate="false">
101 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>102 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>
102 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>103 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
103 ······</cpe-lang:logical-test>104 ······</cpe-lang:logical-test>
104 ····</cpe-lang:platform>105 ····</cpe-lang:platform>
105 ····<cpe-lang:platform·id="mount_tmp">106 ····<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">
106 ······<cpe-lang:logical-test·operator="AND"·negate="false">107 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 108 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 109 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
 110 ········</cpe-lang:logical-test>
 111 ········<cpe-lang:logical-test·operator="AND"·negate="true">
107 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_tmp:def:1"/>112 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
 113 ········</cpe-lang:logical-test>
 114 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
108 ······</cpe-lang:logical-test>115 ······</cpe-lang:logical-test>
109 ····</cpe-lang:platform>116 ····</cpe-lang:platform>
110 ····<cpe-lang:platform·id="package_firewalld_and_package_nftables_and_system_with_kernel">117 ····<cpe-lang:platform·id="ipv6_enabled">
111 ······<cpe-lang:logical-test·operator="AND"·negate="false">118 ······<cpe-lang:logical-test·operator="AND"·negate="false">
112 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/> 
113 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>119 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-ipv6_enabled:def:1"/>
114 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
115 ······</cpe-lang:logical-test>120 ······</cpe-lang:logical-test>
116 ····</cpe-lang:platform>121 ····</cpe-lang:platform>
117 ····<cpe-lang:platform·id="mount_var-log">122 ····<cpe-lang:platform·id="package_gdm">
118 ······<cpe-lang:logical-test·operator="AND"·negate="false">123 ······<cpe-lang:logical-test·operator="AND"·negate="false">
119 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-log:def:1"/>124 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-package_gdm:def:1"/>
120 ······</cpe-lang:logical-test>125 ······</cpe-lang:logical-test>
121 ····</cpe-lang:platform>126 ····</cpe-lang:platform>
122 ····<cpe-lang:platform·id="uefi">127 ····<cpe-lang:platform·id="package_rsyslog">
123 ······<cpe-lang:logical-test·operator="AND"·negate="false">128 ······<cpe-lang:logical-test·operator="AND"·negate="false">
124 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>129 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>
125 ······</cpe-lang:logical-test>130 ······</cpe-lang:logical-test>
126 ····</cpe-lang:platform>131 ····</cpe-lang:platform>
127 ····<cpe-lang:platform·id="package_bash">132 ····<cpe-lang:platform·id="package_bash">
128 ······<cpe-lang:logical-test·operator="AND"·negate="false">133 ······<cpe-lang:logical-test·operator="AND"·negate="false">
129 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>134 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>
130 ······</cpe-lang:logical-test>135 ······</cpe-lang:logical-test>
131 ····</cpe-lang:platform>136 ····</cpe-lang:platform>
132 ····<cpe-lang:platform·id="package_telnet-server_and_system_with_kernel">137 ····<cpe-lang:platform·id="uefi">
133 ······<cpe-lang:logical-test·operator="AND"·negate="false">138 ······<cpe-lang:logical-test·operator="AND"·negate="false">
134 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-package_telnet-server:def:1"/> 
135 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>139 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>
136 ······</cpe-lang:logical-test>140 ······</cpe-lang:logical-test>
137 ····</cpe-lang:platform>141 ····</cpe-lang:platform>
138 ····<cpe-lang:platform·id="grub2">142 ····<cpe-lang:platform·id="package_logrotate">
139 ······<cpe-lang:logical-test·operator="AND"·negate="false">143 ······<cpe-lang:logical-test·operator="AND"·negate="false">
140 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>144 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-package_logrotate:def:1"/>
141 ······</cpe-lang:logical-test>145 ······</cpe-lang:logical-test>
142 ····</cpe-lang:platform>146 ····</cpe-lang:platform>
143 ····<cpe-lang:platform·id="wifi-iface">147 ····<cpe-lang:platform·id="package_chrony">
144 ······<cpe-lang:logical-test·operator="AND"·negate="false">148 ······<cpe-lang:logical-test·operator="AND"·negate="false">
145 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_wifi_interface:def:1"/>149 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
146 ······</cpe-lang:logical-test>150 ······</cpe-lang:logical-test>
147 ····</cpe-lang:platform>151 ····</cpe-lang:platform>
148 ····<cpe-lang:platform·id="package_rsyslog">152 ····<cpe-lang:platform·id="package_firewalld">
149 ······<cpe-lang:logical-test·operator="AND"·negate="false">153 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 154 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>
 155 ······</cpe-lang:logical-test>
 156 ····</cpe-lang:platform>
 157 ····<cpe-lang:platform·id="package_rsh-server">
 158 ······<cpe-lang:logical-test·operator="AND"·negate="false">
150 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>159 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-package_rsh-server:def:1"/>
151 ······</cpe-lang:logical-test>160 ······</cpe-lang:logical-test>
152 ····</cpe-lang:platform>161 ····</cpe-lang:platform>
153 ····<cpe-lang:platform·id="package_systemd">162 ····<cpe-lang:platform·id="package_systemd">
154 ······<cpe-lang:logical-test·operator="AND"·negate="false">163 ······<cpe-lang:logical-test·operator="AND"·negate="false">
155 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>164 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>
156 ······</cpe-lang:logical-test>165 ······</cpe-lang:logical-test>
157 ····</cpe-lang:platform>166 ····</cpe-lang:platform>
158 ····<cpe-lang:platform·id="package_avahi_and_system_with_kernel">167 ····<cpe-lang:platform·id="not_bootc_and_not_container">
159 ······<cpe-lang:logical-test·operator="AND"·negate="false">168 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 169 ········<cpe-lang:logical-test·operator="AND"·negate="true">
160 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-package_avahi:def:1"/>170 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-bootc:def:1"/>
 171 ········</cpe-lang:logical-test>
 172 ········<cpe-lang:logical-test·operator="AND"·negate="true">
161 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>173 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_container:def:1"/>
 174 ········</cpe-lang:logical-test>
162 ······</cpe-lang:logical-test>175 ······</cpe-lang:logical-test>
163 ····</cpe-lang:platform>176 ····</cpe-lang:platform>
164 ····<cpe-lang:platform·id="package_polkit">177 ····<cpe-lang:platform·id="mount_tmp">
165 ······<cpe-lang:logical-test·operator="AND"·negate="false">178 ······<cpe-lang:logical-test·operator="AND"·negate="false">
166 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-package_polkit:def:1"/>179 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_tmp:def:1"/>
167 ······</cpe-lang:logical-test>180 ······</cpe-lang:logical-test>
168 ····</cpe-lang:platform>181 ····</cpe-lang:platform>
169 ····<cpe-lang:platform·id="mount_var">182 ····<cpe-lang:platform·id="package_pam">
170 ······<cpe-lang:logical-test·operator="AND"·negate="false">183 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 184 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>
 185 ······</cpe-lang:logical-test>
 186 ····</cpe-lang:platform>
 187 ····<cpe-lang:platform·id="machine">
 188 ······<cpe-lang:logical-test·operator="AND"·negate="false">
171 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var:def:1"/>189 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
172 ······</cpe-lang:logical-test>190 ······</cpe-lang:logical-test>
173 ····</cpe-lang:platform>191 ····</cpe-lang:platform>
Max diff block lines reached; 118952/132240 bytes (89.95%) of diff not shown.
1.03 MB
./usr/share/xml/scap/ssg/content/ssg-anolis23-ds.xml
1.03 MB
./usr/share/xml/scap/ssg/content/ssg-anolis23-ds.xml
    
Offset 19, 23 lines modifiedOffset 19, 23 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-anolis23-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-anolis23-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-anolis23-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-anolis23-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-anolis23-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-anolis23-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-anolis23-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-anolis23-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-anolis23-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-anolis23-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-anolis23-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-anolis23-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-anolis23-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-anolis23-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:anolis:anolis_os:23">28 ······<cpe-dict:cpe-item·name="cpe:/o:anolis:anolis_os:23">
29 ········<cpe-dict:title·xml:lang="en-us">Anolis·OS·23</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Anolis·OS·23</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml">oval:ssg-installed_OS_is_anolis23:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml">oval:ssg-installed_OS_is_anolis23:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ····</cpe-dict:cpe-list>32 ····</cpe-dict:cpe-list>
33 ··</ds:component>33 ··</ds:component>
34 ··<ds:component·id="scap_org.open-scap_comp_ssg-anolis23-xccdf.xml"·timestamp="2025-02-28T20:08:00">34 ··<ds:component·id="scap_org.open-scap_comp_ssg-anolis23-xccdf.xml"·timestamp="2025-03-01T22:08:00">
35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_ANOLIS-23"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_ANOLIS-23"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Anolis·OS·23</xccdf-1.2:title>37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Anolis·OS·23</xccdf-1.2:title>
38 ······<xccdf-1.2:description>38 ······<xccdf-1.2:description>
39 ········This·guide·presents·a·catalog·of·security-relevant39 ········This·guide·presents·a·catalog·of·security-relevant
40 configuration·settings·for·Anolis·OS·23.·It·is·a·rendering·of40 configuration·settings·for·Anolis·OS·23.·It·is·a·rendering·of
41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 104, 122 lines modifiedOffset 104, 118 lines modified
104 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>104 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
105 ······<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>105 ······<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
106 ······<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>106 ······<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
107 ······<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>107 ······<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
108 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>108 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
109 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>109 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
110 ······<cpe-lang:platform-specification>110 ······<cpe-lang:platform-specification>
111 ········<cpe-lang:platform·id="not_bootc">111 ········<cpe-lang:platform·id="package_autofs_and_system_with_kernel">
112 ··········<cpe-lang:logical-test·operator="AND"·negate="true">112 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
113 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-bootc:def:1"/>113 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>
 114 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
114 ··········</cpe-lang:logical-test>115 ··········</cpe-lang:logical-test>
115 ········</cpe-lang:platform>116 ········</cpe-lang:platform>
116 ········<cpe-lang:platform·id="machine">117 ········<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">
117 ··········<cpe-lang:logical-test·operator="AND"·negate="false">118 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 119 ············<cpe-lang:logical-test·operator="AND"·negate="true">
 120 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
 121 ············</cpe-lang:logical-test>
 122 ············<cpe-lang:logical-test·operator="AND"·negate="true">
 123 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
 124 ············</cpe-lang:logical-test>
118 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>125 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
119 ··········</cpe-lang:logical-test>126 ··········</cpe-lang:logical-test>
120 ········</cpe-lang:platform>127 ········</cpe-lang:platform>
121 ········<cpe-lang:platform·id="package_squid_and_system_with_kernel">128 ········<cpe-lang:platform·id="ipv6_enabled">
122 ··········<cpe-lang:logical-test·operator="AND"·negate="false">129 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
123 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_squid:def:1"/>130 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-ipv6_enabled:def:1"/>
124 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
125 ··········</cpe-lang:logical-test>131 ··········</cpe-lang:logical-test>
126 ········</cpe-lang:platform>132 ········</cpe-lang:platform>
127 ········<cpe-lang:platform·id="package_pam">133 ········<cpe-lang:platform·id="package_gdm">
128 ··········<cpe-lang:logical-test·operator="AND"·negate="false">134 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
129 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>135 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_gdm:def:1"/>
130 ··········</cpe-lang:logical-test>136 ··········</cpe-lang:logical-test>
131 ········</cpe-lang:platform>137 ········</cpe-lang:platform>
132 ········<cpe-lang:platform·id="package_autofs_and_system_with_kernel">138 ········<cpe-lang:platform·id="package_rsyslog">
133 ··········<cpe-lang:logical-test·operator="AND"·negate="false">139 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 140 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>
 141 ··········</cpe-lang:logical-test>
 142 ········</cpe-lang:platform>
 143 ········<cpe-lang:platform·id="package_bash">
 144 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
134 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>145 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>
135 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
136 ··········</cpe-lang:logical-test>146 ··········</cpe-lang:logical-test>
137 ········</cpe-lang:platform>147 ········</cpe-lang:platform>
138 ········<cpe-lang:platform·id="uefi">148 ········<cpe-lang:platform·id="uefi">
139 ··········<cpe-lang:logical-test·operator="AND"·negate="false">149 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
140 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>150 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>
141 ··········</cpe-lang:logical-test>151 ··········</cpe-lang:logical-test>
142 ········</cpe-lang:platform>152 ········</cpe-lang:platform>
143 ········<cpe-lang:platform·id="package_bash">153 ········<cpe-lang:platform·id="package_logrotate">
144 ··········<cpe-lang:logical-test·operator="AND"·negate="false">154 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
145 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>155 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_logrotate:def:1"/>
146 ··········</cpe-lang:logical-test>156 ··········</cpe-lang:logical-test>
147 ········</cpe-lang:platform>157 ········</cpe-lang:platform>
148 ········<cpe-lang:platform·id="package_iptables">158 ········<cpe-lang:platform·id="package_chrony">
149 ··········<cpe-lang:logical-test·operator="AND"·negate="false">159 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
150 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>160 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
151 ··········</cpe-lang:logical-test>161 ··········</cpe-lang:logical-test>
152 ········</cpe-lang:platform>162 ········</cpe-lang:platform>
153 ········<cpe-lang:platform·id="wifi-iface">163 ········<cpe-lang:platform·id="package_ufw_and_system_with_kernel">
154 ··········<cpe-lang:logical-test·operator="AND"·negate="false">164 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 165 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
155 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_wifi_interface:def:1"/>166 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
156 ··········</cpe-lang:logical-test>167 ··········</cpe-lang:logical-test>
157 ········</cpe-lang:platform>168 ········</cpe-lang:platform>
158 ········<cpe-lang:platform·id="package_rsyslog">169 ········<cpe-lang:platform·id="package_firewalld">
159 ··········<cpe-lang:logical-test·operator="AND"·negate="false">170 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
160 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>171 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>
161 ··········</cpe-lang:logical-test>172 ··········</cpe-lang:logical-test>
162 ········</cpe-lang:platform>173 ········</cpe-lang:platform>
163 ········<cpe-lang:platform·id="package_yum">174 ········<cpe-lang:platform·id="package_rsh-server">
164 ··········<cpe-lang:logical-test·operator="AND"·negate="false">175 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
165 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_yum:def:1"/>176 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_rsh-server:def:1"/>
166 ··········</cpe-lang:logical-test>177 ··········</cpe-lang:logical-test>
167 ········</cpe-lang:platform>178 ········</cpe-lang:platform>
168 ········<cpe-lang:platform·id="package_systemd">179 ········<cpe-lang:platform·id="package_systemd">
169 ··········<cpe-lang:logical-test·operator="AND"·negate="false">180 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
170 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>181 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>
171 ··········</cpe-lang:logical-test>182 ··········</cpe-lang:logical-test>
172 ········</cpe-lang:platform>183 ········</cpe-lang:platform>
 184 ········<cpe-lang:platform·id="not_bootc_and_not_container">
173 ········<cpe-lang:platform·id="package_avahi_and_system_with_kernel"> 
174 ··········<cpe-lang:logical-test·operator="AND"·negate="false"> 
175 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_avahi:def:1"/> 
176 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
177 ··········</cpe-lang:logical-test> 
178 ········</cpe-lang:platform> 
179 ········<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables"> 
180 ··········<cpe-lang:logical-test·operator="AND"·negate="false">185 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
181 ············<cpe-lang:logical-test·operator="AND"·negate="true">186 ············<cpe-lang:logical-test·operator="AND"·negate="true">
182 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>187 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-bootc:def:1"/>
183 ············</cpe-lang:logical-test>188 ············</cpe-lang:logical-test>
184 ············<cpe-lang:logical-test·operator="AND"·negate="true">189 ············<cpe-lang:logical-test·operator="AND"·negate="true">
185 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>190 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_container:def:1"/>
186 ············</cpe-lang:logical-test>191 ············</cpe-lang:logical-test>
187 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/> 
188 ··········</cpe-lang:logical-test> 
189 ········</cpe-lang:platform> 
190 ········<cpe-lang:platform·id="package_firewalld"> 
191 ··········<cpe-lang:logical-test·operator="AND"·negate="false"> 
192 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/> 
Max diff block lines reached; 1071254/1085042 bytes (98.73%) of diff not shown.
984 KB
./usr/share/xml/scap/ssg/content/ssg-anolis23-ocil.xml
984 KB
./usr/share/xml/scap/ssg/content/ssg-anolis23-ocil.xml
Ordering differences only
    
Offset 3, 6535 lines modifiedOffset 3, 6500 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_passwd_ocil:questionnaire:1"> 
11 ······<ocil:title>Verify·Group·Who·Owns·passwd·File</ocil:title>10 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_accept_redirects_ocil:questionnaire:1">
 11 ······<ocil:title>Disable·Accepting·ICMP·Redirects·for·All·IPv4·Interfaces</ocil:title>
12 ······<ocil:actions>12 ······<ocil:actions>
13 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_passwd_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_accept_redirects_action:testaction:1</ocil:test_action_ref>
14 ······</ocil:actions>14 ······</ocil:actions>
15 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
16 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_openat_ocil:questionnaire:1"> 
17 ······<ocil:title>Record·Unsuccessful·Access·Attempts·to·Files·-·openat</ocil:title>16 ····<ocil:questionnaire·id="ocil:ssg-service_systemd-journald_enabled_ocil:questionnaire:1">
 17 ······<ocil:title>Enable·systemd-journald·Service</ocil:title>
18 ······<ocil:actions>18 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_openat_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-service_systemd-journald_enabled_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>20 ······</ocil:actions>
21 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-file_owner_cron_monthly_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_open_ocil:questionnaire:1">
23 ······<ocil:title>Verify·Owner·on·cron.monthly</ocil:title>23 ······<ocil:title>Record·Unsuccessful·Access·Attempts·to·Files·-·open</ocil:title>
24 ······<ocil:actions>24 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-file_owner_cron_monthly_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_open_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>26 ······</ocil:actions>
27 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-sshd_limit_user_access_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_time_adjtimex_ocil:questionnaire:1">
29 ······<ocil:title>Limit·Users'·SSH·Access</ocil:title>29 ······<ocil:title>Record·attempts·to·alter·time·through·adjtimex</ocil:title>
30 ······<ocil:actions>30 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-sshd_limit_user_access_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-audit_rules_time_adjtimex_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>32 ······</ocil:actions>
33 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-account_passwords_pam_faillock_audit_ocil:questionnaire:1"> 
35 ······<ocil:title>Account·Lockouts·Must·Be·Logged</ocil:title>34 ····<ocil:questionnaire·id="ocil:ssg-file_owner_cron_weekly_ocil:questionnaire:1">
 35 ······<ocil:title>Verify·Owner·on·cron.weekly</ocil:title>
36 ······<ocil:actions>36 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-account_passwords_pam_faillock_audit_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-file_owner_cron_weekly_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>38 ······</ocil:actions>
39 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_open_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_chown_ocil:questionnaire:1">
41 ······<ocil:title>Record·Unsuccessful·Access·Attempts·to·Files·-·open</ocil:title>41 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·chown</ocil:title>
42 ······<ocil:actions>42 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_open_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_chown_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>44 ······</ocil:actions>
45 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-grub2_systemd_debug-shell_argument_absent_ocil:questionnaire:1">46 ····<ocil:questionnaire·id="ocil:ssg-sysctl_kernel_randomize_va_space_ocil:questionnaire:1">
47 ······<ocil:title>Ensure·debug-shell·service·is·not·enabled·during·boot</ocil:title>47 ······<ocil:title>Enable·Randomized·Layout·of·Virtual·Address·Space</ocil:title>
48 ······<ocil:actions>48 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-grub2_systemd_debug-shell_argument_absent_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-sysctl_kernel_randomize_va_space_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>50 ······</ocil:actions>
51 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_user_known_hosts_ocil:questionnaire:1"> 
53 ······<ocil:title>Disable·SSH·Support·for·User·Known·Hosts</ocil:title>52 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_default_accept_ra_ocil:questionnaire:1">
 53 ······<ocil:title>Disable·Accepting·Router·Advertisements·on·all·IPv6·Interfaces·by·Default</ocil:title>
54 ······<ocil:actions>54 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_user_known_hosts_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_default_accept_ra_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>56 ······</ocil:actions>
57 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-no_empty_passwords_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_randomize_base_ocil:questionnaire:1">
59 ······<ocil:title>Prevent·Login·to·Accounts·With·Empty·Password</ocil:title>59 ······<ocil:title>Randomize·the·address·of·the·kernel·image·(KASLR)</ocil:title>
60 ······<ocil:actions>60 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-no_empty_passwords_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-kernel_config_randomize_base_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>62 ······</ocil:actions>
63 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_last_change_is_in_past_ocil:questionnaire:1"> 
65 ······<ocil:title>Ensure·all·users·last·password·change·date·is·in·the·past</ocil:title>64 ····<ocil:questionnaire·id="ocil:ssg-sshd_limit_user_access_ocil:questionnaire:1">
 65 ······<ocil:title>Limit·Users'·SSH·Access</ocil:title>
66 ······<ocil:actions>66 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-accounts_password_last_change_is_in_past_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-sshd_limit_user_access_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>68 ······</ocil:actions>
69 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_sshd_pub_key_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-partition_for_srv_ocil:questionnaire:1">
71 ······<ocil:title>Verify·Permissions·on·SSH·Server·Public·*.pub·Key·Files</ocil:title>71 ······<ocil:title>Ensure·/srv·Located·On·Separate·Partition</ocil:title>
72 ······<ocil:actions>72 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-file_permissions_sshd_pub_key_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-partition_for_srv_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>74 ······</ocil:actions>
75 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_set_min_life_existing_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_compat_vdso_ocil:questionnaire:1">
77 ······<ocil:title>Set·Existing·Passwords·Minimum·Age</ocil:title>77 ······<ocil:title>Disable·the·32-bit·vDSO</ocil:title>
78 ······<ocil:actions>78 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-accounts_password_set_min_life_existing_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-kernel_config_compat_vdso_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>80 ······</ocil:actions>
81 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-accounts_polyinstantiated_var_tmp_ocil:questionnaire:1"> 
83 ······<ocil:title>Configure·Polyinstantiation·of·/var/tmp·Directories</ocil:title>82 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_accept_source_route_ocil:questionnaire:1">
 83 ······<ocil:title>Disable·Kernel·Parameter·for·Accepting·Source-Routed·Packets·on·IPv4·Interfaces·by·Default</ocil:title>
84 ······<ocil:actions>84 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-accounts_polyinstantiated_var_tmp_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_accept_source_route_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>86 ······</ocil:actions>
87 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_send_redirects_ocil:questionnaire:1"> 
89 ······<ocil:title>Disable·Kernel·Parameter·for·Sending·ICMP·Redirects·on·all·IPv4·Interfaces·by·Default</ocil:title>88 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_page_table_isolation_ocil:questionnaire:1">
 89 ······<ocil:title>Remove·the·kernel·mapping·in·user·mode</ocil:title>
90 ······<ocil:actions>90 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_send_redirects_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-kernel_config_page_table_isolation_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>92 ······</ocil:actions>
93 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_tcp_syncookies_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-auditd_freq_ocil:questionnaire:1">
95 ······<ocil:title>Enable·Kernel·Parameter·to·Use·TCP·Syncookies·on·Network·Interfaces</ocil:title>95 ······<ocil:title>Set·number·of·records·to·cause·an·explicit·flush·to·audit·logs</ocil:title>
96 ······<ocil:actions>96 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_tcp_syncookies_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-auditd_freq_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>98 ······</ocil:actions>
99 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_default_accept_source_route_ocil:questionnaire:1"> 
101 ······<ocil:title>Disable·Kernel·Parameter·for·Accepting·Source-Routed·Packets·on·IPv6·Interfaces·by·Default</ocil:title>100 ····<ocil:questionnaire·id="ocil:ssg-rpm_verify_hashes_ocil:questionnaire:1">
 101 ······<ocil:title>Verify·File·Hashes·with·RPM</ocil:title>
102 ······<ocil:actions>102 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_default_accept_source_route_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-rpm_verify_hashes_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>104 ······</ocil:actions>
105 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_var_log_syslog_ocil:questionnaire:1">106 ····<ocil:questionnaire·id="ocil:ssg-audit_privileged_commands_poweroff_ocil:questionnaire:1">
107 ······<ocil:title>Verify·Group·Who·Owns·/var/log/syslog·File</ocil:title>107 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·poweroff</ocil:title>
108 ······<ocil:actions>108 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_var_log_syslog_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-audit_privileged_commands_poweroff_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>110 ······</ocil:actions>
111 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_backup_etc_passwd_ocil:questionnaire:1">112 ····<ocil:questionnaire·id="ocil:ssg-file_owner_etc_group_ocil:questionnaire:1">
113 ······<ocil:title>Verify·Permissions·on·Backup·passwd·File</ocil:title>113 ······<ocil:title>Verify·User·Who·Owns·group·File</ocil:title>
114 ······<ocil:actions>114 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-file_permissions_backup_etc_passwd_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-file_owner_etc_group_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>116 ······</ocil:actions>
117 ····</ocil:questionnaire>117 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_accept_source_route_ocil:questionnaire:1"> 
119 ······<ocil:title>Disable·Kernel·Parameter·for·Accepting·Source-Routed·Packets·on·all·IPv4·Interfaces</ocil:title>118 ····<ocil:questionnaire·id="ocil:ssg-service_autofs_disabled_ocil:questionnaire:1">
 119 ······<ocil:title>Disable·the·Automounter</ocil:title>
120 ······<ocil:actions>120 ······<ocil:actions>
Max diff block lines reached; 994424/1007193 bytes (98.73%) of diff not shown.
28.1 KB
./usr/share/xml/scap/ssg/content/ssg-anolis23-xccdf.xml
28.0 KB
./usr/share/xml/scap/ssg/content/ssg-anolis23-xccdf.xml
Ordering differences only
    
Offset 71, 122 lines modifiedOffset 71, 118 lines modified
71 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>71 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
72 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>72 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
73 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>73 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
74 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>74 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
75 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>75 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
77 ··<cpe-lang:platform-specification>77 ··<cpe-lang:platform-specification>
78 ····<cpe-lang:platform·id="not_bootc">78 ····<cpe-lang:platform·id="package_autofs_and_system_with_kernel">
79 ······<cpe-lang:logical-test·operator="AND"·negate="true">79 ······<cpe-lang:logical-test·operator="AND"·negate="false">
80 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-bootc:def:1"/>80 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>
 81 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
81 ······</cpe-lang:logical-test>82 ······</cpe-lang:logical-test>
82 ····</cpe-lang:platform>83 ····</cpe-lang:platform>
83 ····<cpe-lang:platform·id="machine">84 ····<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">
84 ······<cpe-lang:logical-test·operator="AND"·negate="false">85 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 86 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 87 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
 88 ········</cpe-lang:logical-test>
 89 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 90 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
 91 ········</cpe-lang:logical-test>
85 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>92 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
86 ······</cpe-lang:logical-test>93 ······</cpe-lang:logical-test>
87 ····</cpe-lang:platform>94 ····</cpe-lang:platform>
88 ····<cpe-lang:platform·id="package_squid_and_system_with_kernel">95 ····<cpe-lang:platform·id="ipv6_enabled">
89 ······<cpe-lang:logical-test·operator="AND"·negate="false">96 ······<cpe-lang:logical-test·operator="AND"·negate="false">
90 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_squid:def:1"/>97 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-ipv6_enabled:def:1"/>
91 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
92 ······</cpe-lang:logical-test>98 ······</cpe-lang:logical-test>
93 ····</cpe-lang:platform>99 ····</cpe-lang:platform>
94 ····<cpe-lang:platform·id="package_pam">100 ····<cpe-lang:platform·id="package_gdm">
95 ······<cpe-lang:logical-test·operator="AND"·negate="false">101 ······<cpe-lang:logical-test·operator="AND"·negate="false">
96 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>102 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_gdm:def:1"/>
97 ······</cpe-lang:logical-test>103 ······</cpe-lang:logical-test>
98 ····</cpe-lang:platform>104 ····</cpe-lang:platform>
99 ····<cpe-lang:platform·id="package_autofs_and_system_with_kernel">105 ····<cpe-lang:platform·id="package_rsyslog">
100 ······<cpe-lang:logical-test·operator="AND"·negate="false">106 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 107 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>
 108 ······</cpe-lang:logical-test>
 109 ····</cpe-lang:platform>
 110 ····<cpe-lang:platform·id="package_bash">
 111 ······<cpe-lang:logical-test·operator="AND"·negate="false">
101 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>112 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>
102 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
103 ······</cpe-lang:logical-test>113 ······</cpe-lang:logical-test>
104 ····</cpe-lang:platform>114 ····</cpe-lang:platform>
105 ····<cpe-lang:platform·id="uefi">115 ····<cpe-lang:platform·id="uefi">
106 ······<cpe-lang:logical-test·operator="AND"·negate="false">116 ······<cpe-lang:logical-test·operator="AND"·negate="false">
107 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>117 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>
108 ······</cpe-lang:logical-test>118 ······</cpe-lang:logical-test>
109 ····</cpe-lang:platform>119 ····</cpe-lang:platform>
110 ····<cpe-lang:platform·id="package_bash">120 ····<cpe-lang:platform·id="package_logrotate">
111 ······<cpe-lang:logical-test·operator="AND"·negate="false">121 ······<cpe-lang:logical-test·operator="AND"·negate="false">
112 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>122 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_logrotate:def:1"/>
113 ······</cpe-lang:logical-test>123 ······</cpe-lang:logical-test>
114 ····</cpe-lang:platform>124 ····</cpe-lang:platform>
115 ····<cpe-lang:platform·id="package_iptables">125 ····<cpe-lang:platform·id="package_chrony">
116 ······<cpe-lang:logical-test·operator="AND"·negate="false">126 ······<cpe-lang:logical-test·operator="AND"·negate="false">
117 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>127 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
118 ······</cpe-lang:logical-test>128 ······</cpe-lang:logical-test>
119 ····</cpe-lang:platform>129 ····</cpe-lang:platform>
120 ····<cpe-lang:platform·id="wifi-iface">130 ····<cpe-lang:platform·id="package_ufw_and_system_with_kernel">
121 ······<cpe-lang:logical-test·operator="AND"·negate="false">131 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 132 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
122 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_wifi_interface:def:1"/>133 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
123 ······</cpe-lang:logical-test>134 ······</cpe-lang:logical-test>
124 ····</cpe-lang:platform>135 ····</cpe-lang:platform>
125 ····<cpe-lang:platform·id="package_rsyslog">136 ····<cpe-lang:platform·id="package_firewalld">
126 ······<cpe-lang:logical-test·operator="AND"·negate="false">137 ······<cpe-lang:logical-test·operator="AND"·negate="false">
127 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>138 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>
128 ······</cpe-lang:logical-test>139 ······</cpe-lang:logical-test>
129 ····</cpe-lang:platform>140 ····</cpe-lang:platform>
130 ····<cpe-lang:platform·id="package_yum">141 ····<cpe-lang:platform·id="package_rsh-server">
131 ······<cpe-lang:logical-test·operator="AND"·negate="false">142 ······<cpe-lang:logical-test·operator="AND"·negate="false">
132 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_yum:def:1"/>143 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_rsh-server:def:1"/>
133 ······</cpe-lang:logical-test>144 ······</cpe-lang:logical-test>
134 ····</cpe-lang:platform>145 ····</cpe-lang:platform>
135 ····<cpe-lang:platform·id="package_systemd">146 ····<cpe-lang:platform·id="package_systemd">
136 ······<cpe-lang:logical-test·operator="AND"·negate="false">147 ······<cpe-lang:logical-test·operator="AND"·negate="false">
137 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>148 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>
138 ······</cpe-lang:logical-test>149 ······</cpe-lang:logical-test>
139 ····</cpe-lang:platform>150 ····</cpe-lang:platform>
 151 ····<cpe-lang:platform·id="not_bootc_and_not_container">
140 ····<cpe-lang:platform·id="package_avahi_and_system_with_kernel"> 
141 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
142 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_avahi:def:1"/> 
143 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
144 ······</cpe-lang:logical-test> 
145 ····</cpe-lang:platform> 
146 ····<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables"> 
147 ······<cpe-lang:logical-test·operator="AND"·negate="false">152 ······<cpe-lang:logical-test·operator="AND"·negate="false">
148 ········<cpe-lang:logical-test·operator="AND"·negate="true">153 ········<cpe-lang:logical-test·operator="AND"·negate="true">
149 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>154 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-bootc:def:1"/>
150 ········</cpe-lang:logical-test>155 ········</cpe-lang:logical-test>
151 ········<cpe-lang:logical-test·operator="AND"·negate="true">156 ········<cpe-lang:logical-test·operator="AND"·negate="true">
152 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>157 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_container:def:1"/>
153 ········</cpe-lang:logical-test>158 ········</cpe-lang:logical-test>
154 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/> 
155 ······</cpe-lang:logical-test> 
156 ····</cpe-lang:platform> 
157 ····<cpe-lang:platform·id="package_firewalld"> 
158 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
159 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/> 
160 ······</cpe-lang:logical-test> 
161 ····</cpe-lang:platform> 
162 ····<cpe-lang:platform·id="non-uefi"> 
163 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
164 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_non_uefi:def:1"/> 
165 ······</cpe-lang:logical-test>159 ······</cpe-lang:logical-test>
166 ····</cpe-lang:platform>160 ····</cpe-lang:platform>
167 ····<cpe-lang:platform·id="package_postfix">161 ····<cpe-lang:platform·id="package_iptables_and_service_disabled_firewalld_and_system_with_kernel">
168 ······<cpe-lang:logical-test·operator="AND"·negate="false">162 ······<cpe-lang:logical-test·operator="AND"·negate="false">
169 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_postfix:def:1"/>163 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
 164 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_firewalld:def:1"/>
 165 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
170 ······</cpe-lang:logical-test>166 ······</cpe-lang:logical-test>
171 ····</cpe-lang:platform>167 ····</cpe-lang:platform>
172 ····<cpe-lang:platform·id="package_audit">168 ····<cpe-lang:platform·id="aarch64_arch_or_x86_64_arch">
173 ······<cpe-lang:logical-test·operator="AND"·negate="false">169 ······<cpe-lang:logical-test·operator="OR"·negate="false">
 170 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
174 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_audit:def:1"/>171 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/>
175 ······</cpe-lang:logical-test>172 ······</cpe-lang:logical-test>
176 ····</cpe-lang:platform>173 ····</cpe-lang:platform>
177 ····<cpe-lang:platform·id="package_snmpd_and_system_with_kernel">174 ····<cpe-lang:platform·id="package_pam">
178 ······<cpe-lang:logical-test·operator="AND"·negate="false">175 ······<cpe-lang:logical-test·operator="AND"·negate="false">
179 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_snmpd:def:1"/>176 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>
180 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
Max diff block lines reached; 14830/28543 bytes (51.96%) of diff not shown.
1.03 MB
./usr/share/xml/scap/ssg/content/ssg-anolis8-ds.xml
1.03 MB
./usr/share/xml/scap/ssg/content/ssg-anolis8-ds.xml
    
Offset 19, 23 lines modifiedOffset 19, 23 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-anolis8-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-anolis8-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-anolis8-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-anolis8-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-anolis8-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-anolis8-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-anolis8-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-anolis8-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-anolis8-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-anolis8-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-anolis8-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-anolis8-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-anolis8-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-anolis8-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:anolis:anolis_os:8">28 ······<cpe-dict:cpe-item·name="cpe:/o:anolis:anolis_os:8">
29 ········<cpe-dict:title·xml:lang="en-us">Anolis·OS·8</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Anolis·OS·8</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml">oval:ssg-installed_OS_is_anolis8:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml">oval:ssg-installed_OS_is_anolis8:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ····</cpe-dict:cpe-list>32 ····</cpe-dict:cpe-list>
33 ··</ds:component>33 ··</ds:component>
34 ··<ds:component·id="scap_org.open-scap_comp_ssg-anolis8-xccdf.xml"·timestamp="2025-02-28T20:08:00">34 ··<ds:component·id="scap_org.open-scap_comp_ssg-anolis8-xccdf.xml"·timestamp="2025-03-01T22:08:00">
35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_ANOLIS-8"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_ANOLIS-8"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Anolis·OS·8</xccdf-1.2:title>37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Anolis·OS·8</xccdf-1.2:title>
38 ······<xccdf-1.2:description>38 ······<xccdf-1.2:description>
39 ········This·guide·presents·a·catalog·of·security-relevant39 ········This·guide·presents·a·catalog·of·security-relevant
40 configuration·settings·for·Anolis·OS·8.·It·is·a·rendering·of40 configuration·settings·for·Anolis·OS·8.·It·is·a·rendering·of
41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 104, 122 lines modifiedOffset 104, 118 lines modified
104 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>104 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
105 ······<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>105 ······<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
106 ······<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>106 ······<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
107 ······<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>107 ······<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
108 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>108 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
109 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>109 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
110 ······<cpe-lang:platform-specification>110 ······<cpe-lang:platform-specification>
111 ········<cpe-lang:platform·id="not_bootc">111 ········<cpe-lang:platform·id="package_autofs_and_system_with_kernel">
112 ··········<cpe-lang:logical-test·operator="AND"·negate="true">112 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
113 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-bootc:def:1"/>113 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>
 114 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
114 ··········</cpe-lang:logical-test>115 ··········</cpe-lang:logical-test>
115 ········</cpe-lang:platform>116 ········</cpe-lang:platform>
116 ········<cpe-lang:platform·id="machine">117 ········<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">
117 ··········<cpe-lang:logical-test·operator="AND"·negate="false">118 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 119 ············<cpe-lang:logical-test·operator="AND"·negate="true">
 120 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
 121 ············</cpe-lang:logical-test>
 122 ············<cpe-lang:logical-test·operator="AND"·negate="true">
 123 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
 124 ············</cpe-lang:logical-test>
118 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>125 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
119 ··········</cpe-lang:logical-test>126 ··········</cpe-lang:logical-test>
120 ········</cpe-lang:platform>127 ········</cpe-lang:platform>
121 ········<cpe-lang:platform·id="package_squid_and_system_with_kernel">128 ········<cpe-lang:platform·id="ipv6_enabled">
122 ··········<cpe-lang:logical-test·operator="AND"·negate="false">129 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
123 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_squid:def:1"/>130 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-ipv6_enabled:def:1"/>
124 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
125 ··········</cpe-lang:logical-test>131 ··········</cpe-lang:logical-test>
126 ········</cpe-lang:platform>132 ········</cpe-lang:platform>
127 ········<cpe-lang:platform·id="package_pam">133 ········<cpe-lang:platform·id="package_gdm">
128 ··········<cpe-lang:logical-test·operator="AND"·negate="false">134 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
129 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>135 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_gdm:def:1"/>
130 ··········</cpe-lang:logical-test>136 ··········</cpe-lang:logical-test>
131 ········</cpe-lang:platform>137 ········</cpe-lang:platform>
132 ········<cpe-lang:platform·id="package_autofs_and_system_with_kernel">138 ········<cpe-lang:platform·id="package_rsyslog">
133 ··········<cpe-lang:logical-test·operator="AND"·negate="false">139 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 140 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>
 141 ··········</cpe-lang:logical-test>
 142 ········</cpe-lang:platform>
 143 ········<cpe-lang:platform·id="package_bash">
 144 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
134 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>145 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>
135 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
136 ··········</cpe-lang:logical-test>146 ··········</cpe-lang:logical-test>
137 ········</cpe-lang:platform>147 ········</cpe-lang:platform>
138 ········<cpe-lang:platform·id="uefi">148 ········<cpe-lang:platform·id="uefi">
139 ··········<cpe-lang:logical-test·operator="AND"·negate="false">149 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
140 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>150 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>
141 ··········</cpe-lang:logical-test>151 ··········</cpe-lang:logical-test>
142 ········</cpe-lang:platform>152 ········</cpe-lang:platform>
143 ········<cpe-lang:platform·id="package_bash">153 ········<cpe-lang:platform·id="package_logrotate">
144 ··········<cpe-lang:logical-test·operator="AND"·negate="false">154 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
145 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>155 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_logrotate:def:1"/>
146 ··········</cpe-lang:logical-test>156 ··········</cpe-lang:logical-test>
147 ········</cpe-lang:platform>157 ········</cpe-lang:platform>
148 ········<cpe-lang:platform·id="package_iptables">158 ········<cpe-lang:platform·id="package_chrony">
149 ··········<cpe-lang:logical-test·operator="AND"·negate="false">159 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
150 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>160 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
151 ··········</cpe-lang:logical-test>161 ··········</cpe-lang:logical-test>
152 ········</cpe-lang:platform>162 ········</cpe-lang:platform>
153 ········<cpe-lang:platform·id="wifi-iface">163 ········<cpe-lang:platform·id="package_ufw_and_system_with_kernel">
154 ··········<cpe-lang:logical-test·operator="AND"·negate="false">164 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 165 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
155 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_wifi_interface:def:1"/>166 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
156 ··········</cpe-lang:logical-test>167 ··········</cpe-lang:logical-test>
157 ········</cpe-lang:platform>168 ········</cpe-lang:platform>
158 ········<cpe-lang:platform·id="package_rsyslog">169 ········<cpe-lang:platform·id="package_firewalld">
159 ··········<cpe-lang:logical-test·operator="AND"·negate="false">170 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
160 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>171 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>
161 ··········</cpe-lang:logical-test>172 ··········</cpe-lang:logical-test>
162 ········</cpe-lang:platform>173 ········</cpe-lang:platform>
163 ········<cpe-lang:platform·id="package_yum">174 ········<cpe-lang:platform·id="package_rsh-server">
164 ··········<cpe-lang:logical-test·operator="AND"·negate="false">175 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
165 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_yum:def:1"/>176 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_rsh-server:def:1"/>
166 ··········</cpe-lang:logical-test>177 ··········</cpe-lang:logical-test>
167 ········</cpe-lang:platform>178 ········</cpe-lang:platform>
168 ········<cpe-lang:platform·id="package_systemd">179 ········<cpe-lang:platform·id="package_systemd">
169 ··········<cpe-lang:logical-test·operator="AND"·negate="false">180 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
170 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>181 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>
171 ··········</cpe-lang:logical-test>182 ··········</cpe-lang:logical-test>
172 ········</cpe-lang:platform>183 ········</cpe-lang:platform>
 184 ········<cpe-lang:platform·id="not_bootc_and_not_container">
173 ········<cpe-lang:platform·id="package_avahi_and_system_with_kernel"> 
174 ··········<cpe-lang:logical-test·operator="AND"·negate="false"> 
175 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_avahi:def:1"/> 
176 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
177 ··········</cpe-lang:logical-test> 
178 ········</cpe-lang:platform> 
179 ········<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables"> 
180 ··········<cpe-lang:logical-test·operator="AND"·negate="false">185 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
181 ············<cpe-lang:logical-test·operator="AND"·negate="true">186 ············<cpe-lang:logical-test·operator="AND"·negate="true">
182 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>187 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-bootc:def:1"/>
183 ············</cpe-lang:logical-test>188 ············</cpe-lang:logical-test>
184 ············<cpe-lang:logical-test·operator="AND"·negate="true">189 ············<cpe-lang:logical-test·operator="AND"·negate="true">
185 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>190 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_container:def:1"/>
186 ············</cpe-lang:logical-test>191 ············</cpe-lang:logical-test>
187 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/> 
188 ··········</cpe-lang:logical-test> 
189 ········</cpe-lang:platform> 
190 ········<cpe-lang:platform·id="package_firewalld"> 
191 ··········<cpe-lang:logical-test·operator="AND"·negate="false"> 
192 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/> 
Max diff block lines reached; 1070888/1084621 bytes (98.73%) of diff not shown.
984 KB
./usr/share/xml/scap/ssg/content/ssg-anolis8-ocil.xml
984 KB
./usr/share/xml/scap/ssg/content/ssg-anolis8-ocil.xml
Ordering differences only
    
Offset 3, 5253 lines modifiedOffset 3, 5253 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_time_watch_localtime_ocil:questionnaire:1"> 
11 ······<ocil:title>Record·Attempts·to·Alter·the·localtime·File</ocil:title> 
12 ······<ocil:actions> 
13 ········<ocil:test_action_ref>ocil:ssg-audit_rules_time_watch_localtime_action:testaction:1</ocil:test_action_ref> 
14 ······</ocil:actions> 
15 ····</ocil:questionnaire> 
16 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_all_accept_ra_ocil:questionnaire:1"> 
17 ······<ocil:title>Configure·Accepting·Router·Advertisements·on·All·IPv6·Interfaces</ocil:title> 
18 ······<ocil:actions> 
19 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_all_accept_ra_action:testaction:1</ocil:test_action_ref> 
20 ······</ocil:actions> 
21 ····</ocil:questionnaire> 
22 ····<ocil:questionnaire·id="ocil:ssg-journald_forward_to_syslog_ocil:questionnaire:1"> 
23 ······<ocil:title>Ensure·journald·is·configured·to·send·logs·to·rsyslog</ocil:title> 
24 ······<ocil:actions> 
25 ········<ocil:test_action_ref>ocil:ssg-journald_forward_to_syslog_action:testaction:1</ocil:test_action_ref> 
26 ······</ocil:actions> 
27 ····</ocil:questionnaire> 
28 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_rhosts_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-auditd_freq_ocil:questionnaire:1">
29 ······<ocil:title>Disable·SSH·Support·for·.rhosts·Files</ocil:title>11 ······<ocil:title>Set·number·of·records·to·cause·an·explicit·flush·to·audit·logs</ocil:title>
30 ······<ocil:actions>12 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_rhosts_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-auditd_freq_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>14 ······</ocil:actions>
33 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-no_direct_root_logins_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-service_qpidd_disabled_ocil:questionnaire:1">
35 ······<ocil:title>Direct·root·Logins·Not·Allowed</ocil:title>17 ······<ocil:title>Disable·Apache·Qpid·(qpidd)</ocil:title>
36 ······<ocil:actions>18 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-no_direct_root_logins_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-service_qpidd_disabled_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>20 ······</ocil:actions>
39 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-partition_for_dev_shm_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_efi_grub2_cfg_ocil:questionnaire:1">
41 ······<ocil:title>Ensure·/dev/shm·is·configured</ocil:title>23 ······<ocil:title>Verify·the·UEFI·Boot·Loader·grub.cfg·Group·Ownership</ocil:title>
42 ······<ocil:actions>24 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-partition_for_dev_shm_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_efi_grub2_cfg_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>26 ······</ocil:actions>
45 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-sshd_set_max_auth_tries_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-no_shelllogin_for_systemaccounts_ocil:questionnaire:1">
47 ······<ocil:title>Set·SSH·authentication·attempt·limit</ocil:title>29 ······<ocil:title>Ensure·that·System·Accounts·Do·Not·Run·a·Shell·Upon·Login</ocil:title>
48 ······<ocil:actions>30 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-sshd_set_max_auth_tries_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-no_shelllogin_for_systemaccounts_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>32 ······</ocil:actions>
51 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-file_ownership_sshd_pub_key_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-package_audit_installed_ocil:questionnaire:1">
53 ······<ocil:title>Verify·Ownership·on·SSH·Server·Public·*.pub·Key·Files</ocil:title>35 ······<ocil:title>Ensure·the·audit·Subsystem·is·Installed</ocil:title>
54 ······<ocil:actions>36 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-file_ownership_sshd_pub_key_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-package_audit_installed_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>38 ······</ocil:actions>
57 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_issue_ocil:questionnaire:1"> 
59 ······<ocil:title>Verify·Group·Ownership·of·System·Login·Banner</ocil:title>40 ····<ocil:questionnaire·id="ocil:ssg-auditd_audispd_syslog_plugin_activated_ocil:questionnaire:1">
 41 ······<ocil:title>Configure·auditd·to·use·audispd's·syslog·plugin</ocil:title>
60 ······<ocil:actions>42 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_issue_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-auditd_audispd_syslog_plugin_activated_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>44 ······</ocil:actions>
63 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_secure_redirects_ocil:questionnaire:1"> 
65 ······<ocil:title>Disable·Kernel·Parameter·for·Accepting·Secure·ICMP·Redirects·on·all·IPv4·Interfaces</ocil:title>46 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_default_mmap_min_addr_ocil:questionnaire:1">
 47 ······<ocil:title>Configure·Low·Address·Space·To·Protect·From·User·Allocation</ocil:title>
66 ······<ocil:actions>48 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_secure_redirects_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-kernel_config_default_mmap_min_addr_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>50 ······</ocil:actions>
69 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_compat_vdso_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_efi_grub2_cfg_ocil:questionnaire:1">
71 ······<ocil:title>Disable·the·32-bit·vDSO</ocil:title>53 ······<ocil:title>Verify·the·UEFI·Boot·Loader·grub.cfg·Permissions</ocil:title>
72 ······<ocil:actions>54 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-kernel_config_compat_vdso_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-file_permissions_efi_grub2_cfg_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>56 ······</ocil:actions>
75 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_arp_ignore_ocil:questionnaire:1"> 
77 ······<ocil:title>Configure·Response·Mode·of·ARP·Requests·for·All·IPv4·Interfaces</ocil:title>58 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_media_export_ocil:questionnaire:1">
 59 ······<ocil:title>Ensure·auditd·Collects·Information·on·Exporting·to·Media·(successful)</ocil:title>
78 ······<ocil:actions>60 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_arp_ignore_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-audit_rules_media_export_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>62 ······</ocil:actions>
81 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-account_use_centralized_automated_auth_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-account_use_centralized_automated_auth_ocil:questionnaire:1">
83 ······<ocil:title>Use·Centralized·and·Automated·Authentication</ocil:title>65 ······<ocil:title>Use·Centralized·and·Automated·Authentication</ocil:title>
84 ······<ocil:actions>66 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-account_use_centralized_automated_auth_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-account_use_centralized_automated_auth_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>68 ······</ocil:actions>
87 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-service_ufw_enabled_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_pubkey_auth_ocil:questionnaire:1">
 71 ······<ocil:title>Disable·PubkeyAuthentication·Authentication</ocil:title>
89 ······<ocil:title>Verify·ufw·Enabled</ocil:title> 
90 ······<ocil:actions> 
91 ········<ocil:test_action_ref>ocil:ssg-service_ufw_enabled_action:testaction:1</ocil:test_action_ref> 
92 ······</ocil:actions> 
93 ····</ocil:questionnaire> 
94 ····<ocil:questionnaire·id="ocil:ssg-account_passwords_pam_faillock_dir_ocil:questionnaire:1"> 
95 ······<ocil:title>Account·Lockouts·Must·Persist</ocil:title> 
96 ······<ocil:actions>72 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-account_passwords_pam_faillock_dir_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_pubkey_auth_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>74 ······</ocil:actions>
99 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_all_disable_ipv6_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-partition_for_tmp_ocil:questionnaire:1">
101 ······<ocil:title>Disable·IPv6·Addressing·on·All·IPv6·Interfaces</ocil:title>77 ······<ocil:title>Ensure·/tmp·Located·On·Separate·Partition</ocil:title>
102 ······<ocil:actions>78 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_all_disable_ipv6_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-partition_for_tmp_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>80 ······</ocil:actions>
105 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_randomize_memory_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-account_unique_id_ocil:questionnaire:1">
107 ······<ocil:title>Randomize·the·kernel·memory·sections</ocil:title>83 ······<ocil:title>Ensure·All·Accounts·on·the·System·Have·Unique·User·IDs</ocil:title>
108 ······<ocil:actions>84 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-kernel_config_randomize_memory_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-account_unique_id_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>86 ······</ocil:actions>
111 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_debug_list_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_time_clock_settime_ocil:questionnaire:1">
113 ······<ocil:title>Enable·checks·on·linked·list·manipulation</ocil:title>89 ······<ocil:title>Record·Attempts·to·Alter·Time·Through·clock_settime</ocil:title>
114 ······<ocil:actions>90 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-kernel_config_debug_list_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-audit_rules_time_clock_settime_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>92 ······</ocil:actions>
117 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_icmp_echo_ignore_broadcasts_ocil:questionnaire:1"> 
119 ······<ocil:title>Enable·Kernel·Parameter·to·Ignore·ICMP·Broadcast·Echo·Requests·on·IPv4·Interfaces</ocil:title>94 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_file_deletion_events_ocil:questionnaire:1">
 95 ······<ocil:title>Ensure·auditd·Collects·File·Deletion·Events·by·User</ocil:title>
120 ······<ocil:actions>96 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_icmp_echo_ignore_broadcasts_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-audit_rules_file_deletion_events_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>98 ······</ocil:actions>
123 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
124 ····<ocil:questionnaire·id="ocil:ssg-partition_for_srv_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_backup_etc_group_ocil:questionnaire:1">
Max diff block lines reached; 995878/1007233 bytes (98.87%) of diff not shown.
28.0 KB
./usr/share/xml/scap/ssg/content/ssg-anolis8-xccdf.xml
27.9 KB
./usr/share/xml/scap/ssg/content/ssg-anolis8-xccdf.xml
Ordering differences only
    
Offset 71, 122 lines modifiedOffset 71, 118 lines modified
71 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>71 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
72 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>72 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
73 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>73 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
74 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>74 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
75 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>75 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
77 ··<cpe-lang:platform-specification>77 ··<cpe-lang:platform-specification>
78 ····<cpe-lang:platform·id="not_bootc">78 ····<cpe-lang:platform·id="package_autofs_and_system_with_kernel">
79 ······<cpe-lang:logical-test·operator="AND"·negate="true">79 ······<cpe-lang:logical-test·operator="AND"·negate="false">
80 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-bootc:def:1"/>80 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>
 81 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
81 ······</cpe-lang:logical-test>82 ······</cpe-lang:logical-test>
82 ····</cpe-lang:platform>83 ····</cpe-lang:platform>
83 ····<cpe-lang:platform·id="machine">84 ····<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">
84 ······<cpe-lang:logical-test·operator="AND"·negate="false">85 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 86 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 87 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
 88 ········</cpe-lang:logical-test>
 89 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 90 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
 91 ········</cpe-lang:logical-test>
85 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>92 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
86 ······</cpe-lang:logical-test>93 ······</cpe-lang:logical-test>
87 ····</cpe-lang:platform>94 ····</cpe-lang:platform>
88 ····<cpe-lang:platform·id="package_squid_and_system_with_kernel">95 ····<cpe-lang:platform·id="ipv6_enabled">
89 ······<cpe-lang:logical-test·operator="AND"·negate="false">96 ······<cpe-lang:logical-test·operator="AND"·negate="false">
90 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_squid:def:1"/>97 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-ipv6_enabled:def:1"/>
91 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
92 ······</cpe-lang:logical-test>98 ······</cpe-lang:logical-test>
93 ····</cpe-lang:platform>99 ····</cpe-lang:platform>
94 ····<cpe-lang:platform·id="package_pam">100 ····<cpe-lang:platform·id="package_gdm">
95 ······<cpe-lang:logical-test·operator="AND"·negate="false">101 ······<cpe-lang:logical-test·operator="AND"·negate="false">
96 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>102 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_gdm:def:1"/>
97 ······</cpe-lang:logical-test>103 ······</cpe-lang:logical-test>
98 ····</cpe-lang:platform>104 ····</cpe-lang:platform>
99 ····<cpe-lang:platform·id="package_autofs_and_system_with_kernel">105 ····<cpe-lang:platform·id="package_rsyslog">
100 ······<cpe-lang:logical-test·operator="AND"·negate="false">106 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 107 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>
 108 ······</cpe-lang:logical-test>
 109 ····</cpe-lang:platform>
 110 ····<cpe-lang:platform·id="package_bash">
 111 ······<cpe-lang:logical-test·operator="AND"·negate="false">
101 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>112 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>
102 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
103 ······</cpe-lang:logical-test>113 ······</cpe-lang:logical-test>
104 ····</cpe-lang:platform>114 ····</cpe-lang:platform>
105 ····<cpe-lang:platform·id="uefi">115 ····<cpe-lang:platform·id="uefi">
106 ······<cpe-lang:logical-test·operator="AND"·negate="false">116 ······<cpe-lang:logical-test·operator="AND"·negate="false">
107 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>117 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>
108 ······</cpe-lang:logical-test>118 ······</cpe-lang:logical-test>
109 ····</cpe-lang:platform>119 ····</cpe-lang:platform>
110 ····<cpe-lang:platform·id="package_bash">120 ····<cpe-lang:platform·id="package_logrotate">
111 ······<cpe-lang:logical-test·operator="AND"·negate="false">121 ······<cpe-lang:logical-test·operator="AND"·negate="false">
112 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>122 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_logrotate:def:1"/>
113 ······</cpe-lang:logical-test>123 ······</cpe-lang:logical-test>
114 ····</cpe-lang:platform>124 ····</cpe-lang:platform>
115 ····<cpe-lang:platform·id="package_iptables">125 ····<cpe-lang:platform·id="package_chrony">
116 ······<cpe-lang:logical-test·operator="AND"·negate="false">126 ······<cpe-lang:logical-test·operator="AND"·negate="false">
117 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>127 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
118 ······</cpe-lang:logical-test>128 ······</cpe-lang:logical-test>
119 ····</cpe-lang:platform>129 ····</cpe-lang:platform>
120 ····<cpe-lang:platform·id="wifi-iface">130 ····<cpe-lang:platform·id="package_ufw_and_system_with_kernel">
121 ······<cpe-lang:logical-test·operator="AND"·negate="false">131 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 132 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
122 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_wifi_interface:def:1"/>133 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
123 ······</cpe-lang:logical-test>134 ······</cpe-lang:logical-test>
124 ····</cpe-lang:platform>135 ····</cpe-lang:platform>
125 ····<cpe-lang:platform·id="package_rsyslog">136 ····<cpe-lang:platform·id="package_firewalld">
126 ······<cpe-lang:logical-test·operator="AND"·negate="false">137 ······<cpe-lang:logical-test·operator="AND"·negate="false">
127 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>138 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>
128 ······</cpe-lang:logical-test>139 ······</cpe-lang:logical-test>
129 ····</cpe-lang:platform>140 ····</cpe-lang:platform>
130 ····<cpe-lang:platform·id="package_yum">141 ····<cpe-lang:platform·id="package_rsh-server">
131 ······<cpe-lang:logical-test·operator="AND"·negate="false">142 ······<cpe-lang:logical-test·operator="AND"·negate="false">
132 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_yum:def:1"/>143 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_rsh-server:def:1"/>
133 ······</cpe-lang:logical-test>144 ······</cpe-lang:logical-test>
134 ····</cpe-lang:platform>145 ····</cpe-lang:platform>
135 ····<cpe-lang:platform·id="package_systemd">146 ····<cpe-lang:platform·id="package_systemd">
136 ······<cpe-lang:logical-test·operator="AND"·negate="false">147 ······<cpe-lang:logical-test·operator="AND"·negate="false">
137 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>148 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>
138 ······</cpe-lang:logical-test>149 ······</cpe-lang:logical-test>
139 ····</cpe-lang:platform>150 ····</cpe-lang:platform>
 151 ····<cpe-lang:platform·id="not_bootc_and_not_container">
140 ····<cpe-lang:platform·id="package_avahi_and_system_with_kernel"> 
141 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
142 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_avahi:def:1"/> 
143 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
144 ······</cpe-lang:logical-test> 
145 ····</cpe-lang:platform> 
146 ····<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables"> 
147 ······<cpe-lang:logical-test·operator="AND"·negate="false">152 ······<cpe-lang:logical-test·operator="AND"·negate="false">
148 ········<cpe-lang:logical-test·operator="AND"·negate="true">153 ········<cpe-lang:logical-test·operator="AND"·negate="true">
149 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>154 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-bootc:def:1"/>
150 ········</cpe-lang:logical-test>155 ········</cpe-lang:logical-test>
151 ········<cpe-lang:logical-test·operator="AND"·negate="true">156 ········<cpe-lang:logical-test·operator="AND"·negate="true">
152 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>157 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_container:def:1"/>
153 ········</cpe-lang:logical-test>158 ········</cpe-lang:logical-test>
154 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/> 
155 ······</cpe-lang:logical-test> 
156 ····</cpe-lang:platform> 
157 ····<cpe-lang:platform·id="package_firewalld"> 
158 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
159 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/> 
160 ······</cpe-lang:logical-test> 
161 ····</cpe-lang:platform> 
162 ····<cpe-lang:platform·id="non-uefi"> 
163 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
164 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_non_uefi:def:1"/> 
165 ······</cpe-lang:logical-test>159 ······</cpe-lang:logical-test>
166 ····</cpe-lang:platform>160 ····</cpe-lang:platform>
167 ····<cpe-lang:platform·id="package_postfix">161 ····<cpe-lang:platform·id="package_iptables_and_service_disabled_firewalld_and_system_with_kernel">
168 ······<cpe-lang:logical-test·operator="AND"·negate="false">162 ······<cpe-lang:logical-test·operator="AND"·negate="false">
169 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_postfix:def:1"/>163 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
 164 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_firewalld:def:1"/>
 165 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
170 ······</cpe-lang:logical-test>166 ······</cpe-lang:logical-test>
171 ····</cpe-lang:platform>167 ····</cpe-lang:platform>
172 ····<cpe-lang:platform·id="package_audit">168 ····<cpe-lang:platform·id="aarch64_arch_or_x86_64_arch">
173 ······<cpe-lang:logical-test·operator="AND"·negate="false">169 ······<cpe-lang:logical-test·operator="OR"·negate="false">
 170 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
174 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_audit:def:1"/>171 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/>
175 ······</cpe-lang:logical-test>172 ······</cpe-lang:logical-test>
176 ····</cpe-lang:platform>173 ····</cpe-lang:platform>
177 ····<cpe-lang:platform·id="package_snmpd_and_system_with_kernel">174 ····<cpe-lang:platform·id="package_pam">
178 ······<cpe-lang:logical-test·operator="AND"·negate="false">175 ······<cpe-lang:logical-test·operator="AND"·negate="false">
179 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_snmpd:def:1"/>176 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>
180 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
Max diff block lines reached; 14780/28445 bytes (51.96%) of diff not shown.
4.0 MB
./usr/share/xml/scap/ssg/content/ssg-centos8-ds.xml
4.0 MB
./usr/share/xml/scap/ssg/content/ssg-centos8-ds.xml
    
Offset 19, 15 lines modifiedOffset 19, 15 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel8-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel8-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel8-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel8-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel8-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel8-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel8-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel8-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel8-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel8-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel8-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel8-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel8-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel8-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux:8">28 ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux:8">
29 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Enterprise·Linux·8</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Enterprise·Linux·8</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml">oval:ssg-installed_OS_is_rhel8:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml">oval:ssg-installed_OS_is_rhel8:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux:8.0">32 ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux:8.0">
33 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Enterprise·Linux·8.0</cpe-dict:title>33 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Enterprise·Linux·8.0</cpe-dict:title>
Offset 75, 15 lines modifiedOffset 75, 15 lines modified
75 ······</cpe-dict:cpe-item>75 ······</cpe-dict:cpe-item>
76 ······<cpe-dict:cpe-item·name="cpe:/o:centos:centos:8">76 ······<cpe-dict:cpe-item·name="cpe:/o:centos:centos:8">
77 ········<cpe-dict:title·xml:lang="en-us">CentOS·8</cpe-dict:title>77 ········<cpe-dict:title·xml:lang="en-us">CentOS·8</cpe-dict:title>
78 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml">oval:ssg-installed_OS_is_centos8:def:1</cpe-dict:check>78 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml">oval:ssg-installed_OS_is_centos8:def:1</cpe-dict:check>
79 ······</cpe-dict:cpe-item>79 ······</cpe-dict:cpe-item>
80 ····</cpe-dict:cpe-list>80 ····</cpe-dict:cpe-list>
81 ··</ds:component>81 ··</ds:component>
82 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel8-xccdf.xml"·timestamp="2025-02-28T20:08:00">82 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel8-xccdf.xml"·timestamp="2025-03-01T22:08:00">
83 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_RHEL-8"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">83 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_RHEL-8"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
84 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>84 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
85 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Red·Hat·Enterprise·Linux·8</xccdf-1.2:title>85 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Red·Hat·Enterprise·Linux·8</xccdf-1.2:title>
86 ······<xccdf-1.2:description>86 ······<xccdf-1.2:description>
87 ········This·guide·presents·a·catalog·of·security-relevant87 ········This·guide·presents·a·catalog·of·security-relevant
88 configuration·settings·for·Red·Hat·Enterprise·Linux·8.·It·is·a·rendering·of88 configuration·settings·for·Red·Hat·Enterprise·Linux·8.·It·is·a·rendering·of
89 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)89 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 203, 264 lines modifiedOffset 203, 223 lines modified
203 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>203 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
204 ······<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>204 ······<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
205 ······<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>205 ······<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
206 ······<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>206 ······<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
207 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>207 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
208 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>208 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
209 ······<cpe-lang:platform-specification>209 ······<cpe-lang:platform-specification>
 210 ········<cpe-lang:platform·id="not_aarch64_arch_and_not_ppc64le_arch_and_system_with_kernel">
210 ········<cpe-lang:platform·id="package_libuser"> 
211 ··········<cpe-lang:logical-test·operator="AND"·negate="false"> 
212 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-package_libuser:def:1"/> 
213 ··········</cpe-lang:logical-test> 
214 ········</cpe-lang:platform> 
215 ········<cpe-lang:platform·id="not_bootc"> 
216 ··········<cpe-lang:logical-test·operator="AND"·negate="true"> 
217 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-bootc:def:1"/> 
218 ··········</cpe-lang:logical-test> 
219 ········</cpe-lang:platform> 
220 ········<cpe-lang:platform·id="package_nftables_and_service_disabled_firewalld_and_system_with_kernel"> 
221 ··········<cpe-lang:logical-test·operator="AND"·negate="false">211 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 212 ············<cpe-lang:logical-test·operator="AND"·negate="true">
 213 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
 214 ············</cpe-lang:logical-test>
 215 ············<cpe-lang:logical-test·operator="AND"·negate="true">
222 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>216 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_ppc64le:def:1"/>
223 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_firewalld:def:1"/>217 ············</cpe-lang:logical-test>
224 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>218 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
225 ··········</cpe-lang:logical-test>219 ··········</cpe-lang:logical-test>
226 ········</cpe-lang:platform>220 ········</cpe-lang:platform>
227 ········<cpe-lang:platform·id="machine">221 ········<cpe-lang:platform·id="not_runtime_kernel_fips_enabled_and_system_with_kernel">
228 ··········<cpe-lang:logical-test·operator="AND"·negate="false">222 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 223 ············<cpe-lang:logical-test·operator="AND"·negate="true">
 224 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-runtime_kernel_fips_enabled:def:1"/>
 225 ············</cpe-lang:logical-test>
229 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>226 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
230 ··········</cpe-lang:logical-test>227 ··········</cpe-lang:logical-test>
231 ········</cpe-lang:platform>228 ········</cpe-lang:platform>
232 ········<cpe-lang:platform·id="package_squid_and_system_with_kernel">229 ········<cpe-lang:platform·id="package_polkit">
233 ··········<cpe-lang:logical-test·operator="AND"·negate="false">230 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
234 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-package_squid:def:1"/>231 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-package_polkit:def:1"/>
235 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
236 ··········</cpe-lang:logical-test>232 ··········</cpe-lang:logical-test>
237 ········</cpe-lang:platform>233 ········</cpe-lang:platform>
238 ········<cpe-lang:platform·id="package_pam">234 ········<cpe-lang:platform·id="mount_var-tmp">
239 ··········<cpe-lang:logical-test·operator="AND"·negate="false">235 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
240 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>236 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-tmp:def:1"/>
241 ··········</cpe-lang:logical-test>237 ··········</cpe-lang:logical-test>
242 ········</cpe-lang:platform>238 ········</cpe-lang:platform>
243 ········<cpe-lang:platform·id="package_autofs_and_system_with_kernel">239 ········<cpe-lang:platform·id="package_autofs_and_system_with_kernel">
244 ··········<cpe-lang:logical-test·operator="AND"·negate="false">240 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
245 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>241 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>
246 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>242 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
247 ··········</cpe-lang:logical-test>243 ··········</cpe-lang:logical-test>
248 ········</cpe-lang:platform>244 ········</cpe-lang:platform>
249 ········<cpe-lang:platform·id="mount_tmp">245 ········<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">
250 ··········<cpe-lang:logical-test·operator="AND"·negate="false">246 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 247 ············<cpe-lang:logical-test·operator="AND"·negate="true">
 248 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
 249 ············</cpe-lang:logical-test>
 250 ············<cpe-lang:logical-test·operator="AND"·negate="true">
251 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_tmp:def:1"/>251 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
 252 ············</cpe-lang:logical-test>
 253 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
252 ··········</cpe-lang:logical-test>254 ··········</cpe-lang:logical-test>
253 ········</cpe-lang:platform>255 ········</cpe-lang:platform>
254 ········<cpe-lang:platform·id="package_firewalld_and_package_nftables_and_system_with_kernel">256 ········<cpe-lang:platform·id="ipv6_enabled">
255 ··········<cpe-lang:logical-test·operator="AND"·negate="false">257 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
256 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/> 
257 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>258 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-ipv6_enabled:def:1"/>
258 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
259 ··········</cpe-lang:logical-test>259 ··········</cpe-lang:logical-test>
260 ········</cpe-lang:platform>260 ········</cpe-lang:platform>
261 ········<cpe-lang:platform·id="not_s390x_arch">261 ········<cpe-lang:platform·id="package_gdm">
262 ··········<cpe-lang:logical-test·operator="AND"·negate="false">262 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
263 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>263 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-package_gdm:def:1"/>
264 ··········</cpe-lang:logical-test>264 ··········</cpe-lang:logical-test>
265 ········</cpe-lang:platform>265 ········</cpe-lang:platform>
266 ········<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">266 ········<cpe-lang:platform·id="package_rsyslog">
267 ··········<cpe-lang:logical-test·operator="AND"·negate="false">267 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
268 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>268 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>
269 ··········</cpe-lang:logical-test>269 ··········</cpe-lang:logical-test>
270 ········</cpe-lang:platform>270 ········</cpe-lang:platform>
271 ········<cpe-lang:platform·id="mount_var-log">271 ········<cpe-lang:platform·id="not_osbuild_and_system_with_kernel">
272 ··········<cpe-lang:logical-test·operator="AND"·negate="false">272 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 273 ············<cpe-lang:logical-test·operator="AND"·negate="true">
273 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-log:def:1"/>274 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_osbuild:def:1"/>
 275 ············</cpe-lang:logical-test>
 276 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
274 ··········</cpe-lang:logical-test>277 ··········</cpe-lang:logical-test>
275 ········</cpe-lang:platform>278 ········</cpe-lang:platform>
276 ········<cpe-lang:platform·id="uefi">279 ········<cpe-lang:platform·id="package_chrony_or_package_ntp">
277 ··········<cpe-lang:logical-test·operator="AND"·negate="false">280 ··········<cpe-lang:logical-test·operator="OR"·negate="false">
 281 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
278 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>282 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-package_ntp:def:1"/>
279 ··········</cpe-lang:logical-test>283 ··········</cpe-lang:logical-test>
Max diff block lines reached; 4184363/4197758 bytes (99.68%) of diff not shown.
590 KB
./usr/share/xml/scap/ssg/content/ssg-centos8-xccdf.xml
590 KB
./usr/share/xml/scap/ssg/content/ssg-centos8-xccdf.xml
Ordering differences only
    
Offset 122, 264 lines modifiedOffset 122, 223 lines modified
122 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>122 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
123 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>123 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
124 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>124 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
125 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>125 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
126 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>126 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
127 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>127 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
128 ··<cpe-lang:platform-specification>128 ··<cpe-lang:platform-specification>
 129 ····<cpe-lang:platform·id="not_aarch64_arch_and_not_ppc64le_arch_and_system_with_kernel">
129 ····<cpe-lang:platform·id="package_libuser"> 
130 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
131 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-package_libuser:def:1"/> 
132 ······</cpe-lang:logical-test> 
133 ····</cpe-lang:platform> 
134 ····<cpe-lang:platform·id="not_bootc"> 
135 ······<cpe-lang:logical-test·operator="AND"·negate="true"> 
136 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-bootc:def:1"/> 
137 ······</cpe-lang:logical-test> 
138 ····</cpe-lang:platform> 
139 ····<cpe-lang:platform·id="package_nftables_and_service_disabled_firewalld_and_system_with_kernel"> 
140 ······<cpe-lang:logical-test·operator="AND"·negate="false">130 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 131 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 132 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
 133 ········</cpe-lang:logical-test>
 134 ········<cpe-lang:logical-test·operator="AND"·negate="true">
141 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>135 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_ppc64le:def:1"/>
142 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_firewalld:def:1"/>136 ········</cpe-lang:logical-test>
143 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>137 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
144 ······</cpe-lang:logical-test>138 ······</cpe-lang:logical-test>
145 ····</cpe-lang:platform>139 ····</cpe-lang:platform>
146 ····<cpe-lang:platform·id="machine">140 ····<cpe-lang:platform·id="not_runtime_kernel_fips_enabled_and_system_with_kernel">
147 ······<cpe-lang:logical-test·operator="AND"·negate="false">141 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 142 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 143 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-runtime_kernel_fips_enabled:def:1"/>
 144 ········</cpe-lang:logical-test>
148 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>145 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
149 ······</cpe-lang:logical-test>146 ······</cpe-lang:logical-test>
150 ····</cpe-lang:platform>147 ····</cpe-lang:platform>
151 ····<cpe-lang:platform·id="package_squid_and_system_with_kernel">148 ····<cpe-lang:platform·id="package_polkit">
152 ······<cpe-lang:logical-test·operator="AND"·negate="false">149 ······<cpe-lang:logical-test·operator="AND"·negate="false">
153 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-package_squid:def:1"/>150 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-package_polkit:def:1"/>
154 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
155 ······</cpe-lang:logical-test>151 ······</cpe-lang:logical-test>
156 ····</cpe-lang:platform>152 ····</cpe-lang:platform>
157 ····<cpe-lang:platform·id="package_pam">153 ····<cpe-lang:platform·id="mount_var-tmp">
158 ······<cpe-lang:logical-test·operator="AND"·negate="false">154 ······<cpe-lang:logical-test·operator="AND"·negate="false">
159 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>155 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-tmp:def:1"/>
160 ······</cpe-lang:logical-test>156 ······</cpe-lang:logical-test>
161 ····</cpe-lang:platform>157 ····</cpe-lang:platform>
162 ····<cpe-lang:platform·id="package_autofs_and_system_with_kernel">158 ····<cpe-lang:platform·id="package_autofs_and_system_with_kernel">
163 ······<cpe-lang:logical-test·operator="AND"·negate="false">159 ······<cpe-lang:logical-test·operator="AND"·negate="false">
164 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>160 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>
165 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>161 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
166 ······</cpe-lang:logical-test>162 ······</cpe-lang:logical-test>
167 ····</cpe-lang:platform>163 ····</cpe-lang:platform>
168 ····<cpe-lang:platform·id="mount_tmp">164 ····<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">
169 ······<cpe-lang:logical-test·operator="AND"·negate="false">165 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 166 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 167 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
 168 ········</cpe-lang:logical-test>
 169 ········<cpe-lang:logical-test·operator="AND"·negate="true">
170 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_tmp:def:1"/>170 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
 171 ········</cpe-lang:logical-test>
 172 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
171 ······</cpe-lang:logical-test>173 ······</cpe-lang:logical-test>
172 ····</cpe-lang:platform>174 ····</cpe-lang:platform>
173 ····<cpe-lang:platform·id="package_firewalld_and_package_nftables_and_system_with_kernel">175 ····<cpe-lang:platform·id="ipv6_enabled">
174 ······<cpe-lang:logical-test·operator="AND"·negate="false">176 ······<cpe-lang:logical-test·operator="AND"·negate="false">
175 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/> 
176 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>177 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-ipv6_enabled:def:1"/>
177 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
178 ······</cpe-lang:logical-test>178 ······</cpe-lang:logical-test>
179 ····</cpe-lang:platform>179 ····</cpe-lang:platform>
180 ····<cpe-lang:platform·id="not_s390x_arch">180 ····<cpe-lang:platform·id="package_gdm">
181 ······<cpe-lang:logical-test·operator="AND"·negate="false">181 ······<cpe-lang:logical-test·operator="AND"·negate="false">
182 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>182 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-package_gdm:def:1"/>
183 ······</cpe-lang:logical-test>183 ······</cpe-lang:logical-test>
184 ····</cpe-lang:platform>184 ····</cpe-lang:platform>
185 ····<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">185 ····<cpe-lang:platform·id="package_rsyslog">
186 ······<cpe-lang:logical-test·operator="AND"·negate="false">186 ······<cpe-lang:logical-test·operator="AND"·negate="false">
187 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>187 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>
188 ······</cpe-lang:logical-test>188 ······</cpe-lang:logical-test>
189 ····</cpe-lang:platform>189 ····</cpe-lang:platform>
190 ····<cpe-lang:platform·id="mount_var-log">190 ····<cpe-lang:platform·id="not_osbuild_and_system_with_kernel">
191 ······<cpe-lang:logical-test·operator="AND"·negate="false">191 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 192 ········<cpe-lang:logical-test·operator="AND"·negate="true">
192 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-log:def:1"/>193 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_osbuild:def:1"/>
 194 ········</cpe-lang:logical-test>
 195 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
193 ······</cpe-lang:logical-test>196 ······</cpe-lang:logical-test>
194 ····</cpe-lang:platform>197 ····</cpe-lang:platform>
195 ····<cpe-lang:platform·id="uefi">198 ····<cpe-lang:platform·id="package_chrony_or_package_ntp">
196 ······<cpe-lang:logical-test·operator="AND"·negate="false">199 ······<cpe-lang:logical-test·operator="OR"·negate="false">
 200 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
197 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>201 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-package_ntp:def:1"/>
198 ······</cpe-lang:logical-test>202 ······</cpe-lang:logical-test>
199 ····</cpe-lang:platform>203 ····</cpe-lang:platform>
200 ····<cpe-lang:platform·id="package_bash">204 ····<cpe-lang:platform·id="os_linux_rhel_le_or_eq_8_3">
201 ······<cpe-lang:logical-test·operator="AND"·negate="false">205 ······<cpe-lang:logical-test·operator="AND"·negate="false">
202 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>206 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_le_or_eq_8_3:def:1"/>
203 ······</cpe-lang:logical-test>207 ······</cpe-lang:logical-test>
204 ····</cpe-lang:platform>208 ····</cpe-lang:platform>
205 ····<cpe-lang:platform·id="package_telnet-server_and_system_with_kernel">209 ····<cpe-lang:platform·id="package_bash">
206 ······<cpe-lang:logical-test·operator="AND"·negate="false">210 ······<cpe-lang:logical-test·operator="AND"·negate="false">
207 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-package_telnet-server:def:1"/>211 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>
208 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
209 ······</cpe-lang:logical-test>212 ······</cpe-lang:logical-test>
210 ····</cpe-lang:platform>213 ····</cpe-lang:platform>
211 ····<cpe-lang:platform·id="package_iptables">214 ····<cpe-lang:platform·id="uefi">
212 ······<cpe-lang:logical-test·operator="AND"·negate="false">215 ······<cpe-lang:logical-test·operator="AND"·negate="false">
213 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>216 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>
214 ······</cpe-lang:logical-test>217 ······</cpe-lang:logical-test>
215 ····</cpe-lang:platform>218 ····</cpe-lang:platform>
216 ····<cpe-lang:platform·id="krb5_server_older_than_1_17-18_and_krb5_workstation_older_than_1_17-18">219 ····<cpe-lang:platform·id="package_logrotate">
217 ······<cpe-lang:logical-test·operator="AND"·negate="false">220 ······<cpe-lang:logical-test·operator="AND"·negate="false">
218 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-krb5_server_older_than_1_17_18:def:1"/> 
219 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-krb5_workstation_older_than_1_17_18:def:1"/>221 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-package_logrotate:def:1"/>
220 ······</cpe-lang:logical-test>222 ······</cpe-lang:logical-test>
221 ····</cpe-lang:platform>223 ····</cpe-lang:platform>
222 ····<cpe-lang:platform·id="grub2">224 ····<cpe-lang:platform·id="package_chrony">
223 ······<cpe-lang:logical-test·operator="AND"·negate="false">225 ······<cpe-lang:logical-test·operator="AND"·negate="false">
224 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>226 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
225 ······</cpe-lang:logical-test>227 ······</cpe-lang:logical-test>
226 ····</cpe-lang:platform>228 ····</cpe-lang:platform>
227 ····<cpe-lang:platform·id="package_sssd">229 ····<cpe-lang:platform·id="package_sssd">
228 ······<cpe-lang:logical-test·operator="AND"·negate="false">230 ······<cpe-lang:logical-test·operator="AND"·negate="false">
229 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-package_sssd:def:1"/>231 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-package_sssd:def:1"/>
230 ······</cpe-lang:logical-test>232 ······</cpe-lang:logical-test>
Max diff block lines reached; 589840/603682 bytes (97.71%) of diff not shown.
2.5 MB
./usr/share/xml/scap/ssg/content/ssg-cs10-ds.xml
2.5 MB
./usr/share/xml/scap/ssg/content/ssg-cs10-ds.xml
    
Offset 19, 27 lines modifiedOffset 19, 27 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel10-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel10-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel10-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel10-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel10-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel10-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel10-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel10-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel10-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel10-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel10-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel10-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel10-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel10-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux:10">28 ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux:10">
29 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Enterprise·Linux·10</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Enterprise·Linux·10</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml">oval:ssg-installed_OS_is_rhel10:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml">oval:ssg-installed_OS_is_rhel10:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ······<cpe-dict:cpe-item·name="cpe:/o:centos:centos:10">32 ······<cpe-dict:cpe-item·name="cpe:/o:centos:centos:10">
33 ········<cpe-dict:title·xml:lang="en-us">CentOS·Stream·10</cpe-dict:title>33 ········<cpe-dict:title·xml:lang="en-us">CentOS·Stream·10</cpe-dict:title>
34 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml">oval:ssg-installed_OS_is_centos10:def:1</cpe-dict:check>34 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml">oval:ssg-installed_OS_is_centos10:def:1</cpe-dict:check>
35 ······</cpe-dict:cpe-item>35 ······</cpe-dict:cpe-item>
36 ····</cpe-dict:cpe-list>36 ····</cpe-dict:cpe-list>
37 ··</ds:component>37 ··</ds:component>
38 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel10-xccdf.xml"·timestamp="2025-02-28T20:08:00">38 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel10-xccdf.xml"·timestamp="2025-03-01T22:08:00">
39 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_RHEL-10"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">39 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_RHEL-10"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
40 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>40 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
41 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Red·Hat·Enterprise·Linux·10</xccdf-1.2:title>41 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Red·Hat·Enterprise·Linux·10</xccdf-1.2:title>
42 ······<xccdf-1.2:description>42 ······<xccdf-1.2:description>
43 ········This·guide·presents·a·catalog·of·security-relevant43 ········This·guide·presents·a·catalog·of·security-relevant
44 configuration·settings·for·Red·Hat·Enterprise·Linux·10.·It·is·a·rendering·of44 configuration·settings·for·Red·Hat·Enterprise·Linux·10.·It·is·a·rendering·of
45 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)45 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 159, 402 lines modifiedOffset 159, 402 lines modified
159 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>159 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
160 ······<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>160 ······<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
161 ······<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>161 ······<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
162 ······<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>162 ······<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
163 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>163 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
164 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>164 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
165 ······<cpe-lang:platform-specification>165 ······<cpe-lang:platform-specification>
166 ········<cpe-lang:platform·id="package_libuser">166 ········<cpe-lang:platform·id="not_aarch64_arch_and_not_ppc64le_arch_and_system_with_kernel">
167 ··········<cpe-lang:logical-test·operator="AND"·negate="false">167 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
168 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_libuser:def:1"/> 
169 ··········</cpe-lang:logical-test> 
170 ········</cpe-lang:platform> 
171 ········<cpe-lang:platform·id="not_bootc"> 
172 ··········<cpe-lang:logical-test·operator="AND"·negate="true">168 ············<cpe-lang:logical-test·operator="AND"·negate="true">
 169 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
 170 ············</cpe-lang:logical-test>
 171 ············<cpe-lang:logical-test·operator="AND"·negate="true">
 172 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_ppc64le:def:1"/>
 173 ············</cpe-lang:logical-test>
173 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-bootc:def:1"/>174 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
174 ··········</cpe-lang:logical-test>175 ··········</cpe-lang:logical-test>
175 ········</cpe-lang:platform>176 ········</cpe-lang:platform>
176 ········<cpe-lang:platform·id="machine">177 ········<cpe-lang:platform·id="package_polkit">
177 ··········<cpe-lang:logical-test·operator="AND"·negate="false">178 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
178 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>179 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_polkit:def:1"/>
179 ··········</cpe-lang:logical-test>180 ··········</cpe-lang:logical-test>
180 ········</cpe-lang:platform>181 ········</cpe-lang:platform>
181 ········<cpe-lang:platform·id="package_squid_and_system_with_kernel">182 ········<cpe-lang:platform·id="mount_var-tmp">
182 ··········<cpe-lang:logical-test·operator="AND"·negate="false">183 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
183 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_squid:def:1"/> 
184 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>184 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-tmp:def:1"/>
185 ··········</cpe-lang:logical-test>185 ··········</cpe-lang:logical-test>
186 ········</cpe-lang:platform>186 ········</cpe-lang:platform>
187 ········<cpe-lang:platform·id="package_pam">187 ········<cpe-lang:platform·id="package_networkmanager">
188 ··········<cpe-lang:logical-test·operator="AND"·negate="false">188 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
189 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>189 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_networkmanager:def:1"/>
190 ··········</cpe-lang:logical-test>190 ··········</cpe-lang:logical-test>
191 ········</cpe-lang:platform>191 ········</cpe-lang:platform>
192 ········<cpe-lang:platform·id="package_autofs_and_system_with_kernel">192 ········<cpe-lang:platform·id="package_autofs_and_system_with_kernel">
193 ··········<cpe-lang:logical-test·operator="AND"·negate="false">193 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
194 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>194 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>
195 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>195 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
196 ··········</cpe-lang:logical-test>196 ··········</cpe-lang:logical-test>
197 ········</cpe-lang:platform>197 ········</cpe-lang:platform>
198 ········<cpe-lang:platform·id="mount_tmp">198 ········<cpe-lang:platform·id="ipv6_enabled">
199 ··········<cpe-lang:logical-test·operator="AND"·negate="false">199 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
200 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_tmp:def:1"/>200 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-ipv6_enabled:def:1"/>
201 ··········</cpe-lang:logical-test>201 ··········</cpe-lang:logical-test>
202 ········</cpe-lang:platform>202 ········</cpe-lang:platform>
203 ········<cpe-lang:platform·id="package_firewalld_and_package_nftables_and_system_with_kernel">203 ········<cpe-lang:platform·id="package_gdm">
204 ··········<cpe-lang:logical-test·operator="AND"·negate="false">204 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
205 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>205 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_gdm:def:1"/>
206 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/> 
207 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
208 ··········</cpe-lang:logical-test>206 ··········</cpe-lang:logical-test>
209 ········</cpe-lang:platform>207 ········</cpe-lang:platform>
210 ········<cpe-lang:platform·id="not_s390x_arch">208 ········<cpe-lang:platform·id="package_rsyslog">
211 ··········<cpe-lang:logical-test·operator="AND"·negate="false">209 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
212 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>210 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>
213 ··········</cpe-lang:logical-test>211 ··········</cpe-lang:logical-test>
214 ········</cpe-lang:platform>212 ········</cpe-lang:platform>
215 ········<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">213 ········<cpe-lang:platform·id="not_osbuild_and_system_with_kernel">
216 ··········<cpe-lang:logical-test·operator="AND"·negate="false">214 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 215 ············<cpe-lang:logical-test·operator="AND"·negate="true">
 216 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_osbuild:def:1"/>
 217 ············</cpe-lang:logical-test>
217 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>218 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
218 ··········</cpe-lang:logical-test>219 ··········</cpe-lang:logical-test>
219 ········</cpe-lang:platform>220 ········</cpe-lang:platform>
220 ········<cpe-lang:platform·id="not_ppc64le_arch">221 ········<cpe-lang:platform·id="package_chrony_or_package_ntp">
221 ··········<cpe-lang:logical-test·operator="AND"·negate="true">222 ··········<cpe-lang:logical-test·operator="OR"·negate="false">
 223 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
222 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_ppc64le:def:1"/>224 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_ntp:def:1"/>
223 ··········</cpe-lang:logical-test>225 ··········</cpe-lang:logical-test>
224 ········</cpe-lang:platform>226 ········</cpe-lang:platform>
225 ········<cpe-lang:platform·id="mount_var-log">227 ········<cpe-lang:platform·id="package_bash">
226 ··········<cpe-lang:logical-test·operator="AND"·negate="false">228 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
227 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-log:def:1"/>229 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>
228 ··········</cpe-lang:logical-test>230 ··········</cpe-lang:logical-test>
229 ········</cpe-lang:platform>231 ········</cpe-lang:platform>
230 ········<cpe-lang:platform·id="uefi">232 ········<cpe-lang:platform·id="uefi">
231 ··········<cpe-lang:logical-test·operator="AND"·negate="false">233 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
232 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>234 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>
233 ··········</cpe-lang:logical-test>235 ··········</cpe-lang:logical-test>
234 ········</cpe-lang:platform>236 ········</cpe-lang:platform>
235 ········<cpe-lang:platform·id="package_bash">237 ········<cpe-lang:platform·id="package_logrotate">
236 ··········<cpe-lang:logical-test·operator="AND"·negate="false">238 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
237 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>239 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_logrotate:def:1"/>
238 ··········</cpe-lang:logical-test>240 ··········</cpe-lang:logical-test>
239 ········</cpe-lang:platform>241 ········</cpe-lang:platform>
240 ········<cpe-lang:platform·id="ppc64le_arch">242 ········<cpe-lang:platform·id="not_aarch64_arch_and_not_ppc64le_arch">
241 ··········<cpe-lang:logical-test·operator="AND"·negate="false">243 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 244 ············<cpe-lang:logical-test·operator="AND"·negate="true">
 245 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
 246 ············</cpe-lang:logical-test>
 247 ············<cpe-lang:logical-test·operator="AND"·negate="true">
242 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_ppc64le:def:1"/>248 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_ppc64le:def:1"/>
 249 ············</cpe-lang:logical-test>
243 ··········</cpe-lang:logical-test>250 ··········</cpe-lang:logical-test>
Max diff block lines reached; 2612389/2626121 bytes (99.48%) of diff not shown.
361 KB
./usr/share/xml/scap/ssg/content/ssg-cs10-xccdf.xml
361 KB
./usr/share/xml/scap/ssg/content/ssg-cs10-xccdf.xml
    
Offset 122, 402 lines modifiedOffset 122, 402 lines modified
122 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>122 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
123 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>123 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
124 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>124 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
125 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>125 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
126 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>126 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
127 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>127 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
128 ··<cpe-lang:platform-specification>128 ··<cpe-lang:platform-specification>
129 ····<cpe-lang:platform·id="package_libuser">129 ····<cpe-lang:platform·id="not_aarch64_arch_and_not_ppc64le_arch_and_system_with_kernel">
130 ······<cpe-lang:logical-test·operator="AND"·negate="false">130 ······<cpe-lang:logical-test·operator="AND"·negate="false">
131 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_libuser:def:1"/> 
132 ······</cpe-lang:logical-test> 
133 ····</cpe-lang:platform> 
134 ····<cpe-lang:platform·id="not_bootc"> 
135 ······<cpe-lang:logical-test·operator="AND"·negate="true">131 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 132 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
 133 ········</cpe-lang:logical-test>
 134 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 135 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_ppc64le:def:1"/>
 136 ········</cpe-lang:logical-test>
136 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-bootc:def:1"/>137 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
137 ······</cpe-lang:logical-test>138 ······</cpe-lang:logical-test>
138 ····</cpe-lang:platform>139 ····</cpe-lang:platform>
139 ····<cpe-lang:platform·id="machine">140 ····<cpe-lang:platform·id="package_polkit">
140 ······<cpe-lang:logical-test·operator="AND"·negate="false">141 ······<cpe-lang:logical-test·operator="AND"·negate="false">
141 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>142 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_polkit:def:1"/>
142 ······</cpe-lang:logical-test>143 ······</cpe-lang:logical-test>
143 ····</cpe-lang:platform>144 ····</cpe-lang:platform>
144 ····<cpe-lang:platform·id="package_squid_and_system_with_kernel">145 ····<cpe-lang:platform·id="mount_var-tmp">
145 ······<cpe-lang:logical-test·operator="AND"·negate="false">146 ······<cpe-lang:logical-test·operator="AND"·negate="false">
146 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_squid:def:1"/> 
147 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>147 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-tmp:def:1"/>
148 ······</cpe-lang:logical-test>148 ······</cpe-lang:logical-test>
149 ····</cpe-lang:platform>149 ····</cpe-lang:platform>
150 ····<cpe-lang:platform·id="package_pam">150 ····<cpe-lang:platform·id="package_networkmanager">
151 ······<cpe-lang:logical-test·operator="AND"·negate="false">151 ······<cpe-lang:logical-test·operator="AND"·negate="false">
152 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>152 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_networkmanager:def:1"/>
153 ······</cpe-lang:logical-test>153 ······</cpe-lang:logical-test>
154 ····</cpe-lang:platform>154 ····</cpe-lang:platform>
155 ····<cpe-lang:platform·id="package_autofs_and_system_with_kernel">155 ····<cpe-lang:platform·id="package_autofs_and_system_with_kernel">
156 ······<cpe-lang:logical-test·operator="AND"·negate="false">156 ······<cpe-lang:logical-test·operator="AND"·negate="false">
157 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>157 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>
158 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>158 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
159 ······</cpe-lang:logical-test>159 ······</cpe-lang:logical-test>
160 ····</cpe-lang:platform>160 ····</cpe-lang:platform>
161 ····<cpe-lang:platform·id="mount_tmp">161 ····<cpe-lang:platform·id="ipv6_enabled">
162 ······<cpe-lang:logical-test·operator="AND"·negate="false">162 ······<cpe-lang:logical-test·operator="AND"·negate="false">
163 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_tmp:def:1"/>163 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-ipv6_enabled:def:1"/>
164 ······</cpe-lang:logical-test>164 ······</cpe-lang:logical-test>
165 ····</cpe-lang:platform>165 ····</cpe-lang:platform>
166 ····<cpe-lang:platform·id="package_firewalld_and_package_nftables_and_system_with_kernel">166 ····<cpe-lang:platform·id="package_gdm">
167 ······<cpe-lang:logical-test·operator="AND"·negate="false">167 ······<cpe-lang:logical-test·operator="AND"·negate="false">
168 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>168 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_gdm:def:1"/>
169 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/> 
170 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
171 ······</cpe-lang:logical-test>169 ······</cpe-lang:logical-test>
172 ····</cpe-lang:platform>170 ····</cpe-lang:platform>
173 ····<cpe-lang:platform·id="not_s390x_arch">171 ····<cpe-lang:platform·id="package_rsyslog">
174 ······<cpe-lang:logical-test·operator="AND"·negate="false">172 ······<cpe-lang:logical-test·operator="AND"·negate="false">
175 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>173 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>
176 ······</cpe-lang:logical-test>174 ······</cpe-lang:logical-test>
177 ····</cpe-lang:platform>175 ····</cpe-lang:platform>
178 ····<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">176 ····<cpe-lang:platform·id="not_osbuild_and_system_with_kernel">
179 ······<cpe-lang:logical-test·operator="AND"·negate="false">177 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 178 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 179 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_osbuild:def:1"/>
 180 ········</cpe-lang:logical-test>
180 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>181 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
181 ······</cpe-lang:logical-test>182 ······</cpe-lang:logical-test>
182 ····</cpe-lang:platform>183 ····</cpe-lang:platform>
183 ····<cpe-lang:platform·id="not_ppc64le_arch">184 ····<cpe-lang:platform·id="package_chrony_or_package_ntp">
184 ······<cpe-lang:logical-test·operator="AND"·negate="true">185 ······<cpe-lang:logical-test·operator="OR"·negate="false">
 186 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
185 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_ppc64le:def:1"/>187 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_ntp:def:1"/>
186 ······</cpe-lang:logical-test>188 ······</cpe-lang:logical-test>
187 ····</cpe-lang:platform>189 ····</cpe-lang:platform>
188 ····<cpe-lang:platform·id="mount_var-log">190 ····<cpe-lang:platform·id="package_bash">
189 ······<cpe-lang:logical-test·operator="AND"·negate="false">191 ······<cpe-lang:logical-test·operator="AND"·negate="false">
190 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-log:def:1"/>192 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>
191 ······</cpe-lang:logical-test>193 ······</cpe-lang:logical-test>
192 ····</cpe-lang:platform>194 ····</cpe-lang:platform>
193 ····<cpe-lang:platform·id="uefi">195 ····<cpe-lang:platform·id="uefi">
194 ······<cpe-lang:logical-test·operator="AND"·negate="false">196 ······<cpe-lang:logical-test·operator="AND"·negate="false">
195 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>197 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>
196 ······</cpe-lang:logical-test>198 ······</cpe-lang:logical-test>
197 ····</cpe-lang:platform>199 ····</cpe-lang:platform>
198 ····<cpe-lang:platform·id="package_bash">200 ····<cpe-lang:platform·id="package_logrotate">
199 ······<cpe-lang:logical-test·operator="AND"·negate="false">201 ······<cpe-lang:logical-test·operator="AND"·negate="false">
200 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>202 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_logrotate:def:1"/>
201 ······</cpe-lang:logical-test>203 ······</cpe-lang:logical-test>
202 ····</cpe-lang:platform>204 ····</cpe-lang:platform>
203 ····<cpe-lang:platform·id="ppc64le_arch">205 ····<cpe-lang:platform·id="not_aarch64_arch_and_not_ppc64le_arch">
204 ······<cpe-lang:logical-test·operator="AND"·negate="false">206 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 207 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 208 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
 209 ········</cpe-lang:logical-test>
 210 ········<cpe-lang:logical-test·operator="AND"·negate="true">
205 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_ppc64le:def:1"/>211 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_ppc64le:def:1"/>
 212 ········</cpe-lang:logical-test>
206 ······</cpe-lang:logical-test>213 ······</cpe-lang:logical-test>
207 ····</cpe-lang:platform>214 ····</cpe-lang:platform>
208 ····<cpe-lang:platform·id="package_telnet-server_and_system_with_kernel">215 ····<cpe-lang:platform·id="package_chrony">
209 ······<cpe-lang:logical-test·operator="AND"·negate="false">216 ······<cpe-lang:logical-test·operator="AND"·negate="false">
210 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_telnet-server:def:1"/>217 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
211 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
212 ······</cpe-lang:logical-test>218 ······</cpe-lang:logical-test>
213 ····</cpe-lang:platform>219 ····</cpe-lang:platform>
214 ····<cpe-lang:platform·id="package_iptables">220 ····<cpe-lang:platform·id="package_sssd">
215 ······<cpe-lang:logical-test·operator="AND"·negate="false">221 ······<cpe-lang:logical-test·operator="AND"·negate="false">
216 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>222 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_sssd:def:1"/>
217 ······</cpe-lang:logical-test>223 ······</cpe-lang:logical-test>
218 ····</cpe-lang:platform>224 ····</cpe-lang:platform>
219 ····<cpe-lang:platform·id="krb5_server_older_than_1_17-18_and_krb5_workstation_older_than_1_17-18">225 ····<cpe-lang:platform·id="package_firewalld">
220 ······<cpe-lang:logical-test·operator="AND"·negate="false">226 ······<cpe-lang:logical-test·operator="AND"·negate="false">
221 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-krb5_server_older_than_1_17_18:def:1"/>227 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>
222 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-krb5_workstation_older_than_1_17_18:def:1"/> 
223 ······</cpe-lang:logical-test>228 ······</cpe-lang:logical-test>
224 ····</cpe-lang:platform>229 ····</cpe-lang:platform>
225 ····<cpe-lang:platform·id="grub2">230 ····<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">
226 ······<cpe-lang:logical-test·operator="AND"·negate="false">231 ······<cpe-lang:logical-test·operator="AND"·negate="false">
227 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>232 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>
228 ······</cpe-lang:logical-test>233 ······</cpe-lang:logical-test>
229 ····</cpe-lang:platform>234 ····</cpe-lang:platform>
230 ····<cpe-lang:platform·id="package_sssd">235 ····<cpe-lang:platform·id="mount_srv">
231 ······<cpe-lang:logical-test·operator="AND"·negate="false">236 ······<cpe-lang:logical-test·operator="AND"·negate="false">
232 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_sssd:def:1"/>237 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_srv:def:1"/>
233 ······</cpe-lang:logical-test>238 ······</cpe-lang:logical-test>
234 ····</cpe-lang:platform>239 ····</cpe-lang:platform>
Max diff block lines reached; 355417/369927 bytes (96.08%) of diff not shown.
3.75 MB
./usr/share/xml/scap/ssg/content/ssg-cs9-ds.xml
3.75 MB
./usr/share/xml/scap/ssg/content/ssg-cs9-ds.xml
    
Offset 19, 27 lines modifiedOffset 19, 27 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel9-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel9-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel9-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel9-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel9-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel9-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel9-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel9-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel9-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel9-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel9-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel9-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel9-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel9-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux:9">28 ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux:9">
29 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Enterprise·Linux·9</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Enterprise·Linux·9</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml">oval:ssg-installed_OS_is_rhel9:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml">oval:ssg-installed_OS_is_rhel9:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ······<cpe-dict:cpe-item·name="cpe:/o:centos:centos:9">32 ······<cpe-dict:cpe-item·name="cpe:/o:centos:centos:9">
33 ········<cpe-dict:title·xml:lang="en-us">CentOS·Stream·9</cpe-dict:title>33 ········<cpe-dict:title·xml:lang="en-us">CentOS·Stream·9</cpe-dict:title>
34 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml">oval:ssg-installed_OS_is_centos9:def:1</cpe-dict:check>34 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml">oval:ssg-installed_OS_is_centos9:def:1</cpe-dict:check>
35 ······</cpe-dict:cpe-item>35 ······</cpe-dict:cpe-item>
36 ····</cpe-dict:cpe-list>36 ····</cpe-dict:cpe-list>
37 ··</ds:component>37 ··</ds:component>
38 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel9-xccdf.xml"·timestamp="2025-02-28T20:08:00">38 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel9-xccdf.xml"·timestamp="2025-03-01T22:08:00">
39 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_RHEL-9"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">39 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_RHEL-9"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
40 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>40 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
41 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Red·Hat·Enterprise·Linux·9</xccdf-1.2:title>41 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Red·Hat·Enterprise·Linux·9</xccdf-1.2:title>
42 ······<xccdf-1.2:description>42 ······<xccdf-1.2:description>
43 ········This·guide·presents·a·catalog·of·security-relevant43 ········This·guide·presents·a·catalog·of·security-relevant
44 configuration·settings·for·Red·Hat·Enterprise·Linux·9.·It·is·a·rendering·of44 configuration·settings·for·Red·Hat·Enterprise·Linux·9.·It·is·a·rendering·of
45 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)45 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 160, 262 lines modifiedOffset 160, 228 lines modified
160 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>160 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
161 ······<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>161 ······<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
162 ······<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>162 ······<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
163 ······<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>163 ······<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
164 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>164 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
165 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>165 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
166 ······<cpe-lang:platform-specification>166 ······<cpe-lang:platform-specification>
167 ········<cpe-lang:platform·id="package_libuser">167 ········<cpe-lang:platform·id="not_aarch64_arch_and_not_ppc64le_arch_and_system_with_kernel">
168 ··········<cpe-lang:logical-test·operator="AND"·negate="false">168 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 169 ············<cpe-lang:logical-test·operator="AND"·negate="true">
 170 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
 171 ············</cpe-lang:logical-test>
 172 ············<cpe-lang:logical-test·operator="AND"·negate="true">
 173 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_ppc64le:def:1"/>
 174 ············</cpe-lang:logical-test>
169 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-package_libuser:def:1"/>175 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
170 ··········</cpe-lang:logical-test>176 ··········</cpe-lang:logical-test>
171 ········</cpe-lang:platform>177 ········</cpe-lang:platform>
172 ········<cpe-lang:platform·id="not_bootc">178 ········<cpe-lang:platform·id="not_runtime_kernel_fips_enabled_and_system_with_kernel">
 179 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
173 ··········<cpe-lang:logical-test·operator="AND"·negate="true">180 ············<cpe-lang:logical-test·operator="AND"·negate="true">
 181 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-runtime_kernel_fips_enabled:def:1"/>
 182 ············</cpe-lang:logical-test>
174 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-bootc:def:1"/>183 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
175 ··········</cpe-lang:logical-test>184 ··········</cpe-lang:logical-test>
176 ········</cpe-lang:platform>185 ········</cpe-lang:platform>
177 ········<cpe-lang:platform·id="machine">186 ········<cpe-lang:platform·id="package_polkit">
178 ··········<cpe-lang:logical-test·operator="AND"·negate="false">187 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
179 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>188 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-package_polkit:def:1"/>
180 ··········</cpe-lang:logical-test>189 ··········</cpe-lang:logical-test>
181 ········</cpe-lang:platform>190 ········</cpe-lang:platform>
182 ········<cpe-lang:platform·id="package_squid_and_system_with_kernel">191 ········<cpe-lang:platform·id="mount_var-tmp">
183 ··········<cpe-lang:logical-test·operator="AND"·negate="false">192 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
184 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-package_squid:def:1"/> 
185 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>193 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-tmp:def:1"/>
186 ··········</cpe-lang:logical-test>194 ··········</cpe-lang:logical-test>
187 ········</cpe-lang:platform>195 ········</cpe-lang:platform>
188 ········<cpe-lang:platform·id="package_pam">196 ········<cpe-lang:platform·id="package_networkmanager">
189 ··········<cpe-lang:logical-test·operator="AND"·negate="false">197 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
190 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>198 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-package_networkmanager:def:1"/>
191 ··········</cpe-lang:logical-test>199 ··········</cpe-lang:logical-test>
192 ········</cpe-lang:platform>200 ········</cpe-lang:platform>
193 ········<cpe-lang:platform·id="package_autofs_and_system_with_kernel">201 ········<cpe-lang:platform·id="package_autofs_and_system_with_kernel">
194 ··········<cpe-lang:logical-test·operator="AND"·negate="false">202 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
195 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>203 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>
196 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>204 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
197 ··········</cpe-lang:logical-test>205 ··········</cpe-lang:logical-test>
198 ········</cpe-lang:platform>206 ········</cpe-lang:platform>
199 ········<cpe-lang:platform·id="mount_tmp">207 ········<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">
200 ··········<cpe-lang:logical-test·operator="AND"·negate="false">208 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 209 ············<cpe-lang:logical-test·operator="AND"·negate="true">
 210 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
 211 ············</cpe-lang:logical-test>
 212 ············<cpe-lang:logical-test·operator="AND"·negate="true">
201 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_tmp:def:1"/>213 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
 214 ············</cpe-lang:logical-test>
 215 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
202 ··········</cpe-lang:logical-test>216 ··········</cpe-lang:logical-test>
203 ········</cpe-lang:platform>217 ········</cpe-lang:platform>
204 ········<cpe-lang:platform·id="package_firewalld_and_package_nftables_and_system_with_kernel">218 ········<cpe-lang:platform·id="ipv6_enabled">
205 ··········<cpe-lang:logical-test·operator="AND"·negate="false">219 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
206 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/> 
207 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>220 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-ipv6_enabled:def:1"/>
208 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
209 ··········</cpe-lang:logical-test>221 ··········</cpe-lang:logical-test>
210 ········</cpe-lang:platform>222 ········</cpe-lang:platform>
211 ········<cpe-lang:platform·id="not_s390x_arch">223 ········<cpe-lang:platform·id="package_gdm">
212 ··········<cpe-lang:logical-test·operator="AND"·negate="false">224 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
213 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>225 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-package_gdm:def:1"/>
214 ··········</cpe-lang:logical-test>226 ··········</cpe-lang:logical-test>
215 ········</cpe-lang:platform>227 ········</cpe-lang:platform>
216 ········<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">228 ········<cpe-lang:platform·id="package_rsyslog">
217 ··········<cpe-lang:logical-test·operator="AND"·negate="false">229 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
218 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>230 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>
219 ··········</cpe-lang:logical-test> 
220 ········</cpe-lang:platform> 
221 ········<cpe-lang:platform·id="not_ppc64le_arch"> 
222 ··········<cpe-lang:logical-test·operator="AND"·negate="true"> 
223 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_ppc64le:def:1"/> 
224 ··········</cpe-lang:logical-test>231 ··········</cpe-lang:logical-test>
225 ········</cpe-lang:platform>232 ········</cpe-lang:platform>
226 ········<cpe-lang:platform·id="mount_var-log">233 ········<cpe-lang:platform·id="not_osbuild_and_system_with_kernel">
227 ··········<cpe-lang:logical-test·operator="AND"·negate="false">234 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 235 ············<cpe-lang:logical-test·operator="AND"·negate="true">
228 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-log:def:1"/>236 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_osbuild:def:1"/>
 237 ············</cpe-lang:logical-test>
 238 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
229 ··········</cpe-lang:logical-test>239 ··········</cpe-lang:logical-test>
230 ········</cpe-lang:platform>240 ········</cpe-lang:platform>
231 ········<cpe-lang:platform·id="uefi">241 ········<cpe-lang:platform·id="package_chrony_or_package_ntp">
232 ··········<cpe-lang:logical-test·operator="AND"·negate="false">242 ··········<cpe-lang:logical-test·operator="OR"·negate="false">
 243 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
233 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>244 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-package_ntp:def:1"/>
234 ··········</cpe-lang:logical-test>245 ··········</cpe-lang:logical-test>
235 ········</cpe-lang:platform>246 ········</cpe-lang:platform>
236 ········<cpe-lang:platform·id="package_bash">247 ········<cpe-lang:platform·id="package_bash">
237 ··········<cpe-lang:logical-test·operator="AND"·negate="false">248 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
238 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>249 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>
239 ··········</cpe-lang:logical-test>250 ··········</cpe-lang:logical-test>
Max diff block lines reached; 3915291/3928918 bytes (99.65%) of diff not shown.
486 KB
./usr/share/xml/scap/ssg/content/ssg-cs9-xccdf.xml
486 KB
./usr/share/xml/scap/ssg/content/ssg-cs9-xccdf.xml
Ordering differences only
    
Offset 123, 262 lines modifiedOffset 123, 228 lines modified
123 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>123 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
124 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>124 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
125 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>125 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
126 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>126 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
127 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>127 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
128 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>128 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
129 ··<cpe-lang:platform-specification>129 ··<cpe-lang:platform-specification>
130 ····<cpe-lang:platform·id="package_libuser">130 ····<cpe-lang:platform·id="not_aarch64_arch_and_not_ppc64le_arch_and_system_with_kernel">
131 ······<cpe-lang:logical-test·operator="AND"·negate="false">131 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 132 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 133 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
 134 ········</cpe-lang:logical-test>
 135 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 136 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_ppc64le:def:1"/>
 137 ········</cpe-lang:logical-test>
132 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-package_libuser:def:1"/>138 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
133 ······</cpe-lang:logical-test>139 ······</cpe-lang:logical-test>
134 ····</cpe-lang:platform>140 ····</cpe-lang:platform>
135 ····<cpe-lang:platform·id="not_bootc">141 ····<cpe-lang:platform·id="not_runtime_kernel_fips_enabled_and_system_with_kernel">
 142 ······<cpe-lang:logical-test·operator="AND"·negate="false">
136 ······<cpe-lang:logical-test·operator="AND"·negate="true">143 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 144 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-runtime_kernel_fips_enabled:def:1"/>
 145 ········</cpe-lang:logical-test>
137 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-bootc:def:1"/>146 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
138 ······</cpe-lang:logical-test>147 ······</cpe-lang:logical-test>
139 ····</cpe-lang:platform>148 ····</cpe-lang:platform>
140 ····<cpe-lang:platform·id="machine">149 ····<cpe-lang:platform·id="package_polkit">
141 ······<cpe-lang:logical-test·operator="AND"·negate="false">150 ······<cpe-lang:logical-test·operator="AND"·negate="false">
142 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>151 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-package_polkit:def:1"/>
143 ······</cpe-lang:logical-test>152 ······</cpe-lang:logical-test>
144 ····</cpe-lang:platform>153 ····</cpe-lang:platform>
145 ····<cpe-lang:platform·id="package_squid_and_system_with_kernel">154 ····<cpe-lang:platform·id="mount_var-tmp">
146 ······<cpe-lang:logical-test·operator="AND"·negate="false">155 ······<cpe-lang:logical-test·operator="AND"·negate="false">
147 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-package_squid:def:1"/> 
148 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>156 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-tmp:def:1"/>
149 ······</cpe-lang:logical-test>157 ······</cpe-lang:logical-test>
150 ····</cpe-lang:platform>158 ····</cpe-lang:platform>
151 ····<cpe-lang:platform·id="package_pam">159 ····<cpe-lang:platform·id="package_networkmanager">
152 ······<cpe-lang:logical-test·operator="AND"·negate="false">160 ······<cpe-lang:logical-test·operator="AND"·negate="false">
153 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>161 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-package_networkmanager:def:1"/>
154 ······</cpe-lang:logical-test>162 ······</cpe-lang:logical-test>
155 ····</cpe-lang:platform>163 ····</cpe-lang:platform>
156 ····<cpe-lang:platform·id="package_autofs_and_system_with_kernel">164 ····<cpe-lang:platform·id="package_autofs_and_system_with_kernel">
157 ······<cpe-lang:logical-test·operator="AND"·negate="false">165 ······<cpe-lang:logical-test·operator="AND"·negate="false">
158 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>166 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>
159 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>167 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
160 ······</cpe-lang:logical-test>168 ······</cpe-lang:logical-test>
161 ····</cpe-lang:platform>169 ····</cpe-lang:platform>
162 ····<cpe-lang:platform·id="mount_tmp">170 ····<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">
163 ······<cpe-lang:logical-test·operator="AND"·negate="false">171 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 172 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 173 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
 174 ········</cpe-lang:logical-test>
 175 ········<cpe-lang:logical-test·operator="AND"·negate="true">
164 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_tmp:def:1"/>176 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
 177 ········</cpe-lang:logical-test>
 178 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
165 ······</cpe-lang:logical-test>179 ······</cpe-lang:logical-test>
166 ····</cpe-lang:platform>180 ····</cpe-lang:platform>
167 ····<cpe-lang:platform·id="package_firewalld_and_package_nftables_and_system_with_kernel">181 ····<cpe-lang:platform·id="ipv6_enabled">
168 ······<cpe-lang:logical-test·operator="AND"·negate="false">182 ······<cpe-lang:logical-test·operator="AND"·negate="false">
169 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/> 
170 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>183 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-ipv6_enabled:def:1"/>
171 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
172 ······</cpe-lang:logical-test>184 ······</cpe-lang:logical-test>
173 ····</cpe-lang:platform>185 ····</cpe-lang:platform>
174 ····<cpe-lang:platform·id="not_s390x_arch">186 ····<cpe-lang:platform·id="package_gdm">
175 ······<cpe-lang:logical-test·operator="AND"·negate="false">187 ······<cpe-lang:logical-test·operator="AND"·negate="false">
176 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>188 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-package_gdm:def:1"/>
177 ······</cpe-lang:logical-test>189 ······</cpe-lang:logical-test>
178 ····</cpe-lang:platform>190 ····</cpe-lang:platform>
179 ····<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">191 ····<cpe-lang:platform·id="package_rsyslog">
180 ······<cpe-lang:logical-test·operator="AND"·negate="false">192 ······<cpe-lang:logical-test·operator="AND"·negate="false">
181 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>193 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>
182 ······</cpe-lang:logical-test> 
183 ····</cpe-lang:platform> 
184 ····<cpe-lang:platform·id="not_ppc64le_arch"> 
185 ······<cpe-lang:logical-test·operator="AND"·negate="true"> 
186 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_ppc64le:def:1"/> 
187 ······</cpe-lang:logical-test>194 ······</cpe-lang:logical-test>
188 ····</cpe-lang:platform>195 ····</cpe-lang:platform>
189 ····<cpe-lang:platform·id="mount_var-log">196 ····<cpe-lang:platform·id="not_osbuild_and_system_with_kernel">
190 ······<cpe-lang:logical-test·operator="AND"·negate="false">197 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 198 ········<cpe-lang:logical-test·operator="AND"·negate="true">
191 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-log:def:1"/>199 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_osbuild:def:1"/>
 200 ········</cpe-lang:logical-test>
 201 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
192 ······</cpe-lang:logical-test>202 ······</cpe-lang:logical-test>
193 ····</cpe-lang:platform>203 ····</cpe-lang:platform>
194 ····<cpe-lang:platform·id="uefi">204 ····<cpe-lang:platform·id="package_chrony_or_package_ntp">
195 ······<cpe-lang:logical-test·operator="AND"·negate="false">205 ······<cpe-lang:logical-test·operator="OR"·negate="false">
 206 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
196 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>207 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-package_ntp:def:1"/>
197 ······</cpe-lang:logical-test>208 ······</cpe-lang:logical-test>
198 ····</cpe-lang:platform>209 ····</cpe-lang:platform>
199 ····<cpe-lang:platform·id="package_bash">210 ····<cpe-lang:platform·id="package_bash">
200 ······<cpe-lang:logical-test·operator="AND"·negate="false">211 ······<cpe-lang:logical-test·operator="AND"·negate="false">
201 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>212 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>
202 ······</cpe-lang:logical-test>213 ······</cpe-lang:logical-test>
203 ····</cpe-lang:platform>214 ····</cpe-lang:platform>
204 ····<cpe-lang:platform·id="ppc64le_arch">215 ····<cpe-lang:platform·id="uefi">
205 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
206 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_ppc64le:def:1"/> 
207 ······</cpe-lang:logical-test> 
208 ····</cpe-lang:platform> 
209 ····<cpe-lang:platform·id="package_telnet-server_and_system_with_kernel"> 
210 ······<cpe-lang:logical-test·operator="AND"·negate="false">216 ······<cpe-lang:logical-test·operator="AND"·negate="false">
211 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-package_telnet-server:def:1"/> 
212 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>217 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>
213 ······</cpe-lang:logical-test>218 ······</cpe-lang:logical-test>
214 ····</cpe-lang:platform>219 ····</cpe-lang:platform>
215 ····<cpe-lang:platform·id="package_iptables">220 ····<cpe-lang:platform·id="package_logrotate">
216 ······<cpe-lang:logical-test·operator="AND"·negate="false">221 ······<cpe-lang:logical-test·operator="AND"·negate="false">
217 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>222 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-package_logrotate:def:1"/>
218 ······</cpe-lang:logical-test>223 ······</cpe-lang:logical-test>
219 ····</cpe-lang:platform>224 ····</cpe-lang:platform>
220 ····<cpe-lang:platform·id="krb5_server_older_than_1_17-18_and_krb5_workstation_older_than_1_17-18">225 ····<cpe-lang:platform·id="not_aarch64_arch_and_not_ppc64le_arch">
221 ······<cpe-lang:logical-test·operator="AND"·negate="false">226 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 227 ········<cpe-lang:logical-test·operator="AND"·negate="true">
222 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-krb5_server_older_than_1_17_18:def:1"/>228 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
 229 ········</cpe-lang:logical-test>
 230 ········<cpe-lang:logical-test·operator="AND"·negate="true">
223 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-krb5_workstation_older_than_1_17_18:def:1"/>231 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_ppc64le:def:1"/>
 232 ········</cpe-lang:logical-test>
224 ······</cpe-lang:logical-test>233 ······</cpe-lang:logical-test>
225 ····</cpe-lang:platform>234 ····</cpe-lang:platform>
226 ····<cpe-lang:platform·id="grub2">235 ····<cpe-lang:platform·id="package_chrony">
Max diff block lines reached; 483718/497460 bytes (97.24%) of diff not shown.
2.46 MB
./usr/share/xml/scap/ssg/content/ssg-fedora-ds.xml
2.46 MB
./usr/share/xml/scap/ssg/content/ssg-fedora-ds.xml
    
Offset 19, 15 lines modifiedOffset 19, 15 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-fedora-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-fedora-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-fedora-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-fedora-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-fedora-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-fedora-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-fedora-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-fedora-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-fedora-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-fedora-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-fedora-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-fedora-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-fedora-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-fedora-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:fedoraproject:fedora:39">28 ······<cpe-dict:cpe-item·name="cpe:/o:fedoraproject:fedora:39">
29 ········<cpe-dict:title·xml:lang="en-us">Fedora·39</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Fedora·39</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml">oval:ssg-installed_OS_is_fedora:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml">oval:ssg-installed_OS_is_fedora:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ······<cpe-dict:cpe-item·name="cpe:/o:fedoraproject:fedora:40">32 ······<cpe-dict:cpe-item·name="cpe:/o:fedoraproject:fedora:40">
33 ········<cpe-dict:title·xml:lang="en-us">Fedora·40</cpe-dict:title>33 ········<cpe-dict:title·xml:lang="en-us">Fedora·40</cpe-dict:title>
Offset 51, 15 lines modifiedOffset 51, 15 lines modified
51 ······</cpe-dict:cpe-item>51 ······</cpe-dict:cpe-item>
52 ······<cpe-dict:cpe-item·name="cpe:/o:fedoraproject:fedora:45">52 ······<cpe-dict:cpe-item·name="cpe:/o:fedoraproject:fedora:45">
53 ········<cpe-dict:title·xml:lang="en-us">Fedora·45</cpe-dict:title>53 ········<cpe-dict:title·xml:lang="en-us">Fedora·45</cpe-dict:title>
54 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml">oval:ssg-installed_OS_is_fedora:def:1</cpe-dict:check>54 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml">oval:ssg-installed_OS_is_fedora:def:1</cpe-dict:check>
55 ······</cpe-dict:cpe-item>55 ······</cpe-dict:cpe-item>
56 ····</cpe-dict:cpe-list>56 ····</cpe-dict:cpe-list>
57 ··</ds:component>57 ··</ds:component>
58 ··<ds:component·id="scap_org.open-scap_comp_ssg-fedora-xccdf.xml"·timestamp="2025-02-28T20:08:00">58 ··<ds:component·id="scap_org.open-scap_comp_ssg-fedora-xccdf.xml"·timestamp="2025-03-01T22:08:00">
59 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_FEDORA"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">59 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_FEDORA"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
60 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>60 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
61 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Fedora</xccdf-1.2:title>61 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Fedora</xccdf-1.2:title>
62 ······<xccdf-1.2:description>62 ······<xccdf-1.2:description>
63 ········This·guide·presents·a·catalog·of·security-relevant63 ········This·guide·presents·a·catalog·of·security-relevant
64 configuration·settings·for·Fedora.·It·is·a·rendering·of64 configuration·settings·for·Fedora.·It·is·a·rendering·of
65 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)65 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 128, 167 lines modifiedOffset 128, 181 lines modified
128 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>128 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
129 ······<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>129 ······<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
130 ······<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>130 ······<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
131 ······<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>131 ······<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
132 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>132 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
133 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>133 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
134 ······<cpe-lang:platform-specification>134 ······<cpe-lang:platform-specification>
135 ········<cpe-lang:platform·id="package_libuser">135 ········<cpe-lang:platform·id="not_aarch64_arch_and_not_ppc64le_arch_and_system_with_kernel">
136 ··········<cpe-lang:logical-test·operator="AND"·negate="false">136 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 137 ············<cpe-lang:logical-test·operator="AND"·negate="true">
 138 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
 139 ············</cpe-lang:logical-test>
 140 ············<cpe-lang:logical-test·operator="AND"·negate="true">
 141 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_ppc64le:def:1"/>
 142 ············</cpe-lang:logical-test>
137 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml"·id-ref="oval:ssg-package_libuser:def:1"/>143 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
138 ··········</cpe-lang:logical-test>144 ··········</cpe-lang:logical-test>
139 ········</cpe-lang:platform>145 ········</cpe-lang:platform>
140 ········<cpe-lang:platform·id="not_bootc">146 ········<cpe-lang:platform·id="not_runtime_kernel_fips_enabled_and_system_with_kernel">
 147 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
141 ··········<cpe-lang:logical-test·operator="AND"·negate="true">148 ············<cpe-lang:logical-test·operator="AND"·negate="true">
 149 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml"·id-ref="oval:ssg-runtime_kernel_fips_enabled:def:1"/>
 150 ············</cpe-lang:logical-test>
142 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml"·id-ref="oval:ssg-bootc:def:1"/>151 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
143 ··········</cpe-lang:logical-test>152 ··········</cpe-lang:logical-test>
144 ········</cpe-lang:platform>153 ········</cpe-lang:platform>
145 ········<cpe-lang:platform·id="machine">154 ········<cpe-lang:platform·id="package_polkit">
146 ··········<cpe-lang:logical-test·operator="AND"·negate="false">155 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
147 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>156 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml"·id-ref="oval:ssg-package_polkit:def:1"/>
148 ··········</cpe-lang:logical-test>157 ··········</cpe-lang:logical-test>
149 ········</cpe-lang:platform>158 ········</cpe-lang:platform>
150 ········<cpe-lang:platform·id="package_pam">159 ········<cpe-lang:platform·id="mount_var-tmp">
151 ··········<cpe-lang:logical-test·operator="AND"·negate="false">160 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
152 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>161 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-tmp:def:1"/>
153 ··········</cpe-lang:logical-test>162 ··········</cpe-lang:logical-test>
154 ········</cpe-lang:platform>163 ········</cpe-lang:platform>
155 ········<cpe-lang:platform·id="package_autofs_and_system_with_kernel">164 ········<cpe-lang:platform·id="package_autofs_and_system_with_kernel">
156 ··········<cpe-lang:logical-test·operator="AND"·negate="false">165 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
157 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>166 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>
158 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>167 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
159 ··········</cpe-lang:logical-test>168 ··········</cpe-lang:logical-test>
160 ········</cpe-lang:platform>169 ········</cpe-lang:platform>
161 ········<cpe-lang:platform·id="mount_tmp">170 ········<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">
162 ··········<cpe-lang:logical-test·operator="AND"·negate="false">171 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 172 ············<cpe-lang:logical-test·operator="AND"·negate="true">
 173 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
 174 ············</cpe-lang:logical-test>
 175 ············<cpe-lang:logical-test·operator="AND"·negate="true">
163 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_tmp:def:1"/>176 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
 177 ············</cpe-lang:logical-test>
 178 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
164 ··········</cpe-lang:logical-test>179 ··········</cpe-lang:logical-test>
165 ········</cpe-lang:platform>180 ········</cpe-lang:platform>
166 ········<cpe-lang:platform·id="package_firewalld_and_package_nftables_and_system_with_kernel">181 ········<cpe-lang:platform·id="ipv6_enabled">
167 ··········<cpe-lang:logical-test·operator="AND"·negate="false">182 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
168 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/> 
169 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>183 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml"·id-ref="oval:ssg-ipv6_enabled:def:1"/>
170 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
171 ··········</cpe-lang:logical-test>184 ··········</cpe-lang:logical-test>
172 ········</cpe-lang:platform>185 ········</cpe-lang:platform>
173 ········<cpe-lang:platform·id="not_s390x_arch">186 ········<cpe-lang:platform·id="package_gdm">
174 ··········<cpe-lang:logical-test·operator="AND"·negate="false">187 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
175 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>188 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml"·id-ref="oval:ssg-package_gdm:def:1"/>
176 ··········</cpe-lang:logical-test>189 ··········</cpe-lang:logical-test>
177 ········</cpe-lang:platform>190 ········</cpe-lang:platform>
178 ········<cpe-lang:platform·id="mount_var-log">191 ········<cpe-lang:platform·id="package_rsyslog">
179 ··········<cpe-lang:logical-test·operator="AND"·negate="false">192 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
180 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-log:def:1"/>193 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>
181 ··········</cpe-lang:logical-test>194 ··········</cpe-lang:logical-test>
182 ········</cpe-lang:platform>195 ········</cpe-lang:platform>
183 ········<cpe-lang:platform·id="uefi">196 ········<cpe-lang:platform·id="not_osbuild_and_system_with_kernel">
184 ··········<cpe-lang:logical-test·operator="AND"·negate="false">197 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 198 ············<cpe-lang:logical-test·operator="AND"·negate="true">
 199 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_osbuild:def:1"/>
 200 ············</cpe-lang:logical-test>
185 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>201 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
 202 ··········</cpe-lang:logical-test>
 203 ········</cpe-lang:platform>
 204 ········<cpe-lang:platform·id="package_chrony_or_package_ntp">
 205 ··········<cpe-lang:logical-test·operator="OR"·negate="false">
 206 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
 207 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml"·id-ref="oval:ssg-package_ntp:def:1"/>
186 ··········</cpe-lang:logical-test>208 ··········</cpe-lang:logical-test>
187 ········</cpe-lang:platform>209 ········</cpe-lang:platform>
188 ········<cpe-lang:platform·id="package_bash">210 ········<cpe-lang:platform·id="package_bash">
189 ··········<cpe-lang:logical-test·operator="AND"·negate="false">211 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
190 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>212 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>
191 ··········</cpe-lang:logical-test>213 ··········</cpe-lang:logical-test>
192 ········</cpe-lang:platform>214 ········</cpe-lang:platform>
193 ········<cpe-lang:platform·id="package_iptables">215 ········<cpe-lang:platform·id="uefi">
194 ··········<cpe-lang:logical-test·operator="AND"·negate="false">216 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
195 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>217 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>
196 ··········</cpe-lang:logical-test>218 ··········</cpe-lang:logical-test>
197 ········</cpe-lang:platform>219 ········</cpe-lang:platform>
198 ········<cpe-lang:platform·id="grub2">220 ········<cpe-lang:platform·id="package_logrotate">
Max diff block lines reached; 2571047/2584118 bytes (99.49%) of diff not shown.
1.96 MB
./usr/share/xml/scap/ssg/content/ssg-fedora-ocil.xml
1.96 MB
./usr/share/xml/scap/ssg/content/ssg-fedora-ocil.xml
Ordering differences only
    
Offset 3, 6060 lines modifiedOffset 3, 6060 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-package_samba_removed_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-package_chrony_installed_ocil:questionnaire:1">
11 ······<ocil:title>Uninstall·Samba·Package</ocil:title>11 ······<ocil:title>The·Chrony·package·is·installed</ocil:title>
12 ······<ocil:actions>12 ······<ocil:actions>
13 ········<ocil:test_action_ref>ocil:ssg-package_samba_removed_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-package_chrony_installed_action:testaction:1</ocil:test_action_ref>
14 ······</ocil:actions>14 ······</ocil:actions>
15 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
16 ····<ocil:questionnaire·id="ocil:ssg-install_smartcard_packages_ocil:questionnaire:1"> 
17 ······<ocil:title>Install·Smart·Card·Packages·For·Multifactor·Authentication</ocil:title>16 ····<ocil:questionnaire·id="ocil:ssg-chronyd_or_ntpd_specify_remote_server_ocil:questionnaire:1">
 17 ······<ocil:title>Specify·a·Remote·NTP·Server</ocil:title>
18 ······<ocil:actions>18 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-install_smartcard_packages_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-chronyd_or_ntpd_specify_remote_server_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>20 ······</ocil:actions>
21 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_sshd_config_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_module_sig_hash_ocil:questionnaire:1">
23 ······<ocil:title>Verify·Permissions·on·SSH·Server·config·file</ocil:title>23 ······<ocil:title>Specify·the·hash·to·use·when·signing·modules</ocil:title>
24 ······<ocil:actions>24 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-file_permissions_sshd_config_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-kernel_config_module_sig_hash_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>26 ······</ocil:actions>
27 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-package_MFEhiplsm_installed_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_gcc_plugin_randstruct_ocil:questionnaire:1">
29 ······<ocil:title>Install·the·Host·Intrusion·Prevention·System·(HIPS)·Module</ocil:title>29 ······<ocil:title>Randomize·layout·of·sensitive·kernel·structures</ocil:title>
30 ······<ocil:actions>30 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-package_MFEhiplsm_installed_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-kernel_config_gcc_plugin_randstruct_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>32 ······</ocil:actions>
33 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_efi_user_cfg_ocil:questionnaire:1"> 
35 ······<ocil:title>Verify·/boot/grub2/user.cfg·Group·Ownership</ocil:title>34 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_successful_file_modification_openat_o_creat_ocil:questionnaire:1">
 35 ······<ocil:title>Record·Successful·Creation·Attempts·to·Files·-·openat·O_CREAT</ocil:title>
36 ······<ocil:actions>36 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_efi_user_cfg_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-audit_rules_successful_file_modification_openat_o_creat_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>38 ······</ocil:actions>
39 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-auditd_freq_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-accounts_passwords_pam_faillock_deny_ocil:questionnaire:1">
41 ······<ocil:title>Set·number·of·records·to·cause·an·explicit·flush·to·audit·logs</ocil:title>41 ······<ocil:title>Lock·Accounts·After·Failed·Password·Attempts</ocil:title>
42 ······<ocil:actions>42 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-auditd_freq_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-accounts_passwords_pam_faillock_deny_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>44 ······</ocil:actions>
45 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_backup_etc_shadow_ocil:questionnaire:1"> 
47 ······<ocil:title>Verify·Permissions·on·Backup·shadow·File</ocil:title>46 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_strict_module_rwx_ocil:questionnaire:1">
 47 ······<ocil:title>Make·the·module·text·and·rodata·read-only</ocil:title>
48 ······<ocil:actions>48 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-file_permissions_backup_etc_shadow_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-kernel_config_strict_module_rwx_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>50 ······</ocil:actions>
51 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-sudo_add_noexec_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-set_password_hashing_algorithm_systemauth_ocil:questionnaire:1">
53 ······<ocil:title>Ensure·Privileged·Escalated·Commands·Cannot·Execute·Other·Commands·-·sudo·NOEXEC</ocil:title>53 ······<ocil:title>Set·PAM''s·Password·Hashing·Algorithm</ocil:title>
54 ······<ocil:actions>54 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-sudo_add_noexec_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-set_password_hashing_algorithm_systemauth_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>56 ······</ocil:actions>
57 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-service_syslogng_enabled_ocil:questionnaire:1"> 
59 ······<ocil:title>Enable·syslog-ng·Service</ocil:title>58 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_dictcheck_ocil:questionnaire:1">
 59 ······<ocil:title>Ensure·PAM·Enforces·Password·Requirements·-·Prevent·the·Use·of·Dictionary·Words</ocil:title>
60 ······<ocil:actions>60 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-service_syslogng_enabled_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-accounts_password_pam_dictcheck_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>62 ······</ocil:actions>
63 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_sudoers_d_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-package_abrt-addon-kerneloops_removed_ocil:questionnaire:1">
65 ······<ocil:title>Ensure·auditd·Collects·System·Administrator·Actions·-·/etc/sudoers.d/</ocil:title>65 ······<ocil:title>Uninstall·abrt-addon-kerneloops·Package</ocil:title>
66 ······<ocil:actions>66 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-audit_rules_sudoers_d_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-package_abrt-addon-kerneloops_removed_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>68 ······</ocil:actions>
69 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_x11_forwarding_ocil:questionnaire:1"> 
71 ······<ocil:title>Disable·X11·Forwarding</ocil:title>70 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_chsh_ocil:questionnaire:1">
 71 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·chsh</ocil:title>
72 ······<ocil:actions>72 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_x11_forwarding_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_chsh_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>74 ······</ocil:actions>
75 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-file_groupownership_home_directories_ocil:questionnaire:1"> 
77 ······<ocil:title>All·Interactive·User·Home·Directories·Must·Be·Group-Owned·By·The·Primary·Group</ocil:title>76 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_bug_ocil:questionnaire:1">
 77 ······<ocil:title>Enable·support·for·BUG()</ocil:title>
78 ······<ocil:actions>78 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-file_groupownership_home_directories_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-kernel_config_bug_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>80 ······</ocil:actions>
81 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-no_rsh_trust_files_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_module_sig_sha512_ocil:questionnaire:1">
83 ······<ocil:title>Remove·Rsh·Trust·Files</ocil:title>83 ······<ocil:title>Sign·kernel·modules·with·SHA-512</ocil:title>
84 ······<ocil:actions>84 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-no_rsh_trust_files_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-kernel_config_module_sig_sha512_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>86 ······</ocil:actions>
87 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_postdrop_ocil:questionnaire:1"> 
89 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·postdrop</ocil:title>88 ····<ocil:questionnaire·id="ocil:ssg-grub2_l1tf_argument_ocil:questionnaire:1">
 89 ······<ocil:title>Configure·L1·Terminal·Fault·mitigations</ocil:title>
90 ······<ocil:actions>90 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_postdrop_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-grub2_l1tf_argument_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>92 ······</ocil:actions>
93 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-package_abrt-plugin-logger_removed_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_binfmt_misc_ocil:questionnaire:1">
95 ······<ocil:title>Uninstall·abrt-plugin-logger·Package</ocil:title>95 ······<ocil:title>Disable·kernel·support·for·MISC·binaries</ocil:title>
96 ······<ocil:actions>96 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-package_abrt-plugin-logger_removed_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-kernel_config_binfmt_misc_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>98 ······</ocil:actions>
99 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-sudo_vdsm_nopasswd_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-file_owner_var_log_messages_ocil:questionnaire:1">
101 ······<ocil:title>Only·the·VDSM·User·Can·Use·sudo·NOPASSWD</ocil:title>101 ······<ocil:title>Verify·User·Who·Owns·/var/log/messages·File</ocil:title>
102 ······<ocil:actions>102 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-sudo_vdsm_nopasswd_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-file_owner_var_log_messages_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>104 ······</ocil:actions>
105 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_mac_modification_usr_share_ocil:questionnaire:1"> 
107 ······<ocil:title>Record·Events·that·Modify·the·System's·Mandatory·Access·Controls·in·usr/share</ocil:title>106 ····<ocil:questionnaire·id="ocil:ssg-no_insecure_locks_exports_ocil:questionnaire:1">
 107 ······<ocil:title>Ensure·Insecure·File·Locking·is·Not·Allowed</ocil:title>
108 ······<ocil:actions>108 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-audit_rules_mac_modification_usr_share_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-no_insecure_locks_exports_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>110 ······</ocil:actions>
111 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-accounts_user_interactive_home_directory_exists_ocil:questionnaire:1">112 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_rhosts_ocil:questionnaire:1">
113 ······<ocil:title>All·Interactive·Users·Home·Directories·Must·Exist</ocil:title>113 ······<ocil:title>Disable·SSH·Support·for·.rhosts·Files</ocil:title>
114 ······<ocil:actions>114 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-accounts_user_interactive_home_directory_exists_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_rhosts_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>116 ······</ocil:actions>
117 ····</ocil:questionnaire>117 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-service_debug-shell_disabled_ocil:questionnaire:1">118 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_unmap_kernel_at_el0_ocil:questionnaire:1">
119 ······<ocil:title>Disable·debug-shell·SystemD·Service</ocil:title>119 ······<ocil:title>Unmap·kernel·when·running·in·userspace·(aka·KAISER)</ocil:title>
120 ······<ocil:actions>120 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-service_debug-shell_disabled_action:testaction:1</ocil:test_action_ref>121 ········<ocil:test_action_ref>ocil:ssg-kernel_config_unmap_kernel_at_el0_action:testaction:1</ocil:test_action_ref>
Max diff block lines reached; 2046361/2058843 bytes (99.39%) of diff not shown.
414 KB
./usr/share/xml/scap/ssg/content/ssg-fedora-xccdf.xml
413 KB
./usr/share/xml/scap/ssg/content/ssg-fedora-xccdf.xml
Ordering differences only
    
Offset 71, 167 lines modifiedOffset 71, 181 lines modified
71 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>71 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
72 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>72 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
73 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>73 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
74 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>74 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
75 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>75 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
77 ··<cpe-lang:platform-specification>77 ··<cpe-lang:platform-specification>
78 ····<cpe-lang:platform·id="package_libuser">78 ····<cpe-lang:platform·id="not_aarch64_arch_and_not_ppc64le_arch_and_system_with_kernel">
79 ······<cpe-lang:logical-test·operator="AND"·negate="false">79 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 80 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 81 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
 82 ········</cpe-lang:logical-test>
 83 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 84 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_ppc64le:def:1"/>
 85 ········</cpe-lang:logical-test>
80 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml"·id-ref="oval:ssg-package_libuser:def:1"/>86 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
81 ······</cpe-lang:logical-test>87 ······</cpe-lang:logical-test>
82 ····</cpe-lang:platform>88 ····</cpe-lang:platform>
83 ····<cpe-lang:platform·id="not_bootc">89 ····<cpe-lang:platform·id="not_runtime_kernel_fips_enabled_and_system_with_kernel">
 90 ······<cpe-lang:logical-test·operator="AND"·negate="false">
84 ······<cpe-lang:logical-test·operator="AND"·negate="true">91 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 92 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml"·id-ref="oval:ssg-runtime_kernel_fips_enabled:def:1"/>
 93 ········</cpe-lang:logical-test>
85 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml"·id-ref="oval:ssg-bootc:def:1"/>94 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
86 ······</cpe-lang:logical-test>95 ······</cpe-lang:logical-test>
87 ····</cpe-lang:platform>96 ····</cpe-lang:platform>
88 ····<cpe-lang:platform·id="machine">97 ····<cpe-lang:platform·id="package_polkit">
89 ······<cpe-lang:logical-test·operator="AND"·negate="false">98 ······<cpe-lang:logical-test·operator="AND"·negate="false">
90 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>99 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml"·id-ref="oval:ssg-package_polkit:def:1"/>
91 ······</cpe-lang:logical-test>100 ······</cpe-lang:logical-test>
92 ····</cpe-lang:platform>101 ····</cpe-lang:platform>
93 ····<cpe-lang:platform·id="package_pam">102 ····<cpe-lang:platform·id="mount_var-tmp">
94 ······<cpe-lang:logical-test·operator="AND"·negate="false">103 ······<cpe-lang:logical-test·operator="AND"·negate="false">
95 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>104 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-tmp:def:1"/>
96 ······</cpe-lang:logical-test>105 ······</cpe-lang:logical-test>
97 ····</cpe-lang:platform>106 ····</cpe-lang:platform>
98 ····<cpe-lang:platform·id="package_autofs_and_system_with_kernel">107 ····<cpe-lang:platform·id="package_autofs_and_system_with_kernel">
99 ······<cpe-lang:logical-test·operator="AND"·negate="false">108 ······<cpe-lang:logical-test·operator="AND"·negate="false">
100 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>109 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>
101 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>110 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
102 ······</cpe-lang:logical-test>111 ······</cpe-lang:logical-test>
103 ····</cpe-lang:platform>112 ····</cpe-lang:platform>
104 ····<cpe-lang:platform·id="mount_tmp">113 ····<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">
105 ······<cpe-lang:logical-test·operator="AND"·negate="false">114 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 115 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 116 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
 117 ········</cpe-lang:logical-test>
 118 ········<cpe-lang:logical-test·operator="AND"·negate="true">
106 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_tmp:def:1"/>119 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
 120 ········</cpe-lang:logical-test>
 121 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
107 ······</cpe-lang:logical-test>122 ······</cpe-lang:logical-test>
108 ····</cpe-lang:platform>123 ····</cpe-lang:platform>
109 ····<cpe-lang:platform·id="package_firewalld_and_package_nftables_and_system_with_kernel">124 ····<cpe-lang:platform·id="ipv6_enabled">
110 ······<cpe-lang:logical-test·operator="AND"·negate="false">125 ······<cpe-lang:logical-test·operator="AND"·negate="false">
111 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/> 
112 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>126 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml"·id-ref="oval:ssg-ipv6_enabled:def:1"/>
113 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
114 ······</cpe-lang:logical-test>127 ······</cpe-lang:logical-test>
115 ····</cpe-lang:platform>128 ····</cpe-lang:platform>
116 ····<cpe-lang:platform·id="not_s390x_arch">129 ····<cpe-lang:platform·id="package_gdm">
117 ······<cpe-lang:logical-test·operator="AND"·negate="false">130 ······<cpe-lang:logical-test·operator="AND"·negate="false">
118 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>131 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml"·id-ref="oval:ssg-package_gdm:def:1"/>
119 ······</cpe-lang:logical-test>132 ······</cpe-lang:logical-test>
120 ····</cpe-lang:platform>133 ····</cpe-lang:platform>
121 ····<cpe-lang:platform·id="mount_var-log">134 ····<cpe-lang:platform·id="package_rsyslog">
122 ······<cpe-lang:logical-test·operator="AND"·negate="false">135 ······<cpe-lang:logical-test·operator="AND"·negate="false">
123 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-log:def:1"/>136 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>
124 ······</cpe-lang:logical-test>137 ······</cpe-lang:logical-test>
125 ····</cpe-lang:platform>138 ····</cpe-lang:platform>
126 ····<cpe-lang:platform·id="uefi">139 ····<cpe-lang:platform·id="not_osbuild_and_system_with_kernel">
127 ······<cpe-lang:logical-test·operator="AND"·negate="false">140 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 141 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 142 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_osbuild:def:1"/>
 143 ········</cpe-lang:logical-test>
128 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>144 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
 145 ······</cpe-lang:logical-test>
 146 ····</cpe-lang:platform>
 147 ····<cpe-lang:platform·id="package_chrony_or_package_ntp">
 148 ······<cpe-lang:logical-test·operator="OR"·negate="false">
 149 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
 150 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml"·id-ref="oval:ssg-package_ntp:def:1"/>
129 ······</cpe-lang:logical-test>151 ······</cpe-lang:logical-test>
130 ····</cpe-lang:platform>152 ····</cpe-lang:platform>
131 ····<cpe-lang:platform·id="package_bash">153 ····<cpe-lang:platform·id="package_bash">
132 ······<cpe-lang:logical-test·operator="AND"·negate="false">154 ······<cpe-lang:logical-test·operator="AND"·negate="false">
133 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>155 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>
134 ······</cpe-lang:logical-test>156 ······</cpe-lang:logical-test>
135 ····</cpe-lang:platform>157 ····</cpe-lang:platform>
136 ····<cpe-lang:platform·id="package_iptables">158 ····<cpe-lang:platform·id="uefi">
137 ······<cpe-lang:logical-test·operator="AND"·negate="false">159 ······<cpe-lang:logical-test·operator="AND"·negate="false">
138 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>160 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>
139 ······</cpe-lang:logical-test>161 ······</cpe-lang:logical-test>
140 ····</cpe-lang:platform>162 ····</cpe-lang:platform>
141 ····<cpe-lang:platform·id="grub2">163 ····<cpe-lang:platform·id="package_logrotate">
142 ······<cpe-lang:logical-test·operator="AND"·negate="false">164 ······<cpe-lang:logical-test·operator="AND"·negate="false">
143 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>165 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml"·id-ref="oval:ssg-package_logrotate:def:1"/>
144 ······</cpe-lang:logical-test>166 ······</cpe-lang:logical-test>
145 ····</cpe-lang:platform>167 ····</cpe-lang:platform>
146 ····<cpe-lang:platform·id="package_sssd">168 ····<cpe-lang:platform·id="package_chrony">
147 ······<cpe-lang:logical-test·operator="AND"·negate="false">169 ······<cpe-lang:logical-test·operator="AND"·negate="false">
148 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml"·id-ref="oval:ssg-package_sssd:def:1"/>170 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
149 ······</cpe-lang:logical-test>171 ······</cpe-lang:logical-test>
150 ····</cpe-lang:platform>172 ····</cpe-lang:platform>
151 ····<cpe-lang:platform·id="wifi-iface">173 ····<cpe-lang:platform·id="package_sssd">
152 ······<cpe-lang:logical-test·operator="AND"·negate="false">174 ······<cpe-lang:logical-test·operator="AND"·negate="false">
153 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_wifi_interface:def:1"/>175 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml"·id-ref="oval:ssg-package_sssd:def:1"/>
154 ······</cpe-lang:logical-test>176 ······</cpe-lang:logical-test>
155 ····</cpe-lang:platform>177 ····</cpe-lang:platform>
156 ····<cpe-lang:platform·id="package_rsyslog">178 ····<cpe-lang:platform·id="package_ufw_and_system_with_kernel">
157 ······<cpe-lang:logical-test·operator="AND"·negate="false">179 ······<cpe-lang:logical-test·operator="AND"·negate="false">
158 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>180 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
 181 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
159 ······</cpe-lang:logical-test>182 ······</cpe-lang:logical-test>
160 ····</cpe-lang:platform>183 ····</cpe-lang:platform>
161 ····<cpe-lang:platform·id="package_systemd">184 ····<cpe-lang:platform·id="package_firewalld">
162 ······<cpe-lang:logical-test·operator="AND"·negate="false">185 ······<cpe-lang:logical-test·operator="AND"·negate="false">
163 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>186 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>
164 ······</cpe-lang:logical-test>187 ······</cpe-lang:logical-test>
165 ····</cpe-lang:platform>188 ····</cpe-lang:platform>
166 ····<cpe-lang:platform·id="package_polkit">189 ····<cpe-lang:platform·id="package_rsh-server">
167 ······<cpe-lang:logical-test·operator="AND"·negate="false">190 ······<cpe-lang:logical-test·operator="AND"·negate="false">
168 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml"·id-ref="oval:ssg-package_polkit:def:1"/>191 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml"·id-ref="oval:ssg-package_rsh-server:def:1"/>
169 ······</cpe-lang:logical-test>192 ······</cpe-lang:logical-test>
170 ····</cpe-lang:platform>193 ····</cpe-lang:platform>
171 ····<cpe-lang:platform·id="mount_var">194 ····<cpe-lang:platform·id="mount_srv">
172 ······<cpe-lang:logical-test·operator="AND"·negate="false">195 ······<cpe-lang:logical-test·operator="AND"·negate="false">
Max diff block lines reached; 409308/423212 bytes (96.71%) of diff not shown.
254 KB
./usr/share/xml/scap/ssg/content/ssg-kylinserver10-ds.xml
254 KB
./usr/share/xml/scap/ssg/content/ssg-kylinserver10-ds.xml
    
Offset 19, 15 lines modifiedOffset 19, 15 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-kylinserver10-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-kylinserver10-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-kylinserver10-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-kylinserver10-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-kylinserver10-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-kylinserver10-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-kylinserver10-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-kylinserver10-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-kylinserver10-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-kylinserver10-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-kylinserver10-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-kylinserver10-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-kylinserver10-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-kylinserver10-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:Kylin:Kylin:V10_SP1:ga:server">28 ······<cpe-dict:cpe-item·name="cpe:/o:Kylin:Kylin:V10_SP1:ga:server">
29 ········<cpe-dict:title·xml:lang="en-us">Kylin·V10·SP1</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Kylin·V10·SP1</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml">oval:ssg-installed_OS_is_kylinserver10:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml">oval:ssg-installed_OS_is_kylinserver10:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ······<cpe-dict:cpe-item·name="cpe:/o:Kylin:Kylin:V10_SP2:ga:server">32 ······<cpe-dict:cpe-item·name="cpe:/o:Kylin:Kylin:V10_SP2:ga:server">
33 ········<cpe-dict:title·xml:lang="en-us">Kylin·V10·SP2</cpe-dict:title>33 ········<cpe-dict:title·xml:lang="en-us">Kylin·V10·SP2</cpe-dict:title>
Offset 35, 15 lines modifiedOffset 35, 15 lines modified
35 ······</cpe-dict:cpe-item>35 ······</cpe-dict:cpe-item>
36 ······<cpe-dict:cpe-item·name="cpe:/o:Kylin:Kylin:V10_SP3:ga:server">36 ······<cpe-dict:cpe-item·name="cpe:/o:Kylin:Kylin:V10_SP3:ga:server">
37 ········<cpe-dict:title·xml:lang="en-us">Kylin·V10·SP3</cpe-dict:title>37 ········<cpe-dict:title·xml:lang="en-us">Kylin·V10·SP3</cpe-dict:title>
38 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml">oval:ssg-installed_OS_is_kylinserver10:def:1</cpe-dict:check>38 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml">oval:ssg-installed_OS_is_kylinserver10:def:1</cpe-dict:check>
39 ······</cpe-dict:cpe-item>39 ······</cpe-dict:cpe-item>
40 ····</cpe-dict:cpe-list>40 ····</cpe-dict:cpe-list>
41 ··</ds:component>41 ··</ds:component>
42 ··<ds:component·id="scap_org.open-scap_comp_ssg-kylinserver10-xccdf.xml"·timestamp="2025-02-28T20:08:00">42 ··<ds:component·id="scap_org.open-scap_comp_ssg-kylinserver10-xccdf.xml"·timestamp="2025-03-01T22:08:00">
43 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_KYLINSERVER10"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">43 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_KYLINSERVER10"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
44 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>44 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
45 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Kylin·Server·10</xccdf-1.2:title>45 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Kylin·Server·10</xccdf-1.2:title>
46 ······<xccdf-1.2:description>46 ······<xccdf-1.2:description>
47 ········This·guide·presents·a·catalog·of·security-relevant47 ········This·guide·presents·a·catalog·of·security-relevant
48 configuration·settings·for·Kylin·Server·10.·It·is·a·rendering·of48 configuration·settings·for·Kylin·Server·10.·It·is·a·rendering·of
49 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)49 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 112, 94 lines modifiedOffset 112, 94 lines modified
112 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>112 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
113 ······<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>113 ······<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
114 ······<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>114 ······<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
115 ······<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>115 ······<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
116 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>116 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
117 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>117 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
118 ······<cpe-lang:platform-specification>118 ······<cpe-lang:platform-specification>
119 ········<cpe-lang:platform·id="machine">119 ········<cpe-lang:platform·id="package_autofs_and_system_with_kernel">
120 ··········<cpe-lang:logical-test·operator="AND"·negate="false">120 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 121 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>
121 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>122 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
122 ··········</cpe-lang:logical-test>123 ··········</cpe-lang:logical-test>
123 ········</cpe-lang:platform>124 ········</cpe-lang:platform>
124 ········<cpe-lang:platform·id="package_pam">125 ········<cpe-lang:platform·id="package_gdm">
125 ··········<cpe-lang:logical-test·operator="AND"·negate="false">126 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
126 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>127 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-package_gdm:def:1"/>
127 ··········</cpe-lang:logical-test>128 ··········</cpe-lang:logical-test>
128 ········</cpe-lang:platform>129 ········</cpe-lang:platform>
129 ········<cpe-lang:platform·id="package_autofs_and_system_with_kernel">130 ········<cpe-lang:platform·id="package_rsyslog">
130 ··········<cpe-lang:logical-test·operator="AND"·negate="false">131 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
131 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>132 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>
132 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
133 ··········</cpe-lang:logical-test>133 ··········</cpe-lang:logical-test>
134 ········</cpe-lang:platform>134 ········</cpe-lang:platform>
135 ········<cpe-lang:platform·id="uefi">135 ········<cpe-lang:platform·id="package_bash">
136 ··········<cpe-lang:logical-test·operator="AND"·negate="false">136 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
137 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>137 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>
138 ··········</cpe-lang:logical-test>138 ··········</cpe-lang:logical-test>
139 ········</cpe-lang:platform>139 ········</cpe-lang:platform>
140 ········<cpe-lang:platform·id="package_bash">140 ········<cpe-lang:platform·id="uefi">
141 ··········<cpe-lang:logical-test·operator="AND"·negate="false">141 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
142 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>142 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>
143 ··········</cpe-lang:logical-test>143 ··········</cpe-lang:logical-test>
144 ········</cpe-lang:platform>144 ········</cpe-lang:platform>
145 ········<cpe-lang:platform·id="package_rsyslog">145 ········<cpe-lang:platform·id="package_chrony">
146 ··········<cpe-lang:logical-test·operator="AND"·negate="false">146 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
147 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>147 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
148 ··········</cpe-lang:logical-test>148 ··········</cpe-lang:logical-test>
149 ········</cpe-lang:platform>149 ········</cpe-lang:platform>
150 ········<cpe-lang:platform·id="package_firewalld">150 ········<cpe-lang:platform·id="package_firewalld">
151 ··········<cpe-lang:logical-test·operator="AND"·negate="false">151 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
152 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>152 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>
153 ··········</cpe-lang:logical-test>153 ··········</cpe-lang:logical-test>
154 ········</cpe-lang:platform>154 ········</cpe-lang:platform>
155 ········<cpe-lang:platform·id="non-uefi">155 ········<cpe-lang:platform·id="package_pam">
156 ··········<cpe-lang:logical-test·operator="AND"·negate="false">156 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
157 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_non_uefi:def:1"/>157 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>
158 ··········</cpe-lang:logical-test>158 ··········</cpe-lang:logical-test>
159 ········</cpe-lang:platform>159 ········</cpe-lang:platform>
160 ········<cpe-lang:platform·id="package_audit">160 ········<cpe-lang:platform·id="machine">
161 ··········<cpe-lang:logical-test·operator="AND"·negate="false">161 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
162 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-package_audit:def:1"/>162 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
163 ··········</cpe-lang:logical-test>163 ··········</cpe-lang:logical-test>
164 ········</cpe-lang:platform>164 ········</cpe-lang:platform>
165 ········<cpe-lang:platform·id="package_sudo">165 ········<cpe-lang:platform·id="package_sudo">
166 ··········<cpe-lang:logical-test·operator="AND"·negate="false">166 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
167 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-package_sudo:def:1"/>167 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-package_sudo:def:1"/>
168 ··········</cpe-lang:logical-test>168 ··········</cpe-lang:logical-test>
169 ········</cpe-lang:platform>169 ········</cpe-lang:platform>
170 ········<cpe-lang:platform·id="grub2_and_system_with_kernel">170 ········<cpe-lang:platform·id="system_with_kernel">
171 ··········<cpe-lang:logical-test·operator="AND"·negate="false">171 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
172 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/> 
173 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>172 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
174 ··········</cpe-lang:logical-test>173 ··········</cpe-lang:logical-test>
175 ········</cpe-lang:platform>174 ········</cpe-lang:platform>
176 ········<cpe-lang:platform·id="package_dnf">175 ········<cpe-lang:platform·id="non-uefi">
177 ··········<cpe-lang:logical-test·operator="AND"·negate="false">176 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
178 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-package_dnf:def:1"/>177 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_non_uefi:def:1"/>
179 ··········</cpe-lang:logical-test>178 ··········</cpe-lang:logical-test>
180 ········</cpe-lang:platform>179 ········</cpe-lang:platform>
181 ········<cpe-lang:platform·id="package_chrony">180 ········<cpe-lang:platform·id="grub2_and_system_with_kernel">
182 ··········<cpe-lang:logical-test·operator="AND"·negate="false">181 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 182 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>
183 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>183 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
184 ··········</cpe-lang:logical-test>184 ··········</cpe-lang:logical-test>
185 ········</cpe-lang:platform>185 ········</cpe-lang:platform>
186 ········<cpe-lang:platform·id="system_with_kernel">186 ········<cpe-lang:platform·id="package_dnf">
187 ··········<cpe-lang:logical-test·operator="AND"·negate="false">187 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
188 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>188 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-package_dnf:def:1"/>
189 ··········</cpe-lang:logical-test>189 ··········</cpe-lang:logical-test>
190 ········</cpe-lang:platform>190 ········</cpe-lang:platform>
191 ········<cpe-lang:platform·id="package_shadow-utils">191 ········<cpe-lang:platform·id="package_audit">
192 ··········<cpe-lang:logical-test·operator="AND"·negate="false">192 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
193 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-package_shadow-utils:def:1"/>193 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-package_audit:def:1"/>
194 ··········</cpe-lang:logical-test>194 ··········</cpe-lang:logical-test>
195 ········</cpe-lang:platform>195 ········</cpe-lang:platform>
196 ········<cpe-lang:platform·id="package_gdm">196 ········<cpe-lang:platform·id="package_shadow-utils">
197 ··········<cpe-lang:logical-test·operator="AND"·negate="false">197 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
198 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-package_gdm:def:1"/>198 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-package_shadow-utils:def:1"/>
199 ··········</cpe-lang:logical-test>199 ··········</cpe-lang:logical-test>
200 ········</cpe-lang:platform>200 ········</cpe-lang:platform>
201 ······</cpe-lang:platform-specification>201 ······</cpe-lang:platform-specification>
202 ······<xccdf-1.2:platform·idref="cpe:/o:Kylin:Kylin:V10_SP1:ga:server"/>202 ······<xccdf-1.2:platform·idref="cpe:/o:Kylin:Kylin:V10_SP1:ga:server"/>
203 ······<xccdf-1.2:platform·idref="cpe:/o:Kylin:Kylin:V10_SP2:ga:server"/>203 ······<xccdf-1.2:platform·idref="cpe:/o:Kylin:Kylin:V10_SP2:ga:server"/>
204 ······<xccdf-1.2:platform·idref="cpe:/o:Kylin:Kylin:V10_SP3:ga:server"/>204 ······<xccdf-1.2:platform·idref="cpe:/o:Kylin:Kylin:V10_SP3:ga:server"/>
Max diff block lines reached; 246745/260243 bytes (94.81%) of diff not shown.
228 KB
./usr/share/xml/scap/ssg/content/ssg-kylinserver10-ocil.xml
228 KB
./usr/share/xml/scap/ssg/content/ssg-kylinserver10-ocil.xml
Ordering differences only
    
Offset 3, 2152 lines modifiedOffset 3, 2369 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-set_password_hashing_algorithm_systemauth_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_ocredit_ocil:questionnaire:1">
 11 ······<ocil:title>Ensure·PAM·Enforces·Password·Requirements·-·Minimum·Special·Characters</ocil:title>
11 ······<ocil:title>Set·PAM''s·Password·Hashing·Algorithm</ocil:title> 
12 ······<ocil:actions> 
13 ········<ocil:test_action_ref>ocil:ssg-set_password_hashing_algorithm_systemauth_action:testaction:1</ocil:test_action_ref> 
14 ······</ocil:actions> 
15 ····</ocil:questionnaire> 
16 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_group_ocil:questionnaire:1"> 
17 ······<ocil:title>Verify·Group·Who·Owns·group·File</ocil:title> 
18 ······<ocil:actions>12 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_group_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-accounts_password_pam_ocredit_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>14 ······</ocil:actions>
21 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-no_netrc_files_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-file_owner_etc_passwd_ocil:questionnaire:1">
23 ······<ocil:title>Verify·No·netrc·Files·Exist</ocil:title>17 ······<ocil:title>Verify·User·Who·Owns·passwd·File</ocil:title>
24 ······<ocil:actions>18 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-no_netrc_files_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-file_owner_etc_passwd_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>20 ······</ocil:actions>
27 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-sudoers_no_root_target_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-service_auditd_enabled_ocil:questionnaire:1">
29 ······<ocil:title>Don't·target·root·user·in·the·sudoers·file</ocil:title>23 ······<ocil:title>Enable·auditd·Service</ocil:title>
30 ······<ocil:actions>24 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-sudoers_no_root_target_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-service_auditd_enabled_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>26 ······</ocil:actions>
33 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_send_redirects_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-package_tftp_removed_ocil:questionnaire:1">
35 ······<ocil:title>Disable·Kernel·Parameter·for·Sending·ICMP·Redirects·on·all·IPv4·Interfaces</ocil:title>29 ······<ocil:title>Remove·tftp·Daemon</ocil:title>
36 ······<ocil:actions>30 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_send_redirects_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-package_tftp_removed_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>32 ······</ocil:actions>
39 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-package_chrony_installed_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-require_singleuser_auth_ocil:questionnaire:1">
41 ······<ocil:title>The·Chrony·package·is·installed</ocil:title>35 ······<ocil:title>Require·Authentication·for·Single·User·Mode</ocil:title>
42 ······<ocil:actions>36 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-package_chrony_installed_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-require_singleuser_auth_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>38 ······</ocil:actions>
45 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-package_openssh-server_installed_ocil:questionnaire:1"> 
47 ······<ocil:title>Install·the·OpenSSH·Server·Package</ocil:title>40 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_retry_ocil:questionnaire:1">
 41 ······<ocil:title>Ensure·PAM·Enforces·Password·Requirements·-·Authentication·Retry·Prompts·Permitted·Per-Session</ocil:title>
48 ······<ocil:actions>42 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-package_openssh-server_installed_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-accounts_password_pam_retry_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>44 ······</ocil:actions>
51 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-ensure_gpgcheck_globally_activated_ocil:questionnaire:1">46 ····<ocil:questionnaire·id="ocil:ssg-disable_host_auth_ocil:questionnaire:1">
53 ······<ocil:title>Ensure·gpgcheck·Enabled·In·Main·dnf·Configuration</ocil:title>47 ······<ocil:title>Disable·Host-Based·Authentication</ocil:title>
54 ······<ocil:actions>48 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-ensure_gpgcheck_globally_activated_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-disable_host_auth_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>50 ······</ocil:actions>
57 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-file_owner_etc_group_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-banner_etc_issue_ocil:questionnaire:1">
59 ······<ocil:title>Verify·User·Who·Owns·group·File</ocil:title>53 ······<ocil:title>Modify·the·System·Login·Banner</ocil:title>
60 ······<ocil:actions>54 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-file_owner_etc_group_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-banner_etc_issue_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>56 ······</ocil:actions>
63 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_ip_forward_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-ensure_gpgcheck_never_disabled_ocil:questionnaire:1">
65 ······<ocil:title>Disable·Kernel·Parameter·for·IP·Forwarding·on·IPv4·Interfaces</ocil:title>59 ······<ocil:title>Ensure·gpgcheck·Enabled·for·All·dnf·Package·Repositories</ocil:title>
66 ······<ocil:actions>60 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_ip_forward_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-ensure_gpgcheck_never_disabled_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>62 ······</ocil:actions>
69 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-grub2_password_ocil:questionnaire:1"> 
71 ······<ocil:title>Set·Boot·Loader·Password·in·grub2</ocil:title>64 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_rp_filter_ocil:questionnaire:1">
 65 ······<ocil:title>Enable·Kernel·Parameter·to·Use·Reverse·Path·Filtering·on·all·IPv4·Interfaces·by·Default</ocil:title>
72 ······<ocil:actions>66 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-grub2_password_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_rp_filter_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>68 ······</ocil:actions>
75 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-service_nfs_disabled_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_passwd_ocil:questionnaire:1">
77 ······<ocil:title>Disable·Network·File·System·(nfs)</ocil:title>71 ······<ocil:title>Verify·Permissions·on·passwd·File</ocil:title>
78 ······<ocil:actions>72 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-service_nfs_disabled_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-file_permissions_etc_passwd_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>74 ······</ocil:actions>
81 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-accounts_max_concurrent_login_sessions_ocil:questionnaire:1"> 
83 ······<ocil:title>Limit·the·Number·of·Concurrent·Login·Sessions·Allowed·Per·User</ocil:title>76 ····<ocil:questionnaire·id="ocil:ssg-ensure_gpgcheck_globally_activated_ocil:questionnaire:1">
 77 ······<ocil:title>Ensure·gpgcheck·Enabled·In·Main·dnf·Configuration</ocil:title>
84 ······<ocil:actions>78 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-accounts_max_concurrent_login_sessions_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-ensure_gpgcheck_globally_activated_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>80 ······</ocil:actions>
87 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-grub2_uefi_password_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-no_files_unowned_by_user_ocil:questionnaire:1">
89 ······<ocil:title>Set·the·UEFI·Boot·Loader·Password</ocil:title>83 ······<ocil:title>Ensure·All·Files·Are·Owned·by·a·User</ocil:title>
90 ······<ocil:actions>84 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-grub2_uefi_password_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-no_files_unowned_by_user_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>86 ······</ocil:actions>
93 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-package_net-snmp_removed_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-sshd_print_last_log_ocil:questionnaire:1">
95 ······<ocil:title>Uninstall·net-snmp·Package</ocil:title>89 ······<ocil:title>Enable·SSH·Print·Last·Log</ocil:title>
96 ······<ocil:actions>90 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-package_net-snmp_removed_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-sshd_print_last_log_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>92 ······</ocil:actions>
99 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_icmp_echo_ignore_broadcasts_ocil:questionnaire:1"> 
101 ······<ocil:title>Enable·Kernel·Parameter·to·Ignore·ICMP·Broadcast·Echo·Requests·on·IPv4·Interfaces</ocil:title>94 ····<ocil:questionnaire·id="ocil:ssg-use_pam_wheel_for_su_ocil:questionnaire:1">
 95 ······<ocil:title>Enforce·usage·of·pam_wheel·for·su·authentication</ocil:title>
102 ······<ocil:actions>96 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_icmp_echo_ignore_broadcasts_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-use_pam_wheel_for_su_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>98 ······</ocil:actions>
105 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_rp_filter_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_send_redirects_ocil:questionnaire:1">
107 ······<ocil:title>Enable·Kernel·Parameter·to·Use·Reverse·Path·Filtering·on·all·IPv4·Interfaces</ocil:title>101 ······<ocil:title>Disable·Kernel·Parameter·for·Sending·ICMP·Redirects·on·all·IPv4·Interfaces</ocil:title>
108 ······<ocil:actions>102 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_rp_filter_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_send_redirects_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>104 ······</ocil:actions>
111 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-sudo_restrict_privilege_elevation_to_authorized_ocil:questionnaire:1"> 
113 ······<ocil:title>The·operating·system·must·restrict·privilege·elevation·to·authorized·personnel</ocil:title>106 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_shadow_ocil:questionnaire:1">
 107 ······<ocil:title>Verify·Permissions·on·shadow·File</ocil:title>
114 ······<ocil:actions>108 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-sudo_restrict_privilege_elevation_to_authorized_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-file_permissions_etc_shadow_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>110 ······</ocil:actions>
117 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-service_psacct_enabled_ocil:questionnaire:1">112 ····<ocil:questionnaire·id="ocil:ssg-sshd_limit_user_access_ocil:questionnaire:1">
119 ······<ocil:title>Enable·Process·Accounting·(psacct)</ocil:title>113 ······<ocil:title>Limit·Users'·SSH·Access</ocil:title>
120 ······<ocil:actions>114 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-service_psacct_enabled_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-sshd_limit_user_access_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>116 ······</ocil:actions>
123 ····</ocil:questionnaire>117 ····</ocil:questionnaire>
Max diff block lines reached; 221182/233556 bytes (94.70%) of diff not shown.
10.3 KB
./usr/share/xml/scap/ssg/content/ssg-kylinserver10-xccdf.xml
10.2 KB
./usr/share/xml/scap/ssg/content/ssg-kylinserver10-xccdf.xml
Ordering differences only
    
Offset 71, 94 lines modifiedOffset 71, 94 lines modified
71 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>71 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
72 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>72 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
73 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>73 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
74 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>74 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
75 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>75 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
77 ··<cpe-lang:platform-specification>77 ··<cpe-lang:platform-specification>
78 ····<cpe-lang:platform·id="machine">78 ····<cpe-lang:platform·id="package_autofs_and_system_with_kernel">
79 ······<cpe-lang:logical-test·operator="AND"·negate="false">79 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 80 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>
80 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>81 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
81 ······</cpe-lang:logical-test>82 ······</cpe-lang:logical-test>
82 ····</cpe-lang:platform>83 ····</cpe-lang:platform>
83 ····<cpe-lang:platform·id="package_pam">84 ····<cpe-lang:platform·id="package_gdm">
84 ······<cpe-lang:logical-test·operator="AND"·negate="false">85 ······<cpe-lang:logical-test·operator="AND"·negate="false">
85 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>86 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-package_gdm:def:1"/>
86 ······</cpe-lang:logical-test>87 ······</cpe-lang:logical-test>
87 ····</cpe-lang:platform>88 ····</cpe-lang:platform>
88 ····<cpe-lang:platform·id="package_autofs_and_system_with_kernel">89 ····<cpe-lang:platform·id="package_rsyslog">
89 ······<cpe-lang:logical-test·operator="AND"·negate="false">90 ······<cpe-lang:logical-test·operator="AND"·negate="false">
90 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>91 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>
91 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
92 ······</cpe-lang:logical-test>92 ······</cpe-lang:logical-test>
93 ····</cpe-lang:platform>93 ····</cpe-lang:platform>
94 ····<cpe-lang:platform·id="uefi">94 ····<cpe-lang:platform·id="package_bash">
95 ······<cpe-lang:logical-test·operator="AND"·negate="false">95 ······<cpe-lang:logical-test·operator="AND"·negate="false">
96 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>96 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>
97 ······</cpe-lang:logical-test>97 ······</cpe-lang:logical-test>
98 ····</cpe-lang:platform>98 ····</cpe-lang:platform>
99 ····<cpe-lang:platform·id="package_bash">99 ····<cpe-lang:platform·id="uefi">
100 ······<cpe-lang:logical-test·operator="AND"·negate="false">100 ······<cpe-lang:logical-test·operator="AND"·negate="false">
101 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>101 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>
102 ······</cpe-lang:logical-test>102 ······</cpe-lang:logical-test>
103 ····</cpe-lang:platform>103 ····</cpe-lang:platform>
104 ····<cpe-lang:platform·id="package_rsyslog">104 ····<cpe-lang:platform·id="package_chrony">
105 ······<cpe-lang:logical-test·operator="AND"·negate="false">105 ······<cpe-lang:logical-test·operator="AND"·negate="false">
106 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>106 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
107 ······</cpe-lang:logical-test>107 ······</cpe-lang:logical-test>
108 ····</cpe-lang:platform>108 ····</cpe-lang:platform>
109 ····<cpe-lang:platform·id="package_firewalld">109 ····<cpe-lang:platform·id="package_firewalld">
110 ······<cpe-lang:logical-test·operator="AND"·negate="false">110 ······<cpe-lang:logical-test·operator="AND"·negate="false">
111 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>111 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>
112 ······</cpe-lang:logical-test>112 ······</cpe-lang:logical-test>
113 ····</cpe-lang:platform>113 ····</cpe-lang:platform>
114 ····<cpe-lang:platform·id="non-uefi">114 ····<cpe-lang:platform·id="package_pam">
115 ······<cpe-lang:logical-test·operator="AND"·negate="false">115 ······<cpe-lang:logical-test·operator="AND"·negate="false">
116 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_non_uefi:def:1"/>116 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>
117 ······</cpe-lang:logical-test>117 ······</cpe-lang:logical-test>
118 ····</cpe-lang:platform>118 ····</cpe-lang:platform>
119 ····<cpe-lang:platform·id="package_audit">119 ····<cpe-lang:platform·id="machine">
120 ······<cpe-lang:logical-test·operator="AND"·negate="false">120 ······<cpe-lang:logical-test·operator="AND"·negate="false">
121 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-package_audit:def:1"/>121 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
122 ······</cpe-lang:logical-test>122 ······</cpe-lang:logical-test>
123 ····</cpe-lang:platform>123 ····</cpe-lang:platform>
124 ····<cpe-lang:platform·id="package_sudo">124 ····<cpe-lang:platform·id="package_sudo">
125 ······<cpe-lang:logical-test·operator="AND"·negate="false">125 ······<cpe-lang:logical-test·operator="AND"·negate="false">
126 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-package_sudo:def:1"/>126 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-package_sudo:def:1"/>
127 ······</cpe-lang:logical-test>127 ······</cpe-lang:logical-test>
128 ····</cpe-lang:platform>128 ····</cpe-lang:platform>
129 ····<cpe-lang:platform·id="grub2_and_system_with_kernel">129 ····<cpe-lang:platform·id="system_with_kernel">
130 ······<cpe-lang:logical-test·operator="AND"·negate="false">130 ······<cpe-lang:logical-test·operator="AND"·negate="false">
131 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/> 
132 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>131 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
133 ······</cpe-lang:logical-test>132 ······</cpe-lang:logical-test>
134 ····</cpe-lang:platform>133 ····</cpe-lang:platform>
135 ····<cpe-lang:platform·id="package_dnf">134 ····<cpe-lang:platform·id="non-uefi">
136 ······<cpe-lang:logical-test·operator="AND"·negate="false">135 ······<cpe-lang:logical-test·operator="AND"·negate="false">
137 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-package_dnf:def:1"/>136 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_non_uefi:def:1"/>
138 ······</cpe-lang:logical-test>137 ······</cpe-lang:logical-test>
139 ····</cpe-lang:platform>138 ····</cpe-lang:platform>
140 ····<cpe-lang:platform·id="package_chrony">139 ····<cpe-lang:platform·id="grub2_and_system_with_kernel">
141 ······<cpe-lang:logical-test·operator="AND"·negate="false">140 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 141 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>
142 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>142 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
143 ······</cpe-lang:logical-test>143 ······</cpe-lang:logical-test>
144 ····</cpe-lang:platform>144 ····</cpe-lang:platform>
145 ····<cpe-lang:platform·id="system_with_kernel">145 ····<cpe-lang:platform·id="package_dnf">
146 ······<cpe-lang:logical-test·operator="AND"·negate="false">146 ······<cpe-lang:logical-test·operator="AND"·negate="false">
147 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>147 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-package_dnf:def:1"/>
148 ······</cpe-lang:logical-test>148 ······</cpe-lang:logical-test>
149 ····</cpe-lang:platform>149 ····</cpe-lang:platform>
150 ····<cpe-lang:platform·id="package_shadow-utils">150 ····<cpe-lang:platform·id="package_audit">
151 ······<cpe-lang:logical-test·operator="AND"·negate="false">151 ······<cpe-lang:logical-test·operator="AND"·negate="false">
152 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-package_shadow-utils:def:1"/>152 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-package_audit:def:1"/>
153 ······</cpe-lang:logical-test>153 ······</cpe-lang:logical-test>
154 ····</cpe-lang:platform>154 ····</cpe-lang:platform>
155 ····<cpe-lang:platform·id="package_gdm">155 ····<cpe-lang:platform·id="package_shadow-utils">
156 ······<cpe-lang:logical-test·operator="AND"·negate="false">156 ······<cpe-lang:logical-test·operator="AND"·negate="false">
157 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-package_gdm:def:1"/>157 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-package_shadow-utils:def:1"/>
158 ······</cpe-lang:logical-test>158 ······</cpe-lang:logical-test>
159 ····</cpe-lang:platform>159 ····</cpe-lang:platform>
160 ··</cpe-lang:platform-specification>160 ··</cpe-lang:platform-specification>
161 ··<xccdf-1.2:platform·idref="cpe:/o:Kylin:Kylin:V10_SP1:ga:server"/>161 ··<xccdf-1.2:platform·idref="cpe:/o:Kylin:Kylin:V10_SP1:ga:server"/>
162 ··<xccdf-1.2:platform·idref="cpe:/o:Kylin:Kylin:V10_SP2:ga:server"/>162 ··<xccdf-1.2:platform·idref="cpe:/o:Kylin:Kylin:V10_SP2:ga:server"/>
163 ··<xccdf-1.2:platform·idref="cpe:/o:Kylin:Kylin:V10_SP3:ga:server"/>163 ··<xccdf-1.2:platform·idref="cpe:/o:Kylin:Kylin:V10_SP3:ga:server"/>
164 ··<xccdf-1.2:version·update="https://github.com/ComplianceAsCode/content/releases/latest">0.1.76</xccdf-1.2:version>164 ··<xccdf-1.2:version·update="https://github.com/ComplianceAsCode/content/releases/latest">0.1.76</xccdf-1.2:version>
5.76 KB
./usr/share/xml/scap/ssg/content/ssg-macos1015-ds.xml
5.65 KB
./usr/share/xml/scap/ssg/content/ssg-macos1015-ds.xml
    
Offset 19, 23 lines modifiedOffset 19, 23 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-macos1015-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-macos1015-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-macos1015-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-macos1015-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-macos1015-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-macos1015-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-macos1015-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-macos1015-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-macos1015-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-macos1015-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-macos1015-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-macos1015-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-macos1015-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-macos1015-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:apple:macos:10.15">28 ······<cpe-dict:cpe-item·name="cpe:/o:apple:macos:10.15">
29 ········<cpe-dict:title·xml:lang="en-us">Apple·macOS·10.15</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Apple·macOS·10.15</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-macos1015-cpe-oval.xml">oval:ssg-installed_OS_is_macos1015:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-macos1015-cpe-oval.xml">oval:ssg-installed_OS_is_macos1015:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ····</cpe-dict:cpe-list>32 ····</cpe-dict:cpe-list>
33 ··</ds:component>33 ··</ds:component>
34 ··<ds:component·id="scap_org.open-scap_comp_ssg-macos1015-xccdf.xml"·timestamp="2025-02-28T20:08:00">34 ··<ds:component·id="scap_org.open-scap_comp_ssg-macos1015-xccdf.xml"·timestamp="2025-03-01T22:08:00">
35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_macOS-1015"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_macOS-1015"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Apple·macOS·10.15</xccdf-1.2:title>37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Apple·macOS·10.15</xccdf-1.2:title>
38 ······<xccdf-1.2:description>38 ······<xccdf-1.2:description>
39 ········This·guide·presents·a·catalog·of·security-relevant39 ········This·guide·presents·a·catalog·of·security-relevant
40 configuration·settings·for·Apple·macOS·10.15.·It·is·a·rendering·of40 configuration·settings·for·Apple·macOS·10.15.·It·is·a·rendering·of
41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 563, 15 lines modifiedOffset 563, 15 lines modified
563 ··············<xccdf-1.2:check-content-ref·href="ssg-macos1015-ocil.xml"·name="ocil:ssg-audit_failure_halt_ocil:questionnaire:1"/>563 ··············<xccdf-1.2:check-content-ref·href="ssg-macos1015-ocil.xml"·name="ocil:ssg-audit_failure_halt_ocil:questionnaire:1"/>
564 ············</xccdf-1.2:check>564 ············</xccdf-1.2:check>
565 ··········</xccdf-1.2:Rule>565 ··········</xccdf-1.2:Rule>
566 ········</xccdf-1.2:Group>566 ········</xccdf-1.2:Group>
567 ······</xccdf-1.2:Group>567 ······</xccdf-1.2:Group>
568 ····</xccdf-1.2:Benchmark>568 ····</xccdf-1.2:Benchmark>
569 ··</ds:component>569 ··</ds:component>
570 ··<ds:component·id="scap_org.open-scap_comp_ssg-macos1015-oval.xml"·timestamp="2025-02-28T20:08:00">570 ··<ds:component·id="scap_org.open-scap_comp_ssg-macos1015-oval.xml"·timestamp="2025-03-01T22:08:00">
571 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">571 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
572 ······<oval-def:generator>572 ······<oval-def:generator>
573 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>573 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
574 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.2</oval:product_version>574 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.2</oval:product_version>
575 ········<oval:schema_version>5.11</oval:schema_version>575 ········<oval:schema_version>5.11</oval:schema_version>
576 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>576 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
577 ······</oval-def:generator>577 ······</oval-def:generator>
Offset 600, 15 lines modifiedOffset 600, 15 lines modified
600 ··········<ind:filepath>/etc/security/audit_control</ind:filepath>600 ··········<ind:filepath>/etc/security/audit_control</ind:filepath>
601 ··········<ind:pattern·operation="pattern·match">^policy:.*,ahlt.*$</ind:pattern>601 ··········<ind:pattern·operation="pattern·match">^policy:.*,ahlt.*$</ind:pattern>
602 ··········<ind:instance·datatype="int">1</ind:instance>602 ··········<ind:instance·datatype="int">1</ind:instance>
603 ········</ind:textfilecontent54_object>603 ········</ind:textfilecontent54_object>
604 ······</oval-def:objects>604 ······</oval-def:objects>
605 ····</oval-def:oval_definitions>605 ····</oval-def:oval_definitions>
606 ··</ds:component>606 ··</ds:component>
607 ··<ds:component·id="scap_org.open-scap_comp_ssg-macos1015-ocil.xml"·timestamp="2025-02-28T20:08:00">607 ··<ds:component·id="scap_org.open-scap_comp_ssg-macos1015-ocil.xml"·timestamp="2025-03-01T22:08:00">
608 ····<ocil:ocil>608 ····<ocil:ocil>
609 ······<ocil:generator>609 ······<ocil:generator>
610 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>610 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
611 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>611 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
612 ········<ocil:schema_version>2.0</ocil:schema_version>612 ········<ocil:schema_version>2.0</ocil:schema_version>
613 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>613 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
614 ······</ocil:generator>614 ······</ocil:generator>
Offset 659, 15 lines modifiedOffset 659, 15 lines modified
659 $·sudo·grep·-E·"^policy.*ahlt"·/etc/security/audit_control659 $·sudo·grep·-E·"^policy.*ahlt"·/etc/security/audit_control
660 The·output·should·contain·ahlt660 The·output·should·contain·ahlt
661 ······Is·it·the·case·that·auditing·is·not·configured·to·shut·down·on·audit·failure?</ocil:question_text>661 ······Is·it·the·case·that·auditing·is·not·configured·to·shut·down·on·audit·failure?</ocil:question_text>
662 ········</ocil:boolean_question>662 ········</ocil:boolean_question>
663 ······</ocil:questions>663 ······</ocil:questions>
664 ····</ocil:ocil>664 ····</ocil:ocil>
665 ··</ds:component>665 ··</ds:component>
666 ··<ds:component·id="scap_org.open-scap_comp_ssg-macos1015-cpe-oval.xml"·timestamp="2025-02-28T20:08:00">666 ··<ds:component·id="scap_org.open-scap_comp_ssg-macos1015-cpe-oval.xml"·timestamp="2025-03-01T22:08:00">
667 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">667 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
668 ······<oval-def:generator>668 ······<oval-def:generator>
669 ········<oval:product_name>build_cpe.py·from·SCAP·Security·Guide</oval:product_name>669 ········<oval:product_name>build_cpe.py·from·SCAP·Security·Guide</oval:product_name>
670 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.2</oval:product_version>670 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.2</oval:product_version>
671 ········<oval:schema_version>5.11</oval:schema_version>671 ········<oval:schema_version>5.11</oval:schema_version>
672 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>672 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
673 ······</oval-def:generator>673 ······</oval-def:generator>
905 KB
./usr/share/xml/scap/ssg/content/ssg-ocp4-ds.xml
905 KB
./usr/share/xml/scap/ssg/content/ssg-ocp4-ds.xml
    
Offset 19, 15 lines modifiedOffset 19, 15 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ocp4-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ocp4-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ocp4-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ocp4-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ocp4-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ocp4-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ocp4-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ocp4-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ocp4-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ocp4-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ocp4-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ocp4-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-ocp4-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-ocp4-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/a:redhat:openshift_container_platform:4.1">28 ······<cpe-dict:cpe-item·name="cpe:/a:redhat:openshift_container_platform:4.1">
29 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·OpenShift·Container·Platform·4</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·OpenShift·Container·Platform·4</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml">oval:ssg-installed_app_is_ocp4:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml">oval:ssg-installed_app_is_ocp4:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ······<cpe-dict:cpe-item·name="cpe:/a:redhat:openshift_container_platform:4.10">32 ······<cpe-dict:cpe-item·name="cpe:/a:redhat:openshift_container_platform:4.10">
33 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·OpenShift·Container·Platform·4.10</cpe-dict:title>33 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·OpenShift·Container·Platform·4.10</cpe-dict:title>
Offset 111, 15 lines modifiedOffset 111, 15 lines modified
111 ······</cpe-dict:cpe-item>111 ······</cpe-dict:cpe-item>
112 ······<cpe-dict:cpe-item·name="cpe:/o:redhat:openshift_container_platform_node:4">112 ······<cpe-dict:cpe-item·name="cpe:/o:redhat:openshift_container_platform_node:4">
113 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·OpenShift·Container·Platform·4·Node</cpe-dict:title>113 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·OpenShift·Container·Platform·4·Node</cpe-dict:title>
114 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml">oval:ssg-installed_app_is_ocp4_node:def:1</cpe-dict:check>114 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml">oval:ssg-installed_app_is_ocp4_node:def:1</cpe-dict:check>
115 ······</cpe-dict:cpe-item>115 ······</cpe-dict:cpe-item>
116 ····</cpe-dict:cpe-list>116 ····</cpe-dict:cpe-list>
117 ··</ds:component>117 ··</ds:component>
118 ··<ds:component·id="scap_org.open-scap_comp_ssg-ocp4-xccdf.xml"·timestamp="2025-02-28T20:08:00">118 ··<ds:component·id="scap_org.open-scap_comp_ssg-ocp4-xccdf.xml"·timestamp="2025-03-01T22:08:00">
119 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_OCP-4"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">119 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_OCP-4"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
120 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>120 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
121 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Red·Hat·OpenShift·Container·Platform·4</xccdf-1.2:title>121 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Red·Hat·OpenShift·Container·Platform·4</xccdf-1.2:title>
122 ······<xccdf-1.2:description>122 ······<xccdf-1.2:description>
123 ········This·guide·presents·a·catalog·of·security-relevant123 ········This·guide·presents·a·catalog·of·security-relevant
124 configuration·settings·for·Red·Hat·OpenShift·Container·Platform·4.·It·is·a·rendering·of124 configuration·settings·for·Red·Hat·OpenShift·Container·Platform·4.·It·is·a·rendering·of
125 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)125 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 189, 197 lines modifiedOffset 189, 197 lines modified
189 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>189 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
190 ······<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>190 ······<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
191 ······<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>191 ······<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
192 ······<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>192 ······<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
193 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=container-platform">stigid</xccdf-1.2:reference>193 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=container-platform">stigid</xccdf-1.2:reference>
194 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>194 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
195 ······<cpe-lang:platform-specification>195 ······<cpe-lang:platform-specification>
196 ········<cpe-lang:platform·id="not_ocp4-on-hypershift-hosted_and_ocp4.6_or_ocp4.7_or_ocp4.8">196 ········<cpe-lang:platform·id="not_ocp4-on-hypershift_and_not_ocp4-on-hypershift-hosted">
197 ··········<cpe-lang:logical-test·operator="AND"·negate="false">197 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
198 ············<cpe-lang:logical-test·operator="AND"·negate="true">198 ············<cpe-lang:logical-test·operator="AND"·negate="true">
199 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_on_hypershift_hosted:def:1"/>199 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_on_hypershift:def:1"/>
200 ············</cpe-lang:logical-test>200 ············</cpe-lang:logical-test>
201 ············<cpe-lang:logical-test·operator="OR"·negate="false">201 ············<cpe-lang:logical-test·operator="AND"·negate="true">
202 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_6:def:1"/>202 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_on_hypershift_hosted:def:1"/>
203 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_7:def:1"/> 
204 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_8:def:1"/> 
205 ············</cpe-lang:logical-test>203 ············</cpe-lang:logical-test>
206 ··········</cpe-lang:logical-test>204 ··········</cpe-lang:logical-test>
207 ········</cpe-lang:platform>205 ········</cpe-lang:platform>
208 ········<cpe-lang:platform·id="ocp4-on-gcp"> 
209 ··········<cpe-lang:logical-test·operator="AND"·negate="false"> 
210 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_on_gcp:def:1"/> 
211 ··········</cpe-lang:logical-test> 
212 ········</cpe-lang:platform> 
213 ········<cpe-lang:platform·id="ocp4.10_or_ocp4.8_or_ocp4.9"> 
214 ··········<cpe-lang:logical-test·operator="OR"·negate="false"> 
215 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_10:def:1"/> 
216 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_8:def:1"/> 
217 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_9:def:1"/> 
218 ··········</cpe-lang:logical-test> 
219 ········</cpe-lang:platform> 
220 ········<cpe-lang:platform·id="ocp4.6_or_ocp4.7_or_ocp4.8">206 ········<cpe-lang:platform·id="ocp4.6_or_ocp4.7">
221 ··········<cpe-lang:logical-test·operator="OR"·negate="false">207 ··········<cpe-lang:logical-test·operator="OR"·negate="false">
222 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_6:def:1"/>208 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_6:def:1"/>
223 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_7:def:1"/>209 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_7:def:1"/>
224 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_8:def:1"/> 
225 ··········</cpe-lang:logical-test>210 ··········</cpe-lang:logical-test>
226 ········</cpe-lang:platform>211 ········</cpe-lang:platform>
227 ········<cpe-lang:platform·id="not_ocp4-on-hypershift_and_not_ocp4-on-hypershift-hosted">212 ········<cpe-lang:platform·id="not_ocp4-on-hypershift-hosted_and_ocp4.10_or_ocp4.6_or_ocp4.7_or_ocp4.8_or_ocp4.9">
228 ··········<cpe-lang:logical-test·operator="AND"·negate="false">213 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
229 ············<cpe-lang:logical-test·operator="AND"·negate="true">214 ············<cpe-lang:logical-test·operator="AND"·negate="true">
230 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_on_hypershift:def:1"/> 
231 ············</cpe-lang:logical-test> 
232 ············<cpe-lang:logical-test·operator="AND"·negate="true"> 
233 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_on_hypershift_hosted:def:1"/>215 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_on_hypershift_hosted:def:1"/>
234 ············</cpe-lang:logical-test>216 ············</cpe-lang:logical-test>
235 ··········</cpe-lang:logical-test> 
236 ········</cpe-lang:platform> 
237 ········<cpe-lang:platform·id="not_ocp4-on-hypershift-hosted_and_ocp4.6"> 
238 ··········<cpe-lang:logical-test·operator="AND"·negate="false">217 ············<cpe-lang:logical-test·operator="OR"·negate="false">
239 ············<cpe-lang:logical-test·operator="AND"·negate="true">218 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_10:def:1"/>
240 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_on_hypershift_hosted:def:1"/>219 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_6:def:1"/>
 220 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_7:def:1"/>
 221 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_8:def:1"/>
 222 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_9:def:1"/>
241 ············</cpe-lang:logical-test>223 ············</cpe-lang:logical-test>
242 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_6:def:1"/> 
243 ··········</cpe-lang:logical-test> 
244 ········</cpe-lang:platform> 
245 ········<cpe-lang:platform·id="ocp4-node_and_s390x_arch"> 
246 ··········<cpe-lang:logical-test·operator="AND"·negate="false"> 
247 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_node:def:1"/> 
248 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_s390x:def:1"/> 
249 ··········</cpe-lang:logical-test>224 ··········</cpe-lang:logical-test>
250 ········</cpe-lang:platform>225 ········</cpe-lang:platform>
251 ········<cpe-lang:platform·id="ocp4-on-sdn">226 ········<cpe-lang:platform·id="ocp4-on-gcp">
252 ··········<cpe-lang:logical-test·operator="AND"·negate="false">227 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
253 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_on_openshiftsdn:def:1"/>228 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_on_gcp:def:1"/>
254 ··········</cpe-lang:logical-test>229 ··········</cpe-lang:logical-test>
255 ········</cpe-lang:platform>230 ········</cpe-lang:platform>
256 ········<cpe-lang:platform·id="not_ocp4-on-hypershift-hosted_and_ocp4.10_or_ocp4.11_or_ocp4.12_or_ocp4.13_or_ocp4.14_or_ocp4.15_or_ocp4.16_or_ocp4.17_or_ocp4.9">231 ········<cpe-lang:platform·id="not_ocp4-on-hypershift-hosted_and_ocp4.12_or_ocp4.13">
257 ··········<cpe-lang:logical-test·operator="AND"·negate="false">232 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
258 ············<cpe-lang:logical-test·operator="AND"·negate="true">233 ············<cpe-lang:logical-test·operator="AND"·negate="true">
259 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_on_hypershift_hosted:def:1"/>234 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_on_hypershift_hosted:def:1"/>
260 ············</cpe-lang:logical-test>235 ············</cpe-lang:logical-test>
261 ············<cpe-lang:logical-test·operator="OR"·negate="false">236 ············<cpe-lang:logical-test·operator="OR"·negate="false">
262 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_10:def:1"/> 
263 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_11:def:1"/> 
264 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_12:def:1"/>237 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_12:def:1"/>
265 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_13:def:1"/>238 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_13:def:1"/>
266 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_14:def:1"/> 
267 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_15:def:1"/> 
268 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_16:def:1"/> 
269 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_17:def:1"/> 
270 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_9:def:1"/> 
271 ············</cpe-lang:logical-test>239 ············</cpe-lang:logical-test>
272 ··········</cpe-lang:logical-test>240 ··········</cpe-lang:logical-test>
273 ········</cpe-lang:platform>241 ········</cpe-lang:platform>
274 ········<cpe-lang:platform·id="ocp4-on-hypershift">242 ········<cpe-lang:platform·id="ocp4-node-on-sdn">
275 ··········<cpe-lang:logical-test·operator="AND"·negate="false">243 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
276 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_on_hypershift:def:1"/>244 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_node_on_openshift-sdn:def:1"/>
277 ··········</cpe-lang:logical-test>245 ··········</cpe-lang:logical-test>
278 ········</cpe-lang:platform>246 ········</cpe-lang:platform>
279 ········<cpe-lang:platform·id="ocp4-node">247 ········<cpe-lang:platform·id="ocp4-master-node">
280 ··········<cpe-lang:logical-test·operator="AND"·negate="false">248 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
Max diff block lines reached; 912037/926516 bytes (98.44%) of diff not shown.
840 KB
./usr/share/xml/scap/ssg/content/ssg-ocp4-ocil.xml
840 KB
./usr/share/xml/scap/ssg/content/ssg-ocp4-ocil.xml
Ordering differences only
    
Offset 3, 2429 lines modifiedOffset 3, 2429 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_proxy_kubeconfig_ocil:questionnaire:1"> 
11 ······<ocil:title>Verify·Permissions·on·the·Worker·Proxy·Kubeconfig·File</ocil:title> 
12 ······<ocil:actions> 
13 ········<ocil:test_action_ref>ocil:ssg-file_permissions_proxy_kubeconfig_action:testaction:1</ocil:test_action_ref> 
14 ······</ocil:actions> 
15 ····</ocil:questionnaire> 
16 ····<ocil:questionnaire·id="ocil:ssg-file_owner_scheduler_kubeconfig_ocil:questionnaire:1"> 
17 ······<ocil:title>Verify·User·Who·Owns·The·Kubernetes·Scheduler·Kubeconfig·File</ocil:title> 
18 ······<ocil:actions> 
19 ········<ocil:test_action_ref>ocil:ssg-file_owner_scheduler_kubeconfig_action:testaction:1</ocil:test_action_ref> 
20 ······</ocil:actions> 
21 ····</ocil:questionnaire> 
22 ····<ocil:questionnaire·id="ocil:ssg-api_server_api_priority_v1beta2_flowschema_catch_all_ocil:questionnaire:1"> 
23 ······<ocil:title>Ensure·catch-all·FlowSchema·object·for·API·Priority·and·Fairness·Exists</ocil:title> 
24 ······<ocil:actions> 
25 ········<ocil:test_action_ref>ocil:ssg-api_server_api_priority_v1beta2_flowschema_catch_all_action:testaction:1</ocil:test_action_ref> 
26 ······</ocil:actions> 
27 ····</ocil:questionnaire> 
28 ····<ocil:questionnaire·id="ocil:ssg-kubelet_configure_tls_key_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-audit_logging_enabled_ocil:questionnaire:1">
 11 ······<ocil:title>Ensure·that·API·server·audit·logging·is·enabled</ocil:title>
29 ······<ocil:title>Ensure·That·The·kubelet·Server·Key·Is·Correctly·Set</ocil:title> 
30 ······<ocil:actions> 
31 ········<ocil:test_action_ref>ocil:ssg-kubelet_configure_tls_key_action:testaction:1</ocil:test_action_ref> 
32 ······</ocil:actions> 
33 ····</ocil:questionnaire> 
34 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_openshift_pki_cert_files_ocil:questionnaire:1"> 
35 ······<ocil:title>Verify·Permissions·on·the·OpenShift·PKI·Certificate·Files</ocil:title> 
36 ······<ocil:actions>12 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-file_permissions_openshift_pki_cert_files_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-audit_logging_enabled_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>14 ······</ocil:actions>
39 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-kubelet_configure_tls_cert_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_scheduler_kubeconfig_ocil:questionnaire:1">
41 ······<ocil:title>Ensure·That·The·kubelet·Client·Certificate·Is·Correctly·Set</ocil:title>17 ······<ocil:title>Verify·Group·Who·Owns·The·Kubernetes·Scheduler·Kubeconfig·File</ocil:title>
42 ······<ocil:actions>18 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-kubelet_configure_tls_cert_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_scheduler_kubeconfig_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>20 ······</ocil:actions>
45 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-kubelet_eviction_thresholds_set_hard_imagefs_available_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-kubelet_eviction_thresholds_set_hard_imagefs_available_ocil:questionnaire:1">
47 ······<ocil:title>Ensure·Eviction·threshold·Settings·Are·Set·-·evictionHard:·imagefs.available</ocil:title>23 ······<ocil:title>Ensure·Eviction·threshold·Settings·Are·Set·-·evictionHard:·imagefs.available</ocil:title>
48 ······<ocil:actions>24 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-kubelet_eviction_thresholds_set_hard_imagefs_available_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-kubelet_eviction_thresholds_set_hard_imagefs_available_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>26 ······</ocil:actions>
51 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-api_server_profiling_protected_by_rbac_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-api_server_api_priority_v1beta1_flowschema_catch_all_ocil:questionnaire:1">
53 ······<ocil:title>Profiling·is·protected·by·RBAC</ocil:title>29 ······<ocil:title>Ensure·catch-all·FlowSchema·object·for·API·Priority·and·Fairness·Exists</ocil:title>
54 ······<ocil:actions>30 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-api_server_profiling_protected_by_rbac_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-api_server_api_priority_v1beta1_flowschema_catch_all_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>32 ······</ocil:actions>
57 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-api_server_audit_log_path_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-file_owner_ovn_cni_server_sock_ocil:questionnaire:1">
59 ······<ocil:title>Configure·the·Audit·Log·Path</ocil:title>35 ······<ocil:title>Verify·User·Who·Owns·The·OVNKubernetes·Socket</ocil:title>
60 ······<ocil:actions>36 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-api_server_audit_log_path_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-file_owner_ovn_cni_server_sock_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>38 ······</ocil:actions>
63 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-file_owner_worker_kubeconfig_ocil:questionnaire:1"> 
65 ······<ocil:title>Verify·User·Who·Owns·The·Worker·Kubeconfig·File</ocil:title>40 ····<ocil:questionnaire·id="ocil:ssg-openshift_api_server_audit_log_path_ocil:questionnaire:1">
 41 ······<ocil:title>Configure·the·Audit·Log·Path</ocil:title>
66 ······<ocil:actions>42 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-file_owner_worker_kubeconfig_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-openshift_api_server_audit_log_path_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>44 ······</ocil:actions>
69 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-api_server_admission_control_plugin_securitycontextdeny_ocil:questionnaire:1"> 
71 ······<ocil:title>Ensure·that·the·admission·control·plugin·SecurityContextDeny·is·set·if·PodSecurityPolicy·is·not·used</ocil:title>46 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_worker_kubeconfig_ocil:questionnaire:1">
 47 ······<ocil:title>Verify·Group·Who·Owns·The·Worker·Kubeconfig·File</ocil:title>
72 ······<ocil:actions>48 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-api_server_admission_control_plugin_securitycontextdeny_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_worker_kubeconfig_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>50 ······</ocil:actions>
75 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-kubelet_configure_client_ca_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-etcd_unique_ca_ocil:questionnaire:1">
77 ······<ocil:title>kubelet·-·Configure·the·Client·CA·Certificate</ocil:title>53 ······<ocil:title>Configure·A·Unique·CA·Certificate·for·etcd</ocil:title>
78 ······<ocil:actions>54 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-kubelet_configure_client_ca_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-etcd_unique_ca_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>56 ······</ocil:actions>
81 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_worker_ca_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-kube_descheduler_operator_exists_ocil:questionnaire:1">
83 ······<ocil:title>Verify·Group·Who·Owns·the·Worker·Certificate·Authority·File</ocil:title>59 ······<ocil:title>Ensure·that·the·Kube·Descheduler·operator·is·deployed</ocil:title>
84 ······<ocil:actions>60 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_worker_ca_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-kube_descheduler_operator_exists_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>62 ······</ocil:actions>
87 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-ocp_no_ldap_insecure_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_kubelet_ocil:questionnaire:1">
89 ······<ocil:title>Only·Use·LDAP-based·IdPs·with·TLS</ocil:title>65 ······<ocil:title>Verify·Permissions·on·The·Kubelet·Configuration·File</ocil:title>
90 ······<ocil:actions>66 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-ocp_no_ldap_insecure_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-file_permissions_kubelet_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>68 ······</ocil:actions>
93 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-azure_disk_encryption_enabled_ocil:questionnaire:1"> 
95 ······<ocil:title>Ensure·that·the·MachineSets·provisioned·by·Azure·have·disk·encryption·enabled</ocil:title>70 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_controller_manager_kubeconfig_ocil:questionnaire:1">
 71 ······<ocil:title>Verify·Permissions·on·the·OpenShift·Controller·Manager·Kubeconfig·File</ocil:title>
96 ······<ocil:actions>72 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-azure_disk_encryption_enabled_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-file_permissions_controller_manager_kubeconfig_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>74 ······</ocil:actions>
99 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-image_pruner_active_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-scansettingbinding_exists_ocil:questionnaire:1">
101 ······<ocil:title>Configure·ImagePruner·so·that·images·that·are·no·longer·needed·are·automatically·removed</ocil:title>77 ······<ocil:title>Ensure·that·Compliance·Operator·is·scanning·the·cluster</ocil:title>
102 ······<ocil:actions>78 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-image_pruner_active_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-scansettingbinding_exists_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>80 ······</ocil:actions>
105 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-liveness_readiness_probe_in_workload_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-ingress_controller_tls_security_profile_not_old_ocil:questionnaire:1">
107 ······<ocil:title>Ensure·that·all·workloads·have·liveness·and·readiness·probes</ocil:title>83 ······<ocil:title>Ensure·IngressController·is·not·configured·to·use·Old·tlsSecurityProfile</ocil:title>
108 ······<ocil:actions>84 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-liveness_readiness_probe_in_workload_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-ingress_controller_tls_security_profile_not_old_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>86 ······</ocil:actions>
111 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_ip_allocations_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-kubelet_enable_streaming_connections_ocil:questionnaire:1">
113 ······<ocil:title>Verify·Permissions·on·the·OpenShift·SDN·Container·Network·Interface·Plugin·IP·Address·Allocations</ocil:title>89 ······<ocil:title>kubelet·-·Do·Not·Disable·Streaming·Timeouts</ocil:title>
114 ······<ocil:actions>90 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-file_permissions_ip_allocations_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-kubelet_enable_streaming_connections_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>92 ······</ocil:actions>
117 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-directory_permissions_var_log_oauth_audit_ocil:questionnaire:1"> 
119 ······<ocil:title>The·OAuth·Audit·Logs·Directory·Must·Have·Mode·0700</ocil:title>94 ····<ocil:questionnaire·id="ocil:ssg-kubelet_eviction_thresholds_set_soft_nodefs_available_ocil:questionnaire:1">
 95 ······<ocil:title>Ensure·Eviction·threshold·Settings·Are·Set·-·evictionSoft:·nodefs.available</ocil:title>
120 ······<ocil:actions>96 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-directory_permissions_var_log_oauth_audit_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-kubelet_eviction_thresholds_set_soft_nodefs_available_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>98 ······</ocil:actions>
123 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
124 ····<ocil:questionnaire·id="ocil:ssg-scansettingbinding_exists_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-scheduler_profiling_protected_by_rbac_ocil:questionnaire:1">
Max diff block lines reached; 848067/860223 bytes (98.59%) of diff not shown.
26.9 KB
./usr/share/xml/scap/ssg/content/ssg-ocp4-xccdf.xml
26.8 KB
./usr/share/xml/scap/ssg/content/ssg-ocp4-xccdf.xml
Ordering differences only
    
Offset 72, 197 lines modifiedOffset 72, 197 lines modified
72 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>72 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
73 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>73 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
74 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>74 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
75 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>75 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=container-platform">stigid</xccdf-1.2:reference>76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=container-platform">stigid</xccdf-1.2:reference>
77 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>77 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
78 ··<cpe-lang:platform-specification>78 ··<cpe-lang:platform-specification>
79 ····<cpe-lang:platform·id="not_ocp4-on-hypershift-hosted_and_ocp4.6_or_ocp4.7_or_ocp4.8">79 ····<cpe-lang:platform·id="not_ocp4-on-hypershift_and_not_ocp4-on-hypershift-hosted">
80 ······<cpe-lang:logical-test·operator="AND"·negate="false">80 ······<cpe-lang:logical-test·operator="AND"·negate="false">
81 ········<cpe-lang:logical-test·operator="AND"·negate="true">81 ········<cpe-lang:logical-test·operator="AND"·negate="true">
82 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_on_hypershift_hosted:def:1"/>82 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_on_hypershift:def:1"/>
83 ········</cpe-lang:logical-test>83 ········</cpe-lang:logical-test>
84 ········<cpe-lang:logical-test·operator="OR"·negate="false">84 ········<cpe-lang:logical-test·operator="AND"·negate="true">
85 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_6:def:1"/>85 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_on_hypershift_hosted:def:1"/>
86 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_7:def:1"/> 
87 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_8:def:1"/> 
88 ········</cpe-lang:logical-test>86 ········</cpe-lang:logical-test>
89 ······</cpe-lang:logical-test>87 ······</cpe-lang:logical-test>
90 ····</cpe-lang:platform>88 ····</cpe-lang:platform>
91 ····<cpe-lang:platform·id="ocp4-on-gcp"> 
92 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
93 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_on_gcp:def:1"/> 
94 ······</cpe-lang:logical-test> 
95 ····</cpe-lang:platform> 
96 ····<cpe-lang:platform·id="ocp4.10_or_ocp4.8_or_ocp4.9"> 
97 ······<cpe-lang:logical-test·operator="OR"·negate="false"> 
98 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_10:def:1"/> 
99 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_8:def:1"/> 
100 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_9:def:1"/> 
101 ······</cpe-lang:logical-test> 
102 ····</cpe-lang:platform> 
103 ····<cpe-lang:platform·id="ocp4.6_or_ocp4.7_or_ocp4.8">89 ····<cpe-lang:platform·id="ocp4.6_or_ocp4.7">
104 ······<cpe-lang:logical-test·operator="OR"·negate="false">90 ······<cpe-lang:logical-test·operator="OR"·negate="false">
105 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_6:def:1"/>91 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_6:def:1"/>
106 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_7:def:1"/>92 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_7:def:1"/>
107 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_8:def:1"/> 
108 ······</cpe-lang:logical-test>93 ······</cpe-lang:logical-test>
109 ····</cpe-lang:platform>94 ····</cpe-lang:platform>
110 ····<cpe-lang:platform·id="not_ocp4-on-hypershift_and_not_ocp4-on-hypershift-hosted">95 ····<cpe-lang:platform·id="not_ocp4-on-hypershift-hosted_and_ocp4.10_or_ocp4.6_or_ocp4.7_or_ocp4.8_or_ocp4.9">
111 ······<cpe-lang:logical-test·operator="AND"·negate="false">96 ······<cpe-lang:logical-test·operator="AND"·negate="false">
112 ········<cpe-lang:logical-test·operator="AND"·negate="true">97 ········<cpe-lang:logical-test·operator="AND"·negate="true">
113 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_on_hypershift:def:1"/> 
114 ········</cpe-lang:logical-test> 
115 ········<cpe-lang:logical-test·operator="AND"·negate="true"> 
116 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_on_hypershift_hosted:def:1"/>98 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_on_hypershift_hosted:def:1"/>
117 ········</cpe-lang:logical-test>99 ········</cpe-lang:logical-test>
118 ······</cpe-lang:logical-test> 
119 ····</cpe-lang:platform> 
120 ····<cpe-lang:platform·id="not_ocp4-on-hypershift-hosted_and_ocp4.6"> 
121 ······<cpe-lang:logical-test·operator="AND"·negate="false">100 ········<cpe-lang:logical-test·operator="OR"·negate="false">
122 ········<cpe-lang:logical-test·operator="AND"·negate="true">101 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_10:def:1"/>
123 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_on_hypershift_hosted:def:1"/>102 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_6:def:1"/>
 103 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_7:def:1"/>
 104 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_8:def:1"/>
 105 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_9:def:1"/>
124 ········</cpe-lang:logical-test>106 ········</cpe-lang:logical-test>
125 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_6:def:1"/> 
126 ······</cpe-lang:logical-test>107 ······</cpe-lang:logical-test>
127 ····</cpe-lang:platform>108 ····</cpe-lang:platform>
128 ····<cpe-lang:platform·id="ocp4-node_and_s390x_arch"> 
129 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
130 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_node:def:1"/> 
131 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_s390x:def:1"/> 
132 ······</cpe-lang:logical-test> 
133 ····</cpe-lang:platform> 
134 ····<cpe-lang:platform·id="ocp4-on-sdn">109 ····<cpe-lang:platform·id="ocp4-on-gcp">
135 ······<cpe-lang:logical-test·operator="AND"·negate="false">110 ······<cpe-lang:logical-test·operator="AND"·negate="false">
136 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_on_openshiftsdn:def:1"/>111 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_on_gcp:def:1"/>
137 ······</cpe-lang:logical-test>112 ······</cpe-lang:logical-test>
138 ····</cpe-lang:platform>113 ····</cpe-lang:platform>
139 ····<cpe-lang:platform·id="not_ocp4-on-hypershift-hosted_and_ocp4.10_or_ocp4.11_or_ocp4.12_or_ocp4.13_or_ocp4.14_or_ocp4.15_or_ocp4.16_or_ocp4.17_or_ocp4.9">114 ····<cpe-lang:platform·id="not_ocp4-on-hypershift-hosted_and_ocp4.12_or_ocp4.13">
140 ······<cpe-lang:logical-test·operator="AND"·negate="false">115 ······<cpe-lang:logical-test·operator="AND"·negate="false">
141 ········<cpe-lang:logical-test·operator="AND"·negate="true">116 ········<cpe-lang:logical-test·operator="AND"·negate="true">
142 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_on_hypershift_hosted:def:1"/>117 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_on_hypershift_hosted:def:1"/>
143 ········</cpe-lang:logical-test>118 ········</cpe-lang:logical-test>
144 ········<cpe-lang:logical-test·operator="OR"·negate="false">119 ········<cpe-lang:logical-test·operator="OR"·negate="false">
145 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_10:def:1"/> 
146 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_11:def:1"/> 
147 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_12:def:1"/>120 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_12:def:1"/>
148 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_13:def:1"/>121 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_13:def:1"/>
149 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_14:def:1"/> 
150 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_15:def:1"/> 
151 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_16:def:1"/> 
152 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_17:def:1"/> 
153 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_9:def:1"/> 
154 ········</cpe-lang:logical-test>122 ········</cpe-lang:logical-test>
155 ······</cpe-lang:logical-test>123 ······</cpe-lang:logical-test>
156 ····</cpe-lang:platform>124 ····</cpe-lang:platform>
157 ····<cpe-lang:platform·id="ocp4-on-hypershift">125 ····<cpe-lang:platform·id="ocp4-node-on-sdn">
158 ······<cpe-lang:logical-test·operator="AND"·negate="false">126 ······<cpe-lang:logical-test·operator="AND"·negate="false">
159 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_on_hypershift:def:1"/>127 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_node_on_openshift-sdn:def:1"/>
160 ······</cpe-lang:logical-test>128 ······</cpe-lang:logical-test>
161 ····</cpe-lang:platform>129 ····</cpe-lang:platform>
162 ····<cpe-lang:platform·id="ocp4-node">130 ····<cpe-lang:platform·id="ocp4-master-node">
163 ······<cpe-lang:logical-test·operator="AND"·negate="false">131 ······<cpe-lang:logical-test·operator="AND"·negate="false">
164 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_node:def:1"/>132 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-node_is_ocp4_master_node:def:1"/>
165 ······</cpe-lang:logical-test>133 ······</cpe-lang:logical-test>
166 ····</cpe-lang:platform>134 ····</cpe-lang:platform>
 135 ····<cpe-lang:platform·id="ocp4.6_or_ocp4.7_or_ocp4.8">
 136 ······<cpe-lang:logical-test·operator="OR"·negate="false">
 137 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_6:def:1"/>
 138 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_7:def:1"/>
 139 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_8:def:1"/>
 140 ······</cpe-lang:logical-test>
 141 ····</cpe-lang:platform>
 142 ····<cpe-lang:platform·id="not_ocp4-on-hypershift-hosted">
 143 ······<cpe-lang:logical-test·operator="AND"·negate="true">
 144 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_on_hypershift_hosted:def:1"/>
 145 ······</cpe-lang:logical-test>
 146 ····</cpe-lang:platform>
167 ····<cpe-lang:platform·id="ocp4.16">147 ····<cpe-lang:platform·id="ocp4-on-aws">
168 ······<cpe-lang:logical-test·operator="AND"·negate="false">148 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 149 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_on_aws:def:1"/>
 150 ······</cpe-lang:logical-test>
 151 ····</cpe-lang:platform>
 152 ····<cpe-lang:platform·id="not_ocp4-on-hypershift-hosted_and_ocp4.6_or_ocp4.7_or_ocp4.8">
 153 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 154 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 155 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_on_hypershift_hosted:def:1"/>
 156 ········</cpe-lang:logical-test>
 157 ········<cpe-lang:logical-test·operator="OR"·negate="false">
169 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_16:def:1"/>158 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_6:def:1"/>
 159 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_7:def:1"/>
 160 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_8:def:1"/>
 161 ········</cpe-lang:logical-test>
170 ······</cpe-lang:logical-test>162 ······</cpe-lang:logical-test>
171 ····</cpe-lang:platform>163 ····</cpe-lang:platform>
Max diff block lines reached; 13139/27274 bytes (48.17%) of diff not shown.
2.0 MB
./usr/share/xml/scap/ssg/content/ssg-ol10-ds.xml
2.0 MB
./usr/share/xml/scap/ssg/content/ssg-ol10-ds.xml
    
Offset 19, 23 lines modifiedOffset 19, 23 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol10-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol10-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol10-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol10-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol10-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol10-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol10-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol10-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol10-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol10-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol10-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol10-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol10-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol10-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:oracle:linux:10">28 ······<cpe-dict:cpe-item·name="cpe:/o:oracle:linux:10">
29 ········<cpe-dict:title·xml:lang="en-us">Oracle·Linux·10</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Oracle·Linux·10</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml">oval:ssg-installed_OS_is_ol10:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml">oval:ssg-installed_OS_is_ol10:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ····</cpe-dict:cpe-list>32 ····</cpe-dict:cpe-list>
33 ··</ds:component>33 ··</ds:component>
34 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol10-xccdf.xml"·timestamp="2025-02-28T20:08:00">34 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol10-xccdf.xml"·timestamp="2025-03-01T22:08:00">
35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_OL-10"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_OL-10"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Oracle·Linux·10</xccdf-1.2:title>37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Oracle·Linux·10</xccdf-1.2:title>
38 ······<xccdf-1.2:description>38 ······<xccdf-1.2:description>
39 ········This·guide·presents·a·catalog·of·security-relevant39 ········This·guide·presents·a·catalog·of·security-relevant
40 configuration·settings·for·Oracle·Linux·10.·It·is·a·rendering·of40 configuration·settings·for·Oracle·Linux·10.·It·is·a·rendering·of
41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 105, 376 lines modifiedOffset 105, 376 lines modified
105 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>105 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
106 ······<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>106 ······<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
107 ······<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>107 ······<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
108 ······<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>108 ······<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
109 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>109 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
110 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>110 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
111 ······<cpe-lang:platform-specification>111 ······<cpe-lang:platform-specification>
112 ········<cpe-lang:platform·id="package_libuser">112 ········<cpe-lang:platform·id="not_aarch64_arch_and_not_ppc64le_arch_and_system_with_kernel">
113 ··········<cpe-lang:logical-test·operator="AND"·negate="false">113 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
114 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-package_libuser:def:1"/> 
115 ··········</cpe-lang:logical-test> 
116 ········</cpe-lang:platform> 
117 ········<cpe-lang:platform·id="not_bootc"> 
118 ··········<cpe-lang:logical-test·operator="AND"·negate="true">114 ············<cpe-lang:logical-test·operator="AND"·negate="true">
 115 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
 116 ············</cpe-lang:logical-test>
 117 ············<cpe-lang:logical-test·operator="AND"·negate="true">
 118 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_ppc64le:def:1"/>
 119 ············</cpe-lang:logical-test>
119 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-bootc:def:1"/>120 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
120 ··········</cpe-lang:logical-test>121 ··········</cpe-lang:logical-test>
121 ········</cpe-lang:platform>122 ········</cpe-lang:platform>
122 ········<cpe-lang:platform·id="machine">123 ········<cpe-lang:platform·id="package_polkit">
123 ··········<cpe-lang:logical-test·operator="AND"·negate="false">124 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
124 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>125 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-package_polkit:def:1"/>
125 ··········</cpe-lang:logical-test>126 ··········</cpe-lang:logical-test>
126 ········</cpe-lang:platform>127 ········</cpe-lang:platform>
127 ········<cpe-lang:platform·id="package_squid_and_system_with_kernel">128 ········<cpe-lang:platform·id="mount_var-tmp">
128 ··········<cpe-lang:logical-test·operator="AND"·negate="false">129 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
129 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-package_squid:def:1"/> 
130 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>130 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-tmp:def:1"/>
131 ··········</cpe-lang:logical-test>131 ··········</cpe-lang:logical-test>
132 ········</cpe-lang:platform>132 ········</cpe-lang:platform>
133 ········<cpe-lang:platform·id="package_pam">133 ········<cpe-lang:platform·id="package_networkmanager">
134 ··········<cpe-lang:logical-test·operator="AND"·negate="false">134 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
135 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>135 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-package_networkmanager:def:1"/>
136 ··········</cpe-lang:logical-test>136 ··········</cpe-lang:logical-test>
137 ········</cpe-lang:platform>137 ········</cpe-lang:platform>
138 ········<cpe-lang:platform·id="package_autofs_and_system_with_kernel">138 ········<cpe-lang:platform·id="package_autofs_and_system_with_kernel">
139 ··········<cpe-lang:logical-test·operator="AND"·negate="false">139 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
140 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>140 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>
141 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>141 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
142 ··········</cpe-lang:logical-test>142 ··········</cpe-lang:logical-test>
143 ········</cpe-lang:platform>143 ········</cpe-lang:platform>
144 ········<cpe-lang:platform·id="mount_tmp">144 ········<cpe-lang:platform·id="ipv6_enabled">
145 ··········<cpe-lang:logical-test·operator="AND"·negate="false"> 
146 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_tmp:def:1"/> 
147 ··········</cpe-lang:logical-test> 
148 ········</cpe-lang:platform> 
149 ········<cpe-lang:platform·id="package_firewalld_and_package_nftables_and_system_with_kernel"> 
150 ··········<cpe-lang:logical-test·operator="AND"·negate="false">145 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
151 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/> 
152 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>146 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-ipv6_enabled:def:1"/>
153 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
154 ··········</cpe-lang:logical-test>147 ··········</cpe-lang:logical-test>
155 ········</cpe-lang:platform>148 ········</cpe-lang:platform>
156 ········<cpe-lang:platform·id="not_s390x_arch">149 ········<cpe-lang:platform·id="package_gdm">
157 ··········<cpe-lang:logical-test·operator="AND"·negate="false">150 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
158 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>151 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-package_gdm:def:1"/>
159 ··········</cpe-lang:logical-test>152 ··········</cpe-lang:logical-test>
160 ········</cpe-lang:platform>153 ········</cpe-lang:platform>
161 ········<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">154 ········<cpe-lang:platform·id="package_rsyslog">
162 ··········<cpe-lang:logical-test·operator="AND"·negate="false">155 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
163 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>156 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>
164 ··········</cpe-lang:logical-test>157 ··········</cpe-lang:logical-test>
165 ········</cpe-lang:platform>158 ········</cpe-lang:platform>
166 ········<cpe-lang:platform·id="mount_var-log">159 ········<cpe-lang:platform·id="not_osbuild_and_system_with_kernel">
167 ··········<cpe-lang:logical-test·operator="AND"·negate="false">160 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 161 ············<cpe-lang:logical-test·operator="AND"·negate="true">
168 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-log:def:1"/>162 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_osbuild:def:1"/>
 163 ············</cpe-lang:logical-test>
 164 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
169 ··········</cpe-lang:logical-test>165 ··········</cpe-lang:logical-test>
170 ········</cpe-lang:platform>166 ········</cpe-lang:platform>
171 ········<cpe-lang:platform·id="uefi">167 ········<cpe-lang:platform·id="package_chrony_or_package_ntp">
172 ··········<cpe-lang:logical-test·operator="AND"·negate="false">168 ··········<cpe-lang:logical-test·operator="OR"·negate="false">
 169 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
173 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>170 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-package_ntp:def:1"/>
174 ··········</cpe-lang:logical-test>171 ··········</cpe-lang:logical-test>
175 ········</cpe-lang:platform>172 ········</cpe-lang:platform>
176 ········<cpe-lang:platform·id="package_bash">173 ········<cpe-lang:platform·id="package_bash">
177 ··········<cpe-lang:logical-test·operator="AND"·negate="false">174 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
178 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>175 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>
179 ··········</cpe-lang:logical-test>176 ··········</cpe-lang:logical-test>
180 ········</cpe-lang:platform>177 ········</cpe-lang:platform>
181 ········<cpe-lang:platform·id="package_telnet-server_and_system_with_kernel"> 
182 ··········<cpe-lang:logical-test·operator="AND"·negate="false"> 
183 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-package_telnet-server:def:1"/> 
184 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
185 ··········</cpe-lang:logical-test> 
186 ········</cpe-lang:platform>178 ········<cpe-lang:platform·id="uefi">
187 ········<cpe-lang:platform·id="package_iptables"> 
188 ··········<cpe-lang:logical-test·operator="AND"·negate="false">179 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
189 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>180 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>
190 ··········</cpe-lang:logical-test>181 ··········</cpe-lang:logical-test>
191 ········</cpe-lang:platform>182 ········</cpe-lang:platform>
192 ········<cpe-lang:platform·id="os_linux_ol_gt_or_eq_9_and_package_logrotate">183 ········<cpe-lang:platform·id="package_logrotate">
193 ··········<cpe-lang:logical-test·operator="AND"·negate="false">184 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
194 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_9:def:1"/> 
195 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-package_logrotate:def:1"/>185 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-package_logrotate:def:1"/>
196 ··········</cpe-lang:logical-test>186 ··········</cpe-lang:logical-test>
197 ········</cpe-lang:platform>187 ········</cpe-lang:platform>
198 ········<cpe-lang:platform·id="grub2">188 ········<cpe-lang:platform·id="package_chrony">
Max diff block lines reached; 2088611/2101905 bytes (99.37%) of diff not shown.
1.73 MB
./usr/share/xml/scap/ssg/content/ssg-ol10-ocil.xml
1.73 MB
./usr/share/xml/scap/ssg/content/ssg-ol10-ocil.xml
Ordering differences only
    
Offset 3, 12074 lines modifiedOffset 3, 12064 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-dconf_gnome_session_idle_user_locks_ocil:questionnaire:1"> 
11 ······<ocil:title>Ensure·Users·Cannot·Change·GNOME3·Session·Idle·Settings</ocil:title> 
12 ······<ocil:actions> 
13 ········<ocil:test_action_ref>ocil:ssg-dconf_gnome_session_idle_user_locks_action:testaction:1</ocil:test_action_ref> 
14 ······</ocil:actions> 
15 ····</ocil:questionnaire> 
16 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_gcc_plugin_randstruct_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_legacy_ptys_ocil:questionnaire:1">
 11 ······<ocil:title>Disable·legacy·(BSD)·PTY·support</ocil:title>
17 ······<ocil:title>Randomize·layout·of·sensitive·kernel·structures</ocil:title> 
18 ······<ocil:actions> 
19 ········<ocil:test_action_ref>ocil:ssg-kernel_config_gcc_plugin_randstruct_action:testaction:1</ocil:test_action_ref> 
20 ······</ocil:actions> 
21 ····</ocil:questionnaire> 
22 ····<ocil:questionnaire·id="ocil:ssg-accounts_passwords_pam_faillock_unlock_time_ocil:questionnaire:1"> 
23 ······<ocil:title>Set·Lockout·Time·for·Failed·Password·Attempts</ocil:title> 
24 ······<ocil:actions>12 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-accounts_passwords_pam_faillock_unlock_time_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-kernel_config_legacy_ptys_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>14 ······</ocil:actions>
27 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-mount_option_dev_shm_nosuid_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_module_sig_sha512_ocil:questionnaire:1">
29 ······<ocil:title>Add·nosuid·Option·to·/dev/shm</ocil:title>17 ······<ocil:title>Sign·kernel·modules·with·SHA-512</ocil:title>
30 ······<ocil:actions>18 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-mount_option_dev_shm_nosuid_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-kernel_config_module_sig_sha512_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>20 ······</ocil:actions>
33 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-sshd_set_max_auth_tries_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-no_tmux_in_shells_ocil:questionnaire:1">
35 ······<ocil:title>Set·SSH·authentication·attempt·limit</ocil:title>23 ······<ocil:title>Prevent·user·from·disabling·the·screen·lock</ocil:title>
36 ······<ocil:actions>24 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-sshd_set_max_auth_tries_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-no_tmux_in_shells_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>26 ······</ocil:actions>
39 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-mount_option_boot_noexec_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-aide_verify_ext_attributes_ocil:questionnaire:1">
41 ······<ocil:title>Add·noexec·Option·to·/boot</ocil:title>29 ······<ocil:title>Configure·AIDE·to·Verify·Extended·Attributes</ocil:title>
42 ······<ocil:actions>30 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-mount_option_boot_noexec_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-aide_verify_ext_attributes_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>32 ······</ocil:actions>
45 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-accounts_max_concurrent_login_sessions_ocil:questionnaire:1"> 
47 ······<ocil:title>Limit·the·Number·of·Concurrent·Login·Sessions·Allowed·Per·User</ocil:title>34 ····<ocil:questionnaire·id="ocil:ssg-sysctl_kernel_yama_ptrace_scope_ocil:questionnaire:1">
 35 ······<ocil:title>Restrict·usage·of·ptrace·to·descendant·processes</ocil:title>
48 ······<ocil:actions>36 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-accounts_max_concurrent_login_sessions_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-sysctl_kernel_yama_ptrace_scope_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>38 ······</ocil:actions>
51 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-xwindows_runlevel_target_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-sshd_set_loglevel_verbose_ocil:questionnaire:1">
53 ······<ocil:title>Disable·Graphical·Environment·Startup·By·Setting·Default·Target</ocil:title>41 ······<ocil:title>Set·SSH·Daemon·LogLevel·to·VERBOSE</ocil:title>
54 ······<ocil:actions>42 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-xwindows_runlevel_target_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-sshd_set_loglevel_verbose_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>44 ······</ocil:actions>
57 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-auditd_write_logs_ocil:questionnaire:1">46 ····<ocil:questionnaire·id="ocil:ssg-grub2_spectre_v2_argument_ocil:questionnaire:1">
59 ······<ocil:title>Write·Audit·Logs·to·the·Disk</ocil:title>47 ······<ocil:title>Enforce·Spectre·v2·mitigation</ocil:title>
60 ······<ocil:actions>48 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-auditd_write_logs_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-grub2_spectre_v2_argument_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>50 ······</ocil:actions>
63 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_forwarding_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-sysctl_kernel_perf_event_max_sample_rate_ocil:questionnaire:1">
65 ······<ocil:title>Disable·Kernel·Parameter·for·IPv4·Forwarding·on·all·IPv4·Interfaces</ocil:title>53 ······<ocil:title>Limit·sampling·frequency·of·the·Perf·system</ocil:title>
66 ······<ocil:actions>54 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_forwarding_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-sysctl_kernel_perf_event_max_sample_rate_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>56 ······</ocil:actions>
69 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-sshd_enable_pam_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_all_router_solicitations_ocil:questionnaire:1">
71 ······<ocil:title>Enable·PAM</ocil:title>59 ······<ocil:title>Configure·Denying·Router·Solicitations·on·All·IPv6·Interfaces</ocil:title>
72 ······<ocil:actions>60 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-sshd_enable_pam_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_all_router_solicitations_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>62 ······</ocil:actions>
75 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_sshd_config_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-account_disable_post_pw_expiration_ocil:questionnaire:1">
77 ······<ocil:title>Verify·Permissions·on·SSH·Server·config·file</ocil:title>65 ······<ocil:title>Set·Account·Expiration·Following·Inactivity</ocil:title>
78 ······<ocil:actions>66 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-file_permissions_sshd_config_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-account_disable_post_pw_expiration_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>68 ······</ocil:actions>
81 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-package_telnet-server_removed_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_system_shutdown_ocil:questionnaire:1">
83 ······<ocil:title>Uninstall·telnet-server·Package</ocil:title>71 ······<ocil:title>Shutdown·System·When·Auditing·Failures·Occur</ocil:title>
84 ······<ocil:actions>72 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-package_telnet-server_removed_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-audit_rules_system_shutdown_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>74 ······</ocil:actions>
87 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-package_kea_removed_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-sysctl_kernel_perf_event_paranoid_ocil:questionnaire:1">
89 ······<ocil:title>Uninstall·kea·Package</ocil:title>77 ······<ocil:title>Disallow·kernel·profiling·by·unprivileged·users</ocil:title>
90 ······<ocil:actions>78 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-package_kea_removed_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-sysctl_kernel_perf_event_paranoid_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>80 ······</ocil:actions>
93 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-use_kerberos_security_all_exports_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-sssd_enable_pam_services_ocil:questionnaire:1">
95 ······<ocil:title>Use·Kerberos·Security·on·All·Exports</ocil:title>83 ······<ocil:title>Configure·PAM·in·SSSD·Services</ocil:title>
96 ······<ocil:actions>84 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-use_kerberos_security_all_exports_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-sssd_enable_pam_services_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>86 ······</ocil:actions>
99 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_last_change_is_in_past_ocil:questionnaire:1"> 
101 ······<ocil:title>Ensure·all·users·last·password·change·date·is·in·the·past</ocil:title>88 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_default_accept_ra_pinfo_ocil:questionnaire:1">
 89 ······<ocil:title>Configure·Accepting·Prefix·Information·in·Router·Advertisements·on·All·IPv6·Interfaces·By·Default</ocil:title>
102 ······<ocil:actions>90 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-accounts_password_last_change_is_in_past_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_default_accept_ra_pinfo_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>92 ······</ocil:actions>
105 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_shells_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_usergroup_modification_ocil:questionnaire:1">
107 ······<ocil:title>Verify·Group·Who·Owns·/etc/shells·File</ocil:title>95 ······<ocil:title>Record·Events·that·Modify·User/Group·Information</ocil:title>
108 ······<ocil:actions>96 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_shells_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-audit_rules_usergroup_modification_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>98 ······</ocil:actions>
111 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_kernel_module_loading_delete_ocil:questionnaire:1"> 
113 ······<ocil:title>Ensure·auditd·Collects·Information·on·Kernel·Module·Unloading·-·delete_module</ocil:title>100 ····<ocil:questionnaire·id="ocil:ssg-service_kdump_disabled_ocil:questionnaire:1">
 101 ······<ocil:title>Disable·KDump·Kernel·Crash·Analyzer·(kdump)</ocil:title>
114 ······<ocil:actions>102 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-audit_rules_kernel_module_loading_delete_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-service_kdump_disabled_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>104 ······</ocil:actions>
117 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_module_sig_ocil:questionnaire:1">106 ····<ocil:questionnaire·id="ocil:ssg-enable_fips_mode_ocil:questionnaire:1">
119 ······<ocil:title>Enable·module·signature·verification</ocil:title>107 ······<ocil:title>Enable·FIPS·Mode</ocil:title>
120 ······<ocil:actions>108 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-kernel_config_module_sig_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-enable_fips_mode_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>110 ······</ocil:actions>
123 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
124 ····<ocil:questionnaire·id="ocil:ssg-service_firewalld_enabled_ocil:questionnaire:1">112 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_execution_chacl_ocil:questionnaire:1">
125 ······<ocil:title>Verify·firewalld·Enabled</ocil:title>113 ······<ocil:title>Record·Any·Attempts·to·Run·chacl</ocil:title>
Max diff block lines reached; 1805732/1817864 bytes (99.33%) of diff not shown.
192 KB
./usr/share/xml/scap/ssg/content/ssg-ol10-xccdf.xml
192 KB
./usr/share/xml/scap/ssg/content/ssg-ol10-xccdf.xml
    
Offset 72, 376 lines modifiedOffset 72, 376 lines modified
72 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>72 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
73 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>73 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
74 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>74 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
75 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>75 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
77 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>77 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
78 ··<cpe-lang:platform-specification>78 ··<cpe-lang:platform-specification>
79 ····<cpe-lang:platform·id="package_libuser">79 ····<cpe-lang:platform·id="not_aarch64_arch_and_not_ppc64le_arch_and_system_with_kernel">
80 ······<cpe-lang:logical-test·operator="AND"·negate="false">80 ······<cpe-lang:logical-test·operator="AND"·negate="false">
81 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-package_libuser:def:1"/> 
82 ······</cpe-lang:logical-test> 
83 ····</cpe-lang:platform> 
84 ····<cpe-lang:platform·id="not_bootc"> 
85 ······<cpe-lang:logical-test·operator="AND"·negate="true">81 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 82 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
 83 ········</cpe-lang:logical-test>
 84 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 85 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_ppc64le:def:1"/>
 86 ········</cpe-lang:logical-test>
86 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-bootc:def:1"/>87 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
87 ······</cpe-lang:logical-test>88 ······</cpe-lang:logical-test>
88 ····</cpe-lang:platform>89 ····</cpe-lang:platform>
89 ····<cpe-lang:platform·id="machine">90 ····<cpe-lang:platform·id="package_polkit">
90 ······<cpe-lang:logical-test·operator="AND"·negate="false">91 ······<cpe-lang:logical-test·operator="AND"·negate="false">
91 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>92 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-package_polkit:def:1"/>
92 ······</cpe-lang:logical-test>93 ······</cpe-lang:logical-test>
93 ····</cpe-lang:platform>94 ····</cpe-lang:platform>
94 ····<cpe-lang:platform·id="package_squid_and_system_with_kernel">95 ····<cpe-lang:platform·id="mount_var-tmp">
95 ······<cpe-lang:logical-test·operator="AND"·negate="false">96 ······<cpe-lang:logical-test·operator="AND"·negate="false">
96 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-package_squid:def:1"/> 
97 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>97 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-tmp:def:1"/>
98 ······</cpe-lang:logical-test>98 ······</cpe-lang:logical-test>
99 ····</cpe-lang:platform>99 ····</cpe-lang:platform>
100 ····<cpe-lang:platform·id="package_pam">100 ····<cpe-lang:platform·id="package_networkmanager">
101 ······<cpe-lang:logical-test·operator="AND"·negate="false">101 ······<cpe-lang:logical-test·operator="AND"·negate="false">
102 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>102 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-package_networkmanager:def:1"/>
103 ······</cpe-lang:logical-test>103 ······</cpe-lang:logical-test>
104 ····</cpe-lang:platform>104 ····</cpe-lang:platform>
105 ····<cpe-lang:platform·id="package_autofs_and_system_with_kernel">105 ····<cpe-lang:platform·id="package_autofs_and_system_with_kernel">
106 ······<cpe-lang:logical-test·operator="AND"·negate="false">106 ······<cpe-lang:logical-test·operator="AND"·negate="false">
107 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>107 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>
108 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>108 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
109 ······</cpe-lang:logical-test>109 ······</cpe-lang:logical-test>
110 ····</cpe-lang:platform>110 ····</cpe-lang:platform>
111 ····<cpe-lang:platform·id="mount_tmp">111 ····<cpe-lang:platform·id="ipv6_enabled">
112 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
113 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_tmp:def:1"/> 
114 ······</cpe-lang:logical-test> 
115 ····</cpe-lang:platform> 
116 ····<cpe-lang:platform·id="package_firewalld_and_package_nftables_and_system_with_kernel"> 
117 ······<cpe-lang:logical-test·operator="AND"·negate="false">112 ······<cpe-lang:logical-test·operator="AND"·negate="false">
118 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/> 
119 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>113 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-ipv6_enabled:def:1"/>
120 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
121 ······</cpe-lang:logical-test>114 ······</cpe-lang:logical-test>
122 ····</cpe-lang:platform>115 ····</cpe-lang:platform>
123 ····<cpe-lang:platform·id="not_s390x_arch">116 ····<cpe-lang:platform·id="package_gdm">
124 ······<cpe-lang:logical-test·operator="AND"·negate="false">117 ······<cpe-lang:logical-test·operator="AND"·negate="false">
125 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>118 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-package_gdm:def:1"/>
126 ······</cpe-lang:logical-test>119 ······</cpe-lang:logical-test>
127 ····</cpe-lang:platform>120 ····</cpe-lang:platform>
128 ····<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">121 ····<cpe-lang:platform·id="package_rsyslog">
129 ······<cpe-lang:logical-test·operator="AND"·negate="false">122 ······<cpe-lang:logical-test·operator="AND"·negate="false">
130 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>123 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>
131 ······</cpe-lang:logical-test>124 ······</cpe-lang:logical-test>
132 ····</cpe-lang:platform>125 ····</cpe-lang:platform>
133 ····<cpe-lang:platform·id="mount_var-log">126 ····<cpe-lang:platform·id="not_osbuild_and_system_with_kernel">
134 ······<cpe-lang:logical-test·operator="AND"·negate="false">127 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 128 ········<cpe-lang:logical-test·operator="AND"·negate="true">
135 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-log:def:1"/>129 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_osbuild:def:1"/>
 130 ········</cpe-lang:logical-test>
 131 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
136 ······</cpe-lang:logical-test>132 ······</cpe-lang:logical-test>
137 ····</cpe-lang:platform>133 ····</cpe-lang:platform>
138 ····<cpe-lang:platform·id="uefi">134 ····<cpe-lang:platform·id="package_chrony_or_package_ntp">
139 ······<cpe-lang:logical-test·operator="AND"·negate="false">135 ······<cpe-lang:logical-test·operator="OR"·negate="false">
 136 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
140 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>137 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-package_ntp:def:1"/>
141 ······</cpe-lang:logical-test>138 ······</cpe-lang:logical-test>
142 ····</cpe-lang:platform>139 ····</cpe-lang:platform>
143 ····<cpe-lang:platform·id="package_bash">140 ····<cpe-lang:platform·id="package_bash">
144 ······<cpe-lang:logical-test·operator="AND"·negate="false">141 ······<cpe-lang:logical-test·operator="AND"·negate="false">
145 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>142 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>
146 ······</cpe-lang:logical-test>143 ······</cpe-lang:logical-test>
147 ····</cpe-lang:platform>144 ····</cpe-lang:platform>
148 ····<cpe-lang:platform·id="package_telnet-server_and_system_with_kernel"> 
149 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
150 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-package_telnet-server:def:1"/> 
151 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
152 ······</cpe-lang:logical-test> 
153 ····</cpe-lang:platform>145 ····<cpe-lang:platform·id="uefi">
154 ····<cpe-lang:platform·id="package_iptables"> 
155 ······<cpe-lang:logical-test·operator="AND"·negate="false">146 ······<cpe-lang:logical-test·operator="AND"·negate="false">
156 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>147 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>
157 ······</cpe-lang:logical-test>148 ······</cpe-lang:logical-test>
158 ····</cpe-lang:platform>149 ····</cpe-lang:platform>
159 ····<cpe-lang:platform·id="os_linux_ol_gt_or_eq_9_and_package_logrotate">150 ····<cpe-lang:platform·id="package_logrotate">
160 ······<cpe-lang:logical-test·operator="AND"·negate="false">151 ······<cpe-lang:logical-test·operator="AND"·negate="false">
161 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_9:def:1"/> 
162 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-package_logrotate:def:1"/>152 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-package_logrotate:def:1"/>
163 ······</cpe-lang:logical-test>153 ······</cpe-lang:logical-test>
164 ····</cpe-lang:platform>154 ····</cpe-lang:platform>
165 ····<cpe-lang:platform·id="grub2">155 ····<cpe-lang:platform·id="package_chrony">
166 ······<cpe-lang:logical-test·operator="AND"·negate="false">156 ······<cpe-lang:logical-test·operator="AND"·negate="false">
167 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>157 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
168 ······</cpe-lang:logical-test>158 ······</cpe-lang:logical-test>
169 ····</cpe-lang:platform>159 ····</cpe-lang:platform>
170 ····<cpe-lang:platform·id="package_sssd">160 ····<cpe-lang:platform·id="package_sssd">
171 ······<cpe-lang:logical-test·operator="AND"·negate="false">161 ······<cpe-lang:logical-test·operator="AND"·negate="false">
172 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-package_sssd:def:1"/>162 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-package_sssd:def:1"/>
173 ······</cpe-lang:logical-test>163 ······</cpe-lang:logical-test>
174 ····</cpe-lang:platform>164 ····</cpe-lang:platform>
175 ····<cpe-lang:platform·id="wifi-iface"> 
176 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
177 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_wifi_interface:def:1"/> 
178 ······</cpe-lang:logical-test> 
179 ····</cpe-lang:platform> 
180 ····<cpe-lang:platform·id="package_rsyslog">165 ····<cpe-lang:platform·id="package_firewalld">
181 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
182 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/> 
183 ······</cpe-lang:logical-test> 
184 ····</cpe-lang:platform> 
185 ····<cpe-lang:platform·id="package_systemd"> 
186 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
187 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/> 
188 ······</cpe-lang:logical-test> 
189 ····</cpe-lang:platform> 
Max diff block lines reached; 183561/196723 bytes (93.31%) of diff not shown.
2.44 MB
./usr/share/xml/scap/ssg/content/ssg-ol7-ds.xml
2.44 MB
./usr/share/xml/scap/ssg/content/ssg-ol7-ds.xml
    
Offset 21, 23 lines modifiedOffset 21, 23 lines modified
21 ····<ds:checks>21 ····<ds:checks>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol7-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol7-oval.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol7-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol7-oval.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol7-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol7-ocil.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol7-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol7-ocil.xml"/>
24 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol7-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol7-cpe-oval.xml"/>24 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol7-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol7-cpe-oval.xml"/>
25 ······<ds:component-ref·id="scap_org.open-scap_cref_security-oval-com.oracle.elsa-ol7.xml.bz2"·xlink:href="https://linux.oracle.com/security/oval/com.oracle.elsa-ol7.xml.bz2"/>25 ······<ds:component-ref·id="scap_org.open-scap_cref_security-oval-com.oracle.elsa-ol7.xml.bz2"·xlink:href="https://linux.oracle.com/security/oval/com.oracle.elsa-ol7.xml.bz2"/>
26 ····</ds:checks>26 ····</ds:checks>
27 ··</ds:data-stream>27 ··</ds:data-stream>
28 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol7-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">28 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol7-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
29 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">29 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
30 ······<cpe-dict:cpe-item·name="cpe:/o:oracle:linux:7">30 ······<cpe-dict:cpe-item·name="cpe:/o:oracle:linux:7">
31 ········<cpe-dict:title·xml:lang="en-us">Oracle·Linux·7</cpe-dict:title>31 ········<cpe-dict:title·xml:lang="en-us">Oracle·Linux·7</cpe-dict:title>
32 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml">oval:ssg-installed_OS_is_ol7:def:1</cpe-dict:check>32 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml">oval:ssg-installed_OS_is_ol7:def:1</cpe-dict:check>
33 ······</cpe-dict:cpe-item>33 ······</cpe-dict:cpe-item>
34 ····</cpe-dict:cpe-list>34 ····</cpe-dict:cpe-list>
35 ··</ds:component>35 ··</ds:component>
36 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol7-xccdf.xml"·timestamp="2025-02-28T20:08:00">36 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol7-xccdf.xml"·timestamp="2025-03-01T22:08:00">
37 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_OL-7"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">37 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_OL-7"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
38 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>38 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
39 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Oracle·Linux·7</xccdf-1.2:title>39 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Oracle·Linux·7</xccdf-1.2:title>
40 ······<xccdf-1.2:description>40 ······<xccdf-1.2:description>
41 ········This·guide·presents·a·catalog·of·security-relevant41 ········This·guide·presents·a·catalog·of·security-relevant
42 configuration·settings·for·Oracle·Linux·7.·It·is·a·rendering·of42 configuration·settings·for·Oracle·Linux·7.·It·is·a·rendering·of
43 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)43 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 107, 228 lines modifiedOffset 107, 204 lines modified
107 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>107 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
108 ······<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>108 ······<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
109 ······<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>109 ······<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
110 ······<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>110 ······<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
111 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>111 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
112 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>112 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
113 ······<cpe-lang:platform-specification>113 ······<cpe-lang:platform-specification>
 114 ········<cpe-lang:platform·id="not_aarch64_arch_and_not_ppc64le_arch_and_system_with_kernel">
114 ········<cpe-lang:platform·id="package_libuser"> 
115 ··········<cpe-lang:logical-test·operator="AND"·negate="false"> 
116 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-package_libuser:def:1"/> 
117 ··········</cpe-lang:logical-test> 
118 ········</cpe-lang:platform> 
119 ········<cpe-lang:platform·id="not_bootc"> 
120 ··········<cpe-lang:logical-test·operator="AND"·negate="true"> 
121 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-bootc:def:1"/> 
122 ··········</cpe-lang:logical-test> 
123 ········</cpe-lang:platform> 
124 ········<cpe-lang:platform·id="machine"> 
125 ··········<cpe-lang:logical-test·operator="AND"·negate="false">115 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 116 ············<cpe-lang:logical-test·operator="AND"·negate="true">
 117 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
 118 ············</cpe-lang:logical-test>
 119 ············<cpe-lang:logical-test·operator="AND"·negate="true">
 120 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_ppc64le:def:1"/>
 121 ············</cpe-lang:logical-test>
126 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>122 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
127 ··········</cpe-lang:logical-test>123 ··········</cpe-lang:logical-test>
128 ········</cpe-lang:platform>124 ········</cpe-lang:platform>
129 ········<cpe-lang:platform·id="package_squid_and_system_with_kernel">125 ········<cpe-lang:platform·id="not_runtime_kernel_fips_enabled_and_system_with_kernel">
130 ··········<cpe-lang:logical-test·operator="AND"·negate="false">126 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 127 ············<cpe-lang:logical-test·operator="AND"·negate="true">
131 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-package_squid:def:1"/>128 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-runtime_kernel_fips_enabled:def:1"/>
 129 ············</cpe-lang:logical-test>
132 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>130 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
133 ··········</cpe-lang:logical-test>131 ··········</cpe-lang:logical-test>
134 ········</cpe-lang:platform>132 ········</cpe-lang:platform>
135 ········<cpe-lang:platform·id="package_pam">133 ········<cpe-lang:platform·id="mount_var-tmp">
136 ··········<cpe-lang:logical-test·operator="AND"·negate="false">134 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
137 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>135 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-tmp:def:1"/>
138 ··········</cpe-lang:logical-test>136 ··········</cpe-lang:logical-test>
139 ········</cpe-lang:platform>137 ········</cpe-lang:platform>
140 ········<cpe-lang:platform·id="package_autofs_and_system_with_kernel">138 ········<cpe-lang:platform·id="package_autofs_and_system_with_kernel">
141 ··········<cpe-lang:logical-test·operator="AND"·negate="false">139 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
142 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>140 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>
143 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>141 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
144 ··········</cpe-lang:logical-test>142 ··········</cpe-lang:logical-test>
145 ········</cpe-lang:platform>143 ········</cpe-lang:platform>
 144 ········<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">
146 ········<cpe-lang:platform·id="mount_tmp"> 
147 ··········<cpe-lang:logical-test·operator="AND"·negate="false"> 
148 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_tmp:def:1"/> 
149 ··········</cpe-lang:logical-test> 
150 ········</cpe-lang:platform> 
151 ········<cpe-lang:platform·id="not_s390x_arch"> 
152 ··········<cpe-lang:logical-test·operator="AND"·negate="false">145 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 146 ············<cpe-lang:logical-test·operator="AND"·negate="true">
 147 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
 148 ············</cpe-lang:logical-test>
 149 ············<cpe-lang:logical-test·operator="AND"·negate="true">
153 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>150 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
 151 ············</cpe-lang:logical-test>
 152 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
154 ··········</cpe-lang:logical-test>153 ··········</cpe-lang:logical-test>
155 ········</cpe-lang:platform>154 ········</cpe-lang:platform>
156 ········<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">155 ········<cpe-lang:platform·id="ipv6_enabled">
157 ··········<cpe-lang:logical-test·operator="AND"·negate="false">156 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
158 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>157 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-ipv6_enabled:def:1"/>
159 ··········</cpe-lang:logical-test>158 ··········</cpe-lang:logical-test>
160 ········</cpe-lang:platform>159 ········</cpe-lang:platform>
161 ········<cpe-lang:platform·id="mount_var-log">160 ········<cpe-lang:platform·id="package_gdm">
162 ··········<cpe-lang:logical-test·operator="AND"·negate="false">161 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
163 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-log:def:1"/>162 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-package_gdm:def:1"/>
164 ··········</cpe-lang:logical-test>163 ··········</cpe-lang:logical-test>
165 ········</cpe-lang:platform>164 ········</cpe-lang:platform>
166 ········<cpe-lang:platform·id="uefi">165 ········<cpe-lang:platform·id="package_rsyslog">
167 ··········<cpe-lang:logical-test·operator="AND"·negate="false">166 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
168 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>167 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>
169 ··········</cpe-lang:logical-test>168 ··········</cpe-lang:logical-test>
170 ········</cpe-lang:platform>169 ········</cpe-lang:platform>
171 ········<cpe-lang:platform·id="package_bash">170 ········<cpe-lang:platform·id="not_osbuild_and_system_with_kernel">
172 ··········<cpe-lang:logical-test·operator="AND"·negate="false">171 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 172 ············<cpe-lang:logical-test·operator="AND"·negate="true">
 173 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_osbuild:def:1"/>
 174 ············</cpe-lang:logical-test>
173 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>175 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
174 ··········</cpe-lang:logical-test>176 ··········</cpe-lang:logical-test>
175 ········</cpe-lang:platform>177 ········</cpe-lang:platform>
176 ········<cpe-lang:platform·id="os_linux_ol_le_7_4">178 ········<cpe-lang:platform·id="package_chrony_or_package_ntp">
177 ··········<cpe-lang:logical-test·operator="AND"·negate="false">179 ··········<cpe-lang:logical-test·operator="OR"·negate="false">
 180 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
178 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_le_7_4:def:1"/>181 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-package_ntp:def:1"/>
179 ··········</cpe-lang:logical-test>182 ··········</cpe-lang:logical-test>
180 ········</cpe-lang:platform>183 ········</cpe-lang:platform>
181 ········<cpe-lang:platform·id="package_telnet-server_and_system_with_kernel">184 ········<cpe-lang:platform·id="package_bash">
182 ··········<cpe-lang:logical-test·operator="AND"·negate="false">185 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
183 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-package_telnet-server:def:1"/>186 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>
184 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
185 ··········</cpe-lang:logical-test>187 ··········</cpe-lang:logical-test>
186 ········</cpe-lang:platform>188 ········</cpe-lang:platform>
187 ········<cpe-lang:platform·id="package_iptables">189 ········<cpe-lang:platform·id="uefi">
188 ··········<cpe-lang:logical-test·operator="AND"·negate="false">190 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
189 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>191 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>
Max diff block lines reached; 2550106/2563279 bytes (99.49%) of diff not shown.
2.1 MB
./usr/share/xml/scap/ssg/content/ssg-ol7-ocil.xml
2.1 MB
./usr/share/xml/scap/ssg/content/ssg-ol7-ocil.xml
Ordering differences only
    
Offset 3, 15280 lines modifiedOffset 3, 15437 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_all_accept_ra_defrtr_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-package_syslogng_installed_ocil:questionnaire:1">
 11 ······<ocil:title>Ensure·syslog-ng·is·Installed</ocil:title>
11 ······<ocil:title>Configure·Accepting·Default·Router·in·Router·Advertisements·on·All·IPv6·Interfaces</ocil:title> 
12 ······<ocil:actions> 
13 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_all_accept_ra_defrtr_action:testaction:1</ocil:test_action_ref> 
14 ······</ocil:actions> 
15 ····</ocil:questionnaire> 
16 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_lsetxattr_ocil:questionnaire:1"> 
17 ······<ocil:title>Record·Unsuccessful·Permission·Changes·to·Files·-·lsetxattr</ocil:title> 
18 ······<ocil:actions>12 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_lsetxattr_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-package_syslogng_installed_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>14 ······</ocil:actions>
21 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_fchownat_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_maxclassrepeat_ocil:questionnaire:1">
23 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·fchownat</ocil:title>17 ······<ocil:title>Ensure·PAM·Enforces·Password·Requirements·-·Maximum·Consecutive·Repeating·Characters·from·Same·Character·Class</ocil:title>
24 ······<ocil:actions>18 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_fchownat_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-accounts_password_pam_maxclassrepeat_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>20 ······</ocil:actions>
27 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-postfix_network_listening_disabled_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-accounts_umask_etc_login_defs_ocil:questionnaire:1">
29 ······<ocil:title>Disable·Postfix·Network·Listening</ocil:title>23 ······<ocil:title>Ensure·the·Default·Umask·is·Set·Correctly·in·login.defs</ocil:title>
30 ······<ocil:actions>24 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-postfix_network_listening_disabled_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-accounts_umask_etc_login_defs_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>26 ······</ocil:actions>
33 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_disk_error_action_ocil:questionnaire:1"> 
35 ······<ocil:title>Configure·auditd·Disk·Error·Action·on·Disk·Error</ocil:title>28 ····<ocil:questionnaire·id="ocil:ssg-dconf_gnome_session_idle_user_locks_ocil:questionnaire:1">
 29 ······<ocil:title>Ensure·Users·Cannot·Change·GNOME3·Session·Idle·Settings</ocil:title>
36 ······<ocil:actions>30 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-auditd_data_disk_error_action_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-dconf_gnome_session_idle_user_locks_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>32 ······</ocil:actions>
39 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-package_setroubleshoot-server_removed_ocil:questionnaire:1"> 
41 ······<ocil:title>Uninstall·setroubleshoot-server·Package</ocil:title>34 ····<ocil:questionnaire·id="ocil:ssg-sshd_use_approved_macs_ocil:questionnaire:1">
 35 ······<ocil:title>Use·Only·FIPS·140-2·Validated·MACs</ocil:title>
42 ······<ocil:actions>36 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-package_setroubleshoot-server_removed_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-sshd_use_approved_macs_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>38 ······</ocil:actions>
45 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-service_firewalld_enabled_ocil:questionnaire:1"> 
47 ······<ocil:title>Verify·firewalld·Enabled</ocil:title>40 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_backup_etc_group_ocil:questionnaire:1">
 41 ······<ocil:title>Verify·Group·Who·Owns·Backup·group·File</ocil:title>
48 ······<ocil:actions>42 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-service_firewalld_enabled_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_backup_etc_group_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>44 ······</ocil:actions>
51 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-sssd_memcache_timeout_ocil:questionnaire:1"> 
53 ······<ocil:title>Configure·SSSD's·Memory·Cache·to·Expire</ocil:title>46 ····<ocil:questionnaire·id="ocil:ssg-directory_owner_etc_ipsecd_ocil:questionnaire:1">
 47 ······<ocil:title>Verify·User·Who·Owns·/etc/ipsec.d·Directory</ocil:title>
54 ······<ocil:actions>48 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-sssd_memcache_timeout_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-directory_owner_etc_ipsecd_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>50 ······</ocil:actions>
57 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-sebool_domain_fd_use_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-file_owner_etc_hosts_deny_ocil:questionnaire:1">
59 ······<ocil:title>Enable·the·domain_fd_use·SELinux·Boolean</ocil:title>53 ······<ocil:title>Verify·Ownership·of·/etc/hosts.deny</ocil:title>
60 ······<ocil:actions>54 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-sebool_domain_fd_use_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-file_owner_etc_hosts_deny_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>56 ······</ocil:actions>
63 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-sebool_xserver_clients_write_xshm_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-sebool_domain_kernel_load_modules_ocil:questionnaire:1">
65 ······<ocil:title>Disable·the·xserver_clients_write_xshm·SELinux·Boolean</ocil:title>59 ······<ocil:title>Disable·the·domain_kernel_load_modules·SELinux·Boolean</ocil:title>
66 ······<ocil:actions>60 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-sebool_xserver_clients_write_xshm_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-sebool_domain_kernel_load_modules_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>62 ······</ocil:actions>
69 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_set_min_life_existing_ocil:questionnaire:1"> 
71 ······<ocil:title>Set·Existing·Passwords·Minimum·Age</ocil:title>64 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_send_redirects_ocil:questionnaire:1">
 65 ······<ocil:title>Disable·Kernel·Parameter·for·Sending·ICMP·Redirects·on·all·IPv4·Interfaces·by·Default</ocil:title>
72 ······<ocil:actions>66 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-accounts_password_set_min_life_existing_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_send_redirects_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>68 ······</ocil:actions>
75 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-accounts_user_interactive_home_directory_defined_ocil:questionnaire:1"> 
77 ······<ocil:title>All·Interactive·Users·Must·Have·A·Home·Directory·Defined</ocil:title>70 ····<ocil:questionnaire·id="ocil:ssg-service_ip6tables_enabled_ocil:questionnaire:1">
 71 ······<ocil:title>Verify·ip6tables·Enabled·if·Using·IPv6</ocil:title>
78 ······<ocil:actions>72 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-accounts_user_interactive_home_directory_defined_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-service_ip6tables_enabled_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>74 ······</ocil:actions>
81 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-directory_groupowner_etc_sudoersd_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-sshd_set_login_grace_time_ocil:questionnaire:1">
83 ······<ocil:title>Verify·Group·Who·Owns·/etc/sudoers.d·Directory</ocil:title>77 ······<ocil:title>Ensure·SSH·LoginGraceTime·is·configured</ocil:title>
84 ······<ocil:actions>78 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-directory_groupowner_etc_sudoersd_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-sshd_set_login_grace_time_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>80 ······</ocil:actions>
87 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_set_max_life_existing_ocil:questionnaire:1"> 
89 ······<ocil:title>Set·Existing·Passwords·Maximum·Age</ocil:title>82 ····<ocil:questionnaire·id="ocil:ssg-rsyslog_files_ownership_ocil:questionnaire:1">
 83 ······<ocil:title>Ensure·Log·Files·Are·Owned·By·Appropriate·User</ocil:title>
90 ······<ocil:actions>84 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-accounts_password_set_max_life_existing_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-rsyslog_files_ownership_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>86 ······</ocil:actions>
93 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_backup_etc_group_ocil:questionnaire:1"> 
95 ······<ocil:title>Verify·Permissions·on·Backup·group·File</ocil:title>88 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_execution_setfiles_ocil:questionnaire:1">
 89 ······<ocil:title>Record·Any·Attempts·to·Run·setfiles</ocil:title>
96 ······<ocil:actions>90 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-file_permissions_backup_etc_group_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-audit_rules_execution_setfiles_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>92 ······</ocil:actions>
99 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-disallow_bypass_password_sudo_ocil:questionnaire:1"> 
101 ······<ocil:title>Disallow·Configuration·to·Bypass·Password·Requirements·for·Privilege·Escalation</ocil:title>94 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_lsetxattr_ocil:questionnaire:1">
 95 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·lsetxattr</ocil:title>
102 ······<ocil:actions>96 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-disallow_bypass_password_sudo_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_lsetxattr_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>98 ······</ocil:actions>
105 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_open_o_trunc_write_ocil:questionnaire:1"> 
107 ······<ocil:title>Record·Unsuccessful·Modification·Attempts·to·Files·-·open·O_TRUNC_WRITE</ocil:title>100 ····<ocil:questionnaire·id="ocil:ssg-sudo_add_umask_ocil:questionnaire:1">
 101 ······<ocil:title>Ensure·sudo·umask·is·appropriate·-·sudo·umask</ocil:title>
108 ······<ocil:actions>102 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_open_o_trunc_write_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-sudo_add_umask_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>104 ······</ocil:actions>
111 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_var_log_messages_ocil:questionnaire:1"> 
113 ······<ocil:title>Verify·Permissions·on·/var/log/messages·File</ocil:title>106 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_lremovexattr_ocil:questionnaire:1">
 107 ······<ocil:title>Record·Unsuccessful·Permission·Changes·to·Files·-·lremovexattr</ocil:title>
114 ······<ocil:actions>108 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-file_permissions_var_log_messages_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_lremovexattr_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>110 ······</ocil:actions>
117 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
Max diff block lines reached; 2190923/2203297 bytes (99.44%) of diff not shown.
250 KB
./usr/share/xml/scap/ssg/content/ssg-ol7-xccdf.xml
250 KB
./usr/share/xml/scap/ssg/content/ssg-ol7-xccdf.xml
Ordering differences only
    
Offset 72, 228 lines modifiedOffset 72, 204 lines modified
72 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>72 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
73 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>73 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
74 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>74 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
75 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>75 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
77 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>77 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
78 ··<cpe-lang:platform-specification>78 ··<cpe-lang:platform-specification>
 79 ····<cpe-lang:platform·id="not_aarch64_arch_and_not_ppc64le_arch_and_system_with_kernel">
79 ····<cpe-lang:platform·id="package_libuser"> 
80 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
81 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-package_libuser:def:1"/> 
82 ······</cpe-lang:logical-test> 
83 ····</cpe-lang:platform> 
84 ····<cpe-lang:platform·id="not_bootc"> 
85 ······<cpe-lang:logical-test·operator="AND"·negate="true"> 
86 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-bootc:def:1"/> 
87 ······</cpe-lang:logical-test> 
88 ····</cpe-lang:platform> 
89 ····<cpe-lang:platform·id="machine"> 
90 ······<cpe-lang:logical-test·operator="AND"·negate="false">80 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 81 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 82 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
 83 ········</cpe-lang:logical-test>
 84 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 85 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_ppc64le:def:1"/>
 86 ········</cpe-lang:logical-test>
91 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>87 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
92 ······</cpe-lang:logical-test>88 ······</cpe-lang:logical-test>
93 ····</cpe-lang:platform>89 ····</cpe-lang:platform>
94 ····<cpe-lang:platform·id="package_squid_and_system_with_kernel">90 ····<cpe-lang:platform·id="not_runtime_kernel_fips_enabled_and_system_with_kernel">
95 ······<cpe-lang:logical-test·operator="AND"·negate="false">91 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 92 ········<cpe-lang:logical-test·operator="AND"·negate="true">
96 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-package_squid:def:1"/>93 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-runtime_kernel_fips_enabled:def:1"/>
 94 ········</cpe-lang:logical-test>
97 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>95 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
98 ······</cpe-lang:logical-test>96 ······</cpe-lang:logical-test>
99 ····</cpe-lang:platform>97 ····</cpe-lang:platform>
100 ····<cpe-lang:platform·id="package_pam">98 ····<cpe-lang:platform·id="mount_var-tmp">
101 ······<cpe-lang:logical-test·operator="AND"·negate="false">99 ······<cpe-lang:logical-test·operator="AND"·negate="false">
102 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>100 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-tmp:def:1"/>
103 ······</cpe-lang:logical-test>101 ······</cpe-lang:logical-test>
104 ····</cpe-lang:platform>102 ····</cpe-lang:platform>
105 ····<cpe-lang:platform·id="package_autofs_and_system_with_kernel">103 ····<cpe-lang:platform·id="package_autofs_and_system_with_kernel">
106 ······<cpe-lang:logical-test·operator="AND"·negate="false">104 ······<cpe-lang:logical-test·operator="AND"·negate="false">
107 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>105 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>
108 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>106 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
109 ······</cpe-lang:logical-test>107 ······</cpe-lang:logical-test>
110 ····</cpe-lang:platform>108 ····</cpe-lang:platform>
 109 ····<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">
111 ····<cpe-lang:platform·id="mount_tmp"> 
112 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
113 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_tmp:def:1"/> 
114 ······</cpe-lang:logical-test> 
115 ····</cpe-lang:platform> 
116 ····<cpe-lang:platform·id="not_s390x_arch"> 
117 ······<cpe-lang:logical-test·operator="AND"·negate="false">110 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 111 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 112 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
 113 ········</cpe-lang:logical-test>
 114 ········<cpe-lang:logical-test·operator="AND"·negate="true">
118 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>115 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
 116 ········</cpe-lang:logical-test>
 117 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
119 ······</cpe-lang:logical-test>118 ······</cpe-lang:logical-test>
120 ····</cpe-lang:platform>119 ····</cpe-lang:platform>
121 ····<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">120 ····<cpe-lang:platform·id="ipv6_enabled">
122 ······<cpe-lang:logical-test·operator="AND"·negate="false">121 ······<cpe-lang:logical-test·operator="AND"·negate="false">
123 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>122 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-ipv6_enabled:def:1"/>
124 ······</cpe-lang:logical-test>123 ······</cpe-lang:logical-test>
125 ····</cpe-lang:platform>124 ····</cpe-lang:platform>
126 ····<cpe-lang:platform·id="mount_var-log">125 ····<cpe-lang:platform·id="package_gdm">
127 ······<cpe-lang:logical-test·operator="AND"·negate="false">126 ······<cpe-lang:logical-test·operator="AND"·negate="false">
128 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-log:def:1"/>127 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-package_gdm:def:1"/>
129 ······</cpe-lang:logical-test>128 ······</cpe-lang:logical-test>
130 ····</cpe-lang:platform>129 ····</cpe-lang:platform>
131 ····<cpe-lang:platform·id="uefi">130 ····<cpe-lang:platform·id="package_rsyslog">
132 ······<cpe-lang:logical-test·operator="AND"·negate="false">131 ······<cpe-lang:logical-test·operator="AND"·negate="false">
133 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>132 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>
134 ······</cpe-lang:logical-test>133 ······</cpe-lang:logical-test>
135 ····</cpe-lang:platform>134 ····</cpe-lang:platform>
136 ····<cpe-lang:platform·id="package_bash">135 ····<cpe-lang:platform·id="not_osbuild_and_system_with_kernel">
137 ······<cpe-lang:logical-test·operator="AND"·negate="false">136 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 137 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 138 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_osbuild:def:1"/>
 139 ········</cpe-lang:logical-test>
138 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>140 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
139 ······</cpe-lang:logical-test>141 ······</cpe-lang:logical-test>
140 ····</cpe-lang:platform>142 ····</cpe-lang:platform>
141 ····<cpe-lang:platform·id="os_linux_ol_le_7_4">143 ····<cpe-lang:platform·id="package_chrony_or_package_ntp">
142 ······<cpe-lang:logical-test·operator="AND"·negate="false">144 ······<cpe-lang:logical-test·operator="OR"·negate="false">
 145 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
143 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_le_7_4:def:1"/>146 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-package_ntp:def:1"/>
144 ······</cpe-lang:logical-test>147 ······</cpe-lang:logical-test>
145 ····</cpe-lang:platform>148 ····</cpe-lang:platform>
146 ····<cpe-lang:platform·id="package_telnet-server_and_system_with_kernel">149 ····<cpe-lang:platform·id="package_bash">
147 ······<cpe-lang:logical-test·operator="AND"·negate="false">150 ······<cpe-lang:logical-test·operator="AND"·negate="false">
148 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-package_telnet-server:def:1"/>151 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>
149 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
150 ······</cpe-lang:logical-test>152 ······</cpe-lang:logical-test>
151 ····</cpe-lang:platform>153 ····</cpe-lang:platform>
152 ····<cpe-lang:platform·id="package_iptables">154 ····<cpe-lang:platform·id="uefi">
153 ······<cpe-lang:logical-test·operator="AND"·negate="false">155 ······<cpe-lang:logical-test·operator="AND"·negate="false">
154 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>156 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>
155 ······</cpe-lang:logical-test>157 ······</cpe-lang:logical-test>
156 ····</cpe-lang:platform>158 ····</cpe-lang:platform>
157 ····<cpe-lang:platform·id="krb5_server_older_than_1_17-18_and_krb5_workstation_older_than_1_17-18">159 ····<cpe-lang:platform·id="package_logrotate">
158 ······<cpe-lang:logical-test·operator="AND"·negate="false">160 ······<cpe-lang:logical-test·operator="AND"·negate="false">
159 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-krb5_server_older_than_1_17_18:def:1"/> 
160 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-krb5_workstation_older_than_1_17_18:def:1"/>161 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-package_logrotate:def:1"/>
161 ······</cpe-lang:logical-test>162 ······</cpe-lang:logical-test>
162 ····</cpe-lang:platform>163 ····</cpe-lang:platform>
163 ····<cpe-lang:platform·id="grub2">164 ····<cpe-lang:platform·id="package_chrony">
164 ······<cpe-lang:logical-test·operator="AND"·negate="false">165 ······<cpe-lang:logical-test·operator="AND"·negate="false">
165 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>166 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
166 ······</cpe-lang:logical-test>167 ······</cpe-lang:logical-test>
167 ····</cpe-lang:platform>168 ····</cpe-lang:platform>
168 ····<cpe-lang:platform·id="package_sssd">169 ····<cpe-lang:platform·id="package_sssd">
169 ······<cpe-lang:logical-test·operator="AND"·negate="false">170 ······<cpe-lang:logical-test·operator="AND"·negate="false">
170 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-package_sssd:def:1"/>171 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-package_sssd:def:1"/>
171 ······</cpe-lang:logical-test>172 ······</cpe-lang:logical-test>
172 ····</cpe-lang:platform>173 ····</cpe-lang:platform>
173 ····<cpe-lang:platform·id="wifi-iface"> 
174 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
175 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_wifi_interface:def:1"/> 
176 ······</cpe-lang:logical-test> 
177 ····</cpe-lang:platform> 
178 ····<cpe-lang:platform·id="package_rsyslog"> 
Max diff block lines reached; 241747/255463 bytes (94.63%) of diff not shown.
2.84 MB
./usr/share/xml/scap/ssg/content/ssg-ol8-ds.xml
2.84 MB
./usr/share/xml/scap/ssg/content/ssg-ol8-ds.xml
    
Offset 21, 23 lines modifiedOffset 21, 23 lines modified
21 ····<ds:checks>21 ····<ds:checks>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol8-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol8-oval.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol8-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol8-oval.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol8-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol8-ocil.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol8-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol8-ocil.xml"/>
24 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol8-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol8-cpe-oval.xml"/>24 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol8-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol8-cpe-oval.xml"/>
25 ······<ds:component-ref·id="scap_org.open-scap_cref_security-oval-com.oracle.elsa-ol8.xml.bz2"·xlink:href="https://linux.oracle.com/security/oval/com.oracle.elsa-ol8.xml.bz2"/>25 ······<ds:component-ref·id="scap_org.open-scap_cref_security-oval-com.oracle.elsa-ol8.xml.bz2"·xlink:href="https://linux.oracle.com/security/oval/com.oracle.elsa-ol8.xml.bz2"/>
26 ····</ds:checks>26 ····</ds:checks>
27 ··</ds:data-stream>27 ··</ds:data-stream>
28 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol8-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">28 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol8-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
29 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">29 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
30 ······<cpe-dict:cpe-item·name="cpe:/o:oracle:linux:8">30 ······<cpe-dict:cpe-item·name="cpe:/o:oracle:linux:8">
31 ········<cpe-dict:title·xml:lang="en-us">Oracle·Linux·8</cpe-dict:title>31 ········<cpe-dict:title·xml:lang="en-us">Oracle·Linux·8</cpe-dict:title>
32 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml">oval:ssg-installed_OS_is_ol8:def:1</cpe-dict:check>32 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml">oval:ssg-installed_OS_is_ol8:def:1</cpe-dict:check>
33 ······</cpe-dict:cpe-item>33 ······</cpe-dict:cpe-item>
34 ····</cpe-dict:cpe-list>34 ····</cpe-dict:cpe-list>
35 ··</ds:component>35 ··</ds:component>
36 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol8-xccdf.xml"·timestamp="2025-02-28T20:08:00">36 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol8-xccdf.xml"·timestamp="2025-03-01T22:08:00">
37 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_OL-8"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">37 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_OL-8"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
38 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>38 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
39 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Oracle·Linux·8</xccdf-1.2:title>39 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Oracle·Linux·8</xccdf-1.2:title>
40 ······<xccdf-1.2:description>40 ······<xccdf-1.2:description>
41 ········This·guide·presents·a·catalog·of·security-relevant41 ········This·guide·presents·a·catalog·of·security-relevant
42 configuration·settings·for·Oracle·Linux·8.·It·is·a·rendering·of42 configuration·settings·for·Oracle·Linux·8.·It·is·a·rendering·of
43 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)43 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 107, 238 lines modifiedOffset 107, 197 lines modified
107 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>107 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
108 ······<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>108 ······<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
109 ······<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>109 ······<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
110 ······<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>110 ······<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
111 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>111 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
112 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>112 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
113 ······<cpe-lang:platform-specification>113 ······<cpe-lang:platform-specification>
114 ········<cpe-lang:platform·id="machine_and_not_kernel_uek_or_not_secure_boot">114 ········<cpe-lang:platform·id="not_aarch64_arch_and_not_ppc64le_arch_and_system_with_kernel">
115 ··········<cpe-lang:logical-test·operator="AND"·negate="false">115 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
116 ············<cpe-lang:logical-test·operator="OR"·negate="false"> 
117 ··············<cpe-lang:logical-test·operator="AND"·negate="true">116 ············<cpe-lang:logical-test·operator="AND"·negate="true">
118 ················<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-kernel_uek:def:1"/>117 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
119 ··············</cpe-lang:logical-test> 
120 ··············<cpe-lang:logical-test·operator="AND"·negate="true"> 
121 ················<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-secure_boot_enabled:def:1"/> 
122 ··············</cpe-lang:logical-test> 
123 ············</cpe-lang:logical-test>118 ············</cpe-lang:logical-test>
124 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/> 
125 ··········</cpe-lang:logical-test> 
126 ········</cpe-lang:platform> 
127 ········<cpe-lang:platform·id="package_libuser"> 
128 ··········<cpe-lang:logical-test·operator="AND"·negate="false"> 
129 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-package_libuser:def:1"/> 
130 ··········</cpe-lang:logical-test> 
131 ········</cpe-lang:platform> 
132 ········<cpe-lang:platform·id="not_bootc"> 
133 ··········<cpe-lang:logical-test·operator="AND"·negate="true">119 ············<cpe-lang:logical-test·operator="AND"·negate="true">
 120 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_ppc64le:def:1"/>
 121 ············</cpe-lang:logical-test>
134 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-bootc:def:1"/>122 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
135 ··········</cpe-lang:logical-test>123 ··········</cpe-lang:logical-test>
136 ········</cpe-lang:platform>124 ········</cpe-lang:platform>
137 ········<cpe-lang:platform·id="machine">125 ········<cpe-lang:platform·id="not_runtime_kernel_fips_enabled_and_system_with_kernel">
138 ··········<cpe-lang:logical-test·operator="AND"·negate="false">126 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 127 ············<cpe-lang:logical-test·operator="AND"·negate="true">
 128 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-runtime_kernel_fips_enabled:def:1"/>
 129 ············</cpe-lang:logical-test>
139 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>130 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
140 ··········</cpe-lang:logical-test>131 ··········</cpe-lang:logical-test>
141 ········</cpe-lang:platform>132 ········</cpe-lang:platform>
142 ········<cpe-lang:platform·id="package_squid_and_system_with_kernel">133 ········<cpe-lang:platform·id="package_polkit">
143 ··········<cpe-lang:logical-test·operator="AND"·negate="false">134 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
144 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-package_squid:def:1"/>135 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-package_polkit:def:1"/>
145 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
146 ··········</cpe-lang:logical-test>136 ··········</cpe-lang:logical-test>
147 ········</cpe-lang:platform>137 ········</cpe-lang:platform>
148 ········<cpe-lang:platform·id="package_pam">138 ········<cpe-lang:platform·id="mount_var-tmp">
149 ··········<cpe-lang:logical-test·operator="AND"·negate="false">139 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
150 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>140 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-tmp:def:1"/>
151 ··········</cpe-lang:logical-test>141 ··········</cpe-lang:logical-test>
152 ········</cpe-lang:platform>142 ········</cpe-lang:platform>
153 ········<cpe-lang:platform·id="package_autofs_and_system_with_kernel">143 ········<cpe-lang:platform·id="package_autofs_and_system_with_kernel">
154 ··········<cpe-lang:logical-test·operator="AND"·negate="false">144 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
155 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>145 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>
156 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>146 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
157 ··········</cpe-lang:logical-test>147 ··········</cpe-lang:logical-test>
158 ········</cpe-lang:platform>148 ········</cpe-lang:platform>
159 ········<cpe-lang:platform·id="mount_tmp">149 ········<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">
160 ··········<cpe-lang:logical-test·operator="AND"·negate="false">150 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 151 ············<cpe-lang:logical-test·operator="AND"·negate="true">
 152 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
 153 ············</cpe-lang:logical-test>
 154 ············<cpe-lang:logical-test·operator="AND"·negate="true">
161 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_tmp:def:1"/>155 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
 156 ············</cpe-lang:logical-test>
 157 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
162 ··········</cpe-lang:logical-test>158 ··········</cpe-lang:logical-test>
163 ········</cpe-lang:platform>159 ········</cpe-lang:platform>
164 ········<cpe-lang:platform·id="package_firewalld_and_package_nftables_and_system_with_kernel">160 ········<cpe-lang:platform·id="ipv6_enabled">
165 ··········<cpe-lang:logical-test·operator="AND"·negate="false">161 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
166 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/> 
167 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>162 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-ipv6_enabled:def:1"/>
168 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
169 ··········</cpe-lang:logical-test>163 ··········</cpe-lang:logical-test>
170 ········</cpe-lang:platform>164 ········</cpe-lang:platform>
171 ········<cpe-lang:platform·id="not_s390x_arch">165 ········<cpe-lang:platform·id="package_gdm">
172 ··········<cpe-lang:logical-test·operator="AND"·negate="false">166 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
173 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>167 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-package_gdm:def:1"/>
174 ··········</cpe-lang:logical-test>168 ··········</cpe-lang:logical-test>
175 ········</cpe-lang:platform>169 ········</cpe-lang:platform>
176 ········<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">170 ········<cpe-lang:platform·id="package_rsyslog">
177 ··········<cpe-lang:logical-test·operator="AND"·negate="false">171 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
178 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>172 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>
179 ··········</cpe-lang:logical-test>173 ··········</cpe-lang:logical-test>
180 ········</cpe-lang:platform>174 ········</cpe-lang:platform>
181 ········<cpe-lang:platform·id="mount_var-log">175 ········<cpe-lang:platform·id="not_osbuild_and_system_with_kernel">
182 ··········<cpe-lang:logical-test·operator="AND"·negate="false">176 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 177 ············<cpe-lang:logical-test·operator="AND"·negate="true">
183 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-log:def:1"/>178 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_osbuild:def:1"/>
 179 ············</cpe-lang:logical-test>
 180 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
184 ··········</cpe-lang:logical-test>181 ··········</cpe-lang:logical-test>
185 ········</cpe-lang:platform>182 ········</cpe-lang:platform>
186 ········<cpe-lang:platform·id="uefi">183 ········<cpe-lang:platform·id="package_chrony_or_package_ntp">
187 ··········<cpe-lang:logical-test·operator="AND"·negate="false">184 ··········<cpe-lang:logical-test·operator="OR"·negate="false">
 185 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
188 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>186 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-package_ntp:def:1"/>
189 ··········</cpe-lang:logical-test>187 ··········</cpe-lang:logical-test>
190 ········</cpe-lang:platform>188 ········</cpe-lang:platform>
191 ········<cpe-lang:platform·id="package_bash">189 ········<cpe-lang:platform·id="package_bash">
192 ··········<cpe-lang:logical-test·operator="AND"·negate="false">190 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
193 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>191 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>
194 ··········</cpe-lang:logical-test>192 ··········</cpe-lang:logical-test>
Max diff block lines reached; 2967664/2981317 bytes (99.54%) of diff not shown.
2.48 MB
./usr/share/xml/scap/ssg/content/ssg-ol8-ocil.xml
2.48 MB
./usr/share/xml/scap/ssg/content/ssg-ol8-ocil.xml
Ordering differences only
    
Offset 3, 9600 lines modifiedOffset 3, 9600 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-firewalld_sshd_port_enabled_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-configure_libreswan_crypto_policy_ocil:questionnaire:1">
11 ······<ocil:title>Enable·SSH·Server·firewalld·Firewall·Exception</ocil:title>11 ······<ocil:title>Configure·Libreswan·to·use·System·Crypto·Policy</ocil:title>
12 ······<ocil:actions>12 ······<ocil:actions>
13 ········<ocil:test_action_ref>ocil:ssg-firewalld_sshd_port_enabled_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-configure_libreswan_crypto_policy_action:testaction:1</ocil:test_action_ref>
14 ······</ocil:actions>14 ······</ocil:actions>
15 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
16 ····<ocil:questionnaire·id="ocil:ssg-account_unique_id_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-file_owner_backup_etc_shadow_ocil:questionnaire:1">
17 ······<ocil:title>Ensure·All·Accounts·on·the·System·Have·Unique·User·IDs</ocil:title>17 ······<ocil:title>Verify·Group·Who·Owns·Backup·shadow·File</ocil:title>
18 ······<ocil:actions>18 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-account_unique_id_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-file_owner_backup_etc_shadow_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>20 ······</ocil:actions>
21 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-use_kerberos_security_all_exports_ocil:questionnaire:1"> 
23 ······<ocil:title>Use·Kerberos·Security·on·All·Exports</ocil:title>22 ····<ocil:questionnaire·id="ocil:ssg-sudo_custom_logfile_ocil:questionnaire:1">
 23 ······<ocil:title>Ensure·Sudo·Logfile·Exists·-·sudo·logfile</ocil:title>
24 ······<ocil:actions>24 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-use_kerberos_security_all_exports_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-sudo_custom_logfile_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>26 ······</ocil:actions>
27 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_at_allow_ocil:questionnaire:1"> 
29 ······<ocil:title>Verify·Group·Who·Owns·/etc/at.allow·file</ocil:title>28 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_default_max_addresses_ocil:questionnaire:1">
 29 ······<ocil:title>Configure·Maximum·Number·of·Autoconfigured·Addresses·on·All·IPv6·Interfaces·By·Default</ocil:title>
30 ······<ocil:actions>30 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_at_allow_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_default_max_addresses_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>32 ······</ocil:actions>
33 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-sebool_selinuxuser_ping_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_usergroup_modification_gshadow_ocil:questionnaire:1">
35 ······<ocil:title>Enable·the·selinuxuser_ping·SELinux·Boolean</ocil:title>35 ······<ocil:title>Record·Events·that·Modify·User/Group·Information·-·/etc/gshadow</ocil:title>
36 ······<ocil:actions>36 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-sebool_selinuxuser_ping_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-audit_rules_usergroup_modification_gshadow_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>38 ······</ocil:actions>
39 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_default_max_addresses_ocil:questionnaire:1"> 
41 ······<ocil:title>Configure·Maximum·Number·of·Autoconfigured·Addresses·on·All·IPv6·Interfaces·By·Default</ocil:title>40 ····<ocil:questionnaire·id="ocil:ssg-accounts_user_home_paths_only_ocil:questionnaire:1">
 41 ······<ocil:title>Ensure·that·Users·Path·Contains·Only·Local·Directories</ocil:title>
42 ······<ocil:actions>42 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_default_max_addresses_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-accounts_user_home_paths_only_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>44 ······</ocil:actions>
45 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-enable_authselect_ocil:questionnaire:1">46 ····<ocil:questionnaire·id="ocil:ssg-disable_users_coredumps_ocil:questionnaire:1">
47 ······<ocil:title>Enable·authselect</ocil:title>47 ······<ocil:title>Disable·Core·Dumps·for·All·Users</ocil:title>
48 ······<ocil:actions>48 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-enable_authselect_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-disable_users_coredumps_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>50 ······</ocil:actions>
51 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-service_rsh_disabled_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-audit_delete_failed_ocil:questionnaire:1">
53 ······<ocil:title>Disable·rsh·Service</ocil:title>53 ······<ocil:title>Configure·auditing·of·unsuccessful·file·deletions</ocil:title>
54 ······<ocil:actions>54 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-service_rsh_disabled_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-audit_delete_failed_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>56 ······</ocil:actions>
57 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-service_systemd-journald_enabled_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-firewalld_sshd_port_enabled_ocil:questionnaire:1">
59 ······<ocil:title>Enable·systemd-journald·Service</ocil:title>59 ······<ocil:title>Enable·SSH·Server·firewalld·Firewall·Exception</ocil:title>
60 ······<ocil:actions>60 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-service_systemd-journald_enabled_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-firewalld_sshd_port_enabled_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>62 ······</ocil:actions>
63 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_mount_ocil:questionnaire:1"> 
65 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·mount</ocil:title>64 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_openat_rule_order_ocil:questionnaire:1">
 65 ······<ocil:title>Ensure·auditd·Rules·For·Unauthorized·Attempts·To·openat·Are·Ordered·Correctly</ocil:title>
66 ······<ocil:actions>66 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_mount_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_openat_rule_order_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>68 ······</ocil:actions>
69 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_sysadmin_actions_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_backup_etc_group_ocil:questionnaire:1">
71 ······<ocil:title>Ensure·auditd·Collects·System·Administrator·Actions</ocil:title>71 ······<ocil:title>Verify·Group·Who·Owns·Backup·group·File</ocil:title>
72 ······<ocil:actions>72 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-audit_rules_sysadmin_actions_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_backup_etc_group_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>74 ······</ocil:actions>
75 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-account_password_selinux_faillock_dir_ocil:questionnaire:1"> 
77 ······<ocil:title>An·SELinux·Context·must·be·configured·for·the·pam_faillock.so·records·directory</ocil:title>76 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_module_sig_sha512_ocil:questionnaire:1">
 77 ······<ocil:title>Sign·kernel·modules·with·SHA-512</ocil:title>
78 ······<ocil:actions>78 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-account_password_selinux_faillock_dir_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-kernel_config_module_sig_sha512_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>80 ······</ocil:actions>
81 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-accounts_umask_interactive_users_ocil:questionnaire:1"> 
83 ······<ocil:title>Ensure·the·Default·Umask·is·Set·Correctly·For·Interactive·Users</ocil:title>82 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_kernel_module_loading_init_ocil:questionnaire:1">
 83 ······<ocil:title>Ensure·auditd·Collects·Information·on·Kernel·Module·Loading·-·init_module</ocil:title>
84 ······<ocil:actions>84 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-accounts_umask_interactive_users_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-audit_rules_kernel_module_loading_init_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>86 ······</ocil:actions>
87 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-sebool_mock_enable_homedirs_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-sudoers_validate_passwd_ocil:questionnaire:1">
89 ······<ocil:title>Disable·the·mock_enable_homedirs·SELinux·Boolean</ocil:title>89 ······<ocil:title>Ensure·invoking·users·password·for·privilege·escalation·when·using·sudo</ocil:title>
90 ······<ocil:actions>90 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-sebool_mock_enable_homedirs_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-sudoers_validate_passwd_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>92 ······</ocil:actions>
93 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_passwd_ocil:questionnaire:1"> 
95 ······<ocil:title>Verify·Permissions·on·passwd·File</ocil:title>94 ····<ocil:questionnaire·id="ocil:ssg-service_bluetooth_disabled_ocil:questionnaire:1">
 95 ······<ocil:title>Disable·Bluetooth·Service</ocil:title>
96 ······<ocil:actions>96 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-file_permissions_etc_passwd_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-service_bluetooth_disabled_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>98 ······</ocil:actions>
99 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_compat_vdso_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_minlen_login_defs_ocil:questionnaire:1">
101 ······<ocil:title>Disable·the·32-bit·vDSO</ocil:title>101 ······<ocil:title>Set·Password·Minimum·Length·in·login.defs</ocil:title>
102 ······<ocil:actions>102 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-kernel_config_compat_vdso_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-accounts_password_minlen_login_defs_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>104 ······</ocil:actions>
105 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-package_setroubleshoot-server_removed_ocil:questionnaire:1"> 
107 ······<ocil:title>Uninstall·setroubleshoot-server·Package</ocil:title>106 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_tcp_syncookies_ocil:questionnaire:1">
 107 ······<ocil:title>Enable·Kernel·Parameter·to·Use·TCP·Syncookies·on·Network·Interfaces</ocil:title>
108 ······<ocil:actions>108 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-package_setroubleshoot-server_removed_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_tcp_syncookies_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>110 ······</ocil:actions>
111 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_grub2_cfg_ocil:questionnaire:1">112 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_slub_debug_ocil:questionnaire:1">
113 ······<ocil:title>Verify·/boot/grub2/grub.cfg·Permissions</ocil:title>113 ······<ocil:title>Enable·SLUB·debugging·support</ocil:title>
114 ······<ocil:actions>114 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-file_permissions_grub2_cfg_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-kernel_config_slub_debug_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>116 ······</ocil:actions>
117 ····</ocil:questionnaire>117 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-service_iptables_enabled_ocil:questionnaire:1"> 
119 ······<ocil:title>Verify·iptables·Enabled</ocil:title>118 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_successful_file_modification_fchmodat_ocil:questionnaire:1">
 119 ······<ocil:title>Record·Successful·Permission·Changes·to·Files·-·fchmodat</ocil:title>
120 ······<ocil:actions>120 ······<ocil:actions>
Max diff block lines reached; 2587116/2599711 bytes (99.52%) of diff not shown.
257 KB
./usr/share/xml/scap/ssg/content/ssg-ol8-xccdf.xml
257 KB
./usr/share/xml/scap/ssg/content/ssg-ol8-xccdf.xml
Ordering differences only
    
Offset 72, 238 lines modifiedOffset 72, 197 lines modified
72 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>72 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
73 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>73 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
74 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>74 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
75 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>75 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
77 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>77 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
78 ··<cpe-lang:platform-specification>78 ··<cpe-lang:platform-specification>
79 ····<cpe-lang:platform·id="machine_and_not_kernel_uek_or_not_secure_boot">79 ····<cpe-lang:platform·id="not_aarch64_arch_and_not_ppc64le_arch_and_system_with_kernel">
80 ······<cpe-lang:logical-test·operator="AND"·negate="false">80 ······<cpe-lang:logical-test·operator="AND"·negate="false">
81 ········<cpe-lang:logical-test·operator="OR"·negate="false"> 
82 ··········<cpe-lang:logical-test·operator="AND"·negate="true">81 ········<cpe-lang:logical-test·operator="AND"·negate="true">
83 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-kernel_uek:def:1"/>82 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
84 ··········</cpe-lang:logical-test> 
85 ··········<cpe-lang:logical-test·operator="AND"·negate="true"> 
86 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-secure_boot_enabled:def:1"/> 
87 ··········</cpe-lang:logical-test> 
88 ········</cpe-lang:logical-test>83 ········</cpe-lang:logical-test>
89 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/> 
90 ······</cpe-lang:logical-test> 
91 ····</cpe-lang:platform> 
92 ····<cpe-lang:platform·id="package_libuser"> 
93 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
94 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-package_libuser:def:1"/> 
95 ······</cpe-lang:logical-test> 
96 ····</cpe-lang:platform> 
97 ····<cpe-lang:platform·id="not_bootc"> 
98 ······<cpe-lang:logical-test·operator="AND"·negate="true">84 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 85 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_ppc64le:def:1"/>
 86 ········</cpe-lang:logical-test>
99 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-bootc:def:1"/>87 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
100 ······</cpe-lang:logical-test>88 ······</cpe-lang:logical-test>
101 ····</cpe-lang:platform>89 ····</cpe-lang:platform>
102 ····<cpe-lang:platform·id="machine">90 ····<cpe-lang:platform·id="not_runtime_kernel_fips_enabled_and_system_with_kernel">
103 ······<cpe-lang:logical-test·operator="AND"·negate="false">91 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 92 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 93 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-runtime_kernel_fips_enabled:def:1"/>
 94 ········</cpe-lang:logical-test>
104 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>95 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
105 ······</cpe-lang:logical-test>96 ······</cpe-lang:logical-test>
106 ····</cpe-lang:platform>97 ····</cpe-lang:platform>
107 ····<cpe-lang:platform·id="package_squid_and_system_with_kernel">98 ····<cpe-lang:platform·id="package_polkit">
108 ······<cpe-lang:logical-test·operator="AND"·negate="false">99 ······<cpe-lang:logical-test·operator="AND"·negate="false">
109 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-package_squid:def:1"/>100 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-package_polkit:def:1"/>
110 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
111 ······</cpe-lang:logical-test>101 ······</cpe-lang:logical-test>
112 ····</cpe-lang:platform>102 ····</cpe-lang:platform>
113 ····<cpe-lang:platform·id="package_pam">103 ····<cpe-lang:platform·id="mount_var-tmp">
114 ······<cpe-lang:logical-test·operator="AND"·negate="false">104 ······<cpe-lang:logical-test·operator="AND"·negate="false">
115 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>105 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-tmp:def:1"/>
116 ······</cpe-lang:logical-test>106 ······</cpe-lang:logical-test>
117 ····</cpe-lang:platform>107 ····</cpe-lang:platform>
118 ····<cpe-lang:platform·id="package_autofs_and_system_with_kernel">108 ····<cpe-lang:platform·id="package_autofs_and_system_with_kernel">
119 ······<cpe-lang:logical-test·operator="AND"·negate="false">109 ······<cpe-lang:logical-test·operator="AND"·negate="false">
120 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>110 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>
121 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>111 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
122 ······</cpe-lang:logical-test>112 ······</cpe-lang:logical-test>
123 ····</cpe-lang:platform>113 ····</cpe-lang:platform>
124 ····<cpe-lang:platform·id="mount_tmp">114 ····<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">
125 ······<cpe-lang:logical-test·operator="AND"·negate="false">115 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 116 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 117 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
 118 ········</cpe-lang:logical-test>
 119 ········<cpe-lang:logical-test·operator="AND"·negate="true">
126 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_tmp:def:1"/>120 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
 121 ········</cpe-lang:logical-test>
 122 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
127 ······</cpe-lang:logical-test>123 ······</cpe-lang:logical-test>
128 ····</cpe-lang:platform>124 ····</cpe-lang:platform>
129 ····<cpe-lang:platform·id="package_firewalld_and_package_nftables_and_system_with_kernel">125 ····<cpe-lang:platform·id="ipv6_enabled">
130 ······<cpe-lang:logical-test·operator="AND"·negate="false">126 ······<cpe-lang:logical-test·operator="AND"·negate="false">
131 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/> 
132 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>127 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-ipv6_enabled:def:1"/>
133 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
134 ······</cpe-lang:logical-test>128 ······</cpe-lang:logical-test>
135 ····</cpe-lang:platform>129 ····</cpe-lang:platform>
136 ····<cpe-lang:platform·id="not_s390x_arch">130 ····<cpe-lang:platform·id="package_gdm">
137 ······<cpe-lang:logical-test·operator="AND"·negate="false">131 ······<cpe-lang:logical-test·operator="AND"·negate="false">
138 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>132 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-package_gdm:def:1"/>
139 ······</cpe-lang:logical-test>133 ······</cpe-lang:logical-test>
140 ····</cpe-lang:platform>134 ····</cpe-lang:platform>
141 ····<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">135 ····<cpe-lang:platform·id="package_rsyslog">
142 ······<cpe-lang:logical-test·operator="AND"·negate="false">136 ······<cpe-lang:logical-test·operator="AND"·negate="false">
143 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>137 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>
144 ······</cpe-lang:logical-test>138 ······</cpe-lang:logical-test>
145 ····</cpe-lang:platform>139 ····</cpe-lang:platform>
146 ····<cpe-lang:platform·id="mount_var-log">140 ····<cpe-lang:platform·id="not_osbuild_and_system_with_kernel">
147 ······<cpe-lang:logical-test·operator="AND"·negate="false">141 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 142 ········<cpe-lang:logical-test·operator="AND"·negate="true">
148 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-log:def:1"/>143 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_osbuild:def:1"/>
 144 ········</cpe-lang:logical-test>
 145 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
149 ······</cpe-lang:logical-test>146 ······</cpe-lang:logical-test>
150 ····</cpe-lang:platform>147 ····</cpe-lang:platform>
151 ····<cpe-lang:platform·id="uefi">148 ····<cpe-lang:platform·id="package_chrony_or_package_ntp">
152 ······<cpe-lang:logical-test·operator="AND"·negate="false">149 ······<cpe-lang:logical-test·operator="OR"·negate="false">
 150 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
153 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>151 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-package_ntp:def:1"/>
154 ······</cpe-lang:logical-test>152 ······</cpe-lang:logical-test>
155 ····</cpe-lang:platform>153 ····</cpe-lang:platform>
156 ····<cpe-lang:platform·id="package_bash">154 ····<cpe-lang:platform·id="package_bash">
157 ······<cpe-lang:logical-test·operator="AND"·negate="false">155 ······<cpe-lang:logical-test·operator="AND"·negate="false">
158 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>156 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>
159 ······</cpe-lang:logical-test>157 ······</cpe-lang:logical-test>
160 ····</cpe-lang:platform>158 ····</cpe-lang:platform>
161 ····<cpe-lang:platform·id="package_telnet-server_and_system_with_kernel"> 
162 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
163 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-package_telnet-server:def:1"/> 
164 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
165 ······</cpe-lang:logical-test> 
166 ····</cpe-lang:platform>159 ····<cpe-lang:platform·id="uefi">
167 ····<cpe-lang:platform·id="package_iptables"> 
168 ······<cpe-lang:logical-test·operator="AND"·negate="false">160 ······<cpe-lang:logical-test·operator="AND"·negate="false">
169 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>161 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>
170 ······</cpe-lang:logical-test>162 ······</cpe-lang:logical-test>
171 ····</cpe-lang:platform>163 ····</cpe-lang:platform>
172 ····<cpe-lang:platform·id="krb5_server_older_than_1_17-18_and_krb5_workstation_older_than_1_17-18">164 ····<cpe-lang:platform·id="package_logrotate">
173 ······<cpe-lang:logical-test·operator="AND"·negate="false">165 ······<cpe-lang:logical-test·operator="AND"·negate="false">
174 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-krb5_server_older_than_1_17_18:def:1"/> 
175 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-krb5_workstation_older_than_1_17_18:def:1"/>166 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-package_logrotate:def:1"/>
176 ······</cpe-lang:logical-test>167 ······</cpe-lang:logical-test>
177 ····</cpe-lang:platform>168 ····</cpe-lang:platform>
178 ····<cpe-lang:platform·id="grub2">169 ····<cpe-lang:platform·id="package_chrony">
179 ······<cpe-lang:logical-test·operator="AND"·negate="false">170 ······<cpe-lang:logical-test·operator="AND"·negate="false">
180 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>171 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
181 ······</cpe-lang:logical-test>172 ······</cpe-lang:logical-test>
182 ····</cpe-lang:platform>173 ····</cpe-lang:platform>
183 ····<cpe-lang:platform·id="package_sssd">174 ····<cpe-lang:platform·id="package_sssd">
Max diff block lines reached; 249182/262678 bytes (94.86%) of diff not shown.
2.27 MB
./usr/share/xml/scap/ssg/content/ssg-ol9-ds.xml
2.27 MB
./usr/share/xml/scap/ssg/content/ssg-ol9-ds.xml
    
Offset 21, 23 lines modifiedOffset 21, 23 lines modified
21 ····<ds:checks>21 ····<ds:checks>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol9-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol9-oval.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol9-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol9-oval.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol9-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol9-ocil.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol9-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol9-ocil.xml"/>
24 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol9-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol9-cpe-oval.xml"/>24 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol9-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol9-cpe-oval.xml"/>
25 ······<ds:component-ref·id="scap_org.open-scap_cref_security-oval-com.oracle.elsa-ol9.xml.bz2"·xlink:href="https://linux.oracle.com/security/oval/com.oracle.elsa-ol9.xml.bz2"/>25 ······<ds:component-ref·id="scap_org.open-scap_cref_security-oval-com.oracle.elsa-ol9.xml.bz2"·xlink:href="https://linux.oracle.com/security/oval/com.oracle.elsa-ol9.xml.bz2"/>
26 ····</ds:checks>26 ····</ds:checks>
27 ··</ds:data-stream>27 ··</ds:data-stream>
28 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol9-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">28 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol9-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
29 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">29 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
30 ······<cpe-dict:cpe-item·name="cpe:/o:oracle:linux:9">30 ······<cpe-dict:cpe-item·name="cpe:/o:oracle:linux:9">
31 ········<cpe-dict:title·xml:lang="en-us">Oracle·Linux·9</cpe-dict:title>31 ········<cpe-dict:title·xml:lang="en-us">Oracle·Linux·9</cpe-dict:title>
32 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml">oval:ssg-installed_OS_is_ol9:def:1</cpe-dict:check>32 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml">oval:ssg-installed_OS_is_ol9:def:1</cpe-dict:check>
33 ······</cpe-dict:cpe-item>33 ······</cpe-dict:cpe-item>
34 ····</cpe-dict:cpe-list>34 ····</cpe-dict:cpe-list>
35 ··</ds:component>35 ··</ds:component>
36 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol9-xccdf.xml"·timestamp="2025-02-28T20:08:00">36 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol9-xccdf.xml"·timestamp="2025-03-01T22:08:00">
37 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_OL-9"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">37 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_OL-9"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
38 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>38 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
39 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Oracle·Linux·9</xccdf-1.2:title>39 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Oracle·Linux·9</xccdf-1.2:title>
40 ······<xccdf-1.2:description>40 ······<xccdf-1.2:description>
41 ········This·guide·presents·a·catalog·of·security-relevant41 ········This·guide·presents·a·catalog·of·security-relevant
42 configuration·settings·for·Oracle·Linux·9.·It·is·a·rendering·of42 configuration·settings·for·Oracle·Linux·9.·It·is·a·rendering·of
43 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)43 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 108, 230 lines modifiedOffset 108, 201 lines modified
108 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>108 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
109 ······<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>109 ······<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
110 ······<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>110 ······<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
111 ······<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>111 ······<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
112 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>112 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
113 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>113 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
114 ······<cpe-lang:platform-specification>114 ······<cpe-lang:platform-specification>
115 ········<cpe-lang:platform·id="package_libuser">115 ········<cpe-lang:platform·id="not_aarch64_arch_and_not_ppc64le_arch_and_system_with_kernel">
116 ··········<cpe-lang:logical-test·operator="AND"·negate="false">116 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 117 ············<cpe-lang:logical-test·operator="AND"·negate="true">
 118 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
 119 ············</cpe-lang:logical-test>
 120 ············<cpe-lang:logical-test·operator="AND"·negate="true">
 121 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_ppc64le:def:1"/>
 122 ············</cpe-lang:logical-test>
117 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-package_libuser:def:1"/>123 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
118 ··········</cpe-lang:logical-test>124 ··········</cpe-lang:logical-test>
119 ········</cpe-lang:platform>125 ········</cpe-lang:platform>
120 ········<cpe-lang:platform·id="not_bootc">126 ········<cpe-lang:platform·id="not_runtime_kernel_fips_enabled_and_system_with_kernel">
 127 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
121 ··········<cpe-lang:logical-test·operator="AND"·negate="true">128 ············<cpe-lang:logical-test·operator="AND"·negate="true">
 129 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-runtime_kernel_fips_enabled:def:1"/>
 130 ············</cpe-lang:logical-test>
122 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-bootc:def:1"/>131 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
123 ··········</cpe-lang:logical-test>132 ··········</cpe-lang:logical-test>
124 ········</cpe-lang:platform>133 ········</cpe-lang:platform>
125 ········<cpe-lang:platform·id="machine">134 ········<cpe-lang:platform·id="package_polkit">
126 ··········<cpe-lang:logical-test·operator="AND"·negate="false">135 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
127 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>136 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-package_polkit:def:1"/>
128 ··········</cpe-lang:logical-test>137 ··········</cpe-lang:logical-test>
129 ········</cpe-lang:platform>138 ········</cpe-lang:platform>
130 ········<cpe-lang:platform·id="package_squid_and_system_with_kernel">139 ········<cpe-lang:platform·id="mount_var-tmp">
131 ··········<cpe-lang:logical-test·operator="AND"·negate="false">140 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
132 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-package_squid:def:1"/> 
133 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>141 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-tmp:def:1"/>
134 ··········</cpe-lang:logical-test>142 ··········</cpe-lang:logical-test>
135 ········</cpe-lang:platform>143 ········</cpe-lang:platform>
136 ········<cpe-lang:platform·id="package_pam">144 ········<cpe-lang:platform·id="package_networkmanager">
137 ··········<cpe-lang:logical-test·operator="AND"·negate="false">145 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
138 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>146 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-package_networkmanager:def:1"/>
139 ··········</cpe-lang:logical-test>147 ··········</cpe-lang:logical-test>
140 ········</cpe-lang:platform>148 ········</cpe-lang:platform>
141 ········<cpe-lang:platform·id="package_autofs_and_system_with_kernel">149 ········<cpe-lang:platform·id="package_autofs_and_system_with_kernel">
142 ··········<cpe-lang:logical-test·operator="AND"·negate="false">150 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
143 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>151 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>
144 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>152 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
145 ··········</cpe-lang:logical-test>153 ··········</cpe-lang:logical-test>
146 ········</cpe-lang:platform>154 ········</cpe-lang:platform>
147 ········<cpe-lang:platform·id="mount_tmp">155 ········<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">
148 ··········<cpe-lang:logical-test·operator="AND"·negate="false">156 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 157 ············<cpe-lang:logical-test·operator="AND"·negate="true">
 158 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
 159 ············</cpe-lang:logical-test>
 160 ············<cpe-lang:logical-test·operator="AND"·negate="true">
149 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_tmp:def:1"/>161 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
 162 ············</cpe-lang:logical-test>
 163 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
150 ··········</cpe-lang:logical-test>164 ··········</cpe-lang:logical-test>
151 ········</cpe-lang:platform>165 ········</cpe-lang:platform>
152 ········<cpe-lang:platform·id="package_firewalld_and_package_nftables_and_system_with_kernel">166 ········<cpe-lang:platform·id="ipv6_enabled">
153 ··········<cpe-lang:logical-test·operator="AND"·negate="false">167 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
154 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/> 
155 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>168 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-ipv6_enabled:def:1"/>
156 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
157 ··········</cpe-lang:logical-test>169 ··········</cpe-lang:logical-test>
158 ········</cpe-lang:platform>170 ········</cpe-lang:platform>
159 ········<cpe-lang:platform·id="not_s390x_arch">171 ········<cpe-lang:platform·id="package_gdm">
160 ··········<cpe-lang:logical-test·operator="AND"·negate="false">172 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
161 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>173 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-package_gdm:def:1"/>
162 ··········</cpe-lang:logical-test>174 ··········</cpe-lang:logical-test>
163 ········</cpe-lang:platform>175 ········</cpe-lang:platform>
164 ········<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">176 ········<cpe-lang:platform·id="package_rsyslog">
165 ··········<cpe-lang:logical-test·operator="AND"·negate="false">177 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
166 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>178 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>
167 ··········</cpe-lang:logical-test>179 ··········</cpe-lang:logical-test>
168 ········</cpe-lang:platform>180 ········</cpe-lang:platform>
169 ········<cpe-lang:platform·id="mount_var-log">181 ········<cpe-lang:platform·id="not_osbuild_and_system_with_kernel">
170 ··········<cpe-lang:logical-test·operator="AND"·negate="false">182 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 183 ············<cpe-lang:logical-test·operator="AND"·negate="true">
171 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-log:def:1"/>184 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_osbuild:def:1"/>
 185 ············</cpe-lang:logical-test>
 186 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
172 ··········</cpe-lang:logical-test>187 ··········</cpe-lang:logical-test>
173 ········</cpe-lang:platform>188 ········</cpe-lang:platform>
174 ········<cpe-lang:platform·id="uefi">189 ········<cpe-lang:platform·id="package_chrony_or_package_ntp">
175 ··········<cpe-lang:logical-test·operator="AND"·negate="false">190 ··········<cpe-lang:logical-test·operator="OR"·negate="false">
 191 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
176 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>192 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-package_ntp:def:1"/>
177 ··········</cpe-lang:logical-test>193 ··········</cpe-lang:logical-test>
178 ········</cpe-lang:platform>194 ········</cpe-lang:platform>
179 ········<cpe-lang:platform·id="package_bash">195 ········<cpe-lang:platform·id="package_bash">
180 ··········<cpe-lang:logical-test·operator="AND"·negate="false">196 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
181 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>197 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>
182 ··········</cpe-lang:logical-test>198 ··········</cpe-lang:logical-test>
183 ········</cpe-lang:platform>199 ········</cpe-lang:platform>
184 ········<cpe-lang:platform·id="package_telnet-server_and_system_with_kernel"> 
185 ··········<cpe-lang:logical-test·operator="AND"·negate="false"> 
186 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-package_telnet-server:def:1"/> 
187 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
188 ··········</cpe-lang:logical-test> 
189 ········</cpe-lang:platform>200 ········<cpe-lang:platform·id="uefi">
190 ········<cpe-lang:platform·id="package_iptables"> 
191 ··········<cpe-lang:logical-test·operator="AND"·negate="false">201 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
Max diff block lines reached; 2369010/2383037 bytes (99.41%) of diff not shown.
1.97 MB
./usr/share/xml/scap/ssg/content/ssg-ol9-ocil.xml
1.97 MB
./usr/share/xml/scap/ssg/content/ssg-ol9-ocil.xml
Ordering differences only
    
Offset 3, 6596 lines modifiedOffset 3, 6596 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-disable_users_coredumps_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_refcount_full_ocil:questionnaire:1">
 11 ······<ocil:title>Perform·full·reference·count·validation</ocil:title>
11 ······<ocil:title>Disable·Core·Dumps·for·All·Users</ocil:title> 
12 ······<ocil:actions> 
13 ········<ocil:test_action_ref>ocil:ssg-disable_users_coredumps_action:testaction:1</ocil:test_action_ref> 
14 ······</ocil:actions> 
15 ····</ocil:questionnaire> 
16 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_default_accept_ra_defrtr_ocil:questionnaire:1"> 
17 ······<ocil:title>Configure·Accepting·Default·Router·in·Router·Advertisements·on·All·IPv6·Interfaces·By·Default</ocil:title> 
18 ······<ocil:actions>12 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_default_accept_ra_defrtr_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-kernel_config_refcount_full_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>14 ······</ocil:actions>
21 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_execution_chcon_ocil:questionnaire:1"> 
23 ······<ocil:title>Record·Any·Attempts·to·Run·chcon</ocil:title>16 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_all_accept_redirects_ocil:questionnaire:1">
 17 ······<ocil:title>Disable·Accepting·ICMP·Redirects·for·All·IPv6·Interfaces</ocil:title>
24 ······<ocil:actions>18 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-audit_rules_execution_chcon_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_all_accept_redirects_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>20 ······</ocil:actions>
27 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-dconf_gnome_disable_user_list_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-grub2_page_poison_argument_ocil:questionnaire:1">
29 ······<ocil:title>Disable·the·GNOME3·Login·User·List</ocil:title>23 ······<ocil:title>Enable·page·allocator·poisoning</ocil:title>
30 ······<ocil:actions>24 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-dconf_gnome_disable_user_list_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-grub2_page_poison_argument_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>26 ······</ocil:actions>
33 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-rsyslog_files_groupownership_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-disallow_bypass_password_sudo_ocil:questionnaire:1">
35 ······<ocil:title>Ensure·Log·Files·Are·Owned·By·Appropriate·Group</ocil:title>29 ······<ocil:title>Disallow·Configuration·to·Bypass·Password·Requirements·for·Privilege·Escalation</ocil:title>
36 ······<ocil:actions>30 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-rsyslog_files_groupownership_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-disallow_bypass_password_sudo_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>32 ······</ocil:actions>
39 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-mount_option_var_log_nodev_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-package_quagga_removed_ocil:questionnaire:1">
41 ······<ocil:title>Add·nodev·Option·to·/var/log</ocil:title>35 ······<ocil:title>Uninstall·quagga·Package</ocil:title>
42 ······<ocil:actions>36 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-mount_option_var_log_nodev_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-package_quagga_removed_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>38 ······</ocil:actions>
45 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-file_ownership_binary_dirs_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-sssd_enable_pam_services_ocil:questionnaire:1">
47 ······<ocil:title>Verify·that·System·Executables·Have·Root·Ownership</ocil:title>41 ······<ocil:title>Configure·PAM·in·SSSD·Services</ocil:title>
48 ······<ocil:actions>42 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-file_ownership_binary_dirs_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-sssd_enable_pam_services_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>44 ······</ocil:actions>
51 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_issue_net_ocil:questionnaire:1">46 ····<ocil:questionnaire·id="ocil:ssg-chronyd_client_only_ocil:questionnaire:1">
53 ······<ocil:title>Verify·permissions·on·System·Login·Banner·for·Remote·Connections</ocil:title>47 ······<ocil:title>Disable·chrony·daemon·from·acting·as·server</ocil:title>
54 ······<ocil:actions>48 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-file_permissions_etc_issue_net_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-chronyd_client_only_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>50 ······</ocil:actions>
57 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_time_adjtimex_ocil:questionnaire:1"> 
59 ······<ocil:title>Record·attempts·to·alter·time·through·adjtimex</ocil:title>52 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_shared_media_ocil:questionnaire:1">
 53 ······<ocil:title>Configure·Sending·and·Accepting·Shared·Media·Redirects·by·Default</ocil:title>
60 ······<ocil:actions>54 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-audit_rules_time_adjtimex_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_shared_media_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>56 ······</ocil:actions>
63 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_sshd_private_key_ocil:questionnaire:1"> 
65 ······<ocil:title>Verify·Permissions·on·SSH·Server·Private·*_key·Key·Files</ocil:title>58 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_page_table_isolation_ocil:questionnaire:1">
 59 ······<ocil:title>Remove·the·kernel·mapping·in·user·mode</ocil:title>
66 ······<ocil:actions>60 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-file_permissions_sshd_private_key_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-kernel_config_page_table_isolation_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>62 ······</ocil:actions>
69 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_kernel_module_loading_finit_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_binfmt_misc_ocil:questionnaire:1">
71 ······<ocil:title>Ensure·auditd·Collects·Information·on·Kernel·Module·Loading·and·Unloading·-·finit_module</ocil:title>65 ······<ocil:title>Disable·kernel·support·for·MISC·binaries</ocil:title>
72 ······<ocil:actions>66 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-audit_rules_kernel_module_loading_finit_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-kernel_config_binfmt_misc_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>68 ······</ocil:actions>
75 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-kernel_module_tipc_disabled_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-dconf_gnome_session_idle_user_locks_ocil:questionnaire:1">
77 ······<ocil:title>Disable·TIPC·Support</ocil:title>71 ······<ocil:title>Ensure·Users·Cannot·Change·GNOME3·Session·Idle·Settings</ocil:title>
78 ······<ocil:actions>72 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-kernel_module_tipc_disabled_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-dconf_gnome_session_idle_user_locks_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>74 ······</ocil:actions>
81 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-file_owner_systemmap_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_library_dirs_ocil:questionnaire:1">
83 ······<ocil:title>Verify·User·Who·Owns·System.map·Files</ocil:title>77 ······<ocil:title>Verify·that·Shared·Library·Files·Have·Restrictive·Permissions</ocil:title>
84 ······<ocil:actions>78 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-file_owner_systemmap_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-file_permissions_library_dirs_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>80 ······</ocil:actions>
87 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_log_martians_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-securetty_root_login_console_only_ocil:questionnaire:1">
89 ······<ocil:title>Enable·Kernel·Parameter·to·Log·Martian·Packets·on·all·IPv4·Interfaces</ocil:title>83 ······<ocil:title>Restrict·Virtual·Console·Root·Logins</ocil:title>
90 ······<ocil:actions>84 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_log_martians_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-securetty_root_login_console_only_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>86 ······</ocil:actions>
93 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-dconf_gnome_screensaver_user_locks_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-dconf_gnome_screensaver_user_locks_ocil:questionnaire:1">
95 ······<ocil:title>Ensure·Users·Cannot·Change·GNOME3·Screensaver·Settings</ocil:title>89 ······<ocil:title>Ensure·Users·Cannot·Change·GNOME3·Screensaver·Settings</ocil:title>
96 ······<ocil:actions>90 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-dconf_gnome_screensaver_user_locks_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-dconf_gnome_screensaver_user_locks_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>92 ······</ocil:actions>
99 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-rsyslog_encrypt_offload_actionsendstreamdrivermode_ocil:questionnaire:1"> 
101 ······<ocil:title>Ensure·Rsyslog·Encrypts·Off-Loaded·Audit·Records</ocil:title>94 ····<ocil:questionnaire·id="ocil:ssg-package_cryptsetup-luks_installed_ocil:questionnaire:1">
 95 ······<ocil:title>Install·cryptsetup·Package</ocil:title>
102 ······<ocil:actions>96 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-rsyslog_encrypt_offload_actionsendstreamdrivermode_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-package_cryptsetup-luks_installed_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>98 ······</ocil:actions>
105 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-ssh_keys_passphrase_protected_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-selinux_all_devicefiles_labeled_ocil:questionnaire:1">
107 ······<ocil:title>Verify·the·SSH·Private·Key·Files·Have·a·Passcode</ocil:title>101 ······<ocil:title>Ensure·No·Device·Files·are·Unlabeled·by·SELinux</ocil:title>
108 ······<ocil:actions>102 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-ssh_keys_passphrase_protected_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-selinux_all_devicefiles_labeled_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>104 ······</ocil:actions>
111 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_unix_remember_ocil:questionnaire:1"> 
113 ······<ocil:title>Limit·Password·Reuse</ocil:title>106 ····<ocil:questionnaire·id="ocil:ssg-rsyslog_encrypt_offload_defaultnetstreamdriver_ocil:questionnaire:1">
 107 ······<ocil:title>Ensure·Rsyslog·Encrypts·Off-Loaded·Audit·Records</ocil:title>
114 ······<ocil:actions>108 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-accounts_password_pam_unix_remember_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-rsyslog_encrypt_offload_defaultnetstreamdriver_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>110 ······</ocil:actions>
117 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-group_unique_id_ocil:questionnaire:1">112 ····<ocil:questionnaire·id="ocil:ssg-dconf_gnome_banner_enabled_ocil:questionnaire:1">
119 ······<ocil:title>Ensure·All·Groups·on·the·System·Have·Unique·Group·ID</ocil:title>113 ······<ocil:title>Enable·GNOME3·Login·Warning·Banner</ocil:title>
120 ······<ocil:actions>114 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-group_unique_id_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-dconf_gnome_banner_enabled_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>116 ······</ocil:actions>
123 ····</ocil:questionnaire>117 ····</ocil:questionnaire>
Max diff block lines reached; 2054537/2066886 bytes (99.40%) of diff not shown.
211 KB
./usr/share/xml/scap/ssg/content/ssg-ol9-xccdf.xml
211 KB
./usr/share/xml/scap/ssg/content/ssg-ol9-xccdf.xml
Ordering differences only
    
Offset 73, 230 lines modifiedOffset 73, 201 lines modified
73 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>73 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
74 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>74 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
75 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>75 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
76 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>76 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
77 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>77 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
78 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>78 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
79 ··<cpe-lang:platform-specification>79 ··<cpe-lang:platform-specification>
80 ····<cpe-lang:platform·id="package_libuser">80 ····<cpe-lang:platform·id="not_aarch64_arch_and_not_ppc64le_arch_and_system_with_kernel">
81 ······<cpe-lang:logical-test·operator="AND"·negate="false">81 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 82 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 83 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
 84 ········</cpe-lang:logical-test>
 85 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 86 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_ppc64le:def:1"/>
 87 ········</cpe-lang:logical-test>
82 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-package_libuser:def:1"/>88 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
83 ······</cpe-lang:logical-test>89 ······</cpe-lang:logical-test>
84 ····</cpe-lang:platform>90 ····</cpe-lang:platform>
85 ····<cpe-lang:platform·id="not_bootc">91 ····<cpe-lang:platform·id="not_runtime_kernel_fips_enabled_and_system_with_kernel">
 92 ······<cpe-lang:logical-test·operator="AND"·negate="false">
86 ······<cpe-lang:logical-test·operator="AND"·negate="true">93 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 94 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-runtime_kernel_fips_enabled:def:1"/>
 95 ········</cpe-lang:logical-test>
87 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-bootc:def:1"/>96 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
88 ······</cpe-lang:logical-test>97 ······</cpe-lang:logical-test>
89 ····</cpe-lang:platform>98 ····</cpe-lang:platform>
90 ····<cpe-lang:platform·id="machine">99 ····<cpe-lang:platform·id="package_polkit">
91 ······<cpe-lang:logical-test·operator="AND"·negate="false">100 ······<cpe-lang:logical-test·operator="AND"·negate="false">
92 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>101 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-package_polkit:def:1"/>
93 ······</cpe-lang:logical-test>102 ······</cpe-lang:logical-test>
94 ····</cpe-lang:platform>103 ····</cpe-lang:platform>
95 ····<cpe-lang:platform·id="package_squid_and_system_with_kernel">104 ····<cpe-lang:platform·id="mount_var-tmp">
96 ······<cpe-lang:logical-test·operator="AND"·negate="false">105 ······<cpe-lang:logical-test·operator="AND"·negate="false">
97 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-package_squid:def:1"/> 
98 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>106 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-tmp:def:1"/>
99 ······</cpe-lang:logical-test>107 ······</cpe-lang:logical-test>
100 ····</cpe-lang:platform>108 ····</cpe-lang:platform>
101 ····<cpe-lang:platform·id="package_pam">109 ····<cpe-lang:platform·id="package_networkmanager">
102 ······<cpe-lang:logical-test·operator="AND"·negate="false">110 ······<cpe-lang:logical-test·operator="AND"·negate="false">
103 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>111 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-package_networkmanager:def:1"/>
104 ······</cpe-lang:logical-test>112 ······</cpe-lang:logical-test>
105 ····</cpe-lang:platform>113 ····</cpe-lang:platform>
106 ····<cpe-lang:platform·id="package_autofs_and_system_with_kernel">114 ····<cpe-lang:platform·id="package_autofs_and_system_with_kernel">
107 ······<cpe-lang:logical-test·operator="AND"·negate="false">115 ······<cpe-lang:logical-test·operator="AND"·negate="false">
108 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>116 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>
109 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>117 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
110 ······</cpe-lang:logical-test>118 ······</cpe-lang:logical-test>
111 ····</cpe-lang:platform>119 ····</cpe-lang:platform>
112 ····<cpe-lang:platform·id="mount_tmp">120 ····<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">
113 ······<cpe-lang:logical-test·operator="AND"·negate="false">121 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 122 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 123 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
 124 ········</cpe-lang:logical-test>
 125 ········<cpe-lang:logical-test·operator="AND"·negate="true">
114 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_tmp:def:1"/>126 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
 127 ········</cpe-lang:logical-test>
 128 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
115 ······</cpe-lang:logical-test>129 ······</cpe-lang:logical-test>
116 ····</cpe-lang:platform>130 ····</cpe-lang:platform>
117 ····<cpe-lang:platform·id="package_firewalld_and_package_nftables_and_system_with_kernel">131 ····<cpe-lang:platform·id="ipv6_enabled">
118 ······<cpe-lang:logical-test·operator="AND"·negate="false">132 ······<cpe-lang:logical-test·operator="AND"·negate="false">
119 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/> 
120 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>133 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-ipv6_enabled:def:1"/>
121 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
122 ······</cpe-lang:logical-test>134 ······</cpe-lang:logical-test>
123 ····</cpe-lang:platform>135 ····</cpe-lang:platform>
124 ····<cpe-lang:platform·id="not_s390x_arch">136 ····<cpe-lang:platform·id="package_gdm">
125 ······<cpe-lang:logical-test·operator="AND"·negate="false">137 ······<cpe-lang:logical-test·operator="AND"·negate="false">
126 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>138 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-package_gdm:def:1"/>
127 ······</cpe-lang:logical-test>139 ······</cpe-lang:logical-test>
128 ····</cpe-lang:platform>140 ····</cpe-lang:platform>
129 ····<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">141 ····<cpe-lang:platform·id="package_rsyslog">
130 ······<cpe-lang:logical-test·operator="AND"·negate="false">142 ······<cpe-lang:logical-test·operator="AND"·negate="false">
131 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>143 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>
132 ······</cpe-lang:logical-test>144 ······</cpe-lang:logical-test>
133 ····</cpe-lang:platform>145 ····</cpe-lang:platform>
134 ····<cpe-lang:platform·id="mount_var-log">146 ····<cpe-lang:platform·id="not_osbuild_and_system_with_kernel">
135 ······<cpe-lang:logical-test·operator="AND"·negate="false">147 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 148 ········<cpe-lang:logical-test·operator="AND"·negate="true">
136 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-log:def:1"/>149 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_osbuild:def:1"/>
 150 ········</cpe-lang:logical-test>
 151 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
137 ······</cpe-lang:logical-test>152 ······</cpe-lang:logical-test>
138 ····</cpe-lang:platform>153 ····</cpe-lang:platform>
139 ····<cpe-lang:platform·id="uefi">154 ····<cpe-lang:platform·id="package_chrony_or_package_ntp">
140 ······<cpe-lang:logical-test·operator="AND"·negate="false">155 ······<cpe-lang:logical-test·operator="OR"·negate="false">
 156 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
141 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>157 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-package_ntp:def:1"/>
142 ······</cpe-lang:logical-test>158 ······</cpe-lang:logical-test>
143 ····</cpe-lang:platform>159 ····</cpe-lang:platform>
144 ····<cpe-lang:platform·id="package_bash">160 ····<cpe-lang:platform·id="package_bash">
145 ······<cpe-lang:logical-test·operator="AND"·negate="false">161 ······<cpe-lang:logical-test·operator="AND"·negate="false">
146 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>162 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>
147 ······</cpe-lang:logical-test>163 ······</cpe-lang:logical-test>
148 ····</cpe-lang:platform>164 ····</cpe-lang:platform>
149 ····<cpe-lang:platform·id="package_telnet-server_and_system_with_kernel"> 
150 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
151 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-package_telnet-server:def:1"/> 
152 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
153 ······</cpe-lang:logical-test> 
154 ····</cpe-lang:platform>165 ····<cpe-lang:platform·id="uefi">
155 ····<cpe-lang:platform·id="package_iptables"> 
156 ······<cpe-lang:logical-test·operator="AND"·negate="false">166 ······<cpe-lang:logical-test·operator="AND"·negate="false">
157 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>167 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>
158 ······</cpe-lang:logical-test>168 ······</cpe-lang:logical-test>
159 ····</cpe-lang:platform>169 ····</cpe-lang:platform>
160 ····<cpe-lang:platform·id="os_linux_ol_gt_or_eq_9_and_package_logrotate">170 ····<cpe-lang:platform·id="package_logrotate">
161 ······<cpe-lang:logical-test·operator="AND"·negate="false">171 ······<cpe-lang:logical-test·operator="AND"·negate="false">
162 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_9:def:1"/> 
163 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-package_logrotate:def:1"/>172 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-package_logrotate:def:1"/>
164 ······</cpe-lang:logical-test>173 ······</cpe-lang:logical-test>
165 ····</cpe-lang:platform>174 ····</cpe-lang:platform>
166 ····<cpe-lang:platform·id="grub2">175 ····<cpe-lang:platform·id="package_chrony">
167 ······<cpe-lang:logical-test·operator="AND"·negate="false">176 ······<cpe-lang:logical-test·operator="AND"·negate="false">
168 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>177 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
169 ······</cpe-lang:logical-test>178 ······</cpe-lang:logical-test>
170 ····</cpe-lang:platform>179 ····</cpe-lang:platform>
171 ····<cpe-lang:platform·id="package_sssd">180 ····<cpe-lang:platform·id="package_sssd">
172 ······<cpe-lang:logical-test·operator="AND"·negate="false">181 ······<cpe-lang:logical-test·operator="AND"·negate="false">
173 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-package_sssd:def:1"/>182 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-package_sssd:def:1"/>
174 ······</cpe-lang:logical-test>183 ······</cpe-lang:logical-test>
175 ····</cpe-lang:platform>184 ····</cpe-lang:platform>
176 ····<cpe-lang:platform·id="wifi-iface"> 
177 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
178 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_wifi_interface:def:1"/> 
179 ······</cpe-lang:logical-test> 
180 ····</cpe-lang:platform> 
Max diff block lines reached; 201989/216317 bytes (93.38%) of diff not shown.
965 KB
./usr/share/xml/scap/ssg/content/ssg-openembedded-ds.xml
965 KB
./usr/share/xml/scap/ssg/content/ssg-openembedded-ds.xml
    
Offset 19, 15 lines modifiedOffset 19, 15 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-openembedded-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-openembedded-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-openembedded-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-openembedded-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-openembedded-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-openembedded-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-openembedded-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-openembedded-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-openembedded-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-openembedded-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-openembedded-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-openembedded-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-openembedded-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-openembedded-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:openembedded:harden:">28 ······<cpe-dict:cpe-item·name="cpe:/o:openembedded:harden:">
29 ········<cpe-dict:title·xml:lang="en-us">OpenEmbedded·Harden·distribution</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">OpenEmbedded·Harden·distribution</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml">oval:ssg-installed_OS_is_oeharden:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml">oval:ssg-installed_OS_is_oeharden:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ······<cpe-dict:cpe-item·name="cpe:/o:openembedded:nodistro:">32 ······<cpe-dict:cpe-item·name="cpe:/o:openembedded:nodistro:">
33 ········<cpe-dict:title·xml:lang="en-us">OpenEmbedded·nodistro</cpe-dict:title>33 ········<cpe-dict:title·xml:lang="en-us">OpenEmbedded·nodistro</cpe-dict:title>
Offset 39, 15 lines modifiedOffset 39, 15 lines modified
39 ······</cpe-dict:cpe-item>39 ······</cpe-dict:cpe-item>
40 ······<cpe-dict:cpe-item·name="cpe:/o:openembedded:poky:">40 ······<cpe-dict:cpe-item·name="cpe:/o:openembedded:poky:">
41 ········<cpe-dict:title·xml:lang="en-us">OpenEmbedded·Poky·reference·distribution</cpe-dict:title>41 ········<cpe-dict:title·xml:lang="en-us">OpenEmbedded·Poky·reference·distribution</cpe-dict:title>
42 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml">oval:ssg-installed_OS_is_poky:def:1</cpe-dict:check>42 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml">oval:ssg-installed_OS_is_poky:def:1</cpe-dict:check>
43 ······</cpe-dict:cpe-item>43 ······</cpe-dict:cpe-item>
44 ····</cpe-dict:cpe-list>44 ····</cpe-dict:cpe-list>
45 ··</ds:component>45 ··</ds:component>
46 ··<ds:component·id="scap_org.open-scap_comp_ssg-openembedded-xccdf.xml"·timestamp="2025-02-28T20:08:00">46 ··<ds:component·id="scap_org.open-scap_comp_ssg-openembedded-xccdf.xml"·timestamp="2025-03-01T22:08:00">
47 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_OPENEMBEDDED"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">47 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_OPENEMBEDDED"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
48 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>48 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
49 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·OpenEmbedded</xccdf-1.2:title>49 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·OpenEmbedded</xccdf-1.2:title>
50 ······<xccdf-1.2:description>50 ······<xccdf-1.2:description>
51 ········This·guide·presents·a·catalog·of·security-relevant51 ········This·guide·presents·a·catalog·of·security-relevant
52 configuration·settings·for·OpenEmbedded.·It·is·a·rendering·of52 configuration·settings·for·OpenEmbedded.·It·is·a·rendering·of
53 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)53 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 116, 106 lines modifiedOffset 116, 107 lines modified
116 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>116 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
117 ······<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>117 ······<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
118 ······<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>118 ······<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
119 ······<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>119 ······<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
120 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>120 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
121 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>121 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
122 ······<cpe-lang:platform-specification>122 ······<cpe-lang:platform-specification>
123 ········<cpe-lang:platform·id="not_bootc">123 ········<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">
 124 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
124 ··········<cpe-lang:logical-test·operator="AND"·negate="true">125 ············<cpe-lang:logical-test·operator="AND"·negate="true">
 126 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
 127 ············</cpe-lang:logical-test>
 128 ············<cpe-lang:logical-test·operator="AND"·negate="true">
125 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-bootc:def:1"/>129 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
 130 ············</cpe-lang:logical-test>
 131 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
126 ··········</cpe-lang:logical-test>132 ··········</cpe-lang:logical-test>
127 ········</cpe-lang:platform>133 ········</cpe-lang:platform>
128 ········<cpe-lang:platform·id="machine">134 ········<cpe-lang:platform·id="ipv6_enabled">
129 ··········<cpe-lang:logical-test·operator="AND"·negate="false">135 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
130 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>136 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-ipv6_enabled:def:1"/>
131 ··········</cpe-lang:logical-test>137 ··········</cpe-lang:logical-test>
132 ········</cpe-lang:platform>138 ········</cpe-lang:platform>
133 ········<cpe-lang:platform·id="package_squid_and_system_with_kernel">139 ········<cpe-lang:platform·id="package_gdm">
134 ··········<cpe-lang:logical-test·operator="AND"·negate="false">140 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
135 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_squid:def:1"/>141 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_gdm:def:1"/>
136 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
137 ··········</cpe-lang:logical-test>142 ··········</cpe-lang:logical-test>
138 ········</cpe-lang:platform>143 ········</cpe-lang:platform>
139 ········<cpe-lang:platform·id="package_pam">144 ········<cpe-lang:platform·id="package_rsyslog">
140 ··········<cpe-lang:logical-test·operator="AND"·negate="false">145 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
141 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>146 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>
142 ··········</cpe-lang:logical-test>147 ··········</cpe-lang:logical-test>
143 ········</cpe-lang:platform>148 ········</cpe-lang:platform>
144 ········<cpe-lang:platform·id="package_bash">149 ········<cpe-lang:platform·id="package_bash">
145 ··········<cpe-lang:logical-test·operator="AND"·negate="false">150 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
146 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>151 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>
147 ··········</cpe-lang:logical-test>152 ··········</cpe-lang:logical-test>
148 ········</cpe-lang:platform>153 ········</cpe-lang:platform>
149 ········<cpe-lang:platform·id="package_iptables">154 ········<cpe-lang:platform·id="package_logrotate">
150 ··········<cpe-lang:logical-test·operator="AND"·negate="false">155 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
151 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>156 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_logrotate:def:1"/>
152 ··········</cpe-lang:logical-test>157 ··········</cpe-lang:logical-test>
153 ········</cpe-lang:platform>158 ········</cpe-lang:platform>
154 ········<cpe-lang:platform·id="wifi-iface">159 ········<cpe-lang:platform·id="package_chrony">
155 ··········<cpe-lang:logical-test·operator="AND"·negate="false">160 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
156 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_wifi_interface:def:1"/>161 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
157 ··········</cpe-lang:logical-test>162 ··········</cpe-lang:logical-test>
158 ········</cpe-lang:platform>163 ········</cpe-lang:platform>
159 ········<cpe-lang:platform·id="package_rsyslog">164 ········<cpe-lang:platform·id="package_ufw_and_system_with_kernel">
160 ··········<cpe-lang:logical-test·operator="AND"·negate="false">165 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
161 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>166 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
 167 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
162 ··········</cpe-lang:logical-test>168 ··········</cpe-lang:logical-test>
163 ········</cpe-lang:platform>169 ········</cpe-lang:platform>
164 ········<cpe-lang:platform·id="package_systemd">170 ········<cpe-lang:platform·id="package_firewalld">
165 ··········<cpe-lang:logical-test·operator="AND"·negate="false">171 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
166 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>172 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>
167 ··········</cpe-lang:logical-test>173 ··········</cpe-lang:logical-test>
168 ········</cpe-lang:platform>174 ········</cpe-lang:platform>
169 ········<cpe-lang:platform·id="package_avahi_and_system_with_kernel">175 ········<cpe-lang:platform·id="package_rsh-server">
170 ··········<cpe-lang:logical-test·operator="AND"·negate="false">176 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
171 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_avahi:def:1"/>177 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_rsh-server:def:1"/>
172 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
173 ··········</cpe-lang:logical-test>178 ··········</cpe-lang:logical-test>
174 ········</cpe-lang:platform>179 ········</cpe-lang:platform>
175 ········<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">180 ········<cpe-lang:platform·id="package_systemd">
 181 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 182 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>
 183 ··········</cpe-lang:logical-test>
 184 ········</cpe-lang:platform>
 185 ········<cpe-lang:platform·id="not_bootc_and_not_container">
176 ··········<cpe-lang:logical-test·operator="AND"·negate="false">186 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
177 ············<cpe-lang:logical-test·operator="AND"·negate="true">187 ············<cpe-lang:logical-test·operator="AND"·negate="true">
178 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>188 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-bootc:def:1"/>
179 ············</cpe-lang:logical-test>189 ············</cpe-lang:logical-test>
180 ············<cpe-lang:logical-test·operator="AND"·negate="true">190 ············<cpe-lang:logical-test·operator="AND"·negate="true">
181 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>191 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_container:def:1"/>
182 ············</cpe-lang:logical-test>192 ············</cpe-lang:logical-test>
183 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/> 
184 ··········</cpe-lang:logical-test> 
185 ········</cpe-lang:platform> 
186 ········<cpe-lang:platform·id="package_firewalld"> 
187 ··········<cpe-lang:logical-test·operator="AND"·negate="false"> 
188 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/> 
189 ··········</cpe-lang:logical-test>193 ··········</cpe-lang:logical-test>
190 ········</cpe-lang:platform>194 ········</cpe-lang:platform>
 195 ········<cpe-lang:platform·id="package_iptables_and_service_disabled_firewalld_and_system_with_kernel">
191 ········<cpe-lang:platform·id="non-uefi"> 
192 ··········<cpe-lang:logical-test·operator="AND"·negate="false"> 
193 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_non_uefi:def:1"/> 
194 ··········</cpe-lang:logical-test> 
195 ········</cpe-lang:platform> 
196 ········<cpe-lang:platform·id="package_postfix"> 
197 ··········<cpe-lang:logical-test·operator="AND"·negate="false">196 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
Max diff block lines reached; 973890/987776 bytes (98.59%) of diff not shown.
895 KB
./usr/share/xml/scap/ssg/content/ssg-openembedded-ocil.xml
895 KB
./usr/share/xml/scap/ssg/content/ssg-openembedded-ocil.xml
Ordering differences only
    
Offset 3, 2665 lines modifiedOffset 3, 2665 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-package_cron_installed_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_rhosts_rsa_ocil:questionnaire:1">
11 ······<ocil:title>Install·the·cron·service</ocil:title>11 ······<ocil:title>Disable·SSH·Support·for·Rhosts·RSA·Authentication</ocil:title>
12 ······<ocil:actions>12 ······<ocil:actions>
13 ········<ocil:test_action_ref>ocil:ssg-package_cron_installed_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_rhosts_rsa_action:testaction:1</ocil:test_action_ref>
14 ······</ocil:actions>14 ······</ocil:actions>
15 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
16 ····<ocil:questionnaire·id="ocil:ssg-package_nss-tools_installed_ocil:questionnaire:1"> 
17 ······<ocil:title>Ensure·nss-tools·is·installed</ocil:title>16 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_retry_ocil:questionnaire:1">
 17 ······<ocil:title>Ensure·PAM·Enforces·Password·Requirements·-·Authentication·Retry·Prompts·Permitted·Per-Session</ocil:title>
18 ······<ocil:actions>18 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-package_nss-tools_installed_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-accounts_password_pam_retry_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>20 ······</ocil:actions>
21 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_file_deletion_events_rename_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-grub2_l1tf_argument_ocil:questionnaire:1">
23 ······<ocil:title>Ensure·auditd·Collects·File·Deletion·Events·by·User·-·rename</ocil:title>23 ······<ocil:title>Configure·L1·Terminal·Fault·mitigations</ocil:title>
24 ······<ocil:actions>24 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-audit_rules_file_deletion_events_rename_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-grub2_l1tf_argument_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>26 ······</ocil:actions>
27 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-kernel_module_rds_disabled_ocil:questionnaire:1">
29 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands</ocil:title>29 ······<ocil:title>Disable·RDS·Support</ocil:title>
30 ······<ocil:actions>30 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-kernel_module_rds_disabled_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>32 ······</ocil:actions>
33 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-service_named_disabled_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-file_owner_cron_weekly_ocil:questionnaire:1">
35 ······<ocil:title>Disable·named·Service</ocil:title>35 ······<ocil:title>Verify·Owner·on·cron.weekly</ocil:title>
36 ······<ocil:actions>36 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-service_named_disabled_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-file_owner_cron_weekly_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>38 ······</ocil:actions>
39 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_security_yama_ocil:questionnaire:1"> 
41 ······<ocil:title>Enable·Yama·support</ocil:title>40 ····<ocil:questionnaire·id="ocil:ssg-file_owner_backup_etc_gshadow_ocil:questionnaire:1">
 41 ······<ocil:title>Verify·User·Who·Owns·Backup·gshadow·File</ocil:title>
42 ······<ocil:actions>42 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-kernel_config_security_yama_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-file_owner_backup_etc_gshadow_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>44 ······</ocil:actions>
45 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_security_dmesg_restrict_ocil:questionnaire:1"> 
47 ······<ocil:title>Restrict·unprivileged·access·to·the·kernel·syslog</ocil:title>46 ····<ocil:questionnaire·id="ocil:ssg-audit_privileged_commands_shutdown_ocil:questionnaire:1">
 47 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·shutdown</ocil:title>
48 ······<ocil:actions>48 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-kernel_config_security_dmesg_restrict_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-audit_privileged_commands_shutdown_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>50 ······</ocil:actions>
51 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-rsyslog_encrypt_offload_defaultnetstreamdriver_ocil:questionnaire:1"> 
53 ······<ocil:title>Ensure·Rsyslog·Encrypts·Off-Loaded·Audit·Records</ocil:title>52 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_warn_age_login_defs_ocil:questionnaire:1">
 53 ······<ocil:title>Set·Password·Warning·Age</ocil:title>
54 ······<ocil:actions>54 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-rsyslog_encrypt_offload_defaultnetstreamdriver_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-accounts_password_warn_age_login_defs_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>56 ······</ocil:actions>
57 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-group_unique_name_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-banner_etc_issue_ocil:questionnaire:1">
59 ······<ocil:title>Ensure·All·Groups·on·the·System·Have·Unique·Group·Names</ocil:title>59 ······<ocil:title>Modify·the·System·Login·Banner</ocil:title>
60 ······<ocil:actions>60 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-group_unique_name_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-banner_etc_issue_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>62 ······</ocil:actions>
63 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_route_localnet_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_debug_fs_ocil:questionnaire:1">
65 ······<ocil:title>Prevent·Routing·External·Traffic·to·Local·Loopback·on·All·IPv4·Interfaces</ocil:title>65 ······<ocil:title>Disable·kernel·debugfs</ocil:title>
66 ······<ocil:actions>66 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_route_localnet_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-kernel_config_debug_fs_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>68 ······</ocil:actions>
69 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-accounts_no_uid_except_zero_ocil:questionnaire:1"> 
71 ······<ocil:title>Verify·Only·Root·Has·UID·0</ocil:title>70 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_secure_redirects_ocil:questionnaire:1">
 71 ······<ocil:title>Configure·Kernel·Parameter·for·Accepting·Secure·Redirects·By·Default</ocil:title>
72 ······<ocil:actions>72 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-accounts_no_uid_except_zero_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_secure_redirects_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>74 ······</ocil:actions>
75 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_max_log_file_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_max_log_file_ocil:questionnaire:1">
77 ······<ocil:title>Configure·auditd·Max·Log·File·Size</ocil:title>77 ······<ocil:title>Configure·auditd·Max·Log·File·Size</ocil:title>
78 ······<ocil:actions>78 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-auditd_data_retention_max_log_file_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-auditd_data_retention_max_log_file_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>80 ······</ocil:actions>
81 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-sshd_set_login_grace_time_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_kerb_auth_ocil:questionnaire:1">
83 ······<ocil:title>Ensure·SSH·LoginGraceTime·is·configured</ocil:title>83 ······<ocil:title>Disable·Kerberos·Authentication</ocil:title>
84 ······<ocil:actions>84 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-sshd_set_login_grace_time_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_kerb_auth_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>86 ······</ocil:actions>
87 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-set_iptables_default_rule_forward_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_tcp_forwarding_ocil:questionnaire:1">
89 ······<ocil:title>Set·Default·iptables·Policy·for·Forwarded·Packets</ocil:title>89 ······<ocil:title>Disable·SSH·TCP·Forwarding</ocil:title>
90 ······<ocil:actions>90 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-set_iptables_default_rule_forward_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_tcp_forwarding_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>92 ······</ocil:actions>
93 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-dir_permissions_library_dirs_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_cron_allow_ocil:questionnaire:1">
95 ······<ocil:title>Verify·that·Shared·Library·Directories·Have·Restrictive·Permissions</ocil:title>95 ······<ocil:title>Verify·Permissions·on·/etc/cron.allow·file</ocil:title>
96 ······<ocil:actions>96 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-dir_permissions_library_dirs_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-file_permissions_cron_allow_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>98 ······</ocil:actions>
99 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-sudo_remove_nopasswd_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-kernel_module_ipv6_option_disabled_ocil:questionnaire:1">
101 ······<ocil:title>Ensure·Users·Re-Authenticate·for·Privilege·Escalation·-·sudo·NOPASSWD</ocil:title>101 ······<ocil:title>Disable·IPv6·Networking·Support·Automatic·Loading</ocil:title>
102 ······<ocil:actions>102 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-sudo_remove_nopasswd_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-kernel_module_ipv6_option_disabled_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>104 ······</ocil:actions>
105 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_gssapi_auth_ocil:questionnaire:1"> 
107 ······<ocil:title>Disable·GSSAPI·Authentication</ocil:title>106 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_file_deletion_events_rmdir_ocil:questionnaire:1">
 107 ······<ocil:title>Ensure·auditd·Collects·File·Deletion·Events·by·User·-·rmdir</ocil:title>
108 ······<ocil:actions>108 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_gssapi_auth_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-audit_rules_file_deletion_events_rmdir_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>110 ······</ocil:actions>
111 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_page_table_isolation_ocil:questionnaire:1">112 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_time_adjtimex_ocil:questionnaire:1">
113 ······<ocil:title>Remove·the·kernel·mapping·in·user·mode</ocil:title>113 ······<ocil:title>Record·attempts·to·alter·time·through·adjtimex</ocil:title>
114 ······<ocil:actions>114 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-kernel_config_page_table_isolation_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-audit_rules_time_adjtimex_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>116 ······</ocil:actions>
117 ····</ocil:questionnaire>117 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_var_log_syslog_ocil:questionnaire:1">118 ····<ocil:questionnaire·id="ocil:ssg-set_iptables_default_rule_ocil:questionnaire:1">
119 ······<ocil:title>Verify·Group·Who·Owns·/var/log/syslog·File</ocil:title>119 ······<ocil:title>Set·Default·iptables·Policy·for·Incoming·Packets</ocil:title>
120 ······<ocil:actions>120 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_var_log_syslog_action:testaction:1</ocil:test_action_ref>121 ········<ocil:test_action_ref>ocil:ssg-set_iptables_default_rule_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>122 ······</ocil:actions>
123 ····</ocil:questionnaire>123 ····</ocil:questionnaire>
Max diff block lines reached; 903712/916125 bytes (98.65%) of diff not shown.
26.2 KB
./usr/share/xml/scap/ssg/content/ssg-openembedded-xccdf.xml
26.1 KB
./usr/share/xml/scap/ssg/content/ssg-openembedded-xccdf.xml
Ordering differences only
    
Offset 71, 106 lines modifiedOffset 71, 107 lines modified
71 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>71 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
72 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>72 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
73 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>73 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
74 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>74 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
75 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>75 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
77 ··<cpe-lang:platform-specification>77 ··<cpe-lang:platform-specification>
78 ····<cpe-lang:platform·id="not_bootc">78 ····<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">
 79 ······<cpe-lang:logical-test·operator="AND"·negate="false">
79 ······<cpe-lang:logical-test·operator="AND"·negate="true">80 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 81 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
 82 ········</cpe-lang:logical-test>
 83 ········<cpe-lang:logical-test·operator="AND"·negate="true">
80 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-bootc:def:1"/>84 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
 85 ········</cpe-lang:logical-test>
 86 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
81 ······</cpe-lang:logical-test>87 ······</cpe-lang:logical-test>
82 ····</cpe-lang:platform>88 ····</cpe-lang:platform>
83 ····<cpe-lang:platform·id="machine">89 ····<cpe-lang:platform·id="ipv6_enabled">
84 ······<cpe-lang:logical-test·operator="AND"·negate="false">90 ······<cpe-lang:logical-test·operator="AND"·negate="false">
85 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>91 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-ipv6_enabled:def:1"/>
86 ······</cpe-lang:logical-test>92 ······</cpe-lang:logical-test>
87 ····</cpe-lang:platform>93 ····</cpe-lang:platform>
88 ····<cpe-lang:platform·id="package_squid_and_system_with_kernel">94 ····<cpe-lang:platform·id="package_gdm">
89 ······<cpe-lang:logical-test·operator="AND"·negate="false">95 ······<cpe-lang:logical-test·operator="AND"·negate="false">
90 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_squid:def:1"/>96 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_gdm:def:1"/>
91 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
92 ······</cpe-lang:logical-test>97 ······</cpe-lang:logical-test>
93 ····</cpe-lang:platform>98 ····</cpe-lang:platform>
94 ····<cpe-lang:platform·id="package_pam">99 ····<cpe-lang:platform·id="package_rsyslog">
95 ······<cpe-lang:logical-test·operator="AND"·negate="false">100 ······<cpe-lang:logical-test·operator="AND"·negate="false">
96 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>101 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>
97 ······</cpe-lang:logical-test>102 ······</cpe-lang:logical-test>
98 ····</cpe-lang:platform>103 ····</cpe-lang:platform>
99 ····<cpe-lang:platform·id="package_bash">104 ····<cpe-lang:platform·id="package_bash">
100 ······<cpe-lang:logical-test·operator="AND"·negate="false">105 ······<cpe-lang:logical-test·operator="AND"·negate="false">
101 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>106 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>
102 ······</cpe-lang:logical-test>107 ······</cpe-lang:logical-test>
103 ····</cpe-lang:platform>108 ····</cpe-lang:platform>
104 ····<cpe-lang:platform·id="package_iptables">109 ····<cpe-lang:platform·id="package_logrotate">
105 ······<cpe-lang:logical-test·operator="AND"·negate="false">110 ······<cpe-lang:logical-test·operator="AND"·negate="false">
106 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>111 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_logrotate:def:1"/>
107 ······</cpe-lang:logical-test>112 ······</cpe-lang:logical-test>
108 ····</cpe-lang:platform>113 ····</cpe-lang:platform>
109 ····<cpe-lang:platform·id="wifi-iface">114 ····<cpe-lang:platform·id="package_chrony">
110 ······<cpe-lang:logical-test·operator="AND"·negate="false">115 ······<cpe-lang:logical-test·operator="AND"·negate="false">
111 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_wifi_interface:def:1"/>116 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
112 ······</cpe-lang:logical-test>117 ······</cpe-lang:logical-test>
113 ····</cpe-lang:platform>118 ····</cpe-lang:platform>
114 ····<cpe-lang:platform·id="package_rsyslog">119 ····<cpe-lang:platform·id="package_ufw_and_system_with_kernel">
115 ······<cpe-lang:logical-test·operator="AND"·negate="false">120 ······<cpe-lang:logical-test·operator="AND"·negate="false">
116 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>121 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
 122 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
117 ······</cpe-lang:logical-test>123 ······</cpe-lang:logical-test>
118 ····</cpe-lang:platform>124 ····</cpe-lang:platform>
119 ····<cpe-lang:platform·id="package_systemd">125 ····<cpe-lang:platform·id="package_firewalld">
120 ······<cpe-lang:logical-test·operator="AND"·negate="false">126 ······<cpe-lang:logical-test·operator="AND"·negate="false">
121 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>127 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>
122 ······</cpe-lang:logical-test>128 ······</cpe-lang:logical-test>
123 ····</cpe-lang:platform>129 ····</cpe-lang:platform>
124 ····<cpe-lang:platform·id="package_avahi_and_system_with_kernel">130 ····<cpe-lang:platform·id="package_rsh-server">
125 ······<cpe-lang:logical-test·operator="AND"·negate="false">131 ······<cpe-lang:logical-test·operator="AND"·negate="false">
126 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_avahi:def:1"/>132 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_rsh-server:def:1"/>
127 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
128 ······</cpe-lang:logical-test>133 ······</cpe-lang:logical-test>
129 ····</cpe-lang:platform>134 ····</cpe-lang:platform>
130 ····<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">135 ····<cpe-lang:platform·id="package_systemd">
 136 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 137 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>
 138 ······</cpe-lang:logical-test>
 139 ····</cpe-lang:platform>
 140 ····<cpe-lang:platform·id="not_bootc_and_not_container">
131 ······<cpe-lang:logical-test·operator="AND"·negate="false">141 ······<cpe-lang:logical-test·operator="AND"·negate="false">
132 ········<cpe-lang:logical-test·operator="AND"·negate="true">142 ········<cpe-lang:logical-test·operator="AND"·negate="true">
133 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>143 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-bootc:def:1"/>
134 ········</cpe-lang:logical-test>144 ········</cpe-lang:logical-test>
135 ········<cpe-lang:logical-test·operator="AND"·negate="true">145 ········<cpe-lang:logical-test·operator="AND"·negate="true">
136 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>146 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_container:def:1"/>
137 ········</cpe-lang:logical-test>147 ········</cpe-lang:logical-test>
138 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/> 
139 ······</cpe-lang:logical-test> 
140 ····</cpe-lang:platform> 
141 ····<cpe-lang:platform·id="package_firewalld"> 
142 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
143 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/> 
144 ······</cpe-lang:logical-test> 
145 ····</cpe-lang:platform> 
146 ····<cpe-lang:platform·id="non-uefi"> 
147 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
148 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_non_uefi:def:1"/> 
149 ······</cpe-lang:logical-test>148 ······</cpe-lang:logical-test>
150 ····</cpe-lang:platform>149 ····</cpe-lang:platform>
151 ····<cpe-lang:platform·id="package_postfix">150 ····<cpe-lang:platform·id="package_iptables_and_service_disabled_firewalld_and_system_with_kernel">
152 ······<cpe-lang:logical-test·operator="AND"·negate="false">151 ······<cpe-lang:logical-test·operator="AND"·negate="false">
153 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_postfix:def:1"/>152 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
 153 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_firewalld:def:1"/>
 154 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
154 ······</cpe-lang:logical-test>155 ······</cpe-lang:logical-test>
155 ····</cpe-lang:platform>156 ····</cpe-lang:platform>
156 ····<cpe-lang:platform·id="package_audit">157 ····<cpe-lang:platform·id="aarch64_arch_or_x86_64_arch">
157 ······<cpe-lang:logical-test·operator="AND"·negate="false">158 ······<cpe-lang:logical-test·operator="OR"·negate="false">
 159 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
158 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_audit:def:1"/>160 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/>
159 ······</cpe-lang:logical-test>161 ······</cpe-lang:logical-test>
160 ····</cpe-lang:platform>162 ····</cpe-lang:platform>
161 ····<cpe-lang:platform·id="package_snmpd_and_system_with_kernel">163 ····<cpe-lang:platform·id="package_pam">
162 ······<cpe-lang:logical-test·operator="AND"·negate="false">164 ······<cpe-lang:logical-test·operator="AND"·negate="false">
163 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_snmpd:def:1"/>165 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>
164 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
165 ······</cpe-lang:logical-test>166 ······</cpe-lang:logical-test>
166 ····</cpe-lang:platform>167 ····</cpe-lang:platform>
167 ····<cpe-lang:platform·id="package_logrotate">168 ····<cpe-lang:platform·id="machine">
168 ······<cpe-lang:logical-test·operator="AND"·negate="false">169 ······<cpe-lang:logical-test·operator="AND"·negate="false">
169 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_logrotate:def:1"/>170 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
170 ······</cpe-lang:logical-test>171 ······</cpe-lang:logical-test>
171 ····</cpe-lang:platform>172 ····</cpe-lang:platform>
172 ····<cpe-lang:platform·id="not_rhcos4-rhel9_and_service_disabled_nftables_and_service_disabled_ufw_and_system_with_kernel">173 ····<cpe-lang:platform·id="not_rhcos4-rhel9_and_service_disabled_nftables_and_service_disabled_ufw_and_system_with_kernel">
173 ······<cpe-lang:logical-test·operator="AND"·negate="false">174 ······<cpe-lang:logical-test·operator="AND"·negate="false">
174 ········<cpe-lang:logical-test·operator="AND"·negate="true">175 ········<cpe-lang:logical-test·operator="AND"·negate="true">
175 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-installed_OS_is_rhcos4_rhel9:def:1"/>176 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-installed_OS_is_rhcos4_rhel9:def:1"/>
176 ········</cpe-lang:logical-test>177 ········</cpe-lang:logical-test>
Offset 180, 117 lines modifiedOffset 181, 116 lines modified
180 ······</cpe-lang:logical-test>181 ······</cpe-lang:logical-test>
181 ····</cpe-lang:platform>182 ····</cpe-lang:platform>
182 ····<cpe-lang:platform·id="package_sudo">183 ····<cpe-lang:platform·id="package_sudo">
183 ······<cpe-lang:logical-test·operator="AND"·negate="false">184 ······<cpe-lang:logical-test·operator="AND"·negate="false">
184 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_sudo:def:1"/>185 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_sudo:def:1"/>
Max diff block lines reached; 12869/26611 bytes (48.36%) of diff not shown.
582 KB
./usr/share/xml/scap/ssg/content/ssg-openeuler2203-ds.xml
582 KB
./usr/share/xml/scap/ssg/content/ssg-openeuler2203-ds.xml
    
Offset 19, 15 lines modifiedOffset 19, 15 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-openeuler2203-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-openeuler2203-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-openeuler2203-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-openeuler2203-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-openeuler2203-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-openeuler2203-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-openeuler2203-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-openeuler2203-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-openeuler2203-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-openeuler2203-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-openeuler2203-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-openeuler2203-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-openeuler2203-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-openeuler2203-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:openEuler:openEuler:22.03LTS:ga:server">28 ······<cpe-dict:cpe-item·name="cpe:/o:openEuler:openEuler:22.03LTS:ga:server">
29 ········<cpe-dict:title·xml:lang="en-us">openEuler·22.03·LTS</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">openEuler·22.03·LTS</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml">oval:ssg-installed_OS_is_openeuler2203:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml">oval:ssg-installed_OS_is_openeuler2203:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ······<cpe-dict:cpe-item·name="cpe:/o:openEuler:openEuler:22.03LTS_SP1:ga:server">32 ······<cpe-dict:cpe-item·name="cpe:/o:openEuler:openEuler:22.03LTS_SP1:ga:server">
33 ········<cpe-dict:title·xml:lang="en-us">openEuler·22.03·LTS·SP1</cpe-dict:title>33 ········<cpe-dict:title·xml:lang="en-us">openEuler·22.03·LTS·SP1</cpe-dict:title>
Offset 35, 15 lines modifiedOffset 35, 15 lines modified
35 ······</cpe-dict:cpe-item>35 ······</cpe-dict:cpe-item>
36 ······<cpe-dict:cpe-item·name="cpe:/o:openEuler:openEuler:22.03LTS_SP2:ga:server">36 ······<cpe-dict:cpe-item·name="cpe:/o:openEuler:openEuler:22.03LTS_SP2:ga:server">
37 ········<cpe-dict:title·xml:lang="en-us">openEuler·22.03·LTS·SP2</cpe-dict:title>37 ········<cpe-dict:title·xml:lang="en-us">openEuler·22.03·LTS·SP2</cpe-dict:title>
38 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml">oval:ssg-installed_OS_is_openeuler2203:def:1</cpe-dict:check>38 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml">oval:ssg-installed_OS_is_openeuler2203:def:1</cpe-dict:check>
39 ······</cpe-dict:cpe-item>39 ······</cpe-dict:cpe-item>
40 ····</cpe-dict:cpe-list>40 ····</cpe-dict:cpe-list>
41 ··</ds:component>41 ··</ds:component>
42 ··<ds:component·id="scap_org.open-scap_comp_ssg-openeuler2203-xccdf.xml"·timestamp="2025-02-28T20:08:00">42 ··<ds:component·id="scap_org.open-scap_comp_ssg-openeuler2203-xccdf.xml"·timestamp="2025-03-01T22:08:00">
43 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_OPENEULER2203"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">43 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_OPENEULER2203"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
44 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>44 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
45 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·openEuler·2203</xccdf-1.2:title>45 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·openEuler·2203</xccdf-1.2:title>
46 ······<xccdf-1.2:description>46 ······<xccdf-1.2:description>
47 ········This·guide·presents·a·catalog·of·security-relevant47 ········This·guide·presents·a·catalog·of·security-relevant
48 configuration·settings·for·openEuler·2203.·It·is·a·rendering·of48 configuration·settings·for·openEuler·2203.·It·is·a·rendering·of
49 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)49 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 112, 169 lines modifiedOffset 112, 169 lines modified
112 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>112 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
113 ······<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>113 ······<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
114 ······<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>114 ······<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
115 ······<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>115 ······<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
116 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>116 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
117 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>117 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
118 ······<cpe-lang:platform-specification>118 ······<cpe-lang:platform-specification>
119 ········<cpe-lang:platform·id="package_nftables_and_service_disabled_firewalld_and_system_with_kernel">119 ········<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">
120 ··········<cpe-lang:logical-test·operator="AND"·negate="false">120 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 121 ············<cpe-lang:logical-test·operator="AND"·negate="true">
121 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>122 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
122 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_firewalld:def:1"/>123 ············</cpe-lang:logical-test>
 124 ············<cpe-lang:logical-test·operator="AND"·negate="true">
123 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>125 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
 126 ············</cpe-lang:logical-test>
 127 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
124 ··········</cpe-lang:logical-test>128 ··········</cpe-lang:logical-test>
125 ········</cpe-lang:platform>129 ········</cpe-lang:platform>
126 ········<cpe-lang:platform·id="package_pam">130 ········<cpe-lang:platform·id="ipv6_enabled">
127 ··········<cpe-lang:logical-test·operator="AND"·negate="false">131 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
128 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>132 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-ipv6_enabled:def:1"/>
129 ··········</cpe-lang:logical-test>133 ··········</cpe-lang:logical-test>
130 ········</cpe-lang:platform>134 ········</cpe-lang:platform>
131 ········<cpe-lang:platform·id="uefi">135 ········<cpe-lang:platform·id="package_rsyslog">
132 ··········<cpe-lang:logical-test·operator="AND"·negate="false">136 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
133 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>137 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>
134 ··········</cpe-lang:logical-test>138 ··········</cpe-lang:logical-test>
135 ········</cpe-lang:platform>139 ········</cpe-lang:platform>
136 ········<cpe-lang:platform·id="package_bash">140 ········<cpe-lang:platform·id="package_bash">
137 ··········<cpe-lang:logical-test·operator="AND"·negate="false">141 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
138 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>142 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>
139 ··········</cpe-lang:logical-test>143 ··········</cpe-lang:logical-test>
140 ········</cpe-lang:platform>144 ········</cpe-lang:platform>
141 ········<cpe-lang:platform·id="package_iptables"> 
142 ··········<cpe-lang:logical-test·operator="AND"·negate="false"> 
143 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/> 
144 ··········</cpe-lang:logical-test> 
145 ········</cpe-lang:platform> 
146 ········<cpe-lang:platform·id="grub2">145 ········<cpe-lang:platform·id="uefi">
147 ··········<cpe-lang:logical-test·operator="AND"·negate="false"> 
148 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/> 
149 ··········</cpe-lang:logical-test> 
150 ········</cpe-lang:platform> 
151 ········<cpe-lang:platform·id="wifi-iface"> 
152 ··········<cpe-lang:logical-test·operator="AND"·negate="false">146 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
153 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_wifi_interface:def:1"/>147 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>
154 ··········</cpe-lang:logical-test>148 ··········</cpe-lang:logical-test>
155 ········</cpe-lang:platform>149 ········</cpe-lang:platform>
156 ········<cpe-lang:platform·id="package_rsyslog">150 ········<cpe-lang:platform·id="package_chrony">
157 ··········<cpe-lang:logical-test·operator="AND"·negate="false">151 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
158 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>152 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
159 ··········</cpe-lang:logical-test>153 ··········</cpe-lang:logical-test>
160 ········</cpe-lang:platform>154 ········</cpe-lang:platform>
161 ········<cpe-lang:platform·id="package_nftables_and_service_disabled_firewalld">155 ········<cpe-lang:platform·id="package_nftables_and_service_disabled_firewalld_and_service_disabled_ufw">
162 ··········<cpe-lang:logical-test·operator="AND"·negate="false">156 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
163 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>157 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
164 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_firewalld:def:1"/>158 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_firewalld:def:1"/>
 159 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_ufw:def:1"/>
165 ··········</cpe-lang:logical-test>160 ··········</cpe-lang:logical-test>
166 ········</cpe-lang:platform>161 ········</cpe-lang:platform>
167 ········<cpe-lang:platform·id="package_avahi_and_system_with_kernel">162 ········<cpe-lang:platform·id="package_firewalld">
168 ··········<cpe-lang:logical-test·operator="AND"·negate="false">163 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
169 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_avahi:def:1"/>164 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>
170 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
171 ··········</cpe-lang:logical-test>165 ··········</cpe-lang:logical-test>
172 ········</cpe-lang:platform>166 ········</cpe-lang:platform>
173 ········<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">167 ········<cpe-lang:platform·id="not_bootc_and_not_container">
174 ··········<cpe-lang:logical-test·operator="AND"·negate="false">168 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
175 ············<cpe-lang:logical-test·operator="AND"·negate="true">169 ············<cpe-lang:logical-test·operator="AND"·negate="true">
176 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>170 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-bootc:def:1"/>
177 ············</cpe-lang:logical-test>171 ············</cpe-lang:logical-test>
178 ············<cpe-lang:logical-test·operator="AND"·negate="true">172 ············<cpe-lang:logical-test·operator="AND"·negate="true">
179 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>173 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_container:def:1"/>
180 ············</cpe-lang:logical-test>174 ············</cpe-lang:logical-test>
 175 ··········</cpe-lang:logical-test>
 176 ········</cpe-lang:platform>
 177 ········<cpe-lang:platform·id="package_iptables_and_service_disabled_firewalld_and_system_with_kernel">
 178 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
181 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>179 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
 180 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_firewalld:def:1"/>
 181 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
182 ··········</cpe-lang:logical-test>182 ··········</cpe-lang:logical-test>
183 ········</cpe-lang:platform>183 ········</cpe-lang:platform>
184 ········<cpe-lang:platform·id="package_firewalld">184 ········<cpe-lang:platform·id="package_pam">
185 ··········<cpe-lang:logical-test·operator="AND"·negate="false">185 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
186 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>186 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>
187 ··········</cpe-lang:logical-test>187 ··········</cpe-lang:logical-test>
188 ········</cpe-lang:platform>188 ········</cpe-lang:platform>
189 ········<cpe-lang:platform·id="non-uefi">189 ········<cpe-lang:platform·id="package_sudo">
190 ··········<cpe-lang:logical-test·operator="AND"·negate="false">190 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
191 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_non_uefi:def:1"/>191 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_sudo:def:1"/>
192 ··········</cpe-lang:logical-test>192 ··········</cpe-lang:logical-test>
193 ········</cpe-lang:platform>193 ········</cpe-lang:platform>
194 ········<cpe-lang:platform·id="package_audit">194 ········<cpe-lang:platform·id="system_with_kernel">
195 ··········<cpe-lang:logical-test·operator="AND"·negate="false">195 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
Max diff block lines reached; 581536/595595 bytes (97.64%) of diff not shown.
530 KB
./usr/share/xml/scap/ssg/content/ssg-openeuler2203-ocil.xml
530 KB
./usr/share/xml/scap/ssg/content/ssg-openeuler2203-ocil.xml
Ordering differences only
    
Offset 3, 3701 lines modifiedOffset 3, 3774 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-accounts_passwords_pam_faillock_unlock_time_ocil:questionnaire:1"> 
11 ······<ocil:title>Set·Lockout·Time·for·Failed·Password·Attempts</ocil:title> 
12 ······<ocil:actions> 
13 ········<ocil:test_action_ref>ocil:ssg-accounts_passwords_pam_faillock_unlock_time_action:testaction:1</ocil:test_action_ref> 
14 ······</ocil:actions> 
15 ····</ocil:questionnaire> 
16 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_tcp_forwarding_ocil:questionnaire:1"> 
17 ······<ocil:title>Disable·SSH·TCP·Forwarding</ocil:title> 
18 ······<ocil:actions> 
19 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_tcp_forwarding_action:testaction:1</ocil:test_action_ref> 
20 ······</ocil:actions> 
21 ····</ocil:questionnaire> 
22 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_all_accept_redirects_ocil:questionnaire:1"> 
23 ······<ocil:title>Disable·Accepting·ICMP·Redirects·for·All·IPv6·Interfaces</ocil:title> 
24 ······<ocil:actions> 
25 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_all_accept_redirects_action:testaction:1</ocil:test_action_ref> 
26 ······</ocil:actions> 
27 ····</ocil:questionnaire> 
28 ····<ocil:questionnaire·id="ocil:ssg-set_firewalld_appropriate_zone_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-sysctl_fs_protected_symlinks_ocil:questionnaire:1">
29 ······<ocil:title>Ensure·network·interfaces·are·assigned·to·appropriate·zone</ocil:title>11 ······<ocil:title>Enable·Kernel·Parameter·to·Enforce·DAC·on·Symlinks</ocil:title>
30 ······<ocil:actions>12 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-set_firewalld_appropriate_zone_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-sysctl_fs_protected_symlinks_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>14 ······</ocil:actions>
33 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-rsyslog_cron_logging_ocil:questionnaire:1"> 
35 ······<ocil:title>Ensure·cron·Is·Logging·To·Rsyslog</ocil:title>16 ····<ocil:questionnaire·id="ocil:ssg-ensure_gpgcheck_never_disabled_ocil:questionnaire:1">
 17 ······<ocil:title>Ensure·gpgcheck·Enabled·for·All·dnf·Package·Repositories</ocil:title>
36 ······<ocil:actions>18 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-rsyslog_cron_logging_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-ensure_gpgcheck_never_disabled_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>20 ······</ocil:actions>
39 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_admin_space_left_percentage_ocil:questionnaire:1"> 
41 ······<ocil:title>Configure·auditd·admin_space_left·on·Low·Disk·Space</ocil:title>22 ····<ocil:questionnaire·id="ocil:ssg-set_loopback_traffic_ocil:questionnaire:1">
 23 ······<ocil:title>Set·configuration·for·loopback·traffic</ocil:title>
42 ······<ocil:actions>24 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-auditd_data_retention_admin_space_left_percentage_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-set_loopback_traffic_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>26 ······</ocil:actions>
45 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_cron_hourly_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_backup_etc_group_ocil:questionnaire:1">
47 ······<ocil:title>Verify·Group·Who·Owns·cron.hourly</ocil:title>29 ······<ocil:title>Verify·Permissions·on·Backup·group·File</ocil:title>
48 ······<ocil:actions>30 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_cron_hourly_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-file_permissions_backup_etc_group_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>32 ······</ocil:actions>
51 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-service_chronyd_enabled_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-service_auditd_enabled_ocil:questionnaire:1">
53 ······<ocil:title>The·Chronyd·service·is·enabled</ocil:title>35 ······<ocil:title>Enable·auditd·Service</ocil:title>
54 ······<ocil:actions>36 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-service_chronyd_enabled_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-service_auditd_enabled_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>38 ······</ocil:actions>
57 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_secure_redirects_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_dcredit_ocil:questionnaire:1">
59 ······<ocil:title>Disable·Kernel·Parameter·for·Accepting·Secure·ICMP·Redirects·on·all·IPv4·Interfaces</ocil:title>41 ······<ocil:title>Ensure·PAM·Enforces·Password·Requirements·-·Minimum·Digit·Characters</ocil:title>
60 ······<ocil:actions>42 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_secure_redirects_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-accounts_password_pam_dcredit_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>44 ······</ocil:actions>
63 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-set_iptables_default_rule_ocil:questionnaire:1"> 
65 ······<ocil:title>Set·Default·iptables·Policy·for·Incoming·Packets</ocil:title>46 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_successful_file_modification_unlink_ocil:questionnaire:1">
 47 ······<ocil:title>Record·Successful·Delete·Attempts·to·Files·-·unlink</ocil:title>
66 ······<ocil:actions>48 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-set_iptables_default_rule_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-audit_rules_successful_file_modification_unlink_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>50 ······</ocil:actions>
69 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-package_ypserv_removed_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_cron_hourly_ocil:questionnaire:1">
71 ······<ocil:title>Uninstall·ypserv·Package</ocil:title>53 ······<ocil:title>Verify·Group·Who·Owns·cron.hourly</ocil:title>
72 ······<ocil:actions>54 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-package_ypserv_removed_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_cron_hourly_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>56 ······</ocil:actions>
75 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_gshadow_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_issue_ocil:questionnaire:1">
77 ······<ocil:title>Verify·Permissions·on·gshadow·File</ocil:title>59 ······<ocil:title>Verify·Group·Ownership·of·System·Login·Banner</ocil:title>
78 ······<ocil:actions>60 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-file_permissions_etc_gshadow_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_issue_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>62 ······</ocil:actions>
81 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_passwd_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-service_nftables_enabled_ocil:questionnaire:1">
83 ······<ocil:title>Verify·Permissions·on·passwd·File</ocil:title>65 ······<ocil:title>Verify·nftables·Service·is·Enabled</ocil:title>
84 ······<ocil:actions>66 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-file_permissions_etc_passwd_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-service_nftables_enabled_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>68 ······</ocil:actions>
87 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_backup_etc_gshadow_ocil:questionnaire:1"> 
89 ······<ocil:title>Verify·Group·Who·Owns·Backup·gshadow·File</ocil:title>70 ····<ocil:questionnaire·id="ocil:ssg-service_firewalld_enabled_ocil:questionnaire:1">
 71 ······<ocil:title>Verify·firewalld·Enabled</ocil:title>
90 ······<ocil:actions>72 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_backup_etc_gshadow_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-service_firewalld_enabled_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>74 ······</ocil:actions>
93 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_shadow_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-sshd_use_strong_kex_ocil:questionnaire:1">
95 ······<ocil:title>Verify·Group·Who·Owns·shadow·File</ocil:title>77 ······<ocil:title>Use·Only·Strong·Key·Exchange·algorithms</ocil:title>
96 ······<ocil:actions>78 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_shadow_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-sshd_use_strong_kex_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>80 ······</ocil:actions>
99 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-file_owner_cron_weekly_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-sysctl_fs_protected_hardlinks_ocil:questionnaire:1">
101 ······<ocil:title>Verify·Owner·on·cron.weekly</ocil:title>83 ······<ocil:title>Enable·Kernel·Parameter·to·Enforce·DAC·on·Hardlinks</ocil:title>
102 ······<ocil:actions>84 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-file_owner_cron_weekly_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-sysctl_fs_protected_hardlinks_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>86 ······</ocil:actions>
105 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-require_emergency_target_auth_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-nftables_ensure_default_deny_policy_ocil:questionnaire:1">
107 ······<ocil:title>Require·Authentication·for·Emergency·Systemd·Target</ocil:title>89 ······<ocil:title>Ensure·nftables·Default·Deny·Firewall·Policy</ocil:title>
108 ······<ocil:actions>90 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-require_emergency_target_auth_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-nftables_ensure_default_deny_policy_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>92 ······</ocil:actions>
111 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_num_logs_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-ntpd_configure_restrictions_ocil:questionnaire:1">
113 ······<ocil:title>Configure·auditd·Number·of·Logs·Retained</ocil:title>95 ······<ocil:title>Configure·server·restrictions·for·ntpd</ocil:title>
114 ······<ocil:actions>96 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-auditd_data_retention_num_logs_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-ntpd_configure_restrictions_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>98 ······</ocil:actions>
117 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_accept_source_route_ocil:questionnaire:1"> 
119 ······<ocil:title>Disable·Kernel·Parameter·for·Accepting·Source-Routed·Packets·on·IPv4·Interfaces·by·Default</ocil:title>100 ····<ocil:questionnaire·id="ocil:ssg-rsyslog_remote_access_monitoring_ocil:questionnaire:1">
 101 ······<ocil:title>Ensure·remote·access·methods·are·monitored·in·Rsyslog</ocil:title>
120 ······<ocil:actions>102 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_accept_source_route_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-rsyslog_remote_access_monitoring_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>104 ······</ocil:actions>
123 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
124 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_log_martians_ocil:questionnaire:1">106 ····<ocil:questionnaire·id="ocil:ssg-rsyslog_cron_logging_ocil:questionnaire:1">
Max diff block lines reached; 530241/542201 bytes (97.79%) of diff not shown.
22.8 KB
./usr/share/xml/scap/ssg/content/ssg-openeuler2203-xccdf.xml
22.7 KB
./usr/share/xml/scap/ssg/content/ssg-openeuler2203-xccdf.xml
Ordering differences only
    
Offset 71, 169 lines modifiedOffset 71, 169 lines modified
71 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>71 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
72 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>72 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
73 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>73 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
74 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>74 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
75 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>75 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
77 ··<cpe-lang:platform-specification>77 ··<cpe-lang:platform-specification>
78 ····<cpe-lang:platform·id="package_nftables_and_service_disabled_firewalld_and_system_with_kernel">78 ····<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">
79 ······<cpe-lang:logical-test·operator="AND"·negate="false">79 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 80 ········<cpe-lang:logical-test·operator="AND"·negate="true">
80 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>81 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
81 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_firewalld:def:1"/>82 ········</cpe-lang:logical-test>
 83 ········<cpe-lang:logical-test·operator="AND"·negate="true">
82 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>84 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
 85 ········</cpe-lang:logical-test>
 86 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
83 ······</cpe-lang:logical-test>87 ······</cpe-lang:logical-test>
84 ····</cpe-lang:platform>88 ····</cpe-lang:platform>
85 ····<cpe-lang:platform·id="package_pam">89 ····<cpe-lang:platform·id="ipv6_enabled">
86 ······<cpe-lang:logical-test·operator="AND"·negate="false">90 ······<cpe-lang:logical-test·operator="AND"·negate="false">
87 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>91 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-ipv6_enabled:def:1"/>
88 ······</cpe-lang:logical-test>92 ······</cpe-lang:logical-test>
89 ····</cpe-lang:platform>93 ····</cpe-lang:platform>
90 ····<cpe-lang:platform·id="uefi">94 ····<cpe-lang:platform·id="package_rsyslog">
91 ······<cpe-lang:logical-test·operator="AND"·negate="false">95 ······<cpe-lang:logical-test·operator="AND"·negate="false">
92 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>96 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>
93 ······</cpe-lang:logical-test>97 ······</cpe-lang:logical-test>
94 ····</cpe-lang:platform>98 ····</cpe-lang:platform>
95 ····<cpe-lang:platform·id="package_bash">99 ····<cpe-lang:platform·id="package_bash">
96 ······<cpe-lang:logical-test·operator="AND"·negate="false">100 ······<cpe-lang:logical-test·operator="AND"·negate="false">
97 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>101 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>
98 ······</cpe-lang:logical-test>102 ······</cpe-lang:logical-test>
99 ····</cpe-lang:platform>103 ····</cpe-lang:platform>
100 ····<cpe-lang:platform·id="package_iptables"> 
101 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
102 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/> 
103 ······</cpe-lang:logical-test> 
104 ····</cpe-lang:platform> 
105 ····<cpe-lang:platform·id="grub2">104 ····<cpe-lang:platform·id="uefi">
106 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
107 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/> 
108 ······</cpe-lang:logical-test> 
109 ····</cpe-lang:platform> 
110 ····<cpe-lang:platform·id="wifi-iface"> 
111 ······<cpe-lang:logical-test·operator="AND"·negate="false">105 ······<cpe-lang:logical-test·operator="AND"·negate="false">
112 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_wifi_interface:def:1"/>106 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>
113 ······</cpe-lang:logical-test>107 ······</cpe-lang:logical-test>
114 ····</cpe-lang:platform>108 ····</cpe-lang:platform>
115 ····<cpe-lang:platform·id="package_rsyslog">109 ····<cpe-lang:platform·id="package_chrony">
116 ······<cpe-lang:logical-test·operator="AND"·negate="false">110 ······<cpe-lang:logical-test·operator="AND"·negate="false">
117 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>111 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
118 ······</cpe-lang:logical-test>112 ······</cpe-lang:logical-test>
119 ····</cpe-lang:platform>113 ····</cpe-lang:platform>
120 ····<cpe-lang:platform·id="package_nftables_and_service_disabled_firewalld">114 ····<cpe-lang:platform·id="package_nftables_and_service_disabled_firewalld_and_service_disabled_ufw">
121 ······<cpe-lang:logical-test·operator="AND"·negate="false">115 ······<cpe-lang:logical-test·operator="AND"·negate="false">
122 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>116 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
123 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_firewalld:def:1"/>117 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_firewalld:def:1"/>
 118 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_ufw:def:1"/>
124 ······</cpe-lang:logical-test>119 ······</cpe-lang:logical-test>
125 ····</cpe-lang:platform>120 ····</cpe-lang:platform>
126 ····<cpe-lang:platform·id="package_avahi_and_system_with_kernel">121 ····<cpe-lang:platform·id="package_firewalld">
127 ······<cpe-lang:logical-test·operator="AND"·negate="false">122 ······<cpe-lang:logical-test·operator="AND"·negate="false">
128 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_avahi:def:1"/>123 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>
129 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
130 ······</cpe-lang:logical-test>124 ······</cpe-lang:logical-test>
131 ····</cpe-lang:platform>125 ····</cpe-lang:platform>
132 ····<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">126 ····<cpe-lang:platform·id="not_bootc_and_not_container">
133 ······<cpe-lang:logical-test·operator="AND"·negate="false">127 ······<cpe-lang:logical-test·operator="AND"·negate="false">
134 ········<cpe-lang:logical-test·operator="AND"·negate="true">128 ········<cpe-lang:logical-test·operator="AND"·negate="true">
135 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>129 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-bootc:def:1"/>
136 ········</cpe-lang:logical-test>130 ········</cpe-lang:logical-test>
137 ········<cpe-lang:logical-test·operator="AND"·negate="true">131 ········<cpe-lang:logical-test·operator="AND"·negate="true">
138 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>132 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_container:def:1"/>
139 ········</cpe-lang:logical-test>133 ········</cpe-lang:logical-test>
 134 ······</cpe-lang:logical-test>
 135 ····</cpe-lang:platform>
 136 ····<cpe-lang:platform·id="package_iptables_and_service_disabled_firewalld_and_system_with_kernel">
 137 ······<cpe-lang:logical-test·operator="AND"·negate="false">
140 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>138 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
 139 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_firewalld:def:1"/>
 140 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
141 ······</cpe-lang:logical-test>141 ······</cpe-lang:logical-test>
142 ····</cpe-lang:platform>142 ····</cpe-lang:platform>
143 ····<cpe-lang:platform·id="package_firewalld">143 ····<cpe-lang:platform·id="package_pam">
144 ······<cpe-lang:logical-test·operator="AND"·negate="false">144 ······<cpe-lang:logical-test·operator="AND"·negate="false">
145 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>145 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>
146 ······</cpe-lang:logical-test>146 ······</cpe-lang:logical-test>
147 ····</cpe-lang:platform>147 ····</cpe-lang:platform>
148 ····<cpe-lang:platform·id="non-uefi">148 ····<cpe-lang:platform·id="package_sudo">
149 ······<cpe-lang:logical-test·operator="AND"·negate="false">149 ······<cpe-lang:logical-test·operator="AND"·negate="false">
150 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_non_uefi:def:1"/>150 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_sudo:def:1"/>
151 ······</cpe-lang:logical-test>151 ······</cpe-lang:logical-test>
152 ····</cpe-lang:platform>152 ····</cpe-lang:platform>
153 ····<cpe-lang:platform·id="package_audit">153 ····<cpe-lang:platform·id="system_with_kernel">
154 ······<cpe-lang:logical-test·operator="AND"·negate="false">154 ······<cpe-lang:logical-test·operator="AND"·negate="false">
155 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_audit:def:1"/>155 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
156 ······</cpe-lang:logical-test>156 ······</cpe-lang:logical-test>
157 ····</cpe-lang:platform>157 ····</cpe-lang:platform>
158 ····<cpe-lang:platform·id="package_ntp">158 ····<cpe-lang:platform·id="package_ntp">
159 ······<cpe-lang:logical-test·operator="AND"·negate="false">159 ······<cpe-lang:logical-test·operator="AND"·negate="false">
160 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_ntp:def:1"/>160 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_ntp:def:1"/>
161 ······</cpe-lang:logical-test>161 ······</cpe-lang:logical-test>
162 ····</cpe-lang:platform>162 ····</cpe-lang:platform>
163 ····<cpe-lang:platform·id="package_sudo">163 ····<cpe-lang:platform·id="package_iptables">
164 ······<cpe-lang:logical-test·operator="AND"·negate="false">164 ······<cpe-lang:logical-test·operator="AND"·negate="false">
165 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_sudo:def:1"/>165 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
166 ······</cpe-lang:logical-test>166 ······</cpe-lang:logical-test>
167 ····</cpe-lang:platform>167 ····</cpe-lang:platform>
168 ····<cpe-lang:platform·id="not_aarch64_arch">168 ····<cpe-lang:platform·id="non-uefi">
169 ······<cpe-lang:logical-test·operator="AND"·negate="true">169 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 170 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_non_uefi:def:1"/>
 171 ······</cpe-lang:logical-test>
 172 ····</cpe-lang:platform>
 173 ····<cpe-lang:platform·id="wifi-iface">
 174 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 175 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_wifi_interface:def:1"/>
 176 ······</cpe-lang:logical-test>
 177 ····</cpe-lang:platform>
 178 ····<cpe-lang:platform·id="grub2">
 179 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 180 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>
 181 ······</cpe-lang:logical-test>
 182 ····</cpe-lang:platform>
 183 ····<cpe-lang:platform·id="package_nftables_and_service_disabled_firewalld_and_system_with_kernel">
 184 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 185 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
 186 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_firewalld:def:1"/>
Max diff block lines reached; 9265/23072 bytes (40.16%) of diff not shown.
696 KB
./usr/share/xml/scap/ssg/content/ssg-opensuse-ds.xml
696 KB
./usr/share/xml/scap/ssg/content/ssg-opensuse-ds.xml
    
Offset 19, 15 lines modifiedOffset 19, 15 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-opensuse-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-opensuse-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-opensuse-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-opensuse-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-opensuse-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-opensuse-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-opensuse-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-opensuse-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-opensuse-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-opensuse-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-opensuse-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-opensuse-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-opensuse-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-opensuse-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:opensuse:leap:15.0">28 ······<cpe-dict:cpe-item·name="cpe:/o:opensuse:leap:15.0">
29 ········<cpe-dict:title·xml:lang="en-us">openSUSE·Leap·15.0</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">openSUSE·Leap·15.0</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml">oval:ssg-installed_OS_is_opensuse_leap15:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml">oval:ssg-installed_OS_is_opensuse_leap15:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ······<cpe-dict:cpe-item·name="cpe:/o:opensuse:leap:42.1">32 ······<cpe-dict:cpe-item·name="cpe:/o:opensuse:leap:42.1">
33 ········<cpe-dict:title·xml:lang="en-us">openSUSE·Leap·42.1</cpe-dict:title>33 ········<cpe-dict:title·xml:lang="en-us">openSUSE·Leap·42.1</cpe-dict:title>
Offset 39, 15 lines modifiedOffset 39, 15 lines modified
39 ······</cpe-dict:cpe-item>39 ······</cpe-dict:cpe-item>
40 ······<cpe-dict:cpe-item·name="cpe:/o:opensuse:leap:42.3">40 ······<cpe-dict:cpe-item·name="cpe:/o:opensuse:leap:42.3">
41 ········<cpe-dict:title·xml:lang="en-us">openSUSE·Leap·42.3</cpe-dict:title>41 ········<cpe-dict:title·xml:lang="en-us">openSUSE·Leap·42.3</cpe-dict:title>
42 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml">oval:ssg-installed_OS_is_opensuse_leap42:def:1</cpe-dict:check>42 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml">oval:ssg-installed_OS_is_opensuse_leap42:def:1</cpe-dict:check>
43 ······</cpe-dict:cpe-item>43 ······</cpe-dict:cpe-item>
44 ····</cpe-dict:cpe-list>44 ····</cpe-dict:cpe-list>
45 ··</ds:component>45 ··</ds:component>
46 ··<ds:component·id="scap_org.open-scap_comp_ssg-opensuse-xccdf.xml"·timestamp="2025-02-28T20:08:00">46 ··<ds:component·id="scap_org.open-scap_comp_ssg-opensuse-xccdf.xml"·timestamp="2025-03-01T22:08:00">
47 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_OPENSUSE"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">47 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_OPENSUSE"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
48 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>48 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
49 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·openSUSE</xccdf-1.2:title>49 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·openSUSE</xccdf-1.2:title>
50 ······<xccdf-1.2:description>50 ······<xccdf-1.2:description>
51 ········This·guide·presents·a·catalog·of·security-relevant51 ········This·guide·presents·a·catalog·of·security-relevant
52 configuration·settings·for·openSUSE.·It·is·a·rendering·of52 configuration·settings·for·openSUSE.·It·is·a·rendering·of
53 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)53 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 116, 165 lines modifiedOffset 116, 165 lines modified
116 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>116 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
117 ······<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>117 ······<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
118 ······<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>118 ······<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
119 ······<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>119 ······<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
120 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>120 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
121 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>121 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
122 ······<cpe-lang:platform-specification>122 ······<cpe-lang:platform-specification>
123 ········<cpe-lang:platform·id="machine">123 ········<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">
124 ··········<cpe-lang:logical-test·operator="AND"·negate="false">124 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 125 ············<cpe-lang:logical-test·operator="AND"·negate="true">
 126 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
 127 ············</cpe-lang:logical-test>
 128 ············<cpe-lang:logical-test·operator="AND"·negate="true">
 129 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
 130 ············</cpe-lang:logical-test>
125 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>131 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
126 ··········</cpe-lang:logical-test>132 ··········</cpe-lang:logical-test>
127 ········</cpe-lang:platform>133 ········</cpe-lang:platform>
128 ········<cpe-lang:platform·id="package_pam">134 ········<cpe-lang:platform·id="package_gdm">
129 ··········<cpe-lang:logical-test·operator="AND"·negate="false">135 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
130 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>136 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_gdm:def:1"/>
131 ··········</cpe-lang:logical-test>137 ··········</cpe-lang:logical-test>
132 ········</cpe-lang:platform>138 ········</cpe-lang:platform>
133 ········<cpe-lang:platform·id="package_iptables">139 ········<cpe-lang:platform·id="package_rsyslog">
134 ··········<cpe-lang:logical-test·operator="AND"·negate="false">140 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
135 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>141 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>
136 ··········</cpe-lang:logical-test>142 ··········</cpe-lang:logical-test>
137 ········</cpe-lang:platform>143 ········</cpe-lang:platform>
138 ········<cpe-lang:platform·id="package_rsyslog">144 ········<cpe-lang:platform·id="package_logrotate">
139 ··········<cpe-lang:logical-test·operator="AND"·negate="false">145 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 146 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_logrotate:def:1"/>
 147 ··········</cpe-lang:logical-test>
 148 ········</cpe-lang:platform>
 149 ········<cpe-lang:platform·id="package_chrony">
 150 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
140 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>151 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
 152 ··········</cpe-lang:logical-test>
 153 ········</cpe-lang:platform>
 154 ········<cpe-lang:platform·id="package_ufw_and_system_with_kernel">
 155 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 156 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
 157 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
 158 ··········</cpe-lang:logical-test>
 159 ········</cpe-lang:platform>
 160 ········<cpe-lang:platform·id="package_rsh-server">
 161 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 162 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_rsh-server:def:1"/>
141 ··········</cpe-lang:logical-test>163 ··········</cpe-lang:logical-test>
142 ········</cpe-lang:platform>164 ········</cpe-lang:platform>
143 ········<cpe-lang:platform·id="package_systemd">165 ········<cpe-lang:platform·id="package_systemd">
144 ··········<cpe-lang:logical-test·operator="AND"·negate="false">166 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
145 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>167 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>
146 ··········</cpe-lang:logical-test>168 ··········</cpe-lang:logical-test>
147 ········</cpe-lang:platform>169 ········</cpe-lang:platform>
148 ········<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">170 ········<cpe-lang:platform·id="not_bootc_and_not_container">
149 ··········<cpe-lang:logical-test·operator="AND"·negate="false">171 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
150 ············<cpe-lang:logical-test·operator="AND"·negate="true">172 ············<cpe-lang:logical-test·operator="AND"·negate="true">
151 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>173 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-bootc:def:1"/>
152 ············</cpe-lang:logical-test>174 ············</cpe-lang:logical-test>
153 ············<cpe-lang:logical-test·operator="AND"·negate="true">175 ············<cpe-lang:logical-test·operator="AND"·negate="true">
154 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>176 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_container:def:1"/>
155 ············</cpe-lang:logical-test>177 ············</cpe-lang:logical-test>
156 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/> 
157 ··········</cpe-lang:logical-test>178 ··········</cpe-lang:logical-test>
158 ········</cpe-lang:platform>179 ········</cpe-lang:platform>
159 ········<cpe-lang:platform·id="package_postfix">180 ········<cpe-lang:platform·id="package_iptables_and_service_disabled_firewalld_and_system_with_kernel">
160 ··········<cpe-lang:logical-test·operator="AND"·negate="false">181 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
161 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_postfix:def:1"/>182 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
 183 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_firewalld:def:1"/>
 184 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
162 ··········</cpe-lang:logical-test>185 ··········</cpe-lang:logical-test>
163 ········</cpe-lang:platform>186 ········</cpe-lang:platform>
 187 ········<cpe-lang:platform·id="aarch64_arch_or_x86_64_arch">
 188 ··········<cpe-lang:logical-test·operator="OR"·negate="false">
 189 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
 190 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/>
 191 ··········</cpe-lang:logical-test>
 192 ········</cpe-lang:platform>
164 ········<cpe-lang:platform·id="package_audit">193 ········<cpe-lang:platform·id="package_pam">
165 ··········<cpe-lang:logical-test·operator="AND"·negate="false">194 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
166 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_audit:def:1"/>195 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>
167 ··········</cpe-lang:logical-test>196 ··········</cpe-lang:logical-test>
168 ········</cpe-lang:platform>197 ········</cpe-lang:platform>
169 ········<cpe-lang:platform·id="package_logrotate">198 ········<cpe-lang:platform·id="machine">
170 ··········<cpe-lang:logical-test·operator="AND"·negate="false">199 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
171 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_logrotate:def:1"/>200 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
172 ··········</cpe-lang:logical-test>201 ··········</cpe-lang:logical-test>
173 ········</cpe-lang:platform>202 ········</cpe-lang:platform>
174 ········<cpe-lang:platform·id="package_sudo">203 ········<cpe-lang:platform·id="package_sudo">
175 ··········<cpe-lang:logical-test·operator="AND"·negate="false">204 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
176 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_sudo:def:1"/>205 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_sudo:def:1"/>
177 ··········</cpe-lang:logical-test>206 ··········</cpe-lang:logical-test>
178 ········</cpe-lang:platform>207 ········</cpe-lang:platform>
179 ········<cpe-lang:platform·id="aarch64_arch_or_x86_64_arch"> 
180 ··········<cpe-lang:logical-test·operator="OR"·negate="false"> 
Max diff block lines reached; 699036/712211 bytes (98.15%) of diff not shown.
642 KB
./usr/share/xml/scap/ssg/content/ssg-opensuse-ocil.xml
642 KB
./usr/share/xml/scap/ssg/content/ssg-opensuse-ocil.xml
Ordering differences only
    
Offset 3, 5581 lines modifiedOffset 3, 5668 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-accounts_minimum_age_login_defs_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_page_poisoning_zero_ocil:questionnaire:1">
 11 ······<ocil:title>Use·zero·for·poisoning·instead·of·debugging·value</ocil:title>
11 ······<ocil:title>Set·Password·Minimum·Age</ocil:title> 
12 ······<ocil:actions> 
13 ········<ocil:test_action_ref>ocil:ssg-accounts_minimum_age_login_defs_action:testaction:1</ocil:test_action_ref> 
14 ······</ocil:actions> 
15 ····</ocil:questionnaire> 
16 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_mac_modification_usr_share_ocil:questionnaire:1"> 
17 ······<ocil:title>Record·Events·that·Modify·the·System's·Mandatory·Access·Controls·in·usr/share</ocil:title> 
18 ······<ocil:actions> 
19 ········<ocil:test_action_ref>ocil:ssg-audit_rules_mac_modification_usr_share_action:testaction:1</ocil:test_action_ref> 
20 ······</ocil:actions> 
21 ····</ocil:questionnaire> 
22 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_ocil:questionnaire:1"> 
23 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands</ocil:title> 
24 ······<ocil:actions>12 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-kernel_config_page_poisoning_zero_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>14 ······</ocil:actions>
27 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_binfmt_misc_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_systemmap_ocil:questionnaire:1">
29 ······<ocil:title>Disable·kernel·support·for·MISC·binaries</ocil:title>17 ······<ocil:title>Verify·Permissions·on·System.map·Files</ocil:title>
30 ······<ocil:actions>18 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-kernel_config_binfmt_misc_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-file_permissions_systemmap_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>20 ······</ocil:actions>
33 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-partition_for_var_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-no_all_squash_exports_ocil:questionnaire:1">
35 ······<ocil:title>Ensure·/var·Located·On·Separate·Partition</ocil:title>23 ······<ocil:title>Ensure·All-Squashing·Disabled·On·All·Exports</ocil:title>
36 ······<ocil:actions>24 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-partition_for_var_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-no_all_squash_exports_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>26 ······</ocil:actions>
39 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_arp_filter_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-set_ip6tables_default_rule_ocil:questionnaire:1">
41 ······<ocil:title>Configure·ARP·filtering·for·All·IPv4·Interfaces</ocil:title>29 ······<ocil:title>Set·Default·ip6tables·Policy·for·Incoming·Packets</ocil:title>
42 ······<ocil:actions>30 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_arp_filter_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-set_ip6tables_default_rule_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>32 ······</ocil:actions>
45 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-sysctl_fs_protected_hardlinks_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-sshd_enable_pubkey_auth_ocil:questionnaire:1">
47 ······<ocil:title>Enable·Kernel·Parameter·to·Enforce·DAC·on·Hardlinks</ocil:title>35 ······<ocil:title>Enable·Public·Key·Authentication</ocil:title>
48 ······<ocil:actions>36 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-sysctl_fs_protected_hardlinks_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-sshd_enable_pubkey_auth_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>38 ······</ocil:actions>
51 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-sudoers_no_command_negation_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_file_deletion_events_rename_ocil:questionnaire:1">
53 ······<ocil:title>Don't·define·allowed·commands·in·sudoers·by·means·of·exclusion</ocil:title>41 ······<ocil:title>Ensure·auditd·Collects·File·Deletion·Events·by·User·-·rename</ocil:title>
54 ······<ocil:actions>42 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-sudoers_no_command_negation_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-audit_rules_file_deletion_events_rename_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>44 ······</ocil:actions>
57 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-sysctl_kernel_panic_on_oops_ocil:questionnaire:1">46 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_ia32_emulation_ocil:questionnaire:1">
59 ······<ocil:title>Kernel·panic·on·oops</ocil:title>47 ······<ocil:title>Disable·IA32·emulation</ocil:title>
60 ······<ocil:actions>48 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-sysctl_kernel_panic_on_oops_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-kernel_config_ia32_emulation_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>50 ······</ocil:actions>
63 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-package_syslogng_installed_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_page_table_isolation_ocil:questionnaire:1">
65 ······<ocil:title>Ensure·syslog-ng·is·Installed</ocil:title>53 ······<ocil:title>Remove·the·kernel·mapping·in·user·mode</ocil:title>
66 ······<ocil:actions>54 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-package_syslogng_installed_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-kernel_config_page_table_isolation_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>56 ······</ocil:actions>
69 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-directory_permissions_var_log_audit_ocil:questionnaire:1"> 
71 ······<ocil:title>System·Audit·Logs·Must·Have·Mode·0750·or·Less·Permissive</ocil:title>58 ····<ocil:questionnaire·id="ocil:ssg-sudo_add_noexec_ocil:questionnaire:1">
 59 ······<ocil:title>Ensure·Privileged·Escalated·Commands·Cannot·Execute·Other·Commands·-·sudo·NOEXEC</ocil:title>
72 ······<ocil:actions>60 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-directory_permissions_var_log_audit_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-sudo_add_noexec_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>62 ······</ocil:actions>
75 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-auditd_audispd_syslog_plugin_activated_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_space_left_action_ocil:questionnaire:1">
77 ······<ocil:title>Configure·auditd·to·use·audispd's·syslog·plugin</ocil:title>65 ······<ocil:title>Configure·auditd·space_left·Action·on·Low·Disk·Space</ocil:title>
78 ······<ocil:actions>66 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-auditd_audispd_syslog_plugin_activated_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-auditd_data_retention_space_left_action_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>68 ······</ocil:actions>
81 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-file_groupownership_audit_configuration_ocil:questionnaire:1"> 
83 ······<ocil:title>Audit·Configuration·Files·Must·Be·Owned·By·Group·root</ocil:title>70 ····<ocil:questionnaire·id="ocil:ssg-service_syslogng_enabled_ocil:questionnaire:1">
 71 ······<ocil:title>Enable·syslog-ng·Service</ocil:title>
84 ······<ocil:actions>72 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-file_groupownership_audit_configuration_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-service_syslogng_enabled_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>74 ······</ocil:actions>
87 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_debug_fs_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-display_login_attempts_ocil:questionnaire:1">
89 ······<ocil:title>Disable·kernel·debugfs</ocil:title>77 ······<ocil:title>Ensure·PAM·Displays·Last·Logon/Access·Notification</ocil:title>
90 ······<ocil:actions>78 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-kernel_config_debug_fs_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-display_login_attempts_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>80 ······</ocil:actions>
93 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-file_owner_backup_etc_gshadow_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-disallow_bypass_password_sudo_ocil:questionnaire:1">
95 ······<ocil:title>Verify·User·Who·Owns·Backup·gshadow·File</ocil:title>83 ······<ocil:title>Disallow·Configuration·to·Bypass·Password·Requirements·for·Privilege·Escalation</ocil:title>
96 ······<ocil:actions>84 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-file_owner_backup_etc_gshadow_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-disallow_bypass_password_sudo_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>86 ······</ocil:actions>
99 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_time_settimeofday_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-accounts_no_uid_except_zero_ocil:questionnaire:1">
101 ······<ocil:title>Record·attempts·to·alter·time·through·settimeofday</ocil:title>89 ······<ocil:title>Verify·Only·Root·Has·UID·0</ocil:title>
102 ······<ocil:actions>90 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-audit_rules_time_settimeofday_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-accounts_no_uid_except_zero_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>92 ······</ocil:actions>
105 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-sshd_set_keepalive_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-sshd_set_loglevel_verbose_ocil:questionnaire:1">
107 ······<ocil:title>Set·SSH·Client·Alive·Count·Max</ocil:title>95 ······<ocil:title>Set·SSH·Daemon·LogLevel·to·VERBOSE</ocil:title>
108 ······<ocil:actions>96 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-sshd_set_keepalive_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-sshd_set_loglevel_verbose_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>98 ······</ocil:actions>
111 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_gshadow_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-kernel_module_ipv6_option_disabled_ocil:questionnaire:1">
113 ······<ocil:title>Verify·Permissions·on·gshadow·File</ocil:title>101 ······<ocil:title>Disable·IPv6·Networking·Support·Automatic·Loading</ocil:title>
114 ······<ocil:actions>102 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-file_permissions_etc_gshadow_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-kernel_module_ipv6_option_disabled_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>104 ······</ocil:actions>
117 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-sudo_add_requiretty_ocil:questionnaire:1">106 ····<ocil:questionnaire·id="ocil:ssg-package_syslogng_installed_ocil:questionnaire:1">
119 ······<ocil:title>Ensure·Only·Users·Logged·In·To·Real·tty·Can·Execute·Sudo·-·sudo·requiretty</ocil:title>107 ······<ocil:title>Ensure·syslog-ng·is·Installed</ocil:title>
120 ······<ocil:actions>108 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-sudo_add_requiretty_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-package_syslogng_installed_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>110 ······</ocil:actions>
123 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
124 ····<ocil:questionnaire·id="ocil:ssg-package_logrotate_installed_ocil:questionnaire:1">112 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_arp_ignore_ocil:questionnaire:1">
125 ······<ocil:title>Ensure·logrotate·is·Installed</ocil:title>113 ······<ocil:title>Configure·Response·Mode·of·ARP·Requests·for·All·IPv4·Interfaces</ocil:title>
126 ······<ocil:actions>114 ······<ocil:actions>
Max diff block lines reached; 644951/657378 bytes (98.11%) of diff not shown.
19.0 KB
./usr/share/xml/scap/ssg/content/ssg-opensuse-xccdf.xml
18.9 KB
./usr/share/xml/scap/ssg/content/ssg-opensuse-xccdf.xml
Ordering differences only
    
Offset 71, 165 lines modifiedOffset 71, 165 lines modified
71 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>71 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
72 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>72 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
73 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>73 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
74 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>74 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
75 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>75 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
77 ··<cpe-lang:platform-specification>77 ··<cpe-lang:platform-specification>
78 ····<cpe-lang:platform·id="machine">78 ····<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">
79 ······<cpe-lang:logical-test·operator="AND"·negate="false">79 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 80 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 81 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
 82 ········</cpe-lang:logical-test>
 83 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 84 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
 85 ········</cpe-lang:logical-test>
80 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>86 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
81 ······</cpe-lang:logical-test>87 ······</cpe-lang:logical-test>
82 ····</cpe-lang:platform>88 ····</cpe-lang:platform>
83 ····<cpe-lang:platform·id="package_pam">89 ····<cpe-lang:platform·id="package_gdm">
84 ······<cpe-lang:logical-test·operator="AND"·negate="false">90 ······<cpe-lang:logical-test·operator="AND"·negate="false">
85 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>91 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_gdm:def:1"/>
86 ······</cpe-lang:logical-test>92 ······</cpe-lang:logical-test>
87 ····</cpe-lang:platform>93 ····</cpe-lang:platform>
88 ····<cpe-lang:platform·id="package_iptables">94 ····<cpe-lang:platform·id="package_rsyslog">
89 ······<cpe-lang:logical-test·operator="AND"·negate="false">95 ······<cpe-lang:logical-test·operator="AND"·negate="false">
90 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>96 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>
91 ······</cpe-lang:logical-test>97 ······</cpe-lang:logical-test>
92 ····</cpe-lang:platform>98 ····</cpe-lang:platform>
93 ····<cpe-lang:platform·id="package_rsyslog">99 ····<cpe-lang:platform·id="package_logrotate">
94 ······<cpe-lang:logical-test·operator="AND"·negate="false">100 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 101 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_logrotate:def:1"/>
 102 ······</cpe-lang:logical-test>
 103 ····</cpe-lang:platform>
 104 ····<cpe-lang:platform·id="package_chrony">
 105 ······<cpe-lang:logical-test·operator="AND"·negate="false">
95 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>106 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
 107 ······</cpe-lang:logical-test>
 108 ····</cpe-lang:platform>
 109 ····<cpe-lang:platform·id="package_ufw_and_system_with_kernel">
 110 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 111 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
 112 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
 113 ······</cpe-lang:logical-test>
 114 ····</cpe-lang:platform>
 115 ····<cpe-lang:platform·id="package_rsh-server">
 116 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 117 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_rsh-server:def:1"/>
96 ······</cpe-lang:logical-test>118 ······</cpe-lang:logical-test>
97 ····</cpe-lang:platform>119 ····</cpe-lang:platform>
98 ····<cpe-lang:platform·id="package_systemd">120 ····<cpe-lang:platform·id="package_systemd">
99 ······<cpe-lang:logical-test·operator="AND"·negate="false">121 ······<cpe-lang:logical-test·operator="AND"·negate="false">
100 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>122 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>
101 ······</cpe-lang:logical-test>123 ······</cpe-lang:logical-test>
102 ····</cpe-lang:platform>124 ····</cpe-lang:platform>
103 ····<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">125 ····<cpe-lang:platform·id="not_bootc_and_not_container">
104 ······<cpe-lang:logical-test·operator="AND"·negate="false">126 ······<cpe-lang:logical-test·operator="AND"·negate="false">
105 ········<cpe-lang:logical-test·operator="AND"·negate="true">127 ········<cpe-lang:logical-test·operator="AND"·negate="true">
106 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>128 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-bootc:def:1"/>
107 ········</cpe-lang:logical-test>129 ········</cpe-lang:logical-test>
108 ········<cpe-lang:logical-test·operator="AND"·negate="true">130 ········<cpe-lang:logical-test·operator="AND"·negate="true">
109 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>131 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_container:def:1"/>
110 ········</cpe-lang:logical-test>132 ········</cpe-lang:logical-test>
111 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/> 
112 ······</cpe-lang:logical-test>133 ······</cpe-lang:logical-test>
113 ····</cpe-lang:platform>134 ····</cpe-lang:platform>
114 ····<cpe-lang:platform·id="package_postfix">135 ····<cpe-lang:platform·id="package_iptables_and_service_disabled_firewalld_and_system_with_kernel">
115 ······<cpe-lang:logical-test·operator="AND"·negate="false">136 ······<cpe-lang:logical-test·operator="AND"·negate="false">
116 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_postfix:def:1"/>137 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
 138 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_firewalld:def:1"/>
 139 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
117 ······</cpe-lang:logical-test>140 ······</cpe-lang:logical-test>
118 ····</cpe-lang:platform>141 ····</cpe-lang:platform>
 142 ····<cpe-lang:platform·id="aarch64_arch_or_x86_64_arch">
 143 ······<cpe-lang:logical-test·operator="OR"·negate="false">
 144 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
 145 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/>
 146 ······</cpe-lang:logical-test>
 147 ····</cpe-lang:platform>
119 ····<cpe-lang:platform·id="package_audit">148 ····<cpe-lang:platform·id="package_pam">
120 ······<cpe-lang:logical-test·operator="AND"·negate="false">149 ······<cpe-lang:logical-test·operator="AND"·negate="false">
121 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_audit:def:1"/>150 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>
122 ······</cpe-lang:logical-test>151 ······</cpe-lang:logical-test>
123 ····</cpe-lang:platform>152 ····</cpe-lang:platform>
124 ····<cpe-lang:platform·id="package_logrotate">153 ····<cpe-lang:platform·id="machine">
125 ······<cpe-lang:logical-test·operator="AND"·negate="false">154 ······<cpe-lang:logical-test·operator="AND"·negate="false">
126 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_logrotate:def:1"/>155 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
127 ······</cpe-lang:logical-test>156 ······</cpe-lang:logical-test>
128 ····</cpe-lang:platform>157 ····</cpe-lang:platform>
129 ····<cpe-lang:platform·id="package_sudo">158 ····<cpe-lang:platform·id="package_sudo">
130 ······<cpe-lang:logical-test·operator="AND"·negate="false">159 ······<cpe-lang:logical-test·operator="AND"·negate="false">
131 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_sudo:def:1"/>160 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_sudo:def:1"/>
132 ······</cpe-lang:logical-test>161 ······</cpe-lang:logical-test>
133 ····</cpe-lang:platform>162 ····</cpe-lang:platform>
 163 ····<cpe-lang:platform·id="system_with_kernel">
134 ····<cpe-lang:platform·id="aarch64_arch_or_x86_64_arch"> 
135 ······<cpe-lang:logical-test·operator="OR"·negate="false"> 
136 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/> 
137 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/> 
138 ······</cpe-lang:logical-test> 
139 ····</cpe-lang:platform> 
140 ····<cpe-lang:platform·id="x86_64_arch"> 
141 ······<cpe-lang:logical-test·operator="AND"·negate="false">164 ······<cpe-lang:logical-test·operator="AND"·negate="false">
142 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/>165 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
143 ······</cpe-lang:logical-test>166 ······</cpe-lang:logical-test>
144 ····</cpe-lang:platform>167 ····</cpe-lang:platform>
145 ····<cpe-lang:platform·id="not_aarch64_arch_and_not_s390x_arch">168 ····<cpe-lang:platform·id="not_aarch64_arch_and_not_s390x_arch">
146 ······<cpe-lang:logical-test·operator="AND"·negate="false">169 ······<cpe-lang:logical-test·operator="AND"·negate="false">
147 ········<cpe-lang:logical-test·operator="AND"·negate="true">170 ········<cpe-lang:logical-test·operator="AND"·negate="true">
148 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>171 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
149 ········</cpe-lang:logical-test>172 ········</cpe-lang:logical-test>
150 ········<cpe-lang:logical-test·operator="AND"·negate="true">173 ········<cpe-lang:logical-test·operator="AND"·negate="true">
151 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_s390x:def:1"/>174 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_s390x:def:1"/>
152 ········</cpe-lang:logical-test>175 ········</cpe-lang:logical-test>
153 ······</cpe-lang:logical-test>176 ······</cpe-lang:logical-test>
154 ····</cpe-lang:platform>177 ····</cpe-lang:platform>
155 ····<cpe-lang:platform·id="not_aarch64_arch">178 ····<cpe-lang:platform·id="package_postfix">
156 ······<cpe-lang:logical-test·operator="AND"·negate="true">179 ······<cpe-lang:logical-test·operator="AND"·negate="false">
157 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>180 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_postfix:def:1"/>
158 ······</cpe-lang:logical-test>181 ······</cpe-lang:logical-test>
159 ····</cpe-lang:platform>182 ····</cpe-lang:platform>
160 ····<cpe-lang:platform·id="package_ufw_and_system_with_kernel">183 ····<cpe-lang:platform·id="package_iptables">
161 ······<cpe-lang:logical-test·operator="AND"·negate="false">184 ······<cpe-lang:logical-test·operator="AND"·negate="false">
162 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>185 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
163 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
164 ······</cpe-lang:logical-test>186 ······</cpe-lang:logical-test>
165 ····</cpe-lang:platform>187 ····</cpe-lang:platform>
166 ····<cpe-lang:platform·id="grub2_and_system_with_kernel">188 ····<cpe-lang:platform·id="aarch64_arch">
Max diff block lines reached; 6395/19208 bytes (33.29%) of diff not shown.
1.67 MB
./usr/share/xml/scap/ssg/content/ssg-rhcos4-ds.xml
1.67 MB
./usr/share/xml/scap/ssg/content/ssg-rhcos4-ds.xml
    
Offset 19, 23 lines modifiedOffset 19, 23 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhcos4-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhcos4-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhcos4-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhcos4-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhcos4-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhcos4-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhcos4-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhcos4-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhcos4-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhcos4-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhcos4-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhcos4-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhcos4-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhcos4-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux_coreos:4">28 ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux_coreos:4">
29 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Enterprise·Linux·CoreOS·4</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Enterprise·Linux·CoreOS·4</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml">oval:ssg-installed_OS_is_rhcos4:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml">oval:ssg-installed_OS_is_rhcos4:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ····</cpe-dict:cpe-list>32 ····</cpe-dict:cpe-list>
33 ··</ds:component>33 ··</ds:component>
34 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhcos4-xccdf.xml"·timestamp="2025-02-28T20:08:00">34 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhcos4-xccdf.xml"·timestamp="2025-03-01T22:08:00">
35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_RHCOS-4"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_RHCOS-4"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Red·Hat·Enterprise·Linux·CoreOS·4</xccdf-1.2:title>37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Red·Hat·Enterprise·Linux·CoreOS·4</xccdf-1.2:title>
38 ······<xccdf-1.2:description>38 ······<xccdf-1.2:description>
39 ········This·guide·presents·a·catalog·of·security-relevant39 ········This·guide·presents·a·catalog·of·security-relevant
40 configuration·settings·for·Red·Hat·Enterprise·Linux·CoreOS·4.·It·is·a·rendering·of40 configuration·settings·for·Red·Hat·Enterprise·Linux·CoreOS·4.·It·is·a·rendering·of
41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 104, 353 lines modifiedOffset 104, 353 lines modified
104 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>104 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
105 ······<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>105 ······<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
106 ······<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>106 ······<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
107 ······<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>107 ······<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
108 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=container-platform">stigid</xccdf-1.2:reference>108 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=container-platform">stigid</xccdf-1.2:reference>
109 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>109 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
110 ······<cpe-lang:platform-specification>110 ······<cpe-lang:platform-specification>
 111 ········<cpe-lang:platform·id="not_aarch64_arch_and_not_ppc64le_arch_and_system_with_kernel">
111 ········<cpe-lang:platform·id="not_bootc"> 
112 ··········<cpe-lang:logical-test·operator="AND"·negate="true"> 
113 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-bootc:def:1"/> 
114 ··········</cpe-lang:logical-test> 
115 ········</cpe-lang:platform> 
116 ········<cpe-lang:platform·id="machine"> 
117 ··········<cpe-lang:logical-test·operator="AND"·negate="false">112 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 113 ············<cpe-lang:logical-test·operator="AND"·negate="true">
 114 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
 115 ············</cpe-lang:logical-test>
 116 ············<cpe-lang:logical-test·operator="AND"·negate="true">
 117 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_ppc64le:def:1"/>
 118 ············</cpe-lang:logical-test>
118 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>119 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
119 ··········</cpe-lang:logical-test>120 ··········</cpe-lang:logical-test>
120 ········</cpe-lang:platform>121 ········</cpe-lang:platform>
121 ········<cpe-lang:platform·id="package_pam">122 ········<cpe-lang:platform·id="package_polkit">
122 ··········<cpe-lang:logical-test·operator="AND"·negate="false">123 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
123 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>124 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_polkit:def:1"/>
124 ··········</cpe-lang:logical-test>125 ··········</cpe-lang:logical-test>
125 ········</cpe-lang:platform>126 ········</cpe-lang:platform>
126 ········<cpe-lang:platform·id="rhcos4-rhel9">127 ········<cpe-lang:platform·id="mount_var-tmp">
127 ··········<cpe-lang:logical-test·operator="AND"·negate="false">128 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
128 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-installed_OS_is_rhcos4_rhel9:def:1"/>129 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-tmp:def:1"/>
129 ··········</cpe-lang:logical-test>130 ··········</cpe-lang:logical-test>
130 ········</cpe-lang:platform>131 ········</cpe-lang:platform>
131 ········<cpe-lang:platform·id="package_autofs_and_system_with_kernel">132 ········<cpe-lang:platform·id="package_autofs_and_system_with_kernel">
132 ··········<cpe-lang:logical-test·operator="AND"·negate="false">133 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
133 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>134 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>
134 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>135 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
135 ··········</cpe-lang:logical-test>136 ··········</cpe-lang:logical-test>
136 ········</cpe-lang:platform>137 ········</cpe-lang:platform>
137 ········<cpe-lang:platform·id="mount_tmp">138 ········<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">
138 ··········<cpe-lang:logical-test·operator="AND"·negate="false">139 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 140 ············<cpe-lang:logical-test·operator="AND"·negate="true">
 141 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
 142 ············</cpe-lang:logical-test>
 143 ············<cpe-lang:logical-test·operator="AND"·negate="true">
139 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_tmp:def:1"/>144 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
 145 ············</cpe-lang:logical-test>
 146 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
140 ··········</cpe-lang:logical-test>147 ··········</cpe-lang:logical-test>
141 ········</cpe-lang:platform>148 ········</cpe-lang:platform>
142 ········<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">149 ········<cpe-lang:platform·id="ipv6_enabled">
143 ··········<cpe-lang:logical-test·operator="AND"·negate="false">150 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
144 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>151 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-ipv6_enabled:def:1"/>
145 ··········</cpe-lang:logical-test>152 ··········</cpe-lang:logical-test>
146 ········</cpe-lang:platform>153 ········</cpe-lang:platform>
147 ········<cpe-lang:platform·id="mount_var-log">154 ········<cpe-lang:platform·id="package_gdm">
148 ··········<cpe-lang:logical-test·operator="AND"·negate="false">155 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
149 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-log:def:1"/>156 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_gdm:def:1"/>
150 ··········</cpe-lang:logical-test>157 ··········</cpe-lang:logical-test>
151 ········</cpe-lang:platform>158 ········</cpe-lang:platform>
152 ········<cpe-lang:platform·id="uefi">159 ········<cpe-lang:platform·id="package_rsyslog">
153 ··········<cpe-lang:logical-test·operator="AND"·negate="false">160 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
154 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>161 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>
155 ··········</cpe-lang:logical-test>162 ··········</cpe-lang:logical-test>
156 ········</cpe-lang:platform>163 ········</cpe-lang:platform>
157 ········<cpe-lang:platform·id="package_bash">164 ········<cpe-lang:platform·id="not_osbuild_and_system_with_kernel">
158 ··········<cpe-lang:logical-test·operator="AND"·negate="false">165 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 166 ············<cpe-lang:logical-test·operator="AND"·negate="true">
 167 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_osbuild:def:1"/>
 168 ············</cpe-lang:logical-test>
159 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>169 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
160 ··········</cpe-lang:logical-test>170 ··········</cpe-lang:logical-test>
161 ········</cpe-lang:platform>171 ········</cpe-lang:platform>
162 ········<cpe-lang:platform·id="package_iptables">172 ········<cpe-lang:platform·id="package_chrony_or_package_ntp">
163 ··········<cpe-lang:logical-test·operator="AND"·negate="false">173 ··········<cpe-lang:logical-test·operator="OR"·negate="false">
 174 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
164 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>175 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_ntp:def:1"/>
165 ··········</cpe-lang:logical-test>176 ··········</cpe-lang:logical-test>
166 ········</cpe-lang:platform>177 ········</cpe-lang:platform>
167 ········<cpe-lang:platform·id="krb5_server_older_than_1_17-18_and_krb5_workstation_older_than_1_17-18">178 ········<cpe-lang:platform·id="package_bash">
168 ··········<cpe-lang:logical-test·operator="AND"·negate="false">179 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
169 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-krb5_server_older_than_1_17_18:def:1"/>180 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>
170 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-krb5_workstation_older_than_1_17_18:def:1"/> 
171 ··········</cpe-lang:logical-test>181 ··········</cpe-lang:logical-test>
172 ········</cpe-lang:platform>182 ········</cpe-lang:platform>
173 ········<cpe-lang:platform·id="grub2">183 ········<cpe-lang:platform·id="uefi">
174 ··········<cpe-lang:logical-test·operator="AND"·negate="false">184 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
175 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>185 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>
176 ··········</cpe-lang:logical-test>186 ··········</cpe-lang:logical-test>
177 ········</cpe-lang:platform>187 ········</cpe-lang:platform>
178 ········<cpe-lang:platform·id="package_sssd">188 ········<cpe-lang:platform·id="package_logrotate">
179 ··········<cpe-lang:logical-test·operator="AND"·negate="false">189 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
180 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_sssd:def:1"/>190 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_logrotate:def:1"/>
181 ··········</cpe-lang:logical-test>191 ··········</cpe-lang:logical-test>
182 ········</cpe-lang:platform>192 ········</cpe-lang:platform>
183 ········<cpe-lang:platform·id="wifi-iface">193 ········<cpe-lang:platform·id="package_chrony">
184 ··········<cpe-lang:logical-test·operator="AND"·negate="false">194 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
185 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_wifi_interface:def:1"/>195 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
186 ··········</cpe-lang:logical-test>196 ··········</cpe-lang:logical-test>
187 ········</cpe-lang:platform>197 ········</cpe-lang:platform>
188 ········<cpe-lang:platform·id="package_rsyslog">198 ········<cpe-lang:platform·id="package_sssd">
189 ··········<cpe-lang:logical-test·operator="AND"·negate="false">199 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
Max diff block lines reached; 1737864/1751791 bytes (99.20%) of diff not shown.
1.55 MB
./usr/share/xml/scap/ssg/content/ssg-rhcos4-ocil.xml
1.55 MB
./usr/share/xml/scap/ssg/content/ssg-rhcos4-ocil.xml
Ordering differences only
    
Offset 3, 6103 lines modifiedOffset 3, 6103 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_openat_o_trunc_write_ocil:questionnaire:1"> 
11 ······<ocil:title>Record·Unsuccessful·Modification·Attempts·to·Files·-·openat·O_TRUNC_WRITE</ocil:title>10 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_retpoline_ocil:questionnaire:1">
 11 ······<ocil:title>Avoid·speculative·indirect·branches·in·kernel</ocil:title>
12 ······<ocil:actions>12 ······<ocil:actions>
13 ········<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_openat_o_trunc_write_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-kernel_config_retpoline_action:testaction:1</ocil:test_action_ref>
14 ······</ocil:actions>14 ······</ocil:actions>
15 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
16 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_all_accept_redirects_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_shared_media_ocil:questionnaire:1">
17 ······<ocil:title>Disable·Accepting·ICMP·Redirects·for·All·IPv6·Interfaces</ocil:title>17 ······<ocil:title>Configure·Sending·and·Accepting·Shared·Media·Redirects·for·All·IPv4·Interfaces</ocil:title>
18 ······<ocil:actions>18 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_all_accept_redirects_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_shared_media_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>20 ······</ocil:actions>
21 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_login_events_faillock_ocil:questionnaire:1"> 
23 ······<ocil:title>Record·Attempts·to·Alter·Logon·and·Logout·Events·-·faillock</ocil:title>22 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_ia32_emulation_ocil:questionnaire:1">
 23 ······<ocil:title>Disable·IA32·emulation</ocil:title>
24 ······<ocil:actions>24 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-audit_rules_login_events_faillock_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-kernel_config_ia32_emulation_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>26 ······</ocil:actions>
27 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_sudoedit_ocil:questionnaire:1"> 
29 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·sudoedit</ocil:title>28 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_default_mmap_min_addr_ocil:questionnaire:1">
 29 ······<ocil:title>Configure·Low·Address·Space·To·Protect·From·User·Allocation</ocil:title>
30 ······<ocil:actions>30 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_sudoedit_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-kernel_config_default_mmap_min_addr_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>32 ······</ocil:actions>
33 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-directory_owner_etc_sudoersd_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-mount_option_dev_shm_nodev_ocil:questionnaire:1">
35 ······<ocil:title>Verify·User·Who·Owns·/etc/sudoers.d·Directory</ocil:title>35 ······<ocil:title>Add·nodev·Option·to·/dev/shm</ocil:title>
36 ······<ocil:actions>36 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-directory_owner_etc_sudoersd_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-mount_option_dev_shm_nodev_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>38 ······</ocil:actions>
39 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-mount_option_boot_nosuid_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_compat_vdso_ocil:questionnaire:1">
41 ······<ocil:title>Add·nosuid·Option·to·/boot</ocil:title>41 ······<ocil:title>Disable·the·32-bit·vDSO</ocil:title>
42 ······<ocil:actions>42 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-mount_option_boot_nosuid_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-kernel_config_compat_vdso_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>44 ······</ocil:actions>
45 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_utempter_ocil:questionnaire:1"> 
47 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·utempter</ocil:title>46 ····<ocil:questionnaire·id="ocil:ssg-mount_option_nodev_removable_partitions_ocil:questionnaire:1">
 47 ······<ocil:title>Add·nodev·Option·to·Removable·Media·Partitions</ocil:title>
48 ······<ocil:actions>48 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_utempter_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-mount_option_nodev_removable_partitions_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>50 ······</ocil:actions>
51 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_usergroup_modification_shadow_ocil:questionnaire:1"> 
53 ······<ocil:title>Record·Events·that·Modify·User/Group·Information·-·/etc/shadow</ocil:title>52 ····<ocil:questionnaire·id="ocil:ssg-package_ntp_installed_ocil:questionnaire:1">
 53 ······<ocil:title>Install·the·ntp·service</ocil:title>
54 ······<ocil:actions>54 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-audit_rules_usergroup_modification_shadow_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-package_ntp_installed_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>56 ······</ocil:actions>
57 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_compression_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-systemd_tmp_mount_enabled_ocil:questionnaire:1">
59 ······<ocil:title>Disable·Compression·Or·Set·Compression·to·delayed</ocil:title>59 ······<ocil:title>Ensure·tmp.mount·Unit·Is·Enabled</ocil:title>
60 ······<ocil:actions>60 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_compression_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-systemd_tmp_mount_enabled_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>62 ······</ocil:actions>
63 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_module_sig_key_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_issue_net_ocil:questionnaire:1">
65 ······<ocil:title>Specify·module·signing·key·to·use</ocil:title>65 ······<ocil:title>Verify·permissions·on·System·Login·Banner·for·Remote·Connections</ocil:title>
66 ······<ocil:actions>66 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-kernel_config_module_sig_key_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-file_permissions_etc_issue_net_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>68 ······</ocil:actions>
69 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-sshd_enable_x11_forwarding_ocil:questionnaire:1"> 
71 ······<ocil:title>Enable·Encrypted·X11·Forwarding</ocil:title>70 ····<ocil:questionnaire·id="ocil:ssg-accounts_max_concurrent_login_sessions_ocil:questionnaire:1">
 71 ······<ocil:title>Limit·the·Number·of·Concurrent·Login·Sessions·Allowed·Per·User</ocil:title>
72 ······<ocil:actions>72 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-sshd_enable_x11_forwarding_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-accounts_max_concurrent_login_sessions_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>74 ······</ocil:actions>
75 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-package_pam_apparmor_installed_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-grub2_ipv6_disable_argument_ocil:questionnaire:1">
77 ······<ocil:title>Install·the·pam_apparmor·Package</ocil:title>77 ······<ocil:title>Ensure·IPv6·is·disabled·through·kernel·boot·parameter</ocil:title>
78 ······<ocil:actions>78 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-package_pam_apparmor_installed_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-grub2_ipv6_disable_argument_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>80 ······</ocil:actions>
81 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_hibernation_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-mount_option_boot_nodev_ocil:questionnaire:1">
83 ······<ocil:title>Disable·hibernation</ocil:title>83 ······<ocil:title>Add·nodev·Option·to·/boot</ocil:title>
84 ······<ocil:actions>84 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-kernel_config_hibernation_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-mount_option_boot_nodev_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>86 ······</ocil:actions>
87 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-file_owner_system_journal_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-file_owner_systemmap_ocil:questionnaire:1">
89 ······<ocil:title>Verify·Owner·on·the·system·journal</ocil:title>89 ······<ocil:title>Verify·User·Who·Owns·System.map·Files</ocil:title>
90 ······<ocil:actions>90 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-file_owner_system_journal_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-file_owner_systemmap_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>92 ······</ocil:actions>
93 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-auditd_audispd_network_failure_action_ocil:questionnaire:1"> 
95 ······<ocil:title>Configure·audispd's·Plugin·network_failure_action·On·Network·Failure</ocil:title>94 ····<ocil:questionnaire·id="ocil:ssg-directory_permissions_etc_nftables_ocil:questionnaire:1">
 95 ······<ocil:title>Verify·Permissions·On·/etc/nftables·Directory</ocil:title>
96 ······<ocil:actions>96 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-auditd_audispd_network_failure_action_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-directory_permissions_etc_nftables_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>98 ······</ocil:actions>
99 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-package_bind_removed_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_group_ocil:questionnaire:1">
101 ······<ocil:title>Uninstall·bind·Package</ocil:title>101 ······<ocil:title>Verify·Group·Who·Owns·group·File</ocil:title>
102 ······<ocil:actions>102 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-package_bind_removed_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_group_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>104 ······</ocil:actions>
105 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_fchmod_ocil:questionnaire:1"> 
107 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·fchmod</ocil:title>106 ····<ocil:questionnaire·id="ocil:ssg-sysctl_fs_suid_dumpable_ocil:questionnaire:1">
 107 ······<ocil:title>Disable·Core·Dumps·for·SUID·programs</ocil:title>
108 ······<ocil:actions>108 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_fchmod_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-sysctl_fs_suid_dumpable_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>110 ······</ocil:actions>
111 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-file_groupownership_system_commands_dirs_ocil:questionnaire:1">112 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_rhosts_ocil:questionnaire:1">
113 ······<ocil:title>Verify·that·system·commands·files·are·group·owned·by·root·or·a·system·account</ocil:title>113 ······<ocil:title>Disable·SSH·Support·for·.rhosts·Files</ocil:title>
114 ······<ocil:actions>114 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-file_groupownership_system_commands_dirs_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_rhosts_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>116 ······</ocil:actions>
117 ····</ocil:questionnaire>117 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_crontab_ocil:questionnaire:1">118 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_action_mail_acct_ocil:questionnaire:1">
119 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·crontab</ocil:title>119 ······<ocil:title>Configure·auditd·mail_acct·Action·on·Low·Disk·Space</ocil:title>
120 ······<ocil:actions>120 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_crontab_action:testaction:1</ocil:test_action_ref>121 ········<ocil:test_action_ref>ocil:ssg-auditd_data_retention_action_mail_acct_action:testaction:1</ocil:test_action_ref>
Max diff block lines reached; 1615564/1628202 bytes (99.22%) of diff not shown.
49.9 KB
./usr/share/xml/scap/ssg/content/ssg-rhcos4-xccdf.xml
49.8 KB
./usr/share/xml/scap/ssg/content/ssg-rhcos4-xccdf.xml
Ordering differences only
    
Offset 71, 353 lines modifiedOffset 71, 353 lines modified
71 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>71 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
72 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>72 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
73 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>73 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
74 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>74 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
75 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=container-platform">stigid</xccdf-1.2:reference>75 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=container-platform">stigid</xccdf-1.2:reference>
76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
77 ··<cpe-lang:platform-specification>77 ··<cpe-lang:platform-specification>
 78 ····<cpe-lang:platform·id="not_aarch64_arch_and_not_ppc64le_arch_and_system_with_kernel">
78 ····<cpe-lang:platform·id="not_bootc"> 
79 ······<cpe-lang:logical-test·operator="AND"·negate="true"> 
80 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-bootc:def:1"/> 
81 ······</cpe-lang:logical-test> 
82 ····</cpe-lang:platform> 
83 ····<cpe-lang:platform·id="machine"> 
84 ······<cpe-lang:logical-test·operator="AND"·negate="false">79 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 80 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 81 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
 82 ········</cpe-lang:logical-test>
 83 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 84 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_ppc64le:def:1"/>
 85 ········</cpe-lang:logical-test>
85 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>86 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
86 ······</cpe-lang:logical-test>87 ······</cpe-lang:logical-test>
87 ····</cpe-lang:platform>88 ····</cpe-lang:platform>
88 ····<cpe-lang:platform·id="package_pam">89 ····<cpe-lang:platform·id="package_polkit">
89 ······<cpe-lang:logical-test·operator="AND"·negate="false">90 ······<cpe-lang:logical-test·operator="AND"·negate="false">
90 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>91 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_polkit:def:1"/>
91 ······</cpe-lang:logical-test>92 ······</cpe-lang:logical-test>
92 ····</cpe-lang:platform>93 ····</cpe-lang:platform>
93 ····<cpe-lang:platform·id="rhcos4-rhel9">94 ····<cpe-lang:platform·id="mount_var-tmp">
94 ······<cpe-lang:logical-test·operator="AND"·negate="false">95 ······<cpe-lang:logical-test·operator="AND"·negate="false">
95 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-installed_OS_is_rhcos4_rhel9:def:1"/>96 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-tmp:def:1"/>
96 ······</cpe-lang:logical-test>97 ······</cpe-lang:logical-test>
97 ····</cpe-lang:platform>98 ····</cpe-lang:platform>
98 ····<cpe-lang:platform·id="package_autofs_and_system_with_kernel">99 ····<cpe-lang:platform·id="package_autofs_and_system_with_kernel">
99 ······<cpe-lang:logical-test·operator="AND"·negate="false">100 ······<cpe-lang:logical-test·operator="AND"·negate="false">
100 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>101 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>
101 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>102 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
102 ······</cpe-lang:logical-test>103 ······</cpe-lang:logical-test>
103 ····</cpe-lang:platform>104 ····</cpe-lang:platform>
104 ····<cpe-lang:platform·id="mount_tmp">105 ····<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">
105 ······<cpe-lang:logical-test·operator="AND"·negate="false">106 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 107 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 108 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
 109 ········</cpe-lang:logical-test>
 110 ········<cpe-lang:logical-test·operator="AND"·negate="true">
106 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_tmp:def:1"/>111 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
 112 ········</cpe-lang:logical-test>
 113 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
107 ······</cpe-lang:logical-test>114 ······</cpe-lang:logical-test>
108 ····</cpe-lang:platform>115 ····</cpe-lang:platform>
109 ····<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">116 ····<cpe-lang:platform·id="ipv6_enabled">
110 ······<cpe-lang:logical-test·operator="AND"·negate="false">117 ······<cpe-lang:logical-test·operator="AND"·negate="false">
111 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>118 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-ipv6_enabled:def:1"/>
112 ······</cpe-lang:logical-test>119 ······</cpe-lang:logical-test>
113 ····</cpe-lang:platform>120 ····</cpe-lang:platform>
114 ····<cpe-lang:platform·id="mount_var-log">121 ····<cpe-lang:platform·id="package_gdm">
115 ······<cpe-lang:logical-test·operator="AND"·negate="false">122 ······<cpe-lang:logical-test·operator="AND"·negate="false">
116 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-log:def:1"/>123 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_gdm:def:1"/>
117 ······</cpe-lang:logical-test>124 ······</cpe-lang:logical-test>
118 ····</cpe-lang:platform>125 ····</cpe-lang:platform>
119 ····<cpe-lang:platform·id="uefi">126 ····<cpe-lang:platform·id="package_rsyslog">
120 ······<cpe-lang:logical-test·operator="AND"·negate="false">127 ······<cpe-lang:logical-test·operator="AND"·negate="false">
121 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>128 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>
122 ······</cpe-lang:logical-test>129 ······</cpe-lang:logical-test>
123 ····</cpe-lang:platform>130 ····</cpe-lang:platform>
124 ····<cpe-lang:platform·id="package_bash">131 ····<cpe-lang:platform·id="not_osbuild_and_system_with_kernel">
125 ······<cpe-lang:logical-test·operator="AND"·negate="false">132 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 133 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 134 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_osbuild:def:1"/>
 135 ········</cpe-lang:logical-test>
126 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>136 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
127 ······</cpe-lang:logical-test>137 ······</cpe-lang:logical-test>
128 ····</cpe-lang:platform>138 ····</cpe-lang:platform>
129 ····<cpe-lang:platform·id="package_iptables">139 ····<cpe-lang:platform·id="package_chrony_or_package_ntp">
130 ······<cpe-lang:logical-test·operator="AND"·negate="false">140 ······<cpe-lang:logical-test·operator="OR"·negate="false">
 141 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
131 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>142 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_ntp:def:1"/>
132 ······</cpe-lang:logical-test>143 ······</cpe-lang:logical-test>
133 ····</cpe-lang:platform>144 ····</cpe-lang:platform>
134 ····<cpe-lang:platform·id="krb5_server_older_than_1_17-18_and_krb5_workstation_older_than_1_17-18">145 ····<cpe-lang:platform·id="package_bash">
135 ······<cpe-lang:logical-test·operator="AND"·negate="false">146 ······<cpe-lang:logical-test·operator="AND"·negate="false">
136 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-krb5_server_older_than_1_17_18:def:1"/>147 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>
137 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-krb5_workstation_older_than_1_17_18:def:1"/> 
138 ······</cpe-lang:logical-test>148 ······</cpe-lang:logical-test>
139 ····</cpe-lang:platform>149 ····</cpe-lang:platform>
140 ····<cpe-lang:platform·id="grub2">150 ····<cpe-lang:platform·id="uefi">
141 ······<cpe-lang:logical-test·operator="AND"·negate="false">151 ······<cpe-lang:logical-test·operator="AND"·negate="false">
142 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>152 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>
143 ······</cpe-lang:logical-test>153 ······</cpe-lang:logical-test>
144 ····</cpe-lang:platform>154 ····</cpe-lang:platform>
145 ····<cpe-lang:platform·id="package_sssd">155 ····<cpe-lang:platform·id="package_logrotate">
146 ······<cpe-lang:logical-test·operator="AND"·negate="false">156 ······<cpe-lang:logical-test·operator="AND"·negate="false">
147 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_sssd:def:1"/>157 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_logrotate:def:1"/>
148 ······</cpe-lang:logical-test>158 ······</cpe-lang:logical-test>
149 ····</cpe-lang:platform>159 ····</cpe-lang:platform>
150 ····<cpe-lang:platform·id="wifi-iface">160 ····<cpe-lang:platform·id="package_chrony">
151 ······<cpe-lang:logical-test·operator="AND"·negate="false">161 ······<cpe-lang:logical-test·operator="AND"·negate="false">
152 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_wifi_interface:def:1"/>162 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
153 ······</cpe-lang:logical-test>163 ······</cpe-lang:logical-test>
154 ····</cpe-lang:platform>164 ····</cpe-lang:platform>
155 ····<cpe-lang:platform·id="package_rsyslog">165 ····<cpe-lang:platform·id="package_sssd">
156 ······<cpe-lang:logical-test·operator="AND"·negate="false">166 ······<cpe-lang:logical-test·operator="AND"·negate="false">
157 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>167 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_sssd:def:1"/>
158 ······</cpe-lang:logical-test>168 ······</cpe-lang:logical-test>
159 ····</cpe-lang:platform>169 ····</cpe-lang:platform>
160 ····<cpe-lang:platform·id="package_systemd">170 ····<cpe-lang:platform·id="package_ufw_and_system_with_kernel">
161 ······<cpe-lang:logical-test·operator="AND"·negate="false">171 ······<cpe-lang:logical-test·operator="AND"·negate="false">
162 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>172 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
 173 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
163 ······</cpe-lang:logical-test>174 ······</cpe-lang:logical-test>
164 ····</cpe-lang:platform>175 ····</cpe-lang:platform>
165 ····<cpe-lang:platform·id="package_polkit">176 ····<cpe-lang:platform·id="package_firewalld">
166 ······<cpe-lang:logical-test·operator="AND"·negate="false">177 ······<cpe-lang:logical-test·operator="AND"·negate="false">
167 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_polkit:def:1"/>178 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>
168 ······</cpe-lang:logical-test>179 ······</cpe-lang:logical-test>
169 ····</cpe-lang:platform>180 ····</cpe-lang:platform>
170 ····<cpe-lang:platform·id="mount_var">181 ····<cpe-lang:platform·id="package_rsh-server">
171 ······<cpe-lang:logical-test·operator="AND"·negate="false">182 ······<cpe-lang:logical-test·operator="AND"·negate="false">
172 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var:def:1"/>183 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_rsh-server:def:1"/>
173 ······</cpe-lang:logical-test>184 ······</cpe-lang:logical-test>
174 ····</cpe-lang:platform>185 ····</cpe-lang:platform>
175 ····<cpe-lang:platform·id="machine_and_package_apparmor">186 ····<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">
176 ······<cpe-lang:logical-test·operator="AND"·negate="false">187 ······<cpe-lang:logical-test·operator="AND"·negate="false">
177 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/> 
178 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_apparmor:def:1"/>188 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>
179 ······</cpe-lang:logical-test>189 ······</cpe-lang:logical-test>
Max diff block lines reached; 36985/50874 bytes (72.70%) of diff not shown.
2.5 MB
./usr/share/xml/scap/ssg/content/ssg-rhel10-ds.xml
2.5 MB
./usr/share/xml/scap/ssg/content/ssg-rhel10-ds.xml
    
Offset 19, 23 lines modifiedOffset 19, 23 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel10-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel10-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel10-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel10-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel10-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel10-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel10-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel10-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel10-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel10-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel10-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel10-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel10-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel10-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux:10">28 ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux:10">
29 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Enterprise·Linux·10</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Enterprise·Linux·10</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml">oval:ssg-installed_OS_is_rhel10:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml">oval:ssg-installed_OS_is_rhel10:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ····</cpe-dict:cpe-list>32 ····</cpe-dict:cpe-list>
33 ··</ds:component>33 ··</ds:component>
34 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel10-xccdf.xml"·timestamp="2025-02-28T20:08:00">34 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel10-xccdf.xml"·timestamp="2025-03-01T22:08:00">
35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_RHEL-10"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_RHEL-10"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Red·Hat·Enterprise·Linux·10</xccdf-1.2:title>37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Red·Hat·Enterprise·Linux·10</xccdf-1.2:title>
38 ······<xccdf-1.2:description>38 ······<xccdf-1.2:description>
39 ········This·guide·presents·a·catalog·of·security-relevant39 ········This·guide·presents·a·catalog·of·security-relevant
40 configuration·settings·for·Red·Hat·Enterprise·Linux·10.·It·is·a·rendering·of40 configuration·settings·for·Red·Hat·Enterprise·Linux·10.·It·is·a·rendering·of
41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 105, 402 lines modifiedOffset 105, 402 lines modified
105 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>105 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
106 ······<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>106 ······<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
107 ······<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>107 ······<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
108 ······<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>108 ······<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
109 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>109 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
110 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>110 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
111 ······<cpe-lang:platform-specification>111 ······<cpe-lang:platform-specification>
112 ········<cpe-lang:platform·id="package_libuser">112 ········<cpe-lang:platform·id="not_aarch64_arch_and_not_ppc64le_arch_and_system_with_kernel">
113 ··········<cpe-lang:logical-test·operator="AND"·negate="false">113 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
114 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_libuser:def:1"/> 
115 ··········</cpe-lang:logical-test> 
116 ········</cpe-lang:platform> 
117 ········<cpe-lang:platform·id="not_bootc"> 
118 ··········<cpe-lang:logical-test·operator="AND"·negate="true">114 ············<cpe-lang:logical-test·operator="AND"·negate="true">
 115 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
 116 ············</cpe-lang:logical-test>
 117 ············<cpe-lang:logical-test·operator="AND"·negate="true">
 118 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_ppc64le:def:1"/>
 119 ············</cpe-lang:logical-test>
119 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-bootc:def:1"/>120 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
120 ··········</cpe-lang:logical-test>121 ··········</cpe-lang:logical-test>
121 ········</cpe-lang:platform>122 ········</cpe-lang:platform>
122 ········<cpe-lang:platform·id="machine">123 ········<cpe-lang:platform·id="package_polkit">
123 ··········<cpe-lang:logical-test·operator="AND"·negate="false">124 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
124 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>125 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_polkit:def:1"/>
125 ··········</cpe-lang:logical-test>126 ··········</cpe-lang:logical-test>
126 ········</cpe-lang:platform>127 ········</cpe-lang:platform>
127 ········<cpe-lang:platform·id="package_squid_and_system_with_kernel">128 ········<cpe-lang:platform·id="mount_var-tmp">
128 ··········<cpe-lang:logical-test·operator="AND"·negate="false">129 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
129 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_squid:def:1"/> 
130 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>130 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-tmp:def:1"/>
131 ··········</cpe-lang:logical-test>131 ··········</cpe-lang:logical-test>
132 ········</cpe-lang:platform>132 ········</cpe-lang:platform>
133 ········<cpe-lang:platform·id="package_pam">133 ········<cpe-lang:platform·id="package_networkmanager">
134 ··········<cpe-lang:logical-test·operator="AND"·negate="false">134 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
135 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>135 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_networkmanager:def:1"/>
136 ··········</cpe-lang:logical-test>136 ··········</cpe-lang:logical-test>
137 ········</cpe-lang:platform>137 ········</cpe-lang:platform>
138 ········<cpe-lang:platform·id="package_autofs_and_system_with_kernel">138 ········<cpe-lang:platform·id="package_autofs_and_system_with_kernel">
139 ··········<cpe-lang:logical-test·operator="AND"·negate="false">139 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
140 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>140 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>
141 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>141 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
142 ··········</cpe-lang:logical-test>142 ··········</cpe-lang:logical-test>
143 ········</cpe-lang:platform>143 ········</cpe-lang:platform>
144 ········<cpe-lang:platform·id="mount_tmp">144 ········<cpe-lang:platform·id="ipv6_enabled">
145 ··········<cpe-lang:logical-test·operator="AND"·negate="false">145 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
146 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_tmp:def:1"/>146 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-ipv6_enabled:def:1"/>
147 ··········</cpe-lang:logical-test>147 ··········</cpe-lang:logical-test>
148 ········</cpe-lang:platform>148 ········</cpe-lang:platform>
149 ········<cpe-lang:platform·id="package_firewalld_and_package_nftables_and_system_with_kernel">149 ········<cpe-lang:platform·id="package_gdm">
150 ··········<cpe-lang:logical-test·operator="AND"·negate="false">150 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
151 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>151 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_gdm:def:1"/>
152 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/> 
153 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
154 ··········</cpe-lang:logical-test>152 ··········</cpe-lang:logical-test>
155 ········</cpe-lang:platform>153 ········</cpe-lang:platform>
156 ········<cpe-lang:platform·id="not_s390x_arch">154 ········<cpe-lang:platform·id="package_rsyslog">
157 ··········<cpe-lang:logical-test·operator="AND"·negate="false">155 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
158 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>156 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>
159 ··········</cpe-lang:logical-test>157 ··········</cpe-lang:logical-test>
160 ········</cpe-lang:platform>158 ········</cpe-lang:platform>
161 ········<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">159 ········<cpe-lang:platform·id="not_osbuild_and_system_with_kernel">
162 ··········<cpe-lang:logical-test·operator="AND"·negate="false">160 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 161 ············<cpe-lang:logical-test·operator="AND"·negate="true">
 162 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_osbuild:def:1"/>
 163 ············</cpe-lang:logical-test>
163 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>164 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
164 ··········</cpe-lang:logical-test>165 ··········</cpe-lang:logical-test>
165 ········</cpe-lang:platform>166 ········</cpe-lang:platform>
166 ········<cpe-lang:platform·id="not_ppc64le_arch">167 ········<cpe-lang:platform·id="package_chrony_or_package_ntp">
167 ··········<cpe-lang:logical-test·operator="AND"·negate="true">168 ··········<cpe-lang:logical-test·operator="OR"·negate="false">
 169 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
168 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_ppc64le:def:1"/>170 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_ntp:def:1"/>
169 ··········</cpe-lang:logical-test>171 ··········</cpe-lang:logical-test>
170 ········</cpe-lang:platform>172 ········</cpe-lang:platform>
171 ········<cpe-lang:platform·id="mount_var-log">173 ········<cpe-lang:platform·id="package_bash">
172 ··········<cpe-lang:logical-test·operator="AND"·negate="false">174 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
173 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-log:def:1"/>175 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>
174 ··········</cpe-lang:logical-test>176 ··········</cpe-lang:logical-test>
175 ········</cpe-lang:platform>177 ········</cpe-lang:platform>
176 ········<cpe-lang:platform·id="uefi">178 ········<cpe-lang:platform·id="uefi">
177 ··········<cpe-lang:logical-test·operator="AND"·negate="false">179 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
178 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>180 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>
179 ··········</cpe-lang:logical-test>181 ··········</cpe-lang:logical-test>
180 ········</cpe-lang:platform>182 ········</cpe-lang:platform>
181 ········<cpe-lang:platform·id="package_bash">183 ········<cpe-lang:platform·id="package_logrotate">
182 ··········<cpe-lang:logical-test·operator="AND"·negate="false">184 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
183 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>185 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_logrotate:def:1"/>
184 ··········</cpe-lang:logical-test>186 ··········</cpe-lang:logical-test>
185 ········</cpe-lang:platform>187 ········</cpe-lang:platform>
186 ········<cpe-lang:platform·id="ppc64le_arch">188 ········<cpe-lang:platform·id="not_aarch64_arch_and_not_ppc64le_arch">
187 ··········<cpe-lang:logical-test·operator="AND"·negate="false">189 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 190 ············<cpe-lang:logical-test·operator="AND"·negate="true">
 191 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
 192 ············</cpe-lang:logical-test>
 193 ············<cpe-lang:logical-test·operator="AND"·negate="true">
188 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_ppc64le:def:1"/>194 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_ppc64le:def:1"/>
 195 ············</cpe-lang:logical-test>
189 ··········</cpe-lang:logical-test>196 ··········</cpe-lang:logical-test>
190 ········</cpe-lang:platform>197 ········</cpe-lang:platform>
191 ········<cpe-lang:platform·id="package_telnet-server_and_system_with_kernel">198 ········<cpe-lang:platform·id="package_chrony">
192 ··········<cpe-lang:logical-test·operator="AND"·negate="false">199 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
193 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_telnet-server:def:1"/>200 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
Max diff block lines reached; 2612276/2626423 bytes (99.46%) of diff not shown.
2.05 MB
./usr/share/xml/scap/ssg/content/ssg-rhel10-ocil.xml
2.05 MB
./usr/share/xml/scap/ssg/content/ssg-rhel10-ocil.xml
Ordering differences only
    
Offset 3, 14814 lines modifiedOffset 3, 15221 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_unix_remember_ocil:questionnaire:1"> 
11 ······<ocil:title>Limit·Password·Reuse</ocil:title>10 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_debug_fs_ocil:questionnaire:1">
 11 ······<ocil:title>Disable·kernel·debugfs</ocil:title>
12 ······<ocil:actions>12 ······<ocil:actions>
13 ········<ocil:test_action_ref>ocil:ssg-accounts_password_pam_unix_remember_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-kernel_config_debug_fs_action:testaction:1</ocil:test_action_ref>
14 ······</ocil:actions>14 ······</ocil:actions>
15 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
16 ····<ocil:questionnaire·id="ocil:ssg-mount_option_tmp_nodev_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_media_export_ocil:questionnaire:1">
17 ······<ocil:title>Add·nodev·Option·to·/tmp</ocil:title>17 ······<ocil:title>Ensure·auditd·Collects·Information·on·Exporting·to·Media·(successful)</ocil:title>
18 ······<ocil:actions>18 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-mount_option_tmp_nodev_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-audit_rules_media_export_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>20 ······</ocil:actions>
21 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_openat_ocil:questionnaire:1"> 
23 ······<ocil:title>Record·Unsuccessful·Access·Attempts·to·Files·-·openat</ocil:title>22 ····<ocil:questionnaire·id="ocil:ssg-rsyslog_encrypt_offload_defaultnetstreamdriver_ocil:questionnaire:1">
 23 ······<ocil:title>Ensure·Rsyslog·Encrypts·Off-Loaded·Audit·Records</ocil:title>
24 ······<ocil:actions>24 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_openat_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-rsyslog_encrypt_offload_defaultnetstreamdriver_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>26 ······</ocil:actions>
27 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_kernel_module_loading_finit_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_strict_module_rwx_ocil:questionnaire:1">
29 ······<ocil:title>Ensure·auditd·Collects·Information·on·Kernel·Module·Loading·and·Unloading·-·finit_module</ocil:title>29 ······<ocil:title>Make·the·module·text·and·rodata·read-only</ocil:title>
30 ······<ocil:actions>30 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-audit_rules_kernel_module_loading_finit_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-kernel_config_strict_module_rwx_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>32 ······</ocil:actions>
33 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_pwhistory_remember_password_auth_ocil:questionnaire:1"> 
35 ······<ocil:title>Limit·Password·Reuse:·password-auth</ocil:title>34 ····<ocil:questionnaire·id="ocil:ssg-accounts_umask_etc_csh_cshrc_ocil:questionnaire:1">
 35 ······<ocil:title>Ensure·the·Default·C·Shell·Umask·is·Set·Correctly</ocil:title>
36 ······<ocil:actions>36 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-accounts_password_pam_pwhistory_remember_password_auth_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-accounts_umask_etc_csh_cshrc_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>38 ······</ocil:actions>
39 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-dir_permissions_library_dirs_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-sshd_rekey_limit_ocil:questionnaire:1">
41 ······<ocil:title>Verify·that·Shared·Library·Directories·Have·Restrictive·Permissions</ocil:title>41 ······<ocil:title>Force·frequent·session·key·renegotiation</ocil:title>
42 ······<ocil:actions>42 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-dir_permissions_library_dirs_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-sshd_rekey_limit_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>44 ······</ocil:actions>
45 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-file_owner_etc_ipsec_conf_ocil:questionnaire:1">46 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_rhosts_rsa_ocil:questionnaire:1">
47 ······<ocil:title>Verify·User·Who·Owns·/etc/ipsec.conf·File</ocil:title>47 ······<ocil:title>Disable·SSH·Support·for·Rhosts·RSA·Authentication</ocil:title>
48 ······<ocil:actions>48 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-file_owner_etc_ipsec_conf_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_rhosts_rsa_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>50 ······</ocil:actions>
51 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-package_cryptsetup-luks_installed_ocil:questionnaire:1"> 
53 ······<ocil:title>Install·cryptsetup·Package</ocil:title>52 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_postdrop_ocil:questionnaire:1">
 53 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·postdrop</ocil:title>
54 ······<ocil:actions>54 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-package_cryptsetup-luks_installed_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_postdrop_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>56 ······</ocil:actions>
57 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-audit_owner_change_failed_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_chown_ocil:questionnaire:1">
59 ······<ocil:title>Configure·auditing·of·unsuccessful·ownership·changes</ocil:title>59 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·chown</ocil:title>
60 ······<ocil:actions>60 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-audit_owner_change_failed_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_chown_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>62 ······</ocil:actions>
63 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-package_openssh-clients_installed_ocil:questionnaire:1"> 
65 ······<ocil:title>Install·OpenSSH·client·software</ocil:title>64 ····<ocil:questionnaire·id="ocil:ssg-directory_groupowner_etc_selinux_ocil:questionnaire:1">
 65 ······<ocil:title>Verify·Group·Who·Owns·/etc/selinux·Directory</ocil:title>
66 ······<ocil:actions>66 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-package_openssh-clients_installed_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-directory_groupowner_etc_selinux_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>68 ······</ocil:actions>
69 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-selinux_all_devicefiles_labeled_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-selinux_confinement_of_daemons_ocil:questionnaire:1">
71 ······<ocil:title>Ensure·No·Device·Files·are·Unlabeled·by·SELinux</ocil:title>71 ······<ocil:title>Ensure·No·Daemons·are·Unconfined·by·SELinux</ocil:title>
72 ······<ocil:actions>72 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-selinux_all_devicefiles_labeled_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-selinux_confinement_of_daemons_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>74 ······</ocil:actions>
75 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-sudo_remove_nopasswd_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_set_max_life_existing_ocil:questionnaire:1">
77 ······<ocil:title>Ensure·Users·Re-Authenticate·for·Privilege·Escalation·-·sudo·NOPASSWD</ocil:title>77 ······<ocil:title>Set·Existing·Passwords·Maximum·Age</ocil:title>
78 ······<ocil:actions>78 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-sudo_remove_nopasswd_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-accounts_password_set_max_life_existing_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>80 ······</ocil:actions>
81 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-package_setroubleshoot-plugins_removed_ocil:questionnaire:1"> 
83 ······<ocil:title>Uninstall·setroubleshoot-plugins·Package</ocil:title>82 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_kernel_module_loading_query_ocil:questionnaire:1">
 83 ······<ocil:title>Ensure·auditd·Collects·Information·on·Kernel·Module·Loading·and·Unloading·-·query_module</ocil:title>
84 ······<ocil:actions>84 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-package_setroubleshoot-plugins_removed_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-audit_rules_kernel_module_loading_query_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>86 ······</ocil:actions>
87 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-partition_for_usr_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-postfix_client_configure_mail_alias_ocil:questionnaire:1">
89 ······<ocil:title>Ensure·/usr·Located·On·Separate·Partition</ocil:title>89 ······<ocil:title>Configure·System·to·Forward·All·Mail·For·The·Root·Account</ocil:title>
90 ······<ocil:actions>90 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-partition_for_usr_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-postfix_client_configure_mail_alias_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>92 ······</ocil:actions>
93 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_chown_ocil:questionnaire:1"> 
95 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·chown</ocil:title>94 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_log_martians_ocil:questionnaire:1">
 95 ······<ocil:title>Enable·Kernel·Paremeter·to·Log·Martian·Packets·on·all·IPv4·Interfaces·by·Default</ocil:title>
96 ······<ocil:actions>96 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_chown_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_log_martians_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>98 ······</ocil:actions>
99 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-sshd_set_max_auth_tries_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_accept_source_route_ocil:questionnaire:1">
101 ······<ocil:title>Set·SSH·authentication·attempt·limit</ocil:title>101 ······<ocil:title>Disable·Kernel·Parameter·for·Accepting·Source-Routed·Packets·on·IPv4·Interfaces·by·Default</ocil:title>
102 ······<ocil:actions>102 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-sshd_set_max_auth_tries_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_accept_source_route_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>104 ······</ocil:actions>
105 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_all_accept_ra_ocil:questionnaire:1">106 ····<ocil:questionnaire·id="ocil:ssg-directory_owner_etc_sudoersd_ocil:questionnaire:1">
107 ······<ocil:title>Configure·Accepting·Router·Advertisements·on·All·IPv6·Interfaces</ocil:title>107 ······<ocil:title>Verify·User·Who·Owns·/etc/sudoers.d·Directory</ocil:title>
108 ······<ocil:actions>108 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_all_accept_ra_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-directory_owner_etc_sudoersd_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>110 ······</ocil:actions>
111 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-package_fapolicyd_installed_ocil:questionnaire:1">112 ····<ocil:questionnaire·id="ocil:ssg-no_netrc_files_ocil:questionnaire:1">
113 ······<ocil:title>Install·fapolicyd·Package</ocil:title>113 ······<ocil:title>Verify·No·netrc·Files·Exist</ocil:title>
114 ······<ocil:actions>114 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-package_fapolicyd_installed_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-no_netrc_files_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>116 ······</ocil:actions>
117 ····</ocil:questionnaire>117 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-audit_delete_success_ocil:questionnaire:1">118 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_execution_setfiles_ocil:questionnaire:1">
119 ······<ocil:title>Configure·auditing·of·successful·file·deletions</ocil:title>119 ······<ocil:title>Record·Any·Attempts·to·Run·setfiles</ocil:title>
120 ······<ocil:actions>120 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-audit_delete_success_action:testaction:1</ocil:test_action_ref>121 ········<ocil:test_action_ref>ocil:ssg-audit_rules_execution_setfiles_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>122 ······</ocil:actions>
Max diff block lines reached; 2141574/2154366 bytes (99.41%) of diff not shown.
362 KB
./usr/share/xml/scap/ssg/content/ssg-rhel10-xccdf.xml
362 KB
./usr/share/xml/scap/ssg/content/ssg-rhel10-xccdf.xml
    
Offset 72, 402 lines modifiedOffset 72, 402 lines modified
72 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>72 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
73 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>73 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
74 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>74 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
75 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>75 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
77 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>77 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
78 ··<cpe-lang:platform-specification>78 ··<cpe-lang:platform-specification>
79 ····<cpe-lang:platform·id="package_libuser">79 ····<cpe-lang:platform·id="not_aarch64_arch_and_not_ppc64le_arch_and_system_with_kernel">
80 ······<cpe-lang:logical-test·operator="AND"·negate="false">80 ······<cpe-lang:logical-test·operator="AND"·negate="false">
81 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_libuser:def:1"/> 
82 ······</cpe-lang:logical-test> 
83 ····</cpe-lang:platform> 
84 ····<cpe-lang:platform·id="not_bootc"> 
85 ······<cpe-lang:logical-test·operator="AND"·negate="true">81 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 82 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
 83 ········</cpe-lang:logical-test>
 84 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 85 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_ppc64le:def:1"/>
 86 ········</cpe-lang:logical-test>
86 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-bootc:def:1"/>87 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
87 ······</cpe-lang:logical-test>88 ······</cpe-lang:logical-test>
88 ····</cpe-lang:platform>89 ····</cpe-lang:platform>
89 ····<cpe-lang:platform·id="machine">90 ····<cpe-lang:platform·id="package_polkit">
90 ······<cpe-lang:logical-test·operator="AND"·negate="false">91 ······<cpe-lang:logical-test·operator="AND"·negate="false">
91 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>92 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_polkit:def:1"/>
92 ······</cpe-lang:logical-test>93 ······</cpe-lang:logical-test>
93 ····</cpe-lang:platform>94 ····</cpe-lang:platform>
94 ····<cpe-lang:platform·id="package_squid_and_system_with_kernel">95 ····<cpe-lang:platform·id="mount_var-tmp">
95 ······<cpe-lang:logical-test·operator="AND"·negate="false">96 ······<cpe-lang:logical-test·operator="AND"·negate="false">
96 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_squid:def:1"/> 
97 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>97 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-tmp:def:1"/>
98 ······</cpe-lang:logical-test>98 ······</cpe-lang:logical-test>
99 ····</cpe-lang:platform>99 ····</cpe-lang:platform>
100 ····<cpe-lang:platform·id="package_pam">100 ····<cpe-lang:platform·id="package_networkmanager">
101 ······<cpe-lang:logical-test·operator="AND"·negate="false">101 ······<cpe-lang:logical-test·operator="AND"·negate="false">
102 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>102 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_networkmanager:def:1"/>
103 ······</cpe-lang:logical-test>103 ······</cpe-lang:logical-test>
104 ····</cpe-lang:platform>104 ····</cpe-lang:platform>
105 ····<cpe-lang:platform·id="package_autofs_and_system_with_kernel">105 ····<cpe-lang:platform·id="package_autofs_and_system_with_kernel">
106 ······<cpe-lang:logical-test·operator="AND"·negate="false">106 ······<cpe-lang:logical-test·operator="AND"·negate="false">
107 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>107 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>
108 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>108 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
109 ······</cpe-lang:logical-test>109 ······</cpe-lang:logical-test>
110 ····</cpe-lang:platform>110 ····</cpe-lang:platform>
111 ····<cpe-lang:platform·id="mount_tmp">111 ····<cpe-lang:platform·id="ipv6_enabled">
112 ······<cpe-lang:logical-test·operator="AND"·negate="false">112 ······<cpe-lang:logical-test·operator="AND"·negate="false">
113 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_tmp:def:1"/>113 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-ipv6_enabled:def:1"/>
114 ······</cpe-lang:logical-test>114 ······</cpe-lang:logical-test>
115 ····</cpe-lang:platform>115 ····</cpe-lang:platform>
116 ····<cpe-lang:platform·id="package_firewalld_and_package_nftables_and_system_with_kernel">116 ····<cpe-lang:platform·id="package_gdm">
117 ······<cpe-lang:logical-test·operator="AND"·negate="false">117 ······<cpe-lang:logical-test·operator="AND"·negate="false">
118 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>118 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_gdm:def:1"/>
119 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/> 
120 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
121 ······</cpe-lang:logical-test>119 ······</cpe-lang:logical-test>
122 ····</cpe-lang:platform>120 ····</cpe-lang:platform>
123 ····<cpe-lang:platform·id="not_s390x_arch">121 ····<cpe-lang:platform·id="package_rsyslog">
124 ······<cpe-lang:logical-test·operator="AND"·negate="false">122 ······<cpe-lang:logical-test·operator="AND"·negate="false">
125 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>123 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>
126 ······</cpe-lang:logical-test>124 ······</cpe-lang:logical-test>
127 ····</cpe-lang:platform>125 ····</cpe-lang:platform>
128 ····<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">126 ····<cpe-lang:platform·id="not_osbuild_and_system_with_kernel">
129 ······<cpe-lang:logical-test·operator="AND"·negate="false">127 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 128 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 129 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_osbuild:def:1"/>
 130 ········</cpe-lang:logical-test>
130 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>131 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
131 ······</cpe-lang:logical-test>132 ······</cpe-lang:logical-test>
132 ····</cpe-lang:platform>133 ····</cpe-lang:platform>
133 ····<cpe-lang:platform·id="not_ppc64le_arch">134 ····<cpe-lang:platform·id="package_chrony_or_package_ntp">
134 ······<cpe-lang:logical-test·operator="AND"·negate="true">135 ······<cpe-lang:logical-test·operator="OR"·negate="false">
 136 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
135 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_ppc64le:def:1"/>137 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_ntp:def:1"/>
136 ······</cpe-lang:logical-test>138 ······</cpe-lang:logical-test>
137 ····</cpe-lang:platform>139 ····</cpe-lang:platform>
138 ····<cpe-lang:platform·id="mount_var-log">140 ····<cpe-lang:platform·id="package_bash">
139 ······<cpe-lang:logical-test·operator="AND"·negate="false">141 ······<cpe-lang:logical-test·operator="AND"·negate="false">
140 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-log:def:1"/>142 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>
141 ······</cpe-lang:logical-test>143 ······</cpe-lang:logical-test>
142 ····</cpe-lang:platform>144 ····</cpe-lang:platform>
143 ····<cpe-lang:platform·id="uefi">145 ····<cpe-lang:platform·id="uefi">
144 ······<cpe-lang:logical-test·operator="AND"·negate="false">146 ······<cpe-lang:logical-test·operator="AND"·negate="false">
145 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>147 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>
146 ······</cpe-lang:logical-test>148 ······</cpe-lang:logical-test>
147 ····</cpe-lang:platform>149 ····</cpe-lang:platform>
148 ····<cpe-lang:platform·id="package_bash">150 ····<cpe-lang:platform·id="package_logrotate">
149 ······<cpe-lang:logical-test·operator="AND"·negate="false">151 ······<cpe-lang:logical-test·operator="AND"·negate="false">
150 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>152 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_logrotate:def:1"/>
151 ······</cpe-lang:logical-test>153 ······</cpe-lang:logical-test>
152 ····</cpe-lang:platform>154 ····</cpe-lang:platform>
153 ····<cpe-lang:platform·id="ppc64le_arch">155 ····<cpe-lang:platform·id="not_aarch64_arch_and_not_ppc64le_arch">
154 ······<cpe-lang:logical-test·operator="AND"·negate="false">156 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 157 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 158 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
 159 ········</cpe-lang:logical-test>
 160 ········<cpe-lang:logical-test·operator="AND"·negate="true">
155 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_ppc64le:def:1"/>161 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_ppc64le:def:1"/>
 162 ········</cpe-lang:logical-test>
156 ······</cpe-lang:logical-test>163 ······</cpe-lang:logical-test>
157 ····</cpe-lang:platform>164 ····</cpe-lang:platform>
158 ····<cpe-lang:platform·id="package_telnet-server_and_system_with_kernel">165 ····<cpe-lang:platform·id="package_chrony">
159 ······<cpe-lang:logical-test·operator="AND"·negate="false">166 ······<cpe-lang:logical-test·operator="AND"·negate="false">
160 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_telnet-server:def:1"/>167 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
161 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
162 ······</cpe-lang:logical-test>168 ······</cpe-lang:logical-test>
163 ····</cpe-lang:platform>169 ····</cpe-lang:platform>
164 ····<cpe-lang:platform·id="package_iptables">170 ····<cpe-lang:platform·id="package_sssd">
165 ······<cpe-lang:logical-test·operator="AND"·negate="false">171 ······<cpe-lang:logical-test·operator="AND"·negate="false">
166 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>172 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_sssd:def:1"/>
167 ······</cpe-lang:logical-test>173 ······</cpe-lang:logical-test>
168 ····</cpe-lang:platform>174 ····</cpe-lang:platform>
169 ····<cpe-lang:platform·id="krb5_server_older_than_1_17-18_and_krb5_workstation_older_than_1_17-18">175 ····<cpe-lang:platform·id="package_firewalld">
170 ······<cpe-lang:logical-test·operator="AND"·negate="false">176 ······<cpe-lang:logical-test·operator="AND"·negate="false">
171 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-krb5_server_older_than_1_17_18:def:1"/>177 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>
172 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-krb5_workstation_older_than_1_17_18:def:1"/> 
173 ······</cpe-lang:logical-test>178 ······</cpe-lang:logical-test>
174 ····</cpe-lang:platform>179 ····</cpe-lang:platform>
175 ····<cpe-lang:platform·id="grub2">180 ····<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">
176 ······<cpe-lang:logical-test·operator="AND"·negate="false">181 ······<cpe-lang:logical-test·operator="AND"·negate="false">
177 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>182 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>
178 ······</cpe-lang:logical-test>183 ······</cpe-lang:logical-test>
179 ····</cpe-lang:platform>184 ····</cpe-lang:platform>
180 ····<cpe-lang:platform·id="package_sssd">185 ····<cpe-lang:platform·id="mount_srv">
181 ······<cpe-lang:logical-test·operator="AND"·negate="false">186 ······<cpe-lang:logical-test·operator="AND"·negate="false">
182 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_sssd:def:1"/>187 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_srv:def:1"/>
183 ······</cpe-lang:logical-test>188 ······</cpe-lang:logical-test>
184 ····</cpe-lang:platform>189 ····</cpe-lang:platform>
Max diff block lines reached; 356050/370558 bytes (96.08%) of diff not shown.
4.0 MB
./usr/share/xml/scap/ssg/content/ssg-rhel8-ds.xml
4.0 MB
./usr/share/xml/scap/ssg/content/ssg-rhel8-ds.xml
    
Offset 19, 15 lines modifiedOffset 19, 15 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel8-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel8-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel8-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel8-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel8-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel8-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel8-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel8-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel8-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel8-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel8-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel8-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel8-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel8-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux:8">28 ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux:8">
29 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Enterprise·Linux·8</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Enterprise·Linux·8</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml">oval:ssg-installed_OS_is_rhel8:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml">oval:ssg-installed_OS_is_rhel8:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux:8.0">32 ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux:8.0">
33 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Enterprise·Linux·8.0</cpe-dict:title>33 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Enterprise·Linux·8.0</cpe-dict:title>
Offset 71, 15 lines modifiedOffset 71, 15 lines modified
71 ······</cpe-dict:cpe-item>71 ······</cpe-dict:cpe-item>
72 ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux:8.9">72 ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux:8.9">
73 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Enterprise·Linux·8.9</cpe-dict:title>73 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Enterprise·Linux·8.9</cpe-dict:title>
74 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml">oval:ssg-installed_OS_is_rhel8_9:def:1</cpe-dict:check>74 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml">oval:ssg-installed_OS_is_rhel8_9:def:1</cpe-dict:check>
75 ······</cpe-dict:cpe-item>75 ······</cpe-dict:cpe-item>
76 ····</cpe-dict:cpe-list>76 ····</cpe-dict:cpe-list>
77 ··</ds:component>77 ··</ds:component>
78 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel8-xccdf.xml"·timestamp="2025-02-28T20:08:00">78 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel8-xccdf.xml"·timestamp="2025-03-01T22:08:00">
79 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_RHEL-8"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">79 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_RHEL-8"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
80 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>80 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
81 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Red·Hat·Enterprise·Linux·8</xccdf-1.2:title>81 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Red·Hat·Enterprise·Linux·8</xccdf-1.2:title>
82 ······<xccdf-1.2:description>82 ······<xccdf-1.2:description>
83 ········This·guide·presents·a·catalog·of·security-relevant83 ········This·guide·presents·a·catalog·of·security-relevant
84 configuration·settings·for·Red·Hat·Enterprise·Linux·8.·It·is·a·rendering·of84 configuration·settings·for·Red·Hat·Enterprise·Linux·8.·It·is·a·rendering·of
85 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)85 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 149, 264 lines modifiedOffset 149, 223 lines modified
149 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>149 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
150 ······<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>150 ······<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
151 ······<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>151 ······<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
152 ······<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>152 ······<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
153 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>153 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
154 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>154 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
155 ······<cpe-lang:platform-specification>155 ······<cpe-lang:platform-specification>
 156 ········<cpe-lang:platform·id="not_aarch64_arch_and_not_ppc64le_arch_and_system_with_kernel">
156 ········<cpe-lang:platform·id="package_libuser"> 
157 ··········<cpe-lang:logical-test·operator="AND"·negate="false"> 
158 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-package_libuser:def:1"/> 
159 ··········</cpe-lang:logical-test> 
160 ········</cpe-lang:platform> 
161 ········<cpe-lang:platform·id="not_bootc"> 
162 ··········<cpe-lang:logical-test·operator="AND"·negate="true"> 
163 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-bootc:def:1"/> 
164 ··········</cpe-lang:logical-test> 
165 ········</cpe-lang:platform> 
166 ········<cpe-lang:platform·id="package_nftables_and_service_disabled_firewalld_and_system_with_kernel"> 
167 ··········<cpe-lang:logical-test·operator="AND"·negate="false">157 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 158 ············<cpe-lang:logical-test·operator="AND"·negate="true">
 159 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
 160 ············</cpe-lang:logical-test>
 161 ············<cpe-lang:logical-test·operator="AND"·negate="true">
168 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>162 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_ppc64le:def:1"/>
169 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_firewalld:def:1"/>163 ············</cpe-lang:logical-test>
170 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>164 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
171 ··········</cpe-lang:logical-test>165 ··········</cpe-lang:logical-test>
172 ········</cpe-lang:platform>166 ········</cpe-lang:platform>
173 ········<cpe-lang:platform·id="machine">167 ········<cpe-lang:platform·id="not_runtime_kernel_fips_enabled_and_system_with_kernel">
174 ··········<cpe-lang:logical-test·operator="AND"·negate="false">168 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 169 ············<cpe-lang:logical-test·operator="AND"·negate="true">
 170 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-runtime_kernel_fips_enabled:def:1"/>
 171 ············</cpe-lang:logical-test>
175 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>172 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
176 ··········</cpe-lang:logical-test>173 ··········</cpe-lang:logical-test>
177 ········</cpe-lang:platform>174 ········</cpe-lang:platform>
178 ········<cpe-lang:platform·id="package_squid_and_system_with_kernel">175 ········<cpe-lang:platform·id="package_polkit">
179 ··········<cpe-lang:logical-test·operator="AND"·negate="false">176 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
180 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-package_squid:def:1"/>177 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-package_polkit:def:1"/>
181 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
182 ··········</cpe-lang:logical-test>178 ··········</cpe-lang:logical-test>
183 ········</cpe-lang:platform>179 ········</cpe-lang:platform>
184 ········<cpe-lang:platform·id="package_pam">180 ········<cpe-lang:platform·id="mount_var-tmp">
185 ··········<cpe-lang:logical-test·operator="AND"·negate="false">181 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
186 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>182 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-tmp:def:1"/>
187 ··········</cpe-lang:logical-test>183 ··········</cpe-lang:logical-test>
188 ········</cpe-lang:platform>184 ········</cpe-lang:platform>
189 ········<cpe-lang:platform·id="package_autofs_and_system_with_kernel">185 ········<cpe-lang:platform·id="package_autofs_and_system_with_kernel">
190 ··········<cpe-lang:logical-test·operator="AND"·negate="false">186 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
191 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>187 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>
192 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>188 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
193 ··········</cpe-lang:logical-test>189 ··········</cpe-lang:logical-test>
194 ········</cpe-lang:platform>190 ········</cpe-lang:platform>
195 ········<cpe-lang:platform·id="mount_tmp">191 ········<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">
196 ··········<cpe-lang:logical-test·operator="AND"·negate="false">192 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 193 ············<cpe-lang:logical-test·operator="AND"·negate="true">
 194 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
 195 ············</cpe-lang:logical-test>
 196 ············<cpe-lang:logical-test·operator="AND"·negate="true">
197 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_tmp:def:1"/>197 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
 198 ············</cpe-lang:logical-test>
 199 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
198 ··········</cpe-lang:logical-test>200 ··········</cpe-lang:logical-test>
199 ········</cpe-lang:platform>201 ········</cpe-lang:platform>
200 ········<cpe-lang:platform·id="package_firewalld_and_package_nftables_and_system_with_kernel">202 ········<cpe-lang:platform·id="ipv6_enabled">
201 ··········<cpe-lang:logical-test·operator="AND"·negate="false">203 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
202 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/> 
203 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>204 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-ipv6_enabled:def:1"/>
204 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
205 ··········</cpe-lang:logical-test>205 ··········</cpe-lang:logical-test>
206 ········</cpe-lang:platform>206 ········</cpe-lang:platform>
207 ········<cpe-lang:platform·id="not_s390x_arch">207 ········<cpe-lang:platform·id="package_gdm">
208 ··········<cpe-lang:logical-test·operator="AND"·negate="false">208 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
209 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>209 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-package_gdm:def:1"/>
210 ··········</cpe-lang:logical-test>210 ··········</cpe-lang:logical-test>
211 ········</cpe-lang:platform>211 ········</cpe-lang:platform>
212 ········<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">212 ········<cpe-lang:platform·id="package_rsyslog">
213 ··········<cpe-lang:logical-test·operator="AND"·negate="false">213 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
214 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>214 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>
215 ··········</cpe-lang:logical-test>215 ··········</cpe-lang:logical-test>
216 ········</cpe-lang:platform>216 ········</cpe-lang:platform>
217 ········<cpe-lang:platform·id="mount_var-log">217 ········<cpe-lang:platform·id="not_osbuild_and_system_with_kernel">
218 ··········<cpe-lang:logical-test·operator="AND"·negate="false">218 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 219 ············<cpe-lang:logical-test·operator="AND"·negate="true">
219 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-log:def:1"/>220 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_osbuild:def:1"/>
 221 ············</cpe-lang:logical-test>
 222 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
220 ··········</cpe-lang:logical-test>223 ··········</cpe-lang:logical-test>
221 ········</cpe-lang:platform>224 ········</cpe-lang:platform>
222 ········<cpe-lang:platform·id="uefi">225 ········<cpe-lang:platform·id="package_chrony_or_package_ntp">
223 ··········<cpe-lang:logical-test·operator="AND"·negate="false">226 ··········<cpe-lang:logical-test·operator="OR"·negate="false">
 227 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
224 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>228 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-package_ntp:def:1"/>
225 ··········</cpe-lang:logical-test>229 ··········</cpe-lang:logical-test>
Max diff block lines reached; 4185047/4198474 bytes (99.68%) of diff not shown.
3.27 MB
./usr/share/xml/scap/ssg/content/ssg-rhel8-ocil.xml
3.27 MB
./usr/share/xml/scap/ssg/content/ssg-rhel8-ocil.xml
Ordering differences only
    
Offset 3, 10262 lines modifiedOffset 3, 10262 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-rsyslog_remote_loghost_ocil:questionnaire:1"> 
11 ······<ocil:title>Ensure·Logs·Sent·To·Remote·Host</ocil:title>10 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_unix_remember_ocil:questionnaire:1">
 11 ······<ocil:title>Limit·Password·Reuse</ocil:title>
12 ······<ocil:actions>12 ······<ocil:actions>
13 ········<ocil:test_action_ref>ocil:ssg-rsyslog_remote_loghost_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-accounts_password_pam_unix_remember_action:testaction:1</ocil:test_action_ref>
14 ······</ocil:actions>14 ······</ocil:actions>
15 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
16 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_all_autoconf_ocil:questionnaire:1"> 
17 ······<ocil:title>Configure·Auto·Configuration·on·All·IPv6·Interfaces</ocil:title>16 ····<ocil:questionnaire·id="ocil:ssg-sebool_minidlna_read_generic_user_content_ocil:questionnaire:1">
 17 ······<ocil:title>Disable·the·minidlna_read_generic_user_content·SELinux·Boolean</ocil:title>
18 ······<ocil:actions>18 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_all_autoconf_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-sebool_minidlna_read_generic_user_content_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>20 ······</ocil:actions>
21 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-sebool_httpd_execmem_ocil:questionnaire:1"> 
23 ······<ocil:title>Disable·the·httpd_execmem·SELinux·Boolean</ocil:title>22 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_default_accept_ra_pinfo_ocil:questionnaire:1">
 23 ······<ocil:title>Configure·Accepting·Prefix·Information·in·Router·Advertisements·on·All·IPv6·Interfaces·By·Default</ocil:title>
24 ······<ocil:actions>24 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-sebool_httpd_execmem_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_default_accept_ra_pinfo_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>26 ······</ocil:actions>
27 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-service_ntpdate_disabled_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-package_psacct_installed_ocil:questionnaire:1">
29 ······<ocil:title>Disable·ntpdate·Service·(ntpdate)</ocil:title>29 ······<ocil:title>Install·the·psacct·package</ocil:title>
30 ······<ocil:actions>30 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-service_ntpdate_disabled_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-package_psacct_installed_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>32 ······</ocil:actions>
33 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_debug_credentials_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-sshd_enable_pam_ocil:questionnaire:1">
35 ······<ocil:title>Enable·checks·on·credential·management</ocil:title>35 ······<ocil:title>Enable·PAM</ocil:title>
36 ······<ocil:actions>36 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-kernel_config_debug_credentials_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-sshd_enable_pam_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>38 ······</ocil:actions>
39 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-sebool_secadm_exec_content_ocil:questionnaire:1"> 
41 ······<ocil:title>Enable·the·secadm_exec_content·SELinux·Boolean</ocil:title>40 ····<ocil:questionnaire·id="ocil:ssg-package_libreport-plugin-rhtsupport_removed_ocil:questionnaire:1">
 41 ······<ocil:title>Uninstall·libreport-plugin-rhtsupport·Package</ocil:title>
42 ······<ocil:actions>42 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-sebool_secadm_exec_content_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-package_libreport-plugin-rhtsupport_removed_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>44 ······</ocil:actions>
45 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-group_unique_id_ocil:questionnaire:1">46 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_immutable_login_uids_ocil:questionnaire:1">
47 ······<ocil:title>Ensure·All·Groups·on·the·System·Have·Unique·Group·ID</ocil:title>47 ······<ocil:title>Configure·immutable·Audit·login·UIDs</ocil:title>
48 ······<ocil:actions>48 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-group_unique_id_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-audit_rules_immutable_login_uids_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>50 ······</ocil:actions>
51 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-journald_storage_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-audit_modify_failed_ocil:questionnaire:1">
53 ······<ocil:title>Ensure·journald·is·configured·to·write·log·files·to·persistent·disk</ocil:title>53 ······<ocil:title>Configure·auditing·of·unsuccessful·file·modifications</ocil:title>
54 ······<ocil:actions>54 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-journald_storage_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-audit_modify_failed_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>56 ······</ocil:actions>
57 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_default_accept_source_route_ocil:questionnaire:1"> 
59 ······<ocil:title>Disable·Kernel·Parameter·for·Accepting·Source-Routed·Packets·on·IPv6·Interfaces·by·Default</ocil:title>58 ····<ocil:questionnaire·id="ocil:ssg-sebool_httpd_can_network_memcache_ocil:questionnaire:1">
 59 ······<ocil:title>Disable·the·httpd_can_network_memcache·SELinux·Boolean</ocil:title>
60 ······<ocil:actions>60 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_default_accept_source_route_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-sebool_httpd_can_network_memcache_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>62 ······</ocil:actions>
63 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_module_sig_hash_ocil:questionnaire:1"> 
65 ······<ocil:title>Specify·the·hash·to·use·when·signing·modules</ocil:title>64 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_enforce_root_ocil:questionnaire:1">
 65 ······<ocil:title>Ensure·PAM·Enforces·Password·Requirements·-·Enforce·for·root·User</ocil:title>
66 ······<ocil:actions>66 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-kernel_config_module_sig_hash_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-accounts_password_pam_enforce_root_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>68 ······</ocil:actions>
69 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-service_iptables_enabled_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_compression_ocil:questionnaire:1">
71 ······<ocil:title>Verify·iptables·Enabled</ocil:title>71 ······<ocil:title>Disable·Compression·Or·Set·Compression·to·delayed</ocil:title>
72 ······<ocil:actions>72 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-service_iptables_enabled_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_compression_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>74 ······</ocil:actions>
75 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-mount_option_krb_sec_remote_filesystems_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_execution_setsebool_ocil:questionnaire:1">
77 ······<ocil:title>Mount·Remote·Filesystems·with·Kerberos·Security</ocil:title>77 ······<ocil:title>Record·Any·Attempts·to·Run·setsebool</ocil:title>
78 ······<ocil:actions>78 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-mount_option_krb_sec_remote_filesystems_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-audit_rules_execution_setsebool_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>80 ······</ocil:actions>
81 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-sshd_print_last_log_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_etc_passwd_open_ocil:questionnaire:1">
83 ······<ocil:title>Enable·SSH·Print·Last·Log</ocil:title>83 ······<ocil:title>Record·Events·that·Modify·User/Group·Information·via·open·syscall·-·/etc/passwd</ocil:title>
84 ······<ocil:actions>84 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-sshd_print_last_log_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-audit_rules_etc_passwd_open_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>86 ······</ocil:actions>
87 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-sebool_domain_kernel_load_modules_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-sebool_virt_transition_userdomain_ocil:questionnaire:1">
89 ······<ocil:title>Disable·the·domain_kernel_load_modules·SELinux·Boolean</ocil:title>89 ······<ocil:title>Disable·the·virt_transition_userdomain·SELinux·Boolean</ocil:title>
90 ······<ocil:actions>90 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-sebool_domain_kernel_load_modules_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-sebool_virt_transition_userdomain_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>92 ······</ocil:actions>
93 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_ipsec_secrets_ocil:questionnaire:1"> 
95 ······<ocil:title>Verify·Group·Who·Owns·/etc/ipsec.secrets·File</ocil:title>94 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_open_by_handle_at_ocil:questionnaire:1">
 95 ······<ocil:title>Record·Unsuccessful·Access·Attempts·to·Files·-·open_by_handle_at</ocil:title>
96 ······<ocil:actions>96 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_ipsec_secrets_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_open_by_handle_at_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>98 ······</ocil:actions>
99 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_accept_redirects_ocil:questionnaire:1"> 
101 ······<ocil:title>Disable·Accepting·ICMP·Redirects·for·All·IPv4·Interfaces</ocil:title>100 ····<ocil:questionnaire·id="ocil:ssg-usbguard_allow_hid_ocil:questionnaire:1">
 101 ······<ocil:title>Authorize·Human·Interface·Devices·in·USBGuard·daemon</ocil:title>
102 ······<ocil:actions>102 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_accept_redirects_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-usbguard_allow_hid_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>104 ······</ocil:actions>
105 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-account_password_selinux_faillock_dir_ocil:questionnaire:1">106 ····<ocil:questionnaire·id="ocil:ssg-package_tuned_removed_ocil:questionnaire:1">
107 ······<ocil:title>An·SELinux·Context·must·be·configured·for·the·pam_faillock.so·records·directory</ocil:title>107 ······<ocil:title>Uninstall·tuned·Package</ocil:title>
108 ······<ocil:actions>108 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-account_password_selinux_faillock_dir_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-package_tuned_removed_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>110 ······</ocil:actions>
111 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_open_by_handle_at_ocil:questionnaire:1"> 
113 ······<ocil:title>Record·Unsuccessful·Access·Attempts·to·Files·-·open_by_handle_at</ocil:title>112 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_route_localnet_ocil:questionnaire:1">
 113 ······<ocil:title>Prevent·Routing·External·Traffic·to·Local·Loopback·on·All·IPv4·Interfaces</ocil:title>
114 ······<ocil:actions>114 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_open_by_handle_at_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_route_localnet_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>116 ······</ocil:actions>
117 ····</ocil:questionnaire>117 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-sebool_irc_use_any_tcp_ports_ocil:questionnaire:1">118 ····<ocil:questionnaire·id="ocil:ssg-sebool_tmpreaper_use_samba_ocil:questionnaire:1">
119 ······<ocil:title>Disable·the·irc_use_any_tcp_ports·SELinux·Boolean</ocil:title>119 ······<ocil:title>Disable·the·tmpreaper_use_samba·SELinux·Boolean</ocil:title>
120 ······<ocil:actions>120 ······<ocil:actions>
Max diff block lines reached; 3416474/3429201 bytes (99.63%) of diff not shown.
590 KB
./usr/share/xml/scap/ssg/content/ssg-rhel8-xccdf.xml
590 KB
./usr/share/xml/scap/ssg/content/ssg-rhel8-xccdf.xml
Ordering differences only
    
Offset 72, 264 lines modifiedOffset 72, 223 lines modified
72 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>72 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
73 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>73 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
74 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>74 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
75 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>75 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
77 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>77 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
78 ··<cpe-lang:platform-specification>78 ··<cpe-lang:platform-specification>
 79 ····<cpe-lang:platform·id="not_aarch64_arch_and_not_ppc64le_arch_and_system_with_kernel">
79 ····<cpe-lang:platform·id="package_libuser"> 
80 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
81 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-package_libuser:def:1"/> 
82 ······</cpe-lang:logical-test> 
83 ····</cpe-lang:platform> 
84 ····<cpe-lang:platform·id="not_bootc"> 
85 ······<cpe-lang:logical-test·operator="AND"·negate="true"> 
86 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-bootc:def:1"/> 
87 ······</cpe-lang:logical-test> 
88 ····</cpe-lang:platform> 
89 ····<cpe-lang:platform·id="package_nftables_and_service_disabled_firewalld_and_system_with_kernel"> 
90 ······<cpe-lang:logical-test·operator="AND"·negate="false">80 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 81 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 82 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
 83 ········</cpe-lang:logical-test>
 84 ········<cpe-lang:logical-test·operator="AND"·negate="true">
91 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>85 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_ppc64le:def:1"/>
92 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_firewalld:def:1"/>86 ········</cpe-lang:logical-test>
93 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>87 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
94 ······</cpe-lang:logical-test>88 ······</cpe-lang:logical-test>
95 ····</cpe-lang:platform>89 ····</cpe-lang:platform>
96 ····<cpe-lang:platform·id="machine">90 ····<cpe-lang:platform·id="not_runtime_kernel_fips_enabled_and_system_with_kernel">
97 ······<cpe-lang:logical-test·operator="AND"·negate="false">91 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 92 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 93 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-runtime_kernel_fips_enabled:def:1"/>
 94 ········</cpe-lang:logical-test>
98 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>95 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
99 ······</cpe-lang:logical-test>96 ······</cpe-lang:logical-test>
100 ····</cpe-lang:platform>97 ····</cpe-lang:platform>
101 ····<cpe-lang:platform·id="package_squid_and_system_with_kernel">98 ····<cpe-lang:platform·id="package_polkit">
102 ······<cpe-lang:logical-test·operator="AND"·negate="false">99 ······<cpe-lang:logical-test·operator="AND"·negate="false">
103 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-package_squid:def:1"/>100 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-package_polkit:def:1"/>
104 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
105 ······</cpe-lang:logical-test>101 ······</cpe-lang:logical-test>
106 ····</cpe-lang:platform>102 ····</cpe-lang:platform>
107 ····<cpe-lang:platform·id="package_pam">103 ····<cpe-lang:platform·id="mount_var-tmp">
108 ······<cpe-lang:logical-test·operator="AND"·negate="false">104 ······<cpe-lang:logical-test·operator="AND"·negate="false">
109 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>105 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-tmp:def:1"/>
110 ······</cpe-lang:logical-test>106 ······</cpe-lang:logical-test>
111 ····</cpe-lang:platform>107 ····</cpe-lang:platform>
112 ····<cpe-lang:platform·id="package_autofs_and_system_with_kernel">108 ····<cpe-lang:platform·id="package_autofs_and_system_with_kernel">
113 ······<cpe-lang:logical-test·operator="AND"·negate="false">109 ······<cpe-lang:logical-test·operator="AND"·negate="false">
114 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>110 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>
115 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>111 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
116 ······</cpe-lang:logical-test>112 ······</cpe-lang:logical-test>
117 ····</cpe-lang:platform>113 ····</cpe-lang:platform>
118 ····<cpe-lang:platform·id="mount_tmp">114 ····<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">
119 ······<cpe-lang:logical-test·operator="AND"·negate="false">115 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 116 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 117 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
 118 ········</cpe-lang:logical-test>
 119 ········<cpe-lang:logical-test·operator="AND"·negate="true">
120 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_tmp:def:1"/>120 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
 121 ········</cpe-lang:logical-test>
 122 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
121 ······</cpe-lang:logical-test>123 ······</cpe-lang:logical-test>
122 ····</cpe-lang:platform>124 ····</cpe-lang:platform>
123 ····<cpe-lang:platform·id="package_firewalld_and_package_nftables_and_system_with_kernel">125 ····<cpe-lang:platform·id="ipv6_enabled">
124 ······<cpe-lang:logical-test·operator="AND"·negate="false">126 ······<cpe-lang:logical-test·operator="AND"·negate="false">
125 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/> 
126 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>127 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-ipv6_enabled:def:1"/>
127 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
128 ······</cpe-lang:logical-test>128 ······</cpe-lang:logical-test>
129 ····</cpe-lang:platform>129 ····</cpe-lang:platform>
130 ····<cpe-lang:platform·id="not_s390x_arch">130 ····<cpe-lang:platform·id="package_gdm">
131 ······<cpe-lang:logical-test·operator="AND"·negate="false">131 ······<cpe-lang:logical-test·operator="AND"·negate="false">
132 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>132 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-package_gdm:def:1"/>
133 ······</cpe-lang:logical-test>133 ······</cpe-lang:logical-test>
134 ····</cpe-lang:platform>134 ····</cpe-lang:platform>
135 ····<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">135 ····<cpe-lang:platform·id="package_rsyslog">
136 ······<cpe-lang:logical-test·operator="AND"·negate="false">136 ······<cpe-lang:logical-test·operator="AND"·negate="false">
137 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>137 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>
138 ······</cpe-lang:logical-test>138 ······</cpe-lang:logical-test>
139 ····</cpe-lang:platform>139 ····</cpe-lang:platform>
140 ····<cpe-lang:platform·id="mount_var-log">140 ····<cpe-lang:platform·id="not_osbuild_and_system_with_kernel">
141 ······<cpe-lang:logical-test·operator="AND"·negate="false">141 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 142 ········<cpe-lang:logical-test·operator="AND"·negate="true">
142 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-log:def:1"/>143 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_osbuild:def:1"/>
 144 ········</cpe-lang:logical-test>
 145 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
143 ······</cpe-lang:logical-test>146 ······</cpe-lang:logical-test>
144 ····</cpe-lang:platform>147 ····</cpe-lang:platform>
145 ····<cpe-lang:platform·id="uefi">148 ····<cpe-lang:platform·id="package_chrony_or_package_ntp">
146 ······<cpe-lang:logical-test·operator="AND"·negate="false">149 ······<cpe-lang:logical-test·operator="OR"·negate="false">
 150 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
147 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>151 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-package_ntp:def:1"/>
148 ······</cpe-lang:logical-test>152 ······</cpe-lang:logical-test>
149 ····</cpe-lang:platform>153 ····</cpe-lang:platform>
150 ····<cpe-lang:platform·id="package_bash">154 ····<cpe-lang:platform·id="os_linux_rhel_le_or_eq_8_3">
151 ······<cpe-lang:logical-test·operator="AND"·negate="false">155 ······<cpe-lang:logical-test·operator="AND"·negate="false">
152 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>156 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_le_or_eq_8_3:def:1"/>
153 ······</cpe-lang:logical-test>157 ······</cpe-lang:logical-test>
154 ····</cpe-lang:platform>158 ····</cpe-lang:platform>
155 ····<cpe-lang:platform·id="package_telnet-server_and_system_with_kernel">159 ····<cpe-lang:platform·id="package_bash">
156 ······<cpe-lang:logical-test·operator="AND"·negate="false">160 ······<cpe-lang:logical-test·operator="AND"·negate="false">
157 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-package_telnet-server:def:1"/>161 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>
158 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
159 ······</cpe-lang:logical-test>162 ······</cpe-lang:logical-test>
160 ····</cpe-lang:platform>163 ····</cpe-lang:platform>
161 ····<cpe-lang:platform·id="package_iptables">164 ····<cpe-lang:platform·id="uefi">
162 ······<cpe-lang:logical-test·operator="AND"·negate="false">165 ······<cpe-lang:logical-test·operator="AND"·negate="false">
163 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>166 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>
164 ······</cpe-lang:logical-test>167 ······</cpe-lang:logical-test>
165 ····</cpe-lang:platform>168 ····</cpe-lang:platform>
166 ····<cpe-lang:platform·id="krb5_server_older_than_1_17-18_and_krb5_workstation_older_than_1_17-18">169 ····<cpe-lang:platform·id="package_logrotate">
167 ······<cpe-lang:logical-test·operator="AND"·negate="false">170 ······<cpe-lang:logical-test·operator="AND"·negate="false">
168 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-krb5_server_older_than_1_17_18:def:1"/> 
169 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-krb5_workstation_older_than_1_17_18:def:1"/>171 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-package_logrotate:def:1"/>
170 ······</cpe-lang:logical-test>172 ······</cpe-lang:logical-test>
171 ····</cpe-lang:platform>173 ····</cpe-lang:platform>
172 ····<cpe-lang:platform·id="grub2">174 ····<cpe-lang:platform·id="package_chrony">
173 ······<cpe-lang:logical-test·operator="AND"·negate="false">175 ······<cpe-lang:logical-test·operator="AND"·negate="false">
174 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>176 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
175 ······</cpe-lang:logical-test>177 ······</cpe-lang:logical-test>
176 ····</cpe-lang:platform>178 ····</cpe-lang:platform>
177 ····<cpe-lang:platform·id="package_sssd">179 ····<cpe-lang:platform·id="package_sssd">
178 ······<cpe-lang:logical-test·operator="AND"·negate="false">180 ······<cpe-lang:logical-test·operator="AND"·negate="false">
179 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-package_sssd:def:1"/>181 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-package_sssd:def:1"/>
180 ······</cpe-lang:logical-test>182 ······</cpe-lang:logical-test>
Max diff block lines reached; 590522/604362 bytes (97.71%) of diff not shown.
3.75 MB
./usr/share/xml/scap/ssg/content/ssg-rhel9-ds.xml
3.75 MB
./usr/share/xml/scap/ssg/content/ssg-rhel9-ds.xml
    
Offset 19, 23 lines modifiedOffset 19, 23 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel9-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel9-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel9-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel9-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel9-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel9-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel9-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel9-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel9-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel9-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel9-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel9-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel9-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel9-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux:9">28 ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux:9">
29 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Enterprise·Linux·9</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Enterprise·Linux·9</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml">oval:ssg-installed_OS_is_rhel9:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml">oval:ssg-installed_OS_is_rhel9:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ····</cpe-dict:cpe-list>32 ····</cpe-dict:cpe-list>
33 ··</ds:component>33 ··</ds:component>
34 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel9-xccdf.xml"·timestamp="2025-02-28T20:08:00">34 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel9-xccdf.xml"·timestamp="2025-03-01T22:08:00">
35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_RHEL-9"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_RHEL-9"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Red·Hat·Enterprise·Linux·9</xccdf-1.2:title>37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Red·Hat·Enterprise·Linux·9</xccdf-1.2:title>
38 ······<xccdf-1.2:description>38 ······<xccdf-1.2:description>
39 ········This·guide·presents·a·catalog·of·security-relevant39 ········This·guide·presents·a·catalog·of·security-relevant
40 configuration·settings·for·Red·Hat·Enterprise·Linux·9.·It·is·a·rendering·of40 configuration·settings·for·Red·Hat·Enterprise·Linux·9.·It·is·a·rendering·of
41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 106, 262 lines modifiedOffset 106, 228 lines modified
106 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>106 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
107 ······<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>107 ······<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
108 ······<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>108 ······<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
109 ······<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>109 ······<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
110 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>110 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
111 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>111 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
112 ······<cpe-lang:platform-specification>112 ······<cpe-lang:platform-specification>
113 ········<cpe-lang:platform·id="package_libuser">113 ········<cpe-lang:platform·id="not_aarch64_arch_and_not_ppc64le_arch_and_system_with_kernel">
114 ··········<cpe-lang:logical-test·operator="AND"·negate="false">114 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 115 ············<cpe-lang:logical-test·operator="AND"·negate="true">
 116 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
 117 ············</cpe-lang:logical-test>
 118 ············<cpe-lang:logical-test·operator="AND"·negate="true">
 119 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_ppc64le:def:1"/>
 120 ············</cpe-lang:logical-test>
115 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-package_libuser:def:1"/>121 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
116 ··········</cpe-lang:logical-test>122 ··········</cpe-lang:logical-test>
117 ········</cpe-lang:platform>123 ········</cpe-lang:platform>
118 ········<cpe-lang:platform·id="not_bootc">124 ········<cpe-lang:platform·id="not_runtime_kernel_fips_enabled_and_system_with_kernel">
 125 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
119 ··········<cpe-lang:logical-test·operator="AND"·negate="true">126 ············<cpe-lang:logical-test·operator="AND"·negate="true">
 127 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-runtime_kernel_fips_enabled:def:1"/>
 128 ············</cpe-lang:logical-test>
120 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-bootc:def:1"/>129 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
121 ··········</cpe-lang:logical-test>130 ··········</cpe-lang:logical-test>
122 ········</cpe-lang:platform>131 ········</cpe-lang:platform>
123 ········<cpe-lang:platform·id="machine">132 ········<cpe-lang:platform·id="package_polkit">
124 ··········<cpe-lang:logical-test·operator="AND"·negate="false">133 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
125 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>134 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-package_polkit:def:1"/>
126 ··········</cpe-lang:logical-test>135 ··········</cpe-lang:logical-test>
127 ········</cpe-lang:platform>136 ········</cpe-lang:platform>
128 ········<cpe-lang:platform·id="package_squid_and_system_with_kernel">137 ········<cpe-lang:platform·id="mount_var-tmp">
129 ··········<cpe-lang:logical-test·operator="AND"·negate="false">138 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
130 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-package_squid:def:1"/> 
131 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>139 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-tmp:def:1"/>
132 ··········</cpe-lang:logical-test>140 ··········</cpe-lang:logical-test>
133 ········</cpe-lang:platform>141 ········</cpe-lang:platform>
134 ········<cpe-lang:platform·id="package_pam">142 ········<cpe-lang:platform·id="package_networkmanager">
135 ··········<cpe-lang:logical-test·operator="AND"·negate="false">143 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
136 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>144 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-package_networkmanager:def:1"/>
137 ··········</cpe-lang:logical-test>145 ··········</cpe-lang:logical-test>
138 ········</cpe-lang:platform>146 ········</cpe-lang:platform>
139 ········<cpe-lang:platform·id="package_autofs_and_system_with_kernel">147 ········<cpe-lang:platform·id="package_autofs_and_system_with_kernel">
140 ··········<cpe-lang:logical-test·operator="AND"·negate="false">148 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
141 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>149 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>
142 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>150 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
143 ··········</cpe-lang:logical-test>151 ··········</cpe-lang:logical-test>
144 ········</cpe-lang:platform>152 ········</cpe-lang:platform>
145 ········<cpe-lang:platform·id="mount_tmp">153 ········<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">
146 ··········<cpe-lang:logical-test·operator="AND"·negate="false">154 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 155 ············<cpe-lang:logical-test·operator="AND"·negate="true">
 156 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
 157 ············</cpe-lang:logical-test>
 158 ············<cpe-lang:logical-test·operator="AND"·negate="true">
147 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_tmp:def:1"/>159 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
 160 ············</cpe-lang:logical-test>
 161 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
148 ··········</cpe-lang:logical-test>162 ··········</cpe-lang:logical-test>
149 ········</cpe-lang:platform>163 ········</cpe-lang:platform>
150 ········<cpe-lang:platform·id="package_firewalld_and_package_nftables_and_system_with_kernel">164 ········<cpe-lang:platform·id="ipv6_enabled">
151 ··········<cpe-lang:logical-test·operator="AND"·negate="false">165 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
152 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/> 
153 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>166 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-ipv6_enabled:def:1"/>
154 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
155 ··········</cpe-lang:logical-test>167 ··········</cpe-lang:logical-test>
156 ········</cpe-lang:platform>168 ········</cpe-lang:platform>
157 ········<cpe-lang:platform·id="not_s390x_arch">169 ········<cpe-lang:platform·id="package_gdm">
158 ··········<cpe-lang:logical-test·operator="AND"·negate="false">170 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
159 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>171 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-package_gdm:def:1"/>
160 ··········</cpe-lang:logical-test>172 ··········</cpe-lang:logical-test>
161 ········</cpe-lang:platform>173 ········</cpe-lang:platform>
162 ········<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">174 ········<cpe-lang:platform·id="package_rsyslog">
163 ··········<cpe-lang:logical-test·operator="AND"·negate="false">175 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
164 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>176 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>
165 ··········</cpe-lang:logical-test> 
166 ········</cpe-lang:platform> 
167 ········<cpe-lang:platform·id="not_ppc64le_arch"> 
168 ··········<cpe-lang:logical-test·operator="AND"·negate="true"> 
169 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_ppc64le:def:1"/> 
170 ··········</cpe-lang:logical-test>177 ··········</cpe-lang:logical-test>
171 ········</cpe-lang:platform>178 ········</cpe-lang:platform>
172 ········<cpe-lang:platform·id="mount_var-log">179 ········<cpe-lang:platform·id="not_osbuild_and_system_with_kernel">
173 ··········<cpe-lang:logical-test·operator="AND"·negate="false">180 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 181 ············<cpe-lang:logical-test·operator="AND"·negate="true">
174 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-log:def:1"/>182 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_osbuild:def:1"/>
 183 ············</cpe-lang:logical-test>
 184 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
175 ··········</cpe-lang:logical-test>185 ··········</cpe-lang:logical-test>
176 ········</cpe-lang:platform>186 ········</cpe-lang:platform>
177 ········<cpe-lang:platform·id="uefi">187 ········<cpe-lang:platform·id="package_chrony_or_package_ntp">
178 ··········<cpe-lang:logical-test·operator="AND"·negate="false">188 ··········<cpe-lang:logical-test·operator="OR"·negate="false">
 189 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
179 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>190 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-package_ntp:def:1"/>
180 ··········</cpe-lang:logical-test>191 ··········</cpe-lang:logical-test>
181 ········</cpe-lang:platform>192 ········</cpe-lang:platform>
182 ········<cpe-lang:platform·id="package_bash">193 ········<cpe-lang:platform·id="package_bash">
183 ··········<cpe-lang:logical-test·operator="AND"·negate="false">194 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
184 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>195 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>
185 ··········</cpe-lang:logical-test>196 ··········</cpe-lang:logical-test>
186 ········</cpe-lang:platform>197 ········</cpe-lang:platform>
187 ········<cpe-lang:platform·id="ppc64le_arch"> 
188 ··········<cpe-lang:logical-test·operator="AND"·negate="false"> 
189 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_ppc64le:def:1"/> 
Max diff block lines reached; 3915298/3929148 bytes (99.65%) of diff not shown.
3.14 MB
./usr/share/xml/scap/ssg/content/ssg-rhel9-ocil.xml
3.14 MB
./usr/share/xml/scap/ssg/content/ssg-rhel9-ocil.xml
Ordering differences only
    
Offset 3, 13442 lines modifiedOffset 3, 13442 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-directory_access_var_log_audit_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-sebool_varnishd_connect_any_ocil:questionnaire:1">
11 ······<ocil:title>Record·Access·Events·to·Audit·Log·Directory</ocil:title>11 ······<ocil:title>Disable·the·varnishd_connect_any·SELinux·Boolean</ocil:title>
12 ······<ocil:actions>12 ······<ocil:actions>
13 ········<ocil:test_action_ref>ocil:ssg-directory_access_var_log_audit_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-sebool_varnishd_connect_any_action:testaction:1</ocil:test_action_ref>
14 ······</ocil:actions>14 ······</ocil:actions>
15 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
16 ····<ocil:questionnaire·id="ocil:ssg-directory_owner_etc_sysctld_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_passwd_ocil:questionnaire:1">
17 ······<ocil:title>Verify·User·Who·Owns·/etc/sysctl.d·Directory</ocil:title>17 ······<ocil:title>Verify·Permissions·on·passwd·File</ocil:title>
18 ······<ocil:actions>18 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-directory_owner_etc_sysctld_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-file_permissions_etc_passwd_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>20 ······</ocil:actions>
21 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_kernel_module_loading_ocil:questionnaire:1"> 
23 ······<ocil:title>Ensure·auditd·Collects·Information·on·Kernel·Module·Loading·and·Unloading</ocil:title>22 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_rp_filter_ocil:questionnaire:1">
 23 ······<ocil:title>Enable·Kernel·Parameter·to·Use·Reverse·Path·Filtering·on·all·IPv4·Interfaces</ocil:title>
24 ······<ocil:actions>24 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-audit_rules_kernel_module_loading_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_rp_filter_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>26 ······</ocil:actions>
27 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-partition_for_home_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_efi_grub2_cfg_ocil:questionnaire:1">
29 ······<ocil:title>Ensure·/home·Located·On·Separate·Partition</ocil:title>29 ······<ocil:title>Verify·the·UEFI·Boot·Loader·grub.cfg·Permissions</ocil:title>
30 ······<ocil:actions>30 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-partition_for_home_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-file_permissions_efi_grub2_cfg_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>32 ······</ocil:actions>
33 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_pwhistory_remember_password_auth_ocil:questionnaire:1"> 
35 ······<ocil:title>Limit·Password·Reuse:·password-auth</ocil:title>34 ····<ocil:questionnaire·id="ocil:ssg-directory_permissions_etc_selinux_ocil:questionnaire:1">
 35 ······<ocil:title>Verify·Permissions·On·/etc/selinux·Directory</ocil:title>
36 ······<ocil:actions>36 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-accounts_password_pam_pwhistory_remember_password_auth_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-directory_permissions_etc_selinux_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>38 ······</ocil:actions>
39 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_successful_file_modification_unlinkat_ocil:questionnaire:1"> 
41 ······<ocil:title>Record·Successful·Delete·Attempts·to·Files·-·unlinkat</ocil:title>40 ····<ocil:questionnaire·id="ocil:ssg-sebool_puppetagent_manage_all_files_ocil:questionnaire:1">
 41 ······<ocil:title>Disable·the·puppetagent_manage_all_files·SELinux·Boolean</ocil:title>
42 ······<ocil:actions>42 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-audit_rules_successful_file_modification_unlinkat_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-sebool_puppetagent_manage_all_files_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>44 ······</ocil:actions>
45 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-accounts_root_gid_zero_ocil:questionnaire:1">46 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_sudoers_ocil:questionnaire:1">
47 ······<ocil:title>Verify·Root·Has·A·Primary·GID·0</ocil:title>47 ······<ocil:title>Verify·Group·Who·Owns·/etc/sudoers·File</ocil:title>
48 ······<ocil:actions>48 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-accounts_root_gid_zero_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_sudoers_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>50 ······</ocil:actions>
51 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-sebool_mcelog_exec_scripts_ocil:questionnaire:1"> 
53 ······<ocil:title>Enable·the·mcelog_exec_scripts·SELinux·Boolean</ocil:title>52 ····<ocil:questionnaire·id="ocil:ssg-audit_owner_change_failed_aarch64_ocil:questionnaire:1">
 53 ······<ocil:title>Configure·auditing·of·unsuccessful·ownership·changes·(AArch64)</ocil:title>
54 ······<ocil:actions>54 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-sebool_mcelog_exec_scripts_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-audit_owner_change_failed_aarch64_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>56 ······</ocil:actions>
57 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-mount_option_proc_hidepid_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-sebool_mozilla_plugin_use_spice_ocil:questionnaire:1">
59 ······<ocil:title>Add·hidepid·Option·to·/proc</ocil:title>59 ······<ocil:title>Disable·the·mozilla_plugin_use_spice·SELinux·Boolean</ocil:title>
60 ······<ocil:actions>60 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-mount_option_proc_hidepid_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-sebool_mozilla_plugin_use_spice_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>62 ······</ocil:actions>
63 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_usergroup_modification_gshadow_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-sebool_user_exec_content_ocil:questionnaire:1">
65 ······<ocil:title>Record·Events·that·Modify·User/Group·Information·-·/etc/gshadow</ocil:title>65 ······<ocil:title>Enable·the·user_exec_content·SELinux·Boolean</ocil:title>
66 ······<ocil:actions>66 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-audit_rules_usergroup_modification_gshadow_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-sebool_user_exec_content_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>68 ······</ocil:actions>
69 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_shells_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-file_owner_etc_ipsec_conf_ocil:questionnaire:1">
71 ······<ocil:title>Verify·Group·Who·Owns·/etc/shells·File</ocil:title>71 ······<ocil:title>Verify·User·Who·Owns·/etc/ipsec.conf·File</ocil:title>
72 ······<ocil:actions>72 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_shells_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-file_owner_etc_ipsec_conf_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>74 ······</ocil:actions>
75 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-sssd_ldap_start_tls_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-sebool_mplayer_execstack_ocil:questionnaire:1">
77 ······<ocil:title>Configure·SSSD·LDAP·Backend·to·Use·TLS·For·All·Transactions</ocil:title>77 ······<ocil:title>Disable·the·mplayer_execstack·SELinux·Boolean</ocil:title>
78 ······<ocil:actions>78 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-sssd_ldap_start_tls_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-sebool_mplayer_execstack_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>80 ······</ocil:actions>
81 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-sebool_httpd_sys_script_anon_write_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-kernel_module_atm_disabled_ocil:questionnaire:1">
83 ······<ocil:title>Disable·the·httpd_sys_script_anon_write·SELinux·Boolean</ocil:title>83 ······<ocil:title>Disable·ATM·Support</ocil:title>
84 ······<ocil:actions>84 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-sebool_httpd_sys_script_anon_write_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-kernel_module_atm_disabled_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>86 ······</ocil:actions>
87 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_etc_group_open_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-enable_fips_mode_ocil:questionnaire:1">
89 ······<ocil:title>Record·Events·that·Modify·User/Group·Information·via·open·syscall·-·/etc/group</ocil:title>89 ······<ocil:title>Enable·FIPS·Mode</ocil:title>
90 ······<ocil:actions>90 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-audit_rules_etc_group_open_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-enable_fips_mode_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>92 ······</ocil:actions>
93 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-mount_option_home_noexec_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-mount_option_home_grpquota_ocil:questionnaire:1">
95 ······<ocil:title>Add·noexec·Option·to·/home</ocil:title>95 ······<ocil:title>Add·grpquota·Option·to·/home</ocil:title>
96 ······<ocil:actions>96 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-mount_option_home_noexec_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-mount_option_home_grpquota_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>98 ······</ocil:actions>
99 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-no_legacy_plus_entries_etc_group_ocil:questionnaire:1"> 
101 ······<ocil:title>Ensure·there·are·no·legacy·+·NIS·entries·in·/etc/group</ocil:title>100 ····<ocil:questionnaire·id="ocil:ssg-sebool_xserver_object_manager_ocil:questionnaire:1">
 101 ······<ocil:title>Disable·the·xserver_object_manager·SELinux·Boolean</ocil:title>
102 ······<ocil:actions>102 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-no_legacy_plus_entries_etc_group_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-sebool_xserver_object_manager_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>104 ······</ocil:actions>
105 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_unlink_ocil:questionnaire:1"> 
107 ······<ocil:title>Record·Unsuccessful·Delete·Attempts·to·Files·-·unlink</ocil:title>106 ····<ocil:questionnaire·id="ocil:ssg-sebool_selinuxuser_use_ssh_chroot_ocil:questionnaire:1">
 107 ······<ocil:title>Disable·the·selinuxuser_use_ssh_chroot·SELinux·Boolean</ocil:title>
108 ······<ocil:actions>108 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_unlink_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-sebool_selinuxuser_use_ssh_chroot_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>110 ······</ocil:actions>
111 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-ensure_redhat_gpgkey_installed_ocil:questionnaire:1">112 ····<ocil:questionnaire·id="ocil:ssg-mount_option_var_nosuid_ocil:questionnaire:1">
113 ······<ocil:title>Ensure·Red·Hat·GPG·Key·Installed</ocil:title>113 ······<ocil:title>Add·nosuid·Option·to·/var</ocil:title>
114 ······<ocil:actions>114 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-ensure_redhat_gpgkey_installed_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-mount_option_var_nosuid_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>116 ······</ocil:actions>
117 ····</ocil:questionnaire>117 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-grub2_mds_argument_ocil:questionnaire:1">118 ····<ocil:questionnaire·id="ocil:ssg-sebool_openvpn_run_unconfined_ocil:questionnaire:1">
119 ······<ocil:title>Configure·Microarchitectural·Data·Sampling·mitigation</ocil:title>119 ······<ocil:title>Disable·the·openvpn_run_unconfined·SELinux·Boolean</ocil:title>
120 ······<ocil:actions>120 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-grub2_mds_argument_action:testaction:1</ocil:test_action_ref>121 ········<ocil:test_action_ref>ocil:ssg-sebool_openvpn_run_unconfined_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>122 ······</ocil:actions>
123 ····</ocil:questionnaire>123 ····</ocil:questionnaire>
Max diff block lines reached; 3280509/3293388 bytes (99.61%) of diff not shown.
487 KB
./usr/share/xml/scap/ssg/content/ssg-rhel9-xccdf.xml
486 KB
./usr/share/xml/scap/ssg/content/ssg-rhel9-xccdf.xml
Ordering differences only
    
Offset 73, 262 lines modifiedOffset 73, 228 lines modified
73 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>73 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
74 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>74 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
75 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>75 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
76 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>76 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
77 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>77 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
78 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>78 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
79 ··<cpe-lang:platform-specification>79 ··<cpe-lang:platform-specification>
80 ····<cpe-lang:platform·id="package_libuser">80 ····<cpe-lang:platform·id="not_aarch64_arch_and_not_ppc64le_arch_and_system_with_kernel">
81 ······<cpe-lang:logical-test·operator="AND"·negate="false">81 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 82 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 83 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
 84 ········</cpe-lang:logical-test>
 85 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 86 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_ppc64le:def:1"/>
 87 ········</cpe-lang:logical-test>
82 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-package_libuser:def:1"/>88 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
83 ······</cpe-lang:logical-test>89 ······</cpe-lang:logical-test>
84 ····</cpe-lang:platform>90 ····</cpe-lang:platform>
85 ····<cpe-lang:platform·id="not_bootc">91 ····<cpe-lang:platform·id="not_runtime_kernel_fips_enabled_and_system_with_kernel">
 92 ······<cpe-lang:logical-test·operator="AND"·negate="false">
86 ······<cpe-lang:logical-test·operator="AND"·negate="true">93 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 94 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-runtime_kernel_fips_enabled:def:1"/>
 95 ········</cpe-lang:logical-test>
87 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-bootc:def:1"/>96 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
88 ······</cpe-lang:logical-test>97 ······</cpe-lang:logical-test>
89 ····</cpe-lang:platform>98 ····</cpe-lang:platform>
90 ····<cpe-lang:platform·id="machine">99 ····<cpe-lang:platform·id="package_polkit">
91 ······<cpe-lang:logical-test·operator="AND"·negate="false">100 ······<cpe-lang:logical-test·operator="AND"·negate="false">
92 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>101 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-package_polkit:def:1"/>
93 ······</cpe-lang:logical-test>102 ······</cpe-lang:logical-test>
94 ····</cpe-lang:platform>103 ····</cpe-lang:platform>
95 ····<cpe-lang:platform·id="package_squid_and_system_with_kernel">104 ····<cpe-lang:platform·id="mount_var-tmp">
96 ······<cpe-lang:logical-test·operator="AND"·negate="false">105 ······<cpe-lang:logical-test·operator="AND"·negate="false">
97 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-package_squid:def:1"/> 
98 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>106 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-tmp:def:1"/>
99 ······</cpe-lang:logical-test>107 ······</cpe-lang:logical-test>
100 ····</cpe-lang:platform>108 ····</cpe-lang:platform>
101 ····<cpe-lang:platform·id="package_pam">109 ····<cpe-lang:platform·id="package_networkmanager">
102 ······<cpe-lang:logical-test·operator="AND"·negate="false">110 ······<cpe-lang:logical-test·operator="AND"·negate="false">
103 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>111 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-package_networkmanager:def:1"/>
104 ······</cpe-lang:logical-test>112 ······</cpe-lang:logical-test>
105 ····</cpe-lang:platform>113 ····</cpe-lang:platform>
106 ····<cpe-lang:platform·id="package_autofs_and_system_with_kernel">114 ····<cpe-lang:platform·id="package_autofs_and_system_with_kernel">
107 ······<cpe-lang:logical-test·operator="AND"·negate="false">115 ······<cpe-lang:logical-test·operator="AND"·negate="false">
108 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>116 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>
109 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>117 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
110 ······</cpe-lang:logical-test>118 ······</cpe-lang:logical-test>
111 ····</cpe-lang:platform>119 ····</cpe-lang:platform>
112 ····<cpe-lang:platform·id="mount_tmp">120 ····<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">
113 ······<cpe-lang:logical-test·operator="AND"·negate="false">121 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 122 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 123 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
 124 ········</cpe-lang:logical-test>
 125 ········<cpe-lang:logical-test·operator="AND"·negate="true">
114 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_tmp:def:1"/>126 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
 127 ········</cpe-lang:logical-test>
 128 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
115 ······</cpe-lang:logical-test>129 ······</cpe-lang:logical-test>
116 ····</cpe-lang:platform>130 ····</cpe-lang:platform>
117 ····<cpe-lang:platform·id="package_firewalld_and_package_nftables_and_system_with_kernel">131 ····<cpe-lang:platform·id="ipv6_enabled">
118 ······<cpe-lang:logical-test·operator="AND"·negate="false">132 ······<cpe-lang:logical-test·operator="AND"·negate="false">
119 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/> 
120 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>133 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-ipv6_enabled:def:1"/>
121 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
122 ······</cpe-lang:logical-test>134 ······</cpe-lang:logical-test>
123 ····</cpe-lang:platform>135 ····</cpe-lang:platform>
124 ····<cpe-lang:platform·id="not_s390x_arch">136 ····<cpe-lang:platform·id="package_gdm">
125 ······<cpe-lang:logical-test·operator="AND"·negate="false">137 ······<cpe-lang:logical-test·operator="AND"·negate="false">
126 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>138 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-package_gdm:def:1"/>
127 ······</cpe-lang:logical-test>139 ······</cpe-lang:logical-test>
128 ····</cpe-lang:platform>140 ····</cpe-lang:platform>
129 ····<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">141 ····<cpe-lang:platform·id="package_rsyslog">
130 ······<cpe-lang:logical-test·operator="AND"·negate="false">142 ······<cpe-lang:logical-test·operator="AND"·negate="false">
131 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>143 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>
132 ······</cpe-lang:logical-test> 
133 ····</cpe-lang:platform> 
134 ····<cpe-lang:platform·id="not_ppc64le_arch"> 
135 ······<cpe-lang:logical-test·operator="AND"·negate="true"> 
136 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_ppc64le:def:1"/> 
137 ······</cpe-lang:logical-test>144 ······</cpe-lang:logical-test>
138 ····</cpe-lang:platform>145 ····</cpe-lang:platform>
139 ····<cpe-lang:platform·id="mount_var-log">146 ····<cpe-lang:platform·id="not_osbuild_and_system_with_kernel">
140 ······<cpe-lang:logical-test·operator="AND"·negate="false">147 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 148 ········<cpe-lang:logical-test·operator="AND"·negate="true">
141 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-log:def:1"/>149 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_osbuild:def:1"/>
 150 ········</cpe-lang:logical-test>
 151 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
142 ······</cpe-lang:logical-test>152 ······</cpe-lang:logical-test>
143 ····</cpe-lang:platform>153 ····</cpe-lang:platform>
144 ····<cpe-lang:platform·id="uefi">154 ····<cpe-lang:platform·id="package_chrony_or_package_ntp">
145 ······<cpe-lang:logical-test·operator="AND"·negate="false">155 ······<cpe-lang:logical-test·operator="OR"·negate="false">
 156 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
146 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>157 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-package_ntp:def:1"/>
147 ······</cpe-lang:logical-test>158 ······</cpe-lang:logical-test>
148 ····</cpe-lang:platform>159 ····</cpe-lang:platform>
149 ····<cpe-lang:platform·id="package_bash">160 ····<cpe-lang:platform·id="package_bash">
150 ······<cpe-lang:logical-test·operator="AND"·negate="false">161 ······<cpe-lang:logical-test·operator="AND"·negate="false">
151 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>162 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>
152 ······</cpe-lang:logical-test>163 ······</cpe-lang:logical-test>
153 ····</cpe-lang:platform>164 ····</cpe-lang:platform>
154 ····<cpe-lang:platform·id="ppc64le_arch">165 ····<cpe-lang:platform·id="uefi">
155 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
156 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_ppc64le:def:1"/> 
157 ······</cpe-lang:logical-test> 
158 ····</cpe-lang:platform> 
159 ····<cpe-lang:platform·id="package_telnet-server_and_system_with_kernel"> 
160 ······<cpe-lang:logical-test·operator="AND"·negate="false">166 ······<cpe-lang:logical-test·operator="AND"·negate="false">
161 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-package_telnet-server:def:1"/> 
162 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>167 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>
163 ······</cpe-lang:logical-test>168 ······</cpe-lang:logical-test>
164 ····</cpe-lang:platform>169 ····</cpe-lang:platform>
165 ····<cpe-lang:platform·id="package_iptables">170 ····<cpe-lang:platform·id="package_logrotate">
166 ······<cpe-lang:logical-test·operator="AND"·negate="false">171 ······<cpe-lang:logical-test·operator="AND"·negate="false">
167 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>172 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-package_logrotate:def:1"/>
168 ······</cpe-lang:logical-test>173 ······</cpe-lang:logical-test>
169 ····</cpe-lang:platform>174 ····</cpe-lang:platform>
170 ····<cpe-lang:platform·id="krb5_server_older_than_1_17-18_and_krb5_workstation_older_than_1_17-18">175 ····<cpe-lang:platform·id="not_aarch64_arch_and_not_ppc64le_arch">
171 ······<cpe-lang:logical-test·operator="AND"·negate="false">176 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 177 ········<cpe-lang:logical-test·operator="AND"·negate="true">
172 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-krb5_server_older_than_1_17_18:def:1"/>178 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
 179 ········</cpe-lang:logical-test>
 180 ········<cpe-lang:logical-test·operator="AND"·negate="true">
173 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-krb5_workstation_older_than_1_17_18:def:1"/>181 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_ppc64le:def:1"/>
 182 ········</cpe-lang:logical-test>
174 ······</cpe-lang:logical-test>183 ······</cpe-lang:logical-test>
175 ····</cpe-lang:platform>184 ····</cpe-lang:platform>
176 ····<cpe-lang:platform·id="grub2">185 ····<cpe-lang:platform·id="package_chrony">
Max diff block lines reached; 484275/498015 bytes (97.24%) of diff not shown.
1.71 MB
./usr/share/xml/scap/ssg/content/ssg-rhv4-ds.xml
1.71 MB
./usr/share/xml/scap/ssg/content/ssg-rhv4-ds.xml
    
Offset 19, 27 lines modifiedOffset 19, 27 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhv4-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhv4-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhv4-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhv4-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhv4-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhv4-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhv4-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhv4-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhv4-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhv4-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhv4-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhv4-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhv4-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhv4-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/a:redhat:enterprise_virtualization_manager:4">28 ······<cpe-dict:cpe-item·name="cpe:/a:redhat:enterprise_virtualization_manager:4">
29 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Virtualization·4·Manager</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Virtualization·4·Manager</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml">oval:ssg-installed_app_is_rhv4:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml">oval:ssg-installed_app_is_rhv4:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux:8::hypervisor">32 ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux:8::hypervisor">
33 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Virtualization·4·Host</cpe-dict:title>33 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Virtualization·4·Host</cpe-dict:title>
34 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml">oval:ssg-installed_OS_is_rhv4:def:1</cpe-dict:check>34 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml">oval:ssg-installed_OS_is_rhv4:def:1</cpe-dict:check>
35 ······</cpe-dict:cpe-item>35 ······</cpe-dict:cpe-item>
36 ····</cpe-dict:cpe-list>36 ····</cpe-dict:cpe-list>
37 ··</ds:component>37 ··</ds:component>
38 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhv4-xccdf.xml"·timestamp="2025-02-28T20:08:00">38 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhv4-xccdf.xml"·timestamp="2025-03-01T22:08:00">
39 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_RHV-4"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">39 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_RHV-4"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
40 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>40 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
41 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Red·Hat·Virtualization·4</xccdf-1.2:title>41 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Red·Hat·Virtualization·4</xccdf-1.2:title>
42 ······<xccdf-1.2:description>42 ······<xccdf-1.2:description>
43 ········This·guide·presents·a·catalog·of·security-relevant43 ········This·guide·presents·a·catalog·of·security-relevant
44 configuration·settings·for·Red·Hat·Virtualization·4.·It·is·a·rendering·of44 configuration·settings·for·Red·Hat·Virtualization·4.·It·is·a·rendering·of
45 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)45 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 108, 318 lines modifiedOffset 108, 318 lines modified
108 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>108 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
109 ······<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>109 ······<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
110 ······<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>110 ······<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
111 ······<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>111 ······<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
112 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>112 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
113 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>113 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
114 ······<cpe-lang:platform-specification>114 ······<cpe-lang:platform-specification>
 115 ········<cpe-lang:platform·id="not_runtime_kernel_fips_enabled_and_system_with_kernel">
115 ········<cpe-lang:platform·id="package_libuser"> 
116 ··········<cpe-lang:logical-test·operator="AND"·negate="false"> 
117 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-package_libuser:def:1"/> 
118 ··········</cpe-lang:logical-test> 
119 ········</cpe-lang:platform> 
120 ········<cpe-lang:platform·id="not_bootc"> 
121 ··········<cpe-lang:logical-test·operator="AND"·negate="true"> 
122 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-bootc:def:1"/> 
123 ··········</cpe-lang:logical-test> 
124 ········</cpe-lang:platform> 
125 ········<cpe-lang:platform·id="machine"> 
126 ··········<cpe-lang:logical-test·operator="AND"·negate="false">116 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 117 ············<cpe-lang:logical-test·operator="AND"·negate="true">
 118 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-runtime_kernel_fips_enabled:def:1"/>
 119 ············</cpe-lang:logical-test>
127 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>120 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
128 ··········</cpe-lang:logical-test>121 ··········</cpe-lang:logical-test>
129 ········</cpe-lang:platform>122 ········</cpe-lang:platform>
130 ········<cpe-lang:platform·id="package_pam">123 ········<cpe-lang:platform·id="package_polkit">
131 ··········<cpe-lang:logical-test·operator="AND"·negate="false">124 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
132 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>125 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-package_polkit:def:1"/>
133 ··········</cpe-lang:logical-test>126 ··········</cpe-lang:logical-test>
134 ········</cpe-lang:platform>127 ········</cpe-lang:platform>
135 ········<cpe-lang:platform·id="package_autofs_and_system_with_kernel">128 ········<cpe-lang:platform·id="package_autofs_and_system_with_kernel">
136 ··········<cpe-lang:logical-test·operator="AND"·negate="false">129 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
137 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>130 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>
138 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>131 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
139 ··········</cpe-lang:logical-test>132 ··········</cpe-lang:logical-test>
140 ········</cpe-lang:platform>133 ········</cpe-lang:platform>
141 ········<cpe-lang:platform·id="uefi">134 ········<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">
142 ··········<cpe-lang:logical-test·operator="AND"·negate="false">135 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 136 ············<cpe-lang:logical-test·operator="AND"·negate="true">
 137 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
 138 ············</cpe-lang:logical-test>
 139 ············<cpe-lang:logical-test·operator="AND"·negate="true">
143 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>140 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
 141 ············</cpe-lang:logical-test>
 142 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
144 ··········</cpe-lang:logical-test>143 ··········</cpe-lang:logical-test>
145 ········</cpe-lang:platform>144 ········</cpe-lang:platform>
146 ········<cpe-lang:platform·id="package_telnet-server_and_system_with_kernel">145 ········<cpe-lang:platform·id="ipv6_enabled">
147 ··········<cpe-lang:logical-test·operator="AND"·negate="false">146 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
148 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-package_telnet-server:def:1"/> 
149 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>147 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-ipv6_enabled:def:1"/>
150 ··········</cpe-lang:logical-test>148 ··········</cpe-lang:logical-test>
151 ········</cpe-lang:platform>149 ········</cpe-lang:platform>
152 ········<cpe-lang:platform·id="package_iptables">150 ········<cpe-lang:platform·id="package_gdm">
153 ··········<cpe-lang:logical-test·operator="AND"·negate="false">151 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
154 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>152 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-package_gdm:def:1"/>
155 ··········</cpe-lang:logical-test>153 ··········</cpe-lang:logical-test>
156 ········</cpe-lang:platform>154 ········</cpe-lang:platform>
157 ········<cpe-lang:platform·id="grub2">155 ········<cpe-lang:platform·id="package_rsyslog">
158 ··········<cpe-lang:logical-test·operator="AND"·negate="false">156 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
159 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>157 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>
160 ··········</cpe-lang:logical-test>158 ··········</cpe-lang:logical-test>
161 ········</cpe-lang:platform>159 ········</cpe-lang:platform>
162 ········<cpe-lang:platform·id="package_sssd">160 ········<cpe-lang:platform·id="not_osbuild_and_system_with_kernel">
163 ··········<cpe-lang:logical-test·operator="AND"·negate="false">161 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 162 ············<cpe-lang:logical-test·operator="AND"·negate="true">
164 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-package_sssd:def:1"/>163 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_osbuild:def:1"/>
 164 ············</cpe-lang:logical-test>
 165 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
165 ··········</cpe-lang:logical-test>166 ··········</cpe-lang:logical-test>
166 ········</cpe-lang:platform>167 ········</cpe-lang:platform>
167 ········<cpe-lang:platform·id="wifi-iface">168 ········<cpe-lang:platform·id="package_chrony_or_package_ntp">
168 ··········<cpe-lang:logical-test·operator="AND"·negate="false">169 ··········<cpe-lang:logical-test·operator="OR"·negate="false">
 170 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
169 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_wifi_interface:def:1"/>171 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-package_ntp:def:1"/>
170 ··········</cpe-lang:logical-test>172 ··········</cpe-lang:logical-test>
171 ········</cpe-lang:platform>173 ········</cpe-lang:platform>
172 ········<cpe-lang:platform·id="package_rsyslog">174 ········<cpe-lang:platform·id="uefi">
173 ··········<cpe-lang:logical-test·operator="AND"·negate="false">175 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
174 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>176 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>
175 ··········</cpe-lang:logical-test>177 ··········</cpe-lang:logical-test>
176 ········</cpe-lang:platform>178 ········</cpe-lang:platform>
177 ········<cpe-lang:platform·id="package_yum">179 ········<cpe-lang:platform·id="package_logrotate">
178 ··········<cpe-lang:logical-test·operator="AND"·negate="false">180 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
179 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-package_yum:def:1"/>181 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-package_logrotate:def:1"/>
180 ··········</cpe-lang:logical-test>182 ··········</cpe-lang:logical-test>
181 ········</cpe-lang:platform>183 ········</cpe-lang:platform>
182 ········<cpe-lang:platform·id="package_systemd">184 ········<cpe-lang:platform·id="package_chrony">
183 ··········<cpe-lang:logical-test·operator="AND"·negate="false">185 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
184 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>186 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
185 ··········</cpe-lang:logical-test>187 ··········</cpe-lang:logical-test>
186 ········</cpe-lang:platform>188 ········</cpe-lang:platform>
187 ········<cpe-lang:platform·id="package_polkit">189 ········<cpe-lang:platform·id="package_sssd">
188 ··········<cpe-lang:logical-test·operator="AND"·negate="false">190 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
189 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-package_polkit:def:1"/>191 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-package_sssd:def:1"/>
190 ··········</cpe-lang:logical-test>192 ··········</cpe-lang:logical-test>
191 ········</cpe-lang:platform>193 ········</cpe-lang:platform>
192 ········<cpe-lang:platform·id="mount_var">194 ········<cpe-lang:platform·id="package_ufw_and_system_with_kernel">
Max diff block lines reached; 1781693/1794890 bytes (99.26%) of diff not shown.
1.49 MB
./usr/share/xml/scap/ssg/content/ssg-rhv4-ocil.xml
1.49 MB
./usr/share/xml/scap/ssg/content/ssg-rhv4-ocil.xml
Ordering differences only
    
Offset 3, 9299 lines modifiedOffset 3, 9299 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_binfmt_misc_ocil:questionnaire:1"> 
11 ······<ocil:title>Disable·kernel·support·for·MISC·binaries</ocil:title> 
12 ······<ocil:actions> 
13 ········<ocil:test_action_ref>ocil:ssg-kernel_config_binfmt_misc_action:testaction:1</ocil:test_action_ref> 
14 ······</ocil:actions> 
15 ····</ocil:questionnaire> 
16 ····<ocil:questionnaire·id="ocil:ssg-package_tftp-server_removed_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_x11_forwarding_ocil:questionnaire:1">
17 ······<ocil:title>Uninstall·tftp-server·Package</ocil:title>11 ······<ocil:title>Disable·X11·Forwarding</ocil:title>
18 ······<ocil:actions>12 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-package_tftp-server_removed_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_x11_forwarding_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>14 ······</ocil:actions>
21 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_unauthorized_world_writable_ocil:questionnaire:1"> 
23 ······<ocil:title>Ensure·No·World-Writable·Files·Exist</ocil:title>16 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_last_change_is_in_past_ocil:questionnaire:1">
 17 ······<ocil:title>Ensure·all·users·last·password·change·date·is·in·the·past</ocil:title>
24 ······<ocil:actions>18 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-file_permissions_unauthorized_world_writable_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-accounts_password_last_change_is_in_past_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>20 ······</ocil:actions>
27 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-audit_privileged_commands_poweroff_ocil:questionnaire:1"> 
29 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·poweroff</ocil:title>22 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_sshd_pub_key_ocil:questionnaire:1">
 23 ······<ocil:title>Verify·Permissions·on·SSH·Server·Public·*.pub·Key·Files</ocil:title>
30 ······<ocil:actions>24 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-audit_privileged_commands_poweroff_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-file_permissions_sshd_pub_key_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>26 ······</ocil:actions>
33 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_var_log_messages_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_issue_net_ocil:questionnaire:1">
35 ······<ocil:title>Verify·Group·Who·Owns·/var/log/messages·File</ocil:title>29 ······<ocil:title>Verify·permissions·on·System·Login·Banner·for·Remote·Connections</ocil:title>
36 ······<ocil:actions>30 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_var_log_messages_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-file_permissions_etc_issue_net_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>32 ······</ocil:actions>
39 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-file_owner_grub2_cfg_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_page_table_isolation_ocil:questionnaire:1">
41 ······<ocil:title>Verify·/boot/grub2/grub.cfg·User·Ownership</ocil:title>35 ······<ocil:title>Remove·the·kernel·mapping·in·user·mode</ocil:title>
42 ······<ocil:actions>36 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-file_owner_grub2_cfg_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-kernel_config_page_table_isolation_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>38 ······</ocil:actions>
45 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-sebool_login_console_enabled_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-service_zebra_disabled_ocil:questionnaire:1">
47 ······<ocil:title>Enable·the·login_console_enabled·SELinux·Boolean</ocil:title>41 ······<ocil:title>Disable·Quagga·Service</ocil:title>
48 ······<ocil:actions>42 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-sebool_login_console_enabled_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-service_zebra_disabled_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>44 ······</ocil:actions>
51 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-sysctl_kernel_kptr_restrict_ocil:questionnaire:1"> 
53 ······<ocil:title>Restrict·Exposed·Kernel·Pointer·Addresses·Access</ocil:title>46 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_openat_ocil:questionnaire:1">
 47 ······<ocil:title>Record·Unsuccessful·Access·Attempts·to·Files·-·openat</ocil:title>
54 ······<ocil:actions>48 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-sysctl_kernel_kptr_restrict_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_openat_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>50 ······</ocil:actions>
57 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-install_mcafee_antivirus_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_grub2_cfg_ocil:questionnaire:1">
59 ······<ocil:title>Install·McAfee·Virus·Scanning·Software</ocil:title>53 ······<ocil:title>Verify·/boot/grub2/grub.cfg·Permissions</ocil:title>
60 ······<ocil:actions>54 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-install_mcafee_antivirus_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-file_permissions_grub2_cfg_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>56 ······</ocil:actions>
63 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_flush_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-network_configure_name_resolution_ocil:questionnaire:1">
65 ······<ocil:title>Configure·auditd·flush·priority</ocil:title>59 ······<ocil:title>Configure·Multiple·DNS·Servers·in·/etc/resolv.conf</ocil:title>
66 ······<ocil:actions>60 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-auditd_data_retention_flush_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-network_configure_name_resolution_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>62 ······</ocil:actions>
69 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_maxclassrepeat_ocil:questionnaire:1"> 
71 ······<ocil:title>Ensure·PAM·Enforces·Password·Requirements·-·Maximum·Consecutive·Repeating·Characters·from·Same·Character·Class</ocil:title>64 ····<ocil:questionnaire·id="ocil:ssg-sshd_enable_strictmodes_ocil:questionnaire:1">
 65 ······<ocil:title>Enable·Use·of·Strict·Mode·Checking</ocil:title>
72 ······<ocil:actions>66 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-accounts_password_pam_maxclassrepeat_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-sshd_enable_strictmodes_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>68 ······</ocil:actions>
75 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-no_user_host_based_files_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-account_unique_name_ocil:questionnaire:1">
77 ······<ocil:title>Remove·User·Host-Based·Authentication·Files</ocil:title>71 ······<ocil:title>Ensure·All·Accounts·on·the·System·Have·Unique·Names</ocil:title>
78 ······<ocil:actions>72 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-no_user_host_based_files_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-account_unique_name_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>74 ······</ocil:actions>
81 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_successful_file_modification_chown_ocil:questionnaire:1"> 
83 ······<ocil:title>Record·Successful·Ownership·Changes·to·Files·-·chown</ocil:title>76 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_pwhistory_remember_system_auth_ocil:questionnaire:1">
 77 ······<ocil:title>Limit·Password·Reuse:·system-auth</ocil:title>
84 ······<ocil:actions>78 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-audit_rules_successful_file_modification_chown_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-accounts_password_pam_pwhistory_remember_system_auth_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>80 ······</ocil:actions>
87 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-accounts_users_home_files_permissions_ocil:questionnaire:1"> 
89 ······<ocil:title>All·User·Files·and·Directories·In·The·Home·Directory·Must·Have·Mode·0750·Or·Less·Permissive</ocil:title>82 ····<ocil:questionnaire·id="ocil:ssg-set_password_hashing_algorithm_systemauth_ocil:questionnaire:1">
 83 ······<ocil:title>Set·PAM''s·Password·Hashing·Algorithm</ocil:title>
90 ······<ocil:actions>84 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-accounts_users_home_files_permissions_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-set_password_hashing_algorithm_systemauth_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>86 ······</ocil:actions>
93 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_fsetxattr_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-aide_periodic_cron_checking_ocil:questionnaire:1">
95 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·fsetxattr</ocil:title>89 ······<ocil:title>Configure·Periodic·Execution·of·AIDE</ocil:title>
96 ······<ocil:actions>90 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_fsetxattr_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-aide_periodic_cron_checking_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>92 ······</ocil:actions>
99 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-package_audit_installed_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-package_binutils_installed_ocil:questionnaire:1">
101 ······<ocil:title>Ensure·the·audit·Subsystem·is·Installed</ocil:title>95 ······<ocil:title>Install·binutils·Package</ocil:title>
102 ······<ocil:actions>96 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-package_audit_installed_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-package_binutils_installed_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>98 ······</ocil:actions>
105 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-service_telnet_disabled_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-sudo_remove_no_authenticate_ocil:questionnaire:1">
107 ······<ocil:title>Disable·telnet·Service</ocil:title>101 ······<ocil:title>Ensure·Users·Re-Authenticate·for·Privilege·Escalation·-·sudo·!authenticate</ocil:title>
108 ······<ocil:actions>102 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-service_telnet_disabled_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-sudo_remove_no_authenticate_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>104 ······</ocil:actions>
111 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_bug_ocil:questionnaire:1">106 ····<ocil:questionnaire·id="ocil:ssg-sebool_xguest_mount_media_ocil:questionnaire:1">
113 ······<ocil:title>Enable·support·for·BUG()</ocil:title>107 ······<ocil:title>Disable·the·xguest_mount_media·SELinux·Boolean</ocil:title>
114 ······<ocil:actions>108 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-kernel_config_bug_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-sebool_xguest_mount_media_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>110 ······</ocil:actions>
117 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_sshd_private_key_ocil:questionnaire:1"> 
119 ······<ocil:title>Verify·Permissions·on·SSH·Server·Private·*_key·Key·Files</ocil:title>112 ····<ocil:questionnaire·id="ocil:ssg-install_mcafee_antivirus_ocil:questionnaire:1">
 113 ······<ocil:title>Install·McAfee·Virus·Scanning·Software</ocil:title>
120 ······<ocil:actions>114 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-file_permissions_sshd_private_key_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-install_mcafee_antivirus_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>116 ······</ocil:actions>
Max diff block lines reached; 1554649/1566951 bytes (99.21%) of diff not shown.
145 KB
./usr/share/xml/scap/ssg/content/ssg-rhv4-xccdf.xml
145 KB
./usr/share/xml/scap/ssg/content/ssg-rhv4-xccdf.xml
Ordering differences only
    
Offset 71, 318 lines modifiedOffset 71, 318 lines modified
71 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>71 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
72 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>72 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
73 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>73 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
74 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>74 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
75 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>75 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
77 ··<cpe-lang:platform-specification>77 ··<cpe-lang:platform-specification>
 78 ····<cpe-lang:platform·id="not_runtime_kernel_fips_enabled_and_system_with_kernel">
78 ····<cpe-lang:platform·id="package_libuser"> 
79 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
80 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-package_libuser:def:1"/> 
81 ······</cpe-lang:logical-test> 
82 ····</cpe-lang:platform> 
83 ····<cpe-lang:platform·id="not_bootc"> 
84 ······<cpe-lang:logical-test·operator="AND"·negate="true"> 
85 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-bootc:def:1"/> 
86 ······</cpe-lang:logical-test> 
87 ····</cpe-lang:platform> 
88 ····<cpe-lang:platform·id="machine"> 
89 ······<cpe-lang:logical-test·operator="AND"·negate="false">79 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 80 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 81 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-runtime_kernel_fips_enabled:def:1"/>
 82 ········</cpe-lang:logical-test>
90 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>83 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
91 ······</cpe-lang:logical-test>84 ······</cpe-lang:logical-test>
92 ····</cpe-lang:platform>85 ····</cpe-lang:platform>
93 ····<cpe-lang:platform·id="package_pam">86 ····<cpe-lang:platform·id="package_polkit">
94 ······<cpe-lang:logical-test·operator="AND"·negate="false">87 ······<cpe-lang:logical-test·operator="AND"·negate="false">
95 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>88 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-package_polkit:def:1"/>
96 ······</cpe-lang:logical-test>89 ······</cpe-lang:logical-test>
97 ····</cpe-lang:platform>90 ····</cpe-lang:platform>
98 ····<cpe-lang:platform·id="package_autofs_and_system_with_kernel">91 ····<cpe-lang:platform·id="package_autofs_and_system_with_kernel">
99 ······<cpe-lang:logical-test·operator="AND"·negate="false">92 ······<cpe-lang:logical-test·operator="AND"·negate="false">
100 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>93 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>
101 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>94 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
102 ······</cpe-lang:logical-test>95 ······</cpe-lang:logical-test>
103 ····</cpe-lang:platform>96 ····</cpe-lang:platform>
104 ····<cpe-lang:platform·id="uefi">97 ····<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">
105 ······<cpe-lang:logical-test·operator="AND"·negate="false">98 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 99 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 100 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
 101 ········</cpe-lang:logical-test>
 102 ········<cpe-lang:logical-test·operator="AND"·negate="true">
106 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>103 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
 104 ········</cpe-lang:logical-test>
 105 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
107 ······</cpe-lang:logical-test>106 ······</cpe-lang:logical-test>
108 ····</cpe-lang:platform>107 ····</cpe-lang:platform>
109 ····<cpe-lang:platform·id="package_telnet-server_and_system_with_kernel">108 ····<cpe-lang:platform·id="ipv6_enabled">
110 ······<cpe-lang:logical-test·operator="AND"·negate="false">109 ······<cpe-lang:logical-test·operator="AND"·negate="false">
111 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-package_telnet-server:def:1"/> 
112 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>110 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-ipv6_enabled:def:1"/>
113 ······</cpe-lang:logical-test>111 ······</cpe-lang:logical-test>
114 ····</cpe-lang:platform>112 ····</cpe-lang:platform>
115 ····<cpe-lang:platform·id="package_iptables">113 ····<cpe-lang:platform·id="package_gdm">
116 ······<cpe-lang:logical-test·operator="AND"·negate="false">114 ······<cpe-lang:logical-test·operator="AND"·negate="false">
117 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>115 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-package_gdm:def:1"/>
118 ······</cpe-lang:logical-test>116 ······</cpe-lang:logical-test>
119 ····</cpe-lang:platform>117 ····</cpe-lang:platform>
120 ····<cpe-lang:platform·id="grub2">118 ····<cpe-lang:platform·id="package_rsyslog">
121 ······<cpe-lang:logical-test·operator="AND"·negate="false">119 ······<cpe-lang:logical-test·operator="AND"·negate="false">
122 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>120 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>
123 ······</cpe-lang:logical-test>121 ······</cpe-lang:logical-test>
124 ····</cpe-lang:platform>122 ····</cpe-lang:platform>
125 ····<cpe-lang:platform·id="package_sssd">123 ····<cpe-lang:platform·id="not_osbuild_and_system_with_kernel">
126 ······<cpe-lang:logical-test·operator="AND"·negate="false">124 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 125 ········<cpe-lang:logical-test·operator="AND"·negate="true">
127 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-package_sssd:def:1"/>126 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_osbuild:def:1"/>
 127 ········</cpe-lang:logical-test>
 128 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
128 ······</cpe-lang:logical-test>129 ······</cpe-lang:logical-test>
129 ····</cpe-lang:platform>130 ····</cpe-lang:platform>
130 ····<cpe-lang:platform·id="wifi-iface">131 ····<cpe-lang:platform·id="package_chrony_or_package_ntp">
131 ······<cpe-lang:logical-test·operator="AND"·negate="false">132 ······<cpe-lang:logical-test·operator="OR"·negate="false">
 133 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
132 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_wifi_interface:def:1"/>134 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-package_ntp:def:1"/>
133 ······</cpe-lang:logical-test>135 ······</cpe-lang:logical-test>
134 ····</cpe-lang:platform>136 ····</cpe-lang:platform>
135 ····<cpe-lang:platform·id="package_rsyslog">137 ····<cpe-lang:platform·id="uefi">
136 ······<cpe-lang:logical-test·operator="AND"·negate="false">138 ······<cpe-lang:logical-test·operator="AND"·negate="false">
137 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>139 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>
138 ······</cpe-lang:logical-test>140 ······</cpe-lang:logical-test>
139 ····</cpe-lang:platform>141 ····</cpe-lang:platform>
140 ····<cpe-lang:platform·id="package_yum">142 ····<cpe-lang:platform·id="package_logrotate">
141 ······<cpe-lang:logical-test·operator="AND"·negate="false">143 ······<cpe-lang:logical-test·operator="AND"·negate="false">
142 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-package_yum:def:1"/>144 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-package_logrotate:def:1"/>
143 ······</cpe-lang:logical-test>145 ······</cpe-lang:logical-test>
144 ····</cpe-lang:platform>146 ····</cpe-lang:platform>
145 ····<cpe-lang:platform·id="package_systemd">147 ····<cpe-lang:platform·id="package_chrony">
146 ······<cpe-lang:logical-test·operator="AND"·negate="false">148 ······<cpe-lang:logical-test·operator="AND"·negate="false">
147 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>149 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
148 ······</cpe-lang:logical-test>150 ······</cpe-lang:logical-test>
149 ····</cpe-lang:platform>151 ····</cpe-lang:platform>
150 ····<cpe-lang:platform·id="package_polkit">152 ····<cpe-lang:platform·id="package_sssd">
151 ······<cpe-lang:logical-test·operator="AND"·negate="false">153 ······<cpe-lang:logical-test·operator="AND"·negate="false">
152 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-package_polkit:def:1"/>154 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-package_sssd:def:1"/>
153 ······</cpe-lang:logical-test>155 ······</cpe-lang:logical-test>
154 ····</cpe-lang:platform>156 ····</cpe-lang:platform>
155 ····<cpe-lang:platform·id="mount_var">157 ····<cpe-lang:platform·id="package_ufw_and_system_with_kernel">
156 ······<cpe-lang:logical-test·operator="AND"·negate="false">158 ······<cpe-lang:logical-test·operator="AND"·negate="false">
157 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var:def:1"/>159 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
 160 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
158 ······</cpe-lang:logical-test>161 ······</cpe-lang:logical-test>
159 ····</cpe-lang:platform>162 ····</cpe-lang:platform>
160 ····<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">163 ····<cpe-lang:platform·id="package_firewalld">
161 ······<cpe-lang:logical-test·operator="AND"·negate="false">164 ······<cpe-lang:logical-test·operator="AND"·negate="false">
162 ········<cpe-lang:logical-test·operator="AND"·negate="true"> 
163 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/> 
164 ········</cpe-lang:logical-test> 
165 ········<cpe-lang:logical-test·operator="AND"·negate="true"> 
166 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>165 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>
167 ········</cpe-lang:logical-test> 
168 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/> 
169 ······</cpe-lang:logical-test>166 ······</cpe-lang:logical-test>
170 ····</cpe-lang:platform>167 ····</cpe-lang:platform>
171 ····<cpe-lang:platform·id="nfs_mount_defined">168 ····<cpe-lang:platform·id="package_rsh-server">
172 ······<cpe-lang:logical-test·operator="AND"·negate="false">169 ······<cpe-lang:logical-test·operator="AND"·negate="false">
173 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-nfs_mount_defined:def:1"/>170 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-package_rsh-server:def:1"/>
174 ······</cpe-lang:logical-test>171 ······</cpe-lang:logical-test>
175 ····</cpe-lang:platform>172 ····</cpe-lang:platform>
176 ····<cpe-lang:platform·id="package_firewalld">173 ····<cpe-lang:platform·id="mount_srv">
177 ······<cpe-lang:logical-test·operator="AND"·negate="false">174 ······<cpe-lang:logical-test·operator="AND"·negate="false">
178 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>175 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_srv:def:1"/>
179 ······</cpe-lang:logical-test>176 ······</cpe-lang:logical-test>
180 ····</cpe-lang:platform>177 ····</cpe-lang:platform>
181 ····<cpe-lang:platform·id="non-uefi">178 ····<cpe-lang:platform·id="package_systemd">
182 ······<cpe-lang:logical-test·operator="AND"·negate="false">179 ······<cpe-lang:logical-test·operator="AND"·negate="false">
Max diff block lines reached; 134982/148527 bytes (90.88%) of diff not shown.
1.83 MB
./usr/share/xml/scap/ssg/content/ssg-sle12-ds.xml
1.83 MB
./usr/share/xml/scap/ssg/content/ssg-sle12-ds.xml
    
Offset 21, 27 lines modifiedOffset 21, 27 lines modified
21 ····<ds:checks>21 ····<ds:checks>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-sle12-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-sle12-oval.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-sle12-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-sle12-oval.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-sle12-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-sle12-ocil.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-sle12-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-sle12-ocil.xml"/>
24 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-sle12-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-sle12-cpe-oval.xml"/>24 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-sle12-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-sle12-cpe-oval.xml"/>
25 ······<ds:component-ref·id="scap_org.open-scap_cref_pub-projects-security-oval-suse.linux.enterprise.12-patch.xml.bz2"·xlink:href="https://ftp.suse.com/pub/projects/security/oval/suse.linux.enterprise.12-patch.xml.bz2"/>25 ······<ds:component-ref·id="scap_org.open-scap_cref_pub-projects-security-oval-suse.linux.enterprise.12-patch.xml.bz2"·xlink:href="https://ftp.suse.com/pub/projects/security/oval/suse.linux.enterprise.12-patch.xml.bz2"/>
26 ····</ds:checks>26 ····</ds:checks>
27 ··</ds:data-stream>27 ··</ds:data-stream>
28 ··<ds:component·id="scap_org.open-scap_comp_ssg-sle12-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">28 ··<ds:component·id="scap_org.open-scap_comp_ssg-sle12-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
29 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">29 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
30 ······<cpe-dict:cpe-item·name="cpe:/o:suse:linux_enterprise_desktop:12">30 ······<cpe-dict:cpe-item·name="cpe:/o:suse:linux_enterprise_desktop:12">
31 ········<cpe-dict:title·xml:lang="en-us">SUSE·Linux·Enterprise·Desktop·12</cpe-dict:title>31 ········<cpe-dict:title·xml:lang="en-us">SUSE·Linux·Enterprise·Desktop·12</cpe-dict:title>
32 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml">oval:ssg-installed_OS_is_sle12:def:1</cpe-dict:check>32 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml">oval:ssg-installed_OS_is_sle12:def:1</cpe-dict:check>
33 ······</cpe-dict:cpe-item>33 ······</cpe-dict:cpe-item>
34 ······<cpe-dict:cpe-item·name="cpe:/o:suse:linux_enterprise_server:12">34 ······<cpe-dict:cpe-item·name="cpe:/o:suse:linux_enterprise_server:12">
35 ········<cpe-dict:title·xml:lang="en-us">SUSE·Linux·Enterprise·Server·12</cpe-dict:title>35 ········<cpe-dict:title·xml:lang="en-us">SUSE·Linux·Enterprise·Server·12</cpe-dict:title>
36 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml">oval:ssg-installed_OS_is_sle12:def:1</cpe-dict:check>36 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml">oval:ssg-installed_OS_is_sle12:def:1</cpe-dict:check>
37 ······</cpe-dict:cpe-item>37 ······</cpe-dict:cpe-item>
38 ····</cpe-dict:cpe-list>38 ····</cpe-dict:cpe-list>
39 ··</ds:component>39 ··</ds:component>
40 ··<ds:component·id="scap_org.open-scap_comp_ssg-sle12-xccdf.xml"·timestamp="2025-02-28T20:08:00">40 ··<ds:component·id="scap_org.open-scap_comp_ssg-sle12-xccdf.xml"·timestamp="2025-03-01T22:08:00">
41 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_SLE-12"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">41 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_SLE-12"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
42 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>42 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
43 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·SUSE·Linux·Enterprise·12</xccdf-1.2:title>43 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·SUSE·Linux·Enterprise·12</xccdf-1.2:title>
44 ······<xccdf-1.2:description>44 ······<xccdf-1.2:description>
45 ········This·guide·presents·a·catalog·of·security-relevant45 ········This·guide·presents·a·catalog·of·security-relevant
46 configuration·settings·for·SUSE·Linux·Enterprise·12.·It·is·a·rendering·of46 configuration·settings·for·SUSE·Linux·Enterprise·12.·It·is·a·rendering·of
47 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)47 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 111, 385 lines modifiedOffset 111, 385 lines modified
111 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>111 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
112 ······<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>112 ······<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
113 ······<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>113 ······<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
114 ······<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>114 ······<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
115 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>115 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
116 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>116 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
117 ······<cpe-lang:platform-specification>117 ······<cpe-lang:platform-specification>
 118 ········<cpe-lang:platform·id="not_aarch64_arch_and_not_ppc64le_arch_and_system_with_kernel">
118 ········<cpe-lang:platform·id="package_aide_and_package_systemd"> 
119 ··········<cpe-lang:logical-test·operator="AND"·negate="false"> 
120 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-package_aide:def:1"/> 
121 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/> 
122 ··········</cpe-lang:logical-test> 
123 ········</cpe-lang:platform> 
124 ········<cpe-lang:platform·id="package_libuser"> 
125 ··········<cpe-lang:logical-test·operator="AND"·negate="false"> 
126 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-package_libuser:def:1"/> 
127 ··········</cpe-lang:logical-test> 
128 ········</cpe-lang:platform> 
129 ········<cpe-lang:platform·id="not_bootc"> 
130 ··········<cpe-lang:logical-test·operator="AND"·negate="true"> 
131 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-bootc:def:1"/> 
132 ··········</cpe-lang:logical-test> 
133 ········</cpe-lang:platform> 
134 ········<cpe-lang:platform·id="machine"> 
135 ··········<cpe-lang:logical-test·operator="AND"·negate="false"> 
136 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/> 
137 ··········</cpe-lang:logical-test> 
138 ········</cpe-lang:platform> 
139 ········<cpe-lang:platform·id="package_squid_and_system_with_kernel"> 
140 ··········<cpe-lang:logical-test·operator="AND"·negate="false">119 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 120 ············<cpe-lang:logical-test·operator="AND"·negate="true">
141 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-package_squid:def:1"/>121 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
 122 ············</cpe-lang:logical-test>
 123 ············<cpe-lang:logical-test·operator="AND"·negate="true">
 124 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_ppc64le:def:1"/>
 125 ············</cpe-lang:logical-test>
142 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>126 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
143 ··········</cpe-lang:logical-test>127 ··········</cpe-lang:logical-test>
144 ········</cpe-lang:platform>128 ········</cpe-lang:platform>
145 ········<cpe-lang:platform·id="package_pam">129 ········<cpe-lang:platform·id="mount_var-tmp">
146 ··········<cpe-lang:logical-test·operator="AND"·negate="false">130 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
147 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>131 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-tmp:def:1"/>
148 ··········</cpe-lang:logical-test>132 ··········</cpe-lang:logical-test>
149 ········</cpe-lang:platform>133 ········</cpe-lang:platform>
150 ········<cpe-lang:platform·id="package_autofs_and_system_with_kernel">134 ········<cpe-lang:platform·id="package_autofs_and_system_with_kernel">
151 ··········<cpe-lang:logical-test·operator="AND"·negate="false">135 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
152 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>136 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>
153 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>137 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
154 ··········</cpe-lang:logical-test>138 ··········</cpe-lang:logical-test>
155 ········</cpe-lang:platform>139 ········</cpe-lang:platform>
156 ········<cpe-lang:platform·id="mount_tmp">140 ········<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">
157 ··········<cpe-lang:logical-test·operator="AND"·negate="false">141 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 142 ············<cpe-lang:logical-test·operator="AND"·negate="true">
 143 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
 144 ············</cpe-lang:logical-test>
 145 ············<cpe-lang:logical-test·operator="AND"·negate="true">
158 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_tmp:def:1"/>146 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
 147 ············</cpe-lang:logical-test>
 148 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
159 ··········</cpe-lang:logical-test>149 ··········</cpe-lang:logical-test>
160 ········</cpe-lang:platform>150 ········</cpe-lang:platform>
161 ········<cpe-lang:platform·id="not_s390x_arch">151 ········<cpe-lang:platform·id="ipv6_enabled">
162 ··········<cpe-lang:logical-test·operator="AND"·negate="false">152 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
163 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>153 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-ipv6_enabled:def:1"/>
164 ··········</cpe-lang:logical-test>154 ··········</cpe-lang:logical-test>
165 ········</cpe-lang:platform>155 ········</cpe-lang:platform>
166 ········<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">156 ········<cpe-lang:platform·id="package_gdm">
167 ··········<cpe-lang:logical-test·operator="AND"·negate="false">157 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
168 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>158 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-package_gdm:def:1"/>
169 ··········</cpe-lang:logical-test>159 ··········</cpe-lang:logical-test>
170 ········</cpe-lang:platform>160 ········</cpe-lang:platform>
171 ········<cpe-lang:platform·id="not_package_chrony_and_not_package_ntp">161 ········<cpe-lang:platform·id="package_rsyslog">
 162 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 163 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>
 164 ··········</cpe-lang:logical-test>
 165 ········</cpe-lang:platform>
 166 ········<cpe-lang:platform·id="not_osbuild_and_system_with_kernel">
172 ··········<cpe-lang:logical-test·operator="AND"·negate="false">167 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
173 ············<cpe-lang:logical-test·operator="AND"·negate="true">168 ············<cpe-lang:logical-test·operator="AND"·negate="true">
174 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/> 
175 ············</cpe-lang:logical-test> 
176 ············<cpe-lang:logical-test·operator="AND"·negate="true"> 
177 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-package_ntp:def:1"/>169 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_osbuild:def:1"/>
178 ············</cpe-lang:logical-test>170 ············</cpe-lang:logical-test>
 171 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
179 ··········</cpe-lang:logical-test>172 ··········</cpe-lang:logical-test>
180 ········</cpe-lang:platform>173 ········</cpe-lang:platform>
 174 ········<cpe-lang:platform·id="package_chrony_or_package_ntp">
 175 ··········<cpe-lang:logical-test·operator="OR"·negate="false">
 176 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
 177 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-package_ntp:def:1"/>
 178 ··········</cpe-lang:logical-test>
 179 ········</cpe-lang:platform>
181 ········<cpe-lang:platform·id="mount_var-log">180 ········<cpe-lang:platform·id="package_bash">
182 ··········<cpe-lang:logical-test·operator="AND"·negate="false">181 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
183 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-log:def:1"/>182 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>
184 ··········</cpe-lang:logical-test>183 ··········</cpe-lang:logical-test>
185 ········</cpe-lang:platform>184 ········</cpe-lang:platform>
Max diff block lines reached; 1908133/1920580 bytes (99.35%) of diff not shown.
1.7 MB
./usr/share/xml/scap/ssg/content/ssg-sle12-ocil.xml
1.7 MB
./usr/share/xml/scap/ssg/content/ssg-sle12-ocil.xml
Ordering differences only
    
Offset 3, 12638 lines modifiedOffset 3, 12840 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-package_logrotate_installed_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-vlock_installed_ocil:questionnaire:1">
 11 ······<ocil:title>Check·that·vlock·is·installed·to·allow·session·locking</ocil:title>
11 ······<ocil:title>Ensure·logrotate·is·Installed</ocil:title> 
12 ······<ocil:actions> 
13 ········<ocil:test_action_ref>ocil:ssg-package_logrotate_installed_action:testaction:1</ocil:test_action_ref> 
14 ······</ocil:actions> 
15 ····</ocil:questionnaire> 
16 ····<ocil:questionnaire·id="ocil:ssg-sudo_custom_logfile_ocil:questionnaire:1"> 
17 ······<ocil:title>Ensure·Sudo·Logfile·Exists·-·sudo·logfile</ocil:title> 
18 ······<ocil:actions>12 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-sudo_custom_logfile_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-vlock_installed_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>14 ······</ocil:actions>
21 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-gnome_gdm_disable_unattended_automatic_login_ocil:questionnaire:1"> 
23 ······<ocil:title>Disable·GDM·Unattended·or·Automatic·Login</ocil:title>16 ····<ocil:questionnaire·id="ocil:ssg-package_openssh-server_removed_ocil:questionnaire:1">
 17 ······<ocil:title>Remove·the·OpenSSH·Server·Package</ocil:title>
24 ······<ocil:actions>18 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-gnome_gdm_disable_unattended_automatic_login_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-package_openssh-server_removed_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>20 ······</ocil:actions>
27 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-accounts_user_dot_group_ownership_ocil:questionnaire:1"> 
29 ······<ocil:title>User·Initialization·Files·Must·Be·Group-Owned·By·The·Primary·Group</ocil:title>22 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_debug_list_ocil:questionnaire:1">
 23 ······<ocil:title>Enable·checks·on·linked·list·manipulation</ocil:title>
30 ······<ocil:actions>24 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-accounts_user_dot_group_ownership_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-kernel_config_debug_list_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>26 ······</ocil:actions>
33 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-partition_for_var_log_audit_ocil:questionnaire:1"> 
35 ······<ocil:title>Ensure·/var/log/audit·Located·On·Separate·Partition</ocil:title>28 ····<ocil:questionnaire·id="ocil:ssg-dir_perms_world_writable_root_owned_ocil:questionnaire:1">
 29 ······<ocil:title>Ensure·All·World-Writable·Directories·Are·Owned·by·root·User</ocil:title>
36 ······<ocil:actions>30 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-partition_for_var_log_audit_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-dir_perms_world_writable_root_owned_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>32 ······</ocil:actions>
39 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-sysctl_kernel_perf_event_paranoid_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_execution_chmod_ocil:questionnaire:1">
41 ······<ocil:title>Disallow·kernel·profiling·by·unprivileged·users</ocil:title>35 ······<ocil:title>Record·Any·Attempts·to·Run·chmod</ocil:title>
42 ······<ocil:actions>36 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-sysctl_kernel_perf_event_paranoid_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-audit_rules_execution_chmod_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>38 ······</ocil:actions>
45 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-dir_ownership_binary_dirs_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-audit_sudo_log_events_ocil:questionnaire:1">
47 ······<ocil:title>Verify·that·System·Executable·Have·Root·Ownership</ocil:title>41 ······<ocil:title>Record·Attempts·to·perform·maintenance·activities</ocil:title>
48 ······<ocil:actions>42 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-dir_ownership_binary_dirs_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-audit_sudo_log_events_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>44 ······</ocil:actions>
51 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-package_rsh-server_removed_ocil:questionnaire:1"> 
53 ······<ocil:title>Uninstall·rsh-server·Package</ocil:title>46 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_log_martians_ocil:questionnaire:1">
 47 ······<ocil:title>Enable·Kernel·Paremeter·to·Log·Martian·Packets·on·all·IPv4·Interfaces·by·Default</ocil:title>
54 ······<ocil:actions>48 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-package_rsh-server_removed_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_log_martians_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>50 ······</ocil:actions>
57 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_tcp_forwarding_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-package_strongswan_installed_ocil:questionnaire:1">
59 ······<ocil:title>Disable·SSH·TCP·Forwarding</ocil:title>53 ······<ocil:title>Install·strongswan·Package</ocil:title>
60 ······<ocil:actions>54 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_tcp_forwarding_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-package_strongswan_installed_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>56 ······</ocil:actions>
63 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_num_logs_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-sysctl_kernel_perf_event_paranoid_ocil:questionnaire:1">
65 ······<ocil:title>Configure·auditd·Number·of·Logs·Retained</ocil:title>59 ······<ocil:title>Disallow·kernel·profiling·by·unprivileged·users</ocil:title>
66 ······<ocil:actions>60 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-auditd_data_retention_num_logs_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-sysctl_kernel_perf_event_paranoid_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>62 ······</ocil:actions>
69 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-grub2_password_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_local_var_log_messages_ocil:questionnaire:1">
71 ······<ocil:title>Set·Boot·Loader·Password·in·grub2</ocil:title>65 ······<ocil:title>Verify·that·local·/var/log/messages·is·not·world-readable</ocil:title>
72 ······<ocil:actions>66 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-grub2_password_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-file_permissions_local_var_log_messages_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>68 ······</ocil:actions>
75 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_all_accept_ra_rtr_pref_ocil:questionnaire:1"> 
77 ······<ocil:title>Configure·Accepting·Router·Preference·in·Router·Advertisements·on·All·IPv6·Interfaces</ocil:title>70 ····<ocil:questionnaire·id="ocil:ssg-file_owner_var_log_messages_ocil:questionnaire:1">
 71 ······<ocil:title>Verify·User·Who·Owns·/var/log/messages·File</ocil:title>
78 ······<ocil:actions>72 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_all_accept_ra_rtr_pref_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-file_owner_var_log_messages_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>74 ······</ocil:actions>
81 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-sudo_add_noexec_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_file_deletion_events_ocil:questionnaire:1">
83 ······<ocil:title>Ensure·Privileged·Escalated·Commands·Cannot·Execute·Other·Commands·-·sudo·NOEXEC</ocil:title>77 ······<ocil:title>Ensure·auditd·Collects·File·Deletion·Events·by·User</ocil:title>
84 ······<ocil:actions>78 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-sudo_add_noexec_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-audit_rules_file_deletion_events_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>80 ······</ocil:actions>
87 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-rsyslog_encrypt_offload_actionsendstreamdriverauthmode_ocil:questionnaire:1"> 
89 ······<ocil:title>Ensure·Rsyslog·Authenticates·Off-Loaded·Audit·Records</ocil:title>82 ····<ocil:questionnaire·id="ocil:ssg-sebool_selinuxuser_execstack_ocil:questionnaire:1">
 83 ······<ocil:title>Disable·the·selinuxuser_execstack·SELinux·Boolean</ocil:title>
90 ······<ocil:actions>84 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-rsyslog_encrypt_offload_actionsendstreamdriverauthmode_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-sebool_selinuxuser_execstack_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>86 ······</ocil:actions>
93 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-package_strongswan_installed_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-accounts_logon_fail_delay_ocil:questionnaire:1">
95 ······<ocil:title>Install·strongswan·Package</ocil:title>89 ······<ocil:title>Ensure·the·Logon·Failure·Delay·is·Set·Correctly·in·login.defs</ocil:title>
96 ······<ocil:actions>90 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-package_strongswan_installed_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-accounts_logon_fail_delay_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>92 ······</ocil:actions>
99 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_proc_kcore_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-no_host_based_files_ocil:questionnaire:1">
101 ······<ocil:title>Disable·support·for·/proc/kkcore</ocil:title>95 ······<ocil:title>Remove·Host-Based·Authentication·Files</ocil:title>
102 ······<ocil:actions>96 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-kernel_config_proc_kcore_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-no_host_based_files_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>98 ······</ocil:actions>
105 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-service_named_disabled_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-sudo_remove_no_authenticate_ocil:questionnaire:1">
107 ······<ocil:title>Disable·named·Service</ocil:title>101 ······<ocil:title>Ensure·Users·Re-Authenticate·for·Privilege·Escalation·-·sudo·!authenticate</ocil:title>
108 ······<ocil:actions>102 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-service_named_disabled_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-sudo_remove_no_authenticate_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>104 ······</ocil:actions>
111 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-sshd_enable_gssapi_auth_ocil:questionnaire:1">106 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_security_ocil:questionnaire:1">
113 ······<ocil:title>Enable·GSSAPI·Authentication</ocil:title>107 ······<ocil:title>Enable·different·security·models</ocil:title>
114 ······<ocil:actions>108 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-sshd_enable_gssapi_auth_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-kernel_config_security_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>110 ······</ocil:actions>
117 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_login_events_faillock_ocil:questionnaire:1">112 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_usergroup_modification_gshadow_ocil:questionnaire:1">
119 ······<ocil:title>Record·Attempts·to·Alter·Logon·and·Logout·Events·-·faillock</ocil:title>113 ······<ocil:title>Record·Events·that·Modify·User/Group·Information·-·/etc/gshadow</ocil:title>
120 ······<ocil:actions>114 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-audit_rules_login_events_faillock_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-audit_rules_usergroup_modification_gshadow_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>116 ······</ocil:actions>
Max diff block lines reached; 1773010/1785200 bytes (99.32%) of diff not shown.
48.4 KB
./usr/share/xml/scap/ssg/content/ssg-sle12-xccdf.xml
48.3 KB
./usr/share/xml/scap/ssg/content/ssg-sle12-xccdf.xml
Ordering differences only
    
Offset 72, 385 lines modifiedOffset 72, 385 lines modified
72 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>72 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
73 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>73 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
74 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>74 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
75 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>75 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
77 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>77 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
78 ··<cpe-lang:platform-specification>78 ··<cpe-lang:platform-specification>
 79 ····<cpe-lang:platform·id="not_aarch64_arch_and_not_ppc64le_arch_and_system_with_kernel">
79 ····<cpe-lang:platform·id="package_aide_and_package_systemd"> 
80 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
81 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-package_aide:def:1"/> 
82 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/> 
83 ······</cpe-lang:logical-test> 
84 ····</cpe-lang:platform> 
85 ····<cpe-lang:platform·id="package_libuser"> 
86 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
87 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-package_libuser:def:1"/> 
88 ······</cpe-lang:logical-test> 
89 ····</cpe-lang:platform> 
90 ····<cpe-lang:platform·id="not_bootc"> 
91 ······<cpe-lang:logical-test·operator="AND"·negate="true"> 
92 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-bootc:def:1"/> 
93 ······</cpe-lang:logical-test> 
94 ····</cpe-lang:platform> 
95 ····<cpe-lang:platform·id="machine"> 
96 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
97 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/> 
98 ······</cpe-lang:logical-test> 
99 ····</cpe-lang:platform> 
100 ····<cpe-lang:platform·id="package_squid_and_system_with_kernel"> 
101 ······<cpe-lang:logical-test·operator="AND"·negate="false">80 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 81 ········<cpe-lang:logical-test·operator="AND"·negate="true">
102 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-package_squid:def:1"/>82 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
 83 ········</cpe-lang:logical-test>
 84 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 85 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_ppc64le:def:1"/>
 86 ········</cpe-lang:logical-test>
103 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>87 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
104 ······</cpe-lang:logical-test>88 ······</cpe-lang:logical-test>
105 ····</cpe-lang:platform>89 ····</cpe-lang:platform>
106 ····<cpe-lang:platform·id="package_pam">90 ····<cpe-lang:platform·id="mount_var-tmp">
107 ······<cpe-lang:logical-test·operator="AND"·negate="false">91 ······<cpe-lang:logical-test·operator="AND"·negate="false">
108 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>92 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-tmp:def:1"/>
109 ······</cpe-lang:logical-test>93 ······</cpe-lang:logical-test>
110 ····</cpe-lang:platform>94 ····</cpe-lang:platform>
111 ····<cpe-lang:platform·id="package_autofs_and_system_with_kernel">95 ····<cpe-lang:platform·id="package_autofs_and_system_with_kernel">
112 ······<cpe-lang:logical-test·operator="AND"·negate="false">96 ······<cpe-lang:logical-test·operator="AND"·negate="false">
113 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>97 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>
114 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>98 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
115 ······</cpe-lang:logical-test>99 ······</cpe-lang:logical-test>
116 ····</cpe-lang:platform>100 ····</cpe-lang:platform>
117 ····<cpe-lang:platform·id="mount_tmp">101 ····<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">
118 ······<cpe-lang:logical-test·operator="AND"·negate="false">102 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 103 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 104 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
 105 ········</cpe-lang:logical-test>
 106 ········<cpe-lang:logical-test·operator="AND"·negate="true">
119 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_tmp:def:1"/>107 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
 108 ········</cpe-lang:logical-test>
 109 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
120 ······</cpe-lang:logical-test>110 ······</cpe-lang:logical-test>
121 ····</cpe-lang:platform>111 ····</cpe-lang:platform>
122 ····<cpe-lang:platform·id="not_s390x_arch">112 ····<cpe-lang:platform·id="ipv6_enabled">
123 ······<cpe-lang:logical-test·operator="AND"·negate="false">113 ······<cpe-lang:logical-test·operator="AND"·negate="false">
124 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>114 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-ipv6_enabled:def:1"/>
125 ······</cpe-lang:logical-test>115 ······</cpe-lang:logical-test>
126 ····</cpe-lang:platform>116 ····</cpe-lang:platform>
127 ····<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">117 ····<cpe-lang:platform·id="package_gdm">
128 ······<cpe-lang:logical-test·operator="AND"·negate="false">118 ······<cpe-lang:logical-test·operator="AND"·negate="false">
129 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>119 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-package_gdm:def:1"/>
130 ······</cpe-lang:logical-test>120 ······</cpe-lang:logical-test>
131 ····</cpe-lang:platform>121 ····</cpe-lang:platform>
132 ····<cpe-lang:platform·id="not_package_chrony_and_not_package_ntp">122 ····<cpe-lang:platform·id="package_rsyslog">
 123 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 124 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>
 125 ······</cpe-lang:logical-test>
 126 ····</cpe-lang:platform>
 127 ····<cpe-lang:platform·id="not_osbuild_and_system_with_kernel">
133 ······<cpe-lang:logical-test·operator="AND"·negate="false">128 ······<cpe-lang:logical-test·operator="AND"·negate="false">
134 ········<cpe-lang:logical-test·operator="AND"·negate="true">129 ········<cpe-lang:logical-test·operator="AND"·negate="true">
135 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/> 
136 ········</cpe-lang:logical-test> 
137 ········<cpe-lang:logical-test·operator="AND"·negate="true"> 
138 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-package_ntp:def:1"/>130 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_osbuild:def:1"/>
139 ········</cpe-lang:logical-test>131 ········</cpe-lang:logical-test>
 132 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
140 ······</cpe-lang:logical-test>133 ······</cpe-lang:logical-test>
141 ····</cpe-lang:platform>134 ····</cpe-lang:platform>
142 ····<cpe-lang:platform·id="mount_var-log">135 ····<cpe-lang:platform·id="package_chrony_or_package_ntp">
 136 ······<cpe-lang:logical-test·operator="OR"·negate="false">
 137 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
 138 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-package_ntp:def:1"/>
 139 ······</cpe-lang:logical-test>
 140 ····</cpe-lang:platform>
 141 ····<cpe-lang:platform·id="package_bash">
143 ······<cpe-lang:logical-test·operator="AND"·negate="false">142 ······<cpe-lang:logical-test·operator="AND"·negate="false">
144 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-log:def:1"/>143 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>
145 ······</cpe-lang:logical-test>144 ······</cpe-lang:logical-test>
146 ····</cpe-lang:platform>145 ····</cpe-lang:platform>
147 ····<cpe-lang:platform·id="uefi">146 ····<cpe-lang:platform·id="uefi">
148 ······<cpe-lang:logical-test·operator="AND"·negate="false">147 ······<cpe-lang:logical-test·operator="AND"·negate="false">
149 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>148 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>
150 ······</cpe-lang:logical-test>149 ······</cpe-lang:logical-test>
151 ····</cpe-lang:platform>150 ····</cpe-lang:platform>
152 ····<cpe-lang:platform·id="package_bash">151 ····<cpe-lang:platform·id="package_logrotate">
153 ······<cpe-lang:logical-test·operator="AND"·negate="false">152 ······<cpe-lang:logical-test·operator="AND"·negate="false">
154 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>153 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-package_logrotate:def:1"/>
155 ······</cpe-lang:logical-test>154 ······</cpe-lang:logical-test>
156 ····</cpe-lang:platform>155 ····</cpe-lang:platform>
157 ····<cpe-lang:platform·id="package_iptables">156 ····<cpe-lang:platform·id="package_chrony">
158 ······<cpe-lang:logical-test·operator="AND"·negate="false">157 ······<cpe-lang:logical-test·operator="AND"·negate="false">
159 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>158 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
160 ······</cpe-lang:logical-test>159 ······</cpe-lang:logical-test>
161 ····</cpe-lang:platform>160 ····</cpe-lang:platform>
162 ····<cpe-lang:platform·id="grub2">161 ····<cpe-lang:platform·id="package_sssd">
163 ······<cpe-lang:logical-test·operator="AND"·negate="false">162 ······<cpe-lang:logical-test·operator="AND"·negate="false">
164 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>163 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-package_sssd:def:1"/>
165 ······</cpe-lang:logical-test>164 ······</cpe-lang:logical-test>
166 ····</cpe-lang:platform>165 ····</cpe-lang:platform>
167 ····<cpe-lang:platform·id="package_sssd">166 ····<cpe-lang:platform·id="package_ufw_and_system_with_kernel">
168 ······<cpe-lang:logical-test·operator="AND"·negate="false">167 ······<cpe-lang:logical-test·operator="AND"·negate="false">
169 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-package_sssd:def:1"/>168 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
 169 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
170 ······</cpe-lang:logical-test>170 ······</cpe-lang:logical-test>
171 ····</cpe-lang:platform>171 ····</cpe-lang:platform>
172 ····<cpe-lang:platform·id="wifi-iface">172 ····<cpe-lang:platform·id="package_firewalld">
173 ······<cpe-lang:logical-test·operator="AND"·negate="false">173 ······<cpe-lang:logical-test·operator="AND"·negate="false">
Max diff block lines reached; 36766/49290 bytes (74.59%) of diff not shown.
1.93 MB
./usr/share/xml/scap/ssg/content/ssg-sle15-ds.xml
1.93 MB
./usr/share/xml/scap/ssg/content/ssg-sle15-ds.xml
    
Offset 21, 27 lines modifiedOffset 21, 27 lines modified
21 ····<ds:checks>21 ····<ds:checks>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-sle15-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-sle15-oval.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-sle15-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-sle15-oval.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-sle15-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-sle15-ocil.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-sle15-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-sle15-ocil.xml"/>
24 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-sle15-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-sle15-cpe-oval.xml"/>24 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-sle15-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-sle15-cpe-oval.xml"/>
25 ······<ds:component-ref·id="scap_org.open-scap_cref_pub-projects-security-oval-suse.linux.enterprise.15-patch.xml.bz2"·xlink:href="https://ftp.suse.com/pub/projects/security/oval/suse.linux.enterprise.15-patch.xml.bz2"/>25 ······<ds:component-ref·id="scap_org.open-scap_cref_pub-projects-security-oval-suse.linux.enterprise.15-patch.xml.bz2"·xlink:href="https://ftp.suse.com/pub/projects/security/oval/suse.linux.enterprise.15-patch.xml.bz2"/>
26 ····</ds:checks>26 ····</ds:checks>
27 ··</ds:data-stream>27 ··</ds:data-stream>
28 ··<ds:component·id="scap_org.open-scap_comp_ssg-sle15-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">28 ··<ds:component·id="scap_org.open-scap_comp_ssg-sle15-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
29 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">29 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
30 ······<cpe-dict:cpe-item·name="cpe:/o:suse:linux_enterprise_desktop:15">30 ······<cpe-dict:cpe-item·name="cpe:/o:suse:linux_enterprise_desktop:15">
31 ········<cpe-dict:title·xml:lang="en-us">SUSE·Linux·Enterprise·Desktop·15</cpe-dict:title>31 ········<cpe-dict:title·xml:lang="en-us">SUSE·Linux·Enterprise·Desktop·15</cpe-dict:title>
32 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml">oval:ssg-installed_OS_is_sle15:def:1</cpe-dict:check>32 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml">oval:ssg-installed_OS_is_sle15:def:1</cpe-dict:check>
33 ······</cpe-dict:cpe-item>33 ······</cpe-dict:cpe-item>
34 ······<cpe-dict:cpe-item·name="cpe:/o:suse:linux_enterprise_server:15">34 ······<cpe-dict:cpe-item·name="cpe:/o:suse:linux_enterprise_server:15">
35 ········<cpe-dict:title·xml:lang="en-us">SUSE·Linux·Enterprise·Server·15</cpe-dict:title>35 ········<cpe-dict:title·xml:lang="en-us">SUSE·Linux·Enterprise·Server·15</cpe-dict:title>
36 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml">oval:ssg-installed_OS_is_sle15:def:1</cpe-dict:check>36 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml">oval:ssg-installed_OS_is_sle15:def:1</cpe-dict:check>
37 ······</cpe-dict:cpe-item>37 ······</cpe-dict:cpe-item>
38 ····</cpe-dict:cpe-list>38 ····</cpe-dict:cpe-list>
39 ··</ds:component>39 ··</ds:component>
40 ··<ds:component·id="scap_org.open-scap_comp_ssg-sle15-xccdf.xml"·timestamp="2025-02-28T20:08:00">40 ··<ds:component·id="scap_org.open-scap_comp_ssg-sle15-xccdf.xml"·timestamp="2025-03-01T22:08:00">
41 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_SLE-15"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">41 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_SLE-15"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
42 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>42 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
43 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·SUSE·Linux·Enterprise·15</xccdf-1.2:title>43 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·SUSE·Linux·Enterprise·15</xccdf-1.2:title>
44 ······<xccdf-1.2:description>44 ······<xccdf-1.2:description>
45 ········This·guide·presents·a·catalog·of·security-relevant45 ········This·guide·presents·a·catalog·of·security-relevant
46 configuration·settings·for·SUSE·Linux·Enterprise·15.·It·is·a·rendering·of46 configuration·settings·for·SUSE·Linux·Enterprise·15.·It·is·a·rendering·of
47 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)47 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 111, 420 lines modifiedOffset 111, 420 lines modified
111 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>111 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
112 ······<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>112 ······<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
113 ······<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>113 ······<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
114 ······<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>114 ······<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
115 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>115 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
116 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>116 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
117 ······<cpe-lang:platform-specification>117 ······<cpe-lang:platform-specification>
 118 ········<cpe-lang:platform·id="not_aarch64_arch_and_not_ppc64le_arch_and_system_with_kernel">
118 ········<cpe-lang:platform·id="package_aide_and_package_systemd"> 
119 ··········<cpe-lang:logical-test·operator="AND"·negate="false"> 
120 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-package_aide:def:1"/> 
121 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/> 
122 ··········</cpe-lang:logical-test> 
123 ········</cpe-lang:platform> 
124 ········<cpe-lang:platform·id="package_libuser"> 
125 ··········<cpe-lang:logical-test·operator="AND"·negate="false"> 
126 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-package_libuser:def:1"/> 
127 ··········</cpe-lang:logical-test> 
128 ········</cpe-lang:platform> 
129 ········<cpe-lang:platform·id="not_bootc"> 
130 ··········<cpe-lang:logical-test·operator="AND"·negate="true"> 
131 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-bootc:def:1"/> 
132 ··········</cpe-lang:logical-test> 
133 ········</cpe-lang:platform> 
134 ········<cpe-lang:platform·id="package_nftables_and_service_disabled_firewalld_and_system_with_kernel"> 
135 ··········<cpe-lang:logical-test·operator="AND"·negate="false"> 
136 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/> 
137 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_firewalld:def:1"/> 
138 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
139 ··········</cpe-lang:logical-test> 
140 ········</cpe-lang:platform> 
141 ········<cpe-lang:platform·id="machine"> 
142 ··········<cpe-lang:logical-test·operator="AND"·negate="false"> 
143 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/> 
144 ··········</cpe-lang:logical-test> 
145 ········</cpe-lang:platform> 
146 ········<cpe-lang:platform·id="package_squid_and_system_with_kernel"> 
147 ··········<cpe-lang:logical-test·operator="AND"·negate="false">119 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 120 ············<cpe-lang:logical-test·operator="AND"·negate="true">
148 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-package_squid:def:1"/>121 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
 122 ············</cpe-lang:logical-test>
 123 ············<cpe-lang:logical-test·operator="AND"·negate="true">
 124 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_ppc64le:def:1"/>
 125 ············</cpe-lang:logical-test>
149 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>126 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
150 ··········</cpe-lang:logical-test>127 ··········</cpe-lang:logical-test>
151 ········</cpe-lang:platform>128 ········</cpe-lang:platform>
152 ········<cpe-lang:platform·id="package_pam">129 ········<cpe-lang:platform·id="mount_var-tmp">
153 ··········<cpe-lang:logical-test·operator="AND"·negate="false">130 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
154 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>131 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-tmp:def:1"/>
155 ··········</cpe-lang:logical-test>132 ··········</cpe-lang:logical-test>
156 ········</cpe-lang:platform>133 ········</cpe-lang:platform>
157 ········<cpe-lang:platform·id="package_autofs_and_system_with_kernel">134 ········<cpe-lang:platform·id="package_autofs_and_system_with_kernel">
158 ··········<cpe-lang:logical-test·operator="AND"·negate="false">135 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
159 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>136 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>
160 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>137 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
161 ··········</cpe-lang:logical-test>138 ··········</cpe-lang:logical-test>
162 ········</cpe-lang:platform>139 ········</cpe-lang:platform>
163 ········<cpe-lang:platform·id="mount_tmp">140 ········<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">
164 ··········<cpe-lang:logical-test·operator="AND"·negate="false">141 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 142 ············<cpe-lang:logical-test·operator="AND"·negate="true">
 143 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
 144 ············</cpe-lang:logical-test>
 145 ············<cpe-lang:logical-test·operator="AND"·negate="true">
165 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_tmp:def:1"/>146 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
 147 ············</cpe-lang:logical-test>
 148 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
166 ··········</cpe-lang:logical-test>149 ··········</cpe-lang:logical-test>
167 ········</cpe-lang:platform>150 ········</cpe-lang:platform>
168 ········<cpe-lang:platform·id="package_firewalld_and_package_nftables_and_system_with_kernel">151 ········<cpe-lang:platform·id="ipv6_enabled">
169 ··········<cpe-lang:logical-test·operator="AND"·negate="false">152 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
170 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/> 
171 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>153 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-ipv6_enabled:def:1"/>
172 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
173 ··········</cpe-lang:logical-test>154 ··········</cpe-lang:logical-test>
174 ········</cpe-lang:platform>155 ········</cpe-lang:platform>
175 ········<cpe-lang:platform·id="not_s390x_arch">156 ········<cpe-lang:platform·id="package_gdm">
176 ··········<cpe-lang:logical-test·operator="AND"·negate="false">157 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
177 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>158 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-package_gdm:def:1"/>
178 ··········</cpe-lang:logical-test>159 ··········</cpe-lang:logical-test>
179 ········</cpe-lang:platform>160 ········</cpe-lang:platform>
180 ········<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">161 ········<cpe-lang:platform·id="package_rsyslog">
181 ··········<cpe-lang:logical-test·operator="AND"·negate="false">162 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
182 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>163 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>
183 ··········</cpe-lang:logical-test>164 ··········</cpe-lang:logical-test>
184 ········</cpe-lang:platform>165 ········</cpe-lang:platform>
185 ········<cpe-lang:platform·id="not_package_chrony_and_not_package_ntp">166 ········<cpe-lang:platform·id="not_osbuild_and_system_with_kernel">
186 ··········<cpe-lang:logical-test·operator="AND"·negate="false">167 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
187 ············<cpe-lang:logical-test·operator="AND"·negate="true">168 ············<cpe-lang:logical-test·operator="AND"·negate="true">
188 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/> 
189 ············</cpe-lang:logical-test> 
190 ············<cpe-lang:logical-test·operator="AND"·negate="true"> 
191 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-package_ntp:def:1"/>169 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_osbuild:def:1"/>
192 ············</cpe-lang:logical-test>170 ············</cpe-lang:logical-test>
 171 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
193 ··········</cpe-lang:logical-test>172 ··········</cpe-lang:logical-test>
194 ········</cpe-lang:platform>173 ········</cpe-lang:platform>
 174 ········<cpe-lang:platform·id="package_chrony_or_package_ntp">
 175 ··········<cpe-lang:logical-test·operator="OR"·negate="false">
Max diff block lines reached; 2011050/2024416 bytes (99.34%) of diff not shown.
1.79 MB
./usr/share/xml/scap/ssg/content/ssg-sle15-ocil.xml
1.79 MB
./usr/share/xml/scap/ssg/content/ssg-sle15-ocil.xml
Ordering differences only
    
Offset 3, 9084 lines modifiedOffset 3, 9084 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-no_legacy_plus_entries_etc_group_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_syn_cookies_ocil:questionnaire:1">
11 ······<ocil:title>Ensure·there·are·no·legacy·+·NIS·entries·in·/etc/group</ocil:title>11 ······<ocil:title>Enable·TCP/IP·syncookie·support</ocil:title>
12 ······<ocil:actions>12 ······<ocil:actions>
13 ········<ocil:test_action_ref>ocil:ssg-no_legacy_plus_entries_etc_group_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-kernel_config_syn_cookies_action:testaction:1</ocil:test_action_ref>
14 ······</ocil:actions>14 ······</ocil:actions>
15 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
16 ····<ocil:questionnaire·id="ocil:ssg-chronyd_configure_pool_and_server_ocil:questionnaire:1"> 
17 ······<ocil:title>Chrony·Configure·Pool·and·Server</ocil:title>16 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_modprobe_ocil:questionnaire:1">
 17 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·modprobe</ocil:title>
18 ······<ocil:actions>18 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-chronyd_configure_pool_and_server_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_modprobe_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>20 ······</ocil:actions>
21 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-file_owner_etc_gshadow_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-package_dhcp_removed_ocil:questionnaire:1">
23 ······<ocil:title>Verify·User·Who·Owns·gshadow·File</ocil:title>23 ······<ocil:title>Uninstall·DHCP·Server·Package</ocil:title>
24 ······<ocil:actions>24 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-file_owner_etc_gshadow_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-package_dhcp_removed_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>26 ······</ocil:actions>
27 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-kernel_module_uvcvideo_disabled_ocil:questionnaire:1"> 
29 ······<ocil:title>Disable·the·uvcvideo·module</ocil:title>28 ····<ocil:questionnaire·id="ocil:ssg-accounts_logon_fail_delay_ocil:questionnaire:1">
 29 ······<ocil:title>Ensure·the·Logon·Failure·Delay·is·Set·Correctly·in·login.defs</ocil:title>
30 ······<ocil:actions>30 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-kernel_module_uvcvideo_disabled_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-accounts_logon_fail_delay_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>32 ······</ocil:actions>
33 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_execution_chmod_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_cron_weekly_ocil:questionnaire:1">
35 ······<ocil:title>Record·Any·Attempts·to·Run·chmod</ocil:title>35 ······<ocil:title>Verify·Permissions·on·cron.weekly</ocil:title>
36 ······<ocil:actions>36 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-audit_rules_execution_chmod_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-file_permissions_cron_weekly_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>38 ······</ocil:actions>
39 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-kernel_module_dccp_disabled_ocil:questionnaire:1"> 
41 ······<ocil:title>Disable·DCCP·Support</ocil:title>40 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_arp_filter_ocil:questionnaire:1">
 41 ······<ocil:title>Configure·ARP·filtering·for·All·IPv4·Interfaces</ocil:title>
42 ······<ocil:actions>42 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-kernel_module_dccp_disabled_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_arp_filter_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>44 ······</ocil:actions>
45 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_fremovexattr_ocil:questionnaire:1"> 
47 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·fremovexattr</ocil:title>46 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_accept_local_ocil:questionnaire:1">
 47 ······<ocil:title>Disable·Accepting·Packets·Routed·Between·Local·Interfaces</ocil:title>
48 ······<ocil:actions>48 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_fremovexattr_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_accept_local_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>50 ······</ocil:actions>
51 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-dconf_gnome_remote_access_credential_prompt_ocil:questionnaire:1"> 
53 ······<ocil:title>Require·Credential·Prompting·for·Remote·Access·in·GNOME3</ocil:title>52 ····<ocil:questionnaire·id="ocil:ssg-sshd_set_loglevel_info_ocil:questionnaire:1">
 53 ······<ocil:title>Set·LogLevel·to·INFO</ocil:title>
54 ······<ocil:actions>54 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-dconf_gnome_remote_access_credential_prompt_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-sshd_set_loglevel_info_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>56 ······</ocil:actions>
57 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_execution_semanage_ocil:questionnaire:1"> 
59 ······<ocil:title>Record·Any·Attempts·to·Run·semanage</ocil:title>58 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_var_log_audit_ocil:questionnaire:1">
 59 ······<ocil:title>System·Audit·Logs·Must·Have·Mode·0640·or·Less·Permissive</ocil:title>
60 ······<ocil:actions>60 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-audit_rules_execution_semanage_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-file_permissions_var_log_audit_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>62 ······</ocil:actions>
63 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_backup_etc_shadow_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-require_emergency_target_auth_ocil:questionnaire:1">
65 ······<ocil:title>Verify·User·Who·Owns·Backup·shadow·File</ocil:title>65 ······<ocil:title>Require·Authentication·for·Emergency·Systemd·Target</ocil:title>
66 ······<ocil:actions>66 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_backup_etc_shadow_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-require_emergency_target_auth_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>68 ······</ocil:actions>
69 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_kernel_module_loading_ocil:questionnaire:1"> 
71 ······<ocil:title>Ensure·auditd·Collects·Information·on·Kernel·Module·Loading·and·Unloading</ocil:title>70 ····<ocil:questionnaire·id="ocil:ssg-accounts_users_home_files_groupownership_ocil:questionnaire:1">
 71 ······<ocil:title>All·User·Files·and·Directories·In·The·Home·Directory·Must·Be·Group-Owned·By·The·Primary·Group</ocil:title>
72 ······<ocil:actions>72 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-audit_rules_kernel_module_loading_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-accounts_users_home_files_groupownership_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>74 ······</ocil:actions>
75 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-package_audit-libs_installed_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-package_tcp_wrappers_removed_ocil:questionnaire:1">
77 ······<ocil:title>Ensure·the·libaudit1·package·as·a·part·of·audit·Subsystem·is·Installed</ocil:title>77 ······<ocil:title>Uninstall·tcpd·Package</ocil:title>
78 ······<ocil:actions>78 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-package_audit-libs_installed_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-package_tcp_wrappers_removed_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>80 ······</ocil:actions>
81 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_su_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-kernel_module_cramfs_disabled_ocil:questionnaire:1">
83 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·su</ocil:title>83 ······<ocil:title>Disable·Mounting·of·cramfs</ocil:title>
84 ······<ocil:actions>84 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_su_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-kernel_module_cramfs_disabled_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>86 ······</ocil:actions>
87 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_group_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-file_groupownership_sshd_private_key_ocil:questionnaire:1">
89 ······<ocil:title>Verify·Group·Who·Owns·group·File</ocil:title>89 ······<ocil:title>Verify·Group·Ownership·on·SSH·Server·Private·*_key·Key·Files</ocil:title>
90 ······<ocil:actions>90 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_group_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-file_groupownership_sshd_private_key_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>92 ······</ocil:actions>
93 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-service_avahi-daemon_disabled_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-sshd_enable_strictmodes_ocil:questionnaire:1">
95 ······<ocil:title>Disable·Avahi·Server·Software</ocil:title>95 ······<ocil:title>Enable·Use·of·Strict·Mode·Checking</ocil:title>
96 ······<ocil:actions>96 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-service_avahi-daemon_disabled_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-sshd_enable_strictmodes_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>98 ······</ocil:actions>
99 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-set_nftables_new_connections_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-auditd_audispd_disk_full_action_ocil:questionnaire:1">
101 ······<ocil:title>Ensure·all·outbound·and·established·connections·are·configured·for·nftables</ocil:title>101 ······<ocil:title>Configure·audispd's·Plugin·disk_full_action·When·Disk·Is·Full</ocil:title>
102 ······<ocil:actions>102 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-set_nftables_new_connections_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-auditd_audispd_disk_full_action_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>104 ······</ocil:actions>
105 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_setxattr_ocil:questionnaire:1"> 
107 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·setxattr</ocil:title>106 ····<ocil:questionnaire·id="ocil:ssg-grub2_rng_core_default_quality_argument_ocil:questionnaire:1">
 107 ······<ocil:title>Configure·the·confidence·in·TPM·for·entropy</ocil:title>
108 ······<ocil:actions>108 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_setxattr_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-grub2_rng_core_default_quality_argument_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>110 ······</ocil:actions>
111 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_umount_ocil:questionnaire:1"> 
113 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·umount</ocil:title>112 ····<ocil:questionnaire·id="ocil:ssg-account_passwords_pam_faillock_audit_ocil:questionnaire:1">
 113 ······<ocil:title>Account·Lockouts·Must·Be·Logged</ocil:title>
114 ······<ocil:actions>114 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_umount_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-account_passwords_pam_faillock_audit_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>116 ······</ocil:actions>
117 ····</ocil:questionnaire>117 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_grub2_cfg_ocil:questionnaire:1">118 ····<ocil:questionnaire·id="ocil:ssg-sudoers_explicit_command_args_ocil:questionnaire:1">
119 ······<ocil:title>Verify·/boot/grub2/grub.cfg·Group·Ownership</ocil:title>119 ······<ocil:title>Explicit·arguments·in·sudo·specifications</ocil:title>
120 ······<ocil:actions>120 ······<ocil:actions>
Max diff block lines reached; 1868166/1880850 bytes (99.33%) of diff not shown.
54.6 KB
./usr/share/xml/scap/ssg/content/ssg-sle15-xccdf.xml
54.5 KB
./usr/share/xml/scap/ssg/content/ssg-sle15-xccdf.xml
Ordering differences only
    
Offset 72, 420 lines modifiedOffset 72, 420 lines modified
72 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>72 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
73 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>73 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
74 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>74 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
75 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>75 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
77 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>77 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
78 ··<cpe-lang:platform-specification>78 ··<cpe-lang:platform-specification>
 79 ····<cpe-lang:platform·id="not_aarch64_arch_and_not_ppc64le_arch_and_system_with_kernel">
79 ····<cpe-lang:platform·id="package_aide_and_package_systemd"> 
80 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
81 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-package_aide:def:1"/> 
82 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/> 
83 ······</cpe-lang:logical-test> 
84 ····</cpe-lang:platform> 
85 ····<cpe-lang:platform·id="package_libuser"> 
86 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
87 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-package_libuser:def:1"/> 
88 ······</cpe-lang:logical-test> 
89 ····</cpe-lang:platform> 
90 ····<cpe-lang:platform·id="not_bootc"> 
91 ······<cpe-lang:logical-test·operator="AND"·negate="true"> 
92 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-bootc:def:1"/> 
93 ······</cpe-lang:logical-test> 
94 ····</cpe-lang:platform> 
95 ····<cpe-lang:platform·id="package_nftables_and_service_disabled_firewalld_and_system_with_kernel"> 
96 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
97 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/> 
98 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_firewalld:def:1"/> 
99 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
100 ······</cpe-lang:logical-test> 
101 ····</cpe-lang:platform> 
102 ····<cpe-lang:platform·id="machine"> 
103 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
104 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/> 
105 ······</cpe-lang:logical-test> 
106 ····</cpe-lang:platform> 
107 ····<cpe-lang:platform·id="package_squid_and_system_with_kernel"> 
108 ······<cpe-lang:logical-test·operator="AND"·negate="false">80 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 81 ········<cpe-lang:logical-test·operator="AND"·negate="true">
109 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-package_squid:def:1"/>82 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
 83 ········</cpe-lang:logical-test>
 84 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 85 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_ppc64le:def:1"/>
 86 ········</cpe-lang:logical-test>
110 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>87 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
111 ······</cpe-lang:logical-test>88 ······</cpe-lang:logical-test>
112 ····</cpe-lang:platform>89 ····</cpe-lang:platform>
113 ····<cpe-lang:platform·id="package_pam">90 ····<cpe-lang:platform·id="mount_var-tmp">
114 ······<cpe-lang:logical-test·operator="AND"·negate="false">91 ······<cpe-lang:logical-test·operator="AND"·negate="false">
115 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>92 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-tmp:def:1"/>
116 ······</cpe-lang:logical-test>93 ······</cpe-lang:logical-test>
117 ····</cpe-lang:platform>94 ····</cpe-lang:platform>
118 ····<cpe-lang:platform·id="package_autofs_and_system_with_kernel">95 ····<cpe-lang:platform·id="package_autofs_and_system_with_kernel">
119 ······<cpe-lang:logical-test·operator="AND"·negate="false">96 ······<cpe-lang:logical-test·operator="AND"·negate="false">
120 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>97 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>
121 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>98 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
122 ······</cpe-lang:logical-test>99 ······</cpe-lang:logical-test>
123 ····</cpe-lang:platform>100 ····</cpe-lang:platform>
124 ····<cpe-lang:platform·id="mount_tmp">101 ····<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">
125 ······<cpe-lang:logical-test·operator="AND"·negate="false">102 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 103 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 104 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
 105 ········</cpe-lang:logical-test>
 106 ········<cpe-lang:logical-test·operator="AND"·negate="true">
126 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_tmp:def:1"/>107 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
 108 ········</cpe-lang:logical-test>
 109 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
127 ······</cpe-lang:logical-test>110 ······</cpe-lang:logical-test>
128 ····</cpe-lang:platform>111 ····</cpe-lang:platform>
129 ····<cpe-lang:platform·id="package_firewalld_and_package_nftables_and_system_with_kernel">112 ····<cpe-lang:platform·id="ipv6_enabled">
130 ······<cpe-lang:logical-test·operator="AND"·negate="false">113 ······<cpe-lang:logical-test·operator="AND"·negate="false">
131 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/> 
132 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>114 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-ipv6_enabled:def:1"/>
133 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
134 ······</cpe-lang:logical-test>115 ······</cpe-lang:logical-test>
135 ····</cpe-lang:platform>116 ····</cpe-lang:platform>
136 ····<cpe-lang:platform·id="not_s390x_arch">117 ····<cpe-lang:platform·id="package_gdm">
137 ······<cpe-lang:logical-test·operator="AND"·negate="false">118 ······<cpe-lang:logical-test·operator="AND"·negate="false">
138 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>119 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-package_gdm:def:1"/>
139 ······</cpe-lang:logical-test>120 ······</cpe-lang:logical-test>
140 ····</cpe-lang:platform>121 ····</cpe-lang:platform>
141 ····<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">122 ····<cpe-lang:platform·id="package_rsyslog">
142 ······<cpe-lang:logical-test·operator="AND"·negate="false">123 ······<cpe-lang:logical-test·operator="AND"·negate="false">
143 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>124 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>
144 ······</cpe-lang:logical-test>125 ······</cpe-lang:logical-test>
145 ····</cpe-lang:platform>126 ····</cpe-lang:platform>
146 ····<cpe-lang:platform·id="not_package_chrony_and_not_package_ntp">127 ····<cpe-lang:platform·id="not_osbuild_and_system_with_kernel">
147 ······<cpe-lang:logical-test·operator="AND"·negate="false">128 ······<cpe-lang:logical-test·operator="AND"·negate="false">
148 ········<cpe-lang:logical-test·operator="AND"·negate="true">129 ········<cpe-lang:logical-test·operator="AND"·negate="true">
149 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/> 
150 ········</cpe-lang:logical-test> 
151 ········<cpe-lang:logical-test·operator="AND"·negate="true"> 
152 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-package_ntp:def:1"/>130 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_osbuild:def:1"/>
153 ········</cpe-lang:logical-test>131 ········</cpe-lang:logical-test>
 132 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
154 ······</cpe-lang:logical-test>133 ······</cpe-lang:logical-test>
155 ····</cpe-lang:platform>134 ····</cpe-lang:platform>
156 ····<cpe-lang:platform·id="mount_var-log">135 ····<cpe-lang:platform·id="package_chrony_or_package_ntp">
 136 ······<cpe-lang:logical-test·operator="OR"·negate="false">
 137 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
 138 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-package_ntp:def:1"/>
 139 ······</cpe-lang:logical-test>
 140 ····</cpe-lang:platform>
 141 ····<cpe-lang:platform·id="package_bash">
157 ······<cpe-lang:logical-test·operator="AND"·negate="false">142 ······<cpe-lang:logical-test·operator="AND"·negate="false">
158 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-log:def:1"/>143 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>
159 ······</cpe-lang:logical-test>144 ······</cpe-lang:logical-test>
160 ····</cpe-lang:platform>145 ····</cpe-lang:platform>
161 ····<cpe-lang:platform·id="uefi">146 ····<cpe-lang:platform·id="uefi">
162 ······<cpe-lang:logical-test·operator="AND"·negate="false">147 ······<cpe-lang:logical-test·operator="AND"·negate="false">
163 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>148 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>
164 ······</cpe-lang:logical-test>149 ······</cpe-lang:logical-test>
165 ····</cpe-lang:platform>150 ····</cpe-lang:platform>
166 ····<cpe-lang:platform·id="package_bash">151 ····<cpe-lang:platform·id="package_logrotate">
167 ······<cpe-lang:logical-test·operator="AND"·negate="false">152 ······<cpe-lang:logical-test·operator="AND"·negate="false">
168 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>153 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-package_logrotate:def:1"/>
169 ······</cpe-lang:logical-test>154 ······</cpe-lang:logical-test>
170 ····</cpe-lang:platform>155 ····</cpe-lang:platform>
171 ····<cpe-lang:platform·id="package_telnet-server_and_system_with_kernel">156 ····<cpe-lang:platform·id="package_chrony">
172 ······<cpe-lang:logical-test·operator="AND"·negate="false">157 ······<cpe-lang:logical-test·operator="AND"·negate="false">
173 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-package_telnet-server:def:1"/>158 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
174 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
175 ······</cpe-lang:logical-test>159 ······</cpe-lang:logical-test>
176 ····</cpe-lang:platform>160 ····</cpe-lang:platform>
177 ····<cpe-lang:platform·id="package_iptables">161 ····<cpe-lang:platform·id="package_sssd">
178 ······<cpe-lang:logical-test·operator="AND"·negate="false">162 ······<cpe-lang:logical-test·operator="AND"·negate="false">
179 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>163 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-package_sssd:def:1"/>
Max diff block lines reached; 42893/55664 bytes (77.06%) of diff not shown.
1.05 MB
./usr/share/xml/scap/ssg/content/ssg-slmicro5-ds.xml
1.05 MB
./usr/share/xml/scap/ssg/content/ssg-slmicro5-ds.xml
    
Offset 21, 15 lines modifiedOffset 21, 15 lines modified
21 ····<ds:checks>21 ····<ds:checks>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-slmicro5-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-slmicro5-oval.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-slmicro5-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-slmicro5-oval.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-slmicro5-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-slmicro5-ocil.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-slmicro5-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-slmicro5-ocil.xml"/>
24 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-slmicro5-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-slmicro5-cpe-oval.xml"/>24 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-slmicro5-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-slmicro5-cpe-oval.xml"/>
25 ······<ds:component-ref·id="scap_org.open-scap_cref_pub-projects-security-oval-suse.linux.enterprise.micro.5-patch.xml.bz2"·xlink:href="https://ftp.suse.com/pub/projects/security/oval/suse.linux.enterprise.micro.5-patch.xml.bz2"/>25 ······<ds:component-ref·id="scap_org.open-scap_cref_pub-projects-security-oval-suse.linux.enterprise.micro.5-patch.xml.bz2"·xlink:href="https://ftp.suse.com/pub/projects/security/oval/suse.linux.enterprise.micro.5-patch.xml.bz2"/>
26 ····</ds:checks>26 ····</ds:checks>
27 ··</ds:data-stream>27 ··</ds:data-stream>
28 ··<ds:component·id="scap_org.open-scap_comp_ssg-slmicro5-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">28 ··<ds:component·id="scap_org.open-scap_comp_ssg-slmicro5-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
29 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">29 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
30 ······<cpe-dict:cpe-item·name="cpe:/o:suse:sle-micro:5.3">30 ······<cpe-dict:cpe-item·name="cpe:/o:suse:sle-micro:5.3">
31 ········<cpe-dict:title·xml:lang="en-us">SLE·Micro·5.3</cpe-dict:title>31 ········<cpe-dict:title·xml:lang="en-us">SLE·Micro·5.3</cpe-dict:title>
32 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml">oval:ssg-installed_OS_is_slmicro5:def:1</cpe-dict:check>32 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml">oval:ssg-installed_OS_is_slmicro5:def:1</cpe-dict:check>
33 ······</cpe-dict:cpe-item>33 ······</cpe-dict:cpe-item>
34 ······<cpe-dict:cpe-item·name="cpe:/o:suse:sle-micro:5.4">34 ······<cpe-dict:cpe-item·name="cpe:/o:suse:sle-micro:5.4">
35 ········<cpe-dict:title·xml:lang="en-us">SLE·Micro·5.4</cpe-dict:title>35 ········<cpe-dict:title·xml:lang="en-us">SLE·Micro·5.4</cpe-dict:title>
Offset 41, 15 lines modifiedOffset 41, 15 lines modified
41 ······</cpe-dict:cpe-item>41 ······</cpe-dict:cpe-item>
42 ······<cpe-dict:cpe-item·name="cpe:/o:suse:sle-microos:5.2">42 ······<cpe-dict:cpe-item·name="cpe:/o:suse:sle-microos:5.2">
43 ········<cpe-dict:title·xml:lang="en-us">SLE·MicroOS·5.2</cpe-dict:title>43 ········<cpe-dict:title·xml:lang="en-us">SLE·MicroOS·5.2</cpe-dict:title>
44 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml">oval:ssg-installed_OS_is_slmicro5:def:1</cpe-dict:check>44 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml">oval:ssg-installed_OS_is_slmicro5:def:1</cpe-dict:check>
45 ······</cpe-dict:cpe-item>45 ······</cpe-dict:cpe-item>
46 ····</cpe-dict:cpe-list>46 ····</cpe-dict:cpe-list>
47 ··</ds:component>47 ··</ds:component>
48 ··<ds:component·id="scap_org.open-scap_comp_ssg-slmicro5-xccdf.xml"·timestamp="2025-02-28T20:08:00">48 ··<ds:component·id="scap_org.open-scap_comp_ssg-slmicro5-xccdf.xml"·timestamp="2025-03-01T22:08:00">
49 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_SLMICRO5"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">49 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_SLMICRO5"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
50 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>50 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
51 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·SUSE·Linux·Enterprise·Micro·5</xccdf-1.2:title>51 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·SUSE·Linux·Enterprise·Micro·5</xccdf-1.2:title>
52 ······<xccdf-1.2:description>52 ······<xccdf-1.2:description>
53 ········This·guide·presents·a·catalog·of·security-relevant53 ········This·guide·presents·a·catalog·of·security-relevant
54 configuration·settings·for·SUSE·Linux·Enterprise·Micro·5.·It·is·a·rendering·of54 configuration·settings·for·SUSE·Linux·Enterprise·Micro·5.·It·is·a·rendering·of
55 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)55 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 119, 307 lines modifiedOffset 119, 307 lines modified
119 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>119 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
120 ······<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>120 ······<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
121 ······<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>121 ······<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
122 ······<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>122 ······<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
123 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>123 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
124 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>124 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
125 ······<cpe-lang:platform-specification>125 ······<cpe-lang:platform-specification>
126 ········<cpe-lang:platform·id="package_aide_and_package_systemd">126 ········<cpe-lang:platform·id="not_aarch64_arch_and_not_ppc64le_arch_and_system_with_kernel">
127 ··········<cpe-lang:logical-test·operator="AND"·negate="false">127 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
128 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-package_aide:def:1"/> 
129 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/> 
130 ··········</cpe-lang:logical-test> 
131 ········</cpe-lang:platform> 
132 ········<cpe-lang:platform·id="not_bootc"> 
133 ··········<cpe-lang:logical-test·operator="AND"·negate="true">128 ············<cpe-lang:logical-test·operator="AND"·negate="true">
 129 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
 130 ············</cpe-lang:logical-test>
 131 ············<cpe-lang:logical-test·operator="AND"·negate="true">
 132 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_ppc64le:def:1"/>
 133 ············</cpe-lang:logical-test>
134 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-bootc:def:1"/>134 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
135 ··········</cpe-lang:logical-test>135 ··········</cpe-lang:logical-test>
136 ········</cpe-lang:platform>136 ········</cpe-lang:platform>
137 ········<cpe-lang:platform·id="package_nftables_and_service_disabled_firewalld_and_system_with_kernel">137 ········<cpe-lang:platform·id="package_autofs_and_system_with_kernel">
138 ··········<cpe-lang:logical-test·operator="AND"·negate="false">138 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
139 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>139 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>
140 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_firewalld:def:1"/> 
141 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>140 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
142 ··········</cpe-lang:logical-test>141 ··········</cpe-lang:logical-test>
143 ········</cpe-lang:platform>142 ········</cpe-lang:platform>
144 ········<cpe-lang:platform·id="machine">143 ········<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">
145 ··········<cpe-lang:logical-test·operator="AND"·negate="false">144 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 145 ············<cpe-lang:logical-test·operator="AND"·negate="true">
 146 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
 147 ············</cpe-lang:logical-test>
 148 ············<cpe-lang:logical-test·operator="AND"·negate="true">
 149 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
 150 ············</cpe-lang:logical-test>
146 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>151 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
147 ··········</cpe-lang:logical-test>152 ··········</cpe-lang:logical-test>
148 ········</cpe-lang:platform>153 ········</cpe-lang:platform>
149 ········<cpe-lang:platform·id="package_squid_and_system_with_kernel">154 ········<cpe-lang:platform·id="ipv6_enabled">
150 ··········<cpe-lang:logical-test·operator="AND"·negate="false">155 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
151 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-package_squid:def:1"/>156 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-ipv6_enabled:def:1"/>
152 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
153 ··········</cpe-lang:logical-test>157 ··········</cpe-lang:logical-test>
154 ········</cpe-lang:platform>158 ········</cpe-lang:platform>
155 ········<cpe-lang:platform·id="package_pam">159 ········<cpe-lang:platform·id="package_gdm">
156 ··········<cpe-lang:logical-test·operator="AND"·negate="false">160 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
157 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>161 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-package_gdm:def:1"/>
158 ··········</cpe-lang:logical-test>162 ··········</cpe-lang:logical-test>
159 ········</cpe-lang:platform>163 ········</cpe-lang:platform>
160 ········<cpe-lang:platform·id="package_autofs_and_system_with_kernel">164 ········<cpe-lang:platform·id="not_osbuild_and_system_with_kernel">
161 ··········<cpe-lang:logical-test·operator="AND"·negate="false">165 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 166 ············<cpe-lang:logical-test·operator="AND"·negate="true">
162 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>167 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_osbuild:def:1"/>
 168 ············</cpe-lang:logical-test>
163 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>169 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
164 ··········</cpe-lang:logical-test>170 ··········</cpe-lang:logical-test>
165 ········</cpe-lang:platform>171 ········</cpe-lang:platform>
166 ········<cpe-lang:platform·id="package_firewalld_and_package_nftables_and_system_with_kernel">172 ········<cpe-lang:platform·id="package_chrony_or_package_ntp">
167 ··········<cpe-lang:logical-test·operator="AND"·negate="false">173 ··········<cpe-lang:logical-test·operator="OR"·negate="false">
168 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>174 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
169 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>175 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-package_ntp:def:1"/>
170 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
171 ··········</cpe-lang:logical-test>176 ··········</cpe-lang:logical-test>
172 ········</cpe-lang:platform>177 ········</cpe-lang:platform>
173 ········<cpe-lang:platform·id="not_s390x_arch">178 ········<cpe-lang:platform·id="package_bash">
174 ··········<cpe-lang:logical-test·operator="AND"·negate="false">179 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
175 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>180 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>
176 ··········</cpe-lang:logical-test>181 ··········</cpe-lang:logical-test>
177 ········</cpe-lang:platform>182 ········</cpe-lang:platform>
178 ········<cpe-lang:platform·id="uefi">183 ········<cpe-lang:platform·id="uefi">
179 ··········<cpe-lang:logical-test·operator="AND"·negate="false">184 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
180 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>185 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>
181 ··········</cpe-lang:logical-test>186 ··········</cpe-lang:logical-test>
182 ········</cpe-lang:platform>187 ········</cpe-lang:platform>
183 ········<cpe-lang:platform·id="package_bash"> 
184 ··········<cpe-lang:logical-test·operator="AND"·negate="false"> 
185 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/> 
186 ··········</cpe-lang:logical-test> 
187 ········</cpe-lang:platform> 
188 ········<cpe-lang:platform·id="package_iptables">188 ········<cpe-lang:platform·id="package_logrotate">
189 ··········<cpe-lang:logical-test·operator="AND"·negate="false">189 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
190 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>190 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-package_logrotate:def:1"/>
191 ··········</cpe-lang:logical-test>191 ··········</cpe-lang:logical-test>
192 ········</cpe-lang:platform>192 ········</cpe-lang:platform>
193 ········<cpe-lang:platform·id="grub2">193 ········<cpe-lang:platform·id="package_chrony">
194 ··········<cpe-lang:logical-test·operator="AND"·negate="false">194 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
195 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>195 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
196 ··········</cpe-lang:logical-test>196 ··········</cpe-lang:logical-test>
197 ········</cpe-lang:platform>197 ········</cpe-lang:platform>
198 ········<cpe-lang:platform·id="package_sssd">198 ········<cpe-lang:platform·id="package_sssd">
199 ··········<cpe-lang:logical-test·operator="AND"·negate="false">199 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
200 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-package_sssd:def:1"/>200 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-package_sssd:def:1"/>
Max diff block lines reached; 1082810/1096689 bytes (98.73%) of diff not shown.
989 KB
./usr/share/xml/scap/ssg/content/ssg-slmicro5-ocil.xml
988 KB
./usr/share/xml/scap/ssg/content/ssg-slmicro5-ocil.xml
Ordering differences only
    
Offset 3, 7316 lines modifiedOffset 3, 7358 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-set_ipv6_loopback_traffic_ocil:questionnaire:1"> 
11 ······<ocil:title>Set·configuration·for·IPv6·loopback·traffic</ocil:title> 
12 ······<ocil:actions> 
13 ········<ocil:test_action_ref>ocil:ssg-set_ipv6_loopback_traffic_action:testaction:1</ocil:test_action_ref> 
14 ······</ocil:actions> 
15 ····</ocil:questionnaire> 
16 ····<ocil:questionnaire·id="ocil:ssg-package_logrotate_installed_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-postfix_network_listening_disabled_ocil:questionnaire:1">
17 ······<ocil:title>Ensure·logrotate·is·Installed</ocil:title>11 ······<ocil:title>Disable·Postfix·Network·Listening</ocil:title>
18 ······<ocil:actions>12 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-package_logrotate_installed_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-postfix_network_listening_disabled_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>14 ······</ocil:actions>
21 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_ip_forward_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-partition_for_dev_shm_ocil:questionnaire:1">
23 ······<ocil:title>Disable·Kernel·Parameter·for·IP·Forwarding·on·IPv4·Interfaces</ocil:title>17 ······<ocil:title>Ensure·/dev/shm·is·configured</ocil:title>
24 ······<ocil:actions>18 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_ip_forward_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-partition_for_dev_shm_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>20 ······</ocil:actions>
27 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_unauthorized_world_writable_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_issue_net_ocil:questionnaire:1">
29 ······<ocil:title>Ensure·No·World-Writable·Files·Exist</ocil:title>23 ······<ocil:title>Verify·permissions·on·System·Login·Banner·for·Remote·Connections</ocil:title>
30 ······<ocil:actions>24 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-file_permissions_unauthorized_world_writable_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-file_permissions_etc_issue_net_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>26 ······</ocil:actions>
33 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-accounts_have_homedir_login_defs_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-chronyd_or_ntpd_set_maxpoll_ocil:questionnaire:1">
35 ······<ocil:title>Ensure·Home·Directories·are·Created·for·New·Users</ocil:title>29 ······<ocil:title>Configure·Time·Service·Maxpoll·Interval</ocil:title>
36 ······<ocil:actions>30 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-accounts_have_homedir_login_defs_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-chronyd_or_ntpd_set_maxpoll_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>32 ······</ocil:actions>
39 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-package_xorg-x11-server-common_removed_ocil:questionnaire:1"> 
41 ······<ocil:title>Remove·the·X·Windows·Package·Group</ocil:title>34 ····<ocil:questionnaire·id="ocil:ssg-package_policycoreutils-python-utils_installed_ocil:questionnaire:1">
 35 ······<ocil:title>Install·policycoreutils-python-utils·package</ocil:title>
42 ······<ocil:actions>36 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-package_xorg-x11-server-common_removed_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-package_policycoreutils-python-utils_installed_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>38 ······</ocil:actions>
45 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_space_left_action_ocil:questionnaire:1"> 
47 ······<ocil:title>Configure·auditd·space_left·Action·on·Low·Disk·Space</ocil:title>40 ····<ocil:questionnaire·id="ocil:ssg-file_owner_grub2_cfg_ocil:questionnaire:1">
 41 ······<ocil:title>Verify·/boot/grub2/grub.cfg·User·Ownership</ocil:title>
48 ······<ocil:actions>42 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-auditd_data_retention_space_left_action_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-file_owner_grub2_cfg_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>44 ······</ocil:actions>
51 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-set_loopback_traffic_ocil:questionnaire:1">46 ····<ocil:questionnaire·id="ocil:ssg-service_dovecot_disabled_ocil:questionnaire:1">
53 ······<ocil:title>Set·configuration·for·loopback·traffic</ocil:title>47 ······<ocil:title>Disable·Dovecot·Service</ocil:title>
54 ······<ocil:actions>48 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-set_loopback_traffic_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-service_dovecot_disabled_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>50 ······</ocil:actions>
57 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_time_stime_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-sudo_add_use_pty_ocil:questionnaire:1">
59 ······<ocil:title>Record·Attempts·to·Alter·Time·Through·stime</ocil:title>53 ······<ocil:title>Ensure·Only·Users·Logged·In·To·Real·tty·Can·Execute·Sudo·-·sudo·use_pty</ocil:title>
60 ······<ocil:actions>54 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-audit_rules_time_stime_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-sudo_add_use_pty_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>56 ······</ocil:actions>
63 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_admin_space_left_action_ocil:questionnaire:1"> 
65 ······<ocil:title>Configure·auditd·admin_space_left·Action·on·Low·Disk·Space</ocil:title>58 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_creat_ocil:questionnaire:1">
 59 ······<ocil:title>Record·Unsuccessful·Access·Attempts·to·Files·-·creat</ocil:title>
66 ······<ocil:actions>60 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-auditd_data_retention_admin_space_left_action_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_creat_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>62 ······</ocil:actions>
69 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-chronyd_run_as_chrony_user_ocil:questionnaire:1"> 
71 ······<ocil:title>Ensure·that·chronyd·is·running·under·chrony·user·account</ocil:title>64 ····<ocil:questionnaire·id="ocil:ssg-file_owner_backup_etc_shadow_ocil:questionnaire:1">
 65 ······<ocil:title>Verify·Group·Who·Owns·Backup·shadow·File</ocil:title>
72 ······<ocil:actions>66 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-chronyd_run_as_chrony_user_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-file_owner_backup_etc_shadow_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>68 ······</ocil:actions>
75 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_mac_modification_usr_share_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-banner_etc_motd_ocil:questionnaire:1">
77 ······<ocil:title>Record·Events·that·Modify·the·System's·Mandatory·Access·Controls·in·usr/share</ocil:title>71 ······<ocil:title>Modify·the·System·Message·of·the·Day·Banner</ocil:title>
78 ······<ocil:actions>72 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-audit_rules_mac_modification_usr_share_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-banner_etc_motd_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>74 ······</ocil:actions>
81 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_user_known_hosts_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_passwd_ocil:questionnaire:1">
83 ······<ocil:title>Disable·SSH·Support·for·User·Known·Hosts</ocil:title>77 ······<ocil:title>Verify·Group·Who·Owns·passwd·File</ocil:title>
84 ······<ocil:actions>78 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_user_known_hosts_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_passwd_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>80 ······</ocil:actions>
87 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-journald_forward_to_syslog_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-mount_option_dev_shm_nosuid_ocil:questionnaire:1">
89 ······<ocil:title>Ensure·journald·is·configured·to·send·logs·to·rsyslog</ocil:title>83 ······<ocil:title>Add·nosuid·Option·to·/dev/shm</ocil:title>
90 ······<ocil:actions>84 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-journald_forward_to_syslog_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-mount_option_dev_shm_nosuid_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>86 ······</ocil:actions>
93 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-ensure_GPG_keys_are_configured_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_rmmod_ocil:questionnaire:1">
95 ······<ocil:title>Ensure·GPG·keys·are·configured</ocil:title>89 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·rmmod</ocil:title>
96 ······<ocil:actions>90 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-ensure_GPG_keys_are_configured_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_rmmod_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>92 ······</ocil:actions>
99 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-ensure_gpgcheck_globally_activated_ocil:questionnaire:1"> 
101 ······<ocil:title>Ensure·gpgcheck·Enabled·In·Main·zypper·Configuration</ocil:title>94 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_backup_etc_passwd_ocil:questionnaire:1">
 95 ······<ocil:title>Verify·Group·Who·Owns·Backup·passwd·File</ocil:title>
102 ······<ocil:actions>96 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-ensure_gpgcheck_globally_activated_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_backup_etc_passwd_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>98 ······</ocil:actions>
105 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-sysctl_kernel_dmesg_restrict_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_execution_chmod_ocil:questionnaire:1">
107 ······<ocil:title>Restrict·Access·to·Kernel·Message·Buffer</ocil:title>101 ······<ocil:title>Record·Any·Attempts·to·Run·chmod</ocil:title>
108 ······<ocil:actions>102 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-sysctl_kernel_dmesg_restrict_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-audit_rules_execution_chmod_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>104 ······</ocil:actions>
111 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-set_ip6tables_default_rule_ocil:questionnaire:1">106 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_grub2_cfg_ocil:questionnaire:1">
113 ······<ocil:title>Set·Default·ip6tables·Policy·for·Incoming·Packets</ocil:title>107 ······<ocil:title>Verify·/boot/grub2/grub.cfg·Group·Ownership</ocil:title>
114 ······<ocil:actions>108 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-set_ip6tables_default_rule_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_grub2_cfg_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>110 ······</ocil:actions>
117 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-sshd_use_approved_macs_ordered_stig_ocil:questionnaire:1"> 
119 ······<ocil:title>Use·Only·FIPS·140-2·Validated·MACs</ocil:title>112 ····<ocil:questionnaire·id="ocil:ssg-display_login_attempts_ocil:questionnaire:1">
 113 ······<ocil:title>Ensure·PAM·Displays·Last·Logon/Access·Notification</ocil:title>
120 ······<ocil:actions>114 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-sshd_use_approved_macs_ordered_stig_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-display_login_attempts_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>116 ······</ocil:actions>
123 ····</ocil:questionnaire>117 ····</ocil:questionnaire>
Max diff block lines reached; 999498/1012037 bytes (98.76%) of diff not shown.
39.8 KB
./usr/share/xml/scap/ssg/content/ssg-slmicro5-xccdf.xml
39.7 KB
./usr/share/xml/scap/ssg/content/ssg-slmicro5-xccdf.xml
Ordering differences only
    
Offset 72, 307 lines modifiedOffset 72, 307 lines modified
72 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>72 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
73 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>73 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
74 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>74 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
75 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>75 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
77 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>77 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
78 ··<cpe-lang:platform-specification>78 ··<cpe-lang:platform-specification>
79 ····<cpe-lang:platform·id="package_aide_and_package_systemd">79 ····<cpe-lang:platform·id="not_aarch64_arch_and_not_ppc64le_arch_and_system_with_kernel">
80 ······<cpe-lang:logical-test·operator="AND"·negate="false">80 ······<cpe-lang:logical-test·operator="AND"·negate="false">
81 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-package_aide:def:1"/> 
82 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/> 
83 ······</cpe-lang:logical-test> 
84 ····</cpe-lang:platform> 
85 ····<cpe-lang:platform·id="not_bootc"> 
86 ······<cpe-lang:logical-test·operator="AND"·negate="true">81 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 82 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
 83 ········</cpe-lang:logical-test>
 84 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 85 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_ppc64le:def:1"/>
 86 ········</cpe-lang:logical-test>
87 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-bootc:def:1"/>87 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
88 ······</cpe-lang:logical-test>88 ······</cpe-lang:logical-test>
89 ····</cpe-lang:platform>89 ····</cpe-lang:platform>
90 ····<cpe-lang:platform·id="package_nftables_and_service_disabled_firewalld_and_system_with_kernel">90 ····<cpe-lang:platform·id="package_autofs_and_system_with_kernel">
91 ······<cpe-lang:logical-test·operator="AND"·negate="false">91 ······<cpe-lang:logical-test·operator="AND"·negate="false">
92 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>92 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>
93 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_firewalld:def:1"/> 
94 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>93 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
95 ······</cpe-lang:logical-test>94 ······</cpe-lang:logical-test>
96 ····</cpe-lang:platform>95 ····</cpe-lang:platform>
97 ····<cpe-lang:platform·id="machine">96 ····<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">
98 ······<cpe-lang:logical-test·operator="AND"·negate="false">97 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 98 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 99 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
 100 ········</cpe-lang:logical-test>
 101 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 102 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
 103 ········</cpe-lang:logical-test>
99 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>104 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
100 ······</cpe-lang:logical-test>105 ······</cpe-lang:logical-test>
101 ····</cpe-lang:platform>106 ····</cpe-lang:platform>
102 ····<cpe-lang:platform·id="package_squid_and_system_with_kernel">107 ····<cpe-lang:platform·id="ipv6_enabled">
103 ······<cpe-lang:logical-test·operator="AND"·negate="false">108 ······<cpe-lang:logical-test·operator="AND"·negate="false">
104 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-package_squid:def:1"/>109 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-ipv6_enabled:def:1"/>
105 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
106 ······</cpe-lang:logical-test>110 ······</cpe-lang:logical-test>
107 ····</cpe-lang:platform>111 ····</cpe-lang:platform>
108 ····<cpe-lang:platform·id="package_pam">112 ····<cpe-lang:platform·id="package_gdm">
109 ······<cpe-lang:logical-test·operator="AND"·negate="false">113 ······<cpe-lang:logical-test·operator="AND"·negate="false">
110 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>114 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-package_gdm:def:1"/>
111 ······</cpe-lang:logical-test>115 ······</cpe-lang:logical-test>
112 ····</cpe-lang:platform>116 ····</cpe-lang:platform>
113 ····<cpe-lang:platform·id="package_autofs_and_system_with_kernel">117 ····<cpe-lang:platform·id="not_osbuild_and_system_with_kernel">
114 ······<cpe-lang:logical-test·operator="AND"·negate="false">118 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 119 ········<cpe-lang:logical-test·operator="AND"·negate="true">
115 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>120 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_osbuild:def:1"/>
 121 ········</cpe-lang:logical-test>
116 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>122 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
117 ······</cpe-lang:logical-test>123 ······</cpe-lang:logical-test>
118 ····</cpe-lang:platform>124 ····</cpe-lang:platform>
119 ····<cpe-lang:platform·id="package_firewalld_and_package_nftables_and_system_with_kernel">125 ····<cpe-lang:platform·id="package_chrony_or_package_ntp">
120 ······<cpe-lang:logical-test·operator="AND"·negate="false">126 ······<cpe-lang:logical-test·operator="OR"·negate="false">
121 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>127 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
122 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>128 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-package_ntp:def:1"/>
123 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
124 ······</cpe-lang:logical-test>129 ······</cpe-lang:logical-test>
125 ····</cpe-lang:platform>130 ····</cpe-lang:platform>
126 ····<cpe-lang:platform·id="not_s390x_arch">131 ····<cpe-lang:platform·id="package_bash">
127 ······<cpe-lang:logical-test·operator="AND"·negate="false">132 ······<cpe-lang:logical-test·operator="AND"·negate="false">
128 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>133 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>
129 ······</cpe-lang:logical-test>134 ······</cpe-lang:logical-test>
130 ····</cpe-lang:platform>135 ····</cpe-lang:platform>
131 ····<cpe-lang:platform·id="uefi">136 ····<cpe-lang:platform·id="uefi">
132 ······<cpe-lang:logical-test·operator="AND"·negate="false">137 ······<cpe-lang:logical-test·operator="AND"·negate="false">
133 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>138 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>
134 ······</cpe-lang:logical-test>139 ······</cpe-lang:logical-test>
135 ····</cpe-lang:platform>140 ····</cpe-lang:platform>
136 ····<cpe-lang:platform·id="package_bash"> 
137 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
138 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/> 
139 ······</cpe-lang:logical-test> 
140 ····</cpe-lang:platform> 
141 ····<cpe-lang:platform·id="package_iptables">141 ····<cpe-lang:platform·id="package_logrotate">
142 ······<cpe-lang:logical-test·operator="AND"·negate="false">142 ······<cpe-lang:logical-test·operator="AND"·negate="false">
143 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>143 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-package_logrotate:def:1"/>
144 ······</cpe-lang:logical-test>144 ······</cpe-lang:logical-test>
145 ····</cpe-lang:platform>145 ····</cpe-lang:platform>
146 ····<cpe-lang:platform·id="grub2">146 ····<cpe-lang:platform·id="package_chrony">
147 ······<cpe-lang:logical-test·operator="AND"·negate="false">147 ······<cpe-lang:logical-test·operator="AND"·negate="false">
148 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>148 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
149 ······</cpe-lang:logical-test>149 ······</cpe-lang:logical-test>
150 ····</cpe-lang:platform>150 ····</cpe-lang:platform>
151 ····<cpe-lang:platform·id="package_sssd">151 ····<cpe-lang:platform·id="package_sssd">
152 ······<cpe-lang:logical-test·operator="AND"·negate="false">152 ······<cpe-lang:logical-test·operator="AND"·negate="false">
153 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-package_sssd:def:1"/>153 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-package_sssd:def:1"/>
154 ······</cpe-lang:logical-test>154 ······</cpe-lang:logical-test>
155 ····</cpe-lang:platform>155 ····</cpe-lang:platform>
156 ····<cpe-lang:platform·id="wifi-iface"> 
157 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
158 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_wifi_interface:def:1"/> 
159 ······</cpe-lang:logical-test> 
160 ····</cpe-lang:platform> 
161 ····<cpe-lang:platform·id="package_nftables_and_service_disabled_firewalld">156 ····<cpe-lang:platform·id="package_nftables_and_service_disabled_firewalld_and_service_disabled_ufw">
162 ······<cpe-lang:logical-test·operator="AND"·negate="false">157 ······<cpe-lang:logical-test·operator="AND"·negate="false">
163 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>158 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
164 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_firewalld:def:1"/>159 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_firewalld:def:1"/>
 160 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_ufw:def:1"/>
165 ······</cpe-lang:logical-test>161 ······</cpe-lang:logical-test>
166 ····</cpe-lang:platform>162 ····</cpe-lang:platform>
167 ····<cpe-lang:platform·id="package_pam_apparmor">163 ····<cpe-lang:platform·id="package_firewalld">
168 ······<cpe-lang:logical-test·operator="AND"·negate="false">164 ······<cpe-lang:logical-test·operator="AND"·negate="false">
169 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-package_pam_apparmor:def:1"/>165 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>
170 ······</cpe-lang:logical-test>166 ······</cpe-lang:logical-test>
171 ····</cpe-lang:platform>167 ····</cpe-lang:platform>
172 ····<cpe-lang:platform·id="package_systemd">168 ····<cpe-lang:platform·id="package_systemd">
173 ······<cpe-lang:logical-test·operator="AND"·negate="false">169 ······<cpe-lang:logical-test·operator="AND"·negate="false">
174 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>170 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>
175 ······</cpe-lang:logical-test>171 ······</cpe-lang:logical-test>
176 ····</cpe-lang:platform>172 ····</cpe-lang:platform>
 173 ····<cpe-lang:platform·id="not_bootc_and_not_container">
177 ····<cpe-lang:platform·id="package_avahi_and_system_with_kernel"> 
178 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
179 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-package_avahi:def:1"/> 
180 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
181 ······</cpe-lang:logical-test> 
182 ····</cpe-lang:platform> 
183 ····<cpe-lang:platform·id="service_disabled_iptables_and_service_disabled_ufw_and_system_with_kernel"> 
Max diff block lines reached; 26398/40547 bytes (65.10%) of diff not shown.